Thanks for your reply Bobbye,
Eset found nothing so didnt produce a log.
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000000d
Kernel Drivers (total 123):
0x804D7000 \WINDOWS\system32\ntoskrnl.exe
0x806EF000 \WINDOWS\system32\hal.dll
0xF7A0F000 \WINDOWS\system32\KDCOM.DLL
0xF791F000 \WINDOWS\system32\BOOTVID.dll
0xF74C0000 ACPI.sys
0xF7A11000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF74AF000 pci.sys
0xF750F000 isapnp.sys
0xF7A13000 viaide.sys
0xF778F000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF751F000 MountMgr.sys
0xF7490000 ftdisk.sys
0xF7A15000 dmload.sys
0xF746A000 dmio.sys
0xF7797000 PartMgr.sys
0xF752F000 VolSnap.sys
0xF7452000 atapi.sys
0xF743F000 viamraid.sys
0xF7427000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
0xF753F000 disk.sys
0xF754F000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF7407000 fltmgr.sys
0xF73F5000 sr.sys
0xF73DE000 KSecDD.sys
0xF7351000 Ntfs.sys
0xF7324000 NDIS.sys
0xF755F000 uagp35.sys
0xF779F000 viaagp1.sys
0xF730A000 Mup.sys
0xF76DF000 \SystemRoot\system32\DRIVERS\amdk7.sys
0xF72A0000 \SystemRoot\system32\DRIVERS\vtmini.sys
0xF728C000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF76EF000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF76FF000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF7269000 \SystemRoot\system32\DRIVERS\ks.sys
0xF77FF000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF7245000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF7A33000 \SystemRoot\System32\Drivers\vulfnth.sys
0xF7807000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF71AB000 \SystemRoot\system32\drivers\ALCXWDM.SYS
0xF7187000 \SystemRoot\system32\drivers\portcls.sys
0xF770F000 \SystemRoot\system32\drivers\drmk.sys
0xF7125000 \SystemRoot\system32\drivers\ALCXSENS.SYS
0xF771F000 \SystemRoot\system32\DRIVERS\fetnd5b.sys
0xF780F000 \SystemRoot\system32\DRIVERS\fdc.sys
0xF772F000 \SystemRoot\system32\DRIVERS\serial.sys
0xF79EF000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF7111000 \SystemRoot\system32\DRIVERS\parport.sys
0xF773F000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xF7817000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF7B36000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF774F000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF79F3000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF70FA000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF775F000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF776F000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF781F000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF70E9000 \SystemRoot\system32\DRIVERS\psched.sys
0xF777F000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF7877000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF78E7000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF59D7000 \SystemRoot\system32\DRIVERS\rdpdr.sys
0xF76CF000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF78EF000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF7A5D000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF5979000 \SystemRoot\system32\DRIVERS\update.sys
0xF79B3000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF7081000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF79DB000 \SystemRoot\System32\Drivers\vulfntr.sys
0xF7041000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF7A65000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF78C7000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0xF7A73000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7B3B000 \SystemRoot\System32\Drivers\Null.SYS
0xF7A77000 \SystemRoot\System32\Drivers\Beep.SYS
0xF77CF000 \SystemRoot\System32\drivers\vga.sys
0xF7A79000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF7A7D000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF77EF000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF77F7000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF6374000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xF080D000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xF07B4000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xF078C000 \SystemRoot\system32\DRIVERS\netbt.sys
0xF076A000 \SystemRoot\System32\drivers\afd.sys
0xF5904000 \SystemRoot\system32\DRIVERS\netbios.sys
0xF7867000 \SystemRoot\System32\Drivers\StarOpen.SYS
0xF640F000 \SystemRoot\system32\DRIVERS\ssmdrv.sys
0xF073F000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xF06CF000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF58D4000 \SystemRoot\System32\Drivers\Fips.SYS
0xF053F000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xF75CF000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xF0519000 \SystemRoot\system32\DRIVERS\avipbb.sys
0xF7A99000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
0xF637C000 \SystemRoot\system32\DRIVERS\hidusb.sys
0xF759F000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0xF78A7000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xF78AF000 \SystemRoot\system32\DRIVERS\NuidFltr.sys
0xF7071000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS
0xF049E000 \SystemRoot\system32\DRIVERS\Wdf01000.sys
0xF0844000 \SystemRoot\system32\DRIVERS\mouhid.sys
0xEEA0C000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xED713000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF7A6B000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xEDF0B000 \SystemRoot\System32\drivers\Dxapi.sys
0xEE6B2000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7AF0000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF14B000 \SystemRoot\System32\ATMFD.DLL
0xEB2DE000 \SystemRoot\system32\DRIVERS\avgntflt.sys
0xEFFFC000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xEB239000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xF7A81000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xEB1AC000 \SystemRoot\system32\drivers\wdmaud.sys
0xEFB0E000 \SystemRoot\system32\drivers\sysaudio.sys
0xED7BC000 \SystemRoot\system32\DRIVERS\srv.sys
0xEDD5A000 \SystemRoot\System32\Drivers\HTTP.sys
0xBFF50000 \SystemRoot\System32\TSDDD.dll
0xBF012000 \SystemRoot\System32\vtdisp.dll
0xEB181000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll
Processes (total 38):
