Hello,
Hope you had a good time! (Wish I had a BBQ right now)... Did Florida Gators win?
Anyway here is the log. Lol you know everything about my computer now with all them details

. I did uninstall uTorrent by the way, so I don't know why it is still there :/
ComboFix 09-09-25.01 - malli 09/26/2009 16:03.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1564 [GMT 1:00]
Running from: c:\documents and settings\malli\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\malli\Local Settings\Temporary Internet Files\mcc182.tmp
c:\documents and settings\malli\Local Settings\Temporary Internet Files\mcc268.tmp
c:\documents and settings\malli\Local Settings\Temporary Internet Files\mccB765.tmp
c:\documents and settings\malli\Local Settings\Temporary Internet Files\mccBE.tmp
c:\documents and settings\malli\Local Settings\Temporary Internet Files\mccD90B.tmp
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
c:\windows\Installer\f240eb.msi
c:\windows\system\update.exe
c:\windows\system32\tmp74.tmp
c:\windows\system32\tmp75.tmp
D:\AUTORUN.INF
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
((((((((((((((((((((((((( Files Created from 2009-08-26 to 2009-09-26 )))))))))))))))))))))))))))))))
.
2009-09-23 01:06 . 2009-09-23 01:06 -------- d-----w- c:\program files\ESET
2009-09-22 22:03 . 2009-09-22 22:03 -------- d-----w- c:\documents and settings\malli\Application Data\Malwarebytes
2009-09-22 22:03 . 2009-09-10 13:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-22 22:03 . 2009-09-22 22:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-22 22:03 . 2009-09-22 22:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-22 22:03 . 2009-09-10 13:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-22 21:49 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-09-22 21:49 . 2009-09-22 21:49 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-09-22 21:49 . 2009-09-22 21:49 -------- d-----w- c:\program files\Lavasoft
2009-09-22 14:48 . 2009-09-22 21:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-09-22 14:30 . 2009-09-22 21:44 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-20 23:03 . 2009-09-22 13:02 -------- d-----w- c:\documents and settings\malli\Local Settings\Application Data\AVG Security Toolbar(2)
2009-09-20 23:02 . 2009-09-22 13:02 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar(2)
2009-09-20 22:50 . 2009-09-26 09:15 0 ----a-r- c:\windows\win32k.sys
2009-09-20 18:35 . 2009-09-22 13:05 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8(2)
2009-09-20 16:22 . 2009-09-22 13:06 -------- d-----w- c:\program files\Monitor Calibration Wizard
2009-09-20 15:10 . 2009-09-20 15:10 -------- d-----w- c:\windows\system32\wbem\Repository
2009-09-18 23:44 . 2009-09-18 23:44 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-09-18 23:44 . 2009-07-15 10:48 29000 ----a-w- c:\windows\system32\uxtuneup.dll
2009-09-18 23:44 . 2009-09-18 23:44 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-09-18 23:44 . 2009-09-18 23:44 -------- d-----w- c:\documents and settings\malli\Application Data\TuneUp Software
2009-09-18 23:44 . 2009-09-18 23:44 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-09-18 23:44 . 2009-09-18 23:44 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-09-18 19:12 . 2009-09-18 19:12 -------- d-----w- c:\windows\system32\AGEIA
2009-09-18 19:12 . 2009-09-18 19:12 -------- d-----w- c:\program files\AGEIA Technologies
2009-09-05 06:49 . 2009-09-05 06:49 45 ----a-w- c:\documents and settings\malli\jagex_runescape_preferences2.dat
2009-08-31 12:42 . 2009-08-31 12:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-26 01:04 . 2009-05-24 20:11 -------- d-----w- c:\documents and settings\malli\Application Data\uTorrent
2009-09-22 21:41 . 2009-07-19 13:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-22 21:28 . 2009-09-21 20:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-22 13:01 . 2009-09-21 00:03 -------- d-----w- c:\documents and settings\malli\Application Data\WinPatrol
2009-09-22 13:01 . 2009-08-06 00:54 -------- d-----w- c:\program files\Opera
2009-09-20 15:09 . 2009-08-20 22:26 774088 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-09-20 15:08 . 2009-07-19 12:25 -------- d-----w- c:\documents and settings\malli\Application Data\Bioshock
