Gringo,
The PC is running fairly normal but has had the typical trojan detected once lately. The PC has been running slowly for the past 6 mos or so, and I am not sure if it is driver related or not. Here is the ComboFix report.
ComboFix 11-09-04.03 - Lawrence Sanders 09/04/2011 18:45:05.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2148 [GMT -4:00]
Running from: c:\documents and settings\Lawrence Sanders\My Documents\Downloads\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\LAWREN~1\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\Lawrence Sanders\Application Data\9ABE.4F0
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{38caccba-31ec-4e96-b83b-b5d8bfeb8572}
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{38caccba-31ec-4e96-b83b-b5d8bfeb8572}\chrome.manifest
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{38caccba-31ec-4e96-b83b-b5d8bfeb8572}\chrome\xulcache.jar
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{38caccba-31ec-4e96-b83b-b5d8bfeb8572}\defaults\preferences\xulcache.js
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{38caccba-31ec-4e96-b83b-b5d8bfeb8572}\install.rdf
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{43bcf826-77e3-4968-becd-af4563796391}
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{43bcf826-77e3-4968-becd-af4563796391}\chrome.manifest
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{43bcf826-77e3-4968-becd-af4563796391}\chrome\xulcache.jar
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{43bcf826-77e3-4968-becd-af4563796391}\defaults\preferences\xulcache.js
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{43bcf826-77e3-4968-becd-af4563796391}\install.rdf
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{915d17c0-b051-45d3-b561-1051e55c3625}
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{915d17c0-b051-45d3-b561-1051e55c3625}\chrome.manifest
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{915d17c0-b051-45d3-b561-1051e55c3625}\chrome\xulcache.jar
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{915d17c0-b051-45d3-b561-1051e55c3625}\defaults\preferences\xulcache.js
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{915d17c0-b051-45d3-b561-1051e55c3625}\install.rdf
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{ac0f9642-2635-4cd6-86fb-a56181566300}
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{ac0f9642-2635-4cd6-86fb-a56181566300}\chrome.manifest
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{ac0f9642-2635-4cd6-86fb-a56181566300}\chrome\xulcache.jar
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{ac0f9642-2635-4cd6-86fb-a56181566300}\defaults\preferences\xulcache.js
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{ac0f9642-2635-4cd6-86fb-a56181566300}\install.rdf
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{ac7d7697-11e4-4d16-8c17-2a0187ad3d5d}
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{ac7d7697-11e4-4d16-8c17-2a0187ad3d5d}\chrome.manifest
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{ac7d7697-11e4-4d16-8c17-2a0187ad3d5d}\chrome\xulcache.jar
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{ac7d7697-11e4-4d16-8c17-2a0187ad3d5d}\defaults\preferences\xulcache.js
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{ac7d7697-11e4-4d16-8c17-2a0187ad3d5d}\install.rdf
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{c1eae872-eb7d-4d68-b1f4-e668005c3cff}
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{c1eae872-eb7d-4d68-b1f4-e668005c3cff}\chrome.manifest
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{c1eae872-eb7d-4d68-b1f4-e668005c3cff}\chrome\xulcache.jar
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{c1eae872-eb7d-4d68-b1f4-e668005c3cff}\defaults\preferences\xulcache.js
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{c1eae872-eb7d-4d68-b1f4-e668005c3cff}\install.rdf
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{c30e0ee3-f621-4bc8-b8ce-57cf513454fa}
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{c30e0ee3-f621-4bc8-b8ce-57cf513454fa}\chrome.manifest
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{c30e0ee3-f621-4bc8-b8ce-57cf513454fa}\chrome\xulcache.jar
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{c30e0ee3-f621-4bc8-b8ce-57cf513454fa}\defaults\preferences\xulcache.js
c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\extensions\{c30e0ee3-f621-4bc8-b8ce-57cf513454fa}\install.rdf
c:\documents and settings\Lawrence Sanders\g2mdlhlpx.exe
c:\documents and settings\Lawrence Sanders\gbfgstiywc.tmp
c:\documents and settings\Lawrence Sanders\Local Settings\Application Data\.#
c:\documents and settings\Lawrence Sanders\Local Settings\Temp\IadHide5.dll
c:\documents and settings\LocalService\Application Data\02000000ee6099fd1406C.manifest
c:\documents and settings\LocalService\Application Data\02000000ee6099fd1406O.manifest
c:\documents and settings\LocalService\Application Data\02000000ee6099fd1406P.manifest
