sorry mate ihave been working away the last week so havent been able to get onto the computer but any way heres my logs
Malwarebytes' Anti-Malware 1.28 Database version: 1226 Windows 6.0.6000
4/10/2008 12:48:11 PM mbam-log-2008-10-04 (12-48-11).txt
Scan type: Full Scan (C:\|D:\|) Objects scanned: 126798 Time elapsed: 1 hour(s), 39 minute(s), 42 second(s)
Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 37 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 13
Memory Processes Infected: (No malicious items detected)
Memory Modules Infected: (No malicious items detected)
Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\MicroAV (Rogue.MicroAntivirus) -> Quarantined and deleted successfully.
Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur74e1.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur75da.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur7944.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur7b95.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurfaa3.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur74e1.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur75da.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur7944.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur7b95.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurfaa3.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur21e1.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur223f.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur21f1.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurd69f.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurc88c.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurdd24.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yure0cc.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurdbdd.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurf65f.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur8a64.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur8a63.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yuraafd.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurd577.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur9c0.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur7982.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur91d3.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur7a3d.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurd9f9.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurf881.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurba81.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur8f69.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yureb86.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yureb87.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurf546.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yuredf6.exe (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur68df.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected: (No malicious items detected)
Folders Infected: C:\Program Files\MicroAV (Rogue.MicroAntivirus) -> Quarantined and deleted successfully.
Files Infected: C:\Program Files\MicroAV\MicroAV.cpl (Rogue.MicroAntivirus) -> Quarantined and deleted successfully. C:\Windows\System32\1.ico (Malware.Trace) -> Quarantined and deleted successfully. C:\Windows\System32\2.ico (Malware.Trace) -> Quarantined and deleted successfully. C:\Windows\System32\YUR74E1.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\System32\YUR75DA.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\System32\YUR7944.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\System32\YUR7B95.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\System32\YURFAA3.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\System32\urQjHwxu.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Windows\System32\awTLccCT.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Windows\System32\hggfgEuR.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Windows\System32\MicroAV.cpl (Rogue.MicroAntivirus) -> Quarantined and deleted successfully. C:\Users\user\Desktop\Micro Antivirus 2009.lnk (Rogue.XPertAntivirus) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2:00:07 PM, on 4/10/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16711) Boot mode: Normal
Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Program Files\Toshiba\ConfigFree\NDSTray.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\ltmoh\ltmoh.exe C:\Program Files\Toshiba\Power Saver\TPwrMain.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE C:\Program Files\Toshiba\SmoothView\SmoothView.exe C:\Program Files\Toshiba\FlashCards\TCrdMain.exe C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe C:\Program Files\Protector Suite QL\psqltray.exe C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe C:\Program Files\Synaptics\SynTP\SynToshiba.exe C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe C:\Windows\system32\wuauclt.exe C:\Windows\Explorer.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEUser.exe C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\Dependent\HSChkProxyExe.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O2 - BHO: TSToolbarBHO - {C1656CCA-D2EA-4A32-94AE-AE0B180E6449} - C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\TSToolbar.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Transaction Protector - {E7620C98-FCCC-40E5-92EC-C7685D2E1E40} - C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\TSToolbar.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [RegKillElbyCheck] "C:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe" /L RegKill O4 - HKLM\..\Run: [RegKillTray] "C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe" O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [pep] c:\WINDOWS\system32\pep.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Global Startup: Bluetooth Manager.lnk = ? O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspxO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O13 - Gopher Prefix: O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
-- End of file - 10390 bytes
ComboFix 08-10-04.07 - user 2008-10-05 11:52:10.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.274 [GMT 8:00] Running from: C:\Users\user\Desktop\FIX\ComboFix.exe * Created a new restore point .
((((((((((((((((((((((((( Files Created from 2008-09-05 to 2008-10-05 ))))))))))))))))))))))))))))))) .
