Here you go!
ComboFix 09-02-12.03 - HP_Administrator 2009-02-14 1:40:23.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2462 [GMT -8:00]
Running from: c:\documents and settings\HP_Administrator\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\HP_Administrator\Desktop\CFScript.txt
AV: Norton Internet Security 2006 *On-access scanning enabled* (Updated)
FW: Norton Internet Security 2006 *enabled*
* Created a new restore point
FILE ::
c:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\zskenoxzyz.dll
c:\windows\Imudeca.dll
c:\windows\system32\jkse73hedfdgf.dll
c:\windows\system32\svñshost.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\zskenoxzyz.dll
c:\windows\Imudeca.dll
c:\windows\system32\jkse73hedfdgf.dll
c:\windows\system32\svñshost.exe
.
((((((((((((((((((((((((( Files Created from 2009-01-14 to 2009-02-14 )))))))))))))))))))))))))))))))
.
2009-05-08 11:33 . 2009-05-08 11:34 <DIR> d-------- c:\program files\Pidgin
2009-05-08 11:33 . 2009-05-08 11:33 <DIR> d-------- c:\program files\Common Files\GTK
2009-05-08 09:49 . 2009-05-08 09:49 <DIR> d-------- c:\program files\Common Files\Logitech
2009-05-07 23:53 . 2009-05-07 23:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\acccore
2009-05-07 23:52 . 2009-05-07 23:53 <DIR> d-------- c:\program files\AIM6
2009-02-13 09:58 . 2009-02-13 09:58 <DIR> d-------- C:\ComboFixx
2009-02-12 11:34 . 2009-02-12 12:59 345 --a------ c:\windows\gmer.ini
2009-02-12 11:12 . 2009-02-12 11:22 <DIR> d-------- c:\windows\SxsCaPendDel
2009-02-12 11:12 . 2009-02-12 11:12 <DIR> d-------- C:\ed3927e1f4abb5049863e3732651
2009-02-05 17:20 . 2009-02-05 17:25 <DIR> d-------- c:\windows\NV57605824.TMP
2009-02-05 07:28 . 2009-02-05 08:02 <DIR> d-------- C:\ComboFix
2009-02-05 05:21 . 2009-02-05 05:21 <DIR> d-------- C:\OnlineArmor
2009-02-05 05:19 . 2009-02-05 05:21 <DIR> d-------- c:\program files\SpywareBlaster
2009-02-05 05:14 . 2009-02-05 05:14 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-02-05 05:08 . 2009-02-05 05:08 <DIR> d-------- c:\program files\ERUNT
2009-02-05 05:01 . 2009-02-05 05:01 <DIR> d-------- c:\program files\Trend Micro
2009-02-05 04:58 . 2009-02-05 04:58 <DIR> d-------- C:\VundoFix Backups
2009-01-27 11:54 . 2009-01-27 11:54 <DIR> d-------- c:\program files\Common Files\Skype
2009-01-27 11:54 . 2009-01-27 11:54 56 --ah----- c:\windows\system32\ezsidmv.dat
2009-01-21 14:21 . 2009-01-21 14:21 <DIR> d-------- c:\program files\MSBuild
2009-01-21 14:20 . 2009-02-12 11:13 <DIR> d-------- c:\windows\system32\XPSViewer
2009-01-21 14:20 . 2009-01-21 14:20 <DIR> d-------- c:\program files\Reference Assemblies
2009-01-21 14:19 . 2006-06-29 13:07 14,048 --a------ c:\windows\system32\spmsg2.dll
2009-01-21 14:17 . 2009-01-21 14:18 <DIR> d-------- c:\program files\Microsoft Games for Windows - LIVE
2009-01-21 14:16 . 2008-07-12 08:18 3,851,784 --a------ c:\windows\system32\D3DX9_39.dll
2009-01-21 14:16 . 2008-07-12 08:18 1,493,528 --a------ c:\windows\system32\D3DCompiler_39.dll
2009-01-21 14:16 . 2008-07-31 10:40 509,448 --a------ c:\windows\system32\XAudio2_2.dll
2009-01-21 14:16 . 2008-07-12 08:18 467,984 --a------ c:\windows\system32\d3dx10_39.dll
2009-01-21 14:16 . 2008-07-31 10:41 238,088 --a------ c:\windows\system32\xactengine3_2.dll
2009-01-21 14:16 . 2008-07-31 10:41 68,616 --a------ c:\windows\system32\XAPOFX1_1.dll
