Hi ali,
Thanks for the quick response!
While reading your post, I got my first pop up since MBAM, this time it was loading a geeks to go url followed by a random string of characters.
Combofix did not prompt me to install the recovery console, so I guess I already have it.
After starting Combofix, it detected a rootkit and needed to reboot. Afterwards, my taskbar and desktop icons didn't come up, but the Windows Genuine prompt showed up before Combofix reappeared. The scan was completed and the log is below.
I don't know if it's relevant, but getting back on the internet, IE is no longer my default browser
_ _ _ _ _
ComboFix 10-06-24.03 - default 06/25/2010 6:44.2.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.237 [GMT -4:00]
Running from: c:\documents and settings\default\Desktop\PC Tools\tools from geeks to go\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
FW: ZoneAlarm Pro Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system\Drivers
c:\windows\system\Drivers\hp53pw2k.sys
c:\windows\xpsp1hfm.log
Infected copy of c:\windows\system32\drivers\dmio.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((( Files Created from 2010-05-25 to 2010-06-25 )))))))))))))))))))))))))))))))
.
2010-06-25 07:02 . 2010-06-25 07:02 -------- d-----w- c:\windows\system32\KB905474
2010-06-25 00:03 . 2010-06-25 00:03 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-06-24 21:51 . 2010-06-24 21:51 -------- d-----w- c:\program files\ERUNT
2010-06-24 21:40 . 2010-06-24 21:40 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-06-22 05:21 . 2010-06-22 05:21 -------- d-----w- c:\documents and settings\default\Application Data\ylanukmgh
2010-06-22 05:21 . 2010-06-22 05:21 -------- d-----w- c:\documents and settings\default\Application Data\ylanukmgh
2010-06-03 06:08 . 2010-06-03 06:08 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Matrox
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-25 01:54 . 2009-09-06 13:49 1316 ----a-w- c:\windows\system32\d3d8caps.dat
2010-06-24 05:25 . 2007-04-03 00:06 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-05-25 22:02 . 2010-05-25 22:02 503808 ----a-w- c:\documents and settings\default\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6d509401-n\msvcp71.dll
2010-05-25 22:02 . 2010-05-25 22:02 499712 ----a-w- c:\documents and settings\default\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6d509401-n\jmc.dll
2010-05-25 22:02 . 2010-05-25 22:02 348160 ----a-w- c:\documents and settings\default\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6d509401-n\msvcr71.dll
2010-05-25 22:02 . 2010-05-25 22:02 61440 ----a-w- c:\documents and settings\default\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3275dc46-n\decora-sse.dll
2010-05-25 22:02 . 2010-05-25 22:02 12800 ----a-w- c:\documents and settings\default\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3275dc46-n\decora-d3d.dll
2010-05-19 04:44 . 2010-05-19 04:44 1 ----a-w- c:\documents and settings\default\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-19 04:44 . 2010-05-19 04:44 -------- d-----w- c:\documents and settings\default\Application Data\OpenOffice.org
2010-05-19 04:40 . 2010-05-19 04:40 -------- d-----w- c:\program files\JRE
2010-05-19 04:40 . 2010-05-19 04:40 -------- d-----w- c:\program files\OpenOffice.org 3
2010-05-19 04:38 . 2009-08-13 17:50 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-04-29 19:39 . 2009-07-02 07:58 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2009-07-02 07:58 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2003-11-07 04:11 . 2001-01-30 15:20 1439 ----a-w- c:\program files\GUIDE PLUS+ System (2).lnk
2003-11-07 04:11 . 2001-01-21 04:30 1439 ----a-w- c:\program files\GUIDE PLUS+ System.lnk
2003-11-07 04:11 . 1980-01-01 04:00 820 ----a-w- c:\program files\Dell Accessories.lnk
2001-01-28 21:58 . 2001-01-28 21:58 516 ----a-w- c:\program files\Acrobat Reader 4.0.lnk
