I was able to run it with CFScript.
ComboFix 09-09-11.05 - Gen-XDM(Games) 09/12/2009 9:09.4.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1023.591 [GMT -7:00]
Running from: E:\Combo-Fix.exe
Command switches used :: E:\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Created a new restore point
FILE ::
"c:\windows\system32\xa.tmp"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\127bfe.msp
.
--------------- FCopy ---------------
c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll --> c:\windows\system32\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_GEL90XNE
-------\Legacy_MEMSWEEP2
-------\Legacy_XDVA090
-------\Legacy_XDVA143
-------\Legacy_XDVA275
-------\Legacy_XDVA279
-------\Service_gel90xne
-------\Service_ProtoWall
-------\Service_XDva090
-------\Service_XDva143
-------\Service_XDva275
-------\Service_XDva279
((((((((((((((((((((((((( Files Created from 2009-08-12 to 2009-09-12 )))))))))))))))))))))))))))))))
.
2009-09-09 00:45 . 2009-09-09 01:05 -------- d-----w- C:\ComboFix
2009-08-30 17:27 . 2009-08-30 17:27 20747 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-08-30 17:27 . 2004-04-30 22:12 40960 ----a-w- c:\windows\system32\AWLL5025.dll
2009-08-30 17:27 . 2003-10-13 22:30 94208 ----a-w- c:\windows\system32\GTW32N50.dll
2009-08-30 17:27 . 2003-09-26 05:15 15872 ----a-w- c:\windows\system32\GTNDIS5.sys
2009-08-28 15:13 . 2009-08-03 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-28 15:13 . 2009-08-31 22:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-28 15:13 . 2009-08-03 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-27 04:04 . 2009-09-06 19:28 -------- d-----w- c:\documents and settings\Rawr\Tracing
2009-08-27 04:04 . 2009-08-27 04:04 -------- d-----w- c:\documents and settings\Rawr\Local Settings\Application Data\Yahoo
2009-08-26 18:24 . 2009-08-26 18:24 -------- d-----w- c:\documents and settings\Gen-XDM(Games)\.housecall6.6
2009-08-26 17:24 . 2009-08-26 17:24 -------- d-----w- c:\documents and settings\Gen-XDM(Games)\Application Data\McAfee
2009-08-26 00:46 . 2009-08-26 00:56 -------- d-----w- c:\documents and settings\All Users\Application Data\SecTaskMan
2009-08-26 00:46 . 2009-08-26 00:56 -------- d-----w- c:\program files\Security Task Manager
2009-08-25 21:09 . 2009-07-08 20:44 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-08-25 21:09 . 2009-07-08 20:44 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-08-25 21:09 . 2009-07-08 20:44 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-08-25 21:09 . 2009-07-16 19:32 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-08-25 21:08 . 2009-08-25 21:09 -------- d-----w- c:\program files\Common Files\McAfee
2009-08-25 21:08 . 2009-08-25 21:09 -------- d-----w- c:\program files\McAfee.com
2009-08-25 21:08 . 2009-09-01 22:19 -------- d-----w- c:\program files\McAfee
2009-08-25 20:48 . 2009-07-08 20:43 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-08-23 02:51 . 2009-08-26 02:48 -------- d-----w- c:\program files\VstPlugins
2009-08-23 02:51 . 2006-06-20 08:56 225280 ----a-w- c:\windows\system32\rewire.dll
2009-08-23 02:50 . 2009-08-23 02:50 -------- d-----w- c:\program files\Outsim
2009-08-23 02:44 . 2009-08-25 23:06 -------- d-----w- c:\program files\Image-Line
2009-08-20 20:39 . 2009-08-20 20:39 -------- d-----w- c:\program files\BlackIsle
2009-08-20 20:35 . 2009-08-20 20:39 52736 ----a-w- c:\windows\ipuninst.exe
2009-08-20 18:30 . 2009-08-20 18:30 -------- d-----w- c:\documents and settings\Gen-XDM(Games)\Application Data\SlySoft
2009-08-20 18:25 . 2009-08-20 18:25 -------- d-----w- c:\documents and settings\All Users\Application Data\SlySoft
2009-08-16 05:42 . 2009-08-16 05:43 -------- d-----w- C:\844daf670dcd1f731db2c24aaa
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-07 03:53 . 2009-05-24 19:02 -------- d-----w- c:\program files\Cheat Engine
2009-08-31 03:55 . 2007-12-04 03:07 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-08-30 17:27 . 2006-06-03 17:42 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-28 20:11 . 2006-06-20 04:40 -------- d-----w- c:\program files\Warcraft III
