I was confused with the step involving the removal of one of my anti-virus programs. I removed Avira but wasn't sure if i should then use the avira link you posted or the norton 360 link. So just to be clear I still Have norton 360 on my computer. And on a side note after using combo fix my "NetgearWNDA 3100v2 Smart wizard" does not work. It is the program I use to connect to wireless, ATM I am using windows default service. THANKS again!
ComboFix 10-02-12.01 - matt 02/15/2010 12:53:26.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.455 [GMT -5:00]
Running from: c:\documents and settings\matt\My Documents\Downloads\ComboFix.exe
AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\CyberDefender
c:\program files\CyberDefender\cdinstx.exe
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\INSTALL.LOG
c:\program files\WinPCap\NetMonInstaller.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\program files\WinPCap\Uninstall.exe
c:\windows\system32\2973195295.dat
c:\windows\system32\drivers\npf.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\Packet.dll
c:\windows\system32\Process.exe
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SIntf16.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\system32\WS2Fix.exe
Infected copy of c:\windows\system32\ws2_32.dll was found and disinfected
Restored copy from - c:\windows\$NtServicePackUninstall$\ws2_32.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2010-01-15 to 2010-02-15 )))))))))))))))))))))))))))))))
.
2010-02-10 23:05 . 2010-02-11 23:07 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-02-10 03:07 . 2010-02-10 03:07 -------- d-----w- c:\documents and settings\matt\Local Settings\Application Data\Rawr
2010-02-09 19:12 . 2010-02-09 19:12 -------- d-sh--w- c:\documents and settings\matt\PrivacIE
2010-02-09 19:06 . 2010-02-09 19:06 -------- d-----w- c:\program files\TrendMicro
2010-02-09 18:13 . 2010-02-09 18:13 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-02-09 18:05 . 2010-02-09 18:05 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-02-09 18:04 . 2010-02-09 18:04 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-02-09 18:04 . 2010-02-09 18:04 -------- d-----w- c:\documents and settings\matt\Application Data\SUPERAntiSpyware.com
2010-02-09 05:50 . 2010-02-09 05:50 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-02-09 05:20 . 2010-02-09 05:20 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-02-09 05:17 . 2010-02-09 05:17 -------- d-sh--w- c:\documents and settings\matt\IETldCache
2010-02-09 05:10 . 2009-12-11 08:38 69120 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-02-09 05:09 . 2010-02-09 05:09 -------- d-----w- c:\windows\ie8updates
2010-02-09 05:08 . 2009-12-21 19:14 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-02-09 05:08 . 2009-12-21 19:14 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-02-09 05:08 . 2009-12-21 19:14 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-02-09 05:08 . 2009-12-21 19:14 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-02-09 05:08 . 2009-12-21 19:14 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-02-09 05:08 . 2009-12-21 19:14 11070464 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-02-09 05:05 . 2010-02-09 05:07 -------- dc-h--w- c:\windows\ie8
2010-02-09 04:49 . 2010-02-09 04:49 -------- d-----w- c:\documents and settings\All Users\Application Data\UAB
2010-02-09 04:49 . 2010-02-09 04:49 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2010-02-09 04:48 . 2010-02-09 04:48 -------- d-----w- c:\documents and settings\matt\Local Settings\Application Data\PC_Drivers_Headquarters
2010-02-09 04:47 . 2010-02-09 04:47 -------- d-----w- c:\program files\PC Drivers HeadQuarters
2010-02-08 22:57 . 2010-02-08 20:22 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-02-08 20:14 . 2009-12-02 13:19 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-02-08 20:03 . 2010-02-08 20:03 -------- d-----w- C:\ProgramData
2010-02-08 20:02 . 2010-02-08 20:02 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-02-08 19:45 . 2010-02-08 19:45 -------- d-----w- c:\documents and settings\matt\Application Data\Malwarebytes
2010-02-08 19:45 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-08 19:45 . 2010-02-08 19:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-08 19:45 . 2010-02-08 19:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-08 19:45 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-08 19:44 . 2010-02-08 20:09 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2010-02-08 06:22 . 2010-02-08 17:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-08 06:22 . 2010-02-08 06:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-08 06:08 . 2010-02-08 06:08 -------- d-----w- c:\documents and settings\matt\Local Settings\Application Data\Symantec
2010-02-06 20:39 . 2008-04-13 19:45 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-02-06 20:39 . 2008-04-13 19:45 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-02-03 22:37 . 2010-02-03 22:37 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA
2010-02-03 22:30 . 2010-02-03 22:30 -------- d--h--r- c:\documents and settings\matt\Application Data\SecuROM
