Alright, here's the ComboFix log file contents...
ComboFix 08-09-01.01 - Mitz 2008-09-02 0:49:09.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2586 [GMT -5:00]
Running from: C:\Documents and Settings\Mitz.DELL8400\Desktop\ComboFix.exe
* Created a new restore point
[color=\"red\"]
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Justin.DELL8400\Application Data\macromedia\Flash Player\#SharedObjects\DNNKJY7X\bin.clearspring.com
C:\Documents and Settings\Justin.DELL8400\Application Data\macromedia\Flash Player\#SharedObjects\DNNKJY7X\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\Justin.DELL8400\Application Data\macromedia\Flash Player\#SharedObjects\DNNKJY7X\interclick.com
C:\Documents and Settings\Justin.DELL8400\Application Data\macromedia\Flash Player\#SharedObjects\DNNKJY7X\interclick.com\ud.sol
C:\Documents and Settings\Justin.DELL8400\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\Justin.DELL8400\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\Justin.DELL8400\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Justin.DELL8400\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Mitz.DELL8400\Application Data\macromedia\Flash Player\#SharedObjects\AJUGRYFX\bin.clearspring.com
C:\Documents and Settings\Mitz.DELL8400\Application Data\macromedia\Flash Player\#SharedObjects\AJUGRYFX\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\Mitz.DELL8400\Application Data\macromedia\Flash Player\#SharedObjects\AJUGRYFX\interclick.com
C:\Documents and Settings\Mitz.DELL8400\Application Data\macromedia\Flash Player\#SharedObjects\AJUGRYFX\interclick.com\ud.sol
C:\Documents and Settings\Mitz.DELL8400\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\Mitz.DELL8400\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\Mitz.DELL8400\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Mitz.DELL8400\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Mitz\Application Data\macromedia\Flash Player\#SharedObjects\T8B4VECJ\bin.clearspring.com
C:\Documents and Settings\Mitz\Application Data\macromedia\Flash Player\#SharedObjects\T8B4VECJ\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\Mitz\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\Mitz\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\Mitz\Cookies\mitz@myspace[1].txt
C:\Documents and Settings\Mitz\Cookies\
[email protected][2].txt
C:\Program Files\outlook
C:\WINDOWS\BMef99702a.txt
C:\WINDOWS\BMef99702a.xml
C:\WINDOWS\SYSTEM32\cbmwkttt.ini
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\khrboabp.ini
C:\WINDOWS\SYSTEM32\KjiRqBeg.ini
C:\WINDOWS\SYSTEM32\KjiRqBeg.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\wanpacket.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Legacy_IPRIP
-------\Legacy_NPF
-------\Service_6to4
-------\Service_Iprip
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2008-08-02 to 2008-09-02 )))))))))))))))))))))))))))))))
.
2008-09-01 22:54 . 2008-09-01 22:55 <DIR> d-------- C:\Dell922
2008-09-01 22:42 . 2008-09-01 22:42 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-01 22:23 . 2008-09-01 22:33 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SecTaskMan
2008-09-01 22:22 . 2008-09-01 22:23 <DIR> d-------- C:\Program Files\Security Task Manager
2008-09-01 22:03 . 2008-09-01 22:03 <DIR> d-------- C:\spoolerlogs
2008-09-01 15:01 . 2008-09-01 15:01 <DIR> d-------- C:\Documents and Settings\Mitz.DELL8400\Application Data\Media Player Classic
2008-09-01 14:44 . 2008-09-01 14:44 <DIR> d-------- C:\Documents and Settings\Mitz.DELL8400\Application Data\CyberLink
2008-09-01 14:37 . 2008-09-01 14:37 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\NVIDIA Corporation
2008-09-01 14:37 . 2006-03-29 08:50 671,744 --a------ C:\WINDOWS\SYSTEM32\DolbyHph.dll
2008-09-01 14:37 . 2006-03-29 08:51 60,416 --a------ C:\WINDOWS\SYSTEM32\DSETUP.dll
2008-09-01 14:37 . 2006-03-29 08:49 9,856 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pfc.sys
2008-09-01 14:37 . 2006-05-05 19:21 4,608 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\nvport.sys
2008-08-31 16:42 . 2008-08-31 16:44 <DIR> d-------- C:\WINDOWS\SYSTEM32\Adobe
2008-08-30 01:02 . 2008-07-22 09:45 1,214,526 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\sysmain.sdb
2008-08-30 01:02 . 2008-07-22 09:45 790,846 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\apph_sp.sdb
2008-08-30 01:02 . 2008-07-22 09:45 9,696 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\drvmain.sdb