No new files created in this timespan
. (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-10-04 21:17 --------- d-----w C:\Program Files\Spyware Doctor 2008-10-04 21:17 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware 2008-10-04 21:17 --------- d-----w C:\Program Files\CCleaner 2008-10-04 05:28 --------- d-----w C:\ProgramData\Yahoo! Companion 2008-10-04 04:56 --------- d---a-w C:\ProgramData\TEMP 2008-10-03 07:24 --------- d-----w C:\Program Files\Yahoo! 2008-10-02 14:24 --------- d-----w C:\Users\user\AppData\Roaming\Malwarebytes 2008-10-02 14:24 --------- d-----w C:\ProgramData\Malwarebytes 2008-10-02 11:51 --------- d-----w C:\Program Files\Trend Micro 2008-10-01 15:18 --------- d-----w C:\Users\user\AppData\Roaming\uTorrent 2008-10-01 13:33 --------- d-----w C:\Users\user\AppData\Roaming\PC Tools 2008-10-01 12:51 --------- d-----w C:\ProgramData\Trend Micro 2008-09-27 02:12 --------- d-----w C:\Program Files\Xvid 2008-09-25 07:16 --------- d-----w C:\Program Files\Google 2008-09-20 05:25 41,763 ----a-w C:\Windows\System32\pep.exe 2008-09-10 11:39 --------- d-----w C:\ProgramData\Microsoft Help 2008-09-09 16:04 38,528 ----a-w C:\Windows\system32\drivers\mbamswissarmy.sys 2008-09-09 16:03 17,200 ----a-w C:\Windows\system32\drivers\mbam.sys 2008-09-06 12:00 --------- d-----w C:\Users\user\AppData\Roaming\toshiba 2008-09-06 10:35 --------- d-----w C:\Users\user\AppData\Roaming\Intel 2008-09-05 03:45 --------- d--h--w C:\ProgramData\CanonBJ 2008-09-03 01:52 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-09-03 01:52 --------- d-----w C:\Program Files\Game Copy Pro 2008-09-02 17:04 268,800 ----a-w C:\Windows\System32\es.dll 2008-09-01 17:53 174 --sha-w C:\Program Files\desktop.ini 2008-09-01 17:48 --------- d-----w C:\Program Files\Windows Sidebar 2008-09-01 17:48 --------- d-----w C:\Program Files\Windows Mail 2008-09-01 17:48 --------- d-----w C:\Program Files\Windows Defender 2008-09-01 17:48 --------- d-----w C:\Program Files\Windows Calendar 2008-09-01 17:37 87,040 ----a-w C:\Windows\System32\msoert2.dll 2008-09-01 17:37 39,424 ----a-w C:\Windows\System32\ACCTRES.dll 2008-09-01 17:37 205,824 ----a-w C:\Windows\System32\msoeacct.dll 2008-09-01 17:35 194,560 ----a-w C:\Windows\System32\WebClnt.dll 2008-09-01 17:35 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys 2008-09-01 17:31 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys 2008-09-01 17:31 2,048 ----a-w C:\Windows\System32\tzres.dll 2008-09-01 17:31 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys 2008-09-01 17:30 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll 2008-09-01 17:29 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL 2008-09-01 17:29 7,680 ----a-w C:\Windows\System32\spwmp.dll 2008-09-01 17:29 4,096 ----a-w C:\Windows\System32\dxmasf.dll 2008-09-01 17:29 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll 2008-09-01 17:28 86,016 ----a-w C:\Windows\System32\icfupgd.dll 2008-09-01 17:28 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys 2008-09-01 17:28 61,952 ----a-w C:\Windows\System32\cmifw.dll 2008-09-01 17:28 396,800 ----a-w C:\Windows\System32\MPSSVC.dll 2008-09-01 17:28 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll 2008-09-01 17:28 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys 2008-09-01 17:28 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll 2008-09-01 17:28 16,896 ----a-w C:\Windows\System32\wfapigp.dll 2008-09-01 