Attached is the Combofix log #1. I ran the ATF Cleaner after the Combfix log came up. I installed Malwarebytes, but it will not run. Currently, there are new Windows that I did not have before, or at least have not seen before. This one is entitled "Security Central". It came up after the Combofix ran.
I could not get the Malwarebytes to run yet, so my only log for you is Combofix.
ComboFix 09-10-27.07 - Mitchell 10/28/2009 7:43.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.665 [GMT -5:00]
Running from: c:\documents and settings\Mitchell\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\buxuhto.exe
c:\docume~1\Mitchell\LOCALS~1\Temp\svchost.exe
c:\docume~1\Mitchell\LOCALS~1\Temp\taskmgr.exe
c:\docume~1\Mitchell\LOCALS~1\Temp\winlogon.exe
c:\documents and settings\All Users\Application Data\29127627
c:\documents and settings\All Users\Application Data\29127627\29127627.bat
c:\documents and settings\All Users\Application Data\29127627\29127627.exe
c:\documents and settings\All Users\Application Data\55983333
c:\documents and settings\All Users\Application Data\55983333\55983333.exe
c:\documents and settings\All Users\Application Data\80165020
c:\documents and settings\All Users\Application Data\80165020\80165020.exe
c:\documents and settings\All Users\Application Data\ebedehil.sys
c:\documents and settings\All Users\Application Data\eqymyxy.reg
c:\documents and settings\All Users\Application Data\izylege.reg
c:\documents and settings\All Users\Application Data\kytakenud.com
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\okohonok.bin
c:\documents and settings\All Users\Application Data\ynibug.reg
c:\documents and settings\All Users\Documents\ylipu.pif
c:\documents and settings\Mitchell\Application Data\eviwaz._dl
c:\documents and settings\Mitchell\Application Data\lizkavd.exe
c:\documents and settings\Mitchell\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk
c:\documents and settings\Mitchell\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk
c:\documents and settings\Mitchell\Application Data\seres.exe
c:\documents and settings\Mitchell\Application Data\svcst.exe
c:\documents and settings\Mitchell\Cookies\nasugyfywi._dl
c:\documents and settings\Mitchell\Desktop\Advanced Virus Remover.lnk
c:\documents and settings\Mitchell\Desktop\AntivirusPro_2010.lnk
c:\documents and settings\Mitchell\Desktop\Security Tool.lnk
c:\documents and settings\Mitchell\Desktop\Windows Police Pro.lnk
c:\documents and settings\Mitchell\Local Settings\Application Data\{632C469C-F8C4-43F7-BD88-88568110F26D}
c:\documents and settings\Mitchell\Local Settings\Application Data\{632C469C-F8C4-43F7-BD88-88568110F26D}\chrome.manifest
c:\documents and settings\Mitchell\Local Settings\Application Data\{632C469C-F8C4-43F7-BD88-88568110F26D}\chrome\content\_cfg.js
c:\documents and settings\Mitchell\Local Settings\Application Data\{632C469C-F8C4-43F7-BD88-88568110F26D}\chrome\content\overlay.xul
c:\documents and settings\Mitchell\Local Settings\Application Data\{632C469C-F8C4-43F7-BD88-88568110F26D}\install.rdf
c:\documents and settings\Mitchell\Local Settings\Application Data\ejafaxuci._dl
c:\documents and settings\Mitchell\Local Settings\Application Data\yzazyherum.pif
c:\documents and settings\Mitchell\Local Settings\Temporary Internet Files\begydulare.exe
c:\documents and settings\Mitchell\Local Settings\Temporary Internet Files\uwyqohasu.dat
c:\documents and settings\Mitchell\Local Settings\Temporary Internet Files\xesiropa.db
c:\documents and settings\Mitchell\ntuser.dll
c:\documents and settings\Mitchell\Start Menu\Advanced Virus Remover.lnk
c:\documents and settings\Mitchell\Start Menu\Programs\AntivirusPro_2010
c:\documents and settings\Mitchell\Start Menu\Programs\AntivirusPro_2010\AntivirusPro_2010.lnk
c:\documents and settings\Mitchell\Start Menu\Programs\AntivirusPro_2010\Uninstall.lnk
c:\documents and settings\Mitchell\Start Menu\Programs\Security Tool.lnk
c:\documents and settings\Mitchell\Start Menu\Programs\Startup\scandisk.dll
c:\documents and settings\Mitchell\Start Menu\Programs\Startup\scandisk.lnk
