I've rebooted, and ran the PC for about 30mins. No iexplore.exe….yet! Btw, thanks for our help so far. How rude of me not to say anything!
ComboFix 10-07-16.01 - Keaton 17/07/2010 20:52:53.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.609 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((( Files Created from 2010-06-17 to 2010-07-17 )))))))))))))))))))))))))))))))
.
2010-07-16 21:17 . 2010-07-16 21:17 ——– d—–w- c:\program files\Common Files\Java
2010-07-16 21:16 . 2010-07-16 21:16 503808 —-a-w- c:\documents and settings\Keaton\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-27f88b55-n\msvcp71.dll
2010-07-16 21:16 . 2010-07-16 21:16 499712 —-a-w- c:\documents and settings\Keaton\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-27f88b55-n\jmc.dll
2010-07-16 21:16 . 2010-07-16 21:16 348160 —-a-w- c:\documents and settings\Keaton\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-27f88b55-n\msvcr71.dll
2010-07-16 21:16 . 2010-07-16 21:16 61440 —-a-w- c:\documents and settings\Keaton\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-201dd199-n\decora-sse.dll
2010-07-16 21:16 . 2010-07-16 21:16 12800 —-a-w- c:\documents and settings\Keaton\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-201dd199-n\decora-d3d.dll
2010-07-16 21:16 . 2010-04-12 16:29 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-16 20:33 . 2010-07-16 20:27 1062184 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-07-16 20:33 . 2010-07-16 19:00 895256 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-07-16 20:33 . 2010-07-16 20:33 56765 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-07-16 20:33 . 2010-07-16 20:33 56997 —-a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-07-16 20:32 . 2010-07-16 20:32 53600 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-07-16 20:32 . 2010-07-16 20:32 57715 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-07-16 20:31 . 2010-07-16 20:31 84054 —-a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-07-16 20:31 . 2010-06-09 23:01 9200 ——w- c:\windows\system32\drivers\cdralw2k.sys
2010-07-16 20:31 . 2010-06-09 23:01 9072 ——w- c:\windows\system32\drivers\cdr4_xp.sys
2010-07-16 20:31 . 2010-06-09 23:01 45648 ——w- c:\windows\system32\drivers\PxHelp20.sys
2010-07-16 20:31 . 2010-06-09 23:01 133616 ——w- c:\windows\system32\pxafs.dll
2010-07-16 20:30 . 2010-07-16 20:30 54644 —-a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-07-16 20:30 . 2010-07-16 20:30 54101 —-a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-07-16 20:30 . 2010-07-16 20:30 57054 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-07-16 20:30 . 2010-07-16 20:30 54166 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-07-16 20:30 . 2010-07-16 20:30 57532 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-07-16 20:30 . 2010-07-16 20:30 56458 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-07-16 20:30 . 2010-07-16 20:30 54174 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-07-16 20:30 . 2010-07-16 20:30 54153 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-07-16 20:30 . 2010-07-16 20:30 57409 —-a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-07-16 20:30 . 2010-07-16 20:30 52963 —-a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-07-16 20:30 . 2010-07-16 20:30 54073 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-07-16 20:29 . 2010-07-16 20:29 56969 —-a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-07-16 17:52 . 2010-07-17 01:00 ——– d—–w- c:\documents and settings\Keaton\Tracing
2010-07-16 17:17 . 2010-04-29 14:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-16 17:17 . 2010-07-16 17:17 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-16 17:17 . 2010-04-29 14:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-16 16:18 . 2010-07-16 16:18 ——– d-sh–w- c:\documents and settings\NetworkService\PrivacIE
2010-07-16 15:17 . 2010-07-16 15:17 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2010-07-16 10:03 . 2010-07-16 10:03 ——– d-sh–w- c:\documents and settings\Keaton\IECompatCache
