ComboFix. I removed the entries for .purple and Arduino.
ComboFix 12-05-26.01 - rcboosted 05/25/2012 21:33:09.12.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2090 [GMT -7:00]
Running from: c:\documents and settings\rcboosted\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\rcboosted\Desktop\CFScript.txt
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\Doctor Web
c:\documents and settings\All Users\Application Data\Doctor Web\Logs\dwservice.log
c:\documents and settings\All Users\Application Data\Doctor Web\Logs\dwupdater.log
c:\documents and settings\All Users\Application Data\Doctor Web\Logs\netfilter.log
c:\documents and settings\All Users\Application Data\Doctor Web\Logs\spiderg3.log
c:\documents and settings\rcboosted\Doctor Web
c:\documents and settings\rcboosted\Doctor Web\dwscanner(3492).log
c:\documents and settings\rcboosted\Doctor Web\dwscanner(3992).log
c:\documents and settings\rcboosted\Doctor Web\dwscanner.log
C:\DrWeb Quarantine
c:\program files\Common Files\Doctor Web
c:\program files\DrWeb
c:\program files\DrWeb\drweboem.key
C:\username123
c:\username123\023.dat
c:\username123\023v.dat
c:\username123\023w7.dat
c:\username123\AppDataFile.cfx
c:\username123\AppDataFolder.cfx
c:\username123\appinit.bad
c:\username123\asp.str
c:\username123\Assoc.cmd
c:\username123\ATTRIB.cfxxe
c:\username123\Auto-RC.cmd
c:\username123\av.cmd
c:\username123\av.vbs
c:\username123\AWF.cmd
c:\username123\badclsid.c
c:\username123\Boot-Rk.cmd
c:\username123\Boot.bat
c:\username123\BootDrv.vbs
c:\username123\c.bat
c:\username123\c.mrk
c:\username123\Catch-sub.cmd
c:\username123\catchme.cfxxe
c:\username123\CCS.bat
c:\username123\CF-Script.cmd
c:\username123\CF25060.cfxxe
c:\username123\CFVersionOld
c:\username123\CHCP.bat
c:\username123\clsid.c
c:\username123\Combobatch.bat
c:\username123\ComboFix-Download.cfxxe
c:\username123\Create.cmd
c:\username123\Creg.dat
c:\username123\CregC.cmd
c:\username123\CregC.dat
c:\username123\CSCRIPT.cfxxe
c:\username123\CSet.cmd
c:\username123\dd.cfxxe
c:\username123\ddsDo.sed
c:\username123\DelClsid.bat
c:\username123\DelClsid64.bat
c:\username123\desktop.ini
c:\username123\DesktopFile.cfx
c:\username123\DPF.str
c:\username123\DrvRun.vbs
c:\username123\dumphive.cfxxe
c:\username123\embedded.sed
c:\username123\ERDNT.e_e
c:\username123\ERDNTDOS.LOC
c:\username123\ERDNTWIN.LOC
c:\username123\ERUNT.cfxxe
c:\username123\erunt.dat
c:\username123\ERUNT.LOC
c:\username123\Exe.reg
c:\username123\extract.cfxxe
c:\username123\FavoriteFolder.cfx
c:\username123\FavoritesFile.cfx
c:\username123\FD-SV.cmd
c:\username123\ffdefstr.dll
c:\username123\FileKill.cfxxe
c:\username123\files.pif
c:\username123\Fin.dat
c:\username123\FIND3M.bat
c:\username123\FIXLSP.bat
c:\username123\FKMGen.cmd
c:\username123\ForeignWht
c:\username123\GetHive.cmd
c:\username123\grep.cfxxe
c:\username123\gsar.cfxxe
c:\username123\handle.cfxxe
c:\username123\HDPEInfo.cfxxe
c:\username123\hidec.exe
c:\username123\history.bat
c:\username123\hwid.pif
c:\username123\iexplore.exe
c:\username123\image001.gif
c:\username123\Imefile.dat
c:\username123\Install-RC.cmd
c:\username123\katch.cmd
c:\username123\Kill-All.cmd
c:\username123\kmd.dat
c:\username123\Lang.bat
c:\username123\List-B.bat
c:\username123\List-C.bat
c:\username123\List-D.bat
c:\username123\List.bat
c:\username123\lnkread.vbs
c:\username123\LocalAppDataFile.cfx
c:\username123\LocalAppDataFolder.cfx
c:\username123\LocalService.dat
