ComboFix 08-02.03.1 - Administrator 02/02/2008 17:20:42.2 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.687 [GMT -6:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE
C:\WINNT\adsoowf.dll
C:\WINNT\bgrlsmn.dll
C:\WINNT\dntpkwomwx.dll
C:\WINNT\ekxdvft.dll
C:\WINNT\ffvrdgt.exe
C:\WINNT\system32\ftpcjkqy.dll
C:\WINNT\system32\jjllm.bak1
C:\WINNT\system32\jjllm.bak2
C:\WINNT\system32\mlljj.dll
C:\WINNT\system32\mrwpyrft.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\col4309
C:\col4309\1028.mst
C:\col4309\1029.mst
C:\col4309\1030.mst
C:\col4309\1031.mst
C:\col4309\1032.mst
C:\col4309\1033.mst
C:\col4309\1034.mst
C:\col4309\1035.mst
C:\col4309\1036.mst
C:\col4309\1038.mst
C:\col4309\1040.mst
C:\col4309\1041.mst
C:\col4309\1042.mst
C:\col4309\1043.mst
C:\col4309\1044.mst
C:\col4309\1045.mst
C:\col4309\1046.mst
C:\col4309\1049.mst
C:\col4309\1053.mst
C:\col4309\1055.mst
C:\col4309\2052.mst
C:\col4309\ACUECO~1.cab
C:\col4309\ALBUMP~1.cab
C:\col4309\Common\Hewlett-Packard\Scanjet\hpsj3970s.spf
C:\col4309\Common\Hewlett-Packard\Scanjet\hpsj3970t.spf
C:\col4309\CUC780~1.cab
C:\col4309\CUESHA~1.cab
C:\col4309\CUESHA~2.cab
C:\col4309\CUESHA~3.cab
C:\col4309\CUESHA~4.cab
C:\col4309\DIRECT~1.cab
C:\col4309\DIZZYC~1.cab
C:\col4309\FRU10.cab
C:\col4309\HP Photo and Imaging 2.2 - Scanjet 3970 Series.msi
C:\col4309\HPIS10.cab
C:\col4309\HPMD\1028.mst
C:\col4309\HPMD\1029.mst
C:\col4309\HPMD\1030.mst
C:\col4309\HPMD\1031.mst
C:\col4309\HPMD\1032.mst
C:\col4309\HPMD\1033.mst
C:\col4309\HPMD\1034.mst
C:\col4309\HPMD\1035.mst
C:\col4309\HPMD\1036.mst
C:\col4309\HPMD\1038.mst
C:\col4309\HPMD\1040.mst
C:\col4309\HPMD\1041.mst
C:\col4309\HPMD\1042.mst
C:\col4309\HPMD\1043.mst
C:\col4309\HPMD\1044.mst
C:\col4309\HPMD\1045.mst
C:\col4309\HPMD\1046.mst
C:\col4309\HPMD\1049.mst
C:\col4309\HPMD\1053.mst
C:\col4309\HPMD\1055.mst
C:\col4309\HPMD\2052.mst
C:\col4309\HPMD\hpmdinst.msi
C:\col4309\HPSHAR~1.cab
C:\col4309\IMAGEE~1.cab
C:\col4309\instmsiA.exe
C:\col4309\instmsiW.exe
C:\col4309\PHEDB5~1.cab
C:\col4309\PHOTOP~1.cab
C:\col4309\PHOTOV~1.cab
C:\col4309\PHOTOV~2.cab
C:\col4309\PHOTOV~3.cab
C:\col4309\PHOTOV~4.cab
C:\col4309\program files\Hewlett-Packard\Digital Imaging\bin\hpqe3970.dll
C:\col4309\program files\Hewlett-Packard\Digital Imaging\bin\TwainCtrl.dll
C:\col4309\program files\Hewlett-Packard\Digital Imaging\Data\DefaultScanSettings\3970.ini
C:\col4309\program files\Hewlett-Packard\Digital Imaging\Data\DefaultScanSettings\DizzyInis.dll
C:\col4309\program files\Hewlett-Packard\Digital Imaging\Data\Scanner.ini
C:\col4309\program files\Hewlett-Packard\Digital Imaging\Data\ScDirCfg.dll
C:\col4309\program files\Hewlett-Packard\Digital Imaging\Migrate\hpgt3970.cat
C:\col4309\program files\Hewlett-Packard\Digital Imaging\Migrate\hpgt3970.dll
C:\col4309\program files\Hewlett-Packard\Digital Imaging\Migrate\hpgt3970.inf
C:\col4309\program files\Hewlett-Packard\Digital Imaging\Migrate\hpgwiamd.dll
C:\col4309\program files\Hewlett-Packard\Digital Imaging\Migrate\hpqgends.tmp
C:\col4309\SCANNE~1.cab
C:\col4309\SCANNE~2.cab
C:\col4309\SCANSP~1.cab
C:\col4309\setup.exe
C:\col4309\setup.ini
C:\col4309\Sherlock.cab
C:\col4309\System32\98\hpgwiamd.dll
C:\col4309\System32\hpgt3970.dll
C:\col4309\System32\hpgwiamd.dll
C:\col4309\WebReg10.cab
C:\col4309\Windows\inf\catalog\hpgt3970.cat
C:\col4309\Windows\inf\hpgt3970.inf
C:\col4309\Windows\TWAIN.DLL
C:\col4309\Windows\twain_32\hpqgends.tmp
C:\col4309\Windows\twain_32Dut\TWAIN_32.DLL
C:\col4309\Windows\twain_32Eng\TWAIN_32.DLL
C:\col4309\Windows\twain_32Fre\TWAIN_32.DLL
C:\col4309\Windows\twain_32Ger\TWAIN_32.DLL
C:\col4309\Windows\twain_32Ita\TWAIN_32.DLL