2008-08-29 23:22 . 2008-08-29 23:22 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-08-29 23:22 . 2008-08-29 23:22 <DIR> d-------- C:\Documents and Settings\Mitz.DELL8400\Application Data\SUPERAntiSpyware.com
2008-08-29 23:22 . 2008-08-29 23:22 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-08-28 22:32 . 2008-08-28 22:33 <DIR> d-------- C:\Program Files\LimeWire Acceleration Patch
2008-08-28 20:09 . 2008-08-28 20:09 <DIR> d-------- C:\Documents and Settings\LocalService.NT AUTHORITY.000\Application Data\SACore
2008-08-27 18:47 . 2008-08-27 18:47 <DIR> d-------- C:\Program Files\ConvertHelper
2008-08-26 01:37 . 2008-08-26 01:41 <DIR> d-------- C:\Documents and Settings\Mitz.DELL8400\dwhelper
2008-08-25 21:29 . 2008-08-25 21:29 <DIR> d-------- C:\Program Files\DVBPortal
2008-08-22 21:46 . 2008-08-22 21:46 <DIR> d-------- C:\Documents and Settings\Mitz.DELL8400\Application Data\Windows Search
2008-08-14 16:10 . 2008-05-01 09:33 331,776 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\msadce.dll
2008-08-14 16:09 . 2008-04-11 14:04 691,712 -----c--- C:\WINDOWS\SYSTEM32\DLLCACHE\inetcomm.dll
2008-08-11 22:12 . 2008-08-11 22:12 <DIR> d-------- C:\Documents and Settings\Mitz.DELL8400\Application Data\Ubisoft
2008-08-11 22:06 . 2008-08-11 22:06 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Ubisoft
2008-08-11 22:05 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\SYSTEM32\d3dx9_32.dll
2008-08-11 21:56 . 2008-08-11 21:56 <DIR> d-------- C:\Program Files\Ubisoft
2008-08-06 23:38 . 2008-05-16 11:48 446,464 --a------ C:\WINDOWS\SYSTEM32\NVUNINST.EXE
2008-08-06 23:35 . 2008-08-06 23:35 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2008-08-06 23:35 . 2008-08-06 23:35 <DIR> d-------- C:\Documents and Settings\Mitz.DELL8400\Application Data\SystemRequirementsLab
2008-08-06 22:52 . 2008-08-16 11:44 23 --a------ C:\WINDOWS\BlendSettings.ini
2008-08-06 21:58 . 2008-08-10 09:07 <DIR> d-------- C:\Program Files\Bethesda Softworks
2008-08-06 21:40 . 2008-08-06 21:40 <DIR> d-------- C:\Program Files\PowerISO
2008-08-02 00:17 . 2008-08-02 00:17 <DIR> d-------- C:\AeriaGames
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-01 19:37 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-09-01 19:33 --------- d-----w C:\Documents and Settings\Mitz.DELL8400\Application Data\uTorrent
2008-08-30 04:21 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-08-29 04:28 --------- d-----w C:\Program Files\TuneUp Utilities 2007
2008-08-29 04:16 --------- d-----w C:\Program Files\McAfee
2008-08-29 04:05 --------- d-----w C:\Documents and Settings\Mitz.DELL8400\Application Data\LimeWire
2008-08-29 03:30 --------- d-----w C:\Program Files\LimeWire
2008-08-29 00:40 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\SiteAdvisor
2008-08-29 00:40 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee
2008-08-23 14:33 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-18 22:02 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-12 02:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-10 01:48 --------- d-----w C:\Program Files\Winamp
2008-08-06 03:50 --------- d-----w C:\Program Files\PopCap Games
2008-07-26 14:15 --------- d-----w C:\Documents and Settings\Mitz.DELL8400\Application Data\MCMPEGEnc
2008-07-26 14:07 --------- d-----w C:\Program Files\Avid
2008-07-26 13:29 --------- d-----w C:\Documents and Settings\Justin.DELL8400\Application Data\Windows Search
2008-07-26 13:28 --------- d-----w C:\Documents and Settings\Justin.DELL8400\Application Data\TuneUp Software
2008-07-26 06:19 --------- d-----w C:\Documents and Settings\Justin.DELL8400\Application Data\Windows Desktop Search
2008-07-25 19:43 --------- d-----w C:\Documents and Settings\Mitz.DELL8400\Application Data\Windows Desktop Search
2008-07-25 19:41 --------- d-----w C:\Program Files\Windows Desktop Search
2008-07-25 17:08 --------- d-----w C:\Program Files\Dell
2008-07-25 17:08 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Dell
2008-07-24 21:55 --------- d-----w C:\Program Files\Click'N Design 3D (V5)
2008-07-24 21:55 --------- d-----w C:\Documents and Settings\Mitz\Application Data\Bioshock
2008-07-24 21:55 --------- d-----w C:\Documents and Settings\Mitz.DELL8400\Application Data\Move Networks
2008-07-24 21:55 --------- d-----w C:\Documents and Settings\Justin.DELL8400\Application Data\uTorrent
2008-07-24 04:57 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-07-21 04:04 --------- d-----w C:\Program Files\Yahoo!
