Hi there Rorschach112,
thanks a million for your help on this one!! Here is the text from the combofix log
ComboFix 09-10-19.01 - Jackal 20/10/2009 12:29.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.64.1033.18.511.161 [GMT 13:00]
Running from: c:\documents and settings\jackal\Desktop\Combo-Fix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\jackal\Application Data\.#
c:\windows\system32\drivers\gasfkyhoymhvcr.sys
c:\windows\system32\gasfkyaehtmckr.dll
c:\windows\system32\gasfkybfalkyxq.dat
c:\windows\system32\gasfkybfhdlyxa.dll
c:\windows\system32\gasfkybgrmmndo.dat
c:\windows\system32\gasfkybnmtklrm.dll
c:\windows\system32\gasfkybotmxdpu.dat
c:\windows\system32\gasfkycbwlxukx.dll
c:\windows\system32\gasfkycdticxty.dat
c:\windows\system32\gasfkycxdpxyym.dat
c:\windows\system32\gasfkycxnostin.dll
c:\windows\system32\gasfkydmcqfgnt.dat
c:\windows\system32\gasfkydsidwfjx.dll
c:\windows\system32\gasfkyedipofdm.dll
c:\windows\system32\gasfkyeepylkvo.dat
c:\windows\system32\gasfkyefwuhjpw.dll
c:\windows\system32\gasfkyesmntymo.dll
c:\windows\system32\gasfkyfasfthpy.dll
c:\windows\system32\gasfkygibsdpxm.dll
c:\windows\system32\gasfkyhorxnqve.dat
c:\windows\system32\gasfkyhqoipmtv.dll
c:\windows\system32\gasfkyicxjqqht.dll
c:\windows\system32\gasfkyithcwyfj.dll
c:\windows\system32\gasfkyivkbebho.dat
c:\windows\system32\gasfkyixrenvst.dll
c:\windows\system32\gasfkyjitaqjnp.dat
c:\windows\system32\gasfkyjpywixth.dll
c:\windows\system32\gasfkykjalriiy.dll
c:\windows\system32\gasfkykoppjpya.dat
c:\windows\system32\gasfkykqgoeplo.dat
c:\windows\system32\gasfkylkmtqlbe.dll
c:\windows\system32\gasfkylog.dat
c:\windows\system32\gasfkylqecxfyp.dll
c:\windows\system32\gasfkylqeecbxm.dat
c:\windows\system32\gasfkymettkwbp.dat
c:\windows\system32\gasfkymkpftexn.dll
c:\windows\system32\gasfkymsbfnmdt.dll
c:\windows\system32\gasfkynbmvyiqd.dll
c:\windows\system32\gasfkyncwkiqvb.dat
c:\windows\system32\gasfkynyymaelv.dat
c:\windows\system32\gasfkyompdivrx.dll
c:\windows\system32\gasfkyospwixgb.dll
c:\windows\system32\gasfkypfvornyy.dll
c:\windows\system32\gasfkypjpbibmu.dll
c:\windows\system32\gasfkypoakayya.dll
c:\windows\system32\gasfkyppjvwqrw.dat
c:\windows\system32\gasfkypulkdwqi.dat
c:\windows\system32\gasfkyqomlwkfy.dat
c:\windows\system32\gasfkyricejmdn.dll
c:\windows\system32\gasfkyrnsvrapq.dll
c:\windows\system32\gasfkyrswuyabd.dat
c:\windows\system32\gasfkysbcoritt.dll
c:\windows\system32\gasfkyscnxvivx.dll
c:\windows\system32\gasfkysetepyyu.dll
c:\windows\system32\gasfkyswwxnvcj.dat
c:\windows\system32\gasfkytewqbpjp.dat
c:\windows\system32\gasfkytnwiwtse.dll
c:\windows\system32\gasfkytnwkbyue.dll
c:\windows\system32\gasfkytowfjwid.dll
c:\windows\system32\gasfkyudoykmxw.dll
c:\windows\system32\gasfkyuevbqcxv.dll
c:\windows\system32\gasfkyunfokmxm.dat
c:\windows\system32\gasfkyuwptgeor.dll
c:\windows\system32\gasfkyvcvrnquq.dll
c:\windows\system32\gasfkyvklnkvxd.dll
c:\windows\system32\gasfkyvmdivxbf.dll
c:\windows\system32\gasfkyvpavpjbo.dat
c:\windows\system32\gasfkyvpetynvx.dll
c:\windows\system32\gasfkywftiqloo.dat
c:\windows\system32\gasfkyxlvrsbxj.dat
c:\windows\system32\gasfkyxnnpwipb.dat
c:\windows\system32\gasfkyxtfqxbnm.dat
c:\windows\system32\gasfkyxublnrvi.dll
c:\windows\system32\gasfkyxusirbrp.dll
c:\windows\system32\gasfkyxxodowka.dat
c:\windows\system32\gasfkyycrjkboe.dat
c:\windows\system32\gasfkyyeyxnsmi.dat
c:\windows\system32\gasfkyyfucrncb.dll
