التقرير الأول
ComboFix 08-12-06.06 - مركز ريوف 12/06/2008 15:32:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.1.1025.18.219 [GMT 3:00]
Running from: c:\documents and settings\مركز ريوف\سطح المكتب\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\
08dgu.com
C:\
0w.com
C:\9.cmd
C:\abk.bat
C:\autorun.inf
C:\b.exe
c:\documents and settings\مركز ريوف\Application Data\addon.dat
C:\e.cmd
C:\ev60a2.cmd
C:\i.bat
C:\ij.bat
C:\lky.exe
C:\m2nl.bat
C:\ncyrf.bat
C:\nq0cq.cmd
C:\pnt.com
c:\program files\Bifrost
c:\program files\bifrost\klog.dat
c:\program files\bifrost\server.exe
C:\rcukd.cmd
c:\windows\IE4 Error Log.txt
c:\windows\system32\9960.dll
c:\windows\system32\AutoRun.inf
c:\windows\system32\ckvo.exe
c:\windows\system32\ckvo0.dll
c:\windows\system32\ckvo1.dll
c:\windows\system32\gasretyw0.dll
c:\windows\system32\gasretyw1.dll
c:\windows\system32\gasretyw2.dll
c:\windows\system32\kamsoft.exe
C:\xih9.cmd
C:\yannh.cmd
D:\
0w.com
D:\abk.bat
D:\Autorun.inf
D:\e.cmd
D:\i.bat
D:\ij.bat
D:\lky.exe
D:\m2nl.bat
D:\ncyrf.bat
D:\nq0cq.cmd
D:\pnt.com
D:\rcukd.cmd
D:\xih9.cmd
D:\yannh.cmd
E:\
08dgu.com
E:\
0w.com
E:\9.cmd
E:\abk.bat
E:\Autorun.inf
E:\b.exe
E:\e.cmd
E:\ev60a2.cmd
E:\i.bat
E:\ij.bat
E:\lky.exe
E:\m2nl.bat
E:\ncyrf.bat
E:\nq0cq.cmd
E:\pnt.com
E:\rcukd.cmd
E:\xih9.cmd
E:\yannh.cmd
F:\
08dgu.com
F:\
0w.com
F:\9.cmd
F:\abk.bat
F:\Autorun.inf
F:\b.exe
F:\e.cmd
F:\i.bat
F:\ij.bat
F:\lky.exe
F:\m2nl.bat
F:\ncyrf.bat
F:\nq0cq.cmd
F:\pnt.com
F:\rcukd.cmd
F:\xih9.cmd
F:\yannh.cmd
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2008-11-06 to 2008-12-06 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-06 12:36 --------- d-----w c:\program files\SpeedBit Video Accelerator
2008-12-06 03:41 174,080 --sh--r C:\2u.com
2008-12-04 16:12 0 ----a-w C:\osy3.sys
2008-12-04 05:33 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-12-04 05:33 --------- d-----w c:\program files\Java
2008-12-04 05:29 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-03 17:27 --------- d-----w c:\program files\Xilisoft
2008-12-03 17:27 --------- d-----w c:\program files\QuickTime
2008-12-03 06:25 --------- d-----w c:\program files\Golden Al-Wafi Translator
2008-11-27 19:48 --------- d-----w c:\program files\Eset
2008-11-27 08:38 --------- d-----w c:\documents and settings\مركز ريوف\Application Data\Datalayer
2008-11-27 08:32 183,296 --sh--r C:\o1.com
2008-11-25 20:50 --------- d-----w c:\program files\Google
2008-11-25 12:21 --------- d-----w c:\documents and settings\مركز ريوف\Application Data\Nokia Multimedia Player
2008-11-24 16:19 --------- d-----w c:\program files\Windows Media Connect 2
2008-11-23 11:19 --------- d-----w c:\program files\Rescue Pro
2008-11-22 11:50 --------- d-----w c:\program files\Hanami
2008-11-21 17:21 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-21 17:18 --------- d-----w c:\program files\Symantec
2008-11-21 17:08 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2008-11-21 14:35 --------- d-----w c:\documents and settings\مركز ريوف\Application Data\Symantec
2008-11-20 00:52 --------- d-----w c:\documents and settings\All Users\Application Data\HP
2008-11-19 15:05 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-17 11:40 --------- d-----w c:\program files\NCH Swift Sound
2008-11-14 17:29 --------- d-----w c:\program files\DAP
2008-11-12 17:35 --------- d-----w c:\documents and settings\مركز ريوف\Application Data\NCH Swift Sound
2008-11-12 10:48 --------- d-----w c:\program files\NCH Software
2008-11-12 10:48 --------- d-----w c:\documents and settings\مركز ريوف\Application Data\Recordpad
2008-11-12 10:48 --------- d-----w c:\documents and settings\All Users\Application Data\NCH Swift Sound
