Hi there,
I ran ComboFix but could not install the windows recovery console - the program ran any way and here is the result:
ComboFix 10-02-04.06 - Owner 05/02/2010 14:49:33.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.991.522 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\rundll32 .exe
c:\documents and settings\Owner\rundll32.exe
c:\documents and settings\Owner\sm56hlpr .exe
c:\documents and settings\Owner\sm56hlpr.exe
c:\documents and settings\Owner\smszac32 .exe
c:\documents and settings\Owner\smszac32.exe
c:\documents and settings\Owner\soundman .exe
c:\documents and settings\Owner\soundman.exe
c:\documents and settings\Tom\Application Data\AntiVirus Plus
c:\documents and settings\Tom\Application Data\AntiVirus Plus\AntiVirus Plus.70700.dll
c:\documents and settings\Tom\Application Data\sdra64.exe
c:\documents and settings\Tom\Application Data\SystemProc
c:\documents and settings\Tom\Application Data\SystemProc\lsass.exe
c:\documents and settings\Tom\rundll32.exe
c:\documents and settings\Tom\sm56hlpr.exe
c:\documents and settings\Tom\smszac32.exe
c:\documents and settings\Tom\soundman.exe
c:\program files\\setup.exe
c:\program files\Adobe\acrotray .exe
c:\program files\autorun.inf
c:\program files\Internet Explorer\js.mui
c:\program files\Internet Explorer\wmpscfgs.exe
C:\s
c:\windows\edazenocopo.dll
c:\windows\msb .exe
c:\windows\sisusbrg .exe
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\26500.exe
c:\windows\system32\41.exe
c:\windows\system32\6334.exe
c:\windows\system32\app_dll.dll
c:\windows\system32\ctfmon .exe
c:\windows\system32\helper32.dll
c:\windows\system32\IS15.exe
c:\windows\system32\keyhook .exe
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\nerocheck .exe
c:\windows\system32\net.net
c:\windows\system32\oprswv96y.dll
c:\windows\system32\reboot.txt
c:\windows\system32\rundll32 .exe
c:\windows\system32\sdra64.exe
c:\windows\system32\sm56hlpr .exe
c:\windows\system32\smss32 .exe
c:\windows\system32\smss32.exe
c:\windows\system32\smszac32 .exe
c:\windows\system32\soundman .exe
c:\windows\system32\spool\prtprocs\w32x86\0000181c.tmp
c:\windows\system32\warning.html
c:\windows\system32\winlogon32.exe
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
c:\windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
c:\windows\TEMP\00000c49.sys
c:\windows\Temp\3177315136.exe
c:\windows\Temp\3856098038.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_00000c49.sys
((((((((((((((((((((((((( Files Created from 2010-01-05 to 2010-02-05 )))))))))))))))))))))))))))))))
.
