Ok,
Ran your scropt through combofix, this is the log:
ComboFix 09-08-10.01 - Tim 08/11/2009 15:02.3.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1611 [GMT -4:00]
Running from: c:\documents and settings\Tim\Desktop\wildman.exe
Command switches used :: c:\documents and settings\Tim\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090810-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"C:\611933923"
file zipped: c:\windows\system32\drivers\527f4a3f.sys
file zipped: c:\windows\system32\drivers\hnzftgwsif.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
?
c:\documents and settings\Tim\Application Data\uTorrent
.
((((((((((((((((((((((((( Files Created from 2009-07-11 to 2009-08-11 )))))))))))))))))))))))))))))))
.
2009-08-10 19:11 . 2009-08-10 19:11 -------- d-----w- c:\program files\Java
2009-08-10 19:09 . 2009-08-10 19:09 -------- d-----w- c:\documents and settings\Tim\.SunDownloadManager
2009-08-10 18:39 . 2009-08-10 18:39 -------- d-----w- c:\program files\XBox 360 Controller for Windows Software
2009-08-10 16:33 . 2009-08-10 16:33 -------- d-----w- C:\872c84c2d43db5fa508fd58bed5c3cee
2009-08-10 16:33 . 2009-08-10 16:40 -------- d-----w- c:\windows\SxsCaPendDel
2009-08-09 22:54 . 2009-08-09 22:54 0 ----a-w- c:\documents and settings\Tim\jagex_runescape_preferences.dat
2009-08-09 22:54 . 2009-08-09 22:54 -------- d-----w- c:\windows\.jagex_cache_32
2009-08-09 21:04 . 2009-02-05 20:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-09 21:04 . 2009-02-05 20:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-09 21:04 . 2009-02-05 20:05 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-09 21:04 . 2009-02-05 20:08 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-09 21:04 . 2009-02-05 20:08 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-09 21:04 . 2009-02-05 20:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-09 21:04 . 2009-02-05 20:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-09 21:04 . 2009-02-05 20:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-08-09 21:04 . 2009-02-05 20:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2009-08-08 16:01 . 2009-08-08 16:01 -------- d-----w- c:\documents and settings\Tim\Application Data\Malwarebytes
2009-08-08 16:01 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-08 16:01 . 2009-08-10 14:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-08 16:01 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-08 09:09 . 2009-08-08 09:09 -------- d-----w- c:\program files\trend micro
2009-08-07 05:52 . 2009-08-07 05:52 -------- d-----w- c:\documents and settings\Tim\Local Settings\Application Data\Symantec
2009-08-07 05:48 . 2009-08-07 08:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-08-07 05:44 . 2009-08-10 18:34 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-08-07 05:42 . 2009-08-07 05:50 -------- d-----w- c:\documents and settings\Tim\Application Data\GetRightToGo
2009-08-06 21:39 . 2009-08-06 21:39 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-08-06 21:31 . 2009-08-06 21:31 9021376 ----a-w- C:\windows-kb890830-v2.12.exe
2009-08-06 21:01 . 2009-08-06 21:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-06 20:07 . 2009-08-06 20:07 -------- d-----w- c:\documents and settings\Tim\Application Data\PC Tools
2009-08-06 18:28 . 2009-08-06 18:32 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-08-06 14:10 . 2009-08-11 19:02 76544 ----a-w- c:\windows\system32\drivers\hnzftgwsif.sys
2009-08-06 14:01 . 2009-08-06 14:08 -------- d-----w- c:\windows\system32\CatRoot
2009-08-06 14:00 . 2009-08-11 19:02 119372 ----a-w- c:\windows\system32\drivers\527f4a3f.sys
2009-08-04 16:56 . 2009-08-04 16:56 -------- d-----w- c:\program files\City Interactive
2009-08-04 08:44 . 2009-08-07 08:38 -------- d-----w- c:\program files\Vendetta Online
2009-08-03 06:58 . 2009-08-07 08:42 -------- d-----w- c:\program files\Driving Simulator 2009
