It seemed to have some problems downloading and installing the recovery console. It managed to run through everything OK.
Here is the report:
ComboFix 09-09-06.03 - Owner 09/06/2009 23:46.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.271 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ctomfx.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-202484281-2063255866-616690263-1003
c:\windows\braviax.exe
c:\windows\cru629.dat
c:\windows\Installer\1324b.msi
c:\windows\system32\~.exe
c:\windows\system32\braviax.exe
c:\windows\system32\cru629.dat
c:\windows\system32\dllcache\beep.sys
c:\windows\system32\dllcache\figaro.sys
c:\windows\system32\drivers\rotscxpeouqsbp.sys
c:\windows\system32\drivers\UACrsvtcalxye.sys
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\rotscxbikoyipr.dat
c:\windows\system32\rotscxgowpseqm.dll
c:\windows\system32\rotscxiwwkicqf.dat
c:\windows\system32\rotscxxcwfvddr.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
D:\Autorun.inf
c:\windows\system32\drivers\beep.sys . . . is infected!!
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\logevent.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_rotscxevsprxby
——-\Legacy_rotscxevsprxby
——-\Service_UACd.sys
——-\Legacy_UACd.sys
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
((((((((((((((((((((((((( Files Created from 2009-08-07 to 2009-09-07 )))))))))))))))))))))))))))))))
.
2009-09-07 04:38 . 2009-09-07 04:38 ——– d—–w- C:\New Folder
2009-09-06 18:31 . 2009-09-06 18:31 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-09-06 17:15 . 2009-09-06 17:15 ——– d—–w- c:\program files\trend micro
2009-09-06 17:15 . 2009-09-06 17:15 ——– d—–w- C:\rsit
2009-09-06 16:43 . 2009-09-07 04:58 ——– d–h–w- c:\windows\PIF
2009-09-06 12:06 . 2009-09-06 12:07 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2009-09-05 06:44 . 2009-09-07 05:02 15648 –sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-09-05 06:44 . 2009-09-07 05:00 259872 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-09-05 06:17 . 2009-09-05 23:14 ——– d—–w- c:\program files\Common Files\ParetoLogic
2009-09-05 06:17 . 2009-09-05 23:14 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-09-05 06:17 . 2009-09-05 06:17 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic Anti-Virus PLUS
2009-09-05 03:55 . 2009-09-05 06:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-05 03:55 . 2009-09-05 03:59 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-09-05 01:44 . 2009-09-05 02:25 ——– d—–w- c:\program files\Sandboxie
2009-09-05 01:08 . 2009-09-05 01:08 ——– d—–w- C:\Sandbox
2009-09-05 00:57 . 2009-09-05 00:57 ——– d—–w- c:\program files\KeyScrambler
2009-09-05 00:57 . 2008-03-22 21:37 113896 —-a-w- c:\windows\system32\drivers\keyscrambler.sys
2009-09-04 12:34 . 2009-09-04 12:34 163840 —-a-w- c:\windows\svchasts.exe
2009-09-04 05:13 . 2009-09-04 05:13 ——– d—–w- c:\documents and settings\Owner\Application Data\AdobeUM
2009-08-27 00:40 . 2009-08-27 00:45 ——– d—–w- c:\documents and settings\Owner\Application Data\PCF-VLC
2009-08-26 04:47 . 2009-08-26 04:47 ——– d—–w- c:\documents and settings\Owner\Application Data\Participatory Culture Foundation
2009-08-26 04:44 . 2009-08-26 04:44 ——– d—–w- c:\program files\Participatory Culture Foundation
2009-08-25 04:26 . 2009-08-25 04:26 ——– d—–w- c:\windows\Sun
2009-08-25 04:26 . 2009-08-25 04:26 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Identities
2009-08-22 17:05 . 2009-08-22 17:05 ——– d—–w- c:\windows\system32\scripting
2009-08-22 17:05 . 2009-08-22 17:05 ——– d—–w- c:\windows\l2schemas
2009-08-22 17:05 . 2009-08-22 17:05 ——– d—–w- c:\windows\system32\en
2009-08-22 17:05 . 2009-08-22 17:05 ——– d—–w- c:\windows\system32\bits
2009-08-22 16:48 . 2009-08-22 16:48 ——– d—–w- c:\windows\EHome
2009-08-22 04:42 . 2009-08-22 04:42 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-08-22 04:41 . 2009-08-03 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-22 04:41 . 2009-08-22 04:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-22 04:41 . 2009-08-22 04:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-22 04:41 . 2009-08-03 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-22 04:20 . 2009-08-22 04:56 ——– d—–w- c:\program files\xeraqv
