Following is the combofix log. Hope I ran everything ok, as it said it ran in reduced functionality mode.
ComboFix 09-10-23.01 - Administrator 11/02/2009 20:27.3.1 - NTFSx86 MINIMAL
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.354 [GMT -5:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\cfscript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
FILE ::
"c:\windows\system32\jejobadi.dll"
"c:\windows\system32\pedisasa.dll"
"c:\windows\system32\toluboli.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\makezimu.dll
c:\windows\system32\pedisasa.dll
c:\windows\system32\romabotu.dll
c:\windows\system32\toluboli.exe
.
((((((((((((((((((((((((( Files Created from 2009-10-03 to 2009-11-03 )))))))))))))))))))))))))))))))
.
2009-11-02 02:45 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-02 02:45 . 2009-11-02 02:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-02 02:45 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-31 20:05 . 2009-10-31 20:05 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2009-10-31 20:04 . 2009-10-31 20:04 149336 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-31 20:01 . 2009-10-31 20:01 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\BVRP Software
2009-10-31 03:02 . 2009-10-31 03:02 -------- d-----w- c:\documents and settings\All Users\Application Data\64759637
2009-10-12 19:30 . 2009-10-12 19:30 -------- d-----w- c:\program files\Common Files\CSUninstall
2009-10-09 02:19 . 2009-10-09 21:14 -------- d-----w- c:\program files\Auslogics
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-25 20:04 . 2005-08-19 00:57 -------- d-----w- c:\program files\Google
2009-10-22 19:47 . 2005-12-31 05:01 -------- d-----w- c:\program files\Crossword Weaver
2009-09-27 20:10 . 2005-06-13 22:18 -------- d-----w- c:\program files\Common Files\Corel
2009-09-27 20:10 . 2008-07-13 03:50 -------- d-----w- c:\program files\Corel
2009-09-27 20:06 . 2005-06-13 22:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-27 20:04 . 2005-11-15 02:55 -------- d-----w- c:\program files\Nancy Drew
2009-09-23 20:41 . 2005-11-12 03:46 -------- d-----w- c:\documents and settings\Patty\Application Data\Apple Computer
2009-09-20 20:04 . 2005-10-21 14:58 -------- d-----w- c:\documents and settings\Lindsey\Application Data\Apple Computer
2009-09-18 01:39 . 2005-11-01 02:54 -------- d-----w- c:\documents and settings\Kelly\Application Data\Apple Computer
2009-09-13 17:21 . 2009-02-03 01:37 115972 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-13 05:58 . 2009-09-13 05:56 -------- d-----w- c:\program files\iTunes
2009-09-13 05:58 . 2009-09-13 05:56 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-13 05:57 . 2005-10-19 00:35 -------- d-----w- c:\program files\iPod
2009-09-13 05:57 . 2008-05-03 19:59 -------- d-----w- c:\program files\Common Files\Apple
2009-09-13 05:50 . 2005-10-19 00:37 -------- d-----w- c:\program files\QuickTime
2009-09-12 19:58 . 2009-09-12 19:31 68940 ----a-w- c:\windows\hpoins05.dat
2009-09-12 19:48 . 2009-09-12 19:48 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-09-12 19:46 . 2005-08-07 03:49 -------- d-----w- c:\program files\Common Files\HP
2009-09-12 19:41 . 2005-08-07 03:20 -------- d-----w- c:\program files\HP
2009-09-12 19:41 . 2009-09-12 19:40 -------- d-----w- c:\program files\Hewlett-Packard
2009-09-11 14:33 . 2004-08-10 17:51 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-08 19:12 . 2009-09-08 19:12 -------- d-----w- c:\documents and settings\Lindsey\Application Data\Malwarebytes
2009-09-04 20:45 . 2004-08-10 17:51 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-10 17:51 916480 ------w- c:\windows\system32\wininet.dll
2009-08-28 23:42 . 2009-06-04 01:08 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-28 23:42 . 2008-12-26 03:41 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-26 08:16 . 2004-08-10 17:51 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-26 00:38 . 2009-08-26 00:38 11360 ----a-w- c:\program files\Common Files\lokenosude._sy
2009-08-17 13:30 . 2009-08-17 13:30 19370 ----a-w- c:\documents and settings\Lindsey\Local Settings\Application Data\uxicacybu.com
2009-08-17 13:30 . 2009-08-17 13:30 17531 ----a-w- c:\program files\Common Files\lepozigu.dll
2009-08-17 13:30 . 2009-08-17 13:30 17421 ----a-w- c:\windows\voqoxepad.pif