2009-07-28 09:18 . 2009-07-28 09:18 -------- d-----w- c:\documents and settings\Tim\Application Data\LucasArts
2009-07-28 09:15 . 2009-07-28 09:18 -------- d-----w- c:\program files\Secret Of Monkey Island SE
2009-07-27 07:05 . 2009-08-11 12:58 1369 --sha-w- c:\windows\system32\mmf.sys
2009-07-27 07:05 . 2009-07-27 07:05 48640 ----a-w- c:\windows\mmfs.dll
2009-07-27 07:05 . 2009-07-27 07:05 2560 ----a-w- c:\windows\Runservice.exe
2009-07-27 06:55 . 2009-07-27 06:55 -------- d-----w- c:\program files\Battlefront
2009-07-27 06:50 . 2009-07-27 06:50 -------- d-----w- c:\documents and settings\Tim\Local Settings\Application Data\Gas Powered Games
2009-07-17 07:31 . 2009-07-17 07:31 -------- d-----w- c:\documents and settings\Tim\Local Settings\Application Data\Ubisoft
2009-07-17 07:24 . 2009-07-17 07:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Ubisoft
2009-07-14 04:13 . 2009-08-11 16:35 -------- d-----w- c:\documents and settings\Tim\Application Data\vlc
2009-07-14 01:41 . 2009-07-14 01:41 -------- d-----w- c:\documents and settings\Tim\Local Settings\Application Data\assembly
2009-07-14 01:39 . 2009-07-14 01:39 -------- d-----w- c:\documents and settings\Tim\Local Settings\Application Data\IsolatedStorage
2009-07-14 01:39 . 2009-07-14 01:39 -------- d-----w- c:\program files\Virtual Earth 3D
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-11 19:07 . 2009-01-09 00:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Bitmeter2
2009-08-11 19:07 . 2008-12-10 08:21 -------- d-----w- c:\program files\PeerGuardian2
2009-08-11 18:57 . 2008-11-23 21:26 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-11 18:57 . 2008-11-23 21:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-11 16:40 . 2008-11-23 21:51 -------- d-----w- c:\program files\Paint Shop Pro 6
2009-08-11 13:01 . 2008-11-23 20:10 -------- d-----w- c:\program files\lg_fwupdate
2009-08-10 21:40 . 2009-01-09 02:47 -------- d-----w- c:\documents and settings\Tim\Application Data\dvdcss
2009-08-10 19:11 . 2008-12-20 16:59 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-10 19:05 . 2008-11-23 21:57 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-10 18:42 . 2009-08-10 18:42 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_xusb21_01005.Wdf
2009-08-10 18:42 . 2009-08-10 18:42 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-08-10 16:41 . 2008-11-23 20:15 20056 ----a-w- c:\documents and settings\Tim\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-09 23:28 . 2008-12-26 21:35 189104 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-08-09 22:56 . 2008-12-26 21:36 139584 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-08-07 08:43 . 2008-12-14 20:13 -------- d-----w- c:\program files\EA GAMES
2009-08-07 08:40 . 2009-06-02 02:16 -------- d-----w- c:\program files\Ubisoft
2009-08-07 08:40 . 2008-11-23 19:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-07 08:36 . 2009-07-03 05:55 -------- d--h--w- c:\documents and settings\All Users\Application Data\{0E8E33D8-193A-414A-A909-0F101A142D26}
2009-08-07 08:34 . 2009-07-02 03:19 -------- d-----w- c:\program files\Nobilis
2009-08-07 08:32 . 2009-07-02 03:38 -------- d-----w- c:\program files\1C Company
2009-08-07 08:26 . 2009-07-01 08:16 -------- d-----w- c:\program files\ZenoClash
2009-08-06 21:43 . 2009-01-11 07:16 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-08-06 16:18 . 2009-06-16 05:14 21040 ----a-w- c:\documents and settings\Nicole\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-02 06:07 . 2009-02-25 17:38 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-30 12:52 . 2009-01-14 11:40 -------- d-----w- c:\program files\Telltale Games
2009-07-28 09:51 . 2008-12-23 00:50 -------- d-----w- c:\program files\LucasArts
2009-07-19 15:45 . 2009-06-16 05:14 -------- d-----w- c:\documents and settings\Nicole\Application Data\BitMeter2