0 System Idle Process
4 System
580 C:\WINDOWS\system32\smss.exe
644 csrss.exe
668 C:\WINDOWS\system32\winlogon.exe
712 C:\WINDOWS\system32\services.exe
724 C:\WINDOWS\system32\lsass.exe
896 C:\WINDOWS\system32\svchost.exe
972 svchost.exe
1068 C:\WINDOWS\system32\svchost.exe
1144 svchost.exe
1264 svchost.exe
1404 C:\WINDOWS\system32\spoolsv.exe
1460 C:\Program Files\Avira\AntiVir Desktop\sched.exe
1528 svchost.exe
1640 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
1796 C:\Program Files\Java\jre6\bin\jqs.exe
1924 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
128 C:\WINDOWS\system32\svchost.exe
1016 explorer.exe
1588 VTTimer.exe
1576 avgnt.exe
1752 jusched.exe
2308 alg.exe
3620 utorrent.exe
3756 csrss.exe
3784 C:\WINDOWS\system32\winlogon.exe
1188 C:\WINDOWS\explorer.exe
492 C:\WINDOWS\system32\VTTimer.exe
456 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
760 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
2112 C:\Program Files\Common Files\Java\Java Update\jusched.exe
2008 C:\WINDOWS\system32\ctfmon.exe
2436 C:\Program Files\Mozilla Firefox\firefox.exe
2656 C:\Program Files\Mozilla Firefox\plugin-container.exe
2584 wscntfy.exe
2564 C:\WINDOWS\system32\wscntfy.exe
2640 C:\Documents and Settings\Geoff\Desktop\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
PhysicalDrive0 Model Number: HDS728080PLAT20, Rev: PF2OA21B
Size Device Name MBR Status
--------------------------------------------
76 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
Done!
ComboFix 11-03-22.02 - Geoff 22-03-2011 20:45:32.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.991.679 [GMT 0:00]
Running from: c:\documents and settings\Geoff\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\components
.
.
((((((((((((((((((((((((( Files Created from 2011-02-22 to 2011-03-22 )))))))))))))))))))))))))))))))
.
.
2011-03-22 19:33 . 2011-03-22 19:33 -------- d-----w- c:\program files\ESET
2011-03-18 20:38 . 2011-03-18 20:38 -------- d-----w- c:\documents and settings\bon\Local Settings\Application Data\Unity
2011-03-08 11:43 . 2011-03-22 19:35 -------- d-----w- c:\documents and settings\bon\Application Data\uTorrent
2011-03-02 17:31 . 2011-03-02 17:31 -------- d-----w- c:\windows\system32\XPSViewer
2011-03-02 17:31 . 2011-03-02 17:31 -------- d-----w- c:\program files\MSBuild
2011-03-02 17:31 . 2011-03-02 17:31 -------- d-----w- c:\program files\Reference Assemblies
2011-03-02 17:30 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-03-02 17:30 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-03-02 17:30 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-03-02 17:30 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2011-03-02 17:30 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2011-03-02 17:30 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2011-03-02 17:30 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2011-03-02 17:30 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-03-02 17:30 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-03-02 17:30 . 2011-03-02 17:30 -------- d-----w- C:\7e1c48bd6a9b2dc97bfb770e77d353
2011-02-27 18:40 . 2011-02-27 18:40 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2011-02-27 14:18 . 2011-02-27 14:18 -------- d-----w- c:\program files\Common Files\Java
2011-02-27 14:17 . 2011-02-27 14:17 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-22 08:23 . 2010-09-05 10:37 664 ----a-w- c:\documents and settings\bon\Local Settings\Application Data\d3d9caps.tmp
2011-02-09 13:53 . 2006-02-28 12:00 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2006-02-28 12:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-02 21:40 . 2010-09-03 15:41 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-02 19:19 . 2010-09-03 15:41 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58 . 2010-09-03 09:42 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2010-09-03 09:42 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2006-02-28 12:00 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2006-02-28 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2006-02-28 12:00 1854976 ----a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2004-01-15 49152]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-14 281768]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VIA RAID TOOL.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\VIA RAID TOOL.lnk
backup=c:\windows\pss\VIA RAID TOOL.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2004-05-12 14:18 241664 ----a-w- c:\program files\HP\hpcoretech\hpcmpmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2004-08-30 05:48 69632 ----a-w- c:\windows\SOUNDMAN.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2004-01-15 12:33 49152 ----a-r- c:\windows\system32\VTTimer.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Geoff\\Desktop\\utorrent.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Documents and Settings\\bon\\Desktop\\utorrent.exe"=
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [10-09-2010 10:49 135336]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [27-10-2010 18:52 136176]
S3 iadusb;MT882;c:\windows\system32\drivers\glauiad.sys [03-09-2010 10:00 30336]
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-27 18:52]
.
2011-03-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-27 18:52]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Geoff\Application Data\Mozilla\Firefox\Profiles\sg7wto9z.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Download Statusbar: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} - %profile%\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-HP Software Update - c:\program files\HP\HP Software Update\HPWuSchd2.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-03-22 20:51
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2260)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
- - - - - - - > 'explorer.exe'(3512)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-03-22 20:54:18
ComboFix-quarantined-files.txt 2011-03-22 20:54
.
Pre-Run: 31,521,017,856 bytes free
Post-Run: 32,743,604,224 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 537FEC28141E8CC74CD6F23D0B27921A