c:\documents and settings\LocalService\Application Data\02000000ee6099fd1406S.manifest
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{38caccba-31ec-4e96-b83b-b5d8bfeb8572}
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{38caccba-31ec-4e96-b83b-b5d8bfeb8572}\chrome.manifest
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{38caccba-31ec-4e96-b83b-b5d8bfeb8572}\chrome\xulcache.jar
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{38caccba-31ec-4e96-b83b-b5d8bfeb8572}\defaults\preferences\xulcache.js
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{38caccba-31ec-4e96-b83b-b5d8bfeb8572}\install.rdf
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{43bcf826-77e3-4968-becd-af4563796391}
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{43bcf826-77e3-4968-becd-af4563796391}\chrome.manifest
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{43bcf826-77e3-4968-becd-af4563796391}\chrome\xulcache.jar
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{43bcf826-77e3-4968-becd-af4563796391}\defaults\preferences\xulcache.js
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{43bcf826-77e3-4968-becd-af4563796391}\install.rdf
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{915d17c0-b051-45d3-b561-1051e55c3625}
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{915d17c0-b051-45d3-b561-1051e55c3625}\chrome.manifest
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{915d17c0-b051-45d3-b561-1051e55c3625}\chrome\xulcache.jar
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{915d17c0-b051-45d3-b561-1051e55c3625}\defaults\preferences\xulcache.js
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{915d17c0-b051-45d3-b561-1051e55c3625}\install.rdf
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{ac0f9642-2635-4cd6-86fb-a56181566300}
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{ac0f9642-2635-4cd6-86fb-a56181566300}\chrome.manifest
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{ac0f9642-2635-4cd6-86fb-a56181566300}\chrome\xulcache.jar
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{ac0f9642-2635-4cd6-86fb-a56181566300}\defaults\preferences\xulcache.js
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{ac0f9642-2635-4cd6-86fb-a56181566300}\install.rdf
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{ac7d7697-11e4-4d16-8c17-2a0187ad3d5d}
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{ac7d7697-11e4-4d16-8c17-2a0187ad3d5d}\chrome.manifest
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{ac7d7697-11e4-4d16-8c17-2a0187ad3d5d}\chrome\xulcache.jar
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{ac7d7697-11e4-4d16-8c17-2a0187ad3d5d}\defaults\preferences\xulcache.js
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{ac7d7697-11e4-4d16-8c17-2a0187ad3d5d}\install.rdf
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{c1eae872-eb7d-4d68-b1f4-e668005c3cff}
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{c1eae872-eb7d-4d68-b1f4-e668005c3cff}\chrome.manifest
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{c1eae872-eb7d-4d68-b1f4-e668005c3cff}\chrome\xulcache.jar
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{c1eae872-eb7d-4d68-b1f4-e668005c3cff}\defaults\preferences\xulcache.js
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{c1eae872-eb7d-4d68-b1f4-e668005c3cff}\install.rdf
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{c30e0ee3-f621-4bc8-b8ce-57cf513454fa}
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{c30e0ee3-f621-4bc8-b8ce-57cf513454fa}\chrome.manifest
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{c30e0ee3-f621-4bc8-b8ce-57cf513454fa}\chrome\xulcache.jar
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{c30e0ee3-f621-4bc8-b8ce-57cf513454fa}\defaults\preferences\xulcache.js
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{c30e0ee3-f621-4bc8-b8ce-57cf513454fa}\install.rdf
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{f877cf94-bcec-4fe8-803f-1ed0733cf355}
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{f877cf94-bcec-4fe8-803f-1ed0733cf355}\chrome.manifest
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{f877cf94-bcec-4fe8-803f-1ed0733cf355}\chrome\xulcache.jar
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{f877cf94-bcec-4fe8-803f-1ed0733cf355}\defaults\preferences\xulcache.js
c:\documents and settings\Toni\Application Data\Mozilla\Firefox\Profiles\7s4q7eir.default\extensions\{f877cf94-bcec-4fe8-803f-1ed0733cf355}\install.rdf
c:\windows\bwUnin-7.2.0.137-8876480SL.exe
c:\windows\dasetup.log
c:\windows\system32\lvci12101110.dll
c:\windows\system32\qXyHiRqr.ini
c:\windows\system32\rfbroshr.ini
c:\windows\system32\ShellManager10E2D762.dll
c:\windows\system32\twain.dll
c:\windows\wiaserviv.log
C:\xcrashdump.dat
.
.
((((((((((((((((((((((((( Files Created from 2011-08-04 to 2011-09-04 )))))))))))))))))))))))))))))))
.
.
