aswMBR version 0.9.8.986 Copyright(c) 2011 AVAST Software
Run date: 2011-08-27 11:05:44
-----------------------------
11:05:44.842 OS Version: Windows 6.0.6002 Service Pack 2
11:05:44.842 Number of processors: 2 586 0xF06
11:05:44.842 ComputerName: SHELDON-PC UserName: Sheldon
11:05:48.805 Initialize success
11:08:49.179 AVAST engine defs: 11082700
11:09:20.067 Disk 0 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T1L0-7
11:09:20.067 Disk 0 Vendor: ST3320620AS 3.AAK Size: 305245MB BusType: 3
11:09:20.082 Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T0L0-0
11:09:20.082 Disk 1 Vendor: ST3320620AS 3.AAK Size: 305245MB BusType: 3
11:09:22.095 Disk 1 MBR read successfully
11:09:22.095 Disk 1 MBR scan
11:09:22.110 Disk 1 Windows VISTA default MBR code
11:09:22.110 Disk 1 scanning sectors +625139712
11:09:22.204 Disk 1 scanning C:\Windows\system32\drivers
11:09:41.657 Service scanning
11:09:42.874 Service sptd C:\Windows\System32\Drivers\sptd.sys **LOCKED** 32
11:09:43.701 Modules scanning
11:09:49.847 Disk 1 trace - called modules:
11:09:49.863 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x84d2c1f8]<<
11:09:49.863 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0x861ac260]
11:09:49.863 3 CLASSPNP.SYS[8a9ca8b3] -> nt!IofCallDriver -> [0x857abf08]
11:09:49.878 5 acpi.sys[807c16bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85759528]
11:09:49.878 \Driver\atapi[0x85797030] -> IRP_MJ_CREATE -> 0x84d2c1f8
11:09:51.423 AVAST engine scan C:\Windows
11:09:56.727 AVAST engine scan C:\Windows\system32
11:12:08.578 File: C:\Windows\system32\offfilt32.exe **INFECTED** Win32:Tracur-DG [Trj]
11:13:17.124 AVAST engine scan C:\Windows\system32\drivers
11:13:33.972 AVAST engine scan C:\Users\Sheldon
11:26:14.871 Disk 1 MBR has been saved successfully to "C:\Users\Sheldon\Desktop\MBR.dat"
11:26:14.879 The log file has been saved successfully to "C:\Users\Sheldon\Desktop\aswMBR.txt"
ComboFix 11-08-27.01 - Sheldon 08/27/2011 11:30:29.1.2 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3006.1401 [GMT -4:00]
Running from: c:\users\Sheldon\Desktop\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
FW: Norton 360 *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
SP: Norton 360 *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\appinfo32.dll
c:\programdata\cngaudit32.exe
c:\users\Sheldon\AppData\Roaming\Mozilla\Firefox\Profiles\c1woehdc.default\extensions\{2b9d4a59-ce75-4148-9429-3be048dc35e9}
c:\users\Sheldon\AppData\Roaming\Mozilla\Firefox\Profiles\c1woehdc.default\extensions\{2b9d4a59-ce75-4148-9429-3be048dc35e9}\chrome.manifest
c:\users\Sheldon\AppData\Roaming\Mozilla\Firefox\Profiles\c1woehdc.default\extensions\{2b9d4a59-ce75-4148-9429-3be048dc35e9}\chrome\xulcache.jar
c:\users\Sheldon\AppData\Roaming\Mozilla\Firefox\Profiles\c1woehdc.default\extensions\{2b9d4a59-ce75-4148-9429-3be048dc35e9}\defaults\preferences\xulcache.js
c:\users\Sheldon\AppData\Roaming\Mozilla\Firefox\Profiles\c1woehdc.default\extensions\{2b9d4a59-ce75-4148-9429-3be048dc35e9}\install.rdf
c:\users\Sheldon\AppData\Roaming\Mozilla\Firefox\Profiles\c1woehdc.default\extensions\{601f956a-d34a-4235-b6bd-ce27d41eb4d1}
c:\users\Sheldon\AppData\Roaming\Mozilla\Firefox\Profiles\c1woehdc.default\extensions\{601f956a-d34a-4235-b6bd-ce27d41eb4d1}\chrome.manifest
c:\users\Sheldon\AppData\Roaming\Mozilla\Firefox\Profiles\c1woehdc.default\extensions\{601f956a-d34a-4235-b6bd-ce27d41eb4d1}\chrome\xulcache.jar
c:\users\Sheldon\AppData\Roaming\Mozilla\Firefox\Profiles\c1woehdc.default\extensions\{601f956a-d34a-4235-b6bd-ce27d41eb4d1}\defaults\preferences\xulcache.js
c:\users\Sheldon\AppData\Roaming\Mozilla\Firefox\Profiles\c1woehdc.default\extensions\{601f956a-d34a-4235-b6bd-ce27d41eb4d1}\install.rdf
c:\users\Sheldon\g2mdlhlpx.exe
c:\users\Sheldon\GoToAssistDownloadHelper.exe
c:\users\Sheldon\WINDOWS
c:\windows\MailSwitch.ocx
c:\windows\system32\comct332.ocx
c:\windows\system32\offfilt32.exe
F:\install.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_ehSched32
.
