01/05/2009 GMT
Hello Rorschach 112,
Thanks very much for your prompt reply.
I ran SDfix and then Combofix. I have pasted both reports here below. There were some issues with my McAfee Total Protection Service, which doesn't appear to have a 'Disable' facility, I had to approve two files/programs generated by combofix, but it did mention the 'deletion' of one other interim file.(I didn't catch the name - sorry).
Can I presume that everything is AOK now or do I have to wait for your confirmation, after your having read through the two reports?
Thanks again from Dublin.
Tony
SDFix: Version 1.240
Run by tony on 01/05/2009 at 09:13
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
AUTOEXEC.NT Restored from backups
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\WINDOWS\system32\10A.tmp - Deleted
C:\WINDOWS\system32\paars.ini - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-01 09:19:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:0000014d
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"="C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe:*:Enabled:McAfee Managed Services Agent"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Disabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Disabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Disabled:RealPlayer"
@="C:\\DOCUME~1\\TONY~1.LIF\\LOCALS~1\\Temp\\ie17F.tmp:*:Enabled:KL"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"="C:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe:*:Enabled:Framework Service"
"C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"="C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe:*:Enabled:McAfee Managed Services Agent"
"C:\\WINDOWS\\system32\\fxsclnt.exe"="C:\\WINDOWS\\system32\\fxsclnt.exe:*:Enabled:Microsoft Fax Console"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:*:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\WINDOWS\\system32\\sm.exe"="C:\\WINDOWS\\system32\\sm.exe:*:Enabled:enable"
"C:\\WINDOWS\\system32\\dd.exe"="C:\\WINDOWS\\system32\\dd.exe:*:Enabled:enable"
"C:\\WINDOWS\\system32\\adirss.exe"="C:\\WINDOWS\\system32\\adirss.exe:*:Enabled:enable"
"C:\\WINDOWS\\system32\\lnwin.exe"="C:\\WINDOWS\\system32\\lnwin.exe:*:Enabled:enable"
"C:\\Program Files\\Lavasoft\\Ad-Aware SE Personal\\Ad-Aware.exe"="C:\\Program Files\\Lavasoft\\Ad-Aware SE Personal\\Ad-Aware.exe:*:Enabled:Ad-Aware SE Personal"
"\\\\lifsbs\\apps\\exch\\enterp\\main\\ENTRPRSE.EXE"="\\\\lifsbs\\apps\\exch\\enterp\\main\\ENTRPRSE.EXE:*:Enabled:Enterprise"
"\\\\lifsbs\\apps\\exch\\enterp\\main\\enter1.exe"="\\\\lifsbs\\apps\\exch\\enterp\\main\\enter1.exe:*:Enabled:enter1"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"="C:\\Program Files\\AVG\\AVG8\\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Mon 14 Apr 2008 1,695,232 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
Thu 20 Jul 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 8 Jun 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 16 Nov 2005 235,008 ...H. --- "C:\Documents and Settings\tony.LANIGANFREIGHT\Application Data\Microsoft\Word\~WRL0336.tmp"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\REPORTS\Assets\My Asset Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\REPORTS\Bank\My Bank Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\REPORTS\Customer\My Customer Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\REPORTS\Finance\My Finance Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\REPORTS\Invoice\My Invoice Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\REPORTS\Nominal\My Nominal Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\REPORTS\POP\My POP Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\REPORTS\Products\My Products Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\REPORTS\Project\My Project Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\REPORTS\SOP\My SOP Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\REPORTS\Supplier\My Supplier Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\DemoData\REPORTS\Assets\My Asset Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\DemoData\REPORTS\Bank\My Bank Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\DemoData\REPORTS\Customer\My Customer Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\DemoData\REPORTS\Finance\My Finance Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\DemoData\REPORTS\Invoice\My Invoice Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\DemoData\REPORTS\Nominal\My Nominal Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\DemoData\REPORTS\POP\My POP Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\DemoData\REPORTS\Products\My Products Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\DemoData\REPORTS\Project\My Project Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\DemoData\REPORTS\SOP\My SOP Reports\rpt.sys"
Fri 9 Aug 2002 0 A..H. --- "C:\Program Files\Sage\Accounts\DemoData\REPORTS\Supplier\My Supplier Reports\rpt.sys"
Finished!
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
ComboFix 09-04-30.05 - tony 01/05/2009 9:31.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.175 [GMT 1:00]
Running from: c:\documents and settings\tony.LIFROOT\Desktop\ComboFix.exe
AV: Total Protection Service *On-access scanning enabled* (Updated)
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\drivers\fad.sys
c:\windows\system32\install.exe
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\tmp.reg
c:\windows\winhelp.ini
----- BITS: Possible infected sites -----
hxxp://basesrv3.net
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\i386\userinit.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_WINCOM32
((((((((((((((((((((((((( Files Created from 2009-04-01 to 2009-05-01 )))))))))))))))))))))))))))))))
.