c:\username123\LocalServiceNetworkRestricted.dat
c:\username123\LocalSettingsFile.cfx
c:\username123\LocalSystemNetworkRestricted.dat
c:\username123\mbr.cfxxe
c:\username123\mbr.chk
c:\username123\md5sum.pif
c:\username123\Mirrors
c:\username123\MoveIt.bat
c:\username123\mtee.cfxxe
c:\username123\MtPt00
c:\username123\mynul.dat
c:\username123\N_\13819
c:\username123\N_\14250
c:\username123\N_\18566
c:\username123\N_\21789
c:\username123\N_\2346
c:\username123\N_\24425
c:\username123\N_\25199
c:\username123\N_\27146
c:\username123\N_\27388
c:\username123\N_\29293
c:\username123\N_\2991
c:\username123\N_\30182
c:\username123\N_\3341
c:\username123\N_\3579
c:\username123\N_\3785
c:\username123\N_\3921
c:\username123\N_\6935
c:\username123\N_\8257
c:\username123\N_\9689
c:\username123\N_\pingtest
c:\username123\ncmd.com
c:\username123\ND_.bat
c:\username123\ND_64.bat
c:\username123\ndis_combofix.dat
c:\username123\netsvc.bad.dat
c:\username123\netsvc.dat
c:\username123\netsvc.vista.dat
c:\username123\netsvc.xp.dat
c:\username123\NetworkService.dat
c:\username123\NirCmd.cfxxe
c:\username123\NircmdB.exe
c:\username123\NirCmdC.cfxxe
c:\username123\NIRKMD.cfxxe
c:\username123\NlsLanguageDefault
c:\username123\NT-OS.cmd
c:\username123\NULL
c:\username123\OSid.vbs
c:\username123\OsVer
c:\username123\pausep.cfxxe
c:\username123\PersonalFile.cfx
c:\username123\PersonalFolder.cfx
c:\username123\PEV.cfxxe
c:\username123\pev.exe
c:\username123\pevb.cfxxe
c:\username123\PING.cfxxe
c:\username123\Policies.dat
c:\username123\powp.dat
c:\username123\Prep.inf
c:\username123\ProfilesFile.cfx
c:\username123\ProfilesFolder.cfx
c:\username123\ProgramsFile.cfx
c:\username123\ProgramsFolder.cfx
c:\username123\Purity.dat
c:\username123\PV.cfxxe
c:\username123\pv.com
c:\username123\RCLink.dat
c:\username123\REGDACL.sed
c:\username123\RegDo.sed
c:\username123\region.dat
c:\username123\RegScan.cmd
c:\username123\RegScan64.cmd
c:\username123\Resident.txt
c:\username123\restore_pt.vbs
c:\username123\Rkey.cmd
c:\username123\rmbr.cfxxe
c:\username123\rogues.dat
c:\username123\ROUTE.cfxxe
c:\username123\run2.sed
c:\username123\Rust.str
c:\username123\s0rt.cfxxe
c:\username123\safeboot.dat
c:\username123\safeboot.def.dat
c:\username123\safeboot.def.vista.dat
c:\username123\Safeboot.def.w7.dat
c:\username123\sed.cfxxe
c:\username123\SetEnvmt.bat
c:\username123\setpath.cfxxe
c:\username123\SF.exe
c:\username123\sfx.cmd
c:\username123\SnapShot.cmd
c:\username123\SRestore.cmd
c:\username123\srizbi.md5
c:\username123\Start_dat
c:\username123\StartMenuFile.cfx
c:\username123\StartMenuFolder.cfx
c:\username123\StartUpFile.cfx
c:\username123\SuppScan.cmd
c:\username123\svc_wht.dat
c:\username123\SvcDrv.vbs
c:\username123\svchost.dat
c:\username123\svchost.vista.dat
c:\username123\svchost.vista.x64.dat
c:\username123\svchost.w7.dat
c:\username123\svchost.w7.x64.dat
c:\username123\SWREG.cfxxe
c:\username123\swreg.exe
c:\username123\swsc.cfxxe
c:\username123\swxcacls.cfxxe
c:\username123\system_ini.dat
c:\username123\tail.cfxxe
c:\username123\TemplatesFile.cfx
c:\username123\TemplatesFolder.cfx
c:\username123\toolbar.sed
c:\username123\Update-CF.cmd
c:\username123\VerCF.bat
c:\username123\version.txt
c:\username123\VikPev00
c:\username123\VInfo
c:\username123\VInfo2
c:\username123\Vipev.dat
c:\username123\vistaMcode.dat
c:\username123\vistareg.dat
c:\username123\vun.dat
c:\username123\VwinTemp.dacl
c:\username123\w_sock.dll