.
((((((((((((((((((((((((( Files Created from 2011-07-27 to 2011-08-27 )))))))))))))))))))))))))))))))
.
.
2011-08-27 15:43 . 2011-08-27 15:43 270336 ----a-w- c:\programdata\CNQI480432.dll
2011-08-27 15:40 . 2011-08-27 15:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-27 15:39 . 2011-08-16 22:02 1208832 ----a-w- c:\programdata\appinfo32.exe
2011-08-25 20:51 . 2011-08-25 20:51 -------- d-----w- c:\users\Sheldon\AppData\Roaming\Malwarebytes
2011-08-25 20:51 . 2011-07-06 23:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-25 20:51 . 2011-08-25 20:51 -------- d-----w- c:\programdata\Malwarebytes
2011-08-25 20:51 . 2011-08-25 20:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-25 20:51 . 2011-07-06 23:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-25 12:18 . 2011-08-25 12:18 -------- d-----w- c:\users\Sheldon\AppData\Roaming\Sammsoft
2011-08-25 12:18 . 2011-08-25 12:18 -------- d-----w- c:\program files\ARO 2011
2011-08-24 04:48 . 2011-07-11 13:25 2048 ----a-w- c:\windows\system32\tzres.dll
2011-08-17 17:14 . 2011-08-17 17:14 0 ---ha-w- c:\windows\keslmyjgtf.tmp
2011-08-11 07:11 . 2011-07-22 02:44 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-08-11 07:10 . 2011-07-22 03:00 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-08-11 07:10 . 2011-07-22 02:46 194048 ----a-w- c:\program files\Internet Explorer\IEShims.dll
2011-08-11 07:10 . 2011-07-22 02:54 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-08-11 07:10 . 2011-07-22 02:48 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-08-10 13:25 . 2011-07-06 15:31 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-08-10 13:25 . 2011-06-06 10:59 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-08-10 13:25 . 2011-06-20 08:54 3602832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-08-10 13:25 . 2011-06-20 08:54 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-08-10 13:25 . 2011-06-17 20:13 905104 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-28 10:27 . 2011-07-28 10:27 121464 ----a-w- c:\windows\system32\drivers\AnyDVD.sys
2011-07-21 18:53 . 2011-06-11 14:50 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-29 12:06 . 2011-06-29 12:06 161792 ----a-w- c:\windows\system32\msls31.dll
2011-06-29 12:06 . 2011-06-29 12:06 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-06-29 12:06 . 2011-06-29 12:06 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-06-29 12:06 . 2011-06-29 12:06 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-06-29 12:06 . 2011-06-29 12:06 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-06-29 12:06 . 2011-06-29 12:06 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-06-29 12:06 . 2011-06-29 12:06 367104 ----a-w- c:\windows\system32\html.iec
2011-06-29 12:06 . 2011-06-29 12:06 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-06-29 12:06 . 2011-06-29 12:06 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-29 12:06 . 2011-06-29 12:06 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-29 12:06 . 2011-06-29 12:06 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-06-29 12:06 . 2011-06-29 12:06 152064 ----a-w- c:\windows\system32\wextract.exe
2011-06-29 12:06 . 2011-06-29 12:06 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-06-29 12:06 . 2011-06-29 12:06 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-06-29 12:06 . 2011-06-29 12:06 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-06-29 12:06 . 2011-06-29 12:06 11776 ----a-w- c:\windows\system32\mshta.exe
2011-06-29 12:06 . 2011-06-29 12:06 101888 ----a-w- c:\windows\system32\admparse.dll
2011-06-29 12:06 . 2011-06-29 12:06 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-06-17 16:03 . 2011-08-10 13:25 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-06-06 19:55 . 2011-06-06 19:55 47512 ----a-w- c:\windows\system32\AdobePDF.dll
2011-06-06 19:55 . 2011-06-06 19:55 22936 ----a-w- c:\windows\system32\AdobePDFUI.dll
2011-06-02 13:34 . 2011-07-13 07:38 2043392 ----a-w- c:\windows\system32\win32k.sys
2011-08-19 12:25 . 2011-03-28 21:59 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2009-04-01 02:47 . 2008-04-28 20:43 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2011-03-04 2741616]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2011-07-28 5242488]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-03-20 217544]
"PowerSuite"="c:\progra~1\Uniblue\POWERS~1\launcher.exe" [2011-07-18 67448]
"AROReminder"="c:\program files\ARO 2011\ARO.exe" [2011-01-25 2312048]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-13 122880]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2005-03-18 98304]
"JMB36X IDE Setup"="c:\windows\JM\JMInsIDE.exe" [2006-10-31 36864]
"JMB36X Configure"="c:\windows\system32\JMRaidSetup.exe" [2006-10-31 1953792]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"CTXFIREG"="CTxfiReg.exe" [2007-03-05 43520]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13687328]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 92704]
"CTHelper"="CTHELPER.EXE" [2007-03-05 19456]
"CTxfiHlp"="CTXFIHLP.EXE" [2007-03-05 19968]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2011-06-06 36760]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2011-06-06 2903448]
"Simpo PDF Creator Lite Server"="c:\program files\Simpo PDF Creator Lite\SpcLiteSrv.exe" [2010-08-18 101376]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DevconDefaultDB"="c:\windows\system32\READREG" [X]
"CtxfiReg"="CTXFIREG.exe" [2007-03-05 43520]
.