2008-11-09 15:58 1,949,184 ----a-w c:\windows\system32\logonui.exe
2008-11-09 15:52 --------- d-----w c:\program files\Kaspersky Lab
2008-11-09 15:41 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-09 15:34 182,272 --sh--r C:\whi.com
2008-11-08 16:00 110,013 --sh--r C:\sq.com
2008-11-06 16:29 --------- d-----w c:\documents and settings\مركز ريوف\Application Data\HP
2008-11-06 16:29 --------- d-----w c:\documents and settings\All Users\Application Data\WEBREG
2008-11-06 16:28 --------- d-----w c:\program files\HP
2008-11-06 16:28 --------- d-----w c:\documents and settings\All Users\Application Data\HPSSUPPLY
2008-11-06 16:27 --------- d-----w c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-11-06 16:26 --------- d-----w c:\program files\Common Files\HP
2008-11-06 16:22 --------- d-----w c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-11-04 04:45 --------- d-----w c:\program files\Sun
2008-11-01 15:07 --------- d-----w c:\program files\XTerm Medical Dictionary
2008-10-30 08:00 --------- d-----w c:\documents and settings\مركز ريوف\Application Data\Nokia
2008-10-28 16:14 45,056 ----a-w c:\windows\NCUNINST.EXE
2008-10-28 16:12 --------- d-----w c:\program files\Common Files\SWF Studio
2008-10-24 19:17 182,272 --sh--r C:\xlk9.com
2008-10-24 17:22 90,112 ----a-w c:\windows\DUMP4546.tmp
2008-10-24 17:14 --------- d-----w c:\documents and settings\مركز ريوف\Application Data\Media Player Classic
2008-10-24 17:13 47,104 ------w c:\windows\AKDeInstall.exe
2008-10-24 17:13 --------- d-----w c:\program files\mpegable
2008-10-24 17:13 --------- d-----w c:\program files\K-Lite Codec Pack
2008-10-24 17:08 --------- d-----w c:\documents and settings\All Users\Application Data\ESET
2008-10-24 12:37 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-10-24 03:52 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-24 03:52 --------- d-----w c:\program files\Common Files\Panda Software
2008-10-23 20:57 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-23 16:30 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2008-10-23 16:30 --------- d-----w c:\program files\Windows Live
2008-10-23 16:18 --------- d-----w c:\program files\SereneScreen
2008-10-23 16:14 178,176 --sh--r C:\2fiji.com
2008-10-23 14:25 --------- d-----w c:\program files\Microsoft.NET
2008-10-23 14:24 --------- d-----w c:\program files\Microsoft Works
2008-10-22 18:52 --------- dc-h--w c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2008-10-22 17:42 --------- d-----w c:\program files\Messenger Plus! Live
2008-10-22 12:12 --------- d-----w c:\documents and settings\مركز ريوف\Application Data\CyberLink
2008-10-10 19:13 --------- d-----w c:\program files\Conduits Pocket Slides
2008-10-10 17:42 --------- d-----w c:\documents and settings\مركز ريوف\Application Data\DMCache
2008-10-10 17:31 56,594 ----a-w c:\program files\Allah.ani
2008-10-10 12:44 --------- d-----w c:\documents and settings\Guest\Application Data\PC Suite
2008-10-09 18:52 16,608 ----a-w c:\windows\gdrv.sys
2008-10-09 07:51 --------- d-----w c:\program files\Intel
2008-10-09 07:34 180 ----a-w c:\windows\system32\drivers\sthdae.log
2008-10-09 07:33 --------- d-----w c:\program files\Realtek
2008-10-09 07:29 --------- d-----w c:\program files\Sigmatel
2008-10-09 07:25 315,392 ----a-w c:\windows\HideWin.exe
2008-10-08 17:28 --------- d-----w c:\documents and settings\All Users\Application Data\Backup
2008-10-08 17:25 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-07 18:41 --------- d-----w c:\documents and settings\مركز ريوف\Application Data\AdobeUM
2008-10-07 16:10 --------- d-----w c:\program files\Frame Maker Pro
2008-10-07 15:30 --------- d-----w c:\documents and settings\مركز ريوف\Application Data\Regsdrvway