2009-07-17 05:19 . 2009-07-10 05:21 -------- d-----w- c:\program files\Velvet Assassin
2009-07-09 02:31 . 2009-07-09 02:31 -------- d-----w- c:\documents and settings\Tim\Application Data\Ubisoft
2009-07-09 02:23 . 2009-03-05 00:59 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-07-09 02:23 . 2009-03-05 00:59 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-07-09 01:13 . 2008-12-26 06:38 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-07-09 00:30 . 2008-12-26 21:35 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-07-06 09:40 . 2008-11-23 22:07 -------- d-----w- c:\program files\DivX
2009-07-06 09:40 . 2009-07-03 22:19 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-07-06 07:13 . 2008-12-21 22:52 -------- d-----w- c:\program files\Codemasters
2009-07-04 21:44 . 2009-03-13 05:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-07-04 06:09 . 2009-01-26 19:46 -------- d-----w- c:\program files\Google
2009-07-03 06:49 . 2009-07-03 06:49 -------- d-----w- c:\program files\Flagship Studios
2009-07-03 05:54 . 2009-07-02 08:27 -------- d-----w- c:\program files\Sins of a Solar Empire
2009-07-03 05:52 . 2008-11-24 00:40 -------- d-----w- c:\program files\Stardock Games
2009-07-02 08:21 . 2009-06-21 09:02 -------- d-----w- c:\program files\Hinterland
2009-07-02 03:03 . 2009-07-02 03:03 -------- d-----w- c:\program files\Strategy First
2009-07-02 02:39 . 2009-07-02 02:39 -------- d-----w- c:\program files\Sierra
2009-07-01 07:39 . 2009-07-01 07:30 -------- d-----w- c:\program files\Postal2STP
2009-07-01 05:32 . 2008-12-27 19:08 -------- d-----w- c:\program files\Bethesda Softworks
2009-07-01 04:46 . 2008-12-26 06:52 -------- d-----w- c:\program files\Activision
2009-07-01 02:12 . 2009-05-10 06:23 127872 ----a-w- c:\documents and settings\Tim\Application Data\Move Networks\uninstall.exe
2009-07-01 02:12 . 2009-01-15 04:35 -------- d-----w- c:\documents and settings\Tim\Application Data\Move Networks
2009-07-01 02:12 . 2009-06-16 06:35 4183416 ----a-w- c:\documents and settings\Tim\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-07-01 02:12 . 2009-07-01 02:06 1685856 ----a-w- c:\documents and settings\Tim\Application Data\Move Networks\MoveMediaPlayerWinSilent_071503000010.exe
2009-06-29 16:12 . 2008-04-14 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2008-04-14 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2008-04-14 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-29 07:57 . 2009-06-29 07:57 -------- d-----w- c:\program files\Common Files\DirectX
2009-06-23 07:19 . 2009-06-23 07:19 -------- d-----w- c:\program files\Mad Scientist Productions
2009-06-16 14:36 . 2008-04-14 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2008-04-14 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 06:35 . 2009-06-16 06:35 97144 ----a-w- c:\documents and settings\Tim\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-06-14 07:25 . 2009-06-14 07:25 126 ----a-w- c:\documents and settings\Tim\Local Settings\Application Data\fusioncache.dat
2009-06-13 20:17 . 2008-12-26 21:36 22328 ----a-w- c:\documents and settings\Tim\Application Data\PnkBstrK.sys
2009-06-13 20:17 . 2008-12-26 21:36 22328 ----a-w- c:\documents and settings\Tim\Application Data\PnkBstrK.sys
2009-06-13 20:16 . 2009-01-25 22:22 669184 ----a-w- c:\windows\system32\pbsvc.exe
2009-06-13 17:14 . 2009-06-13 17:14 390664 ----a-w- c:\documents and settings\Tim\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
2009-06-03 19:09 . 2008-04-14 12:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-06-01 22:28 . 2009-03-12 00:29 6442 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2009-05-26 17:00 . 2009-05-26 17:00 10134 ----a-r- c:\documents and settings\Tim\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\00269b811530a16cff ----
---- Directory of C:\04c5c7f96ec14cf236ae2e45b0 ----