c:\documents and settings\Mitchell\Start Menu\Programs\Windows Police Pro
c:\documents and settings\Mitchell\Start Menu\Programs\Windows Police Pro\Windows Police Pro.lnk
C:\dtacmawh.exe
c:\program files\AdvancedVirusRemover
c:\program files\AdvancedVirusRemover\PAVRM.exe
c:\program files\Antispyware
c:\program files\AntivirusPro_2010
c:\program files\AntivirusPro_2010\AntivirusPro_2010.cfg
c:\program files\AntivirusPro_2010\AntivirusPro_2010.exe
c:\program files\AntivirusPro_2010\AVEngn.dll
c:\program files\AntivirusPro_2010\data\daily.cvd
c:\program files\AntivirusPro_2010\htmlayout.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcm80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcp80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcr80.dll
c:\program files\AntivirusPro_2010\pthreadVC2.dll
c:\program files\AntivirusPro_2010\Uninstall.exe
c:\program files\AntivirusPro_2010\wscui.cpl
c:\program files\Common Files\beloho._sy
c:\program files\Common Files\bobejy.inf
c:\program files\Common Files\uzudypi.dll
c:\program files\Common Files\veteqijec.ban
c:\program files\Common Files\ybujofuk.com
c:\program files\Windows Police Pro
c:\program files\Windows Police Pro\msvcm80.dll
c:\program files\Windows Police Pro\msvcp80.dll
c:\program files\Windows Police Pro\msvcr80.dll
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\windows\cafyq.vbs
c:\windows\ceapoe.dll
c:\windows\epecefudar._sy
c:\windows\eqecatev.dll
c:\windows\qixerelyn.inf
c:\windows\svohost.exe
c:\windows\system32\_scui.cpl
c:\windows\system32\41.exe
c:\windows\system32\arizeg.dll
c:\windows\system32\AVR09.exe
c:\windows\system32\bincd32.dat
c:\windows\system32\calc.dll
c:\windows\system32\cpcp.cpo
c:\windows\system32\critical_warning.html
c:\windows\system32\drivers\npf.sys
c:\windows\system32\ehovolisu.reg
c:\windows\system32\fujobila.exe
c:\windows\system32\gibetara.exe
c:\windows\system32\husugudi.dll
c:\windows\system32\jifujeme.exe
c:\windows\system32\lepayuje.dll
c:\windows\system32\lijujepo.exe
c:\windows\system32\nuar.old
c:\windows\system32\nubobevu.dll
c:\windows\system32\Packet.dll
c:\windows\system32\pivojobe.exe
c:\windows\system32\plUGie.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\qadekih.reg
c:\windows\system32\schtml
c:\windows\system32\schtml\dbsinit.exe
c:\windows\system32\schtml\images\i1.gif
c:\windows\system32\schtml\images\i2.gif
c:\windows\system32\schtml\images\i3.gif
c:\windows\system32\schtml\images\j1.gif
c:\windows\system32\schtml\images\j2.gif
c:\windows\system32\schtml\images\j3.gif
c:\windows\system32\schtml\images\jj1.gif
c:\windows\system32\schtml\images\jj2.gif
c:\windows\system32\schtml\images\jj3.gif
c:\windows\system32\schtml\images\l1.gif
c:\windows\system32\schtml\images\l2.gif
c:\windows\system32\schtml\images\l3.gif
c:\windows\system32\schtml\images\pix.gif
c:\windows\system32\schtml\images\t1.gif
c:\windows\system32\schtml\images\t2.gif
c:\windows\system32\schtml\images\up1.gif
c:\windows\system32\schtml\images\up2.gif
c:\windows\system32\schtml\images\w1.gif
c:\windows\system32\schtml\images\w11.gif
c:\windows\system32\schtml\images\w2.gif
c:\windows\system32\schtml\images\w3.gif
c:\windows\system32\schtml\images\w3.jpg
c:\windows\system32\schtml\images\word.doc
c:\windows\system32\schtml\images\wt1.gif
c:\windows\system32\schtml\images\wt2.gif
c:\windows\system32\schtml\images\wt3.gif
c:\windows\system32\schtml\wispex.html
c:\windows\system32\skynet.dat
c:\windows\system32\terowuko.dll
c:\windows\system32\viveveno.dll
c:\windows\system32\voladeti.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\winhelper.dll
c:\windows\system32\winupdate.exe
c:\windows\system32\wpcap.dll
c:\windows\system32\yyW4l.dll
c:\windows\system32\zanumoyu.exe
c:\windows\system32\zazaliwu.dll
c:\windows\ucicihor._sy
c:\windows\zexetugozi.ban
----- BITS: Possible infected sites -----
hxxp://82.98.235.208
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_npf
-------\Legacy_WDefend
-------\Service_WDefend
((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-28 )))))))))))))))))))))))))))))))
.