2001-01-21 04:14 . 1980-01-01 04:00 23357 ---h--w- c:\program files\FOLDER.HTT
2001-01-08 19:46 . 2001-01-08 19:46 594 ----a-w- c:\program files\Launch DellNet by MSN.lnk
2001-01-08 19:43 . 2001-01-08 19:43 444 ----a-w- c:\program files\Send and Receive a Fax.lnk
2001-01-08 19:43 . 2001-01-08 19:43 388 ----a-w- c:\program files\PhoneTools.lnk
1998-12-09 06:53 . 1998-12-09 06:53 99840 ------w- c:\program files\Common Files\IRAABOUT.DLL
1998-12-09 06:53 . 1998-12-09 06:53 70144 ------w- c:\program files\Common Files\IRAMDMTR.DLL
1998-12-09 06:53 . 1998-12-09 06:53 48640 ------w- c:\program files\Common Files\IRALPTTR.DLL
1998-12-09 06:53 . 1998-12-09 06:53 31744 ------w- c:\program files\Common Files\IRAWEBTR.DLL
1998-12-09 06:53 . 1998-12-09 06:53 186368 ------w- c:\program files\Common Files\IRAREG.DLL
1998-12-09 06:53 . 1998-12-09 06:53 17920 ------w- c:\program files\Common Files\IRASRIAL.DLL
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCTVOICE"="pctspk.exe" [2002-08-14 167936]
"Matrox Powerdesk"="c:\windows\System32\PDesk\PDesk.exe" [2001-09-21 622592]
"MpsOnn"="c:\windows\System32\spool\DRIVERS\W32X86\3\MpsOnn.exe" [2003-06-09 22528]
"Matrox PowerDesk SE"="c:\program files\Matrox Graphics Inc\PowerDesk SE\Matrox.PowerDesk SE.exe" [2009-02-06 4223232]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-07-13 169264]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-11-16 2054360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\D:\0autocheck autochk *
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eDualHead Toolbar.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\eDualHead Toolbar.lnk
backup=c:\windows\pss\eDualHead Toolbar.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=c:\windows\pss\ymetray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^default^Start Menu^Programs^Startup^IMsecure.lnk]
path=c:\documents and settings\default\Start Menu\Programs\Startup\IMsecure.lnk
backup=c:\windows\pss\IMsecure.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^default^Start Menu^Programs^Startup^OpenOffice.org 3.2.lnk]
path=c:\documents and settings\default\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
backup=c:\windows\pss\OpenOffice.org 3.2.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 05:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
2003-07-25 15:15 536576 ----a-w- c:\program files\Eraser\eraser.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 23:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
2002-03-19 12:53 29184 ----a-w- c:\progra~1\ScanSoft\PAPERP~1\Pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Pitstop Optimize Scheduler]
2006-07-26 19:59 1684480 ----a-w- c:\program files\PCPitstop\Optimize\PCPOptimize.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PestPatrol Control Center]
2004-11-15 15:49 98304 ----a-w- c:\progra~1\PESTPA~1\PPControl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPMemCheck]
2003-04-19 11:53 148480 ----a-w- c:\progra~1\PESTPA~1\PPMemCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2004-07-10 02:57 98304 ----a-w- c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
2007-01-28 07:55 1003520 ----a-w- c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
2002-04-17 13:42 69632 ----a-w- c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StorageGuard]
2002-06-18 04:01 155648 ----a-w- c:\program files\VERITAS Software\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 19:21 246504 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2004-07-10 03:57 180269 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
2007-08-30 21:43 4670704 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AIM"=c:\program files\AIM95\aim.exe -cnetwait.odl
"ATI Scheduler"=c:\program files\ATI MULTIMEDIA\MAIN\ATISched.EXE
"MoneyAgent"="c:\program files\Microsoft Money\System\Money Express.exe"
"MSMSGS"="c:\program files\MESSENGER\MSMSGS.EXE" /background
"ATI Launchpad"="c:\program files\ATI MULTIMEDIA\MAIN\LAUNCHPD.EXE"
