Ok I followed your instructions.
Here is the corresponding SDfix log followed by the combofix log.
SDfix
SDFix: Version 1.240 Run by Nathan Panec on 2009-01-14 at 09:18
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-14 09:40:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:cc,ee,16,a9,b0,2f,9d,4f,e5,44,ed,e3,03,f6,4f,3f,7f,85,9f,63,23,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:88,20,0f,57,b1,4a,d7,cf,9f,57,62,42,80,19,43,8d,2b,de,0c,6a,5b,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,f7,69,38,32,6d,16,0b,b2,03,47,ce,d7,69,53,b1,61,e9,..
"khjeh"=hex:3d,42,18,10,99,16,ae,c5,d2,48,88,06,bd,2b,d8,11,05,9e,fb,52,14,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:a0,e4,3d,87,ac,6d,8e,2c,9f,70,70,06,af,7e,0b,ea,14,af,43,56,67,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:cc,ee,16,a9,b0,2f,9d,4f,e5,44,ed,e3,03,f6,4f,3f,7f,85,9f,63,23,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="c:\program,files\permissionresearch\prai.dll,c:\program,files\permissionresearch\prai.dll,C:\program files\permissionresearch\prai.dll"
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
"LoadAppInit_DLLs"=dword:00000001
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\games\\black and white\\runblack.exe"="C:\\games\\black and white\\runblack.exe:*:Disabled:lh"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\games\\Soulstorm\\Soulstorm.exe"="C:\\games\\Soulstorm\\Soulstorm.exe:*:Enabled:Soulstorm"
"C:\\games\\Civ4\\Civilization4.exe"="C:\\games\\Civ4\\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4"
"C:\\games\\Civ4\\Beyond the Sword\\Civ4BeyondSword.exe"="C:\\games\\Civ4\\Beyond the Sword\\Civ4BeyondSword.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword"
"C:\\games\\Civ4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"="C:\\games\\Civ4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword Pitboss"
"C:\\games\\dark crusade\\Dawn of War - Dark Crusade\\DarkCrusade.exe"="C:\\games\\dark crusade\\Dawn of War - Dark Crusade\\DarkCrusade.exe:*:Enabled:DarkCrusade"
"C:\\WINDOWS\\system32\\ftp.exe"="C:\\WINDOWS\\system32\\ftp.exe:*:Enabled:File Transfer Protocol"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\Electronic Arts\\EADM\\Core.exe"="C:\\Program Files\\Electronic Arts\\EADM\\Core.exe:*:Enabled:EA Download Manager"
"C:\\games\\Dawn Of War\\W40k.exe"="C:\\games\\Dawn Of War\\W40k.exe:*:Enabled:W40k"
"C:\\Program Files\\Java\\jre6\\bin\\javaw.exe"="C:\\Program Files\\Java\\jre6\\bin\\javaw.exe:*:Enabled:Java Platform SE binary"
"C:\\games\\NWN\\nwmain.exe"="C:\\games\\NWN\\nwmain.exe:*:Enabled:Neverwinter Nights"
"C:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"="C:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe:*:Enabled:left4dead"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
Files with Hidden Attributes :
Sat 20 Aug 2005 121,237 A..HR --- "C:\games\Dawn Of War\Disk1Check.EXE"
Mon 9 Jun 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Thu 5 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\f7db876e78b88fd8276fd7d29cb7e4eb\BIT6.tmp"
Tue 30 Dec 2008 7,232 ...HR --- "C:\Documents and Settings\Nathan Panec\Application Data\SecuROM\UserData\securom_v7_01.bak"
Fri 2 May 2008 3,493,888 A..H. --- "C:\Documents and Settings\Nathan Panec\Application Data\U3\temp\Launchpad Removal.exe"
Finished!Combofix
ComboFix 09-01-13.04 - Nathan Panec 2009-01-14 9:48:32.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1392 [GMT -8:00]
Running from: c:\new folder\ComboFix.exe
AV: Trend Micro AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-12-14 to 2009-01-14 )))))))))))))))))))))))))))))))
.
