ComboFix 12-08-24.02 - Owner 08/24/2012 14:47:26.1.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1982.1256 [GMT -7:00] Running from: I:\ComboFix.exe . WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\Administrator.DBOX\WINDOWS c:\documents and settings\Default User\WINDOWS c:\documents and settings\Guest\WINDOWS c:\documents and settings\Owner\LicenceWM.exe c:\documents and settings\Owner\pPokerNetSetup.exe c:\documents and settings\Owner\WINDOWS C:\IIO1F.tmp C:\IIO274.tmp C:\IIO2A2.tmp C:\IIO42.tmp C:\IIO46.tmp c:\program files\Downloaded Installers c:\program files\Downloaded Installers\{93E68D8C-DCD4-434E-99EB-15CE067C7B6D}\setup.msi c:\program files\MyScrapNook_12EI c:\program files\MyScrapNook_12EI\Installr\1.bin\12EIPlug.dll c:\program files\MyScrapNook_12EI\Installr\1.bin\12EZSETP.dll c:\program files\MyScrapNook_12EI\Installr\1.bin\NP12EISb.dll c:\program files\screensavers.com c:\program files\screensavers.com\Installer\temp\RKeula2.rtf c:\program files\screensavers.com\SSSInst\bin\iebyterange.xml c:\program files\screensavers.com\SSSInst\bin\iebyterange.xml.backup c:\program files\screensavers.com\SSSInst\bin\SSSUninst.exe c:\program files\screensavers.com\SSSInst\temp\dmE5.tmp.exe c:\windows\~GLC0000.TMP c:\windows\~GLC0001.TMP c:\windows\~GLC0002.TMP c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf c:\windows\system32\config\systemprofile\WINDOWS c:\windows\system32\download c:\windows\system32\Download\ispinfo.csv c:\windows\system32\OLD68.tmp c:\windows\system32\OLD6B.tmp c:\windows\system32\OLD6E.tmp c:\windows\system32\SET3BE.tmp c:\windows\system32\SET3C3.tmp c:\windows\system32\SET411.tmp c:\windows\system32\URTTemp c:\windows\system32\URTTemp\fusion.dll c:\windows\system32\URTTemp\mscoree.dll c:\windows\system32\URTTemp\mscoree.dll.local c:\windows\system32\URTTemp\mscorsn.dll c:\windows\system32\URTTemp\mscorwks.dll c:\windows\system32\URTTemp\msvcr71.dll c:\windows\system32\URTTemp\regtlib.exe . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_EPSONSTATUSAGENT2 -------\Service_EPSONStatusAgent2 . . ((((((((((((((((((((((((( Files Created from 2012-07-24 to 2012-08-24 ))))))))))))))))))))))))))))))) . . 2012-08-13 01:40 . 2012-08-13 01:40 -------- d-----w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com 2012-08-13 01:39 . 2012-08-13 01:40 -------- d-----w- c:\program files\SUPERAntiSpyware 2012-08-13 01:39 . 2012-08-13 01:39 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2012-08-10 17:10 . 2012-08-23 00:34 -------- d-----w- c:\documents and settings\Administrator.DBOX . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-06-29 21:25 . 2012-04-08 18:42 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-06-29 21:25 . 2011-06-06 14:37 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-06-13 13:19 . 2004-10-12 03:48 1866112 ----a-w- c:\windows\system32\win32k.sys 2012-06-05 15:50 . 2007-05-15 22:43 1372672 ----a-w- c:\windows\system32\msxml6.dll 2012-06-05 15:50 . 2004-10-12 03:47 1172480 ----a-w- c:\windows\system32\msxml3.dll 2012-06-05 00:35 . 2006-10-22 04:48 222448 ----a-w- c:\windows\system32\muweb.dll 2012-06-04 04:32 . 2004-10-12 03:48 152576 ----a-w- c:\windows\system32\schannel.dll 2012-06-02 22:19 . 2007-05-31 01:05 22040 ----a-w- c:\windows\system32\wucltui.dll.mui 2012-06-02 22:19 . 2007-05-31 01:05 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui 2012-06-02 22:19 . 2004-10-12 03:48 329240 ----a-w- c:\windows\system32\wucltui.dll 2012-06-02 22:19 . 2004-10-12 03:48 219160 ----a-w- c:\windows\system32\wuaucpl.cpl 2012-06-02 22:19 . 2004-10-12 03:48 210968 ----a-w- c:\windows\system32\wuweb.dll 2012-06-02 22:19 . 2007-05-31 01:05 15384 ----a-w- c:\windows\system32\wuapi.dll.mui 2012-06-02 22:19 . 2005-05-26 11:16 45080 ----a-w- c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2004-12-01 02:49 35864 ----a-w- c:\windows\system32\wups.dll 2012-06-02 22:19 . 2004-10-12 03:48 53784 ----a-w- c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2004-10-12 03:44 97304 ----a-w- c:\windows\system32\cdm.dll 2012-06-02 22:19 . 2007-05-31 01:05 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui 2012-06-02 22:19 . 2004-10-12 03:48 577048 ----a-w- c:\windows\system32\wuapi.dll 2012-06-02 22:19 . 2004-10-12 03:48 1933848 ----a-w- c:\windows\system32\wuaueng.dll 2012-06-02 22:18 . 2007-06-01 00:48 17136 ----a-w- c:\windows\system32\mucltui.dll.mui 2012-06-02 22:18 . 2006-10-22 04:48 275696 ----a-w- c:\windows\system32\mucltui.dll 2012-05-31 13:22 . 2004-10-12 03:44 599040 ----a-w- c:\windows\system32\crypt32.dll 2005-04-21 15:51 . 