17:28 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS 2008-09-01 17:26 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys 2008-09-01 17:26 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe 2008-09-01 17:26 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe 2008-09-01 17:26 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys 2008-09-01 17:26 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys 2008-09-01 17:26 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys 2008-09-01 17:26 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys 2008-09-01 17:26 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys 2008-09-01 17:25 2,048 ----a-w C:\Windows\System32\msxml3r.dll 2008-09-01 17:25 1,191,936 ----a-w C:\Windows\System32\msxml3.dll 2008-09-01 17:23 797,696 ----a-w C:\Windows\System32\NaturalLanguage6.dll 2008-09-01 17:23 6,917,120 ----a-w C:\Windows\System32\NlsLexicons0c1a.dll 2008-09-01 17:23 4,493,312 ----a-w C:\Windows\System32\NlsData0816.dll 2008-09-01 17:23 4,493,312 ----a-w C:\Windows\System32\NlsData0416.dll 2008-09-01 17:23 4,493,312 ----a-w C:\Windows\System32\NlsData0414.dll 2008-09-01 17:23 1,963,520 ----a-w C:\Windows\System32\NlsData0c1a.dll 2008-09-01 17:23 1,963,520 ----a-w C:\Windows\System32\NlsData081a.dll 2008-09-01 17:23 1,963,520 ----a-w C:\Windows\System32\NlsData000f.dll 2008-09-01 17:20 826,368 ----a-w C:\Windows\System32\wininet.dll 2008-09-01 17:20 56,320 ----a-w C:\Windows\System32\iesetup.dll 2008-09-01 17:20 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll 2008-09-01 17:20 26,624 ----a-w C:\Windows\System32\ieUnatt.exe 2008-09-01 17:18 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll 2008-09-01 17:18 595,456 ----a-w C:\Windows\System32\schedsvc.dll 2008-09-01 17:18 54,784 ----a-w C:\Windows\system32\drivers\i8042prt.sys 2008-09-01 17:18 495,160 ----a-w C:\Windows\system32\drivers\Wdf01000.sys 2008-09-01 17:18 35,384 ----a-w C:\Windows\system32\drivers\WdfLdr.sys 2008-09-01 17:18 35,384 ----a-w C:\Windows\system32\drivers\kbdclass.sys 2008-09-01 17:18 35,328 ----a-w C:\Windows\System32\dispci.dll 2008-09-01 17:18 34,360 ----a-w C:\Windows\system32\drivers\mouclass.sys 2008-09-01 17:18 19,968 ----a-w C:\Windows\system32\drivers\sermouse.sys 2008-09-01 17:18 12,800 ----a-w C:\Windows\System32\batt.dll 2008-09-01 17:16 82,432 ----a-w C:\Windows\system32\drivers\sdbus.sys 2008-09-01 17:16 13,312 ----a-w C:\Windows\system32\drivers\sffdisk.sys 2008-09-01 17:16 12,800 ----a-w C:\Windows\system32\drivers\sffp_sd.sys 2008-09-01 17:15 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL 2008-09-01 17:15 296,448 ----a-w C:\Windows\System32\gdi32.dll 2008-09-01 17:15 223,232 ----a-w C:\Windows\System32\WMASF.DLL 2008-09-01 17:15 2,048 ----a-w C:\Windows\System32\asferror.dll 2008-09-01 17:15 2,027,008 ----a-w C:\Windows\System32\win32k.sys 2008-09-01 17:14 57,856 ----a-w C:\Windows\System32\SLUINotify.dll 2008-09-01 17:14 566,784 ----a-w C:\Windows\System32\SLCommDlg.dll 2008-09-01 17:14 39,936 ----a-w C:\Windows\System32\slcinst.dll 2008-09-01 17:14 351,232 ----a-w C:\Windows\System32\SLUI.exe 2008-09-01 17:14 33,280 ----a-w C:\Windows\System32\slwmi.dll 2008-09-01 17:14 268,288 ----a-w C:\Windows\System32\mcbuilder.exe 2008-09-01 17:14 223,232 ----a-w C:\Windows\System32\SLC.dll 2008-09-01 17:14 2,605,568 ----a-w C:\Windows\System32\SLsvc.exe 2008-09-01 17:14 186,368 ----a-w C:\Windows\System32\SLLUA.exe .