2010-02-03 22:26 . 2010-02-03 22:26 -------- d-----w- c:\documents and settings\matt\Local Settings\Application Data\Downloaded Installations
2010-02-03 19:52 . 2010-02-03 19:52 -------- d-----w- c:\program files\SystemRequirementsLab
2010-02-03 19:34 . 2010-02-03 19:33 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys
2010-02-03 19:33 . 2010-02-03 19:33 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2010-02-03 19:33 . 2010-02-03 19:33 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-02-03 19:33 . 2010-02-03 19:34 -------- d-----w- c:\program files\Symantec
2010-02-03 19:32 . 2010-02-08 06:14 -------- d-----w- c:\windows\system32\drivers\N360
2010-02-03 19:32 . 2010-02-03 19:32 -------- d-----w- c:\program files\Norton 360
2010-02-03 19:32 . 2010-02-03 19:32 -------- d-----w- c:\program files\Windows Sidebar
2010-02-03 19:22 . 2010-02-03 19:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-02-03 19:19 . 2010-02-03 19:19 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-02-03 18:53 . 2010-02-03 19:32 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-02-03 18:53 . 2010-02-03 18:53 -------- d-----w- c:\program files\NortonInstaller
2010-02-03 18:43 . 2010-02-03 18:44 -------- d-----w- c:\documents and settings\All Users\Symantec Temporary Files
2010-02-03 17:50 . 2009-05-05 17:00 632576 ----a-w- c:\windows\system32\drivers\bcmwlhigh5.sys
2010-02-03 17:50 . 2008-11-14 22:35 196608 ----a-w- c:\windows\system32\wps_api.dll
2010-02-03 17:49 . 2010-02-03 17:49 -------- d-----w- c:\program files\NETGEAR
2010-02-03 17:48 . 2010-02-03 17:48 -------- d-----w- c:\documents and settings\matt\Application Data\InstallShield
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-15 18:04 . 2005-12-28 02:57 -------- d-----w- c:\program files\Steam
2010-02-09 20:07 . 2009-07-24 01:58 -------- d-----w- c:\program files\Trash
2010-02-09 19:07 . 2010-02-09 19:07 388096 ----a-r- c:\documents and settings\matt\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-02-09 18:53 . 2010-02-09 18:14 117760 ----a-w- c:\documents and settings\matt\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-02-09 18:14 . 2010-02-09 18:14 52224 ----a-w- c:\documents and settings\matt\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-02-09 18:03 . 2006-03-08 15:50 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-09 03:31 . 2006-02-15 18:34 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2010-02-09 00:36 . 2009-07-26 14:58 -------- d-----w- c:\documents and settings\matt\Application Data\Trash
2010-02-08 23:37 . 2005-12-17 08:58 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-08 20:23 . 2010-02-08 20:23 327000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-02-08 20:14 . 2009-06-30 23:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-02-08 20:00 . 2010-02-08 20:03 38784 ----a-w- c:\documents and settings\matt\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-08 20:00 . 2010-02-08 20:02 38784 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-07 02:15 . 2009-09-13 17:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-02-03 22:37 . 2006-01-17 13:41 35648 ----a-w- c:\documents and settings\matt\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-03 22:30 . 2006-09-11 17:42 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-02-03 19:55 . 2009-09-13 17:49 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-02-03 19:36 . 2009-09-23 21:54 -------- d-----w- c:\program files\World of Warcraft
2010-02-03 19:33 . 2010-02-03 19:33 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-02-03 19:33 . 2010-02-03 19:33 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-02-03 19:33 . 2006-09-19 20:44 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-02-03 19:33 . 2010-02-03 19:33 1291104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2010-02-03 19:33 . 2010-02-03 19:33 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2010-02-03 19:33 . 2010-02-15 18:03 165240 ----a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2010-02-03 19:33 . 2006-10-03 23:47 107368 ----a-r- c:\windows\system32\GEARAspi.dll
2010-02-03 19:33 . 2010-02-03 19:37 554352 ----a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
2010-02-03 19:33 . 2010-02-03 19:33 771440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2010-02-03 17:43 . 2009-06-23 20:43 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-03 09:26 . 2010-02-15 17:48 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100215.002\NAVENG32.DLL
2010-02-03 09:26 . 2010-02-15 17:48 1647984 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100215.002\NAVEX32A.DLL
2010-02-03 09:26 . 2010-02-15 17:48 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100215.002\EECTRL.SYS
2010-02-03 09:26 . 2010-02-15 17:48 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100215.002\CCERASER.DLL
2010-02-03 09:26 . 2010-02-15 17:48 259440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100215.002\ECMSVR32.DLL
2010-02-03 09:26 . 2010-02-15 17:48 102448 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100215.002\ERASER.SYS
2010-02-03 09:00 . 2010-02-15 17:48 84912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100215.002\NAVENG.SYS