"Mozilla Quick Launch"="c:\program files\Netscape\Netscp.exe" -aim
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adaptec DirectCD"=c:\progra~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
"CreateCD"=c:\progra~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
"hpppta"=c:\program files\Hewlett-Packard\HP PrecisionScan\PrecisionScan\hpppta.exe /ICON
"RealTray"=c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
"ATIPTA"=c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
"HPID Scheduler"=c:\program files\Hewlett-Packard\HP Instant Delivery\hpidschd.exe
"LoadQM"=loadqm.exe
"LTWinModem1"=ltmsg.exe 9
"QuickTime Task"="c:\windows\SYSTEM32\qttask.exe" -atboottime
"PestPatrol Control Center"=c:\program files\PestPatrol\PPControl.exe
"WinampAgent"="c:\program files\WINAMP\WINAMPa.exe"
"PCHealth"=c:\windows\PCHealth\Support\PCHSchd.exe -s
"RxMon"=c:\program files\Dell\Resolution Assistant\Common\bin\RxMon9x.exe
"madexe"=c:\program files\Dell\Resolution Assistant\MotiveAssistant\bin\mad.exe
"Share-to-Web Namespace Daemon"=c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
"MMTray"=c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"MotiveMonitor"=c:\program files\Motive\motmon.exe
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"LoadQM"=loadqm.exe
"PPMemCheck"=c:\progra~1\PESTPA~1\PPMemCheck.exe
"StorageGuard"="c:\program files\VERITAS Software\Update Manager\sgtray.exe" /r
"dla"=c:\windows\system\dla\tfswctrl.exe
"hpppta"=c:\program files\Hewlett-Packard\HP PrecisionScan\PrecisionScan\hpppta.exe /ICON
"Logitech Utility"=LOGI_MWX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices-]
"ATIPOLAB"=
"StillImageMonitor"=c:\windows\SYSTEM32\STIMON.EXE
"LoadBlackD"=c:\program files\Network ICE\BlackICE\blackd.exe
"SchedulingAgent"=mstask.exe
"ATIPOLL"=ati2evxx.exe
"Machine Debug Manager"=c:\windows\SYSTEM32\MDM.EXE
"RNBOStart"=c:\windows\SYSTEM\RNBOSENT\SENTSTRT.EXE
"ATISmart"=c:\windows\SYSTEM\ati2s9ag.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AIM95\\aim.exe"=
"c:\\WINDOWS\\System32\\ZoneLabs\\VSMON.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 pavboot;pavboot;c:\windows\SYSTEM32\DRIVERS\pavboot.sys [9/12/2008 9:18 PM 28544]
R1 ehdrv;ehdrv;c:\windows\SYSTEM32\DRIVERS\ehdrv.sys [11/16/2009 9:03 AM 108792]
R2 ALIEHCD;ALi PCI to USB Enhanced Host Controller;c:\windows\SYSTEM32\DRIVERS\AliEhci.sys [11/8/2003 8:41 PM 104088]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [11/16/2009 9:04 AM 735960]
R2 Matrox Centering Service;Matrox Centering Service;c:\program files\Matrox Graphics Inc\PowerDesk\Services\Matrox.PowerDesk.Services.exe [2/6/2009 2:09 PM 1263872]
R2 Matrox.Pdesk.ServicesHost;Matrox.Pdesk.ServicesHost;c:\program files\Matrox Graphics Inc\PowerDesk SE\Matrox.Pdesk.ServicesHost.exe [2/6/2009 2:08 PM 344832]
R3 aliroothub;USB 2.0 Root Hub;c:\windows\SYSTEM32\DRIVERS\AliRtHub.sys [11/8/2003 8:41 PM 5337]
R3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter;c:\windows\SYSTEM32\DRIVERS\lne100v5.sys [11/10/2003 2:17 PM 36224]
R3 WlanUIG;2Wire 802.11g USB Driver;c:\windows\SYSTEM32\DRIVERS\WlanUIG.sys [5/30/2005 10:21 PM 347648]
S3 G550DH;G550DH;c:\windows\SYSTEM32\DRIVERS\g550dhm.sys [9/28/2001 1:13 PM 324747]
S3 UtilNT;UtilNT;c:\windows\SYSTEM32\DRIVERS\UtilNt.sys [11/14/2003 10:43 PM 5533]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
2008-04-13 23:12 73216 ----a-w- c:\program files\Outlook Express\setup50.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
2008-04-13 23:12 73216 ----a-w- c:\program files\Outlook Express\setup50.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
2008-04-13 23:12 73216 ----a-w- c:\program files\Outlook Express\setup50.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
2008-04-13 23:12 73216 ----a-w- c:\program files\Outlook Express\setup50.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
2001-03-23 20:17 7168 ------w- c:\windows\SYSTEM32\updcrl.exe
.
