Hello,
I ran ComboFix again as you instructed. I am posting the log. It did not upload anything, then I went to the location you listed and there was nothing or any zip files for that matter in the folder. I checked and nothing was hidden as well.
I also ran the scannow and it just disappeared. I am assuming it ran. It did not request my installation disk. I hope I completed all required tasks.
ComboFix 09-06-04.04 - Rex 06/05/2009 7:11.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.665 [GMT -4:00]
Running from: c:\documents and settings\Rex\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Rex\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Rex\LOCALS~1\Temp\pdk-Rex-1780\
0fdf6651ec58af7738a5f192a16308f3\WinError.dll
c:\docume~1\Rex\LOCALS~1\Temp\pdk-Rex-1780\1c4c331123ae5269fbd179de68e18722\Socket.dll
c:\docume~1\Rex\LOCALS~1\Temp\pdk-Rex-1780\37dbb36b1afb4153f311e1937d13beb9\Win32.dll
c:\docume~1\Rex\LOCALS~1\Temp\pdk-Rex-1780\463172d63e5c347ebd2a2c9f3e30a769\Cwd.dll
c:\docume~1\Rex\LOCALS~1\Temp\pdk-Rex-1780\4698d6dad1d9192f189448cd2250e41c\Registry.dll
c:\docume~1\Rex\LOCALS~1\Temp\pdk-Rex-1780\4e2f70cf514e42eb8319b6c42723ed06\Dumper.dll
c:\docume~1\Rex\LOCALS~1\Temp\pdk-Rex-1780\b1ef31ab16378a4b392b3d07f25c074a\Service.dll
c:\docume~1\Rex\LOCALS~1\Temp\pdk-Rex-1780\c147fa650a1a0662dceef2f7ea370a7d\List.dll
c:\docume~1\Rex\LOCALS~1\Temp\pdk-Rex-1780\e247dd11d21a2bfdb97ad0cdd295b32d\Encode.dll
c:\docume~1\Rex\LOCALS~1\Temp\pdk-Rex-1780\e51718032942dd5fb4b1590be1ec8d83\Process.dll
c:\docume~1\Rex\LOCALS~1\Temp\pdk-Rex-1780\perl58.dll
c:\documents and settings\Rex\Local Settings\temp\pdk-Rex-1780\
0fdf6651ec58af7738a5f192a16308f3\WinError.dll
c:\documents and settings\Rex\Local Settings\temp\pdk-Rex-1780\1c4c331123ae5269fbd179de68e18722\Socket.dll
c:\documents and settings\Rex\Local Settings\temp\pdk-Rex-1780\37dbb36b1afb4153f311e1937d13beb9\Win32.dll
c:\documents and settings\Rex\Local Settings\temp\pdk-Rex-1780\463172d63e5c347ebd2a2c9f3e30a769\Cwd.dll
c:\documents and settings\Rex\Local Settings\temp\pdk-Rex-1780\4698d6dad1d9192f189448cd2250e41c\Registry.dll
c:\documents and settings\Rex\Local Settings\temp\pdk-Rex-1780\4e2f70cf514e42eb8319b6c42723ed06\Dumper.dll
c:\documents and settings\Rex\Local Settings\temp\pdk-Rex-1780\b1ef31ab16378a4b392b3d07f25c074a\Service.dll
c:\documents and settings\Rex\Local Settings\temp\pdk-Rex-1780\c147fa650a1a0662dceef2f7ea370a7d\List.dll
c:\documents and settings\Rex\Local Settings\temp\pdk-Rex-1780\e247dd11d21a2bfdb97ad0cdd295b32d\Encode.dll
c:\documents and settings\Rex\Local Settings\temp\pdk-Rex-1780\e51718032942dd5fb4b1590be1ec8d83\Process.dll
c:\documents and settings\Rex\Local Settings\temp\pdk-Rex-1780\perl58.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IDRMKL
-------\Service_idrmkl
-------\Service_jqgpjnb
((((((((((((((((((((((((( Files Created from 2009-05-05 to 2009-06-05 )))))))))))))))))))))))))))))))
.