2010-02-03 09:00 . 2010-02-15 17:48 1324720 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100215.002\NAVEX15.SYS
2010-01-11 22:00 . 2010-01-11 22:00 -------- d-----w- c:\program files\MSBuild
2010-01-11 22:00 . 2010-01-11 22:00 -------- d-----w- c:\program files\Reference Assemblies
2009-12-31 16:50 . 2003-07-16 20:46 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2005-10-21 17:51 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-16 18:43 . 2005-11-27 07:18 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2003-07-16 20:26 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:27 . 2003-07-16 20:39 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2002-08-29 01:04 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-07 14:10 . 2010-02-08 20:09 2953352 -c--a-w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-AwareInstallation.exe
2009-12-04 18:22 . 2003-07-16 20:34 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:11 . 2005-12-18 23:53 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 17:11 . 2005-08-30 14:14 1291776 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 16:07 . 2003-07-16 20:36 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-17 22:36 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2003-07-16 20:36 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2003-07-16 20:24 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2001-08-17 22:36 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-21 15:51 . 2003-07-16 20:23 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igndlm.exe"="c:\program files\IGN\Download Manager\DLM.exe" [2006-11-07 972432]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160]
"Steam"="c:\program files\Steam\Steam.exe" [2010-02-10 1217808]
"NvMediaCenter"="c:\windows\system32\NVMCTRAY.DLL" [2003-10-06 49152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-10-06 5058560]
"nwiz"="nwiz.exe" [2003-10-06 741376]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2003-10-06 49152]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WNDA3100v2 Smart Wizard.lnk - c:\program files\NETGEAR\WNDA3100v2\WNDA3100v2.exe [2010-2-3 3272704]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ 'autocheck autochk *'\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\World of Warcraft\\Repair.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Steam\\SteamApps\\cmiley\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2/8/2010 3:14 PM 64288]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SymEFA.sys [2/3/2010 9:46 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0308000.029\BHDrvx86.sys [2/3/2010 9:46 PM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0308000.029\cchpx86.sys [2/3/2010 9:46 PM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100210.001\IDSXpx86.sys [2/15/2010 12:48 PM 329592]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/2/2009 8:19 AM 1181328]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe [2/3/2010 9:44 PM 117640]
R3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\drivers\bcmwlhigh5.sys [2/3/2010 12:50 PM 632576]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/3/2010 4:26 AM 102448]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
S3 USBFVNETR;NETGEAR MA101 USB Adapter;c:\windows\system32\drivers\ma101rndxp.sys [12/17/2005 3:58 AM 76160]
.
Contents of the 'Scheduled Tasks' folder
2010-02-15 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 20:22]
2010-02-15 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 20:22]
2010-02-15 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 20:22]
2010-02-15 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 20:22]
2010-02-15 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 20:22]
2010-02-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\matt\Application Data\Mozilla\Firefox\Profiles\pvyspo5s.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
Toolbar-SITEguard - (no file)
WebBrowser-{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - (no file)
HKCU-Run-BitTorrent - c:\program files\BitTorrent\bittorrent.exe
AddRemove-Vuze - c:\program files\Vuze\uninstall.exe
AddRemove-WinPcapInst - c:\program files\WinPcap\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-02-15 13:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.8.0.41\diMaster.dll\" /prefetch:1"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PSSdk23]
"ImagePath"="\??\c:\windows\system32\Drivers\PsSdk23.drv"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-343818398-854245398-682003330-1004\Software\SecuROM\License information*]
"datasecu"=hex:62,fb,54,88,3b,0c,de,26,25,77,f0,45,bf,c3,86,6e,af,69,14,68,e5,
82,18,04,58,09,cd,05,86,c5,94,31,d5,59,4b,35,02,ed,5c,fd,86,6a,df,72,64,29,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1452)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2016)
c:\windows\system32\WININET.dll
c:\windows\system32\nView.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2010-02-15 13:18:11 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-15 18:18
Pre-Run: 15,773,057,024 bytes free
Post-Run: 15,751,237,632 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - 37AEF5475E237485F4DBED11A8CD944A