WOW! THAT WAS INTENSE! HOPE I DID IT RIGHT:)ComboFix 10-07-30.01 - paula small 07/30/2010 18:28:19.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.766.303 [GMT -4:00]
Running from: c:\documents and settings\paula small\Desktop\ComboFix.exe
AV: Norton Security Suite *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
FW: Norton Security Suite *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\PAULAS~1\LOCALS~1\Temp\1.tmp\F_IN_BOX.dll
c:\documents and settings\paula small\Local Settings\Temp\1.tmp\F_IN_BOX.dll
c:\documents and settings\paula small\Recent\Thumbs.db
C:\ntload.dll
c:\program files\Common
c:\program files\INSTALL.LOG
c:\program files\Need2Find
c:\program files\Need2Find\bar\1.bin\N2FFXTBR.JAR
c:\program files\Need2Find\bar\1.bin\N2NTSTBR.JAR
c:\program files\Need2Find\bar\1.bin\PARTNER.DAT
c:\program files\Need2Find\bar\Cache\2C4F534B.g
c:\program files\Need2Find\bar\Cache\2C4F581E
c:\program files\Need2Find\bar\History\search
c:\program files\Need2Find\bar\Settings\prevcfg.htm
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\Downloaded Program Files\f3initialsetup1.0.0.6.inf
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\Install.txt
c:\windows\Readme.txt
c:\windows\system32\_006795_.tmp.dll
c:\windows\system32\_006796_.tmp.dll
c:\windows\system32\_006797_.tmp.dll
c:\windows\system32\_006798_.tmp.dll
c:\windows\system32\_006805_.tmp.dll
c:\windows\system32\_006806_.tmp.dll
c:\windows\system32\_006807_.tmp.dll
c:\windows\system32\_006808_.tmp.dll
c:\windows\system32\_006810_.tmp.dll
c:\windows\system32\_006811_.tmp.dll
c:\windows\system32\_006814_.tmp.dll
c:\windows\system32\_006815_.tmp.dll
c:\windows\system32\_006817_.tmp.dll
c:\windows\system32\_006818_.tmp.dll
c:\windows\system32\_006819_.tmp.dll
c:\windows\system32\_006821_.tmp.dll
c:\windows\system32\_006824_.tmp.dll
c:\windows\system32\_006825_.tmp.dll
c:\windows\system32\_006829_.tmp.dll
c:\windows\system32\_006830_.tmp.dll
c:\windows\system32\_006832_.tmp.dll
c:\windows\system32\_006835_.tmp.dll
c:\windows\system32\_006837_.tmp.dll
c:\windows\system32\_006838_.tmp.dll
c:\windows\system32\_006839_.tmp.dll
c:\windows\system32\_006840_.tmp.dll
c:\windows\system32\_006841_.tmp.dll
c:\windows\system32\_006844_.tmp.dll
c:\windows\system32\_006845_.tmp.dll
c:\windows\system32\_006846_.tmp.dll
c:\windows\system32\_006847_.tmp.dll
c:\windows\system32\_006848_.tmp.dll
c:\windows\system32\_006853_.tmp.dll
c:\windows\system32\_006855_.tmp.dll
c:\windows\system32\_006856_.tmp.dll
c:\windows\system32\aGhOYJjl.ini
c:\windows\system32\aGhOYJjl.ini2
c:\windows\system32\cache329
c:\windows\system32\cache329\B_329_0_0_106800.htm
c:\windows\system32\cache329\B_329_0_0_107400.htm
c:\windows\system32\cache329\B_329_1_0_449200.gif
c:\windows\system32\cache329\B_329_1_0_449600.gif
c:\windows\system32\cache329\B_329_1_0_454300.gif
c:\windows\system32\cache329\B_329_2_0_106800.htm
c:\windows\system32\cache329\B_329_2_0_107400.htm
c:\windows\system32\cache329\B_329_3_0_106800.htm
c:\windows\system32\cache329\B_329_3_0_107400.htm
c:\windows\system32\cache329\B_329_4_0_111600.htm
c:\windows\system32\cache329\B_329_4_0_152400.htm
c:\windows\system32\cache329\B_329_4_0_155300.htm
c:\windows\system32\cache329\B_329_4_0_164100.htm
c:\windows\system32\cache329\t_B_329_0_0_106800.htm
c:\windows\system32\cache329\t_B_329_0_0_107400.htm
c:\windows\system32\cache329\t_B_329_2_0_106800.htm
c:\windows\system32\cache329\t_B_329_2_0_107400.htm
c:\windows\system32\cache329\t_B_329_3_0_106800.htm
c:\windows\system32\cache329\t_B_329_3_0_107400.htm
c:\windows\system32\cache329\t_B_329_4_0_111600.htm
c:\windows\system32\cache329\t_B_329_4_0_152400.htm
c:\windows\system32\cache329\t_B_329_4_0_155300.htm
c:\windows\system32\cache329\t_B_329_4_0_164100.htm
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\drivers\fad.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\fonts
c:\windows\system32\fonts\ACADEMY_.PFB
c:\windows\system32\fonts\ACADEMY_.PFM
c:\windows\system32\fonts\ACADEMY_.TTF
c:\windows\system32\Install.txt
c:\windows\system32\logs
c:\windows\system32\logs\Events.dat
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\Tasks\loudsfmj.job
c:\windows\Tasks\rkjqkeuc.job
c:\windows\wiaserviv.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6TO4
-------\Legacy_NPF
-------\Legacy_WINSTS
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2010-06-28 to 2010-07-30 )))))))))))))))))))))))))))))))
.