2009-01-20 10:54 . 2009-02-05 05:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-01-19 02:16 . 2009-01-19 02:19 <DIR> d-------- c:\windows\NV22482176.TMP
2009-01-16 20:07 . 2009-01-16 20:24 <DIR> d-------- C:\Fraps
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-08 07:53 --------- d-----w c:\program files\Common Files\AOL
2009-05-08 07:53 --------- d-----w c:\documents and settings\HP_Administrator\Application Data\acccore
2009-05-08 07:38 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2009-02-14 08:56 --------- d-----w c:\program files\Steam
2009-02-12 17:38 --------- d-----w c:\program files\World of Warcraft
2009-02-09 01:34 --------- d-----w c:\program files\Magic Workstation
2009-02-07 09:01 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-05 13:43 --------- d-----w c:\program files\Electronic Arts
2009-02-05 13:34 --------- d-----w c:\program files\Soulseek
2009-02-05 13:14 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-02-05 13:12 --------- d-----w c:\program files\Java
2009-01-29 07:20 66,872 ----a-w c:\windows\system32\PnkBstrA.exe
2009-01-29 07:20 22,328 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-01-29 07:20 22,328 ----a-w c:\documents and settings\HP_Administrator\Application Data\PnkBstrK.sys
2009-01-29 07:20 2,250,024 ----a-w c:\windows\system32\pbsvc.exe
2009-01-29 07:20 107,832 ----a-w c:\windows\system32\PnkBstrB.exe
2009-01-28 10:54 --------- d-----w c:\documents and settings\HP_Administrator\Application Data\Skype
2009-01-28 08:04 --------- d-----w c:\documents and settings\HP_Administrator\Application Data\skypePM
2009-01-20 18:49 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-01-20 18:48 --------- d-----w c:\program files\AGEIA Technologies
2009-01-13 10:24 --------- d-----w c:\documents and settings\HP_Administrator\Application Data\uTorrent
2009-01-09 01:07 --------- d-----w c:\documents and settings\HP_Administrator\Application Data\.purple
2009-01-01 21:05 --------- d-----w c:\program files\Apple Software Update
2009-01-01 21:05 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2009-01-01 21:04 --------- d-----w c:\program files\QuickTime
2009-01-01 21:04 --------- d-----w c:\program files\Common Files\Apple
2009-01-01 21:04 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-29 11:26 --------- d-----w c:\program files\CCleaner
2008-12-26 20:44 --------- d-----w c:\program files\Common Files\LogiShrd
2008-12-26 20:41 --------- d-----w c:\program files\Logitech
2008-12-26 20:41 --------- d-----w c:\documents and settings\All Users\Application Data\Logishrd
2008-12-26 08:08 453,152 ----a-w c:\windows\system32\nvudisp.exe
2008-12-24 05:58 453,152 ----a-w c:\windows\system32\NVUNINST.EXE
2008-12-12 17:01 3,067,904 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-11 20:37 42,320 ----a-w c:\windows\system32\xfcodec.dll
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\dllcache\srv.sys
2008-12-10 17:45 70,936 ----a-w c:\windows\system32\PhysXLoader.dll
2008-12-05 11:25 133,120 ----a-w c:\windows\utigimogoyineba.dll
2008-12-04 17:28 24,344 ----a-w c:\windows\system32\PhysXDevice.dll
2008-11-26 16:55 288,024 ----a-w c:\windows\system32\PhysXCplUI.exe
2008-11-25 16:38 288,024 ----a-w c:\windows\system32\PhysXCompatCplUI.exe
2007-12-03 19:59 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2007-10-17 06:11 140,202,521 ----a-w c:\documents and settings\HP_Administrator\WoW-2.2.3.7359-to-0.3.0.7382-enUS-patch.exe
.