2005-04-21 15:51 278528 ----a-w- c:\program files\internet explorer\plugins\PanoViewer.dll 2005-04-21 15:52 . 2005-04-21 15:52 98304 ----a-w- c:\program files\internet explorer\plugins\UPjpeg.dll 2012-06-23 15:57 . 2012-06-05 17:12 85472 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0538CF1C-8419-4800-ADBB-0C00C799FDA2}] 2011-12-19 15:04 87976 ----a-w- c:\documents and settings\Owner\Application Data\Genieo\Application\IEPlugins\bin\IEWrapper.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green] @="{95A27763-F62A-4114-9072-E81D87DE3B68}" [HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}] 2012-06-05 02:23 1014448 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial] @="{E300CD91-100F-4E67-9AF3-1384A6124015}" [HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}] 2012-06-05 02:23 1014448 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow] @="{5E529433-B50E-4bef-A63B-16A6B71B071A}" [HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}] 2012-06-05 02:23 1014448 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-19 200704] "Sticky Pad"="c:\program files\StickyPad\StickyPad.exe" [2007-04-24 528441] "NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-10-12 1961984] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-06 68856] "ContactKeeper Birthday reminder"="c:\program files\ContactKeeper\ContactKeeper.exe" [2009-10-20 876544] "Audiogalaxy"="c:\documents and settings\Owner\Local Settings\Application Data\Audiogalaxy\Audiogalaxy.exe" [2011-07-22 2953960] "GenieoUpdaterService"="c:\documents and settings\Owner\Application Data\Genieo\Application\Updater\bin\genupdater.exe" [2011-12-19 279976] "GenieoSystemTray"="c:\documents and settings\Owner\Application Data\Genieo\Application\TrayUi\bin\gentray.exe" [2011-12-19 561576] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-07-09 4777856] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-01-30 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2003-11-18 118784] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768] "SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-03-12 135168] "Turtle Beach Audio Advantage"="c:\program files\Turtle Beach\Audio Advantage Micro\TBAA.exe" [2004-06-08 1564672] "Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632] "Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-09-14 50688] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800] "Pure Networks Port Magic"="c:\progra~1\PURENE~1\PORTMA~1\PortAOL.exe" [2004-06-30 99480] "HostManager"="c:\program files\Common Files\AOL\1134524958\ee\AOLSoftware.exe" [2008-06-24 41824] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792] "VTTimer"="VTTimer.exe" [2006-09-21 53248] "VTTrayp"="VTtrayp.exe" [2007-02-06 176128] "SoundMan"="SOUNDMAN.EXE" [2006-08-03 577536] "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2007-08-24 240112] "DMXLauncher"="c:\program files\Roxio\CinePlayer\DMXLauncher.exe" [2007-08-14 113136] "YMailAdvisor"="c:\program files\Yahoo!\Common\YMailAdvisor.exe" [2008-06-05 125208] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-15 148888] "LogonStudio"="c:\program files\WinCustomize\LogonStudio\logonstudio.exe" [2002-09-04 987187] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-30 421888] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160] "Eraser"="c:\progra~1\Eraser\Eraser.exe" [2010-11-05 980368] "RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2012-03-09 26112] "Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2012-06-05 1061552] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-7-11 113664] Windows Desktop Search.lnk - c:\program files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe [2005-9-20 238080] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"= "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\America Online 9.0\\waol.exe"= "c:\\Program Files\\MSN\\MSNCoreFiles\\msn.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"= "c:\\Program Files\\Turtle Beach\\Audio Advantage Micro\\3DPlayer\\CmiPlay3D.exe"= "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"= "c:\\Program Files\\Microsoft Codename Max\\max.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Common Files\\AOL\\1134524958\\ee\\aolsoftware.exe"= "c:\\Program Files\\AOL 9.1\\waol.exe"= "c:\\Program Files\\Common Files\\AOL\\1134524958\\ee\\AOLServiceHost.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Documents and Settings\\Owner\\Application Data\\Spotify\\spotify.exe"= "c:\\Program Files\\Common Files\\Motive\\McciServiceHost.