Sorry i had to rename the program in order for it to run. but its done and log is attatched.
ComboFix 09-09-18.01 - Pepe 09/18/2009 13:05.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.152 [GMT -7:00]
Running from: c:\documents and settings\Pepe\Desktop\ComboFi.exe
AV: Verizon Internet Security Suite Anti-Virus *On-access scanning disabled* (Outdated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
FW: Verizon Internet Security Suite Firewall *disabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Protection System
c:\windows\system32\drivers\SKYNETpnbowkeg.sys
c:\windows\system32\drivers\UACsrskducbey.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\Process.exe
c:\windows\system32\SKYNETbabutfmu.dat
c:\windows\system32\SKYNETfjpyfqyw.dll
c:\windows\system32\SKYNETknmqsyek.dll
c:\windows\system32\SKYNETlog.dat
c:\windows\system32\SKYNETqjwdsixa.dll
c:\windows\system32\SKYNETulkyxwww.dat
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\uacinit.dll
c:\windows\system32\UAClthwvrigfl.dll
c:\windows\system32\UACmplidababo.dll
c:\windows\system32\UACmtbqqhxlvm.dat
c:\windows\system32\UACqvppxeuwno.dll
c:\windows\system32\UACxjxjotfqrs.log
c:\windows\system32\UACyxkrjlawvi.dll
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\wingenocx.dll
c:\windows\system32\WS2Fix.exe
c:\windows\system32\ygsuhdf83id.dll
c:\windows\Temp\1503070884.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SKYNETubrdyprr
-------\Legacy_SKYNETubrdyprr
-------\Service_UACd.sys
-------\Legacy_UACd.sys
-------\Legacy_NWCWORKSTATION
-------\Service_NWCWorkstation
((((((((((((((((((((((((( Files Created from 2009-08-18 to 2009-09-18 )))))))))))))))))))))))))))))))
.
2009-09-18 02:09 . 2009-09-18 02:09 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-09-17 05:41 . 2009-09-17 05:41 -------- d-----w- C:\db59e0524fe0aecacffb0ca4
2009-09-14 19:42 . 2009-09-14 19:42 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-09-14 19:42 . 2009-09-14 19:42 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2009-09-14 01:09 . 2009-09-14 01:09 -------- d-----w- c:\program files\Common Files\Real
2009-09-14 01:05 . 2009-09-14 01:09 -------- d-----w- c:\program files\V CAST Music with Rhapsody
2009-09-14 00:57 . 2009-09-14 00:57 -------- d-----w- c:\program files\LG Electronics
2009-09-14 00:57 . 2007-04-09 16:56 21248 ----a-w- c:\windows\system32\drivers\lgusbdiag.sys
2009-09-14 00:57 . 2007-04-09 16:55 22912 ----a-w- c:\windows\system32\drivers\lgusbmodem.sys
2009-09-14 00:57 . 2007-04-09 16:53 12672 ----a-w- c:\windows\system32\drivers\lgusbbus.sys
2009-09-10 06:52 . 2009-09-10 06:52 -------- d-----w- c:\program files\NortonInstaller
2009-09-10 06:52 . 2009-09-10 06:52 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-09-04 20:17 . 2009-09-04 20:17 447216 ----a-w- c:\windows\system32\ZuneWlanCfgSvc.exe
2009-09-04 20:16 . 2009-09-04 20:16 58592 ----a-w- c:\windows\system32\ZuneBusEnum.exe
2009-09-02 07:29 . 2009-09-02 07:29 74240 ----a-w- c:\windows\system32\ZuneUsbTransport.dll
2009-09-02 07:29 . 2009-09-02 07:29 57344 ----a-w- c:\windows\system32\ZuneRegUtil.dll
2009-09-02 07:29 . 2009-09-02 07:29 18944 ----a-w- c:\windows\system32\ZuneTcp2Udp.dll
2009-09-02 07:29 . 2009-09-02 07:29 12800 ----a-w- c:\windows\system32\ZunePTDNS.dll
2009-09-02 07:29 . 2009-09-02 07:29 310784 ----a-w- c:\windows\system32\ZuneNetProxy.dll
2009-09-02 07:29 . 2009-09-02 07:29 147456 ----a-w- c:\windows\system32\ZuneMTPZ.dll
2009-09-02 07:28 . 2009-09-02 07:28 40832 ----a-w- c:\windows\system32\drivers\zumbus.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-18 20:29 . 2008-12-16 06:57 26208032 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-09-18 20:29 . 2007-12-19 23:37 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-18 20:28 . 2008-12-16 06:57 813600 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-09-18 20:24 . 2008-12-16 06:57 77300 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-09-18 20:24 . 2008-12-16 06:57 351980 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-09-17 05:41 . 2009-09-17 05:41 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_09_00.Wdf
2009-09-17 00:14 . 2008-08-26 04:32 -------- d-----w- c:\program files\Zune
2009-09-17 00:07 . 2009-09-17 00:07 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_zumbus_01009.Wdf
2009-09-17 00:07 . 2009-09-17 00:07 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2009-09-15 02:20 . 2008-03-12 04:30 -------- d-----w- c:\program files\Norton Security Scan
2009-09-15 02:14 . 2007-12-08 05:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-09-14 21:25 . 2009-07-31 21:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-14 01:09 . 2009-09-14 01:09 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-09-10 23:04 . 2008-07-15 05:25 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-10 06:52 . 2007-12-08 05:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-09-10 03:47 . 2008-01-15 06:11 -------- d-----w- c:\program files\Lx_cats
2009-08-27 22:04 . 2009-03-31 20:41 -------- d-----w- c:\documents and settings\Pepe\Application Data\uTorrent
2009-08-17 19:37 . 2009-08-17 19:37 1837296 ----a-w- c:\windows\system32\WUDFUpdate_01009.dll
2009-08-17 19:37 . 2009-08-17 19:37 1461992 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2009-08-14 13:58 . 2009-09-16 03:22 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 03:16 . 2008-09-20 02:43 -------- d-----w- c:\program files\NCH Software
2009-08-04 01:49 . 2009-08-04 01:48 -------- d-----w- c:\program files\Windows Defender
2009-07-17 19:01 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 17:35 . 2006-11-02 15:22 444136 ------w- c:\windows\system32\drivers\wdf01000.sys
2009-07-14 17:35 . 2006-11-02 15:22 37608 ------w- c:\windows\system32\drivers\wdfldr.sys
2009-07-14 06:43 . 2004-08-04 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-14 01:16 . 2006-09-29 04:13 39936 ------w- c:\windows\system32\WUDFCoinstaller.dll
