اممممم ضغطت على هذا
ComboFix 09-12-07.01 - user 12/07/2009 14:23.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1256.974.1033.18.2038.1434 [GMT -8:00]
Running from: c:\documents and settings\user\Desktop\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\program files\SpeedBit Toolbar\Toolbar\tbhelper.dll
c:\program files\SpeedBit Video Downloader\Toolbar\tbhelper.dll
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
c:\windows\system32\kakle.dll
c:\windows\system32\twain_32.dll
c:\windows\system32\videocore.dll
c:\windows\system32\videoformat.dll
c:\windows\system32\winitn.dll
D:\AUTORUN.INF
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_AVPsys
((((((((((((((((((((((((( Files Created from 2009-11-07 to 2009-12-07 )))))))))))))))))))))))))))))))
.
2009-12-06 22:07 . 2009-12-06 22:07 91648 ----a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2009-12-06 22:05 . 2009-12-06 22:05 -------- d-----w- c:\program files\SpeedBit Toolbar
2009-11-27 04:04 . 2009-11-27 04:04 -------- d-----w- c:\documents and settings\user\Application Data\Oberonv1002
2009-11-27 03:22 . 2009-04-23 20:52 750984 ----a-w- c:\windows\system32\Magentic Screensaver.scr
2009-11-27 03:22 . 2009-11-27 03:27 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Magentic
2009-11-27 03:22 . 2009-11-27 03:22 -------- d-----w- c:\program files\Magentic
2009-11-22 23:42 . 2009-12-07 22:29 12 ----a-w- c:\windows\bthservsdp.dat
2009-11-18 11:14 . 2009-11-25 22:58 -------- d-----w- c:\program files\HiYo Games
2009-11-18 10:29 . 2009-11-18 10:29 -------- d-----w- c:\documents and settings\user\Application Data\Paltalk
2009-11-18 10:29 . 2009-11-18 10:29 -------- d-----w- c:\windows\PaltalkScene
2009-11-18 10:29 . 2009-11-18 10:30 -------- d-----w- c:\program files\Paltalk Messenger
2009-11-17 08:36 . 2009-11-17 08:36 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\AskToolbar
2009-11-17 08:35 . 2009-11-17 08:35 -------- d-----w- c:\program files\Ask.com
2009-11-17 08:30 . 2009-12-06 22:02 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedBit
2009-11-17 08:30 . 2009-12-06 22:06 -------- d-----w- c:\program files\DAP
2009-11-17 08:30 . 2009-12-06 22:02 -------- d-----w- c:\program files\SpeedBit Video Downloader
2009-11-16 15:47 . 2009-11-16 15:47 -------- d-----w- c:\windows\Sun
2009-11-15 07:08 . 2009-11-15 07:08 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-15 07:08 . 2009-11-15 07:08 -------- d-----w- c:\program files\Java
2009-11-15 07:07 . 2009-11-15 07:07 152576 ----a-w- c:\documents and settings\user\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-14 00:01 . 2009-12-05 16:35 -------- d-----w- c:\documents and settings\user\Application Data\DMCache
2009-11-14 00:01 . 2009-12-03 15:18 -------- d-----w- c:\documents and settings\user\Application Data\IDM
2009-11-14 00:01 . 2009-12-05 16:56 -------- d-----w- c:\program files\Internet Download Manager
2009-11-11 19:48 . 2009-11-11 19:48 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-09 03:31 . 2009-11-12 00:39 0 ----a-w- c:\documents and settings\user\Application Data\GRETECH\GomPlayer\GrLauncherTempSetup.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-07 22:30 . 2009-11-01 19:48 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-06 02:43 . 2009-10-11 15:13 10 ----a-w- c:\windows\popcinfo.dat
2009-11-27 04:03 . 2009-11-01 19:47 -------- d-----w- c:\program files\IncrediGames
2009-11-25 22:52 . 2008-10-16 15:00 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-18 00:00 . 2008-10-16 16:17 321392 ----a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-17 23:20 . 2008-10-16 15:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-17 20:29 . 2009-04-13 17:36 1245184 ----a-w- c:\windows\system32\bkll.dll
2009-11-17 20:29 . 2009-04-13 17:36 2846720 ----a-w- c:\windows\system32\agsaamj.dll
2009-11-17 20:29 . 2009-04-13 17:36 90112 ----a-w- c:\windows\system32\agsaami.dll
2009-11-17 20:29 . 2009-04-13 17:36 215552 ----a-w- c:\windows\system32\ALOWMVFile.dll
2009-11-17 20:29 . 2009-04-13 17:36 403968 ----a-w- c:\windows\system32\ALOWMAFile2.dll
2009-11-17 20:29 . 2009-04-13 17:36 753664 ----a-w- c:\windows\system32\agsaamg.dll
2009-11-17 20:29 . 2009-04-13 17:36 626688 ----a-w- c:\windows\system32\agsaamh.dll