2009-08-26 19:23 . 2007-02-10 16:38 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-26 18:24 . 2008-10-10 21:42 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-08-26 17:20 . 2006-12-26 22:15 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-26 04:11 . 2008-08-04 19:48 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2009-08-26 01:14 . 2009-04-22 21:29 -------- d-----w- c:\program files\PowerISO
2009-08-26 00:31 . 2006-12-12 03:43 -------- d-----w- c:\program files\EA GAMES
2009-08-26 00:31 . 2009-07-19 05:57 -------- d-----w- c:\program files\DivX
2009-08-25 22:26 . 2008-10-14 23:37 -------- d-----w- c:\documents and settings\Gen-XDM(Games)\Application Data\uTorrent
2009-08-25 19:25 . 2007-11-11 00:38 79400 ----a-w- c:\windows\War3Unin.dat
2009-08-25 19:20 . 2006-07-01 19:05 46616 ----a-w- c:\documents and settings\Gen-XDM(Games)\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-24 15:25 . 2008-06-13 13:49 -------- d-----w- c:\program files\Sword of the New World
2009-08-23 18:37 . 2009-07-23 18:20 -------- d-----w- c:\program files\Project64 1.6
2009-08-09 04:48 . 2009-08-08 18:26 -------- d-----w- c:\documents and settings\Gen-XDM(Games)\Application Data\Orbit
2009-08-08 23:57 . 2009-08-08 23:57 -------- d-----w- c:\program files\Trend Micro
2009-08-08 19:07 . 2009-08-08 18:54 -------- d-----w- c:\documents and settings\All Users\Application Data\River Past G5
2009-08-08 18:54 . 2009-08-08 18:54 163513 ----a-w- c:\windows\Audio Converter Uninstaller.exe
2009-08-08 18:54 . 2009-08-08 18:54 -------- d-----w- c:\documents and settings\Gen-XDM(Games)\Application Data\River Past G5
2009-08-08 18:54 . 2009-08-08 18:54 -------- d-----w- c:\program files\Common Files\River Past
2009-08-08 18:54 . 2009-08-08 18:54 -------- d-----w- c:\program files\River Past
2009-08-05 09:11 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-27 02:38 . 2006-06-03 17:57 -------- d-----w- c:\program files\Microsoft Games
2009-07-24 18:42 . 2008-07-01 15:57 34 -c--a-w- c:\documents and settings\Gen-XDM(Games)\jagex_runescape_preferences.dat
2009-07-23 18:17 . 2009-01-05 04:26 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-07-19 06:06 . 2009-07-19 06:06 -------- d-----w- c:\documents and settings\Gen-XDM(Games)\Application Data\DivX
2009-07-19 05:58 . 2009-07-19 05:57 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-07-17 18:55 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 06:43 . 2004-08-04 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-13 05:07 . 2009-07-13 05:07 25280 ----a-w- c:\windows\system32\drivers\hamachi.sys
2009-07-12 19:32 . 2007-02-08 00:12 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2009-07-08 20:44 . 2009-07-08 20:44 214024 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-07-02 19:01 . 2009-07-01 05:49 139016 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-07-02 19:01 . 2009-07-01 05:48 189488 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-07-01 05:49 . 2009-07-01 05:49 139152 ----a-w- c:\documents and settings\Gen-XDM(Games)\Application Data\PnkBstrK.sys
2009-07-01 05:48 . 2009-07-01 05:48 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-07-01 05:48 . 2009-07-01 05:48 794408 ----a-w- c:\windows\system32\pbsvc.exe
2009-06-29 16:12 . 2004-08-04 12:00 827392 ------w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-04 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:44 . 2004-08-04 12:00 724480 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:44 . 2004-08-04 12:00 59392 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:44 . 2004-08-04 12:00 56320 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:44 . 2004-08-04 12:00 298496 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:44 . 2004-08-04 12:00 168448 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:44 . 2004-08-04 12:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-22 11:34 . 2004-08-04 12:00 92544 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-21 15:46 . 2006-06-03 17:13 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-06-16 14:55 . 2004-08-04 12:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-09-08_02.17.55 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-12 16:32 . 2009-09-12 16:32 16384 c:\windows\Temp\Perflib_Perfdata_660.dat
