That's odd, thought I had it all highlighted. Here it is, sorry for the delay:
ComboFix 09-10-19.01 - David J Payson 10/19/2009 16:40.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.628 [GMT -7:00]
Running from: c:\documents and settings\David J Payson\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Mozilla Firefox\extensions\{F1EE2BBE-5D4B-4C4D-AC5A-07F598ABFCEF}
c:\program files\Mozilla Firefox\extensions\{F1EE2BBE-5D4B-4C4D-AC5A-07F598ABFCEF}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{F1EE2BBE-5D4B-4C4D-AC5A-07F598ABFCEF}\chrome\content\overlay.xul
c:\program files\Mozilla Firefox\extensions\{F1EE2BBE-5D4B-4C4D-AC5A-07F598ABFCEF}\install.rdf
c:\windows\Installer\5aab4.msi
c:\windows\run.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Files Created from 2009-09-19 to 2009-10-19 )))))))))))))))))))))))))))))))
.
2009-10-19 23:37 . 2009-10-19 23:39 -------- d-----w- C:\Combo-Fix
2009-10-19 04:57 . 2009-10-19 04:57 -------- d-----w- c:\documents and settings\David J Payson\Application Data\Noteworthy Software
2009-10-19 04:57 . 2009-10-19 04:57 -------- d-----w- c:\program files\Noteworthy Software
2009-10-16 04:04 . 2009-10-16 04:04 -------- d-----w- c:\documents and settings\The Best Mom Ever\Local Settings\Application Data\Conduit
2009-10-16 04:04 . 2009-10-16 04:04 -------- d-----w- c:\documents and settings\The Best Mom Ever\Local Settings\Application Data\WhiteSmoke_Tools
2009-10-16 04:04 . 2009-10-16 04:04 -------- d-----w- c:\documents and settings\The Best Mom Ever\Application Data\WhiteSmoke
2009-10-15 00:44 . 2009-10-15 00:44 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\WhiteSmoke_Tools
2009-10-13 22:55 . 2009-10-19 22:43 -------- d-----w- c:\documents and settings\David J Payson\Application Data\WhiteSmoke
2009-10-13 22:54 . 2009-10-13 22:54 -------- d-----w- c:\documents and settings\David J Payson\Local Settings\Application Data\Conduit
2009-10-13 22:54 . 2009-10-16 18:46 -------- d-----w- c:\documents and settings\David J Payson\Local Settings\Application Data\WhiteSmoke_Tools
2009-10-13 22:54 . 2009-10-13 22:54 -------- d-----w- c:\program files\WhiteSmoke_Tools
2009-10-13 22:54 . 2009-10-13 22:54 -------- d-----w- c:\program files\Conduit
2009-10-13 22:54 . 2009-10-13 22:54 -------- d-----w- c:\program files\WhiteSmoke
2009-10-13 22:21 . 2009-10-13 22:28 -------- d-----w- c:\documents and settings\David J Payson\Application Data\gtk-2.0
2009-10-13 22:21 . 2009-10-13 22:21 -------- d-----w- c:\documents and settings\David J Payson\.thumbnails
2009-10-13 22:17 . 2009-10-18 01:20 -------- d-----w- c:\documents and settings\David J Payson\.gimp-2.6
2009-10-13 22:16 . 2009-10-13 22:16 -------- d-----w- c:\program files\GIMP-2.0
2009-10-11 04:58 . 2009-10-11 05:18 -------- d-----w- C:\Sun
2009-10-11 04:54 . 2009-10-11 04:54 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-09 03:48 . 2009-10-09 03:48 0 ----a-r- C:\logwmemory.bin
2009-10-09 03:46 . 2009-10-09 03:46 -------- d-----w- C:\Soldat
2009-10-04 05:43 . 2009-10-04 05:43 46668 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-27 03:57 . 2009-09-27 03:57 -------- d-----w- c:\program files\Realtek AC97
2009-09-27 01:16 . 2009-09-27 01:17 -------- d-----w- c:\program files\RM Converter
2009-09-25 14:25 . 2009-09-25 14:25 -------- dc----w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-09-25 14:24 . 2009-09-25 14:24 -------- d-----w- c:\documents and settings\David J Payson\Local Settings\Application Data\PCHealth
2009-09-24 00:48 . 2009-09-24 00:48 -------- d-----w- c:\program files\iPod
2009-09-24 00:48 . 2009-09-24 00:49 -------- d-----w- c:\program files\iTunes
2009-09-20 19:17 . 2009-09-20 19:23 19521 ----a-w- c:\windows\hpqins13.dat
2009-09-20 19:14 . 2009-09-20 19:14 -------- d-----w- c:\documents and settings\David J Payson\Local Settings\Application Data\HP
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-18 08:40 . 2009-08-28 23:38 -------- d-----w- c:\documents and settings\David J Payson\Application Data\vlc
2009-10-13 22:54 . 2008-04-29 02:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-12 22:21 . 2009-04-14 01:38 -------- d-----w- c:\program files\Steam
2009-10-11 04:54 . 2008-06-09 17:27 -------- d-----w- c:\program files\Java
2009-10-01 22:10 . 2009-09-12 06:33 -------- d-----w- c:\program files\Turbine
2009-09-25 14:26 . 2008-06-06 03:34 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-25 14:24 . 2009-04-24 22:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-24 00:48 . 2008-04-29 02:28 -------- d-----w- c:\program files\Common Files\Apple