2010-02-05 11:19 . 2010-02-05 11:19 4 —-a-w- c:\program files\6445765.dat
2010-02-05 09:23 . 2010-02-05 09:23 ——– d-sh–w- c:\documents and settings\Owner\PrivacIE
2010-02-03 18:27 . 2010-02-05 09:07 0 —-a-w- c:\windows\system32\41.exe.vir
2010-02-03 16:29 . 2010-02-03 16:29 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2010-02-03 16:27 . 2010-02-03 16:27 114176 —-a-w- C:\xmjkek.exe
2010-02-03 16:26 . 2010-02-05 12:24 39424 —-a-w- c:\windows\system32\smszac32.exe
2010-02-03 16:26 . 2010-02-05 12:24 39424 —-a-w- c:\windows\system32\soundman.exe
2010-02-03 16:26 . 2010-02-05 14:51 39424 —-a-w- c:\windows\system32\sm56hlpr.exe
2010-02-03 16:26 . 2010-02-03 16:27 19456 —-a-w- C:\omav.exe
2010-02-03 16:26 . 2010-02-03 16:27 26624 —-a-w- C:\hnftrf.exe
2010-02-03 16:26 . 2010-02-03 16:27 114176 —-a-w- C:\qhdh.exe
2010-02-03 16:26 . 2010-02-03 16:27 124416 —-a-w- C:\vpwjq.exe
2010-02-03 16:26 . 2010-02-03 16:26 32256 —-a-w- C:\ugts.exe
2010-02-03 16:26 . 2010-02-03 16:26 39424 —-a-w- C:\qxbtlpjm.exe
2010-02-02 10:57 . 2010-02-02 10:57 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\{8F2E32BE-4934-442D-864D-547A1B69FCDC}
2010-01-30 17:41 . 2010-01-30 17:41 336896 –sha-w- c:\documents and settings\Tom\Local Settings\Application Data\av.exe
2010-01-30 17:01 . 2010-01-30 17:01 ——– d—–w- c:\documents and settings\Tom\Application Data\AdobeUM
2010-01-30 16:27 . 2010-02-05 09:05 0 —-a-w- c:\windows\Dwedi.bin
2010-01-30 16:27 . 2010-02-03 18:27 120 —-a-w- c:\windows\Xrohabi.dat
2010-01-30 16:27 . 2010-01-30 16:27 ——– d—–w- c:\documents and settings\Tom\Local Settings\Application Data\{1790732E-8ED0-446E-B2A1-E4FD5DB653FE}
2010-01-30 16:15 . 2010-01-30 16:17 30720 —-a-w- C:\dqccpnq.exe
2010-01-30 16:14 . 2010-01-30 16:17 176128 —-a-w- C:\kkalf.exe
2010-01-30 16:14 . 2010-01-30 16:17 52224 —-a-w- C:\ojjw.exe
2010-01-30 16:14 . 2010-01-30 16:17 114688 —-a-w- C:\horj.exe
2010-01-30 16:14 . 2010-01-30 16:17 16896 —-a-w- C:\duehpow.exe
2010-01-12 18:59 . 2009-11-21 15:51 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-05 15:15 . 2007-02-14 18:45 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-02-05 15:12 . 2007-03-20 18:45 ——– d—–w- c:\program files\iTunes
2010-02-05 15:12 . 2007-03-07 21:19 ——– d—–w- c:\program files\QuickTime
2010-02-05 15:12 . 2005-09-20 14:51 ——– d—–w- c:\program files\Microsoft IntelliPoint
2010-02-05 15:12 . 2005-08-08 11:44 39424 —-a-w- c:\windows\system32\nerocheck.exe
2010-02-05 15:12 . 2005-08-08 11:35 39424 —-a-w- c:\windows\system32\keyhook.exe
2010-02-05 15:10 . 2006-02-24 15:28 12395 —-a-w- c:\windows\system32\tablet.dat
2010-02-05 15:02 . 2007-02-14 18:52 ——– d—–w- c:\program files\Norton Internet Security
2010-02-05 15:02 . 2005-08-08 11:33 39424 —-a-w- c:\windows\sisusbrg.exe
2010-02-05 09:52 . 2004-08-04 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-02-03 16:23 . 2007-02-14 18:46 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-12-21 19:14 . 2004-08-04 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-11-21 15:51 . 2004-08-04 12:00 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2005-09-17 01:02 . 2005-09-17 01:02 774144 —-a-w- c:\program files\RngInterstitial.dll
2005-09-14 13:04 . 2005-09-14 12:55 1116 —-a-w- c:\program files\edge.ico
2005-09-14 13:04 . 2005-09-14 12:59 3 —-a-w- c:\program files\gp.info
2005-04-06 12:00 . 2005-09-14 12:54 1240 -c–a-w- c:\program files\banner.html
2004-02-11 11:14 . 2006-02-25 23:01 153644 -c–a-w- c:\program files\Setup.inx
2004-02-09 11:06 . 2006-02-25 23:01 417 -c–a-w- c:\program files\layout.bin
2004-02-09 11:06 . 2006-02-25 23:01 77671751 —-a-w- c:\program files\data2.cab
2004-02-09 11:06 . 2006-02-25 23:01 135527 -c–a-w- c:\program files\data1.hdr
2004-02-09 11:06 . 2006-02-25 23:01 1009211 -c–a-w- c:\program files\data1.cab
2004-02-09 11:05 . 2006-02-25 23:01 245 —-a-w- c:\program files\Setup.ini
2003-08-29 09:46 . 2006-02-25 23:01 25214 -c–a-w- c:\program files\autorun.ico
2003-05-22 16:13 . 2006-02-25 23:01 26 -c–a-w- c:\program files\AUTORUN.ID
2002-07-25 18:07 . 2006-02-25 23:01 346602 -c–a-w- c:\program files\ikernel.ex_
1998-07-23 16:36 . 2006-02-25 23:01 4173 -c–a-w- c:\program files\AUTORUN.EXE
.