2010-07-16 10:02 . 2010-07-16 10:02 ——– d-sh–w- c:\documents and settings\Keaton\PrivacIE
2010-07-16 09:45 . 2010-07-16 09:45 ——– d—–w- c:\documents and settings\Keaton\Application Data\Malwarebytes
2010-07-16 09:45 . 2010-07-16 09:45 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-15 20:03 . 2010-07-15 20:03 ——– d-sh–w- c:\documents and settings\Paula\PrivacIE
2010-07-15 20:02 . 2010-07-15 20:02 ——– d-sh–w- c:\documents and settings\Paula\IETldCache
2010-07-15 11:41 . 2010-07-15 11:41 ——– d-sh–w- c:\documents and settings\LocalService\PrivacIE
2010-07-15 11:41 . 2010-07-15 11:41 ——– d-sh–w- c:\documents and settings\Keaton\IETldCache
2010-07-15 11:41 . 2010-07-15 11:41 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-07-15 11:34 . 2010-07-16 18:01 ——– d—–w- c:\windows\ie8updates
2010-07-15 11:21 . 2010-07-15 11:27 ——– dc-h–w- c:\windows\ie8
2010-07-15 10:56 . 2010-05-06 10:41 599040 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-07-15 10:56 . 2010-05-06 10:41 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-07-15 10:56 . 2010-05-06 10:41 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-07-15 10:56 . 2010-05-06 10:41 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2010-07-15 10:56 . 2010-05-06 10:41 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-07-15 10:56 . 2010-05-06 10:41 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2010-07-15 10:56 . 2010-05-06 10:41 11076096 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2010-07-15 10:54 . 2010-04-16 11:43 41984 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-07-15 10:53 . 2010-07-15 11:09 ——– d—–w- C:\daa2907668b10745788116
2010-07-15 10:35 . 2010-06-14 14:31 744448 -c—-w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-15 10:28 . 2010-07-15 10:28 ——– d—–w- c:\windows\system32\wbem\Repository
2010-07-15 10:27 . 2010-07-15 10:27 ——– d—–w- c:\program files\Motive
2010-07-15 10:27 . 2010-07-15 10:27 ——– d—–w- c:\program files\Common Files\Futuremark Shared
2010-07-12 21:53 . 2010-07-15 10:27 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-07-12 21:53 . 2010-07-15 10:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-17 19:37 . 2009-08-24 14:08 857 –sha-w- c:\windows\system32\mmf.sys
2010-07-16 21:16 . 2009-08-11 15:59 ——– d—–w- c:\program files\Java
2010-07-16 20:34 . 2008-07-30 12:02 ——– d—–w- c:\documents and settings\Keaton\Application Data\DivX
2010-07-16 20:33 . 2010-04-15 13:08 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2010-07-16 20:33 . 2010-04-15 13:26 57344 -c–a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-16 20:33 . 2009-06-09 10:53 ——– d—–w- c:\program files\Common Files\DivX Shared
2010-07-16 20:33 . 2008-07-30 11:57 ——– d—–w- c:\program files\DivX
2010-07-16 17:10 . 2008-07-30 10:03 ——– d—–w- c:\program files\PeerGuardian2
2010-07-16 16:59 . 2008-08-01 11:59 ——– d—–w- c:\documents and settings\Keaton\Application Data\BitTorrent
2010-07-15 11:40 . 2008-07-30 11:27 ——– d—–w- c:\program files\McAfee
2010-07-12 22:01 . 2008-07-30 09:41 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-07-12 21:56 . 2008-07-30 10:31 ——– d—–w- c:\program files\BT Broadband Basic Help
2010-07-12 21:55 . 2008-07-30 10:31 ——– d—–w- c:\program files\Common Files\Motive
2010-06-14 14:31 . 2008-07-26 22:24 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-12 06:15 . 2008-07-30 11:19 22392 —-a-w- c:\documents and settings\Keaton\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-11 21:13 . 2010-06-11 20:57 ——– d—–w- c:\documents and settings\Keaton\Application Data\Sony Corporation
2010-06-11 21:01 . 2010-06-11 20:57 ——– d—–w- c:\program files\Common Files\Sony Shared
2010-06-11 21:01 . 2010-06-11 20:58 ——– d—–w- c:\program files\Sony
2010-06-11 21:01 . 2010-06-11 21:01 ——– d—–w- c:\program files\Sony Corporation
2010-06-11 20:59 . 2010-06-11 20:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Sony Corporation
2010-06-11 20:57 . 2008-07-30 09:41 ——– d—–w- c:\program files\Common Files\InstallShield
