offline
- blue.lais
- Novi MyCity građanin
- Pridružio: 12 Dec 2008
- Poruke: 4
|
ComboFix 08-12-12.05 - Vladimir Delonga 2008-12-13 15:16:08.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1250.1.1033.18.2046.1091 [GMT 1:00]
Running from: c:\users\Vladimir Delonga\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\rpcnetp.dll
.
((((((((((((((((((((((((( Files Created from 2008-11-13 to 2008-12-13 )))))))))))))))))))))))))))))))
.
2008-12-13 01:24 . 2008-12-13 01:24 <DIR> d-------- c:\users\All Users\NVIDIA
2008-12-13 01:24 . 2008-12-13 01:24 <DIR> d-------- c:\programdata\NVIDIA
2008-12-12 03:04 . 2008-10-22 00:31 2,048 --a------ c:\windows\System32\tzres.dll
2008-12-12 02:55 . 2008-10-21 06:16 297,472 --a------ c:\windows\System32\gdi32.dll
2008-12-04 12:21 . 2008-12-04 12:21 <DIR> d-------- c:\program files\uTorrent
2008-12-04 12:20 . 2008-12-13 04:51 <DIR> d-------- c:\users\Vladimir Delonga\AppData\Roaming\uTorrent
2008-11-29 18:23 . 2008-12-12 21:26 <DIR> d-------- c:\users\All Users\Google Updater
2008-11-29 18:23 . 2008-11-29 18:23 <DIR> d-------- c:\users\All Users\Google
2008-11-29 18:23 . 2008-12-12 21:26 <DIR> d-------- c:\programdata\Google Updater
2008-11-26 10:55 . 2008-10-21 06:16 1,645,568 --------- c:\windows\System32\connect.dll
2008-11-26 10:55 . 2008-10-22 04:43 241,152 --------- c:\windows\System32\PortableDeviceApi.dll
2008-11-26 10:55 . 2008-10-22 04:43 160,768 --------- c:\windows\System32\PortableDeviceTypes.dll
2008-11-26 10:55 . 2008-10-22 04:43 95,232 --------- c:\windows\System32\PortableDeviceClassExtension.dll
2008-11-26 10:54 . 2008-08-28 04:24 712,192 --------- c:\windows\System32\WindowsCodecs.dll
2008-11-26 10:54 . 2008-08-28 04:24 425,472 --------- c:\windows\System32\PhotoMetadataHandler.dll
2008-11-26 10:54 . 2008-08-28 04:24 347,136 --------- c:\windows\System32\WindowsCodecsExt.dll
2008-11-26 10:44 . 2008-11-26 10:44 17,408 --------- c:\windows\System32\rpcnetp.exe
2008-11-24 09:44 . 2008-10-16 22:13 1,809,944 --------- c:\windows\System32\wuaueng.dll
2008-11-24 09:44 . 2008-10-16 21:56 1,524,736 --------- c:\windows\System32\wucltux.dll
2008-11-24 09:44 . 2008-10-16 22:09 51,224 --------- c:\windows\System32\wuauclt.exe
2008-11-24 09:44 . 2008-10-16 22:09 43,544 --------- c:\windows\System32\wups2.dll
2008-11-24 09:43 . 2008-10-16 22:12 561,688 --------- c:\windows\System32\wuapi.dll
2008-11-24 09:43 . 2008-10-16 14:08 162,064 --------- c:\windows\System32\wuwebv.dll
2008-11-24 09:43 . 2008-10-16 21:55 83,456 --------- c:\windows\System32\wudriver.dll
2008-11-24 09:43 . 2008-10-16 22:08 34,328 --------- c:\windows\System32\wups.dll
2008-11-24 09:43 . 2008-10-16 13:56 31,232 --------- c:\windows\System32\wuapp.exe
2008-11-17 10:22 . 2008-12-12 03:12 <DIR> d-------- c:\users\Vladimir Delonga\AppData\Roaming\LimeWire
2008-11-17 10:21 . 2008-11-17 10:21 <DIR> d-------- c:\program files\LimeWire
2008-11-16 22:05 . 2008-12-13 13:59 <DIR> d-------- c:\users\Vladimir Delonga\AppData\Roaming\OpenOffice.org2
2008-11-16 21:59 . 2008-11-16 22:00 <DIR> d-------- c:\program files\OpenOffice.org 2.1
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-13 14:19 --------- d-----w c:\users\Vladimir Delonga\AppData\Roaming\DNA
2008-12-13 12:58 43,706 ----a-w c:\users\Vladimir Delonga\AppData\Roaming\nvModes.dat
2008-12-12 11:09 174 --sha-w c:\program files\desktop.ini
2008-12-12 11:07 --------- d-----w c:\program files\Windows Mail
2008-12-12 02:11 --------- d-----w c:\programdata\Microsoft Help
2008-12-01 10:55 --------- d-----w c:\program files\Picasa2
