I would think those are OK.
While connected to the internet, run a new Combofix scan and be sure to update it if asked.
sorry for taking so long to respond, here's the new combofix log. It was running while the internet was on and didn't ask to update or anything.
ComboFix 10-03-16.03 - Owner 0/2010 Sat 14:20:17.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.932.81.1033.18.2046.1553 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Trend Micro Internet Security *On-access scanning enabled* (Outdated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro Personal Firewall *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.
((((((((((((((((((((((((( Files Created from 2010-02-20 to 2010-03-20 )))))))))))))))))))))))))))))))
.
2010-03-16 01:38 . 2010-03-16 01:38 ——– d—–w- c:\windows\system32\wbem\Repository
2010-03-11 04:48 . 2010-03-11 04:48 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\PunkBuster
2010-03-11 04:47 . 2010-03-20 05:58 139128 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-03-11 04:47 . 2010-03-11 04:47 138056 —-a-w- c:\documents and settings\Owner\Application Data\PnkBstrK.sys
2010-03-11 04:47 . 2010-03-20 06:29 215128 —-a-w- c:\windows\system32\PnkBstrB.exe
2010-03-11 04:47 . 2010-03-11 04:47 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2010-03-11 04:47 . 2010-03-11 04:47 2434856 —-a-w- c:\windows\system32\pbsvc_bc2.exe
2010-03-05 09:19 . 2010-03-05 09:19 ——– d—–w- c:\documents and settings\Owner\Application Data\Octoshape
2010-02-24 05:50 . 2010-02-24 05:50 ——– d—–w- c:\program files\dumps
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-20 18:31 . 2008-12-13 23:55 ——– d—–w- c:\program files\cFosSpeed
2010-03-20 18:10 . 2008-12-13 21:06 ——– d—–w- c:\program files\Steam
2010-03-17 19:36 . 2008-12-19 06:22 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-03-16 19:00 . 2009-02-23 02:38 ——– d—–w- c:\documents and settings\Owner\Application Data\uTorrent
2010-03-10 18:36 . 2009-11-11 02:26 79488 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-03-10 05:47 . 2009-07-09 02:32 ——– d—–w- c:\documents and settings\Owner\Application Data\Ubisoft
2010-03-09 19:13 . 2008-12-20 00:05 1 —-a-w- c:\documents and settings\Owner\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-03-07 09:57 . 2009-04-24 05:36 954272 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-03-07 04:37 . 2009-03-01 22:03 ——– d—–w- c:\documents and settings\Owner\Application Data\Skype
2010-03-07 04:36 . 2009-03-01 22:51 ——– d—–w- c:\documents and settings\Owner\Application Data\skypePM
2010-03-05 01:49 . 2008-12-09 23:36 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-03-02 01:01 . 2008-12-13 20:45 ——– d—–w- c:\program files\PowerArchiver
2010-02-26 08:46 . 2009-10-10 00:46 ——– d—–w- c:\program files\Heroes of Newerth
2010-02-22 02:38 . 2009-12-06 07:13 ——– d—–w- c:\program files\Emerald Viewer
2010-02-13 10:53 . 2008-12-14 22:11 ——– d—–w- c:\documents and settings\Owner\Application Data\mIRC
2010-02-13 10:01 . 2008-12-14 22:11 ——– d—–w- c:\program files\mIRC
2010-02-13 01:40 . 2010-02-13 01:40 ——– d—–w- c:\program files\Microsoft Games for Windows - LIVE
2010-02-13 01:20 . 2010-02-13 01:20 ——– d—–w- c:\program files\2K Games
2010-02-13 00:45 . 2010-02-12 20:12 ——– d—–w- c:\documents and settings\Owner\Application Data\Bioshock2
2010-02-12 08:59 . 2010-02-12 08:59 ——– d-sh–w- c:\documents and settings\All Users\Application Data\SecuROM
2010-02-08 04:38 . 2010-02-08 04:38 117427 —-a-w- c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\digitaleditions\digitaleditions.exe
2010-02-07 05:05 . 2010-02-07 05:05 ——– d—–w- c:\program files\Stardock
2010-01-27 18:31 . 2010-01-24 05:46 ——– d—–w- c:\program files\Mass Effect 2
2010-01-24 06:33 . 2008-12-28 07:31 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-01-24 06:33 . 2009-06-12 01:06 ——– d—–w- c:\program files\AGEIA Technologies
2010-01-24 06:33 . 2008-12-09 23:46 ——– d—–w- c:\program files\NVIDIA Corporation
2010-01-24 06:30 . 2009-11-03 23:49 ——– d—–w- c:\program files\Common Files\BioWare
2010-01-20 05:39 . 2009-07-23 18:13 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-12 21:47 . 2010-01-12 21:47 103784 —-a-w- c:\documents and settings\Owner\GoToAssistDownloadHelper.exe
2010-01-08 18:37 . 2008-12-15 18:00 31352 —-a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-05 10:00 . 2008-04-14 12:00 832512 ——w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2008-04-14 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2008-04-14 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-31 16:50 . 2008-04-14 12:00 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-12-13 20:11 . 2008-12-13 20:11 75 –sh–r- c:\windows\ICMET20.BIN
.