2010-07-30 21:51 . 2010-07-30 21:51 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-07-30 21:37 . 2010-07-30 22:11 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-07-30 21:27 . 2010-07-30 21:26 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-29 21:48 . 2009-08-06 23:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-07-29 21:48 . 2009-08-06 23:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-07-29 20:42 . 2010-07-29 20:42 -------- d-----w- c:\documents and settings\paula small\Application Data\Malwarebytes
2010-07-29 20:42 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-29 20:42 . 2010-07-29 20:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-29 20:42 . 2010-07-29 20:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-29 20:42 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-28 03:01 . 2010-07-28 03:03 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-27 20:35 . 2010-07-27 20:35 -------- d-----w- c:\program files\Microsoft Silverlight
2010-07-27 20:32 . 2010-07-30 00:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Update
2010-07-27 19:25 . 2010-07-27 19:30 -------- d-----w- c:\documents and settings\paula small\Application Data\DivX
2010-07-27 19:16 . 2010-07-27 20:55 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-07-16 00:01 . 2010-03-17 12:16 27072 ----a-w- c:\windows\system32\drivers\AFGSp50.sys
2010-07-16 00:00 . 2010-07-16 00:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Affinegy
2010-07-16 00:00 . 2010-07-16 00:00 -------- d-----w- c:\program files\Belkin
2010-07-14 07:32 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-03 22:48 . 2010-07-03 23:06 -------- d-----w- c:\program files\support.com
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-30 22:57 . 2009-12-15 14:00 -------- d-----w- c:\program files\Spyware Doctor
2010-07-30 22:54 . 2007-02-17 15:14 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-30 21:58 . 2003-02-25 19:13 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-30 21:56 . 2004-01-06 04:14 -------- d-----w- c:\program files\Lavasoft
2010-07-30 21:39 . 2009-02-02 11:04 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-07-30 21:38 . 2010-07-30 21:40 53632 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-07-30 21:37 . 2010-07-30 21:37 77184 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-07-30 21:33 . 2007-09-06 18:36 -------- d-----w- c:\program files\Java
2010-07-30 21:29 . 2007-09-14 14:17 -------- d-----w- c:\program files\Common Files\Java
2010-07-30 21:22 . 2010-07-30 21:22 79488 ----a-w- c:\documents and settings\paula small\Application Data\Sun\Java\jre1.6.0_21\gtapi.dll
2010-07-30 21:22 . 2010-07-30 21:22 152576 ----a-w- c:\documents and settings\paula small\Application Data\Sun\Java\jre1.6.0_21\lzma.dll
2010-07-29 19:28 . 2002-08-29 11:00 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-07-29 13:35 . 2003-04-20 02:20 -------- d-----w- c:\program files\AIM95
2010-07-27 20:49 . 2010-07-27 20:49 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-07-27 19:29 . 2010-07-27 19:29 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-16 18:13 . 2005-11-04 01:39 -------- d-----w- c:\documents and settings\paula small\Application Data\Canon
2010-07-02 00:55 . 2010-04-27 23:00 439816 ----a-w- c:\documents and settings\paula small\Application Data\Real\Update\setup3.10\setup.exe
2010-06-18 12:58 . 2008-05-06 23:34 20 -c-h--w- c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2010-06-18 12:58 . 2008-05-06 23:18 20 -c-h--w- c:\documents and settings\All Users\Application Data\PKP_DLds.DAT
2010-06-17 10:30 . 2007-08-15 20:19 -------- d-----w- c:\program files\CoffeeCup Software
2010-06-09 23:01 . 2007-07-26 08:00 45648 ------w- c:\windows\system32\drivers\pxhelp20.sys
2010-05-27 12:03 . 2010-05-27 12:03 348160 ----a-w- c:\documents and settings\paula small\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3f893591-n\msvcr71.dll
2010-05-27 12:03 . 2010-05-27 12:03 61440 ----a-w- c:\documents and settings\paula small\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-63fc4ada-n\decora-sse.dll
2010-05-27 12:03 . 2010-05-27 12:03 503808 ----a-w- c:\documents and settings\paula small\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3f893591-n\msvcp71.dll
2010-05-27 12:03 . 2010-05-27 12:03 499712 ----a-w- c:\documents and settings\paula small\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3f893591-n\jmc.dll
2010-05-27 12:03 . 2010-05-27 12:03 12800 ----a-w- c:\documents and settings\paula small\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-63fc4ada-n\decora-d3d.dll
2010-05-06 10:41 . 2004-02-06 22:05 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2002-08-29 11:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2002-07-31 23:55 . 2007-09-29 14:22 208 -csh--w- c:\windows\WSYS049.SYS