2008-11-29 17:24 --------- d-----w c:\program files\Google
2008-11-01 03:33 537,600 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:33 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:33 449,536 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:33 28,672 ----a-w c:\windows\System32\Apphlpdm.dll
2008-11-01 03:33 2,144,256 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:33 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-11-01 03:33 1,687,040 ----a-w c:\windows\System32\gameux.dll
2008-10-31 23:38 4,247,552 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-31 23:23 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2008-10-29 06:20 2,923,520 ----a-w c:\windows\explorer.exe
2008-10-21 14:20 2,984 --sh--w c:\windows\System32\KGyGaAvL.sys
2008-10-21 14:20 --------- d-----w c:\users\Vladimir Delonga\AppData\Roaming\Corel
2008-10-18 22:10 --------- d-----w c:\users\Vladimir Delonga\AppData\Roaming\CyberLink
2008-10-16 04:40 826,368 ----a-w c:\windows\System32\wininet.dll
2008-10-16 04:40 56,320 ----a-w c:\windows\System32\iesetup.dll
2008-10-16 04:40 26,624 ----a-w c:\windows\System32\ieUnatt.exe
2008-09-30 15:43 1,286,152 ------w c:\windows\System32\msxml4.dll
2008-09-18 04:27 3,506,744 ------w c:\windows\System32\ntkrnlpa.exe
2008-09-18 04:27 3,472,952 ------w c:\windows\System32\ntoskrnl.exe
2008-09-18 02:03 2,027,520 ------w c:\windows\System32\win32k.sys
2007-11-04 16:38 1,398,352 ------w c:\users\All Users\pswi_preloaded.exe
2007-11-04 16:38 1,398,352 ------w c:\programdata\pswi_preloaded.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-03-26 1232896]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"BitTorrent DNA"="c:\users\Vladimir Delonga\Program Files\DNA\btdna.exe" [2008-11-25 342336]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-29 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPFNF7"="c:\program files\Lenovo\NPDIRECT\TPFNF7SP.exe" [2007-04-09 58416]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"PMHandler"="c:\progra~1\Lenovo\PMDRIV~1\PMHandler.exe" [2007-06-06 34352]
"TPWAUDAP"="c:\program files\Lenovo\HOTKEY\TpWAudAp.exe" [2006-09-06 54824]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-02-12 174872]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-01-13 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-01-13 7766016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-01-13 81920]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2007-01-09 536576]
"FingerPrintSoftware"="c:\program files\Lenovo Fingerprint Software\fpapp.exe" [2007-03-02 933888]
"LPManager"="c:\progra~1\Lenovo\LENOVO~2\LPMGR.exe" [2007-02-28 120368]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-11-16 217176]
"AwaySch"="c:\program files\Lenovo\AwayTask\AwaySch.EXE" [2006-11-07 91688]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"RemoteControl"="c:\program files\Lenovo Multimedia Center\PowerDVD\PDVDServ.exe" [2006-11-24 56928]
"LanguageShortcut"="c:\program files\Lenovo Multimedia Center\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2007-02-01 439856]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2007-03-15 321088]
"Corel Photo Downloader"="c:\program files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe" [2006-11-13 478800]
"ACTray"="c:\program files\ThinkPad\ConnectUtilities\ACTray.exe" [2007-03-31 419376]
"ACWLIcon"="c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2007-03-31 124464]
"cssauth"="c:\program files\Lenovo\Client Security Solution\cssauth.exe" [2006-12-22 2614848]