c:\program files\Common Files\Symantec Shared\ccapp .exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\pifsvc .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Java\jre1.6.0_07\bin\jusched .exe
c:\program files\Microsoft IntelliPoint\point32 .exe
c:\program files\Norton Internet Security\oscheck .exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask .exe
c:\program files\Skype\Phone\skype .exe
c:\program files\USB Flash Disk Utility\UFD Utility\ufdmon .exe
c:\program files\USB Flash Disk Utility\UFD Utility\usbtd .exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [N/A]
"Steam"="" [N/A]
"DiskEventChk"="smszac32.exe" [2010-02-05 39424]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-02-05 39424]
"BitTorrent"="c:\program files\BitTorrent\bittorrent.exe" [N/A]
"smss32.exe"="c:\windows\system32\smss32.exe" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\quicktime\qttask .exe -atboottime" [X]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2010-02-05 39424]
"SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2010-02-05 39424]
"SMSERIAL"="sm56hlpr.exe" [2010-02-05 39424]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2010-02-05 39424]
"UFD Monitor"="c:\program files\USB Flash Disk Utility\UFD Utility\UFDMon.exe" [2010-02-05 39424]
"UFD Utility"="c:\program files\USB Flash Disk Utility\UFD Utility\USBTD.exe" [2010-02-05 39424]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2010-02-05 39424]
"SoundMan"="SOUNDMAN.EXE" [2010-02-05 39424]
"DiskEventChk"="smszac32.exe" [2010-02-05 39424]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2010-02-05 39424]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2010-02-05 39424]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2010-02-05 39424]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-05 39424]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2010-02-05 39424]
"Vgibuxujabowixa"="c:\windows\edazenocopo.dll" [N/A]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"smss32.exe"="c:\windows\system32\smss32.exe" [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"RTHDBPL"="c:\documents and settings\Tom\Application Data\SystemProc\lsass.exe" [N/A]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-2-20 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2006-1-31 1183744]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-4-6 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
TabUserW.exe.lnk - c:\windows\system32\WTablet\TabUserW.exe [2006-2-24 106496]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli prexdp.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\14 Degrees East\\Fallout Tactics\\BOS.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\WINDOWS\\system32\\smszac32.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [12/11/2007 18:25 112688]
R3 RTLWUSB;USB 54M Wireless Network Adapter;c:\windows\system32\drivers\RTL8187.sys [20/09/2006 16:55 167936]
S3 AlcrFilt;Alcor Micro Corp;c:\windows\system32\drivers\AlcrFilt.sys [24/02/2003 10:15 22860]
S3 BTUsbrXP®;BT Voyager 1010 USB Adapter;c:\windows\system32\DRIVERS\btusbrxp.sys –> c:\windows\system32\DRIVERS\btusbrxp.sys [?]
S3 FXDRV;FXDRV;\??\d:\fxdrv.sys –> d:\Fxdrv.sys [?]