2009-05-28 02:55 . 2009-05-28 02:53 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-05-27 23:44 . 2009-05-28 02:56 -------- d-----w- c:\documents and settings\Rex\.housecall6.6
2009-05-27 22:56 . 2007-01-18 12:00 3968 ----a-w- c:\windows\system32\drivers\AvgArCln.sys
2009-05-26 10:46 . 2009-05-26 10:46 390664 ----a-w- c:\documents and settings\Terri\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-20 03:37 . 2009-05-20 03:37 -------- d-----w- c:\documents and settings\Terri\Application Data\Yahoo! Companion
2009-05-20 03:36 . 2009-05-20 03:36 -------- d-----w- c:\documents and settings\Terri\Application Data\Malwarebytes
2009-05-20 02:51 . 2009-05-20 02:51 -------- d-----w- c:\program files\Trend Micro
2009-05-20 01:24 . 2009-05-20 01:24 -------- d-----w- C:\Malwarebytes
2009-05-20 01:23 . 2009-05-20 01:23 -------- d-----w- c:\documents and settings\Rex\Application Data\Yahoo! Companion
2009-05-19 19:46 . 2009-05-19 19:46 -------- d-----w- c:\documents and settings\Megan\Application Data\Yahoo! Companion
2009-05-10 15:18 . 2009-05-10 15:18 -------- d-sh--w- C:\found.001
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-25 20:03 . 2008-08-08 01:58 -------- d-----w- c:\program files\Windows Media Connect 2
2009-05-20 01:33 . 2008-12-29 22:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-05-09 02:25 . 2009-02-02 20:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-09 02:25 . 2008-08-07 02:11 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-09 02:25 . 2008-08-07 02:11 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-04-28 21:22 . 2009-04-28 21:22 -------- d-----w- c:\program files\CCleaner
2009-04-15 22:46 . 2009-02-27 21:37 34 ----a-w- c:\documents and settings\Ryan\jagex_runescape_preferences.dat
2009-04-06 19:32 . 2008-12-29 22:36 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 19:32 . 2008-12-29 22:36 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-04-05 01:28 . 2009-04-04 13:21 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
.
------- Sigcheck -------
[-] 2008-04-23 03:35 827392 41546B396A526918DA7995A02EA04E51 c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
[-] 2008-06-23 16:01 827904 C66402A06B83B036C195242C0C8CF83C c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
[-] 2008-08-26 09:08 827904 77C192FE56A70D7FA0247BA0A6201C32 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
[-] 2008-10-16 20:24 827904 0D5B75171FF51775B630A431B6C667E8 c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
[-] 2008-12-20 23:56 827904 044E0A4E9FE97C0FB9AFE9C89E2A82E6 c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll
[-] 2009-03-03 00:17 828416 C8667854873938CA13C986F16B0CD183 c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\wininet.dll
[-] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[-] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[-] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys
[-] 2007-07-27 12:00 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB951748_0$\tcpip.sys
[-] 2009-02-06 10:30 2066176 607352B9CB3D708C67F6039097801B5A c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[-] 2008-08-14 19:39 2066048 A25E9B86EFFB2AF33BF51E676B68BFB0 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
[-] 2008-08-14 09:33 2066048 4AC58F03EB94A72809949D757FC39D80 c:\windows\$NtUninstallKB956572$\ntkrnlpa.exe
[-] 2008-04-13 18:31 2065792 109F8E3E3C82E337BB71B6BC9B895D61 c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
[-] 2009-02-07 23:35 2189184 EFE8EACE83EAAD5849A7A548FB75B584 c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
[-] 2008-08-14 20:11 2189184 31914172342BFF330063F343AC6958FE c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