2009-12-15 07:46 . 2009-12-15 07:46 2713 --sh--w- c:\windows\SYSTEM32\fohizapi.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM"="c:\program files\AIM95\aim.exe" [2004-02-04 61440]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"NapsterShell"="c:\program files\Napster\napster.exe" [2009-02-03 323216]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2007-04-19 198184]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-08 198160]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-11-18 1243088]
"InstaLAN"="c:\program files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" [2010-03-17 1141144]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
c:\documents and settings\paula small\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-5-6 118784]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]
backup=c:\windows\pss\Exif Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GStartup.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^paula small^Start Menu^Programs^Startup^Messenger Killer Real-time Protector.lnk]
backup=c:\windows\pss\Messenger Killer Real-time Protector.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AltnetPointsManager
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CMESys
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ComcastSUPPORT
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KAZAA
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QAGENT
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Trickler
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updater
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wcmdmgr
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
2002-04-10 22:44 679936 -c--a-w- c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
2004-02-04 20:29 61440 ----a-w- c:\program files\AIM95\aim.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-10-19 12:59 126976 ----a-w- c:\windows\SYSTEM32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-10-19 12:59 155648 ----a-w- c:\windows\SYSTEM32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-01-05 20:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2009-09-08 11:06 222728 ----a-w- c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\REGSHAVE]
2002-02-05 03:32 53248 -c----w- c:\program files\REGSHAVE\REGSHAVE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-09-08 11:05 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\AIM95\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"c:\\WINDOWS\\SYSTEM32\\dfrgntfs.exe"=
"c:\\Program Files\\Broderbund\\The Print Shop\\ps.exe"=
"c:\\WINDOWS\\SYSTEM32\\taskmgr.exe"=
"c:\\WINDOWS\\SYSTEM32\\hkcmd.exe"=
"c:\\Program Files\\Windows Defender\\MSASCui.exe"=
R0 PCTCore;PCTools KDS;c:\windows\SYSTEM32\DRIVERS\PCTCore.sys [12/15/2009 10:00 AM 207792]
R0 SymDS;Symantec Data Store;c:\windows\SYSTEM32\DRIVERS\N360\0402000.00C\symds.sys [6/1/2010 5:12 PM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\SYSTEM32\DRIVERS\N360\0402000.00C\symefa.sys [6/1/2010 5:12 PM 173104]
R0 TfFsMon;TfFsMon;c:\windows\SYSTEM32\DRIVERS\TfFsMon.sys [12/15/2009 4:12 PM 51984]
R0 TfSysMon;TfSysMon;c:\windows\SYSTEM32\DRIVERS\TfSysMon.sys [12/15/2009 4:12 PM 59664]
R1 Asapi;Asapi;c:\windows\SYSTEM32\DRIVERS\asapi.sys [12/23/2003 7:27 PM 11264]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20100709.001\BHDrvx86.sys [7/12/2010 8:36 PM 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\SYSTEM32\DRIVERS\N360\0402000.00C\cchpx86.sys [6/1/2010 5:12 PM 501888]
R1 pctgntdi;pctgntdi;c:\windows\SYSTEM32\DRIVERS\pctgntdi.sys [12/15/2009 10:01 AM 233136]
R1 SymIRON;Symantec Iron Driver;c:\windows\SYSTEM32\DRIVERS\N360\0402000.00C\ironx86.sys [6/1/2010 5:12 PM 116784]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [12/15/2009 10:02 AM 112592]
R2 mrtRate;mrtRate;c:\windows\SYSTEM32\DRIVERS\MrtRate.sys [2/22/2003 12:19 PM 34712]
R2 N360;Norton Security Suite;c:\program files\Norton Security Suite\Engine\4.2.0.12\ccsvchst.exe [6/1/2010 5:11 PM 126392]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [12/15/2009 10:00 AM 359624]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/29/2010 9:13 AM 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20100729.001\IDSXpx86.sys [7/29/2010 11:10 PM 331640]
S0 klmdb;klmdb;c:\windows\system32\drivers\klmdb.sys --> c:\windows\system32\drivers\klmdb.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS --> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 pctplsg;pctplsg;c:\windows\SYSTEM32\DRIVERS\pctplsg.sys [12/15/2009 10:00 AM 70408]
S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS --> c:\program files\SUPERAntiSpyware\SASENUM.SYS [?]