2011-08-31 02:37 . 2007-05-11 03:52 95864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-08-30 05:21 . 2011-08-30 05:21 -------- d-----w- c:\documents and settings\Lawrence Sanders\Application Data\MSNInstaller
2011-08-28 21:04 . 2011-08-28 21:04 -------- d-----w- c:\documents and settings\Lawrence Sanders\Local Settings\Application Data\Western Digital
2011-08-23 04:52 . 2011-08-23 04:52 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2011-08-23 01:21 . 2011-07-06 23:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-23 01:21 . 2011-08-23 01:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-23 01:21 . 2011-07-06 23:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-12 01:33 . 2011-08-12 01:33 -------- d-----w- c:\documents and settings\LocalService\Application Data\Temp
2011-08-11 01:30 . 2011-08-24 12:42 -------- d-----w- c:\documents and settings\Lawrence Sanders\Local Settings\Application Data\Eastman_Kodak_Company
2011-08-11 01:25 . 2011-08-11 01:25 -------- d-----w- c:\documents and settings\Lawrence Sanders\Local Settings\Application Data\Eastman Kodak Company
2011-08-11 01:25 . 2011-08-24 12:40 -------- d-----w- c:\windows\system32\kodak
2011-08-11 01:18 . 2011-08-24 12:42 -------- d-----w- c:\program files\Kodak
2011-08-11 01:11 . 2011-08-11 01:11 -------- d-----w- c:\documents and settings\Lawrence Sanders\Application Data\Temp
2011-08-11 01:11 . 2011-08-24 12:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Kodak
2011-08-10 23:43 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-10 23:42 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-27 00:25 . 2011-06-22 19:13 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-15 13:29 . 2006-02-28 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2006-02-28 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10 . 2007-02-21 11:24 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36 . 2006-02-28 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36 . 2006-02-28 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36 . 2006-02-28 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2006-02-28 12:00 385024 ----a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2006-02-28 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-06-13 03:53 . 2010-02-15 04:10 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2011-06-13 03:53 . 2010-02-15 04:10 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2009-12-04 15:57 . 2009-12-04 15:57 28488 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2009-12-04 15:57 . 2009-12-04 15:57 185240 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2009-12-04 15:57 . 2009-12-04 15:57 46408 ----a-w- c:\program files\mozilla firefox\plugins\atmccli.dll
2009-09-13 03:05 . 2009-09-13 03:05 124240 ----a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll
2009-09-13 03:06 . 2009-09-13 03:06 13136 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2009-09-13 03:06 . 2009-09-13 03:06 70488 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2009-09-13 03:06 . 2009-09-13 03:06 91480 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2009-09-13 03:06 . 2009-09-13 03:06 22360 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2009-09-13 03:07 . 2009-09-13 03:07 255312 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2009-09-13 03:06 . 2009-09-13 03:06 31064 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2009-09-13 03:06 . 2009-09-13 03:06 40280 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2009-12-04 15:57 . 2009-12-04 15:57 99224 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
2009-08-14 17:33 . 2009-08-14 17:33 652640 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2009-09-13 03:06 . 2009-09-13 03:06 23896 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Lawrence Sanders\Application Data\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Lawrence Sanders\Application Data\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\documents and settings\Lawrence Sanders\Application Data\Dropbox\bin\DropboxExt.13.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-12 32768]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-19 76304]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-12 623992]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-19 76304]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"CTHelper"="CTHELPER.EXE" [2006-12-12 19456]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2009-09-13 103768]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-07-08 1753192]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-07-09 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-07-09 13923432]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-13 122880]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"CTxfiHlp"="CTXFIHLP.EXE" [2009-06-04 25600]
"Conime"="c:\windows\system32\conime.exe" [2008-04-14 27648]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-3-12 450560]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-6-16 809488]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-02-19 04:30 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Lawrence Sanders^Start Menu^Programs^Startup^Cyber-shot Viewer Media Check Tool.lnk]
backup=c:\windows\pss\Cyber-shot Viewer Media Check Tool.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Lawrence Sanders^Start Menu^Programs^Startup^HotSync Manager.lnk]
backup=c:\windows\pss\HotSync Manager.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-12 03:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelAudioStudio]