2009-08-17 13:30 . 2009-08-17 13:30 14567 ----a-w- c:\documents and settings\All Users\Application Data\dexa.scr
2009-08-17 13:30 . 2009-08-17 13:30 13318 ----a-w- c:\documents and settings\Lindsey\Local Settings\Application Data\muxon.dat
2009-08-17 13:30 . 2009-08-17 13:30 13146 ----a-w- c:\documents and settings\Lindsey\Application Data\wihazicefu.pif
2009-08-17 13:30 . 2009-08-17 13:30 19939 ----a-w- c:\program files\Common Files\kavunida.scr
2009-08-17 13:30 . 2009-08-17 13:30 18156 ----a-w- c:\documents and settings\Lindsey\Application Data\tarif.bin
2009-08-17 13:30 . 2009-08-17 13:30 12704 ----a-w- c:\program files\Common Files\ybejuwi._dl
2009-08-17 13:30 . 2009-08-17 13:30 12310 ----a-w- c:\documents and settings\Lindsey\Local Settings\Application Data\ydoxono.dll
2009-08-17 13:30 . 2009-08-17 13:30 10992 ----a-w- c:\program files\Common Files\vuhuwylo.com
2009-08-14 21:15 . 2005-08-10 19:27 149336 ----a-w- c:\documents and settings\Patty\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-08 20:59 . 2005-08-07 21:58 149336 ----a-w- c:\documents and settings\Lindsey\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-08 19:57 . 2005-08-07 15:37 149336 ----a-w- c:\documents and settings\Kelly\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-06 23:24 . 2004-08-10 18:02 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 23:24 . 2004-08-10 18:02 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 23:24 . 2005-06-16 03:17 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 23:24 . 2005-05-26 08:16 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 23:24 . 2004-08-10 18:02 53472 ------w- c:\windows\system32\wuauclt.exe
2009-08-06 23:24 . 2004-08-10 17:50 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 23:23 . 2004-08-10 18:02 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 23:23 . 2004-08-10 18:02 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:11 . 2004-08-10 17:51 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-24 20:08 . 2008-07-13 03:59 88 --sh--r- c:\windows\system32\9497AC6F27.sys
2009-07-31 03:02 . 2009-07-31 03:02 53248 --sha-w- c:\windows\system32\gipidiwu.dll
2009-07-31 03:02 . 2009-07-31 03:02 53248 --sha-w- c:\windows\system32\hofalobu.dll
2009-07-24 20:08 . 2008-07-13 03:52 2516 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-07-31 03:02 . 2009-07-31 03:02 1054752 --sha-w- c:\windows\system32\vasidifu.exe
2009-07-31 19:48 . 2009-07-31 19:48 92160 --sha-w- c:\windows\system32\vonibusa.dll
2009-07-31 03:02 . 2009-07-31 03:02 53248 --sha-w- c:\windows\system32\yonevena.dll
2009-07-31 03:02 . 2009-07-31 03:02 39424 --sha-w- c:\windows\system32\zubadira.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-10-29_21.18.19 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-10-29 18:03 . 2009-10-29 18:03 16384 c:\windows\Temp\Perflib_Perfdata_6a8.dat
+ 2009-11-03 01:31 . 2009-11-03 01:31 16384 c:\windows\temp\Perflib_Perfdata_6a8.dat
- 2009-10-29 18:03 . 2009-10-29 18:03 16384 c:\windows\Temp\Perflib_Perfdata_648.dat
+ 2009-11-03 01:31 . 2009-11-03 01:31 16384 c:\windows\temp\Perflib_Perfdata_648.dat
+ 2004-08-10 17:51 . 2009-11-03 01:18 71732 c:\windows\system32\perfc009.dat
- 2004-08-10 17:51 . 2009-10-21 00:25 71732 c:\windows\system32\perfc009.dat
- 2004-08-10 17:51 . 2009-10-21 00:25 442466 c:\windows\system32\perfh009.dat
+ 2004-08-10 17:51 . 2009-11-03 01:18 442466 c:\windows\system32\perfh009.dat
+ 2009-07-17 14:24 . 2009-11-01 20:14 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2009-07-17 14:24 . 2009-10-24 12:50 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fa9fc5c9-e865-4cfc-a8f5-a5630712beb4}]
2009-07-31 03:02 53248 --sha-w- c:\windows\system32\yonevena.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2009-01-09 20:13 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2009-01-09 20:13 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2009-01-09 20:13 583312 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10b.exe" [2009-02-03 240544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-15 1404928]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-29 583048]
"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2009-01-09 669840]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-12-07 180269]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"64759637"="c:\documents and settings\All Users\Application Data\64759637\64759637.exe" [2009-10-31 1054752]