c:\username123\w2k_sock.dll
c:\username123\w2kreg.dat
c:\username123\w7Mcode.dat
c:\username123\w7reg.dat
c:\username123\Wmi_rem.vbs
c:\username123\XP.mac
c:\username123\xpmcode.dat
c:\username123\xpreg.dat
c:\username123\XPSBoot.reg
c:\username123\zDomain.dat
c:\username123\zhsvc.dat
c:\username123\zip.cfxxe
.
c:\windows\system32\Drivers\Volsnap.sys . . . is infected!!
.
.
((((((((((((((((((((((((( Files Created from 2012-04-26 to 2012-05-26 )))))))))))))))))))))))))))))))
.
.
2012-05-26 04:17 . 2012-05-26 04:17 -------- d-----w- C:\_OTM
2012-05-21 04:56 . 2012-05-21 04:56 -------- d-----w- c:\program files\ESET
2012-05-19 19:42 . 2012-04-04 22:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-05-13 19:36 . 2012-05-13 19:43 -------- d-----w- C:\Ascot Hills Park
2012-05-01 02:45 . 2012-05-18 06:43 -------- d-----w- c:\documents and settings\rcboosted\Application Data\.purple
2012-05-01 02:40 . 2012-05-01 02:40 -------- d-----w- c:\program files\Pidgin
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-11 13:14 . 2008-04-13 22:54 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-11 13:12 . 2008-04-13 23:00 1862272 ----a-w- c:\windows\system32\win32k.sys
2012-04-11 12:35 . 2008-04-13 19:01 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-03-18 20:52 . 2011-09-18 14:29 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-13 02:53 . 2012-03-13 02:53 63080 ----a-r- c:\documents and settings\rcboosted\Application Data\Microsoft\Installer\{5F3783B7-F809-45A7-8A92-A44B441FDA7C}\ARPPRODUCTICON.exe
2012-03-01 11:01 . 2008-06-05 01:36 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 11:01 . 2008-06-05 01:35 43520 ------w- c:\windows\system32\licmgr10.dll
2012-03-01 11:01 . 2008-06-05 01:35 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10 . 2008-04-14 03:42 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2008-04-14 03:41 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2008-06-05 01:35 385024 ------w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((( SnapShot@2012-05-21_04.49.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-05-26 04:20 . 2012-05-26 04:20 16384 c:\windows\Temp\Perflib_Perfdata_6ac.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-06 2260480]
"Pogoplug"="c:\program files\Pogoplug\PogoplugMonitor.exe" [2012-01-31 234304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2010-01-01 33636352]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"ASUS Update Checker"="c:\program files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe" [2008-12-11 114688]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-11-21 12669544]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-11-21 110184]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-13 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2001-08-23 44032]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-03-01 66680]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2004-03-12 124128]
"QFan Help"="c:\program files\ASUS\AI Suite\QFan3\QFanHelp.exe" [2009-08-20 603136]
"Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2009-08-21 887936]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"MPlayerForWindows_UpdateReminder"="c:\program files\MPlayer for Windows\AutoUpdate.exe" [2010-02-06 254376]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"WTClient"="WTClient.exe" [2009-10-30 32768]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2009-03-08 128512]
.