2009-09-13 17:37 . 2009-08-15 22:39 -------- d-----w- c:\program files\The 4th Coming
2009-09-13 02:30 . 2008-04-29 02:29 -------- d-----w- c:\documents and settings\David J Payson\Application Data\Apple Computer
2009-09-12 06:33 . 2009-09-12 06:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Turbine
2009-09-11 14:18 . 2004-08-04 13:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 23:49 . 2009-08-28 23:15 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-09-10 01:00 . 2009-09-10 00:59 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-10 00:58 . 2009-09-10 00:58 -------- d-----w- c:\program files\QuickTime
2009-09-08 23:29 . 2009-09-08 23:29 -------- d-----w- c:\program files\Trend Micro
2009-09-05 06:10 . 2009-09-05 06:10 -------- d-----w- c:\program files\easetech
2009-09-05 05:57 . 2009-09-05 05:57 -------- d-----w- c:\program files\Flash Decompiler Gold
2009-09-04 21:03 . 2004-08-04 13:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-30 08:22 . 2009-05-29 00:32 -------- d-----w- c:\program files\Diablo II
2009-08-30 08:22 . 2009-08-30 08:12 17893 ----a-w- c:\windows\DIIUnin.dat
2009-08-30 08:17 . 2008-07-09 20:34 21840 ----atw- c:\windows\system32\SIntfNT.dll
2009-08-30 08:17 . 2008-07-09 20:34 17212 ----atw- c:\windows\system32\SIntf32.dll
2009-08-30 08:17 . 2008-07-09 20:34 12067 ----atw- c:\windows\system32\SIntf16.dll
2009-08-30 08:12 . 2009-08-30 08:12 94208 ----a-w- c:\windows\DIIUnin.exe
2009-08-30 08:12 . 2009-08-30 08:12 2829 ----a-w- c:\windows\DIIUnin.pif
2009-08-28 23:20 . 2009-08-28 23:20 -------- d-----w- c:\program files\VideoLAN
2009-08-28 23:18 . 2008-04-29 02:08 56496 ----a-w- c:\documents and settings\David J Payson\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-28 23:18 . 2009-08-28 23:18 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-08-28 23:11 . 2008-06-16 18:04 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-28 23:09 . 2009-08-28 23:09 -------- d-----w- c:\program files\Adobe Media Player
2009-08-28 23:01 . 2009-08-28 23:01 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-08-28 22:48 . 2009-08-28 22:22 -------- d-----w- c:\documents and settings\David J Payson\Application Data\Download Manager
2009-08-26 21:39 . 2008-05-07 20:37 -------- d-----w- c:\program files\CCleaner
2009-08-26 08:00 . 2004-08-04 13:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-24 14:09 . 2008-05-01 02:25 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-08-23 18:17 . 2009-08-23 07:00 -------- d-----w- c:\documents and settings\David J Payson\Application Data\SUPERAntiSpyware.com
2009-08-23 18:17 . 2009-08-23 07:00 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-08-23 18:15 . 2009-01-17 09:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Ulead Systems
2009-08-23 07:01 . 2009-08-23 07:01 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-08-21 14:18 . 2008-04-29 03:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-14 03:49 . 2008-04-29 04:52 78320 ----a-w- c:\windows\War3Unin.dat
2009-08-07 02:24 . 2008-04-29 01:41 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-07 02:24 . 2008-04-29 01:41 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-07 02:24 . 2008-04-29 01:41 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-07 02:24 . 2007-07-31 02:19 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-07 02:24 . 2008-04-29 01:41 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-07 02:24 . 2004-08-04 13:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-07 02:23 . 2008-04-29 01:41 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-07 02:23 . 2008-04-29 01:41 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2004-08-04 13:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 03:44 . 2004-08-04 13:00 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-03 22:59 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-07-22 19:55 . 2008-10-22 13:47 55720 ----a-w- c:\documents and settings\The Best Mom Ever\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{011f9246-da13-4555-9998-6e4805bd533f}"= "c:\program files\WhiteSmoke_Tools\tbWhit.dll" [2009-07-15 2224152]
[HKEY_CLASSES_ROOT\clsid\{011f9246-da13-4555-9998-6e4805bd533f}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{011f9246-da13-4555-9998-6e4805bd533f}]
2009-07-15 17:09 2224152 ----a-w- c:\program files\WhiteSmoke_Tools\tbWhit.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{011f9246-da13-4555-9998-6e4805bd533f}"= "c:\program files\WhiteSmoke_Tools\tbWhit.dll" [2009-07-15 2224152]
[HKEY_CLASSES_ROOT\clsid\{011f9246-da13-4555-9998-6e4805bd533f}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{011F9246-DA13-4555-9998-6E4805BD533F}"= "c:\program files\WhiteSmoke_Tools\tbWhit.dll" [2009-07-15 2224152]