2009-10-28 12:15 . 2009-10-28 12:15 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-10-28 12:15 . 2009-10-28 12:15 -------- d-----w- c:\program files\NETGEAR
2009-10-28 12:15 . 2007-12-26 15:47 272128 ----a-w- c:\windows\system32\drivers\wg111v2.sys
2009-10-28 12:15 . 2007-12-25 16:24 344064 ----a-w- c:\windows\system32\SCMLib.dll
2009-10-28 12:15 . 2007-12-18 20:46 266240 ----a-w- c:\windows\system32\WG1v2lib.dll
2009-10-28 12:15 . 2007-04-27 11:00 1069056 ----a-w- c:\windows\system32\libeay32.dll
2009-10-28 12:15 . 2006-07-27 19:26 36864 ----a-w- c:\windows\system32\RtlGina2.dll
2009-10-28 12:15 . 2005-07-20 09:53 966765 ----a-w- c:\windows\system32\acAuth.dll
2009-10-28 12:15 . 2005-01-25 19:30 143360 ----a-w- c:\windows\system32\IpLib.dll
2009-10-28 12:15 . 2009-10-28 12:15 -------- d-----w- c:\documents and settings\Mitchell\Application Data\InstallShield
2009-10-27 12:16 . 2009-10-27 12:16 -------- d-----w- c:\program files\Trend Micro
2009-10-23 18:51 . 2009-10-23 18:51 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-10-23 18:51 . 2009-10-23 18:51 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-20 15:26 . 2009-10-27 12:15 58 ----a-w- c:\windows\wp4.dat
2009-10-20 15:26 . 2009-10-27 12:15 3 ----a-w- c:\windows\wp3.dat
2009-10-20 15:22 . 2009-10-28 12:12 0 ----a-w- c:\windows\Kwosifopaniy.bin
2009-10-20 15:22 . 2009-10-22 17:36 120 ----a-w- c:\windows\Ibuvadikujik.dat
2009-10-20 15:20 . 2009-10-20 15:20 11169 ----a-w- c:\documents and settings\Mitchell\Local Settings\Application Data\wubev.dat
2009-10-20 15:20 . 2009-10-20 15:20 11044 ----a-w- c:\windows\xadymiz.dat
2009-10-20 15:19 . 2009-10-20 15:19 -------- d-----w- c:\program files\Security Central
2009-10-20 15:18 . 2009-10-20 15:18 53248 ----a-w- C:\ldvx.exe
2009-10-20 15:18 . 2009-10-20 15:18 27648 ----a-w- C:\vyiy.exe
2009-10-15 13:51 . 2009-10-15 13:51 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-28 12:32 . 2009-10-28 12:32 0 ---ha-w- c:\windows\system32\BIT8.tmp
2009-10-28 12:15 . 2004-07-30 20:23 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-28 05:01 . 2007-10-05 19:33 -------- d-----w- c:\program files\LogMeIn
2009-10-20 15:20 . 2009-10-20 15:20 17594 ----a-w- c:\documents and settings\Mitchell\Application Data\wanehebis.dat
2009-10-13 17:30 . 2006-09-13 13:05 -------- d-----w- c:\documents and settings\Mitchell\Application Data\AdobeUM
2009-10-13 12:41 . 2007-08-08 15:45 -------- d-----w- c:\program files\Access 97 Runtime
2009-10-02 20:17 . 2009-09-02 17:46 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-10-02 12:14 . 2007-10-05 19:33 83288 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2009-10-02 12:14 . 2007-10-05 19:33 28984 ----a-w- c:\windows\system32\LMIport.dll
2009-10-02 12:14 . 2007-10-05 19:33 87352 ----a-w- c:\windows\system32\LMIinit.dll
2009-09-28 18:45 . 2008-09-02 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-14 20:06 . 2004-07-30 20:28 98472 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-11 14:18 . 2004-03-19 22:40 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 12:00 . 2007-05-25 20:22 11552 ----a-w- c:\windows\system32\lmimirr2.dll
2009-09-09 12:00 . 2007-05-25 20:22 25248 ----a-w- c:\windows\system32\lmimirr.dll
2009-09-04 21:03 . 2004-03-30 01:48 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-02 17:46 . 2009-09-02 17:46 0 ----a-w- c:\windows\nsreg.dat
2009-09-02 17:46 . 2009-09-02 17:46 -------- d-----w- c:\documents and settings\Mitchell\Application Data\Thunderbird
2009-08-29 08:08 . 2006-06-23 15:33 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-03-19 22:43 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-07 00:24 . 2007-08-09 11:34 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-07 00:24 . 2007-08-09 11:34 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-07 00:24 . 2007-08-09 11:34 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-07 00:24 . 2007-04-17 02:45 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-07 00:24 . 2004-03-19 22:45 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-07 00:24 . 2004-03-19 22:34 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-07 00:23 . 2007-08-09 11:34 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-07 00:23 . 2004-03-19 22:45 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2002-12-12 05:14 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 15:13 . 1980-01-01 05:00 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 1980-01-01 05:00 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-07-20 15:24 . 2009-07-20 15:24 27136 --sha-w- c:\windows\SYSTEM32\lefopiwo.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2004-02-10 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2004-02-10 118784]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"DwlClient"="c:\program files\Common Files\Dell\EUSW\Support.exe" [2004-05-28 323584]