[-] 2008-08-14 10:11 2189184 EEAF32F8E15A24F62BECB1BD403BB5C5 c:\windows\$NtUninstallKB956572$\ntoskrnl.exe
[-] 2008-04-13 19:27 2188928 0C89243C7C3EE199B96FCC16990E0679 c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
[-] 2009-02-06 11:06 110592 020CEAAEDC8EB655B6506B8C70D53BB6 c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe
[-] 2008-04-14 00:12 108544 0E776ED5F7CC9F94299E70461B7B8185 c:\windows\$NtUninstallKB956572$\services.exe
[-] 2009-03-21 13:59 991744 DA11D9D6ECBDF0F93436A4B7C13F7BEC c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
[-] 2008-04-14 00:11 989696 C24B983D211C34DA8FCC1AC38477971D c:\windows\$NtUninstallKB959426$\kernel32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-05-04 149040]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-07 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-05-04 161328]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-07 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-03 1630208]
c:\documents and settings\Terri\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
SqueezeCenter Tray Tool.lnk - c:\program files\SqueezeCenter\SqueezeTray.exe [2008-8-7 1728601]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-09 02:25 11952 ----a-w- c:\windows\system32\avgrsstx.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9000:TCP"= 9000:TCP:SqueezeCenter 9000 tcp (UI)
"3483:UDP"= 3483:UDP:SqueezeCenter 3483 udp
"3483:TCP"= 3483:TCP:SqueezeCenter 3483 tcp
"9090:TCP"= 9090:TCP:SqueezeCenter 9090 tcp (CLI)
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/6/2008 10:11 PM 325896]
S0 cojf;cojf;c:\windows\system32\drivers\krfc.sys --> c:\windows\system32\drivers\krfc.sys [?]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2/2/2009 4:21 PM 298776]
S2 gupdate1c9661c52fd4afe;Google Update Service (gupdate1c9661c52fd4afe);c:\program files\Google\Update\GoogleUpdate.exe [12/24/2008 7:06 PM 133104]
S2 SqueezeMySQL;SqueezeMySQL;c:\progra~1\SQUEEZ~1\server\Bin\MSWIN3~1\mysqld.exe --defaults-file=c:\docume~1\ALLUSE~1\APPLIC~1\SQUEEZ~1\Cache\my.cnf SqueezeMySQL --> c:\progra~1\SQUEEZ~1\server\Bin\MSWIN3~1\mysqld.exe --defaults-file=c:\docume~1\ALLUSE~1\APPLIC~1\SQUEEZ~1\Cache\my.cnf SqueezeMySQL [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-05-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 21:57]
2009-06-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-07 18:56]
2009-06-05 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-24 14:08]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: Web-Based Email Tools - hxxp://email.secureserver.net/Download.CAB
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-05 07:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\Nalu_1024x768.jpg 586602 bytes
c:\windows\Nalu_1162x864.jpg 721491 bytes
c:\windows\Nalu_1920x1440.jpg 1589587 bytes
c:\windows\Nalu_800x600.jpg 403524 bytes
c:\windows\NeroDigital.ini 69 bytes
c:\windows\network diagnostic
c:\windows\NIRCMD.exe 31232 bytes executable
c:\windows\notepad.exe 69120 bytes executable
c:\windows\SHELLNEW
c:\windows\SIERRA.INI 415 bytes
c:\windows\slrundll.exe 32866 bytes executable
c:\windows\snymsico.dll 90112 bytes executable
c:\windows\Soap Bubbles.bmp 65978 bytes
c:\windows\SoftwareDistribution
c:\windows\soundman.exe 577536 bytes executable
c:\windows\srchasst
c:\windows\Sti_Trace.log 0 bytes
c:\windows\Sun
c:\windows\SWREG.exe 161792 bytes executable
c:\windows\SWSC.exe 136704 bytes executable
c:\windows\SWXCACLS.exe 212480 bytes executable
c:\windows\system.ini 261 bytes
c:\windows\system32
c:\windows\TASKMAN.EXE 15360 bytes executable
c:\windows\Tasks
c:\windows\temp
c:\windows\twain.dll 94784 bytes
c:\windows\twain_32
c:\windows\twain_32.dll 50688 bytes executable