((((((((((((((((((((((((((((( SnapShot_2009-02-13_10.09.53.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-13 18:42:46 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_6c8.dat
+ 2009-02-13 18:42:56 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_a90.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-11 68856]
"Steam"="c:\program files\Steam\Steam.exe" [2008-10-07 1410296]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-10-21 50472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 49152]
"DISCover"="c:\program files\DISC\DISCover.exe" [2006-03-15 1077248]
"DiscUpdateManager"="c:\program files\DISC\DiscUpdMgr.exe" [2006-03-15 61440]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-03-20 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-09-16 52848]
"IS CfgWiz"="c:\program files\Norton Internet Security\cfgwiz.exe" [2005-09-29 120464]
"SSC_UserPrompt"="c:\program files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [2004-11-02 218240]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-13 663552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-15 13680640]
"lxdcamon"="c:\program files\Lexmark 1300 Series\lxdcamon.exe" [2007-04-30 20480]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 77824]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-05 148888]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-15 86016]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 c:\windows\arpwrmsg.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 c:\windows\RTHDCPL.exe]
"kmw_run.exe"="kmw_run.exe" [2005-09-01 c:\windows\system32\kmw_run.exe]
"nwiz"="nwiz.exe" [2009-01-15 c:\windows\system32\nwiz.exe]
"P17Helper"="P17.dll" [2006-03-17 c:\windows\system32\P17.dll]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"vidc.wmv3"= c:\progra~1\COMBIN~1\Filters\wmv9vcm.dll
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ccSetMgr"=2 (0x2)
"SPBBCSvc"=3 (0x3)
"ccProxy"=2 (0x2)
"SNDSrvc"=3 (0x3)
"ccISPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"Symantec Core LC"=3 (0x3)
"SAVScan"=3 (0x3)
"NSCService"=3 (0x3)
"navapsvc"=2 (0x2)
"MDM"=2 (0x2)
"LightScribeService"=2 (0x2)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Documents and Settings\\HP_Administrator\\Desktop\\DLSystems\\utorrent.exe"=
"c:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.1\\cnc3game.dat"=
"c:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.2\\cnc3game.dat"=
"c:\\WINDOWS\\system32\\lxdccoms.exe"=
"c:\\Program Files\\Lexmark 1300 Series\\lxdcamon.exe"=
"c:\\Program Files\\Lexmark 1300 Series\\App4R.exe"=
"c:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.3\\cnc3game.dat"=
"c:\\Program Files\\Electronic Arts\\Command & Conquer 3 Kane's Wrath\\cnc3ep1.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdctime.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdcjswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdcpswx.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\saints row 2\\SR2_pc.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\mass effect\\Binaries\\MassEffect.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\painkiller gold edition\\Bin\\Painkiller.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\stalker shadow of chernobyl\\bin\\XR_3DA.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\peggle extreme\\PeggleExtreme.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\far cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\far cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\far cry 2\\bin\\FC2BenchmarkTool.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\far cry 2\\bin\\FC2ServerLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\advent rising\\System\\advent.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\painkiller gold edition\\Bin\\Editor\\PainEditor.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Blizzard Downloader
R2 lxdc_device;lxdc_device;c:\windows\system32\lxdccoms.exe -service --> c:\windows\system32\lxdccoms.exe -service [?]
R2 lxdcCATSCustConnectService;lxdcCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdcserv.exe [2008-01-14 99248]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-05-22 24652]
R3 p17filt;p17filt;c:\windows\system32\drivers\p17filt.sys [2006-03-20 1452032]
S3 CXFALCON;Conexant Falcon II NTSC Video Capture;c:\windows\system32\drivers\cxfalcon.sys [2006-11-01 82048]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
2009-02-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2006-11-01 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-09-09 14:21]
2009-02-08 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
2008-02-03 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PAVILION&pf=desktop
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=63&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: trymedia.com
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\d48nlogv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.mmo-champion.com/
FF - plugin: c:\program files\Microsoft Silverlight\npctrl.1.0.21115.0.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdsplay.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwmsdrm.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-14 01:44:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2087127818-4242576237-1562189658-1008\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:5b,1a,34,e9,b5,e2,d2,72,a8,ec,24,47,18,ae,ea,95,18,b8,42,64,75,38,68,
01,91,78,e7,72,4c,d4,b1,ab,34,fc,c9,36,3c,9b,27,ec,e2,97,d0,3a,a9,94,a1,5d,\
"??"=hex:98,92,76,c1,aa,88,4f,41,49,86,ff,73,28,c6,e6,0d
[HKEY_USERS\S-1-5-21-2087127818-4242576237-1562189658-1008\Software\SecuROM\License information*]
"datasecu"=hex:20,31,52,82,cf,78,84,fa,23,66,b3,6b,9c,cf,55,b7,bd,69,22,84,31,
84,eb,32,9b,44,fb,ca,2c,6d,b6,c0,14,cb,83,7a,81,ce,d8,23,e3,eb,c0,20,30,12,\
"rkeysecu"=hex:7d,40,10,cb,c7,39,e0,67,0a,69,a8,47,07,da,5b,5c
.
Completion time: 2009-02-14 1:45:45
ComboFix-quarantined-files.txt 2009-02-14 09:45:43
ComboFix2.txt 2009-02-13 18:11:02
ComboFix3.txt 2009-02-12 17:33:26
Pre-Run: 121,566,175,232 bytes free
Post-Run: 121,607,036,928 bytes free
294 --- E O F --- 2009-01-14 03:06:50