2010-06-10 14:16 . 2008-07-30 11:33 ——– d—–w- c:\documents and settings\Keaton\Application Data\Skype
2010-06-10 13:57 . 2008-07-30 12:03 ——– d—–w- c:\documents and settings\Keaton\Application Data\skypePM
2010-06-09 23:01 . 2008-07-30 11:57 126448 ——w- c:\windows\system32\pxinsi64.exe
2010-06-09 23:01 . 2008-07-30 11:57 123888 ——w- c:\windows\system32\pxcpyi64.exe
2010-06-09 08:06 . 2010-06-09 08:06 976832 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13561\AdobeARM.exe
2010-06-09 08:06 . 2010-06-09 08:06 70584 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13561\AdobeExtractFiles.dll
2010-06-09 08:06 . 2010-06-09 08:06 331176 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13561\ReaderUpdater.exe
2010-06-09 08:06 . 2010-06-09 08:06 331176 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13561\AcrobatUpdater.exe
2010-06-05 15:46 . 2009-04-06 13:12 ——– d—–w- c:\program files\Microsoft Silverlight
2010-05-06 10:41 . 2004-08-04 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2004-08-04 12:00 285696 —-a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="c:\program files\PeerGuardian2\pg2.exe" [2005-09-18 1421824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [24/12/2008 18:16 93320]
S2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [24/08/2009 15:08 2560]
S3 CTUPnPSv;Creative Centrale Media Server;c:\program files\Creative\Creative Centrale\CTUPnPSv.exe [21/05/2008 12:42 64000]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26/06/2009 13:43 721904]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {A72DF7D2-AAC2-4775-AC7D-8E42F71927F9} = 62.6.40.178 194.72.9.34
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Keaton\Application Data\Mozilla\Firefox\Profiles\g1z53uos.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-07-17 20:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e6,b0,da,0f,d0,2e,05,40,81,2e,5d,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,e6,b0,da,0f,d0,2e,05,40,81,2e,5d,\
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \C6F447273BC65EF0]
"1"=hex:af,49,68,4a,a1,03,67,91,19,71,84,cd,48,2c,98,f8,ee,08,c6,eb,cb,98,eb,
30,ad,8c,c5,8a,3e,53,91,13
"2"=hex:58,11,50,42,2e,f2,55,51,6f,f7,9a,ef,6b,f3,36,21,ec,a7,58,e2,e8,c3,4d,
78,80,c1,ec,38,21,d8,13,6c
"3"=hex:af,49,68,4a,a1,03,67,91,19,71,84,cd,48,2c,98,f8,e7,e9,9a,5d,76,44,f3,
e8,cb,fa,f8,8a,c7,df,0f,18,db,65,d2,ff,d4,73,8c,c0,e1,dd,91,71,a1,e6,83,ee,\
[HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \C6F447273BC65EF0\3B10FE43EE8F2AE67A30BA813D06F57B]
"1"=hex:8c,de,d0,aa,f8,58,db,1b,5a,48,bb,3c,bc,6d,16,45,21,43,6d,05,a3,3c,8f,
2b
"2"=hex:f4,ca,1b,b0,d7,6e,61,96
"3"=hex:2b,64,81,a5,aa,dc,ea,6d,61,a2,8d,5c,96,37,3b,40,bd,6b,62,de,e6,ef,89,
1c,6e,76,8a,a5,0c,9e,84,10,d2,b7,95,f7,b3,50,fb,1f,a6,58,5e,76,0e,d3,5e,44,\
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:bf,e5,23,7b,b0,66,d6,fc,bc,64,22,fb,7e,d3,39,3e,a3,00,33,13,c0,21,f4,
51,6c,4e,0c,96,e2,dd,ad,8a,b6,c4,05,e8,5a,bd,9a,e9,d4,1a,3d,68,9d,00,32,20
"7"=hex:da,dd,13,74,dd,46,90,2c,b4,13,aa,32,f0,b9,86,f0,9c,c3,0c,e5,75,1e,7c,
9a,18,4b,60,3b,4d,c8,93,e8,cd,89,11,03,14,be,9d,dd,f6,b6,6d,d9,44,db,ea,5d,\
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,bf,0c,1a,52,a6,e7,1b,
f8,8f,ad,2f,ee,2b,2a,17,6b,cf,82,5e,36,77,6d,37,61,05,3a,e2,28,28,8a,de,7a,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:70,56,26,33,e3,20,f8,ab
"10"=hex:f8,fe,42,b7,de,5f,ba,f0
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:81,20,8f,ab,28,6a,52,9c
"13"=hex:81,20,8f,ab,28,6a,52,9c
"14"=hex:81,20,8f,ab,28,6a,52,9c
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:81,20,8f,ab,28,6a,52,9c
"22"=hex:81,20,8f,ab,28,6a,52,9c
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(2932)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-07-17 20:59:54
ComboFix-quarantined-files.txt 2010-07-17 19:59
Pre-Run: 122,747,027,456 bytes free
Post-Run: 122,811,887,616 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 578E866FC1A9CC15B74BFAB2C20FEA61