——- Sigcheck ——-
[7] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\sfcfiles.dll
c:\windows\System32\sfcfiles.dll … is missing !!
.
((((((((((((((((((((((((((((( SnapShot@2010-03-17_02.13.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-20 18:19 . 2010-03-20 18:19 16384 c:\windows\Temp\Perflib_Perfdata_300.dat
+ 2009-07-01 23:19 . 2010-03-17 03:46 316785 c:\windows\system32\drivers\etc\tmvsthfud.bin
- 2009-07-01 23:19 . 2009-07-23 22:30 316785 c:\windows\system32\drivers\etc\tmvsthfud.bin
+ 2009-07-01 23:19 . 2010-03-17 03:45 316785 c:\windows\system32\drivers\etc\tmvsthfss.bin
- 2009-07-01 23:19 . 2009-07-23 22:29 316785 c:\windows\system32\drivers\etc\tmvsthfss.bin
+ 2009-01-01 09:45 . 2009-01-01 09:45 3317760 c:\windows\system32\config\systemprofile\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2010-02-24 1217872]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"cFosSpeed"="c:\program files\cFosSpeed\cFosSpeed.exe" [2007-07-10 838608]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2008-04-14 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2007-09-06 1426432]
"CPU Power Monitor"="c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2007-09-07 626688]
"Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-09-11 880640]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-30 61440]
"LELA"="c:\program files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe" [2008-05-01 131072]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-04-09 648504]
"lxdxmon.exe"="c:\program files\Lexmark 3600-4600 Series\lxdxmon.exe" [2008-03-20 668328]
"EzPrint"="c:\program files\Lexmark 3600-4600 Series\ezprint.exe" [2008-03-20 107176]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"VX3000"="c:\windows\vVX3000.exe" [2008-08-05 721936]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-05 160800]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-01-31 1398024]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-12-23 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
forteManager.lnk - c:\program files\LG Soft India\forteManager\bin\Monitor.exe [2008-12-14 1126400]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Steam\\steamapps\\darkanarchy\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\lxdxcoms.exe"=
"c:\\WINDOWS\\system32\\lxdxcfg.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdxpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdxtime.exe"=
"c:\\Program Files\\Lexmark 3600-4600 Series\\lxdxmon.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdxjswx.exe"=
"c:\\Program Files\\Lexmark 3600-4600 Series\\Wireless\\lxdxwpss.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Documents and Settings\\Owner\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"=
"c:\\Program Files\\Lexmark 3600-4600 Series\\lxdxlscn.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\SecondLife\\SLVoice.exe"=
"c:\\Program Files\\Emerald Viewer\\SLVoice.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Steam\\steamapps\\darkanarchy\\counter-strike\\hl.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\audiosurf\\engine\\QuestViewer.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\street fighter iv\\SF4Launcher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\grand theft auto iv\\RGSC\\RGSCLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\osmos\\osmos.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\battlefield bad company 2\\BFBC2Game.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
R2 lxdx_device;lxdx_device;c:\windows\system32\lxdxcoms.exe -service –> c:\windows\system32\lxdxcoms.exe -service [?]
R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [7/1/2009 10:40 PM 52624]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2/15/2008 11:39 PM 36368]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/28/2008 3:19 AM 24652]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2/15/2008 11:39 PM 333328]
R3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [7/1/2009 10:41 PM 488768]
R3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [7/1/2009 10:41 PM 648456]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/14/2008 6:22 AM 685816]
S2 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [4/18/2008 5:30 AM 204800]
S2 lxdxCATSCustConnectService;lxdxCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdxserv.exe [12/19/2008 10:31 PM 98984]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [11/3/2009 8:00 PM 25832]
S3 LGDDCDevice;LGDDCDevice;c:\program files\LG Soft India\forteManager\bin\I2CDriver.sys [12/14/2008 5:59 AM 14336]
S3 LGII2CDevice;LGII2CDevice;c:\program files\LG Soft India\forteManager\bin\PII2CDriver.sys [12/14/2008 5:59 AM 13312]
.
.
——- Supplementary Scan ——-
.