Contents of the 'Scheduled Tasks' folder
2010-06-25 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-06-25 02:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mWindow Title = Microsoft Internet Explorer provided by Comcast
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Trusted Zone: aol.com\free
DPF: DirectAnimation Java Classes - file://c:\windows\SYSTEM\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: Win32 Classes
FF - ProfilePath -
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
MSConfigStartUp-ATI Launchpad - c:\program files\ATI Multimedia\main\launchpd.exe
MSConfigStartUp-ATI Remote Control - c:\program files\ATI Multimedia\RemCtrl\ATIX10.exe
MSConfigStartUp-ATIPTA - c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
MSConfigStartUp-SpyCop ScanCheck - c:\program files\Internet Explorer\setup.exe
MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
MSConfigStartUp-ymetray - c:\program files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe
ActiveSetup-RNA - rundll rnasetup.dll
AddRemove-3DSexVilla-031.001 - c:\documents and settings\default\My Documents\psfonts\psfonts2\SV\thriXXX\3D SexVilla\Binaries\Uninstall-3DSexVilla-031.001.exe
AddRemove-Adobe After Effects v3.1 - c:\adobe\After Effects 3.1\DeIsL1.isu
AddRemove-Adobe PageMaker 6.5 - c:\pm65\DeIsL1.isu
AddRemove-Adobe Streamline 4.0 - c:\adobe\Streamline 4.0\DeIsL1.isu
AddRemove-mIRC - c:\program files\mIRC\mirc.exe
AddRemove-Office In Color - c:\program files\KMT Software
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-06-25 07:01
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.netdevice: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x82EF1EC5]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf85faf28
\Driver\ACPI -> ACPI.sys @ 0xf856dcb8
\Driver\atapi -> atapi.sys @ 0xf84ff852
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a8
ParseProcedure -> ntoskrnl.exe @ 0x8056c1d6
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a05a8
ParseProcedure -> ntoskrnl.exe @ 0x8056c1d6
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
user & kernel MBR OK
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Reinstall\TP*]
"DisplayName"="?\13?\13"
"DeviceDesc"="?\13?\13"
"ProviderName"=""
"MFG"="???\\"
"ReinstallString"="c:\\WINDOWS\\System32\\ReinstallBackups\\?\13\\DriverFiles\\.INF"
"DeviceInstanceIds"=multi:"07243.inf\00"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(908)
c:\windows\system32\WININET.dll
.
Completion time: 2010-06-25 07:08:57
ComboFix-quarantined-files.txt 2010-06-25 11:08
ComboFix2.txt 2009-07-02 09:20
Pre-Run: 6,258,032,640 bytes free
Post-Run: 6,410,633,216 bytes free
- - End Of File - - DE21E5054C281F2C3C659FD4DDF77FC2