2009-01-14 09:16 . 2009-01-14 09:16 578,560 --a--c--- c:\windows\system32\dllcache\user32.dll
2009-01-14 09:13 . 2009-01-14 09:14 <DIR> d-------- c:\windows\ERUNT
2009-01-14 09:04 . 2009-01-14 09:42 <DIR> d-------- C:\SDFix
2009-01-13 22:23 . 2009-01-13 23:20 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-13 22:23 . 2009-01-13 22:23 <DIR> d-------- c:\documents and settings\Nathan Panec\Application Data\Malwarebytes
2009-01-13 22:23 . 2009-01-13 22:23 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-13 22:23 . 2009-01-04 18:39 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-13 22:23 . 2009-01-04 18:39 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-13 22:17 . 2009-01-13 22:19 <DIR> d-------- c:\windows\BDOSCAN8
2009-01-13 22:11 . 2009-01-13 22:11 <DIR> d-------- c:\program files\CCleaner
2009-01-12 18:45 . 2009-01-12 18:45 <DIR> d-------- c:\documents and settings\Nathan Panec\Interactive
2009-01-09 16:46 . 2009-01-09 16:47 <DIR> d-------- c:\documents and settings\Nathan Panec\Application Data\Stardock
2009-01-09 16:46 . 2009-01-09 16:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\Stardock
2009-01-09 16:46 . 2009-01-09 16:46 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{CC8D4389-E989-40EE-AF09-2330B1EE8BF7}
2009-01-07 17:54 . 2009-01-09 16:46 <DIR> d-------- c:\program files\Stardock
2009-01-07 17:54 . 2009-01-07 17:54 <DIR> d-------- c:\program files\Common Files\Stardock
2009-01-07 17:54 . 2002-01-05 07:40 487,424 --a------ c:\windows\system32\msvcp70.dll
2009-01-07 17:54 . 2002-01-05 08:37 344,064 --a------ c:\windows\system32\msvcr70.dll
2009-01-07 17:54 . 2002-01-05 07:38 54,784 --a------ c:\windows\system32\msvci70.dll
2009-01-07 17:54 . 2000-10-20 01:05 25,088 --a------ c:\windows\system32\msxml3a.dll
2009-01-01 12:46 . 2009-01-14 09:53 <DIR> d-------- c:\program files\Steam
2009-01-01 10:27 . 2009-01-01 10:27 <DIR> d-------- c:\program files\SystemRequirementsLab
2008-12-29 23:04 . 2008-12-29 23:04 445,262 --a------ C:\AnalysisLog.sr0
2008-12-29 23:04 . 2008-12-29 23:04 174,760 --a------ C:\AnalysisLogApi.sr1
2008-12-29 22:02 . 2008-12-29 22:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\ATI
2008-12-25 13:14 . 2008-12-25 13:14 <DIR> d-------- c:\windows\Logs
2008-12-25 13:14 . 2008-05-30 14:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll
2008-12-25 13:14 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2008-12-25 13:14 . 2008-05-30 14:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll
2008-12-24 20:15 . 2008-12-24 20:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Marlin
2008-12-24 20:12 . 2008-12-24 20:12 <DIR> d-------- c:\program files\Common Files\Sony Shared
2008-12-24 19:58 . 2008-12-24 19:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\kinoma
2008-12-24 19:55 . 2008-12-24 19:57 <DIR> d-------- c:\program files\Sony
2008-12-17 18:59 . 2009-01-01 13:15 <DIR> d-------- c:\program files\Cheat Engine
2008-12-17 18:59 . 2008-12-17 18:59 <DIR> d-------- c:\program files\Cartoon Network
2008-12-17 18:59 . 2007-12-26 17:30 1,970,176 --a------ c:\windows\system32\d3dx9.dll
2008-12-17 18:59 . 2007-12-26 17:30 679,936 --a------ c:\windows\system32\D3DX81ab.dll
2008-12-15 11:14 . 2008-12-15 11:14 <DIR> d-------- c:\program files\BBLACK
2008-12-15 11:14 . 2009-01-06 14:53 265 --a------ c:\windows\ACTIVEJP.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-14 07:28 --------- d-----w c:\program files\Trend Micro
2009-01-13 03:05 --------- d-----w c:\program files\PermissionResearch
2009-01-02 20:08 --------- d-----w c:\documents and settings\Nathan Panec\Application Data\U3
2008-12-30 05:11 --------- d-----w c:\program files\ATI Technologies
2008-12-14 19:58 --------- d-----w c:\program files\Common Files\Adobe
2008-12-13 21:41 --------- d-----w c:\documents and settings\Nathan Panec\Application Data\InterTrust
2008-12-03 08:30 --------- d-----w c:\documents and settings\Nathan Panec\Application Data\Creative
2008-12-03 08:28 --------- d-----w c:\documents and settings\All Users\Application Data\Creative
2008-12-03 08:27 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-03 01:05 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2008-12-01 22:13 3,452,928 ----a-w c:\windows\system32\drivers\ati2mtag.sys
2008-12-01 19:51 53,248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2008-11-27 01:42 36,368 ----a-w c:\windows\system32\drivers\tmpreflt.sys
2008-11-27 01:42 205,328 ----a-w c:\windows\system32\drivers\tmxpflt.sys
2008-11-27 01:39 1,195,384 ----a-w c:\windows\system32\drivers\vsapint.sys
2008-11-24 22:35 --------- d-----w c:\documents and settings\Nathan Panec\Application Data\DivX
2008-11-18 18:26 --------- d-----w c:\documents and settings\All Users\Application Data\SlySoft
2008-10-25 15:05 16,384 ----a-w c:\windows\DCEBoot.exe
2008-10-08 01:51 0 ----a-w c:\documents and settings\Nathan Panec\jagex_runescape_preferences.dat