[HKEY_CLASSES_ROOT\clsid\{011f9246-da13-4555-9998-6e4805bd533f}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="c:\program files\AIM\aim.exe" [2006-08-01 67112]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"Turbine Download Manager Tray Icon"="c:\program files\Turbine\Turbine Download Manager\TurbineDownloadManagerIcon.exe" [2009-09-12 472568]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2007-04-16 577536]
c:\documents and settings\The Best Mom Ever\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\David J Payson\Start Menu\Programs\Startup\
SDK Tray Menu.lnk - c:\sun\SDK\jdk\bin\javaw.exe [2009-10-10 139264]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Launch WhiteSmoke.lnk - c:\program files\WhiteSmoke\WSEnrichment.exe [2009-10-13 270336]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Warcraft III\\Frozen Throne.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Warcraft III\\World Editor.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Paint Ball 3 EXTREME\\merope.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"c:\\Program Files\\Call of Duty Game of the Year Edition\\CoDUOMP.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Microsoft Games\\Halo Trial\\halo.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Paint Ball 3 EXTREME\\Paint Ball 3 EXTREME.exe"=
"c:\\Soldat\\Soldat.exe"=
"c:\\Program Files\\Pixel Mine\\PixelMineLauncher.exe"=
"c:\\Program Files\\Pixel Mine\\Ashen Empires\\data\\client.exe"=
"c:\\Program Files\\Steam\\steamapps\\stannous\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.2.9901-to-3.1.3.9947-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Mythology\\aom.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Turbine\\Turbine Download Manager\\TurbineMessageService.exe"=
"c:\\Program Files\\Turbine\\Turbine Download Manager\\TurbineNetworkService.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Warcraft III 1
"6112:UDP"= 6112:UDP:Warcraft III 2
"3724:TCP"= 3724:TCP:Blizzard1
"61789:TCP"= 61789:TCP:*:Disabled:bit1
"61789:UDP"= 61789:UDP:*:Disabled:bit2
"94:TCP"= 94:TCP:VRS Recording System Web Control Panel
"4100:UDP"= 4100:UDP:uPNP Router Control Port
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R2 LiveTurbineMessageService;Turbine Message Service - Live;c:\program files\Turbine\Turbine Download Manager\TurbineMessageService.exe [9/11/2009 11:33 PM 267760]
R3 LiveTurbineNetworkService;Turbine Network Service - Live;c:\program files\Turbine\Turbine Download Manager\TurbineNetworkService.exe [9/11/2009 11:33 PM 218608]
S1 naxmfhgw;naxmfhgw;\??\c:\windows\system32\drivers\naxmfhgw.sys --> c:\windows\system32\drivers\naxmfhgw.sys [?]
S2 gupdate1c9c78bb70523de;Google Update Service (gupdate1c9c78bb70523de);c:\program files\Google\Update\GoogleUpdate.exe [4/27/2009 3:58 PM 133104]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/10/2008 5:28 PM 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [7/10/2008 2:49 AM 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [7/10/2008 5:28 PM 369688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-10-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2009-10-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-27 22:58]
2009-10-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-27 22:58]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT1369718
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Flash Snatch - c:\program files\Flash Decompiler Gold\FlashSnatch.dll/202
IE: {{7484A880-E46E-4831-AB87-7098AEBCA0A7} - res://c:\program files\Flash Decompiler Gold\FlashSnatch.dll/202
FF - ProfilePath - c:\documents and settings\David J Payson\Application Data\Mozilla\Firefox\Profiles\31kng3ju.default\
FF - prefs.js: browser.startup.homepage - hxxp://newgrounds.com
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
Toolbar-SITEguard - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-19 16:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(612)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(2328)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\program files\WhiteSmoke\WHook.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\combo-fix26865c\CF19446.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-10-19 16:59 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-19 23:59
Pre-Run: 85,480,615,936 bytes free
Post-Run: 86,199,185,408 bytes free
- - End Of File - - 46F57360C3F3599B1B5140E4F232BEC7
Edited by Stannous, 20 October 2009 - 05:03 PM.