C:\col4309\Windows\twain_32Kor\TWAIN_32.DLL
C:\col4309\Windows\twain_32Por\TWAIN_32.DLL
C:\col4309\Windows\twain_32SCh\TWAIN_32.DLL
C:\col4309\Windows\twain_32Spa\TWAIN_32.DLL
C:\col4309\Windows\twain_32TCh\TWAIN_32.DLL
C:\col4309\Windows\twainEng\TWAIN.DLL
C:\col4309\Windows\twainFre\TWAIN.DLL
C:\col4309\Windows\twainGer\TWAIN.DLL
C:\col4309\Windows\twainIta\TWAIN.DLL
C:\col4309\Windows\twainKor\TWAIN.DLL
C:\col4309\Windows\twainPor\TWAIN.DLL
C:\col4309\Windows\twainSCh\TWAIN.DLL
C:\col4309\Windows\twainSpa\TWAIN.DLL
C:\col4309\Windows\twainTCh\TWAIN.DLL
C:\col4309\Windows\TWUNK_16.EXE
C:\col4309\Windows\TWUNK_32.EXE
C:\fixwareout
C:\fixwareout\dnsbak.reg
C:\fixwareout\FindT\clsid.bak
C:\fixwareout\FindT\dumphive.exe
C:\fixwareout\FindT\FixWareOut.reg
C:\fixwareout\FindT\nircmd.exe
C:\fixwareout\FindT\patterns.txt
C:\fixwareout\FindT\rbot.bat
C:\fixwareout\FindT\RestartIt.exe
C:\fixwareout\FindT\runback.txt
C:\fixwareout\FindT\runs.vbs
C:\fixwareout\FindT\swreg.exe
C:\fixwareout\FindT\vfind.exe
C:\fixwareout\FindT\XP-2K2.cmd
C:\fixwareout\FixIt.BAT
C:\fixwareout\report.txt
C:\Program Files\Viewpoint
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Common\VistaBoot.sdll
C:\Program Files\Viewpoint\Viewpoint Manager\CPtask.xml
C:\Program Files\Viewpoint\Viewpoint Manager\VETScriptInterpreter.dll
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCP.cpl
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\s.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_av.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_cp.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_header_up.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bg.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_inner_bottom.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab_bg.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_off.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab1_on.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_off.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vm_tab2_on.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\images\vwpt_logo.gif
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\options.ini
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\viewpoint.ico
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPData\vmctrl.html
C:\Program Files\Viewpoint\Viewpoint Manager\ViewCPexe.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgrCore.dll
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\AxMetaStream_0305000D.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\ComponentMgr_0305001C.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\ComponentRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\Cursors.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\JpegReader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\Mts3Reader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SceneComponent.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SreeDMMX.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\SWFView.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VETScriptInterpreter.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMgr.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPVideo.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VMPVideo2.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\WaveletReader.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\DownLoadHist.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\HostRegistry.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MetaStreamConfig.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