2008-10-07 15:30 --------- d-----w c:\documents and settings\All Users\Application Data\aim rect help creative
2008-10-07 15:29 --------- d-----w c:\program files\Regsdrvway
2008-10-05 15:56 73,216 ----a-w c:\windows\ST6UNST.EXE
2008-10-05 15:56 172,032 ------w c:\windows\Setup1.exe
2008-10-05 15:48 155,995 ----a-w c:\windows\java\Packages\KIFP3PZF.ZIP
2008-10-04 15:50 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-10-04 15:50 348,160 ----a-w c:\windows\system32\msvcr71.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [06/27/2006 04:21 PM 1597440]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [08/04/2004 01:09 AM 1667584]
"thirdmeal"="c:\docume~1\9801~1\APPLIC~1\REGSDR~1\part kind 32.exe" [12/03/2008 08:57 AM 598528]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [08/04/2004 12:56 AM 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [08/16/2007 04:19 PM 5797744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [10/04/2008 06:50 PM 333352]
"PCSuiteTrayApplication"="c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [06/15/2006 12:36 PM 307200]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [01/12/2005 03:01 AM 110592]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [12/04/2008 08:33 AM 136600]
"Help Creative Meow City"="c:\documents and settings\All Users\Application Data\aim rect help creative\pile defy.exe" [11/11/2008 06:01 PM 709632]
"igfxtray"="c:\windows\system32\igfxtray.exe" [11/03/2005 10:25 AM 176128]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [11/03/2005 10:22 AM 221184]
"igfxpers"="c:\windows\system32\igfxpers.exe" [11/03/2005 10:26 AM 188416]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [03/11/2007 09:34 PM 126976]
"SpeedBitVideoAccelerator"="c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe" [11/09/2008 07:08 PM 2881136]
"Recordpad"="c:\program files\NCH Swift Sound\Recordpad\recordpad.exe" [12/03/2008 02:20 PM 647172]
"SigmatelSysTrayApp"="sttray.exe" [05/06/2007 12:10 PM 557056 c:\windows\sttray.exe]
"SMSERIAL"="sm56hlpr.exe" [06/06/2005 12:40 PM 696320 c:\windows\sm56hlpr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [08/04/2004 12:56 AM 15360]
c:\documents and settings\ê©èھ ©ïيه\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Shortcut to Hanami.exe.lnk - c:\program files\Hanami\Hanami.exe [2001-03-21 1126400]
c:\documents and settings\All Users\çںê، ں §ڑ\ںé ©ںê¤\ §ک ں颬نïé\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-10-05 183296]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 103424]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 366168]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-10-05 200704]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\(Default)
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\usnsvc.exe"=
"c:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe"=
"c:\\WINDOWS\\system32\\hkcmd.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\MsnMsgr.Exe"=
"c:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE"=
"c:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\reader_sl.exe"=
"c:\\WINDOWS\\sttray.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\userinit.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqSTE08.exe"=
"c:\\WINDOWS\\system32\\mobsync.exe"=
"c:\\docume~1\\9801~1\\applic~1\\regsdr~1\\coal eggs four.exe"=
"c:\\Program Files\\Nokia\\Nokia PC Suite 6\\PcSync2.exe"=
"c:\\PROGRA~1\\COMMON~1\\Nokia\\MPAPI\\MPAPI3s.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"=
"c:\\WINDOWS\\system32\\igfxpers.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\WINWORD.EXE"=
"c:\\PROGRA~1\\COMMON~1\\PCSuite\\DATALA~1\\DATALA~1.EXE"=