"LenovoOobeOffers"="c:\swtools\LenovoWelcome\LenovoOobeOffers.exe" [2006-12-29 28672]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 517768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-10-19 286720]
"WilPrintCapture"="c:\program files\TOSHIBA Viewer V2\GDI&TWAIN\WILCAPV.EXE" [2007-02-27 81920]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-08-12 266497]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 c:\windows\RtHDVCpl.exe]
c:\users\Vladimir Delonga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 2.1.lnk - c:\program files\OpenOffice.org 2.1\program\quickstart.exe [2006-12-14 393216]
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-12-22 344064]
WordWeb.lnk - c:\program files\WordWeb\wweb32.exe [2008-09-18 42168]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2007-03-29 719664]
web'n'walk Manager.lnk - c:\program files\T-Mobile\web'n'walk Manager\web'n'walk Manager.exe [2007-04-05 561152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= c:\progra~1\LENOVO~3\Power2Go\CLMP3Enc.ACM
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli ACGina
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{ED54296D-3274-45FF-90A2-6FA8F8FAE3AB}"= c:\program files\Lenovo Multimedia Center\PowerDirector Express\PDX.EXE:CyberLink PowerDirector Express
"{7C0B9422-1450-4ECC-AADB-547EA10E6A87}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{4D5BB83E-9BAE-4235-8A89-1F196E35452C}"= UDP:c:\program files\TOSHIBA Viewer V2\GDI&TWAIN\WSPROXY.EXE:TOSHIBA WSProxy
"{B27777CF-37E9-483E-8C8E-12218B68BF94}"= TCP:c:\program files\TOSHIBA Viewer V2\GDI&TWAIN\WSPROXY.EXE:TOSHIBA WSProxy
"{2014CC35-8922-4CF4-AEEE-966B9248F4E3}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{7B0DC764-B76F-4F55-A24F-D5113DCC50A4}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{0F092651-68B8-4CCD-87CA-0291A3F954CB}"= TCP:c:\program files\DNA\btdna.exe:DNA
"TCP Query User{FEC4CC50-E8FA-4B82-A602-489296139868}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"UDP Query User{3E212D5A-E50B-4F84-8A42-595DA919F947}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"{D2535CFE-B4B7-401F-85DE-B3A8D0D2E6C7}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{2DD01C25-2663-4AC0-BB0A-9377C23367EE}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{8D95D6F7-583A-4475-9BA9-D0F94D88240B}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{D1403217-8D39-4C04-BE45-52FCA9760455}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\DRIVERS\smiif32.sys [2007-02-19 13744]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;"c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe" [2008-01-11 30312]
R2 FNF5SVC;Fn+F5 Service;c:\program files\LENOVO\HOTKEY\FNF5SVC.exe [2007-05-11 54832]
R2 GtFlashSwitch;GtFlashSwitch;"c:\program files\Common Files\GtFlashSwitch\GtFlashSwitch.exe" [2007-02-09 176128]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-04-07 810320]
R2 TPHKSVC;On Screen Display;c:\program files\LENOVO\HOTKEY\TPHKSVC.exe [2007-05-11 55936]
R2 TVT Backup Protection Service;TVT Backup Protection Service;"c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe" [2007-01-09 569344]
R2 wilusbmonitor;Unimessage Printer Tracking Service;c:\windows\system32\wilpmove.exe [2008-03-26 86016]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2007-02-09 179712]
R3 TVTI2C;Lenovo SM bus driver;c:\windows\system32\DRIVERS\Tvti2c.sys [2006-09-13 35264]
S3 GTFFBUS;GT FF BUS;c:\windows\system32\DRIVERS\gtffbus.sys [2007-01-15 17152]