c:\documents and settings\rcboosted\Start Menu\Programs\Startup\
hosts.bat [2010-10-18 84]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-1-23 813584]
VPN Client.lnk - c:\windows\Installer\{871DF2BE-41D2-4334-AC33-839AF16FC8FE}\Icon3E5562ED7.ico [2010-11-14 6144]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 20:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Pogoplug\\HBPLUG\\HBPLUG.EXE"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57221:TCP"= 57221:TCP

ando Media Booster
"57221:UDP"= 57221:UDP

ando Media Booster
"8378:TCP"= 8378:TCP:League of Legends Launcher
"8378:UDP"= 8378:UDP:League of Legends Launcher
"8379:TCP"= 8379:TCP:League of Legends Launcher
"8379:UDP"= 8379:UDP:League of Legends Launcher
.
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [1/1/2010 2:44 AM 11448]
R2 AsSysCtrlService;ASUS System Control Service;c:\program files\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [1/1/2010 4:36 PM 90112]
R2 DokanCEDriver;DokanCEDriver;c:\program files\Pogoplug\dokance.sys [1/30/2012 6:04 PM 54592]
R2 HBAdmin;HBAdmin;c:\program files\Pogoplug\HBPLUG\hbadmin.exe [1/30/2012 6:04 PM 738112]
R2 PD91Agent;PD91Agent;c:\program files\Raxco\PerfectDisk2008\PD91Agent.exe [4/16/2008 2:00 PM 689416]
R2 UsbClientService;UsbClientService;c:\program files\Synology\Assistant\UsbClientService.exe [2/17/2011 11:18 PM 245760]
R3 busenum;Synology Virtual USB Hub;c:\windows\system32\drivers\busenum.sys [2/17/2011 11:20 PM 46304]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [1/14/2008 3:06 AM 21632]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [1/1/2010 2:18 AM 1381632]
R3 xcetap0;XCETAP0 Adapter;c:\windows\system32\drivers\xcetap0.sys [11/3/2011 11:19 AM 34624]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 2:16 PM 130384]
S2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [1/23/2010 11:35 PM 10384]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [11/13/2010 12:04 AM 30312]
S3 PD91Engine;PD91Engine;c:\program files\Raxco\PerfectDisk2008\PD91Engine.exe [4/16/2008 2:00 PM 894216]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [3/12/2004 4:18 PM 169192]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [11/13/2010 12:04 AM 96488]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [11/13/2010 12:04 AM 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [11/13/2010 12:04 AM 121576]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 1:37 PM 517096]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 2:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-2000478354-682003330-1002Core.job
- c:\documents and settings\rcboosted\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-10-03 08:08]
.
2012-05-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-2000478354-682003330-1002UA.job
- c:\documents and settings\rcboosted\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-10-03 08:08]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.google.com/
TCP: Interfaces\{B4309C5F-C7E9-4B11-A357-B2031DEF8307}: NameServer = 192.168.1.1
DPF: vzTCPConfig - hxxp://my.verizon.com/micro/speedoptimizer/fios/vzTCPConfig.CAB
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-05-25 21:38
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1956)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2012-05-25 21:39:04
ComboFix-quarantined-files.txt 2012-05-26 04:39
ComboFix2.txt 2012-05-21 04:50
ComboFix3.txt 2012-05-19 07:11
.
Pre-Run: 131,561,881,600 bytes free
Post-Run: 131,534,647,296 bytes free
.
- - End Of File - - 37B542F6CE8F2A14E2540EF8C4CDC574