c:\windows\system32\gasfkyyibigwrt.dat
c:\windows\system32\gasfkyymwwfhxl.dat
c:\windows\system32\gasfkyyxoafkmt.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gasfkyhhbgkoob
-------\Legacy_gasfkyhhbgkoob
((((((((((((((((((((((((( Files Created from 2009-09-20 to 2009-10-20 )))))))))))))))))))))))))))))))
.
2009-10-19 23:22 . 2009-10-19 23:22 604140 --sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-10-19 14:35 . 2009-10-19 14:35 -------- d-----w- c:\documents and settings\Brooklyn\Local Settings\Application Data\Google
2009-10-19 01:04 . 1999-04-23 09:22 151552 ----a-w- c:\windows\system32\MSOSS.DLL
2009-10-18 06:52 . 2008-10-16 01:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-10-18 00:33 . 2009-10-18 01:24 108059 ----a-w- c:\windows\system32\drivers\klin.dat
2009-10-18 00:33 . 2009-10-18 01:24 95259 ----a-w- c:\windows\system32\drivers\klick.dat
2009-10-18 00:31 . 2009-10-20 00:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-10-17 12:38 . 2008-11-09 22:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
2009-10-16 23:49 . 2009-10-19 01:00 21840 ----atw- c:\windows\system32\SIntfNT.dll
2009-10-16 23:49 . 2009-10-19 01:00 17212 ----atw- c:\windows\system32\SIntf32.dll
2009-10-16 23:49 . 2009-10-19 01:00 12067 ----atw- c:\windows\system32\SIntf16.dll
2009-10-15 22:47 . 2009-10-15 23:00 -------- d-----w- c:\documents and settings\jackal\Application Data\GetRightToGo
2009-10-15 21:03 . 2009-10-15 21:03 35363 ----a-w- c:\windows\system32\windrvNT.sys
2009-10-15 21:03 . 2009-10-15 21:03 53248 ----a-w- c:\windows\system32\suppdll.dll
2009-10-15 21:01 . 2005-04-11 03:40 73728 ----a-w- c:\windows\system32\FLKill.exe
2009-10-13 12:14 . 2009-10-13 12:36 -------- d-----w- c:\program files\Microsoft Works
2009-10-13 12:07 . 2009-10-13 12:07 -------- d-----w- c:\program files\Microsoft.NET
2009-10-13 11:58 . 2009-10-13 11:58 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-10-13 11:55 . 2009-10-13 11:55 -------- d-----w- c:\documents and settings\jackal\Local Settings\Application Data\Microsoft Help
2009-10-13 11:55 . 2009-10-18 05:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-10 21:40 . 2009-10-10 21:40 5136 ----a-w- c:\windows\system32\pmod11.dll
2009-10-10 21:35 . 2009-10-10 21:35 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-10 21:32 . 2009-10-10 21:32 -------- d-----w- C:\spoolerlogs
2009-09-29 06:15 . 2001-12-11 22:37 30772 ----a-w- c:\windows\system32\drivers\ImHidUsb.sys
2009-09-29 06:15 . 2001-12-11 22:37 16384 ----a-w- c:\windows\system32\imm_enu.dll
2009-09-29 06:15 . 2009-09-29 06:15 -------- d-----w- c:\program files\KYE
2009-09-29 06:15 . 2001-12-11 22:38 106496 ----a-w- c:\windows\system32\ImmPID.dll
2009-09-29 06:15 . 2001-12-11 22:37 1024000 ----a-w- c:\windows\system32\ImmCpl.dll
2009-09-29 06:15 . 2001-07-02 08:45 196608 ----a-w- c:\windows\system32\Ifc22.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-20 00:25 . 2008-08-27 12:38 1632 ----a-w- c:\windows\system32\d3d8caps.dat
2009-10-19 23:55 . 2008-08-28 10:10 3351 ----a-w- c:\windows\bthservsdp.dat
2009-10-19 12:06 . 2008-08-27 11:49 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-19 10:40 . 2009-03-16 08:21 1744 ----a-w- c:\windows\system32\d3d9caps.dat
2009-10-19 09:31 . 2009-03-14 22:01 -------- d-----w- c:\documents and settings\jackal\Application Data\uTorrent
2009-10-18 00:26 . 2009-02-22 11:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-10-17 22:23 . 2007-07-05 01:27 -------- d-----w- c:\program files\Google