2009-08-18 22:07 . 2009-08-18 22:07 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-08-18 04:15 . 2009-09-05 06:17 33128 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-18 04:13 . 2009-08-18 04:13 ——– d—–w- c:\documents and settings\Owner\Application Data\Apple Computer
2009-08-18 04:13 . 2009-03-19 21:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-08-18 04:13 . 2008-04-17 17:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-08-18 04:12 . 2009-08-18 04:12 ——– d—–w- c:\program files\iPod
2009-08-18 04:12 . 2009-08-18 04:13 ——– d—–w- c:\program files\iTunes
2009-08-18 04:12 . 2009-08-18 04:13 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-18 04:12 . 2009-08-18 04:12 ——– d—–w- c:\program files\Bonjour
2009-08-18 04:11 . 2009-08-18 04:12 ——– d—–w- c:\program files\Common Files\Apple
2009-08-13 04:40 . 2009-08-13 04:40 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Adobe
2009-08-12 06:12 . 2009-08-22 16:58 ——– d—–w- c:\windows\ServicePackFiles
2009-08-12 03:23 . 2009-07-10 13:27 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-08-11 01:51 . 2009-08-11 01:51 ——– d—–w- c:\program files\Common Files\Logitech
2009-08-11 01:51 . 2009-09-05 06:16 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Downloaded Installations
2009-08-10 03:55 . 2009-08-10 03:55 ——– d—–w- c:\program files\MSXML 4.0
2009-08-10 00:51 . 2001-08-17 18:48 12160 -c–a-w- c:\windows\system32\dllcache\mouhid.sys
2009-08-10 00:51 . 2001-08-17 18:48 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys
2009-08-10 00:51 . 2008-04-13 18:45 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2009-08-09 23:01 . 2004-08-04 03:29 73216 ——w- c:\windows\system32\drivers\atintuxx.sys
2009-08-09 20:30 . 2008-06-17 19:02 8461312 -c—-w- c:\windows\system32\dllcache\shell32.dll
2009-08-09 20:29 . 2008-06-13 11:05 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2009-08-09 20:29 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2009-08-09 20:28 . 2009-03-06 14:22 284160 -c—-w- c:\windows\system32\dllcache\pdh.dll
2009-08-09 20:28 . 2009-02-09 12:10 401408 -c—-w- c:\windows\system32\dllcache\rpcss.dll
2009-08-09 20:28 . 2009-02-06 11:11 110592 -c—-w- c:\windows\system32\dllcache\services.exe
2009-08-09 20:28 . 2009-02-09 12:10 473600 -c—-w- c:\windows\system32\dllcache\fastprox.dll
2009-08-09 20:28 . 2009-02-06 10:10 227840 -c—-w- c:\windows\system32\dllcache\wmiprvse.exe
2009-08-09 20:28 . 2009-06-25 08:25 730112 -c—-w- c:\windows\system32\dllcache\lsasrv.dll
2009-08-09 20:28 . 2009-02-09 12:10 617472 -c—-w- c:\windows\system32\dllcache\advapi32.dll
2009-08-09 20:28 . 2009-02-09 12:10 453120 -c—-w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-08-09 20:28 . 2009-02-09 12:10 714752 -c—-w- c:\windows\system32\dllcache\ntdll.dll
2009-08-09 20:28 . 2009-02-06 11:06 2145280 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-08-09 20:28 . 2009-02-06 11:08 2189056 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-08-09 20:28 . 2009-02-06 10:32 2023936 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-08-09 20:20 . 2008-05-08 14:02 203136 -c—-w- c:\windows\system32\dllcache\rmcast.sys
2009-08-09 20:20 . 2008-10-24 11:21 455296 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2009-08-09 20:19 . 2008-12-11 10:57 333952 -c—-w- c:\windows\system32\dllcache\srv.sys
2009-08-09 20:18 . 2008-04-11 19:04 691712 -c—-w- c:\windows\system32\dllcache\inetcomm.dll
2009-08-09 20:17 . 2008-10-15 16:34 337408 -c—-w- c:\windows\system32\dllcache\netapi32.dll
2009-08-09 20:14 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2009-08-09 20:14 . 2008-04-21 12:08 215552 -c—-w- c:\windows\system32\dllcache\wordpad.exe
2009-08-09 01:00 . 2009-03-30 15:33 96104 —-a-w- c:\windows\system32\drivers\avipbb.sys
2009-08-09 01:00 . 2009-07-28 21:33 55656 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-09 01:00 . 2009-02-13 17:29 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-08-09 01:00 . 2009-02-13 17:17 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2009-08-09 01:00 . 2009-08-09 01:00 ——– d—–w- c:\program files\Avira