"velikolaw"="c:\windows\system32\vonibusa.dll" [2009-07-31 92160]
"fajatezigu"="gipidiwu.dll" - c:\windows\system32\gipidiwu.dll [2009-07-31 53248]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2006-10-04 53760]
c:\documents and settings\Kelly\Start Menu\Programs\Startup\
DesktopComic.exe [2006-4-13 1056291]
PowerReg Scheduler V3.exe [2006-6-13 225280]
c:\documents and settings\Lindsey\Start Menu\Programs\Startup\
DesktopComic.exe [2006-4-13 1056291]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{d8bf6737-77a4-4d07-8ab6-1eb5494ea88c}"= "c:\windows\system32\vonibusa.dll" [2009-07-31 92160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"firifapek"= {d8bf6737-77a4-4d07-8ab6-1eb5494ea88c} - c:\windows\system32\vonibusa.dll [2009-07-31 92160]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli gipidiwu.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Audible Download Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Audible Download Manager.lnk
backup=c:\windows\pss\Audible Download Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Sonic CinePlayer Quick Launch.lnk
backup=c:\windows\pss\Sonic CinePlayer Quick Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Southwest Airlines\\Ding\\Ding.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\vssvc.exe"=
"c:\\WINDOWS\\system32\\verclsid.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"c:\\Program Files\\HP\\HP Software Update\\hpwuSchd2.exe"=
"c:\\WINDOWS\\system32\\dllhost.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\WINDOWS\\explorer.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgalry.exe"=
"c:\\Program Files\\Carbonite\\Carbonite Backup\\CarboniteUI.exe"=
"c:\\WINDOWS\\system32\\logonui.exe"=
"c:\\WINDOWS\\system32\\winlogon.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/8/2009 1:22 PM 64160]
S2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [12/9/2008 12:37 PM 13088]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 4:34 PM 1028432]
S3 FANTOM;LEGO MINDSTORMS NXT Driver;c:\windows\system32\drivers\fantom.sys [3/10/2006 2:55 PM 39424]
S3 FTD2XX;FTD2XX.SYS FT8U2XX device driver;c:\windows\system32\drivers\FTD2XX.sys [9/28/2006 11:59 AM 34639]
S3 RioS50;RioS50 driver;c:\windows\system32\drivers\RioS50.sys [11/10/2005 7:47 PM 12661]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
BtwSrv
.
Contents of the 'Scheduled Tasks' folder
2009-10-25 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 18:22]
2009-10-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]
2009-10-31 c:\windows\Tasks\User_Feed_Synchronization-{5813F25E-005A-408D-9FE3-953A4E35C839}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.dell4me.com/myway
mStart Page = hxxp://www.google.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
DPF: {6964E06D-0446-43AF-A657-E65920D2E4CC} - hxxp://rep.liebert.com/eforms/lqq/OrderForms/HeatRejection/SAFM-8540-29E/3h/distinct/HeatRejection.CAB
DPF: {CA71228B-EE60-4C95-99DB-C3B7EAF0D483} - hxxp://rep.liebert.com/eforms/lqq/OrderForms/LiebertDS/SAFM-8540-410E/2g/distinct/LiebertDS.CAB
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-02 20:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d9,ca,c6,21,8b,c9,1f,44,83,ff,24,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d9,ca,c6,21,8b,c9,1f,44,83,ff,24,\
[HKEY_USERS\S-1-5-21-2513623303-3009968100-2059323652-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,80,6c,b5,91,42,a2,35,4c,b9,97,4c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,80,6c,b5,91,42,a2,35,4c,b9,97,4c,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(296)
c:\windows\system32\gipidiwu.dll
c:\windows\system32\wininet.dll
- - - - - - - > 'explorer.exe'(748)
c:\windows\system32\WININET.dll
c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\vonibusa.dll
.
------------------------ Other Running Processes ------------------------
.
c:\combofix\CF24256.exe
c:\combofix\PEV.cfxxe
.
**************************************************************************
.
Completion time: 2009-11-03 20:38 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-03 01:38
ComboFix2.txt 2009-10-29 21:28
Pre-Run: 9,872,887,808 bytes free
Post-Run: 9,845,833,728 bytes free
- - End Of File - - D72421FA49868F9EC05ADEB67BCF1E87