— Other Services/Drivers In Memory —
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{ADEEAF15-7FE8-DEDD-3FFF-4DF56EBB1DFB}]
c:\docume~1\Owner\LOCALS~1\Temp\incognito.exe [N/A]
.
Contents of the 'Scheduled Tasks' folder
2009-12-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]
2006-11-05 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8126701198.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 23:52]
2010-01-18 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Owner.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-01-14 09:09]
2010-02-05 c:\windows\Tasks\User_Feed_Synchronization-{A4C7DF90-1DC8-43C5-99FD-910C7D322751}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://by124w.bay124.mail.live.com/mail/ApplicationMainReach.aspx?Control=Today
uInternet Connection Wizard,ShellNext = iexplore
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download.com
Trusted Zone: is-software-download25.com
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
TCP: {598F3782-FAAA-4D51-A0EA-D7EDCFE7FC44} = [removed],[removed]
TCP: {D3A114DF-B1B4-4207-9E8A-2EB5F51D7145} = 93.188.164.209,93.188.166.18
TCP: {FF1904FE-3110-4BD1-B68E-5FF205997C16} = 93.188.164.209,93.188.166.18
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\j0fyj1z1.Default User\
FF - prefs.js: browser.search.selectedEngine - Google.co.uk
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\j0fyj1z1.Default User\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - HiddenExtension: XULRunner: {1790732E-8ED0-446E-B2A1-E4FD5DB653FE} - c:\documents and settings\Tom\Local Settings\Application Data\{1790732E-8ED0-446E-B2A1-E4FD5DB653FE}
FF - HiddenExtension: XULRunner: {8F2E32BE-4934-442D-864D-547A1B69FCDC} - c:\documents and settings\Owner\Local Settings\Application Data\{8F2E32BE-4934-442D-864D-547A1B69FCDC}
.
- - - - ORPHANS REMOVED - - - -
BHO-{C4BF49A2-94F1-42BD-F034-3604811C807D} - c:\windows\system32\oprswv96y.dll
SharedTaskScheduler-{C4BF49A2-94F1-42BD-F034-3604811C807D} - c:\windows\system32\oprswv96y.dll
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\FlashUtil9b.exe
AddRemove-VobSub - c:\program files\Gabest\VobSub\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-05 15:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
RTHDBPL = c:\documents and settings\Tom\Application Data\SystemProc\lsass.exe?#???????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86AD3856]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7604f28
\Driver\ACPI -> ACPI.sys @ 0xf7577cb8
\Driver\atapi -> atapi.sys @ 0xf752f852
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a9
ParseProcedure -> ntoskrnl.exe @ 0x8056ea15
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
user & kernel MBR OK
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fd,e0,cc,8f,b7,21,09,40,95,6e,e4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fd,e0,cc,8f,b7,21,09,40,95,6e,e4,\
[HKEY_USERS\S-1-5-21-839522115-602609370-2147062339-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(756)
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(816)
c:\windows\system32\WININET.dll
c:\windows\prexdp.dll
- - - - - - - > 'explorer.exe'(2876)
c:\windows\system32\WININET.dll
c:\windows\system32\tabhook.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\prexdp.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\windows\system32\Tablet.exe
c:\program files\usb flash disk utility\ufd utility\ufdmon .exe
c:\program files\microsoft intellipoint\point32 .exe
c:\program files\usb flash disk utility\ufd utility\usbtd .exe
c:\program files\java\jre1.6.0_07\bin\jusched .exe
c:\program files\common files\symantec shared\ccapp .exe
c:\program files\itunes\ituneshelper .exe
c:\program files\quicktime\qttask .exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\java\jre1.6.0_07\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2010-02-05 15:27:23 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-05 15:27
Pre-Run: 22,700,576,768 bytes free
Post-Run: 23,586,934,784 bytes free
- - End Of File - - 8F58602AE1A3F23F144E3BC55FE65E39