C:\Program Files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
C:\Program Files\Viewpoint\Viewpoint Media Player\MTSDownloadSites.txt
C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.xpt
C:\WINNT\adsoowf.dll
C:\WINNT\bgrlsmn.dll
C:\WINNT\dntpkwomwx.dll
C:\WINNT\ekxdvft.dll
C:\WINNT\ffvrdgt.exe
C:\WINNT\system32\jjllm.bak1
C:\WINNT\system32\jjllm.bak2
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_VIEWPOINT_MANAGER_SERVICE
-------\Viewpoint Manager Service
((((((((((((((((((((((((( Files Created from 2008-01-02 to 2008-02-02 )))))))))))))))))))))))))))))))
.
2008-02-02 17:20 . 08-02-02 17:20 3 --a------ C:\WINNT\Twain001.Mtx
2008-02-02 14:05 . 08-02-02 14:05 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-25 20:03 . 08-01-25 20:05 <DIR> d-------- C:\Program Files\Age Of Wonders
2008-01-20 14:39 . 08-01-22 10:06 54,156 --ah----- C:\WINNT\QTFont.qfn
2008-01-20 14:39 . 08-01-20 14:39 1,409 --a------ C:\WINNT\QTFont.for
2008-01-14 03:01 . 08-01-14 03:01 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-01-14 01:11 . 08-01-17 15:08 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\BitTorrent
2008-01-14 01:10 . 08-01-14 01:10 <DIR> d-------- C:\Program Files\DNA
2008-01-14 01:10 . 08-01-14 01:10 <DIR> d-------- C:\Program Files\BitTorrent
2008-01-14 01:10 . 08-02-02 17:22 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\DNA
2008-01-13 18:11 . 08-01-13 18:11 <DIR> d-------- C:\Program Files\Photo Viewer
2008-01-13 18:06 . 08-01-13 18:06 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Share-to-Web Upload Folder
2008-01-13 18:06 . 08-01-13 18:06 82,380 --a------ C:\WINNT\system32\drivers\AFS2K.SYS
2008-01-13 18:05 . 03-06-19 13:05 12,592 --a------ C:\WINNT\system32\drivers\usbscan.sys
2008-01-13 18:05 . 03-06-19 13:05 12,592 --a--c--- C:\WINNT\system32\dllcache\usbscan.sys
2008-01-13 18:04 . 08-01-13 18:04 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-01-13 17:52 . 08-01-13 17:52 <DIR> d-------- C:\Program Files\Bonjour
2008-01-13 17:50 . 08-01-13 17:50 <DIR> d-------- C:\WINNT\system32\BWKDLogs
2008-01-13 17:49 . 08-01-13 17:49 <DIR> d-------- C:\Program Files\Common Files\Kodak
2008-01-13 17:48 . 08-01-13 17:48 <DIR> d-------- C:\WINNT\system32\color
2008-01-13 17:48 . 08-01-13 17:48 <DIR> d-------- C:\KPCMS
2008-01-13 17:39 . 08-01-13 17:51 <DIR> d-------- C:\Program Files\Kodak
2008-01-13 17:39 . 08-01-13 17:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kodak
2008-01-07 19:24 . 08-01-07 19:24 <DIR> dr------- C:\Program Files\Liquid Entertainment
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-02 22:49 --------- d---a-w C:\Program Files\Steam
2008-02-02 06:27 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AVG7
2008-02-02 01:42 --------- d-----w C:\Program Files\DivX
2008-01-14 00:06 --------- d-----w C:\Program Files\Hewlett-Packard
2008-01-13 23:52 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-09 20:37 --------- d-----w C:\Program Files\World of Warcraft
2007-12-26 20:16 --------- d-----w C:\Program Files\iTunes
2007-12-26 20:16 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Apple Computer
2007-12-26 20:15 --------- d-----w C:\Program Files\iPod
2007-12-26 20:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-26 19:27 --------- d-----w C:\Program Files\Common Files\Ahead
2007-12-26 19:26 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Ahead
2007-12-26 19:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2007-12-26 19:20 --------- d-----w C:\Program Files\Nero
2007-12-23 07:22 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2007-12-22 22:55 --------- d--h--w C:\Documents and Settings\Administrator\Application Data\yahoo!
