Okay, some SIDENOTES.
Before I ran Combo-Fix, the computer was total sluggish and hardly loading any web sites. so I ran a
Malwarebytes which removed 7 items and Spybot S&D which removed Virtumonde.prx
Then I did have some problems with Combo-Fix, had to interrupt it, but then finally did get through it. Here's the log:
ComboFix 10-07-26.04 - z 07/27/2010 19:52:46.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3710.3041 [GMT -5:00]
Running from: c:\documents and settings\z\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\z\LOCALS~1\Temp\clclean.0001.dir.0001\~df394b.tmp
c:\documents and settings\z\Local Settings\Application Data\{4C96E80D-68EC-4BB8-B340-0BE6EE953952}
c:\documents and settings\z\Local Settings\Application Data\{4C96E80D-68EC-4BB8-B340-0BE6EE953952}\chrome.manifest
c:\documents and settings\z\Local Settings\Application Data\{4C96E80D-68EC-4BB8-B340-0BE6EE953952}\chrome\content\_cfg.js
c:\documents and settings\z\Local Settings\Application Data\{4C96E80D-68EC-4BB8-B340-0BE6EE953952}\chrome\content\overlay.xul
c:\documents and settings\z\Local Settings\Application Data\{4C96E80D-68EC-4BB8-B340-0BE6EE953952}\install.rdf
c:\documents and settings\z\Local Settings\temp\clclean.0001.dir.0001\~df394b.tmp
c:\program files\Mozilla Firefox\searchplugins\google_search.xml
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
((((((((((((((((((((((((( Files Created from 2010-06-28 to 2010-07-28 )))))))))))))))))))))))))))))))
.
2010-07-25 22:54 . 2010-07-27 20:31 0 ----a-w- c:\windows\Qyiveq.bin
2010-07-25 22:54 . 2010-07-26 19:45 120 ----a-w- c:\windows\Nfezikufev.dat
2010-07-25 22:53 . 2010-07-28 01:05 766464 ----a-w- c:\windows\system32\drivers\mwuzwry.sys
2010-07-25 22:53 . 2010-07-25 22:53 -------- d-----w- c:\documents and settings\z\Local Settings\Application Data\ekuffvtur
2010-07-25 22:51 . 2010-07-25 22:52 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-14 06:07 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-28 01:03 . 2007-02-13 20:25 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2010-07-27 17:38 . 2007-10-31 01:59 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-27 17:37 . 2009-04-30 17:32 -------- d-----w- c:\program files\SpywareBlaster
2010-07-27 02:45 . 2010-07-27 02:45 503808 ----a-w- c:\documents and settings\z\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-133298b9-n\msvcp71.dll
2010-07-27 02:45 . 2010-07-27 02:45 499712 ----a-w- c:\documents and settings\z\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-133298b9-n\jmc.dll
2010-07-27 02:45 . 2010-07-27 02:45 348160 ----a-w- c:\documents and settings\z\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-133298b9-n\msvcr71.dll
2010-07-26 18:02 . 2006-12-26 22:49 3874 ----a-w- c:\documents and settings\z\Application Data\SAS7_000.DAT
2010-07-26 01:43 . 2007-09-04 02:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-25 22:51 . 2009-12-17 08:33 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-25 00:22 . 2006-04-06 19:35 -------- d-----w- c:\documents and settings\z\Application Data\Canon
2010-07-24 18:30 . 2007-02-14 02:44 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2010-07-19 02:45 . 2006-03-24 19:44 33832 ----a-w- c:\documents and settings\z\Application Data\wklnhst.dat
2010-07-15 20:18 . 2007-02-20 18:03 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2010-06-16 02:19 . 2010-06-16 02:19 25214 ----a-r- c:\documents and settings\z\Application Data\Microsoft\Installer\{21614F95-2732-417C-881E-FDD545F9B4BC}\ARPPRODUCTICON.exe
2010-06-16 02:19 . 2006-03-31 18:53 -------- d-----w- c:\program files\The Print Shop 21
2010-06-15 19:02 . 2010-02-18 00:45 339024 ----a-w- c:\documents and settings\z\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-15 18:59 . 2006-03-31 18:59 -------- d-----w- c:\program files\Web Publish
2010-06-15 18:23 . 2006-03-31 18:53 -------- d-----w- c:\program files\Common Files\Broderbund
2010-06-14 14:31 . 2005-08-16 10:40 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-13 17:35 . 2010-06-13 17:35 -------- d-----w- c:\program files\ESET
2010-06-09 02:14 . 2009-10-15 17:40 -------- d-----w- c:\program files\Windows Live Safety Center
2010-06-09 01:33 . 2009-11-28 23:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-09 01:20 . 2010-06-09 01:20 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedyPC
2010-06-09 01:20 . 2010-06-09 01:20 -------- d-----w- c:\program files\SpeedyPC
2010-05-04 17:20 . 2005-08-16 10:18 832512 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 17:20 . 2005-08-16 10:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:20 . 2005-08-16 10:18 17408 ----a-w- c:\windows\system32\corpol.dll
2010-05-02 05:22 . 2005-08-16 10:18 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 20:39 . 2009-11-28 23:53 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 20:39 . 2009-11-28 23:53 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-06 18:42 . 2006-03-24 04:04 104 --sh--r- c:\windows\system32\690E1F2E0D.sys
2010-03-06 18:42 . 2006-03-24 04:04 6216 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 24576]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-17 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MBMon"="CTMBHA.DLL" [2005-05-19 1345520]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-15 77824]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2006-12-22 497176]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-23 149280]
"AppMgrGui"="c:\program files\Altiris\StreamingAgent\bin\exeForService.exe" [2009-02-03 54688]
"CTSVolFE"="c:\program files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 57344]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-05-03 160592]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{2D0C3614-D550-4b6b-BF80-D83C4544D6AE}"= "c:\program files\Altiris\StreamingAgent\bin\ShExecHook.dll" [2009-02-03 107936]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