+ 2007-01-27 23:44 . 2008-07-08 13:02 17272 c:\windows\system32\spmsg.dll
- 2007-01-27 23:44 . 2009-05-26 11:40 17272 c:\windows\system32\spmsg.dll
+ 2004-08-04 12:00 . 2009-08-13 15:16 512000 c:\windows\system32\jscript.dll
+ 2006-06-03 04:37 . 2009-06-21 22:04 153088 c:\windows\system32\dllcache\triedit.dll
- 2006-06-03 04:37 . 2004-08-04 12:00 153088 c:\windows\system32\dllcache\triedit.dll
+ 2004-08-04 12:00 . 2009-08-13 15:16 512000 c:\windows\system32\dllcache\jscript.dll
+ 2004-08-04 12:00 . 2009-05-20 11:56 2458112 c:\windows\system32\WMVCore.dll
- 2004-08-04 12:00 . 2008-06-18 13:03 2458112 c:\windows\system32\WMVCore.dll
+ 2004-08-04 12:00 . 2009-05-20 11:56 2458112 c:\windows\system32\dllcache\WMVCore.dll
- 2004-08-04 12:00 . 2008-06-18 13:03 2458112 c:\windows\system32\dllcache\WMVCore.dll
+ 2006-06-06 23:42 . 2009-08-28 21:38 24689600 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"="c:\program files\PeerGuardian2\pg2.exe" [2007-01-30 1432064]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-05-19 3561720]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2006-01-16 1398272]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"EPSON Stylus CX6400"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2L1.EXE" [2003-06-02 99840]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-09-30 185784]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2006-01-06 188416]
"HPHmon04"="c:\windows\system32\hphmon04.exe" [2006-01-06 348160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-07-10 645328]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-16 1630208]
"atwtusb"="atwtusb.exe" - c:\windows\system32\atwtusb.exe [2005-04-26 290816]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2006-10-04 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-6-8 113664]
Launchpad.lnk - c:\program files\IC Media Corp.\ICM532\Launchpad.exe [2009-5-4 49152]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Warcraft III\\War3.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Battlefront\\GameData\\Battlefront.exe"=
"c:\\Program Files\\CCP\\EVE\\bin\\ExeFile.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\bioshock demo\\Builds\\Release\\Bioshock.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\dawn of war ii - spd\\DOW2.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\jamp.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\AeriaGames\\WolfTeam\\Wolfteam.bin"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\River Past\\Audio Converter\\AudioConverter.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56730:TCP"= 56730:TCP:Pando Media Booster
"56730:UDP"= 56730:UDP:Pando Media Booster
"57627:TCP"= 57627:TCP:Pando Media Booster
"57627:UDP"= 57627:UDP:Pando Media Booster
"58871:TCP"= 58871:TCP:Pando Media Booster
"58871:UDP"= 58871:UDP:Pando Media Booster
R2 Airlink101 USB XR Adapter WLService;Airlink101 USB XR Adapter WLService;c:\program files\Airlink101\AWLL5025\WLService.exe [8/30/2009 10:27 AM 49152]
S1 aiptektp;HyperPen;c:\windows\system32\drivers\aiptektp.sys [5/27/2007 7:01 PM 22272]
S3 DCamUSBUVT;ICM532A;c:\windows\system32\Drivers\usbuvt.sys --> c:\windows\system32\Drivers\usbuvt.sys [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2/19/2009 5:27 PM 356920]
S4 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" --> c:\program files\Viewpoint\Common\ViewpointService.exe [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - PGFILTER
.
Contents of the 'Scheduled Tasks' folder
2009-08-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2009-08-25 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-08-25 04:26]
2009-08-25 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-08-25 04:26]
.
.