2008-07-21 03:58 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\eboostr
2008-07-17 22:12 --------- d-----w C:\Program Files\Winamp Toolbar
2008-07-17 22:12 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Winamp Toolbar
2008-07-07 07:40 56,108 ----a-w C:\WINDOWS\system32\drivers\scdemu.sys
2007-04-27 17:23 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2006-05-06 16:42 7,260,160 ----a-w C:\Program Files\mozilla firefox\plugins\libvlc.dll
2008-05-14 04:15 32,768 --sha-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012008051320080514\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:12 15360]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe" [2008-03-07 05:26 1694656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"="C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 10:43 57344]
"Dell Photo AIO Printer 922"="C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-11-10 14:36 290816]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-16 14:01 13529088]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-09-29 12:39 151552]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-03 23:33 582992]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-16 14:01 86016]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 16:54 57344]
"CTHelper"="CTHELPER.EXE" [2007-04-09 12:32 19456 C:\WINDOWS\SYSTEM32\CtHelper.exe]
"nwiz"="nwiz.exe" [2008-05-16 14:01 1630208 C:\WINDOWS\SYSTEM32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-13 19:12 53760 C:\WINDOWS\SYSTEM32\narrator.exe]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 22:19 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"SENTINEL"= snti386.dll
"VIDC.MJPG"= Pvmjpg30.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CTDVDDET"="C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
"IPInSightLAN 02"="C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
"IPInSightMonitor 02"="C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Avid\\Avid Liquid 7\\Program\\RM.exe"=
"C:\\Program Files\\Avid\\Avid Liquid 7\\Program\\StudioU.mod"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"C:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"94:TCP"= 94:TCP:VRS Recording System Web Control Panel
"67:UDP"= 67:UDP:DHCP Discovery Service
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-08-18 10:30]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2008-04-13 19:12]
R2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [2007-01-04 16:38]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [2008-04-13 19:12]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [2008-04-13 19:12]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [2008-04-13 19:12]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [2008-04-13 19:12]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-06-14 09:18]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{834a84fc-074a-11dd-831d-001111bf3bb0}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d35c9f15-8f09-11dc-81da-001111bf3bb0}]
\Shell\AutoRun\command - G:\wd_windows_tools\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d5468c13-90ab-11dc-81db-001111bf3bb0}]
\Shell\AutoRun\command - G:\
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Mitz.DELL8400\Application Data\Mozilla\Firefox\Profiles\hslixf8v.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://att.my.yahoo.com/
FF -: plugin - C:\Documents and Settings\Mitz.DELL8400\Application Data\Mozilla\Firefox\Profiles\hslixf8v.default\extensions\
[email protected]\platform\WINNT_x86-msvc\plugins\npmnqmp07051001.dll
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint_0303001D.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-09-02 00:55:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\McAfee\SiteAdvisor\saHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\CTSVCCDA.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\WINDOWS\SYSTEM32\nvsvc32.exe
C:\WINDOWS\SYSTEM32\tcpsvcs.exe
C:\WINDOWS\SYSTEM32\searchindexer.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\WINDOWS\SYSTEM32\rundll32.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
.
**************************************************************************
.
Completion time: 2008-09-02 1:00:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-02 06:00:11
Pre-Run: 31,390,494,720 bytes free
Post-Run: 31,387,836,416 bytes free
271 --- E O F --- 2008-08-18 22:02:33