------- Sigcheck -------
[-] 2008-06-23 16:01 827904 C66402A06B83B036C195242C0C8CF83C c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
[-] 2008-08-26 09:08 827904 77C192FE56A70D7FA0247BA0A6201C32 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
[-] 2008-10-16 20:24 827904 0D5B75171FF51775B630A431B6C667E8 c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
[-] 2008-12-20 23:56 827904 044E0A4E9FE97C0FB9AFE9C89E2A82E6 c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll
[-] 2009-03-03 00:17 828416 C8667854873938CA13C986F16B0CD183 c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\wininet.dll
[-] 2009-04-29 04:49 828928 62CCA075F44015147B8971DAFFBCFF76 c:\windows\$hf_mig$\KB969897-IE7\SP3QFE\wininet.dll
[-] 2009-06-29 16:23 828928 4C6B4138165A4C53FE8A5B1D809526C3 c:\windows\$hf_mig$\KB972260-IE7\SP3QFE\wininet.dll
[7] 2008-04-14 12:00 666112 7A4F775ABB2F1C97DEF3E73AFA2FAEDD c:\windows\ie7\wininet.dll
[-] 2007-08-13 23:54 818688 A4A0FC92358F39538A6494C42EF99FE9 c:\windows\ie7updates\KB953838-IE7\wininet.dll
[-] 2008-06-23 16:57 826368 8C13D4A7479FA0A026EDA8ABCE82C0ED c:\windows\ie7updates\KB956390-IE7\wininet.dll
[-] 2008-08-26 07:24 826368 EF8EBA98145BFA44E80D17A3B3453300 c:\windows\ie7updates\KB958215-IE7\wininet.dll
[-] 2008-10-16 20:38 826368 6741EAF7B7F110E803A6E38F6E5FA6B0 c:\windows\ie7updates\KB961260-IE7\wininet.dll
[-] 2008-12-20 23:15 826368 A82935D32D0672E8FF4E91AE398E901C c:\windows\ie7updates\KB963027-IE7\wininet.dll
[-] 2009-03-03 00:18 826368 28775945CCD53DEE280EF58DEA1A94C4 c:\windows\ie7updates\KB969897-IE7\wininet.dll
[-] 2009-04-29 04:56 827392 8E2D471157B0DF329D8D0EA5D83B0DDB c:\windows\ie7updates\KB972260-IE7\wininet.dll
[-] 2008-08-20 05:30 666112 9AF5F25124FBDC36E2B510729CBA2674 c:\windows\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp3gdr\wininet.dll
[-] 2008-08-20 04:58 666624 94418F53D2612C26DBADC04DAFBC197C c:\windows\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp3qfe\wininet.dll
[-] 2008-08-26 07:24 826368 EF8EBA98145BFA44E80D17A3B3453300 c:\windows\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2GDR\wininet.dll
[-] 2008-08-26 09:08 827904 77C192FE56A70D7FA0247BA0A6201C32 c:\windows\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2QFE\wininet.dll
[-] 2009-05-13 05:15 915456 366C72AF6970DB7BB39AB0142BF09DB5 c:\windows\SoftwareDistribution\Download\97fe76a20161cb86e78057600e7c82a0\SP3GDR\wininet.dll
[-] 2009-05-13 05:10 915456 C0EB6850C8A02A154281749DC61FAF22 c:\windows\SoftwareDistribution\Download\97fe76a20161cb86e78057600e7c82a0\SP3QFE\wininet.dll
[-] 2008-06-23 16:57 826368 8C13D4A7479FA0A026EDA8ABCE82C0ED c:\windows\SoftwareDistribution\Download\b4e75dba041bc21ee94fbcfa88cb49de\SP2GDR\wininet.dll
[-] 2008-06-23 16:01 827904 C66402A06B83B036C195242C0C8CF83C c:\windows\SoftwareDistribution\Download\b4e75dba041bc21ee94fbcfa88cb49de\SP2QFE\wininet.dll
[-] 2009-06-29 16:12 827392 A39B7BA7AB9B1CC2A0009F59772DB83C c:\windows\system32\wininet.dll
[-] 2009-06-29 16:12 827392 A39B7BA7AB9B1CC2A0009F59772DB83C c:\windows\system32\dllcache\wininet.dll
[-] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\system32\drivers\tcpip.sys
[-] 2009-02-06 10:30 2066176 607352B9CB3D708C67F6039097801B5A c:\windows\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe
[-] 2008-08-14 20:39 2066048 A25E9B86EFFB2AF33BF51E676B68BFB0 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
[-] 2008-08-14 09:33 2023936 8206B5F94A6A9450E934029420C1693F c:\windows\$NtUninstallKB956572$\ntkrnlpa.exe
[-] 2009-02-07 23:02 2066048 5BA7F2141BC6DB06100D0E5A732C617A c:\windows\Driver Cache\i386\ntkrnlpa.exe
[-] 2009-02-06 10:32 2023936 65D4220799E6FC2CB079070A6393CC0E c:\windows\system32\ntkrnlpa.exe
[-] 2009-02-07 23:02 2066048 5BA7F2141BC6DB06100D0E5A732C617A c:\windows\system32\dllcache\ntkrnlpa.exe
[-] 2009-02-07 23:35 2189184 EFE8EACE83EAAD5849A7A548FB75B584 c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe
[-] 2008-08-14 21:11 2189184 31914172342BFF330063F343AC6958FE c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
[-] 2008-08-14 10:09 2145280 F6F8245B3A2E9CA834DD318E7AE0C6D0 c:\windows\$NtUninstallKB956572$\ntoskrnl.exe
[-] 2009-02-06 11:08 2189056 7A95B10A73737EBF24139AAA63F5212B c:\windows\Driver Cache\i386\ntoskrnl.exe
[-] 2009-02-06 11:06 2145280 0CBA44D0938D57F334C0862424148B70 c:\windows\system32\ntoskrnl.exe
[-] 2009-02-06 11:08 2189056 7A95B10A73737EBF24139AAA63F5212B c:\windows\system32\dllcache\ntoskrnl.exe
[-] 2009-02-06 11:06 110592 020CEAAEDC8EB655B6506B8C70D53BB6 c:\windows\$hf_mig$\KB956572\SP3QFE\services.exe
[7] 2008-04-14 12:00 108544 0E776ED5F7CC9F94299E70461B7B8185 c:\windows\$NtUninstallKB956572$\services.exe
[-] 2009-02-06 11:11 110592 65DF52F5B8B6E9BBD183505225C37315 c:\windows\system32\services.exe
[-] 2009-02-06 11:11 110592 65DF52F5B8B6E9BBD183505225C37315 c:\windows\system32\dllcache\services.exe
[-] 2009-03-21 13:59 991744 DA11D9D6ECBDF0F93436A4B7C13F7BEC c:\windows\$hf_mig$\KB959426\SP3QFE\kernel32.dll
[7] 2008-04-14 12:00 989696 C24B983D211C34DA8FCC1AC38477971D c:\windows\$NtUninstallKB959426$\kernel32.dll
[-] 2009-03-21 14:06 989696 B921FB870C9AC0D509B2CCABBBBE95F3 c:\windows\system32\kernel32.dll
[-] 2009-03-21 14:06 989696 B921FB870C9AC0D509B2CCABBBBE95F3 c:\windows\system32\dllcache\kernel32.dll
[-] 2008-06-23 16:01 3594240 28B8231CA8D55FC85E027A57C90F5C88 c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\mshtml.dll
[-] 2008-08-26 09:08 3594752 25CC085720EE3617FD1F8AB9E2F7CAB2 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\mshtml.dll
[-] 2008-10-16 20:24 3595264 B74F31A4BD83797D7A083F922169287D c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\mshtml.dll
[-] 2008-12-13 06:26 3594752 C79FAD61CD4A26ED5AA8C16D991C6FBD c:\windows\$hf_mig$\KB960714-IE7\SP2QFE\mshtml.dll
[-] 2009-01-16 16:24 3596288 CC9D001B7370B292C35B366CA05B12B4 c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\mshtml.dll
[-] 2009-02-21 07:39 3596800 1BB754AB47B327DE8DBF2FA18C36357C c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\mshtml.dll
[-] 2009-04-29 04:49 3598336 C6FD770D518FB024245A0EE217D72BC1 c:\windows\$hf_mig$\KB969897-IE7\SP3QFE\mshtml.dll
[-] 2009-07-19 13:31 3600384 F6098CC1B1C3858D53F20F3CB5774F3B c:\windows\$hf_mig$\KB972260-IE7\SP3QFE\mshtml.dll
[7] 2008-04-14 12:00 3066880 A706E122B398FE1AB85CB9B75D044223 c:\windows\ie7\mshtml.dll
[-] 2007-08-13 23:54 3578368 C6EC2493346ED8888A549F59210A8ED3 c:\windows\ie7updates\KB953838-IE7\mshtml.dll
[-] 2008-06-24 15:57 3592192 EC936148284F557F19C333178768109B c:\windows\ie7updates\KB956390-IE7\mshtml.dll
[-] 2008-08-27 18:54 3593216 1AD035E04A7068EC2820B055A3131ED8 c:\windows\ie7updates\KB958215-IE7\mshtml.dll
[-] 2008-10-17 07:08 3593216 EACAEDEF6FA2A969DE5B36190D45396F c:\windows\ie7updates\KB960714-IE7\mshtml.dll
[-] 2008-12-13 06:40 3593216 121EC39A64D64205A88C2C45B034B455 c:\windows\ie7updates\KB961260-IE7\mshtml.dll
[-] 2009-01-17 02:35 3594752 3B413267DA8AE71C20E5EF3E54F74728 c:\windows\ie7updates\KB963027-IE7\mshtml.dll
[-] 2009-02-20 18:09 3595264 C7C3E41CC2F6EB4A629FE2184136C098 c:\windows\ie7updates\KB969897-IE7\mshtml.dll
[-] 2009-04-29 04:56 3596288 2B4315EC9E3124408A2A5074C4B97700 c:\windows\ie7updates\KB972260-IE7\mshtml.dll
[-] 2008-08-20 05:30 3067904 507BDA42F7DB8209C0F0B3556A043491 c:\windows\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp3gdr\mshtml.dll
[-] 2008-08-20 04:58 3067904 BD45470B132A0F98596277323D9F2E5A c:\windows\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp3qfe\mshtml.dll
[-] 2008-08-27 18:54 3593216 1AD035E04A7068EC2820B055A3131ED8 c:\windows\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2GDR\mshtml.dll
[-] 2008-08-26 09:08 3594752 25CC085720EE3617FD1F8AB9E2F7CAB2 c:\windows\SoftwareDistribution\Download\5d9d48823dca01f9929a959c29f5edc4\SP2QFE\mshtml.dll