"c:\\WINDOWS\\windows Update\\server.exe"=
"c:\\Program Files\\NCH Swift Sound\\Recordpad\\recordpad.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Calibration\\Adobe Gamma Loader.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Nokia\\Nokia PC Suite 6\\SeUpdateDb.exe"=
"c:\\Program Files\\WinZip\\WZQKPICK.EXE"=
"c:\\Program Files\\Hanami\\Hanami.exe"=
"d:\\2u.com"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
R1 BIOS;BIOS;\??\c:\windows\system32\drivers\BIOS.sys [2008-10-08 13696]
R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2007-11-14 33800]
R2 sbbotdi;sbbotdi;\??\c:\progra~1\SPEEDB~1\sbbotdi.sys [2008-11-09 35584]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm []
S3 AVPsys;AVPsys;\??\c:\windows\system32\drivers\cdaudio.sys [2001-08-17 18688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{00264680-a116-11dd-b21f-001bb9eaa134}]
\Shell\AutoRun\command - H:\2u.com
\Shell\explore\Command - H:\2u.com
\Shell\open\Command - H:\2u.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0b50f1bd-9495-11dd-b1c2-001bb9eaa134}]
\Shell\AutoRun\command - I:\rcukd.cmd
\Shell\explore\Command - I:\rcukd.cmd
\Shell\open\Command - I:\rcukd.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0d8b1e76-bb2e-11dd-8865-001bb9eaa134}]
\Shell\AutoRun\command - I:\ij.bat
\Shell\explore\Command - I:\ij.bat
\Shell\open\Command - I:\ij.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0de670cf-a046-11dd-b201-001bb9eaa134}]
\Shell\AutoRun\command - H:\2fiji.com
\Shell\explore\Command - H:\2fiji.com
\Shell\open\Command - H:\2fiji.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2a9509eb-adab-11dd-87d6-001bb9eaa134}]
\Shell\AutoRun\command - I:\sq.com
\Shell\explore\Command - I:\sq.com
\Shell\open\Command - I:\sq.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6af05c8b-a826-11dd-87a6-001bb9eaa134}]
\Shell\AutoRun\command - H:\ij.bat
\Shell\explore\Command - H:\ij.bat
\Shell\open\Command - H:\ij.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{80fcf832-96a7-11dd-b1e3-001bb9eaa134}]
\Shell\AuToPlaY\ComManD - H:\exrya.pif
\Shell\AutoRun\command - H:\exrya.pif
\Shell\Explore\CommAnd - H:\exrya.pif
\Shell\OPen\cOMmANd - H:\exrya.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d1a2c648-c217-11dd-88c0-001bb9eaa134}]
\sHeLl\aUtOPlaY\Command - H:\ubyaib.pif
\sHeLl\AutoRun\command - H:\ubyaib.pif
\sHeLl\eXploRe\COMmaNd - H:\ubyaib.pif
\sHeLl\OpEn\cOMMANd - H:\ubyaib.pif
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fb23484a-955c-11dd-b1cc-001bb9eaa134}]
\Shell\AutoRun\command - H:\pnt.com
\Shell\explore\Command - H:\pnt.com
\Shell\open\Command - H:\pnt.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ff4bcb25-9550-11dd-b1ca-001bb9eaa134}]
\Shell\AutoRun\command - H:\CDSetup.exe
.
s of the 'Scheduled Tasks' folder
2008-12-06 c:\windows\Tasks\AD87C35C919876BC.job
- c:\docume~1\9801~1\applic~1\regsdr~1\coal eggs four.exe [10/07/2008 06:30 PM]
2008-11-21 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [08/13/2003 06:38 PM]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.sa/
uInternet Settings,ProxyOverride = local
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 -: Microsoft XML Parser for Java -
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-12-06 15:35:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Sigmatel\C-Major Audio\WDM\stacsv.exe
c:\progra~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe
c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 12/06/2008 15:37:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-06 12:37:50
Pre-Run: 11,446,345,728 bytes free
Post-Run: 13,652,631,552 bytes free
357 --- E O F --- 2008-10-07 19:21:30