2009-10-17 14:02 . 2009-08-14 08:53 -------- d-----w- c:\program files\PokerStars
2009-10-17 13:56 . 2009-08-09 02:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Kodak
2009-10-17 02:55 . 2006-02-08 21:50 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-17 02:54 . 2009-08-10 10:27 -------- d-----w- c:\documents and settings\jackal\Application Data\Panasonic
2009-10-13 22:27 . 2009-03-04 14:17 72424 ----a-w- c:\documents and settings\jackal\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-13 12:13 . 2009-08-30 15:17 -------- d-----w- c:\program files\MSBuild
2009-10-10 09:23 . 2009-06-28 23:42 -------- d-----w- c:\program files\Windows Media Connect 2
2009-10-02 13:20 . 2009-07-19 14:11 -------- d-----w- c:\documents and settings\jackal\Application Data\vlc
2009-09-30 10:08 . 2009-09-05 13:59 -------- d-----w- c:\documents and settings\jackal\Application Data\SolSuite
2009-09-26 07:33 . 2007-07-05 01:35 -------- d-----w- c:\program files\Picasa2
2009-09-17 09:32 . 2009-09-17 09:22 227 ----a-w- c:\windows\PowerReg.dat
2009-09-17 08:52 . 2009-09-17 08:52 -------- d-----w- c:\documents and settings\jackal\Application Data\Atari
2009-09-17 08:48 . 2009-09-17 08:48 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-09-16 11:33 . 2009-09-16 11:33 -------- d-----w- c:\documents and settings\jackal\Application Data\Leadertech
2009-09-12 12:46 . 2009-08-10 10:50 23856 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-11 14:18 . 2004-08-03 12:56 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-05 13:59 . 2009-09-05 13:59 -------- d-----w- c:\documents and settings\All Users\Application Data\TreeCardGames
2009-09-05 13:58 . 2009-09-04 10:45 -------- d-----w- c:\program files\SolSuite
2009-09-04 21:03 . 2004-08-03 12:56 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-04 11:29 . 2009-08-28 12:55 -------- d-----w- c:\documents and settings\jackal\Application Data\Music Organiser
2009-08-30 15:17 . 2009-08-30 15:17 -------- d-----w- c:\program files\Reference Assemblies
2009-08-29 08:08 . 2004-08-03 12:56 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-28 11:40 . 2009-07-05 12:53 -------- d-----w- c:\program files\PKR
2009-08-28 00:54 . 2009-08-28 00:54 -------- d-----w- c:\program files\ABIT
2009-08-26 08:00 . 2004-08-03 12:56 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-18 13:50 . 2009-08-18 13:50 23600 ----a-w- c:\windows\system32\drivers\TVICHW32.SYS
2009-08-18 09:56 . 2009-08-18 09:56 1632 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\d3d8caps.tmp
2009-08-18 09:56 . 2009-08-18 09:56 1744 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\d3d9caps.tmp
2009-08-17 10:33 . 2009-08-17 10:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-05 09:01 . 2004-08-03 12:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 14:20 . 2004-08-03 22:59 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-08-04 07:44 . 2004-08-03 11:20 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Systweak Memory Optimizer"="c:\program files\advanced system optimizer\memtuneup.exe" [2007-06-21 119024]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-17 39408]
"NVIEW"="nview.dll" - c:\windows\system32\nview.dll [2003-07-28 852038]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2005-12-04 437008]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"QuickTime Task"="c:\windows\system32\qttask.exe" [2009-04-17 98304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-24 31072]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-10-17 122880]