[-] 2009-05-13 05:15 5936128 EEAADAA744B20E68CF5EB4FBB4F8AFA9 c:\windows\SoftwareDistribution\Download\97fe76a20161cb86e78057600e7c82a0\SP3GDR\mshtml.dll
[-] 2009-05-13 05:10 5936128 1290E417BF806185CC7B2845E78A104E c:\windows\SoftwareDistribution\Download\97fe76a20161cb86e78057600e7c82a0\SP3QFE\mshtml.dll
[-] 2008-06-24 15:57 3592192 EC936148284F557F19C333178768109B c:\windows\SoftwareDistribution\Download\b4e75dba041bc21ee94fbcfa88cb49de\SP2GDR\mshtml.dll
[-] 2008-06-23 16:01 3594240 28B8231CA8D55FC85E027A57C90F5C88 c:\windows\SoftwareDistribution\Download\b4e75dba041bc21ee94fbcfa88cb49de\SP2QFE\mshtml.dll
[-] 2009-07-19 13:33 3597824 758C8BEDAB7CE5F9070C85E2E57CBD80 c:\windows\system32\mshtml.dll
[-] 2009-07-19 13:33 3597824 758C8BEDAB7CE5F9070C85E2E57CBD80 c:\windows\system32\dllcache\mshtml.dll
[-] 2009-02-09 10:56 401408 9222562D44021B988B9F9F62207FB6F2 c:\windows\$hf_mig$\KB956572\SP3QFE\rpcss.dll
[7] 2008-04-14 12:00 399360 2589FE6015A316C0F5D5112B4DA7B509 c:\windows\$NtUninstallKB956572$\rpcss.dll
[-] 2009-02-09 12:10 401408 6B27A5C03DFB94B4245739065431322C c:\windows\system32\rpcss.dll
[-] 2009-02-09 12:10 401408 6B27A5C03DFB94B4245739065431322C c:\windows\system32\dllcache\rpcss.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-08-10_18.55.41 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-08-10 18:55 . 2009-08-10 18:55 16384 c:\windows\Temp\Perflib_Perfdata_7d4.dat
+ 2009-08-11 12:58 . 2009-08-11 12:58 16384 c:\windows\Temp\Perflib_Perfdata_7d4.dat
+ 2009-08-11 12:58 . 2009-08-11 12:58 16384 c:\windows\Temp\Perflib_Perfdata_5b4.dat
- 2008-11-29 02:02 . 2009-06-01 21:12 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-08-10 19:07 . 2009-08-11 14:51 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-08-10 19:11 . 2009-08-10 19:11 149280 c:\windows\system32\javaws.exe
+ 2009-08-10 19:11 . 2009-08-10 19:11 145184 c:\windows\system32\javaw.exe
+ 2009-08-10 19:11 . 2009-08-10 19:11 145184 c:\windows\system32\java.exe
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2009-08-10 19:11 . 2009-08-10 19:11 1757696 c:\windows\Installer\84716.msi
+ 2009-08-10 19:05 . 2009-08-10 19:05 3938816 c:\windows\Installer\844ab.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2009-06-25 1578736]
"PeerGuardian"="c:\program files\PeerGuardian2\pg2.exe" [2007-01-30 1432064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-10-21 143360]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-10-21 172032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-10-21 143360]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-15 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 52256]
"LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2008-11-23 548864]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-10-23 385024]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-04-19 198160]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-10 149280]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-16 16862720]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-18 1657376]
c:\documents and settings\Tim\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2008-12-5 225280]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-11-23 113664]
Bitmeter2.lnk - c:\program files\Codebox\BitMeter\BitMeter2.exe [2008-6-29 1462272]
MFWAKeys.lnk - c:\program files\MOTU\FireWire Audio\MFWAKeys.exe [2009-2-17 102400]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Freelancer\\EXE\\Freelancer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Codemasters\\DiRT\\DiRT.exe"=
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Documents and Settings\\Tim\\Desktop\\WiCKED-DOW2\\DOW2.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\EA GAMES\\Mercenaries 2 World in Flames\\Mercenaries2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57533:TCP"= 57533:TCP