2008-07-02 02:19 4,603,742 ----a-w c:\documents and settings\Nathan Panec\20070126140754437_YP-U2J_V1136.zip
2008-07-02 02:09 4,267,166 ----a-w c:\documents and settings\Nathan Panec\20070530154647062_YP-U2J_v1156.zip
2008-07-02 02:00 548,864 ----a-w c:\documents and settings\Nathan Panec\stupdaterapp.exe
2008-06-14 03:43 421,640 ----a-w c:\documents and settings\Nathan Panec\bykhe30.zip
2008-06-07 17:02 1 ----a-w c:\documents and settings\Nathan Panec\SI.bin
2008-09-22 19:56 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092220080923\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Google Update"="c:\documents and settings\Nathan Panec\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-05 133104]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2008-07-21 2752512]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Steam"="c:\program files\steam\steam.exe" [2009-01-01 1410296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-09-12 160160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-11-10 970808]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-23 136600]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"SigmatelSysTrayApp"="stsystra.exe" [2007-02-19 c:\windows\stsystra.exe]
c:\documents and settings\Nathan Panec\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]
PowerReg Scheduler V3.exe [2008-11-06 225280]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C:\WINDOWS
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\c:\windows\system32
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WinRoute"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\games\\black and white\\runblack.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\games\\Soulstorm\\Soulstorm.exe"=
"c:\\games\\Civ4\\Civilization4.exe"=
"c:\\games\\Civ4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\games\\Civ4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\games\\dark crusade\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\games\\Dawn Of War\\W40k.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\games\\NWN\\nwmain.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
R4 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-11-10 36368]
S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\drivers\gan_adapter.sys [2006-08-28 10664]
S3 kvpndev;Kerio VPN adapter;c:\windows\system32\drivers\kvpndrv.sys [2008-06-24 65024]
S3 kwflower;Kerio WinRoute Firewall Driver - Lower Layer;c:\windows\system32\DRIVERS\kwflower.sys --> c:\windows\system32\DRIVERS\kwflower.sys [?]
S3 MaplomL;MaplomL; [x]
S4 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2008-11-10 49680]
S4 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-11-10 677128]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9043711b-a061-11dd-91bb-001c23a5f9ec}]
\Shell\AutoRun\command - j:\_autorun\AUTORUN.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9205e97a-c8a7-11dd-9228-001e4c05249e}]
\Shell\AutoRun\command - G:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97c434f1-9f8d-11dd-91ba-001c23a5f9ec}]
\Shell\AutoRun\command - g:\_autorun\AUTORUN.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bf8e2f06-37d4-11dd-9135-001c23a5f9ec}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-01-10 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe []
2009-01-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1844237615-884357618-839522115-1003.job
- c:\documents and settings\Nathan Panec\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-05 08:57]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-CircleDock - c:\hulk\techtools\dock\Circle Dock 0.9.2
HKLM-Run-c:\windows\system32\kdewy.exe - c:\windows\system32\kdewy.exe
MSConfigStartUp-kdewy - c:\windows\system32\kdewy.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-14 09:53:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1844237615-884357618-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:e8,6a,b8,3e,8a,ab,a2,97,5c,6d,19,96,08,57,54,39,d9,82,32,80,f9,
e3,55,fd,6f,2d,99,74,aa,83,f4,c4,3f,6f,e6,51,ad,cb,dd,10,82,8d,b5,74,46,a7,\
"rkeysecu"=hex:a9,99,9e,c5,a1,49,0b,49,f2,f9,50,b9,23,28,c2,a8
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(848)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\windows\system32\ati2evxx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\ZuneBusEnum.exe
c:\program files\Zune\ZuneNss.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-01-14 9:56:35 - machine was rebooted [Nathan Panec]
ComboFix-quarantined-files.txt 2009-01-14 17:56:33
Pre-Run: 23,864,807,424 bytes free
Post-Run: 23,850,377,216 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(3)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(3)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
214 --- E O F --- 2008-10-23 19:30:02
Please Advise.