2006-10-23 12:50 71216 ----a-r- c:\program files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CallControl 4.5]
2002-05-18 16:05 122368 ----a-w- c:\program files\FaxTalk Communicator\FTCtrl32.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
2004-12-03 00:23 102400 ------w- c:\program files\Creative\MediaSource\Detector\CTDetect.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2005-09-15 15:47 57344 ------w- c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2005-05-15 08:04 332800 ----a-w- c:\progra~1\DELLSU~1\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2005-10-05 09:12 94208 ----a-w- c:\program files\Dell\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-09-29 20:01 67584 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2007-10-08 21:50 41824 ----a-w- c:\program files\Common Files\AOL\1170476348\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-12 02:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
2001-11-20 04:10 196608 ----a-w- c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-10-15 02:50 114688 ----a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-10-15 02:49 94208 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-04-02 21:11 342312 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2006-12-22 18:28 756248 ----a-w- c:\program files\Logitech\QuickCam10\QuickCam10.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
2006-01-18 19:00 8192 ----a-w- c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Omnipage]
2002-02-21 01:01 49152 ----a-w- c:\program files\ScanSoft\OmniPageSE\opware32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-01-05 21:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2006-03-21 15:35 26112 ----a-w- c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
2008-05-03 17:19 160592 ----a-w- c:\program files\Siber Systems\AI RoboForm\robotaskbaricon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2009-03-07 03:54 24095528 ----a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 21:07 2260480 ------w- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 15:03 210472 ----a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-04-17 18:50 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
2000-05-11 07:00 90112 ------w- c:\windows\Updreg.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoiceCenter]
2005-09-19 13:42 1159168 ------w- c:\program files\Creative\VoiceCenter\AndreaVC.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\McAfee.com\\Agent\\mcagent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1170476348\\ee\\aolsoftware.exe"=
R1 APPSTREAM;AppStream;c:\windows\system32\drivers\AppStream.sys [2/2/2009 11:59 PM 160768]
R2 AppMgrService;AWE 6.1 Streaming Agent;c:\program files\Altiris\StreamingAgent\bin\AppMgrService.exe [2/3/2009 12:55 AM 3941792]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [10/1/2008 9:57 PM 93320]
R2 REGHOOK;REGHOOK;c:\windows\system32\drivers\RegHook.sys [2/2/2009 11:58 PM 138752]
--- Other Services/Drivers In Memory ---
*Deregistered* - mwuzwry
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-07-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-07-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-02-20 17:22]
2010-07-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-02-20 17:22]
2010-07-27 c:\windows\Tasks\SpeedyPC Program Check.job
- c:\program files\SpeedyPC\SpeedyPC.exe [2010-03-18 00:03]
2010-06-09 c:\windows\Tasks\SpeedyPC.job
- c:\program files\SpeedyPC\SpeedyPC.exe [2010-03-18 00:03]
2010-07-27 c:\windows\Tasks\Updater.job
- k:\documents and settings\All Users\Application Data\Update\seupd.exe [2010-07-24 22:16]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.aol.com/uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8mStart Page =
hxxp://www.yahoo.comuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: Customize Menu -
file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Fill Forms -
file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar -
file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms -
file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Trusted Zone: citibank.com\online
Trusted Zone: lasallebank.com\onlinebanking
Trusted Zone: musicmatch.com\online
DPF: {3356DB7C-58A7-11D4-AA5C-006097314BF8} -
hxxp://smartdownload.encore.com/new/launcher.cabDPF: {7A7BA269-2D21-4B33-B60A-8510A1865D5F} -
hxxp://public2.uploader.officelive.com/_layouts/1033/wh/ActiveX/MsnPUpld.cab.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Dqokojuyib - c:\windows\irecehez.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-27 20:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mwuzwry]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-4154388428-524900779-1368262275-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:06,70,88,7e,1a,eb,83,91,be,92,ac,83,fb,c1,a3,5f,d1,9c,66,69,bf,eb,d4,
ac,6d,97,17,37,0a,ed,86,3e,50,d8,0e,1c,7d,a2,85,1d,c2,90,61,c8,d6,c3,a5,91,\
"??"=hex:b3,63,35,0c,d0,1b,29,1f,0b,4d,22,c5,a9,03,97,e6
[HKEY_USERS\S-1-5-21-4154388428-524900779-1368262275-1005_Classes\Appstream\GhostRegistryChangesRoot\Software\Classes]
"SymbolicLinkValue"=dword:00000001
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(6520)
c:\windows\system32\WININET.dll
c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\windows\wanmpsvc.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\Rundll32.exe
c:\docume~1\z\LOCALS~1\Temp\clclean.0001
c:\program files\Altiris\StreamingAgent\Bin\AppMgrGui.exe
c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
.
**************************************************************************
.
Completion time: 2010-07-27 20:12:15 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-28 01:12
ComboFix2.txt 2010-06-13 03:03
Pre-Run: 90,074,288,128 bytes free
Post-Run: 90,059,341,824 bytes free
- - End Of File - - E182B904A0E8BD2C0717DC1943912A70