2007-12-21 21:08 --------- d-----w C:\Program Files\Ventrilo
2007-12-21 21:08 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-21 00:51 --------- d-----w C:\Program Files\SystemRequirementsLab
2007-12-21 00:51 --------- d-----w C:\Documents and Settings\Administrator\Application Data\SystemRequirementsLab
2007-12-11 21:54 --------- d-----w C:\Program Files\Yahoo!
2007-12-10 22:04 --------- d-----w C:\Program Files\AIM6
2007-12-10 22:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2007-12-10 22:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2007-12-10 21:56 --------- d-----w C:\Program Files\Common Files\AOL
2007-11-02 08:37 94,208 ----a-w C:\WINNT\DIIUnin.exe
2004-01-01 20:59 271 ---h--w C:\Program Files\desktop.ini
2004-01-01 20:59 21,952 ---h--w C:\Program Files\folder.htt
1999-12-07 17:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [06-11-16 19:04 139264]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [07-08-30 16:43 4670704]
"Steam"="C:\Program Files\Steam\Steam.exe" [04-01-01 00:08 1266936]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [07-10-04 09:20 50528]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [08-01-14 01:10 290112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-06-19 13:05 111376 C:\WINNT\system32\mobsync.exe]
"NvCplDaemon"="C:\WINNT\System32\NvCpl.dll" [06-03-09 15:29 7561216]
"nwiz"="nwiz.exe" [06-03-09 15:29 1519616 C:\WINNT\system32\nwiz.exe]
"NvMediaCenter"="C:\WINNT\System32\NvMcTray.dll" [06-03-09 15:29 86016]
"SoundMax"="C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [05-04-13 02:48 36975]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [06-01-12 15:40 155648]
"QuickTime Task"="C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" [06-10-25 18:58 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [06-10-30 09:36 256576]
"HPDJ Taskbar Utility"="C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe" [01-11-19 08:27 196608]
"ece465ef"="C:\WINNT\system32\ftpcjkqy.dll" [ ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [08-01-28 14:27 579072]
"Share-to-Web Namespace Daemon"="c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [02-04-17 10:42 69632]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [07-10-26 13:44 219136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 13:05 186640]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
D-Link AirPlus.lnk - C:\Program Files\D-Link AirPlus\AirPlus.exe [2004-01-03 19:44:24 262144]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-06-14 23:11:40 180224]
KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 14:12:08 16423]
R1 Avg7RsNT;AVG7 Resident Driver NT;C:\WINNT\system32\Drivers\avg7rsnt.sys [07-10-23 21:13 ]
R3 openhci;Microsoft USB Open Host Controller Driver;C:\WINNT\system32\DRIVERS\openhci.sys [03-06-19 13:05 ]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-02 17:36:13
Windows 5.0.2195 Service Pack 4 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINNT\system32\hidserv.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\Program Files\Java\jre1.5.0_03\bin\jucheck.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2008-02-02 17:45:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-02 23:44:38
ComboFix2.txt 2008-02-02 22:54:29
.
2008-01-14 09:01:17 --- E O F ---