2006-06-07 23:11 9129984 ----a-w- c:\program files\Intel Audio Studio\IntelAudioStudio.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 19:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-07-09 20:24 110696 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 15:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NMIndexingService"=3 (0x3)
"LBTServ"=3 (0x3)
"IntuitUpdateService"=2 (0x2)
"gusvc"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"DAUpdaterSvc"=3 (0x3)
"CTAudSvcService"=2 (0x2)
"Bonjour Service"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3-enUS-downloader.exe"=
"c:\\Program Files\\PhotoParade\\PhotoParade.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.0.3.6299-to-2.0.12.6546-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\BNUpdate.exe"=
"c:\\Program Files\\World of Warcraft\\WoW.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Avira\\AntiVir Desktop\\update.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"c:\\Program Files\\Steam\\steamapps\\freeholdlove@msn.com\\counter-strike\\hl.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Steam\\steam.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Documents and Settings\\Lawrence Sanders\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\World of Warcraft\\wow-2.1.1.1897-enUS-tools-downloader.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Steam\\steamapps\\freeholdlove@msn.com\\day of defeat\\hl.exe"=
"c:\\Program Files\\Steam\\steamapps\\freeholdlove@msn.com\\counter-strike source\\hl2.exe"=
"c:\\Documents and Settings\\Lawrence Sanders\\Local Settings\\Apps\\2.0\\DERB7DPL.LL1\\POQ4RQO8.9Z1\\curs..tion_eee711038731a406_0004.0000_0d453ed5fea2fe48\\CurseClient.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"6881:TCP"= 6881:TCP:Blizzard Downloader
"7230:TCP"= 7230:TCP:Requiem
"7110:TCP"= 7110:TCP:Requiem
"1200:UDP"= 1200:UDP:Steam
"27000:UDP"= 27000:UDP:Steam
"27015:UDP"= 27015:UDP:Steam
"5353:UDP"= 5353:UDP:Bonjour Port 5353
.
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [11/12/2008 5:02 PM 29808]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [4/29/2009 4:41 PM 108289]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [6/4/2009 3:46 AM 171032]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [6/4/2009 3:46 AM 1324056]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [6/4/2009 3:46 AM 72728]
S2 AudioSrv32;Windows Audio ;c:\windows\system32\syssetup32.exe --> c:\windows\system32\syssetup32.exe [?]
S2 WRConsumerService;Webroot Client Service;"c:\program files\WebrootSecurity\WRConsumerService.exe" --> c:\program files\WebrootSecurity\WRConsumerService.exe [?]
S3 cmudaxu;C-Media USB Sound Interface;c:\windows\system32\drivers\cmudaxu.sys [3/12/2007 8:36 AM 1391296]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [12/18/2009 11:58 AM 11336]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2/15/2010 12:47 AM 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [6/4/2009 3:46 AM 171032]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [6/4/2009 3:46 AM 1324056]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [6/4/2009 3:46 AM 72728]
S3 ExterminateIt;ExterminateIt;c:\windows\system32\drivers\extit.sys [4/27/2009 10:15 PM 22016]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [3/27/2009 2:23 PM 23064]
S4 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [12/15/2009 4:07 PM 25832]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]
.
2010-04-18 c:\windows\Tasks\switchShakeIcon.job
- c:\program files\NCH Swift Sound\Switch\switch.exe [2010-04-18 01:17]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: turbotax.com
TCP: DhcpNameServer = 192.168.1.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 - vpnweb.cab
FF - ProfilePath - c:\documents and settings\Lawrence Sanders\Application Data\Mozilla\Firefox\Profiles\4ru2i016.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.type - 4
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
FF - Ext: Zoodles: firefox@zoodles.com - %profile%\extensions\firefox@zoodles.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{690E0B29-DE0B-42F7-BF6D-90E348E6DC09} - c:\windows\system32\atl7132.dll
Notify-a0b69cb1669 - c:\windows\System32\drmclien32.dll
Notify-efcDWnmk - efcDWnmk.dll
MSConfigStartUp-EKAIO2StatusMonitor - c:\windows\System32\spool\DRIVERS\W32X86\3\EKAiO2MUI.exe
MSConfigStartUp-My Web Search Bar - c:\progra~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL
MSConfigStartUp-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\2.bin\M3PLUGIN.DLL
AddRemove-uTorrent - c:\program files\uTorrent\uTorrent.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-09-04 18:56
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(732)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
- - - - - - - > 'explorer.exe'(3800)
c:\windows\system32\WININET.dll
c:\docume~1\LAWREN~1\LOCALS~1\Temp\IadHide5.dll
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\documents and settings\Lawrence Sanders\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\ctagent.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\AMT\LMS.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\CTHELPER.EXE
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\CTXFIHLP.EXE
c:\program files\Citrix\ICA Client\wfcrun32.exe
c:\windows\SYSTEM32\CTXFISPI.EXE
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-09-04 19:06:52 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-04 23:06
.
Pre-Run: 82,564,730,880 bytes free
Post-Run: 82,673,336,320 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 2E882CED8E57B2C271483BB0847F84F1
Thanks,
Zebachiah