2009-08-09 01:00 . 2009-08-09 01:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2009-08-08 22:36 . 2009-08-09 01:00 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-08 22:36 . 2009-08-09 01:00 ——– d—–w- c:\program files\NOS
2009-08-08 22:29 . 2009-08-08 22:29 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Mozilla
2009-08-08 21:49 . 2005-07-19 02:05 135168 —-a-w- c:\windows\system32\igfxres.dll
2009-08-08 21:48 . 2009-09-07 04:58 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\SampleView
2009-08-08 21:48 . 2009-08-08 21:12 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\You've Got Pictures Screensaver
2009-08-08 21:48 . 2009-08-08 21:07 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150020}
2009-08-08 21:48 . 2009-08-08 20:41 ——– d—–w- c:\windows\system32\config\systemprofile\WINDOWS
2009-08-08 21:47 . 2009-08-08 20:41 ——– d—–w- c:\documents and settings\Default User\WINDOWS
2009-08-08 21:22 . 2009-08-08 22:09 ——– d—–w- c:\program files\McAfee
2009-08-08 21:22 . 2009-08-08 21:22 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall
2009-08-08 21:21 . 2009-08-08 21:21 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-08-08 21:20 . 2007-08-11 01:46 26488 —-a-w- c:\windows\system32\spupdsvc.exe
2009-08-08 21:19 . 2009-09-02 02:10 ——– d–h–w- c:\windows\$hf_mig$
2009-08-08 21:16 . 2009-08-08 21:16 ——– d—–w- c:\documents and settings\Owner\Application Data\SampleView
2009-08-08 21:16 . 2004-08-04 19:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-08-08 21:14 . 2003-03-25 12:00 67072 —-a-w- c:\windows\POWERCFG.EXE
2009-08-08 21:12 . 2009-08-08 21:12 ——– d—–w- c:\program files\MSN Encarta Plus
2009-08-08 21:12 . 2009-08-08 21:12 ——– d—–w- c:\documents and settings\Owner\Application Data\You've Got Pictures Screensaver
2009-08-08 21:12 . 2009-08-08 21:12 ——– d—–w- c:\program files\Common Files\Nullsoft
2009-08-08 21:10 . 2009-08-08 20:00 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2009-08-08 21:10 . 2009-08-08 21:10 335 —-a-w- c:\windows\nsreg.dat
2009-08-08 21:10 . 2009-08-08 19:59 ——– d—–w- c:\program files\Common Files\AOL
2009-08-08 21:10 . 2009-08-08 21:10 ——– d—–w- c:\program files\Common Files\Adobe
2009-08-08 21:09 . 2009-08-08 21:09 ——– d—–w- c:\program files\Common Files\Roxio Shared
2009-08-08 21:09 . 2009-08-08 21:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Napster
2009-08-08 21:09 . 2009-08-08 21:09 ——– d—–w- c:\program files\Napster
2009-08-08 21:08 . 2009-08-08 21:08 ——– d—–w- c:\program files\Intel
2009-08-08 21:08 . 2005-02-01 18:18 17992 —-a-w- c:\windows\system32\drivers\bcm42rly.sys
2009-08-08 21:08 . 2009-08-08 21:08 ——– d—–w- C:\ses2_client_bin_2_8_13g
2009-08-08 21:08 . 2009-08-08 21:08 4 —-a-w- c:\windows\Pix11.dat
2009-08-08 21:07 . 2009-08-08 21:08 ——– d—–w- c:\program files\Microsoft Digital Image 2006
2009-08-08 21:07 . 2009-08-08 21:07 ——– d—–w- c:\program files\Java
2009-08-08 21:07 . 2009-08-08 21:07 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150020}
2009-08-08 21:06 . 2009-08-08 21:06 ——– d—–w- c:\program files\CyberLink
2009-08-08 21:06 . 2004-07-15 21:06 471298 —-a-w- c:\windows\wallpg.exe
2009-08-08 21:06 . 2009-08-08 21:48 ——– d—–w- c:\documents and settings\Administrator
2009-08-08 21:06 . 2004-11-05 01:47 90202 —-a-w- c:\windows\system32\SynTPAPI.dll
2009-08-08 21:06 . 2004-11-05 01:47 81920 —-a-w- c:\windows\system32\SynTPCo2.dll
2009-08-08 21:06 . 2004-11-05 01:47 77917 —-a-w- c:\windows\system32\SynCOM.dll
2009-08-08 21:06 . 2004-11-05 01:47 69722 —-a-w- c:\windows\system32\SynTPFcs.dll
2009-08-08 21:06 . 2004-11-05 01:47 185824 —-a-w- c:\windows\system32\drivers\SynTP.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-07 05:00 . 2009-08-08 20:09 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2009-09-07 05:00 . 2009-08-08 20:08 0 —-a-w- c:\windows\system32\drivers\logiflt.iad
2009-09-07 04:59 . 2009-09-05 06:44 4484 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-09-07 04:59 . 2009-09-05 06:44 2468 –sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-09-07 04:39 . 2009-07-23 02:28 56320 —-a-w- c:\windows\system32\eventlog.dll
2009-08-10 15:36 . 2009-08-08 20:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Logishrd