c:\windows\twunk_16.exe 49680 bytes
c:\windows\Favorites
c:\windows\FeatherTexture.bmp 16730 bytes
c:\windows\Fonts
c:\windows\Gone Fishing.bmp 17336 bytes
c:\windows\Greenstone.bmp 26582 bytes
c:\windows\grep.exe 80412 bytes executable
c:\windows\hegames.ini 421 bytes
c:\windows\Help
c:\windows\hh.exe 10752 bytes executable
c:\windows\ie7
c:\windows\ie7updates
c:\windows\ime
c:\windows\inf
c:\windows\Installer
c:\windows\uninst.exe 298496 bytes executable
c:\windows\UNNeroMediaHome.cfg 50 bytes
c:\windows\UNNeroMediaHome.exe 972336 bytes executable
c:\windows\UNNeroShowTime.cfg 50 bytes
c:\windows\UNNeroShowTime.exe 972336 bytes executable
c:\windows\UNNeroVision.cfg 50 bytes
c:\windows\UNNeroVision.exe 972336 bytes executable
c:\windows\UNRecode.cfg 50 bytes
c:\windows\UNRecode.exe 972336 bytes executable
c:\windows\vb.ini 36 bytes
c:\windows\vbaddin.ini 37 bytes
c:\windows\VertoFire1024x768.jpg 462828 bytes
c:\windows\VertoFire1152x864.jpg 546603 bytes
c:\windows\VertoFire800x600.jpg 330881 bytes
c:\windows\vmmreg32.dll 18944 bytes executable
c:\windows\vnDrvBas
c:\windows\vulcan_1024x768.jpg 136105 bytes
c:\windows\Resources
c:\windows\Rhododendron.bmp 17362 bytes
c:\windows\River Sumida.bmp 26680 bytes
c:\windows\RtlRack.ini 169 bytes
c:\windows\Santa Fe Stucco.bmp 65832 bytes
c:\windows\SchedLgU.Txt 32572 bytes
c:\windows\security
c:\windows\sed.exe 98816 bytes executable
c:\windows\ServicePackFiles
c:\windows\clock.avi 82944 bytes
c:\windows\explorer.scf 80 bytes
c:\windows\java
c:\windows\mui
c:\windows\nview
c:\windows\repair
c:\windows\setupapi.old
c:\windows\twunk_32.exe 25600 bytes executable
c:\windows\Coffee Bean.bmp 17062 bytes
c:\windows\Config
c:\windows\Connection Wizard
c:\windows\control.ini 0 bytes
c:\windows\Cursors
c:\windows\Dawn_1024x768.jpg 79737 bytes
c:\windows\Debug
c:\windows\Desktop
c:\windows\desktop.ini 2 bytes
c:\windows\Downloaded Program Files
c:\windows\Driver Cache
c:\windows\Dusk_1024x768.jpg 128539 bytes
c:\windows\ehome
c:\windows\ERDNT
c:\windows\explorer.exe 1033728 bytes executable
c:\windows\WBEM
c:\windows\Web
c:\windows\wiadebug.log 159 bytes
c:\windows\wiaservc.log 48 bytes
c:\windows\win.ini 582 bytes
c:\windows\WindowsUpdate.log 2076182 bytes
c:\windows\winhelp.exe 256192 bytes
c:\windows\winhlp32.exe 283648 bytes executable
c:\windows\winnt.bmp 48680 bytes
c:\windows\winnt256.bmp 48680 bytes
c:\windows\WinSxS
c:\windows\WMSysPr9.prx 316640 bytes
c:\windows\Zapotec.bmp 9522 bytes
c:\windows\zip.exe 68096 bytes executable
c:\windows\_default.pif 707 bytes
c:\windows\bootstat.dat 2048 bytes
c:\windows\cdplayer.ini 50 bytes
c:\windows\ODBCINST.INI
c:\windows\Offline Web Pages
c:\windows\pchealth
c:\windows\PeerNet
c:\windows\PEV.exe 154624 bytes executable
c:\windows\PhotoSnapViewer.INI 151 bytes
c:\windows\Prairie Wind.bmp 65954 bytes
c:\windows\Prefetch
c:\windows\Provisioning
c:\windows\pss
c:\windows\regedit.exe 146432 bytes executable
c:\windows\RegisteredPackages
c:\windows\Registration
c:\windows\REGLOCS.OLD 8192 bytes
c:\windows\IsUninst.exe 306688 bytes executable
c:\windows\l2schemas
c:\windows\Media
c:\windows\msagent
c:\windows\msapps
c:\windows\msdfmap.ini 1405 bytes
c:\windows\msdownld.tmp
scan completed successfully
hidden files: 131
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2036)
c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\windows\soundman.exe
.
**************************************************************************
.
Completion time: 2009-06-05 7:18 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-05 11:18
ComboFix2.txt 2009-06-04 23:30
ComboFix3.txt 2009-05-28 02:18
Pre-Run: 123,287,879,680 bytes free
Post-Run: 123,212,783,616 bytes free
324 --- E O F --- 2009-05-13 22:33