((((((((((((((((((((((((((((( snapshot@2008-10-04_13.52.38.79 ))))))))))))))))))))))))))))))))))))))))) . + 2008-10-05 03:57:44 229,264 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat - 2008-10-04 05:45:10 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2008-10-05 03:58:48 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2008-10-04 05:45:10 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2008-10-05 03:58:48 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2008-10-04 05:46:33 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat + 2008-10-05 04:00:09 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat - 2008-10-04 05:46:33 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat + 2008-10-05 04:00:09 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat + 2008-10-05 04:00:09 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 - 2008-10-04 21:17:37 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat + 2008-10-05 03:52:05 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat - 2008-10-04 05:24:00 108,526 ----a-w C:\Windows\System32\perfc009.dat + 2008-10-04 05:52:05 108,526 ----a-w C:\Windows\System32\perfc009.dat - 2008-10-04 05:24:00 623,342 ----a-w C:\Windows\System32\perfh009.dat + 2008-10-04 05:52:05 623,342 ----a-w C:\Windows\System32\perfh009.dat - 2008-10-04 01:51:46 2,580 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat + 2008-10-05 03:57:45 2,580 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay] @="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}" [HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}] 2006-12-03 14:03 2854912 --a------ C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen] @="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}" [HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}] 2006-12-03 14:03 2854912 --a------ C:\Program Files\Protector Suite QL\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-09-02 1232896] "TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2007-04-21 430080] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 1688872] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728] "pep"="c:\WINDOWS\system32\pep.exe" [2008-09-20 41763] "WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 C:\Windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-05-04 865840] "LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2007-01-09 191552] "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112] "PSQLLauncher"="C:\Program Files\Protector Suite QL\launcher.exe" [2006-12-03 49168] "TPwrMain"="C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192] "HSON"="C:\Program Files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416] "SmoothView"="C:\Program Files\Toshiba\SmoothView\SmoothView.exe" [2007-03-22 448632] "00TCrdMain"="C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744] "Camera Assistant Software"="C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" [2007-04-10 413696] "NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136] "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 2213160] "RegKillElbyCheck"="C:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe" [2001-12-06 45056] "RegKillTray"="C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe" [2002-04-13 49152] "UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1398024] "Malwarebytes Anti-Malware (reboot)"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [2008-09-10 1253040] "NDSTray.exe"="NDSTray.exe" [BU] "RtHDVCpl"="RtHDVCpl.exe" [2007-04-25 C:\Windows\RtHDVCpl.exe]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-02-28 2756608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "DisableCAD"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus] 2006-12-03 13:50 90112 C:\Windows\System32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\vio\dvacm.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKEY_LOCAL_MACHINE\software\microsoft\security center] "AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall] "DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile] "EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{419DE1E0-7C13-44A4-BB85-4BCFB09A0A25}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{7D7598DB-B0D4-4346-A058-EF4FC759A326}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In) "{558C1303-C8CE-4C07-A5D7-5F0D049C273D}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In) "{D37030FB-9235-400E-8BB9-7C3E5D2086F5}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "TCP Query User{4FDE5902-FDB3-4077-BA7F-3F8D64236AFA}C:\\program files\\nero\\nero8\\nero showtime\\showtime.exe"= UDP:C:\program files\nero\nero8\nero showtime\showtime.exe:Nero ShowTime "UDP Query User{AC15CF09-D86A-4157-BF05-18F820345B19}C:\\program files\\nero\\nero8\\nero showtime\\showtime.exe"= TCP:C:\program files\nero\nero8\nero showtime\showtime.exe:Nero ShowTime "{407DDAF4-7E8D-4074-9612-7A6378C33F80}"= UDP:C:\Windows\System32\mpxa.exe:mpxa "{92A4D702-E4A2-4384-BE1A-0C81AE0E20C3}"= TCP:C:\Windows\System32\mpxa.exe:mpxa
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System] "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0)
R1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;C:\Windows\system32\DRIVERS\tmlwf.sys [2008-02-15 141840] R2 tmwfp;Trend Micro WFP Callout Driver;C:\Windows\system32\DRIVERS\tmwfp.sys [2008-02-15 234512] R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-05-16 2602496] R3 FwLnk;FwLnk Driver;C:\Windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168] R3 RegKill;RegKill;C:\Windows\system32\Drivers\RegKill.sys [2002-03-10 6144] R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-01-10 221696] . Contents of the 'Scheduled Tasks' folder
2008-09-01 C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 09:20] . . ------- Supplementary Scan ------- . O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 -: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspxO8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 .
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2008-10-05 12:01:13 Windows 6.0.6000 NTFS
scanning hidden processes ...
C:\Windows\System32\dllhost.exe [2484] 0x847861E8
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe C:\Windows\System32\Ati2evxx.exe C:\Windows\System32\audiodg.exe C:\Windows\System32\Ati2evxx.exe C:\Windows\System32\wlanext.exe C:\Program Files\Protector Suite QL\upeksvr.exe C:\Windows\System32\agrsmsvc.exe C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe C:\Windows\System32\TODDSrv.exe C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Program Files\Trend Micro\BM\TMBMSRV.exe C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe C:\Program Files\Trend Micro\Internet Security\TmProxy.exe C:\Program Files\Toshiba\ConfigFree\NDSTray.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Protector Suite QL\psqltray.exe C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Synaptics\SynTP\SynToshiba.exe C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe . ************************************************************************** . Completion time: 2008-10-05 12:08:13 - machine was rebooted ComboFix-quarantined-files.txt 2008-10-05 04:07:52 ComboFix2.txt 2008-10-04 05:54:14
Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application. Post-Run: 18,429,714,432 bytes free
280 --- E O F --- 2008-09-26 09:19:55
thank you for your help so far
|