"AVP"="d:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-07-03 303376]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-03 44544]
c:\documents and settings\jackal\Start Menu\Programs\Startup\
Xnet Usage Monitor.lnk - c:\program files\Xnet Usage Monitor\XNetUsage.exe [2009-5-6 2241536]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
XH9947 DSE Wireless Client Utility.lnk - c:\program files\DSE\XH9947\Installer\WINXP\DSEWCU.exe [2008-8-28 598016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmod11]
2009-10-10 21:40 5136 ----a-w- c:\windows\system32\pmod11.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Documents and Settings\\Rynee\\My Documents\\My Downloads\\uTorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"d:\\Program files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [15/12/2008 8:41 p.m. 33808]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13/05/2009 5:46 p.m. 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [16/05/2009 8:59 p.m. 19472]
R3 VAD_DEV;Virtual Audio Service;c:\windows\system32\drivers\vad.sys [27/05/2009 2:23 a.m. 16256]
R3 wdm_au8830;Aureal Vortex 8830 Audio Driver (WDM);c:\windows\system32\drivers\adm8830.sys [28/08/2008 12:04 a.m. 747392]
S1 rqeeanox;rqeeanox;\??\c:\windows\system32\drivers\rqeeanox.sys --> c:\windows\system32\drivers\rqeeanox.sys [?]
S3 imhidusb;Immersion's HID USB Driver;c:\windows\system32\drivers\ImHidUsb.sys [29/09/2009 7:15 p.m. 30772]
S3 ngrpci;NETGEAR FA310TX Fast Ethernet Adapter Driver;c:\windows\system32\drivers\Ngrpci.sys [8/02/2006 11:55 p.m. 32840]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-10-20 c:\windows\Tasks\User_Feed_Synchronization-{E4EFB65F-3CF8-4176-93CE-CED3D5D80A1D}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 16:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.tattoodle.com?tid={6BB2DF15-078B-45ea-AD3A-9130CE6DCC17}&v=12
uInternet Settings,ProxyOverride = localhost
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_674125AABFE11C21.dll/cmsidewiki.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DriverUpdaterPro - c:\program files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe
AddRemove-040a_5005 - c:\program files\Kodak\040a_5005\Remove.exe
AddRemove-FolderLock6 - c:\program files\Folder Lock\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-20 13:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\sccfg.sys 20 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2025429265-602609370-682003330-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1028)
c:\windows\system32\pmod11.dll
- - - - - - - > 'explorer.exe'(3592)
c:\windows\system32\WININET.dll
c:\windows\system32\nView.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\program files\Google\Quick Search Box\bin\1.2.1150.158\qsb.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\brss01a.exe
c:\windows\system32\Brmfrmps.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\nvsvc32.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\combo-fix\CF25133.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-10-20 13:34 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-20 00:34
Pre-Run: 2,931,134,464 bytes free
Post-Run: 3,269,726,208 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 0FC7372F5EB4FBEFE85CC4C5330F7A6F