2009-09-20 01:49 . 2009-07-30 04:00 -------- d-----w- c:\documents and settings\malli\Application Data\IMVU
2009-09-19 00:56 . 2009-06-18 19:05 57656 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-10 00:27 . 2009-05-28 22:29 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-10 00:21 . 2009-05-29 06:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-05 06:49 . 2009-08-24 12:30 37 ----a-w- c:\documents and settings\malli\jagex_runescape_preferences.dat
2009-08-28 02:46 . 2009-07-30 03:59 -------- d-----w- c:\documents and settings\malli\Application Data\IMVUClient
2009-08-24 13:43 . 2009-05-24 14:08 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-24 12:55 . 2009-08-24 12:53 -------- d-----w- c:\program files\MixMeister Fusion
2009-08-24 12:54 . 2009-08-24 12:54 -------- d-----w- c:\documents and settings\malli\Application Data\MixMeister Technology
2009-08-20 22:12 . 2009-08-20 22:10 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverScanner
2009-08-20 22:10 . 2009-08-20 22:09 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2009-08-20 22:10 . 2009-08-20 22:02 -------- d-----w- c:\documents and settings\malli\Application Data\uniblue
2009-08-20 22:10 . 2009-08-20 22:00 -------- d-----w- c:\program files\Uniblue
2009-08-20 22:07 . 2009-08-20 22:07 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-08-20 22:05 . 2009-08-20 22:05 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}
2009-08-18 11:44 . 2009-08-18 11:44 128 ----a-w- c:\documents and settings\malli\Local Settings\Application Data\fusioncache.dat
2009-08-17 16:10 . 2009-05-24 14:36 72624 ----a-w- c:\documents and settings\malli\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-17 15:06 . 2009-06-08 16:32 -------- d-----w- c:\program files\Safari
2009-08-17 11:48 . 2009-08-17 11:48 -------- d-----w- c:\program files\GameSpy
2009-08-17 11:45 . 2009-08-17 11:45 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-08-17 11:45 . 2009-08-17 11:45 22328 ----a-w- c:\documents and settings\malli\Application Data\PnkBstrK.sys
2009-08-17 11:45 . 2009-08-17 11:45 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-08-17 11:45 . 2009-08-17 11:45 669184 ----a-w- c:\windows\system32\pbsvc.exe
2009-08-17 11:45 . 2009-08-17 11:45 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-08-14 22:29 . 2009-06-03 15:03 -------- d-----w- c:\program files\Vodafone PC Assistant
2009-08-14 05:58 . 2009-09-22 14:35 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-08-14 00:45 . 2009-08-14 00:45 -------- d-----w- c:\documents and settings\malli\Application Data\Amazon
2009-08-10 10:27 . 2009-08-09 09:08 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-08-09 09:08 . 2009-08-09 09:08 -------- d-----w- c:\documents and settings\malli\Application Data\Atari
2009-08-09 09:08 . 2009-08-09 09:08 -------- d-----w- c:\program files\Common Files\PocketSoft
2009-08-06 12:52 . 2009-05-25 00:05 -------- d-----w- c:\program files\Java
2009-08-06 07:37 . 2009-07-19 18:31 82548 ----a-w- c:\windows\War3Unin.dat
2009-08-05 09:01 . 2008-04-14 12:42 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 20:55 . 2009-08-04 20:55 -------- d-----w- c:\program files\Combined Community Codec Pack
2009-08-04 20:48 . 2009-08-04 20:48 -------- d-----w- c:\documents and settings\malli\Application Data\Media Player Classic
2009-08-03 14:07 . 2009-08-03 14:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
2009-08-03 14:07 . 2009-08-03 14:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
2009-08-03 14:07 . 2009-08-03 14:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
2009-07-31 21:45 . 2009-05-24 17:45 -------- d-----w- c:\documents and settings\malli\Application Data\SPORE
2009-07-25 04:23 . 2009-05-25 00:05 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-20 08:34 . 2009-07-20 08:34 70936 ----a-w- c:\windows\system32\PhysXLoader.dll
2009-07-19 18:45 . 2009-07-19 18:31 2829 ----a-w- c:\windows\War3Unin.pif
2009-07-19 18:45 . 2009-07-19 18:31 139264 ----a-w- c:\windows\War3Unin.exe
2009-07-17 19:01 . 2008-04-14 12:41 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 22:43 . 2009-01-12 02:51 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2009-01-12 02:43 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 18:38 . 2009-06-29 18:38 33061 ----a-w- c:\windows\king-uninstall.exe
.
