My computer seems to run fine. I play COD4 alot and it runs good….My net cuts in/out trying to find a connection when i play or sit idle..
Here is the log.
ComboFix 10-02-27.04 - Keith R 02/27/2010 17:51:26.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1023.727 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: NVIDIA Firewall *enabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2010-01-27 to 2010-02-27 )))))))))))))))))))))))))))))))
.
2010-02-27 18:40 . 2010-02-27 18:40 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-02-27 18:40 . 2010-02-27 18:40 95024 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2010-02-27 18:40 . 2010-02-27 18:40 598368 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScanner.dll
2010-02-27 18:40 . 2010-02-27 18:40 566608 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll
2010-02-27 18:40 . 2010-02-27 18:40 221408 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2010-02-27 18:40 . 2010-02-27 18:40 247120 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll
2010-02-27 18:40 . 2010-02-27 18:40 1230160 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll
2010-02-27 18:40 . 2010-02-27 18:40 17480 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScannerBridge.dll
2010-02-27 15:12 . 2010-02-27 15:12 ——– d—–w- c:\documents and settings\Keith R\Application Data\Malwarebytes
2010-02-27 15:12 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-27 15:12 . 2010-02-27 15:12 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-27 15:12 . 2010-02-27 15:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-27 15:12 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-27 15:11 . 2010-02-27 15:11 ——– d—–w- c:\program files\ERUNT
2010-02-27 04:14 . 2010-02-27 04:14 ——– d—–w- c:\program files\Trend Micro
2010-02-27 04:07 . 2010-02-27 04:07 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-02-27 04:07 . 2010-02-04 15:53 2954656 -c–a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-02-20 21:00 . 2010-02-20 21:00 ——– d—–w- c:\documents and settings\Keith R\Local Settings\Application Data\Nero
2010-02-11 03:16 . 2010-02-11 03:16 41872 —-a-w- c:\windows\system32\xfcodec.dll
2010-02-03 02:41 . 2010-02-27 17:39 ——– d—–w- c:\documents and settings\Keith R\Application Data\skypePM
2010-02-03 02:41 . 2010-02-03 02:41 56 —ha-w- c:\windows\system32\ezsidmv.dat
2010-02-03 02:39 . 2010-02-27 18:59 ——– d—–w- c:\documents and settings\Keith R\Application Data\Skype
2010-02-03 02:39 . 2010-02-03 02:39 ——– d—–w- c:\program files\Common Files\Skype
2010-02-03 02:39 . 2010-02-03 02:39 ——– d—–r- c:\program files\Skype
2010-02-03 02:39 . 2010-02-03 02:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2010-01-30 23:07 . 2010-01-30 23:07 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Xfire
2010-01-29 03:29 . 2010-01-29 03:29 ——– d—–w- c:\documents and settings\Keith R\Application Data\Nero
2010-01-29 03:06 . 2010-01-29 03:17 ——– d—–w- c:\program files\Nero
2010-01-29 03:05 . 2010-01-29 03:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Nero
2010-01-29 03:05 . 2010-01-29 03:12 ——– d—–w- c:\program files\Common Files\Nero
2010-01-29 03:04 . 2010-01-29 03:04 ——– d—–w- c:\program files\MSBuild
2010-01-29 03:04 . 2010-01-29 03:04 62304 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-01-29 03:01 . 2010-01-29 03:01 ——– d—–w- c:\windows\system32\XPSViewer
2010-01-29 03:01 . 2010-01-29 03:01 ——– d—–w- c:\program files\Reference Assemblies
2010-01-29 03:01 . 2006-10-15 00:43 27648 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-01-29 03:01 . 2006-06-29 21:07 14048 ——w- c:\windows\system32\spmsg2.dll
2010-01-29 02:59 . 2006-10-17 00:10 23856 —-a-w- c:\windows\system32\spupdsvc.exe
2010-01-29 02:04 . 2010-01-29 02:04 ——– d—–w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2010-01-29 02:03 . 2010-01-12 04:03 61440 —-a-w- c:\windows\system32\OpenCL.dll