ando Media Booster
"57533:UDP"= 57533:UDP

ando Media Booster
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"= %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000
"%windir%\\system32\\sessmgr.exe"= %windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:*:Enabled

xpsp2res.dll,-22004
"445:TCP"= 445:TCP:*:Enabled

xpsp2res.dll,-22005
"137:UDP"= 137:UDP:*:Enabled

xpsp2res.dll,-22001
"138:UDP"= 138:UDP:*:Enabled

xpsp2res.dll,-22002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"= %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000
"%windir%\\system32\\sessmgr.exe"= %windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"= c:\program files\Windows Media Player\wmplayer.exe:*

isabled:Windows Media Player
"c:\\Program Files\\Freelancer\\EXE\\Freelancer.exe"= c:\program files\Freelancer\EXE\Freelancer.exe:*:Enabled:Freelancer
"c:\\WINDOWS\\system32\\PnkBstrA.exe"= c:\windows\system32\PnkBstrA.exe:*:Enabled

nkBstrA
"c:\\WINDOWS\\system32\\PnkBstrB.exe"= c:\windows\system32\PnkBstrB.exe:*:Enabled

nkBstrB
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"= c:\program files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM)
"c:\\Program Files\\Codemasters\\DiRT\\DiRT.exe"= c:\program files\Codemasters\DiRT\DiRT.exe:*

isabled

iRT Executable
"c:\\Program Files\\Codemasters\\GRID\\GRID.exe"= c:\program files\Codemasters\GRID\GRID.exe:*:Enabled:GRID
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"= c:\program files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"= c:\program files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player
"c:\\Documents and Settings\\Tim\\Desktop\\WiCKED-DOW2\\DOW2.exe"= c:\documents and settings\Tim\Desktop\WiCKED-DOW2\DOW2.exe:*

isabled

OW2
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= c:\program files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary
"c:\\Program Files\\EA GAMES\\Mercenaries 2 World in Flames\\Mercenaries2.exe"= c:\program files\EA GAMES\Mercenaries 2 World in Flames\Mercenaries2.exe:*:Enabled:Mercenaries 2: World in Flames
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"= c:\program files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe:*:Enabled:Far Cry 2 Updater
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"= c:\program files\Ubisoft\Far Cry 2\bin\FC2Editor.exe:*:Enabled:Editor
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"= c:\program files\Ubisoft\Far Cry 2\bin\FarCry2.exe:*:Enabled:Far Cry 2
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= c:\program files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:LocalSubNet:Enabled