S3 GTMNDISIRPXP;GT M 3G+ IRP NDIS;c:\windows\system32\DRIVERS\Gtm51Irp.sys [2007-01-15 122240]
S3 GTPTSER;GT PT SER;c:\windows\system32\DRIVERS\gtptser.sys [2007-01-15 8064]
S3 GTUQBUS;GT UQ BUS;c:\windows\system32\DRIVERS\gtuqbus.sys [2007-01-15 36992]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ [2008-02-26 29183504]
S3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;"c:\program files\Windows Live\Messenger\usnsvc.exe" [2007-10-18 98328]
S3 WILPT;Wordcraft Parallel Filter;\??\c:\windows\system32\drivers\WILPT.sys [2007-03-06 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06a44f2c-be8b-11dd-be71-001dd9edcbca}]
\shell\AutoRun\command - h6o0re.cmd
\shell\explore\Command - h6o0re.cmd
\shell\open\Command - h6o0re.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1ef2d98e-b302-11dd-87a4-001dd9edcbca}]
\shell\AutoRun\command - D:\
\shell\open\Command - rundll32.exe .\\pcwrprof.dll,InstallM
.
Contents of the 'Scheduled Tasks' folder
2008-12-13 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 15:54]
2008-12-12 c:\windows\Tasks\User_Feed_Synchronization-{9D2C9BB4-6A54-4BC9-95FA-E34EFE1291D7}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 10:45]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.hr/
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-12-13 15:22:41
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(4976)
c:\program files\Lenovo\Client Security Solution\tvtpwm_windows_hook.dll
c:\program files\Lenovo\Client Security Solution\tvt_passwordmanager.dll
c:\program files\Lenovo\Client Security Solution\css_banner.dll
c:\program files\Lenovo\Client Security Solution\csswait.dll
c:\windows\system32\cssuserdatadispatcher.dll
c:\program files\Lenovo\Client Security Solution\css_dlgcustompolicy.dll
c:\windows\system32\tvttsp.dll
c:\windows\system32\tcsrpc.dll
c:\program files\Common Files\Lenovo\tvt_lenovo_res2.dll
c:\program files\Lenovo\Client Security Solution\css_lenovo_res.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\windows\System32\IPSSVC.EXE
c:\program files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Lenovo\PM Driver\PMSveH.exe
c:\windows\System32\PSIService.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Lenovo\System Update\SUService.exe
c:\program files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\program files\Lenovo\Client Security Solution\tvttcsd.exe
c:\program files\Lenovo\Rescue and Recovery\rrservice.exe
c:\program files\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\program files\Common Files\Lenovo\Logger\logmon.exe
c:\program files\ThinkPad\ConnectUtilities\AcSvc.exe
c:\program files\Pure Networks\Network Magic\nmsrvc.exe
c:\program files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
c:\windows\System32\conime.exe
c:\windows\System32\rundll32.exe
c:\program files\Lenovo\LenovoCare\LPMGR.EXE
c:\combofix\hidec.exe
c:\windows\ehome\ehmsas.exe
c:\program files\OpenOffice.org 2.1\program\soffice.exe
c:\program files\Lenovo\Bluetooth Software\BTStackServer.exe
c:\program files\OpenOffice.org 2.1\program\soffice.bin
c:\program files\Lenovo\Client Security Solution\tvtpwm_tray.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\windows\System32\VSSVC.exe
c:\combofix\Catchme.tmp
c:\windows\System32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2008-12-13 15:29:41 - machine was rebooted [Vladimir Delonga]
ComboFix-quarantined-files.txt 2008-12-13 14:27:14
Pre-Run: 5.949.394.944 bytes free
Post-Run: 5,655,183,360 bytes free
267 --- E O F --- 2008-12-13 01:12:16
|