2010-01-29 02:03 . 2010-01-12 04:03 4104192 —-a-w- c:\windows\system32\nvcuda.dll
2010-01-29 02:03 . 2010-01-12 04:03 4077672 —-a-w- c:\windows\system32\nvcuvenc.dll
2010-01-29 02:03 . 2010-01-12 04:03 2259560 —-a-w- c:\windows\system32\nvcuvid.dll
2010-01-29 02:03 . 2010-01-12 04:03 2283526 —-a-w- c:\windows\system32\nvdata.bin
2010-01-29 02:03 . 2010-01-12 04:03 11632640 —-a-w- c:\windows\system32\nvcompiler.dll
2010-01-29 02:03 . 2010-01-29 02:03 ——– d—–w- C:\NVIDIA
2010-01-29 02:02 . 2010-01-29 02:02 ——– d—–w- c:\program files\SystemRequirementsLab
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-27 23:51 . 2010-01-19 02:51 ——– d—–w- c:\documents and settings\Keith R\Application Data\Xfire
2010-02-27 21:59 . 2010-01-19 02:40 138576 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-02-27 21:59 . 2010-01-19 02:40 215104 —-a-w- c:\windows\system32\PnkBstrB.exe
2010-02-27 21:11 . 2010-01-23 00:56 ——– d—–w- c:\program files\Steam
2010-02-27 04:07 . 2010-01-23 20:38 ——– d—–w- c:\program files\Lavasoft
2010-02-27 04:03 . 2010-01-23 20:40 3803208 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-02-25 23:01 . 2010-01-19 02:51 ——– d—–w- c:\program files\Xfire
2010-01-29 03:30 . 2010-01-23 20:54 12328 —-a-w- c:\documents and settings\Keith R\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-29 02:04 . 2010-01-19 02:05 ——– d—–w- c:\program files\NVIDIA Corporation
2010-01-28 02:40 . 2010-01-23 20:43 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-01-28 02:40 . 2010-01-23 20:40 8 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2010-01-23 20:40 . 2010-01-23 20:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-22 14:45 . 2010-01-22 14:45 ——– d—–w- c:\program files\MSN Toolbar Installer
2010-01-22 14:45 . 2010-01-22 14:45 ——– d—–w- c:\program files\Common Files\Java
2010-01-22 14:44 . 2010-01-22 14:44 61440 —-a-w- c:\documents and settings\Keith R\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-45fdd050-n\decora-sse.dll
2010-01-22 14:44 . 2010-01-22 14:44 503808 —-a-w- c:\documents and settings\Keith R\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5b972254-n\msvcp71.dll
2010-01-22 14:44 . 2010-01-22 14:44 499712 —-a-w- c:\documents and settings\Keith R\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5b972254-n\jmc.dll
2010-01-22 14:44 . 2010-01-22 14:44 348160 —-a-w- c:\documents and settings\Keith R\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-5b972254-n\msvcr71.dll
2010-01-22 14:44 . 2010-01-22 14:44 12800 —-a-w- c:\documents and settings\Keith R\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-45fdd050-n\decora-d3d.dll
2010-01-22 14:44 . 2010-01-22 14:44 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-01-22 14:44 . 2010-01-22 14:44 ——– d—–w- c:\program files\Java
2010-01-20 04:05 . 2010-01-19 03:56 77423 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-01-20 01:52 . 2010-01-20 01:52 ——– d—–w- c:\documents and settings\Keith R\Application Data\Ventrilo
2010-01-19 05:17 . 2010-01-19 02:39 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2010-01-19 03:56 . 2010-01-19 03:56 ——– d—–w- c:\program files\microsoft frontpage
2010-01-19 03:53 . 2010-01-19 03:53 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-01-19 02:57 . 2010-01-19 02:57 ——– d—–w- c:\program files\Ventrilo
2010-01-19 02:57 . 2010-01-19 02:57 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-01-19 02:56 . 2010-01-19 02:56 ——– d—–w- c:\documents and settings\LocalService\Application Data\Xfire
2010-01-19 02:54 . 2010-01-19 02:54 ——– d—–w- c:\documents and settings\NetworkService\Application Data\Xfire
2010-01-19 02:53 . 2010-01-19 02:53 ——– d—–w- c:\program files\Opera
2010-01-19 02:40 . 2010-01-19 02:40 22328 —-a-w- c:\documents and settings\Keith R\Application Data\PnkBstrK.sys
2010-01-19 02:40 . 2010-01-19 02:40 22328 —-a-w- c:\documents and settings\Keith R\Application Data\PnkBstrK.sys