2009-07-14 01:16 . 2006-09-29 02:56 567808 ------w- c:\windows\system32\WUDFx.dll
2009-07-14 01:16 . 2006-09-29 02:56 64512 ------w- c:\windows\system32\WudfSvc.dll
2009-07-14 01:14 . 2006-09-29 02:56 195584 ------w- c:\windows\system32\WudfHost.exe
2009-07-13 23:50 . 2006-09-29 03:00 132224 ------w- c:\windows\system32\drivers\WudfRd.sys
2009-07-13 23:50 . 2006-09-29 02:56 148480 ------w- c:\windows\system32\WudfPlatform.dll
2009-07-13 23:50 . 2006-09-29 02:55 91904 ------w- c:\windows\system32\drivers\WudfPf.sys
2009-07-13 20:36 . 2009-07-31 21:34 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 20:36 . 2009-07-31 21:34 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-03 17:09 . 2004-08-04 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2004-08-04 12:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-04 12:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-04 12:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-04 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-04 12:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2004-08-04 12:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-07 3885408]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2009-06-30 2836376]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-07-07 344064]
"YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-22 129536]
"LXCECATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 73728]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-30 583048]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-22 136600]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2008-10-21 2303216]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"LXCTCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll" [2006-06-07 106496]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2009-09-04 158448]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-5-16 805392]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 09:42 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^Pepe^Start Menu^Programs^Startup^IMVU.lnk]
path=c:\documents and settings\Pepe\Start Menu\Programs\Startup\IMVU.lnk
backup=c:\windows\pss\IMVU.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"c:\\Documents and Settings\\Pepe\\Desktop\\Unused Desktop Shortcuts\\utorrent.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Zune\\Zune.exe"=
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [3/20/2009 10:15 PM 55152]
R2 fsssvc;Windows Live Protección Infantil;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 6:08 PM 533360]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [12/7/2007 8:44 PM 88192]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [7/31/2009 2:34 PM 38160]
S3 Radialpoint Security Services;Verizon Internet Security Suite;c:\program files\Verizon\Verizon Internet Security Suite\RpsSecurityAwareR.exe [10/24/2008 7:49 PM 96496]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/10/2008 5:28 PM 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [7/10/2008 2:49 AM 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [7/10/2008 5:28 PM 369688]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
2009-09-18 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20]
2009-09-12 c:\windows\Tasks\NSSstub.job
- c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2009-09-10 03:50]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://mx.yahoo.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local;<local>
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\Pepe\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: zune.net
FF - ProfilePath - c:\documents and settings\Pepe\Application Data\Mozilla\Firefox\Profiles\4p30w1dq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://mx.search.yahoo.com/search?ei=UTF-8&fr=ytff-sunm&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://mx.search.yahoo.com/search?ei=UTF-8&fr=ytff-sunm&p=
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-Amazon MP3 Downloader - c:\program files\Amazon\MP3 Downloader\Uninstall.exe
AddRemove-LiveUpdate - c:\program files\Symantec\LiveUpdate\LSETUP.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-18 13:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
LXCTCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e6,11,aa,31,0b,35,ac,44,bf,e7,5c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e6,11,aa,31,0b,35,ac,44,bf,e7,5c,\
[HKEY_USERS\S-1-5-21-682003330-606747145-2146964071-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:a3,46,1a,78,a9,dc,ea,81,e1,c6,dd,5e,44,2a,56,32,ae,6a,a5,a9,35,1a,1a,
1c,e1,35,1f,f1,95,ff,8a,60,b4,16,3b,11,b7,61,6a,55,a1,80,47,ad,eb,24,6b,48,\
"??"=hex:34,16,5f,25,9b,d1,98,7d,d3,ae,b9,32,a9,8f,2c,dc
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1272)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
- - - - - - - > 'explorer.exe'(4532)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Verizon\Verizon Internet Security Suite\Fws.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\windows\system32\scardsvr.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Verizon\Verizon Internet Security Suite\RPS.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lxctcoms.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\Raxco\PerfectDisk\PDAgent.exe
c:\program files\Verizon\VSP\VerizonServicepointComHandler.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\ZuneBusEnum.exe
c:\program files\Zune\ZuneNss.exe
c:\windows\system32\wscntfy.exe
c:\program files\Apoint\hidfind.exe
c:\program files\Apoint\ApntEx.exe
c:\progra~1\Yahoo!\browser\ycommon.exe
c:\windows\system32\lxcecoms.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
.
**************************************************************************
.
Completion time: 2009-09-18 13:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-18 20:36
Pre-Run: 865,071,104 bytes free
Post-Run: 2,175,074,304 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
337 --- E O F --- 2009-09-18 02:11
Edited by Buckeye_Sam, 19 September 2009 - 04:19 PM.