------- Sigcheck -------
[-] 2009-01-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-07 3885408]
"Google Update"="c:\documents and settings\malli\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-08-12 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"btbb_McciTrayApp"="c:\program files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe" [2008-09-11 1517056]
"btbb_wcm_McciTrayApp"="c:\program files\BT Broadband Desktop Help\btbb_wcm\McciTrayApp.exe" [2007-11-29 1474048]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Acrobat Assistant 8.0"="d:\documents\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-18 1848648]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-05-20 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_2"="shell32" [X]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Windows*Updates"=c:\windows\system\Update.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Acrobat Speed Launcher"="d:\documents\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Windows*Updates"=c:\windows\system\Update.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS4\\Server\\bin\\VersionCueCS4.exe"=
"c:\\Program Files\\Codemasters\\GRID Demo\\GRID.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\BT Broadband Desktop Help\\btbb\\BTHelpBrowser.exe"=
"c:\\Program Files\\BT Broadband Desktop Help\\btbb\\BTHelpNotifier.exe"=
"d:\\Games\\Street Fighter\\StreetFighterIV.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Games\\Crysis\\Bin32\\Crysis.exe"=
"d:\\Games\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"3703:TCP"= 3703:TCP:Adobe Version Cue CS4 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS4 Server
"51000:TCP"= 51000:TCP:Adobe Version Cue CS4 Server
"51001:TCP"= 51001:TCP:Adobe Version Cue CS4 Server
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [9/22/2009 10:49 PM 64160]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [9/19/2009 12:44 AM 604488]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [4/1/2009 12:28 PM 93184]
S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\IS360srv.exe --> c:\program files\IObit\IObit Security 360\IS360srv.exe [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 3:49 PM 1029456]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [8/15/2008 5:46 AM 284016]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys --> c:\windows\system32\drivers\Ambfilt.sys [?]
S3 m4301a;Linksys Wireless-B USB Network Adapter v4.0 Driver;c:\windows\system32\drivers\m4301A.sys [5/24/2009 2:33 AM 83552]
S3 MobileAdapter;Huawei Mobile Adapter USB Modem and USB Serial;c:\windows\system32\drivers\hmvmdm.sys [6/3/2009 4:04 PM 101120]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{Y8OBC5C0-4FCB-11CF-AAX5-81CX1C635612}]
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\svchost.exe
.
Contents of the 'Scheduled Tasks' folder
2009-09-26 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 09:54]
2009-09-22 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]
2009-09-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-09-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1757981266-343818398-1003Core.job
- c:\documents and settings\malli\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-12 18:29]
2009-09-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1390067357-1757981266-343818398-1003UA.job
- c:\documents and settings\malli\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-12 18:29]
2009-09-26 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-24 21:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\malli\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: motive.com\pbttbc.bt
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath - c:\documents and settings\malli\Application Data\Mozilla\Firefox\Profiles\t6a4xpzc.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: keyword.URL - hxxp://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_uk&p=
FF - component: c:\documents and settings\malli\Application Data\Mozilla\Firefox\Profiles\t6a4xpzc.default\extensions\{4037A226-F33F-427c-803C-DB710DB665EA}\components\bhelper.dll
FF - plugin: c:\documents and settings\malli\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmidas.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: d:\documents\Adobe\Acrobat 9.0\Acrobat\browser\nppdf32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
Notify-avgrsstarter - avgrsstx.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-26 16:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1390067357-1757981266-343818398-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:18,31,d7,88,02,a1,22,5b,72,64,de,ec,06,41,96,78,bd,40,ca,f9,4a,06,dc,
1e,5f,6c,b0,ce,2e,dd,1b,b2,96,a8,61,cd,cc,70,c8,48,9b,49,7a,57,4e,2e,0e,52,\
"??"=hex:cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b,19,52,fe,22
[HKEY_USERS\S-1-5-21-1390067357-1757981266-343818398-1003\Software\SecuROM\License information*]
"datasecu"=hex:c8,7c,4d,99,e0,20,ed,71,18,8f,91,7b,5d,18,c7,37,3b,0c,47,d4,16,
d3,6a,7f,79,48,5d,6e,7e,9d,29,b8,8d,fe,8e,21,8e,bd,cc,86,f5,00,da,f1,ef,ef,\
"rkeysecu"=hex:64,b6,bd,e1,3e,80,9e,c4,40,b4,90,83,87,8e,33,49
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(820)
c:\windows\system32\Ati2evxx.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(2876)
c:\windows\system32\WININET.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\devldr32.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-09-26 16:15 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-26 15:15
Pre-Run: 8,892,325,888 bytes free
Post-Run: 8,996,417,536 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
297 --- E O F --- 2009-09-10 00:24
Thank you,
(*$malli$*)