S3 TfNetMon;TfNetMon;c:\windows\SYSTEM32\DRIVERS\TfNetMon.sys [12/15/2009 4:12 PM 33552]
S3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service --> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]
S3 tj2knd5;Terayon Cable Modem (NDIS);c:\windows\SYSTEM32\DRIVERS\tj2knd5.sys [8/19/2003 2:18 PM 17616]
S3 tj2kunic;Terayon Cable Modem (WDM);c:\windows\SYSTEM32\DRIVERS\tj2kunic.sys [8/19/2003 2:00 PM 69680]
--- Other Services/Drivers In Memory ---
*Deregistered* - PCTSDInjDriver32
.
Contents of the 'Scheduled Tasks' folder
2010-07-30 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\SYSTEM32\cleanmgr.exe [2002-08-29 00:12]
2010-07-30 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2008-02-22 17:25]
2010-07-27 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2008-02-22 17:25]
2010-07-30 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2009-12-11 19:00]
2010-07-30 c:\windows\Tasks\RegCure Startup.job
- c:\program files\RegCure\RegCure.exe [2009-12-11 19:00]
2010-07-29 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2009-12-11 19:00]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/
Trusted Zone: aol.com\free
.
- - - - ORPHANS REMOVED - - - -
BHO-{7339df72-14b2-4e5d-a9d9-386ba7de8611} - (no file)
Toolbar-Locked - (no file)
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKLM-Run-iinjug - c:\windows\system32\msilojzb.dll
SharedTaskScheduler-{9a23ff0c-faa5-47d7-bb1a-c9490e7793bc} - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
SSODL-vozesevus-{9a23ff0c-faa5-47d7-bb1a-c9490e7793bc} - (no file)
Notify-geBuVOfe - geBuVOfe.dll
SafeBoot-klmd24.sys
SafeBoot-mcmscsvc
SafeBoot-MCODS
MSConfigStartUp-MCAgentExe - c:\progra~1\mcafee.com\agent\mcagent.exe
MSConfigStartUp-MCUpdateExe - c:\progra~1\mcafee.com\agent\McUpdate.exe
MSConfigStartUp-MPFExe - c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe
MSConfigStartUp-VirusScan Online - c:\progra~1\mcafee.com\vso\mcvsshld.exe
MSConfigStartUp-WildTangent CDA - c:\program files\WildTangent\Apps\CDA\cdaEngine0400.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-30 18:54
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton Security Suite\Engine\4.2.0.12\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\4.2.0.12\diMaster.dll\" /prefetch:1"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Cdrom]
"ImagePath"="system32\drivers\tsk84.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3872)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\wltrysvc.exe
c:\windows\System32\bcmwltry.exe
c:\program files\Belkin\Router Setup and Monitor\BelkinService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Spyware Doctor\pctsSvc.exe
c:\windows\System32\wbem\wmiapsrv.exe
c:\program files\Belkin\Router Setup and Monitor\BelkinSetup.exe
c:\program files\Belkin\Router Setup and Monitor\ndis_events.exe
.
**************************************************************************
.
Completion time: 2010-07-30 19:18:51 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-30 23:18
Pre-Run: 19,913,744,384 bytes free
Post-Run: 19,810,865,152 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 35877DFF5B91BB563B791135891273B6