"Dell AIO Printer A920"="c:\program files\Dell AIO Printer A920\dlbkbmgr.exe" [2004-04-15 270336]
"AdobeVersionCue"="c:\program files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe" [2004-03-25 1732608]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 63048]
"PSDiagnosticM"="c:\program files\Linksys Wireless-G Print Server\PSDiagnosticM.exe" [2007-02-27 315392]
"mmtask"="c:\program files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe" [2006-01-17 53248]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-07-21 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Security Central"="c:\program files\Security Central\Security Central.exe" [2009-10-20 1317376]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
NETGEAR WG111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v2\WG111v2.exe [2009-10-28 1261568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-04 13:29 10520 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-10-02 12:14 87352 ----a-w- c:\windows\SYSTEM32\LMIinit.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Linksys Wireless-G Print Server\\PSDiagnosticM.exe"=
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/14/2009 6:12 PM 231704]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [4/17/2007 2:00 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\SYSTEM32\DRIVERS\LMIRfsDriver.sys [10/5/2007 2:33 PM 47640]
R3 lknuhst;Linksys Network USB Host Controller;c:\windows\SYSTEM32\DRIVERS\lknuhst.sys [4/30/2008 11:37 AM 11136]
R3 LKNUHUB;Linksys Network USB Root Hub;c:\windows\SYSTEM32\DRIVERS\lknuhub.sys [4/30/2008 11:37 AM 37248]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\SYSTEM32\DRIVERS\wg111v2.sys [10/28/2009 7:15 AM 272128]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [1/14/2009 6:12 PM 325128]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.jics.org/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {4EF5B7A8-C522-4373-A8E7-561515415A95} = 208.67.222.222,208.67.220.220
.
- - - - ORPHANS REMOVED - - - -
BHO-{becffbca-413b-49e7-9cd7-164ff7952903} - nubobevu.dll
HKCU-Run-inixs - c:\windows\system32\minix32.exe
HKLM-Run-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
HKLM-Run-Xbifugahopir - c:\windows\eqecatev.dll
HKLM-Run-29127627 - c:\documents and settings\All Users\Application Data\29127627\29127627.exe
HKLM-Run-hitimozem - c:\windows\system32\terowuko.dll
HKLM-Run-55983333 - c:\docume~1\ALLUSE~1\APPLIC~1\55983333\55983333.exe
HKLM-Run-vasazilegu - viveveno.dll
SharedTaskScheduler-{e536cd76-e145-4ba9-a092-b85f28cc7ee5} - c:\windows\system32\terowuko.dll
SSODL-kiguzunuk-{e536cd76-e145-4ba9-a092-b85f28cc7ee5} - c:\windows\system32\terowuko.dll
AddRemove-AVG8Uninstall - c:\program files\AVG\AVG8\setup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-28 07:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DwlClient = c:\program files\Common Files\Dell\EUSW\Support.exe?l?e?s?\?D?e?l?l?\?E?U?S?W?\?S?u?p?p?o?r?t?.?e?x ?e???x???x???????????????????x???X???????x???x???????????x???8???????x???x? ?????????? ???????????0????????????????D?w????????????7??w????x???x??????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01 ,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c9,a8,95,a7,66,f3,c0,46,83,5b,68, \
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01 ,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c9,a8,95,a7,66,f3,c0,46,83,5b,68, \
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(892)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
- - - - - - - > 'explorer.exe'(2744)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\LMIRfsClientNP.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\EPSON\EBAPI\eEBSVC.exe
c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\mysql\bin\mysqld-max-nt.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\combofix\CF26623.exe
c:\program files\Dell AIO Printer A920\dlbkbmon.exe
c:\program files\Dell\Support\Alert\bin\NotifyAlert.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\combofix\PEV.cfxxe
.
**************************************************************************
.
Completion time: 2009-10-28 8:01 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-28 13:00
Pre-Run: 122,124,144,640 bytes free
Post-Run: 122,264,330,240 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - 983A51BFF49A823BD6EF65FF64083307