c:\users\Sheldon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\Palm\Hotsync.exe [2007-6-7 1392640]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Snagit 10.lnk - c:\program files\TechSmith\Snagit 10\Snagit32.exe [2011-3-21 7067464]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
R3 f5ipfw;F5 Networks StoneWall Filter;c:\windows\system32\drivers\urfltwlh.sys [2010-10-20 13944]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-07-06 41272]
R3 RemoteControl-USBLAN;RemoteControl-USBLAN;c:\windows\system32\DRIVERS\rcblan.sys [2007-01-24 39704]
R3 rt61x86;Linksys Wireless-G PCI Adapter Driver;c:\windows\system32\DRIVERS\WMP54Gv41x86.sys [2007-06-26 286208]
R3 SMARTMouseFilterx86;HID-compliant mouse;c:\windows\system32\DRIVERS\SMARTMouseFilterx86.sys [x]
R3 SMARTVHidMini2000x86;SMART HID Device;c:\windows\system32\DRIVERS\SMARTVHidMini2000x86.sys [x]
R3 SMARTVTabletPCx86;SMART Virtual TabletPC;c:\windows\system32\DRIVERS\SMARTVTabletPCx86.sys [x]
R3 USBTINSP;TI-Nspire(TM) Handheld Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys [2008-12-05 123392]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2008-09-10 716272]
S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20110826.001\IDSvix86.sys [2010-09-15 287792]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-19 21504]
S2 hidserv32;Human Interface Device Access ;c:\programdata\appinfo32.exe [2011-08-16 1208832]
S2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-08-05 105592]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
S3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2009-02-19 41008]
S3 urvpndrv;F5 Networks VPN Adapter;c:\windows\system32\DRIVERS\covpnwlh.sys [2010-10-20 36472]
S3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [2006-11-02 251904]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - COMHOST
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2011-03-04 16:29 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Supplementary Scan -------
.
uDefault_Search_URL = hxxp://www.earthlink.net/partner/more/msie/button/search.html
uStart Page =
https://mail.nycboe.net/owa/auth/logon.aspx?replaceCurrent=1&url=https://mail.nycboe.net/owa/
mStart Page = hxxp://www.dellnet.com/
uInternet Settings,ProxyServer = 80.179.251.233:80
uInternet Settings,ProxyOverride = hxxp://localhost;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: citadelgroup.com\login
TCP: DhcpNameServer = 167.206.251.129 167.206.251.130 192.168.1.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {A5A76EA0-7B92-4707-9DBF-6F6FE56A6800} - hxxp://scan.networkmagic.com/nmscan/download/WebDiag.4.5.8056.1-ship-WD.V1.cab
FF - ProfilePath - c:\users\Sheldon\AppData\Roaming\Mozilla\Firefox\Profiles\c1woehdc.default\
FF - prefs.js: browser.startup.homepage -
www.yahoo.com
.
.
------- File Associations -------
.
.scr=AutoCADLTScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{00ACAA42-6967-407A-878C-6AB1EA5B4ABa} - c:\windows\system32\appinfo32.dll
HKLM-Run-HotSync - c:\program files\PalmSource\Desktop\HotSync.exe
.
.
.
**************************************************************************
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files:
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{00ACAA42-6967-407A-878C-6AB1EA5B4ABA}"=hex:51,66,7a,6c,4c,1d,38,12,2c,a9,bf,
04,55,27,14,05,f8,9a,29,f1,ef,05,0e,ae
.
[HKEY_LOCAL_MACHINE\SOFTWARE\EarthLink\6.0\Components]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
"MSCurrentCountry"=dword:000000b5
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\system32\AstSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\programdata\cngaudit32.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\windows\System32\CtHelper.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
c:\windows\system32\WerFault.exe
c:\progra~1\Uniblue\POWERS~1\powersuite.exe
c:\program files\Adobe\Acrobat 10.0\Acrobat\AcroDist.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
c:\program files\TechSmith\Snagit 10\TSCHelp.exe
c:\program files\TechSmith\Snagit 10\SnagPriv.exe
.
**************************************************************************
.
Completion time: 2011-08-27 11:52:08 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-27 15:51
.
Pre-Run: 179,304,275,968 bytes free
Post-Run: 178,877,583,360 bytes free
.
- - End Of File - - A602CB86221B69743A48D164EF934731