ComboFix 09-03-04.01 - Joshua Xiong 2009-03-06 9:46:43.2 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.776 [GMT -8:00]
Running from: e:\anti-virus\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090305-1] *On-access scanning enabled* (Updated)
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\JOSHUA~1\LOCALS~1\Temp\svchost.exe
c:\documents and settings\Joshua Xiong\Favorites\Cheap Pharmacy Online.url
c:\documents and settings\Joshua Xiong\Favorites\Search Online.url
c:\documents and settings\Joshua Xiong\Favorites\SMS TRAP.url
c:\documents and settings\Joshua Xiong\Favorites\VIP Casino.url
c:\documents and settings\Joshua Xiong\Joshua Xiong.exe
c:\documents and settings\Joshua Xiong\Start Menu\Cheap Pharmacy Online.url
c:\documents and settings\Joshua Xiong\Start Menu\Search Online.url
c:\documents and settings\Joshua Xiong\Start Menu\SMS TRAP.url
c:\documents and settings\Joshua Xiong\Start Menu\VIP Casino.url
c:\windows\ios.dat
c:\windows\system32\acelpdecl.exe
c:\windows\system32\c.ico
c:\windows\system32\m.ico
c:\windows\system32\m3.ico
c:\windows\system32\p.ico
c:\windows\system32\s.ico
c:\windows\system32\sf.ico
Infected copy of c:\windows\system32\lsass.exe was found and disinfected
Restored copy from - c:\windows\$NtServicePackUninstall$\lsass.exeInfected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\$NtServicePackUninstall$\winlogon.exeInfected copy of c:\windows\system32\services.exe was found and disinfected
Restored copy from - c:\windows\$NtServicePackUninstall$\services.exeInfected copy of c:\windows\system32\spoolsv.exe was found and disinfected
Restored copy from - c:\windows\$NtUninstallKB896423$\spoolsv.exeInfected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\$NtUninstallKB938828$\explorer.exe.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DCOMLAUNCHASWUPDSV
-------\Service_DcomLaunchaswUpdSv
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\TEMP\_av_proI.tm~a01544\setup.lok 0 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\wscntfy.exe
c:\program files\MessengerDiscovery\MessengerDiscovery Live.exe
c:\windows\system32\searchprotocolhost.exe
c:\program files\Windows Live\Messenger\usnsvc.exe
c:\program files\Mozilla Firefox\firefox.exe
c:\windows\system32\searchfilterhost.exe
.
**************************************************************************
.
Completion time: 2009-03-06 9:55:21 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-06 17:55:18
ComboFix2.txt 2009-02-15 21:01:24
Pre-Run: 100,516,937,728 bytes free
Post-Run: 99,534,532,608 bytes free
328 --- E O F --- 2009-03-06 00:00:28