2009-11-17 20:29 . 2009-04-13 17:36 188416 ----a-w- c:\windows\system32\ALOVideoFile.dll
2009-11-17 20:29 . 2009-04-13 17:36 495104 ----a-w- c:\windows\system32\ALOVideoCoreM.dll
2009-11-17 20:29 . 2009-04-13 17:36 551424 ----a-w- c:\windows\system32\agsaame.dll
2009-11-17 20:28 . 2009-04-13 17:36 544256 ----a-w- c:\windows\system32\agsaamd.dll
2009-11-17 20:28 . 2009-04-13 17:36 372736 ----a-w- c:\windows\system32\agsaamc.dll
2009-11-17 20:28 . 2009-04-13 17:36 780288 ----a-w- c:\windows\system32\ALOVideoCompress.dll
2009-11-17 20:28 . 2009-04-13 17:36 249856 ----a-w- c:\windows\system32\ALOQuickTimeFile.dll
2009-11-17 20:28 . 2009-04-13 17:36 538624 ----a-w- c:\windows\system32\agsaamb.dll
2009-11-17 20:28 . 2009-04-13 17:36 331776 ----a-w- c:\windows\system32\agsaama.dll
2009-11-17 20:28 . 2009-04-13 17:36 90112 ----a-w- c:\windows\system32\ALOAudioFormatSettings3.dll
2009-11-17 20:28 . 2009-04-13 17:36 877568 ----a-w- c:\windows\system32\ALOAudioFile2.dll
2009-11-17 20:28 . 2009-04-13 17:36 382464 ----a-w- c:\windows\system32\ALOAVIFile.dll
2009-11-17 20:28 . 2009-04-13 17:36 2846720 ----a-w- c:\windows\system32\ALOAudioCompress3.dll
2009-11-17 20:28 . 2009-04-13 17:36 778240 ----a-w- c:\windows\system32\ALOAudioCompress2.dll
2009-11-08 21:34 . 2009-04-13 17:46 -------- d-----w- c:\program files\Messenger Plus! Live
2009-11-01 19:47 . 2009-11-01 19:47 -------- d-----w- c:\program files\Common Files\Oberon Media
2009-11-01 19:47 . 2009-11-01 19:47 -------- d-----w- c:\program files\Oberon Media
2009-11-01 10:16 . 2009-11-01 10:15 -------- d-----w- c:\documents and settings\All Users\Application Data\IM
2009-11-01 10:15 . 2009-11-01 10:15 -------- d-----w- c:\documents and settings\All Users\Application Data\IncrediMail
2009-11-01 10:15 . 2009-11-01 10:15 -------- d-----w- c:\program files\IncrediMail
2009-10-30 00:21 . 2009-10-30 00:21 -------- d-----w- c:\documents and settings\user\Application Data\HiYo
2009-10-30 00:21 . 2009-10-30 00:21 -------- d-----w- c:\program files\HiYo
2009-10-30 00:21 . 2009-10-30 00:21 -------- d-----w- c:\documents and settings\All Users\Application Data\HiYo
2009-10-27 09:50 . 2009-10-27 09:50 -------- d-----w- c:\documents and settings\All Users\Application Data\TechSmith
2009-10-20 09:10 . 2009-10-20 09:10 -------- d-----w- c:\documents and settings\user\Application Data\Playrix Entertainment
2009-10-20 09:08 . 2009-10-20 09:08 -------- d-----w- c:\program files\Playrix Entertainment
2009-10-11 12:41 . 2009-10-11 12:39 -------- d-----w- c:\program files\Zuma Deluxe
2009-10-11 12:35 . 2009-10-11 12:35 -------- d-----w- c:\program files\PopCap Games
2009-10-09 16:58 . 2009-04-13 17:45 -------- d-----w- c:\program files\Windows Live
2009-10-09 16:58 . 2009-10-09 16:58 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-10-09 16:57 . 2009-10-09 16:57 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-10-09 16:54 . 2009-10-09 16:54 -------- d-----w- c:\program files\Microsoft
2009-10-09 15:56 . 2009-10-09 15:56 -------- d-----w- c:\program files\Common Files\Windows Live
2009-09-26 03:20 . 2006-07-12 01:35 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-09-26 02:47 . 2009-04-13 17:36 344064 ----a-w- c:\windows\system32\dkll.dll
2009-09-26 02:47 . 2009-04-13 17:36 1986560 ----a-w- c:\windows\system32\akll.dll
2009-09-26 02:47 . 2009-04-13 17:36 196608 ----a-w- c:\windows\system32\maag.dll
2009-09-26 02:47 . 2009-04-13 17:36 1212416 ----a-w- c:\windows\system32\ckll.dll
2009-09-10 23:16 . 2009-09-01 02:23 11382816 --sha-w- c:\windows\system32\drivers\fidbox.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{F4F10C1D-87C7-404A-B4B3-000000000000}"= "c:\progra~1\DAP\SBSearch.dll" [2009-12-06 38384]
[HKEY_CLASSES_ROOT\clsid\{f4f10c1d-87c7-404a-b4b3-000000000000}]
[HKEY_CLASSES_ROOT\SearchHook.SrchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{95EFB171-F3DF-4BEC-9EF7-829A800203E6}]
[HKEY_CLASSES_ROOT\SearchHook.SrchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B}]
2009-12-06 22:02 2655736 ----a-w- c:\program files\SpeedBit Video Downloader\Toolbar\tbcore3.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-04-03 03:50 809864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-04-03 809864]