xpsp2res.dll,-22004
"445:TCP"= 445:TCP:LocalSubNet:Enabled

xpsp2res.dll,-22005
"137:UDP"= 137:UDP:LocalSubNet:Enabled

xpsp2res.dll,-22001
"138:UDP"= 138:UDP:LocalSubNet:Enabled

xpsp2res.dll,-22002
"1900:UDP"= 1900:UDP:LocalSubNet

isabled

xpsp2res.dll,-22007
"2869:TCP"= 2869:TCP:LocalSubNet

isabled

xpsp2res.dll,-22008
"57533:TCP"= 57533:TCP:*:Enabled

ando Media Booster
"57533:UDP"= 57533:UDP:*:Enabled

ando Media Booster
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [8/9/2009 5:04 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/9/2009 5:04 PM 20560]
R2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [7/27/2009 3:05 AM 2560]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2/17/2009 3:35 PM 33792]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [11/23/2008 4:03 PM 110080]
S3 MEITUNER;FireBus MPEG2TS Tuner Subunit Device;c:\windows\system32\drivers\meistb.sys [3/6/2009 2:44 PM 22891]
S3 MFWAMIDI;MOTU FireWire Audio MIDI;c:\windows\system32\drivers\MFWAMIDI.sys [2/17/2009 3:30 PM 17024]
S3 MFWAWAVE;MOTU FireWire Audio Wave;c:\windows\system32\drivers\MFWAWave.sys [2/17/2009 3:30 PM 22656]
S3 MotuFWA;MotuFWA;c:\windows\system32\drivers\MotuFWA.sys [2/17/2009 3:30 PM 111616]
S3 MSPANEL;AVC Panel Device;c:\windows\system32\drivers\mstapeo.sys [3/6/2009 2:44 PM 49024]
S3 PciCon;PciCon;\??\d:\pcicon.sys --> d:\PciCon.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - PGFILTER
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService
Alerter
LmHosts
.
Contents of the 'Scheduled Tasks' folder
2009-07-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.msn.com
mStart Page = hxxp://www.msn.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Tim\Application Data\Mozilla\Firefox\Profiles\vjlg1qxr.default\
FF - prefs.js: browser.startup.homepage - hxxp://forums.spybot.info/
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\Tim\Application Data\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: c:\documents and settings\Tim\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-11 15:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1614895754-2111687655-1417001333-1003\Software\SecuROM\License information*]
"datasecu"=hex:2f,e9,e7,8b,71,e7,b3,a8,ed,eb,4f,37,6f,c6,4e,2e,10,1a,78,bf,67,
b0,89,4e,e4,25,d5,69,0d,17,2a,2f,4a,e0,df,7c,83,2e,c5,79,bd,be,2d,49,34,5d,\
"rkeysecu"=hex:39,8e,b4,03,43,b1,cb,7f,cd,57,48,f4,e3,f0,30,67
[HKEY_LOCAL_MACHINE\softwareSoftware\Classes\CLSID\{8D8763AB-E93B-4812-964E-F04E0008FD50}\Version]
@Denied: (A) (Everyone)
@="{8D8763AB-E93B-4812-964E-F04E0008FD50}"
[HKEY_LOCAL_MACHINE\softwareSoftware\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \D25BC253F035D347]
"1"=hex:6a,0b,56,13,c1,93,dc,9c,fb,61,a2,a0,e4,ff,91,20,60,bf,2f,c2,35,91,ae,
25
"2"=hex:fb,e6,50,7f,41,f4,51,a7,7f,ec,2d,f9,42,45,3a,02,3a,b7,45,15,3f,9d,8b,
c3
"3"=hex:6a,0b,56,13,c1,93,dc,9c,fb,61,a2,a0,e4,ff,91,20,5d,f5,58,d1,21,e0,48,
8b,38,57,44,9c,4e,8d,78,88,fd,f1,01,9d,86,d8,b5,cb,d9,bf,23,55,4a,bb,31,1f
[HKEY_LOCAL_MACHINE\softwareSoftware\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \D25BC253F035D347\B7F5EA513569EA3E98352E3A3D1D6A3D]
"1"=hex:df,c7,3a,96,ab,66,13,d2,36,78,6c,b8,10,1c,c4,b0,a6,93,a9,25,23,fb,66,
2c,77,d8,5d,6a,fe,59,6e,ef
"2"=hex:84,e0,11,4a,54,77,0e,d0
"3"=hex:81,20,8f,ab,28,6a,52,9c
"4"=hex:2f,ad,a2,e7,8a,bf,05,5e
"5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
"6"=hex:bf,e5,23,7b,b0,66,d6,fc,bc,64,22,fb,7e,d3,39,3e,a3,00,33,13,c0,21,f4,
51,6c,4e,0c,96,e2,dd,ad,8a,b6,c4,05,e8,5a,bd,9a,e9,d4,1a,3d,68,9d,00,32,20
"7"=hex:58,eb,3b,8d,af,31,32,62,22,1b,23,79,6d,f4,12,c1,db,b4,20,3e,7f,80,2a,
0f,6a,a6,22,9f,10,4c,a5,77,df,44,a4,37,10,4b,bc,75,d7,98,0e,82,a4,8d,85,b3,\
"8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,2e,4e,96,8c,7e,a3,52,
64,c9,4f,a5,f8,51,27,e9,29,77,5c,86,6d,0a,20,f9,c7,d0,f6,13,82,1b,05,61,d1,\
"9"=hex:81,20,8f,ab,28,6a,52,9c
"18"=hex:b6,dd,00,4d,9d,38,11,d1
"10"=hex:81,20,8f,ab,28,6a,52,9c
"11"=hex:81,20,8f,ab,28,6a,52,9c
"12"=hex:81,20,8f,ab,28,6a,52,9c
"13"=hex:81,20,8f,ab,28,6a,52,9c
"14"=hex:81,20,8f,ab,28,6a,52,9c
"24"=hex:81,20,8f,ab,28,6a,52,9c
"26"=hex:81,20,8f,ab,28,6a,52,9c
"27"=hex:81,20,8f,ab,28,6a,52,9c
"19"=hex:81,20,8f,ab,28,6a,52,9c
"22"=hex:81,20,8f,ab,28,6a,52,9c
.
Completion time: 2009-08-11 15:10
ComboFix-quarantined-files.txt 2009-08-11 19:10
ComboFix2.txt 2009-08-10 19:00
ComboFix3.txt 2009-08-10 16:15
Pre-Run: 339,019,460,608 bytes free
Post-Run: 339,058,253,824 bytes free
430 --- E O F --- 2009-08-10 16:38
Upload was successful
After I ran this, I couldn't get internet to run. I'd try to go to control panle to netowrk connections, and it would freeze. I did a restore to the latest point and then ran a dds.