2009-08-08 22:09 . 2009-08-08 21:11 ——– d—–w- c:\program files\Pure Networks
2009-08-08 21:14 . 2009-08-08 21:13 ——– d—–w- c:\program files\Microsoft Money 2005
2009-08-08 21:13 . 2009-08-08 21:12 ——– d—–w- c:\program files\Microsoft Works
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\documents and settings\All Users\Application Data\QuickTime
2009-08-08 21:11 . 2009-08-08 21:11 8552 —-a-w- c:\windows\system32\drivers\asctrm.sys
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\program files\Common Files\Real
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\program files\Real
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\program files\Viewpoint
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Pure Networks
2009-08-08 21:09 . 2009-08-08 21:01 ——– d—–w- c:\program files\Common Files\InstallShield
2009-08-08 21:01 . 2009-08-08 21:00 ——– d—–w- c:\program files\Ahead
2009-08-08 21:00 . 2009-08-08 21:00 ——– d—–w- c:\program files\Common Files\Ahead
2009-08-08 20:41 . 2004-08-26 18:04 ——– d—–w- c:\program files\microsoft frontpage
2009-08-08 20:08 . 2009-08-08 20:04 ——– d—–w- c:\program files\Common Files\LogiShrd
2009-08-08 20:06 . 2009-08-08 20:06 127034 ——r- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2009-08-08 20:06 . 2009-08-08 21:01 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-08 20:06 . 2009-08-08 20:06 ——– d—–w- c:\documents and settings\Owner\Application Data\Leadertech
2009-08-05 09:01 . 2009-07-23 02:30 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2009-07-23 02:27 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 15:08 . 2009-07-23 02:32 286720 —-a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2009-07-23 02:32 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2009-07-23 02:29 78336 ——w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2009-07-23 02:27 17408 ——w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2009-07-23 02:32 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2009-07-23 02:31 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2009-07-23 02:31 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2009-07-23 02:30 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2009-07-23 02:30 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2009-07-23 02:29 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2009-07-23 02:29 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2009-07-23 02:32 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2009-07-23 02:28 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2009-07-23 02:32 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:19 . 2009-07-23 02:30 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2009-07-23 02:27 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2009-07-23 02:32 132096 —-a-w- c:\windows\system32\wkssvc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-07-16 25604904]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-02-25 966656]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 169984]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-8-8 66864]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Participatory Culture Foundation\\Miro\\Miro_Downloader.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [8/8/2009 8:00 PM 108289]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [9/4/2009 7:57 PM 113896]
.
Contents of the 'Scheduled Tasks' folder
2009-09-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: kaspersky.com\www
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: microsoft.com\download
Trusted Zone: microsoft.com\update
Trusted Zone: windowsupdate.com
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8f0jyar.default\
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8f0jyar.default\extensions\[removed]\components\KeyScramblerIE.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-07 00:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(520)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2009-09-07 0:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-07 05:07
Pre-Run: 50,226,511,872 bytes free
Post-Run: 50,350,964,736 bytes free
358 — E O F — 2009-09-02 03:30