"{EBFCD017-BCAD-42C3-9ED5-89DBDFC59171}"= "c:\program files\SpeedBit Toolbar\Toolbar\SpeedBit.dll" [2009-12-06 2598896]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CLASSES_ROOT\clsid\{ebfcd017-bcad-42c3-9ed5-89dbdfc59171}]
[HKEY_CLASSES_ROOT\SPEEDBIT1.SPEEDBIT1.3]
[HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}]
[HKEY_CLASSES_ROOT\SPEEDBIT1.SPEEDBIT1]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-04-03 809864]
"{EBFCD017-BCAD-42C3-9ED5-89DBDFC59171}"= "c:\program files\SpeedBit Toolbar\Toolbar\SpeedBit.dll" [2009-12-06 2598896]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CLASSES_ROOT\clsid\{ebfcd017-bcad-42c3-9ed5-89dbdfc59171}]
[HKEY_CLASSES_ROOT\SPEEDBIT1.SPEEDBIT1.3]
[HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}]
[HKEY_CLASSES_ROOT\SPEEDBIT1.SPEEDBIT1]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2009-11-01 280008]
"Magentic"="c:\progra~1\Magentic\bin\Magentic.exe" [2009-04-23 488808]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2009-12-06 2799104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-06 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-06 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-06 137752]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-10-31 2595616]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-10-31 909208]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-10-31 140568]
"CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2004-09-02 57344]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-08 30208]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-08-18 1447168]
"TrialReset"="c:\windows\fix.exe" [2008-04-28 208353]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2006-11-06 200704]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-26 198160]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Hiyo"="c:\program files\HiYo\bin\HiYo.exe" [2009-12-02 210288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-15 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\user\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2009-4-13 3450608]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653]
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2009-10-26 11551744]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImpCnt.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImLc.exe"=
"c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [12/21/2007 7:21 AM 468224]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [10/16/2008 8:27 AM 105984]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.speedbit.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
ActiveSetup-{18AAA5C0-4FCB-11CF-AAX5-81CX1C605612} - c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\isei.exe
AddRemove-AnswerWorks - c:\windows\IsUninst.exe -fc:\program files\WexTech\AnswerWorks\Uninst.isu
AddRemove-Mario Forever Toolbar - c:\windows\Mario_Forever_Toolbar_Uninstaller_906.exe _?=c:\program files\Mario Forever Toolbar
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-12-07 14:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):c3,35,6a,c7,ef,be,e3,b3,44,77,9e,b5,51,d2,e8,01,c4,1d,08,ac,da,
73,e7,95,0e,7b,df,f7,db,55,e2,76,86,96,08,f9,16,9e,e2,39,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{e4456fa3-01ee-45ba-9216-4b7fa49eaba9}]
@Denied: (Full) (Everyone)
"Model"=dword:00000152
"Therad"=dword:00000016
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(1640)
c:\windows\system32\relog_ap.dll
- - - - - - - > 'explorer.exe'(2996)
c:\program files\Stardock\ObjectDock\DockShellHook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\SigmaTel\C-Major Audio\DellXPM_5515v133\WDM\STacSV.exe
c:\program files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\rundll32.exe
c:\progra~1\Magentic\bin\MgApp.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\IncrediMail\bin\IMApp.exe
.
**************************************************************************
.
Completion time: 2009-12-07 14:35 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-07 22:35
Pre-Run: 84,495,872,000 bytes free
Post-Run: 84,933,877,760 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 9EB038A44FE71A2D5412E4BAA6ABB5D5