2009-05-01 08:12 . 2009-05-01 08:12 578560 ----a-w c:\windows\system32\dllcache\user32.dll
2009-05-01 08:10 . 2009-05-01 08:10 -------- d-----w c:\windows\ERUNT
2009-05-01 08:09 . 2009-05-01 08:09 -------- d-----w c:\documents and settings\tony\Local Settings\Application Data\Adobe
2009-04-30 16:45 . 2009-05-01 08:21 -------- d-----w C:\SDFix
2009-04-30 15:30 . 2006-10-26 14:00 15872 ------w c:\windows\system32\SophosBootTasksR.exe
2009-04-30 09:44 . 2009-04-30 09:44 -------- d-----w c:\documents and settings\tony.LIFROOT\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-04-28 12:04 . 2009-04-30 10:09 -------- d-----w c:\documents and settings\All Users\Application Data\NOS
2009-04-28 12:04 . 2009-04-30 10:09 -------- d-----w c:\program files\NOS
2009-04-23 09:41 . 2008-04-14 00:12 26112 ----a-w c:\windows\system32\stu2.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-30 09:53 . 2005-05-06 10:53 -------- d-----w c:\program files\Common Files\Adobe
2009-04-28 14:52 . 2008-12-23 16:26 1264650 ----a-w C:\Lanigan International Freight Ltd payroll backup 09.zip
2009-04-24 11:33 . 2008-12-17 17:00 -------- d-----w c:\program files\thes2009
2009-04-22 10:42 . 2008-05-09 10:57 -------- d-----w c:\program files\SiteAdvisor
2009-03-24 09:47 . 2009-03-24 09:47 -------- d-----w c:\program files\Vocal Remover
2009-03-05 17:05 . 2009-03-04 11:04 -------- d-----w c:\program files\ros
2009-03-04 11:06 . 2009-03-04 11:04 -------- d--h--w c:\program files\Zero G Registry
2009-03-03 11:24 . 2006-06-09 09:01 55208 ----a-w c:\windows\system32\drivers\mfetdik.sys
2009-03-03 11:24 . 2008-05-09 10:57 34216 ----a-w c:\windows\system32\drivers\MfeRKDK.sys
2009-03-03 11:23 . 2006-06-09 09:01 213768 ----a-w c:\windows\system32\drivers\mfehidk.sys
2009-03-03 11:23 . 2006-06-09 09:01 35272 ----a-w c:\windows\system32\drivers\MfeBOPK.sys
2009-03-03 11:23 . 2006-06-09 09:01 79880 ----a-w c:\windows\system32\drivers\MfeAVFK.sys
2006-08-15 14:48 . 1602-07-12 21:55 1031 --sh--w c:\windows\system\ws32ntfg.dat
2002-04-16 09:27 . 2002-04-16 09:27 5 --sha-w c:\windows\system32\CdI5T.drv
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-26 53248]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"McAfee Managed Services Tray"="c:\program files\McAfee\Managed VirusScan\Agent\StartMyagtTry.exe" [2009-04-13 87360]
"MVS Splash"="c:\program files\McAfee\Managed VirusScan\Agent\Splash.exe" [2009-04-13 468288]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2008-04-14 143360]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-05-18 98304]
"SiteAdvisor"="c:\program files\SiteAdvisor\6173\SiteAdv.exe" [2007-08-28 36640]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\tony.LIFROOT\Start Menu\Programs\Startup\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-1-21 393216]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-4-19 24576]
Lotus QuickStart.lnk - c:\lotus\wordpro\ltsstart.exe [1997-5-14 25600]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"<NO NAME>"= c:\\DOCUME~1\\TONY~1.LIF\\LOCALS~1\\Temp\\ie17F.tmp
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5900:TCP"= 5900:TCP:vnc
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 MEMSWEEP2;MEMSWEEP2; [x]
R4 OMOKKPJ;OMOKKPJ; [x]
S2 EngineServer;EngineServer;c:\program files\McAfee\Managed VirusScan\VScan\EngineServer.exe [2009-03-03 14144]
S2 myAgtSvc;McAfee Virus and Spyware Protection Service;c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe [2009-04-13 175704]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3af26479-f7d5-11db-93a9-0011432640bd}]
\Shell\AutoRun\command - reper.exe
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://www.euro.dell.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: ebay.com\www
Trusted Zone: ebay.ie\www
Trusted Zone: lifsbs
Trusted Zone: microsoft.com\*.update
Trusted Zone: rte.ie\www
Trusted Zone: spybot.com\www
Trusted Zone: windowsupdate.com\download
Trusted Zone: winzip.com\www
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-01 09:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1048)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\BAsfIpM.exe
c:\program files\Dell\OpenManage\Client\Iap.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\SiteAdvisor\6173\SAService.exe
c:\windows\system32\fxssvc.exe
c:\progra~1\McAfee\MANAGE~1\VScan\McShield.exe
c:\windows\system32\wscntfy.exe
c:\program files\McAfee\Managed VirusScan\Agent\myAgtTry.exe
c:\program files\OpenOffice.org 2.4\program\soffice.exe
c:\program files\OpenOffice.org 2.4\program\soffice.bin
c:\program files\McAfee\Managed VirusScan\Agent\myUsrSrv4.7.0.752.exe
.
**************************************************************************
.
Completion time: 2009-05-01 9:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-01 08:41
Pre-Run: 58,977,746,944 bytes free
Post-Run: 58,912,260,096 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
187 --- E O F --- 2008-05-17 02:02
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------