Here it is.
ComboFix 10-05-10.02 - Gianluca Varenni 05/10/2010 20:21:27.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1265 [GMT -7:00]
Running from: c:\documents and settings\Gianluca Varenni\My Documents\Downloads\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\GIANLU~1\LOCALS~1\Temp\install_flash_player.exe
c:\documents and settings\Gianluca Varenni\Local Settings\Application Data\xyrkhwwoj
c:\documents and settings\Gianluca Varenni\Local Settings\Application Data\xyrkhwwoj\wscmrmqtssd.exe
c:\documents and settings\Gianluca Varenni\System
c:\documents and settings\Gianluca Varenni\System\win_qs8.jqx
.
((((((((((((((((((((((((( Files Created from 2010-04-11 to 2010-05-11 )))))))))))))))))))))))))))))))
.
2010-05-07 04:17 . 2010-05-07 04:17 -------- d-----w- c:\documents and settings\Gianluca Varenni\Application Data\Malwarebytes
2010-05-07 04:17 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-07 04:17 . 2010-05-07 04:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-07 04:17 . 2010-05-07 04:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-05-07 04:17 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-07 03:19 . 2010-05-06 15:00 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-05-06 15:01 . 2010-02-04 15:53 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-05-06 15:01 . 2010-05-06 15:00 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-06 14:52 . 2010-05-06 14:52 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-06 14:52 . 2010-02-04 15:53 2954656 -c--a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-05-06 14:50 . 2010-05-06 15:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-05-06 14:50 . 2010-05-06 14:52 -------- d-----w- c:\program files\Lavasoft
2010-04-18 21:14 . 2010-04-18 21:14 -------- d-----w- c:\documents and settings\Gianluca Varenni\Application Data\SmartDraw
2010-04-18 21:11 . 2010-04-18 21:14 -------- d-----w- c:\program files\SmartDraw 2010
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-11 03:24 . 2009-09-23 03:28 -------- d-----w- c:\documents and settings\Gianluca Varenni\Application Data\Skype
2010-05-11 03:13 . 2009-09-23 03:30 -------- d-----w- c:\documents and settings\Gianluca Varenni\Application Data\skypePM
2010-04-18 21:14 . 2009-09-23 02:46 12328 ----a-w- c:\documents and settings\Gianluca Varenni\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-10 06:11 . 2010-04-10 06:11 -------- d-----w- c:\program files\IKEA HomePlanner
2010-04-10 06:10 . 2010-04-10 06:10 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-03-30 05:25 . 2010-03-30 05:25 -------- d-----w- c:\program files\Common Files\Skype
2010-03-24 18:17 . 2010-03-24 08:04 952768 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\6125\AdobeARM.exe
2010-03-24 18:17 . 2010-03-24 08:04 70584 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\6125\AdobeExtractFiles.dll
2010-03-24 18:17 . 2010-03-24 08:04 326056 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\6125\ReaderUpdater.exe
2010-03-24 18:17 . 2010-03-24 08:04 326056 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\6125\AcrobatUpdater.exe
2010-03-09 11:09 . 2008-04-25 20:33 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-02-26 05:43 . 2008-04-25 20:33 667136 ----a-w- c:\windows\system32\wininet.dll
2010-02-26 05:43 . 2008-04-25 20:33 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-02-24 13:11 . 2008-04-25 20:33 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 14:08 . 2008-04-25 20:33 2146304 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2008-04-14 00:01 2024448 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2008-04-25 20:33 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2008-04-25 20:33 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Gianluca Varenni\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-09-23 133104]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"Aim"="c:\program files\AIM\aim.exe" [2009-09-16 3634024]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-03-09 26100520]
"\\sagre\EPSON NX100 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIEDA.EXE" [2008-02-04 188928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BTMeter"="c:\program files\Battery Meter\BTMeter.exe" [2008-07-11 537896]
"WLSS"="c:\program files\Wireless Select Switch\WLSS.exe" [2008-07-11 492840]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-13 16876032]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-14 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-14 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-14 137752]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-7-30 604776]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [9/22/2009 7:14 PM 9856]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/6/2010 8:01 AM 64288]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 8:52 AM 1285864]
R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [9/20/2009 11:46 AM 93968]
--- Other Services/Drivers In Memory ---
*Deregistered* - MBAMSwissArmy
.
Contents of the 'Scheduled Tasks' folder
2010-05-10 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 14:59]
2010-03-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3520309029-3036716248-3072606560-1006Core1cac72ac17536de.job
- c:\documents and settings\Gianluca Varenni\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-23 02:47]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.dell.com/
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-kknlfnja - c:\documents and settings\Gianluca Varenni\Local Settings\Application Data\xyrkhwwoj\wscmrmqtssd_.exe
HKLM-Run-kknlfnja - c:\documents and settings\Gianluca Varenni\Local Settings\Application Data\xyrkhwwoj\wscmrmqtssd_.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-10 20:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-05-10 20:29:37
ComboFix-quarantined-files.txt 2010-05-11 03:29
Pre-Run: 1,303,379,968 bytes free
Post-Run: 1,460,965,376 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 97AE1306C8CACDD4A0498CBAAA0E05C7