2010-01-19 02:39 . 2010-01-19 02:06 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-01-19 02:26 . 2010-01-19 02:26 ——– d—–w- c:\program files\Activision
2010-01-19 02:23 . 2010-01-19 02:23 ——– d—–w- c:\documents and settings\All Users\Application Data\nView_Profiles
2010-01-19 02:17 . 2010-01-19 02:16 ——– d—–w- c:\program files\Razer
2010-01-19 02:11 . 2010-01-19 02:09 ——– d—–w- c:\program files\ASUS
2010-01-19 02:10 . 2010-01-19 02:10 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-19 02:06 . 2010-01-19 02:06 ——– d—–w- c:\program files\Realtek Sound Manager
2010-01-19 02:06 . 2010-01-19 02:06 ——– d—–w- c:\program files\AvRack
2010-01-19 02:06 . 2010-01-19 04:03 ——– d—–w- c:\program files\Common Files\InstallShield
2010-01-12 06:17 . 2010-01-12 06:17 278120 —-a-w- c:\windows\system32\nvmccs.dll
2010-01-12 06:17 . 2010-01-12 06:17 154216 —-a-w- c:\windows\system32\nvsvc32.exe
2010-01-12 06:17 . 2010-01-12 06:17 145000 —-a-w- c:\windows\system32\nvcolor.exe
2010-01-12 06:17 . 2010-01-12 06:17 13666408 —-a-w- c:\windows\system32\nvcpl.dll
2010-01-12 06:17 . 2010-01-12 06:17 110696 —-a-w- c:\windows\system32\nvmctray.dll
2010-01-12 06:17 . 2010-01-12 06:17 81920 —-a-w- c:\windows\system32\nvwddi.dll
2010-01-12 04:03 . 2010-01-19 02:14 592488 —-a-w- c:\windows\system32\nvudisp.exe
2010-01-12 04:03 . 2010-01-19 02:14 14458880 —-a-w- c:\windows\system32\nvoglnt.dll
2010-01-12 04:03 . 2010-01-19 02:13 182888 —-a-w- c:\windows\system32\nvcodins.dll
2010-01-12 04:03 . 2010-01-19 02:13 182888 —-a-w- c:\windows\system32\nvcod.dll
2010-01-12 04:03 . 2010-01-19 02:13 1081344 —-a-w- c:\windows\system32\nvapi.dll
2010-01-12 04:03 . 2010-01-19 02:13 10276768 —-a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-01-12 04:03 . 2010-01-19 02:13 6359168 —-a-w- c:\windows\system32\nv4_disp.dll
2009-12-02 13:19 . 2010-01-23 20:40 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-04-30 266240]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 77824]
"Launch Ai Booster"="c:\program files\ASUS\Ai Booster\OverClk.exe" [2005-06-16 3627520]
"razer"="c:\program files\Razer\Copperhead\razerhid.exe" [2005-10-09 155648]
"Tarantula"="c:\program files\Razer\Tarantula\razerhid.exe" [2006-09-30 176128]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-12 13666408]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-01-12 110696]
c:\documents and settings\Keith R\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1/23/2010 2:40 PM 64288]
R3 Razerlow;Razer Copperhead Driver;c:\windows\system32\drivers\Razerlow.sys [1/18/2010 8:16 PM 19020]
R3 TarFltr;Razer Tarantula USB Keyboard;c:\windows\system32\drivers\UsbFltr.sys [1/18/2010 8:17 PM 44800]
— Other Services/Drivers In Memory —
*NewlyCreated* - PNKBSTRB
.
Contents of the 'Scheduled Tasks' folder
2010-02-27 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 18:40]
2010-02-27 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 18:40]
2010-02-27 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 18:40]
2010-02-27 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 18:40]
2010-02-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 18:40]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
LSP: %SYSTEMROOT%\system32\nvappfilter.dll
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-nwiz - nwiz.exe
SafeBoot-Lavasoft Ad-Aware Service
AddRemove-NVIDIA Display Control Panel - c:\program files\NVIDIA Corporation\Uninstall\nvuninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-27 17:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'lsass.exe'(700)
c:\windows\system32\nvappfilter.dll
.
Completion time: 2010-02-27 17:53:55
ComboFix-quarantined-files.txt 2010-02-27 23:53
Pre-Run: 101,418,168,320 bytes free
Post-Run: 101,389,111,296 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 2DC3467136D182519800CDCC1078E3C8