IE: Download Link Using Mega Manager… - c:\program files\Megaupload\Mega Manager\mm_file.htm
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\43vh8bpq.default\
FF - prefs.js: browser.startup.homepage - optimum.net
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - plugin: c:\documents and settings\Owner\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Move Networks\plugins\npqmp071505000011.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1644491937-1965331169-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"?慴"=hex:ae,e2,c2,f2,e3,5f,8e,44,b4,1c,d3,8b,0f,dc,ee,73,70,b7,8a,df,05,65,a6,
ce,ae,36,d6,a3,a6,1c,84,e3,35,c7,9c,6b,7a,3e,0d,03,ab,96,08,f4,d3,33,62,33,\
"?祥"=hex:d2,dd,c2,f0,01,71,ed,00,5f,ec,f5,bb,f9,fe,5e,e2
[HKEY_USERS\S-1-5-21-1644491937-1965331169-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:8b,61,b2,62,d6,6f,31,a4,f8,6a,84,28,4f,f4,81,e6,9b,f0,f7,3b,d3,
ca,40,7a,93,45,4d,5d,71,09,9c,24,78,4f,24,8d,34,1d,f5,57,f3,52,e5,b7,f3,c0,\
"rkeysecu"=hex:a9,79,04,9f,8b,41,9d,3a,c1,c2,f0,06,51,7b,c9,ad
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1296)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-03-20 14:32:36
ComboFix-quarantined-files.txt 2010-03-20 18:32
ComboFix2.txt 2010-03-17 02:54
ComboFix3.txt 2010-03-17 02:15
Pre-Run: 165,626,707,968 bytes free
Post-Run: 166,577,266,688 bytes free
- - End Of File - - 1DF1948951F8554D3A1FB472A63DA87C
Good job
The following will implement some cleanup procedures as well as reset System Restore points:
Click START then RUN Now type ComboFix /Uninstall in the runbox and click OK . Note the space between the X and the U , it needs to be there.
[external image: Posted Image]
If you used DeFogger
You must remember to re-enable your Emulation drivers once we are finished, double click DeFogger to run the tool.
The application window will appear Click the Re-enable button to re-enable your CD Emulation drivers Click Yes to continue A 'Finished!' message will appear Click OK DeFogger will now ask to reboot the machine - click OK IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.
Your Emulation drivers are now re-enabled.
To be on the safe side, I would also change all my passwords.
Here's my usual all clean post
Log looks good
Make your Internet Explorer more secure - This can be done by following these simple instructions:From within Internet Explorer click on the Tools menu and then click on Options . Click once on the Security tab Click once on the Internet icon so it becomes highlighted. Click once on the Custom Level button. Change the Download signed ActiveX controls to Prompt Change the Download unsigned ActiveX controls to Disable Change the Initialize and script ActiveX controls not marked as safe to Disable Change the Installation of desktop items to Prompt Change the Launching programs and files in an IFRAME to Prompt Change the Navigate sub-frames across different domains to Prompt When all these settings have been made, click on the OK button. If it prompts you as to whether or not you want to save the settings, press the Yes button. Next press the Apply button and then the OK to exit the Internet Properties page. Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
This will ensure your computer has always the latest security updates available installed on your computer.
If there are new updates to install, install them immediately, reboot your computer, and revisit the site
until there are no more critical updates.
Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.
Only run one Anti-Virus and Firewall program.
I would suggest you read How to Prevent Malware:
thank you very much, you've been so helpful!
I'm having a problem, my emulation drivers is not working after I uninstalled Combofix.
your post says to use DeFogger but you never told me to download it. Should I download and run it to re enable my emulation drivers?
here is an attachment of the problem I am getting when I boot up.
I'd reinstall Damon Tools
why do I need to reinstall?
isn't there a way to just active it again?.. wtf?
I never had you run defogger to disable.
download
DeFogger to your
desktop .
Double click
DeFogger to run the tool.
The application window will appear Click the Disable button to disable your CD Emulation drivers Click Yes to continue A 'Finished!' message will appear Click OK DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log
defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.
Please download [url=http://www.jpshortstuff.247fixes.com/Defogger.exe][color=blue][b]DeFogger[/b][/color][/url] to your [b]desktop[/b].
Double click [b]DeFogger[/b] to run the tool.
[list][*] The application window will appear[*] Click the [b]Disable[/b] button to disable your CD Emulation drivers[*] Click [b]Yes[/b] to continue[*] A [b]'Finished!'[/b] message will appear[*] Click [b]OK[/b][*] DeFogger will now ask to reboot the machine - click [b]OK[/b][/list]
[b][color=red]IMPORTANT![/color][/b] If you receive an error message while running DeFogger, please post the log [b]defogger_disable[/b] which will appear on your desktop.
[b]Do not[/b] re-enable these drivers until otherwise instructed.
To re-enable your Emulation drivers, double click
DeFogger to run the tool.
The application window will appear Click the Re-enable button to re-enable your CD Emulation drivers Click Yes to continue A 'Finished!' message will appear Click OK DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log
defogger_enable which will appear on your desktop.
Your Emulation drivers are now re-enabled.
To re-enable your Emulation drivers, double click [b]DeFogger[/b] to run the tool.
[list][*] The application window will appear[*] Click the [b]Re-enable[/b] button to re-enable your CD Emulation drivers[*] Click [b]Yes[/b] to continue[*] A [b]'Finished!'[/b] message will appear[*] Click [b]OK[/b][*] DeFogger will now ask to reboot the machine - click [b]OK[/b][/list]
[b][color=red]IMPORTANT![/color][/b] If you receive an error message while running DeFogger, please post the log [b]defogger_enable[/b] which will appear on your desktop.
Your Emulation drivers are now re-enabled.