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "1886:TCP"= 1886:TCP:Genieo . R0 ViBus;ViBus;c:\windows\system32\drivers\ViBus.sys [5/29/2008 5:29 PM 16896] R0 ViPrt;VIA SATA IDE Device Driver;c:\windows\system32\drivers\ViPrt.sys [5/29/2008 5:29 PM 52224] R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [5/29/2008 5:22 PM 13696] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 9:27 AM 12880] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 2:55 PM 67664] R2 McciServiceHost;McciServiceHost;c:\program files\Common Files\Motive\McciServiceHost.exe [3/30/2012 10:10 AM 315392] R2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [8/24/2007 3:52 PM 166384] S2 gupdate1c9ca0a17d86a74;Google Update Service (gupdate1c9ca0a17d86a74);c:\program files\Google\Update\GoogleUpdate.exe [4/30/2009 8:07 PM 133104] S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [8/24/2007 3:53 PM 362992] S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [8/24/2007 3:52 PM 309744] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/8/2012 11:42 AM 250056] S3 AVC1100;Adaptec AVC-1100 Video Capture;c:\windows\system32\drivers\CA506AV.SYS [12/12/2004 10:04 PM 175042] S3 ca506aaf;Adaptec USB Audio Filter Driver (WDM);c:\windows\system32\drivers\ca506aaf.sys [12/12/2004 10:08 PM 14273] S3 cmuda2;Audio Advantage Micro Interface;c:\windows\system32\drivers\cmuda2.sys [1/18/2005 7:20 PM 705536] S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/30/2009 8:07 PM 133104] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [6/5/2012 10:13 AM 113120] S3 PciTest;WinMTA PCI Service;c:\windows\system32\drivers\pcitest.sys [10/14/2004 8:09 AM 6912] S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [8/24/2007 3:53 PM 72176] S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [8/24/2007 3:52 PM 1083888] . --- Other Services/Drivers In Memory --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] 2009-03-08 11:32 128512 ----a-w- c:\windows\system32\advpack.dll . Contents of the 'Scheduled Tasks' folder . 2012-08-24 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-08 21:25] . 2012-06-13 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34] . 2012-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-01 03:06] . 2012-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-01 03:06] . . ------- Supplementary Scan ------- . uStart Page = hxxp://yahoo.genieo.com/ IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html IE: &MSN Search - c:\program files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html DPF: {26B2A5DA-BFD6-422F-A89A-28A54C74B12B} - hxxp://www.costcophotocenter.com/upload/activex/v3_0_0_4/PhotoCenter_ActiveX_Control.cab FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\1j3y4qql.default\ . - - - - ORPHANS REMOVED - - - - . AddRemove-AOLAntivirus - c:\program files\mcafee.com\antivirus\uninst.exe AddRemove-{D575FBAA-D6D6-4221-A2C4-67541DB7AB5E}_is1 - c:\program files\Device Doctor\1.0.0.1\unins000.exe AddRemove-RewardsArcade - c:\program files\RewardsArcade\Uninstall.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-08-24 14:59 Windows 5.1.2600 Service Pack 3 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-357868212-2267230723-2855511169-1003\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(376) c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll . - - - - - - - > 'explorer.exe'(1368) c:\windows\system32\WININET.dll c:\program files\Common Files\AOL\ACS\WLHook.dll c:\program files\Google\GoogleToolbarNotifier\5.7.7227.1100\gth.dll c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll c:\progra~1\WINDOW~2\wmpband.dll c:\program files\MSN Toolbar Suite\DB\02.05.0000.1082\en-us\dbres.dll c:\program files\MSN Toolbar Suite\EXT\02.05.0001.1119\en-us\msnlExtRes.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Carbonite\Carbonite Backup\carboniteservice.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Motive\McciCMService.exe c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS c:\windows\wanmpsvc.exe c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe c:\windows\system32\wscntfy.exe c:\windows\system32\VTTimer.exe c:\program files\Common Files\AOL\Loader\aolload.exe c:\windows\system32\VTtrayp.exe c:\windows\SOUNDMAN.EXE c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe c:\program files\iPod\bin\iPodService.exe c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\CPSHelpRunner10.exe c:\program files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe . ************************************************************************** . Completion time: 2012-08-24 15:08:46 - machine was rebooted ComboFix-quarantined-files.txt 2012-08-24 22:08 . Pre-Run: 22,830,170,112 bytes free Post-Run: 23,176,224,768 bytes free . - - End Of File - - E23BE3F5F9B2F935CB681DE64BCAB376