mkryan1
Ok, I hope I did it. Here's what I got:
ComboFix 10-11-29.05 - MJR_2 11/30/2010 5:54:06.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.381 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
.
((((((((((((((((((((((((( Files Created from 2010-10-28 to 2010-11-30 )))))))))))))))))))))))))))))))
.
2010-11-28 10:45:40 . 2010-11-28 10:45:38 98392 —-a-w- C:\WINDOWS\system32\drivers\SBREDrv.sys
2010-11-28 00:33:18 . 2010-11-28 00:34:29 ——– d—–w- C:\Documents and Settings\MJR_2\Application Data\Apple Computer
2010-11-25 15:28:16 . 2008-04-14 00:12:07 26624 —-a-w- C:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2010-11-25 15:06:30 . 2010-11-25 15:06:31 ——– d—–w- C:\Program Files\Windows Media Connect 2
2010-11-25 15:05:05 . 2010-11-25 15:05:42 ——– d—–w- C:\WINDOWS\system32\drivers\UMDF
2010-11-25 15:05:05 . 2010-11-25 15:05:05 ——– d—–w- C:\WINDOWS\system32\LogFiles
2010-11-25 14:58:50 . 2010-11-25 15:04:13 ——– d—–w- C:\WINDOWS\system32\NtmsData
2010-11-25 14:22:43 . 2010-11-26 13:18:58 ——– d—–w- C:\Documents and Settings\Guest
2010-11-25 11:35:22 . 2010-09-23 07:46:08 15880 —-a-w- C:\WINDOWS\system32\lsdelete.exe
2010-11-25 10:19:34 . 2010-09-23 07:46:08 64288 —-a-w- C:\WINDOWS\system32\drivers\Lbd.sys
2010-11-25 10:19:24 . 2010-11-25 10:19:24 ——– d—–w- C:\Documents and Settings\MJR_2\Local Settings\Application Data\Sunbelt Software
2010-11-25 10:11:29 . 2010-11-25 10:11:31 ——– dc-h–w- C:\Documents and Settings\All Users\Application Data\{E961CE1B-C3EA-4882-9F67-F859B555D097}
2010-11-25 10:10:47 . 2010-11-25 10:19:39 ——– d—–w- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-11-25 10:10:47 . 2010-11-25 10:10:47 ——– d—–w- C:\Program Files\Lavasoft
2010-11-24 12:04:40 . 2010-11-24 12:04:40 388096 —-a-r- C:\Documents and Settings\MJR_2\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-11-24 11:35:51 . 2010-11-24 11:35:51 ——– d—–w- C:\Program Files\Trend Micro
2010-11-23 06:52:37 . 2010-11-23 06:52:37 ——– d—–w- C:\Documents and Settings\MJR\Application Data\Tific
2010-11-23 06:52:34 . 2010-11-23 06:52:34 ——– d—–w- C:\Documents and Settings\MJR\Local Settings\Application Data\Symantec
2010-11-21 22:05:33 . 2010-11-21 22:05:33 ——– d—–w- C:\Documents and Settings\MJR_2\Application Data\Tific
2010-11-21 22:05:18 . 2010-11-21 22:05:18 ——– d—–w- C:\Documents and Settings\MJR_2\Local Settings\Application Data\Symantec
2010-11-21 22:04:01 . 2010-11-21 22:04:01 ——– d—–w- C:\WINDOWS\system32\wbem\Repository
2010-11-20 22:41:05 . 2010-11-20 22:41:05 ——– d—–w- C:\Documents and Settings\MJR_2\Application Data\Malwarebytes
2010-11-20 22:40:53 . 2010-11-27 02:25:38 ——– d—–w- C:\Program Files\Malwarebytes' Anti-Malware
2010-11-20 22:40:53 . 2010-11-20 22:40:53 ——– d—–w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-11-12 12:40:16 . 2010-11-12 12:40:16 ——– d—–w- C:\Program Files\PurePlay
2010-11-12 12:40:16 . 2010-11-12 12:40:16 ——– d—–w- C:\Documents and Settings\All Users\Application Data\PurePlay
2010-11-12 05:19:05 . 2010-11-12 05:24:40 ——– d—–w- C:\Documents and Settings\MJR\Local Settings\Application Data\Adobe
2010-11-12 02:28:56 . 2008-04-13 19:45:40 32128 -c–a-w- C:\WINDOWS\system32\dllcache\usbccgp.sys
2010-11-12 02:28:56 . 2008-04-13 19:45:40 32128 —-a-w- C:\WINDOWS\system32\drivers\usbccgp.sys
2010-11-06 19:37:34 . 2010-11-06 19:37:34 103864 —-a-w- C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
2010-11-06 19:37:34 . 2010-11-06 19:37:34 103864 —-a-w- C:\Program Files\Internet Explorer\Plugins\nppdf32.dll
2010-10-31 17:02:55 . 2010-10-31 17:03:00 ——– d—–w- C:\Program Files\Veetle
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-15 11:10:24 . 2010-05-26 22:36:08 60808 —-a-w- C:\WINDOWS\system32\S32EVNT1.DLL
2010-10-15 11:10:24 . 2010-05-26 22:36:08 126512 —-a-w- C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2010-09-18 19:23:26 . 2006-02-28 12:00:00 974848 —-a-w- C:\WINDOWS\system32\mfc42u.dll
2010-09-18 06:53:25 . 2006-02-28 12:00:00 974848 —-a-w- C:\WINDOWS\system32\mfc42.dll
2010-09-18 06:53:25 . 2006-02-28 12:00:00 954368 —-a-w- C:\WINDOWS\system32\mfc40.dll
2010-09-18 06:53:25 . 2006-02-28 12:00:00 953856 —-a-w- C:\WINDOWS\system32\mfc40u.dll
2010-09-15 11:50:37 . 2010-05-29 03:34:58 472808 —-a-w- C:\WINDOWS\system32\deployJava1.dll
2010-09-15 09:29:49 . 2010-05-29 03:34:58 73728 —-a-w- C:\WINDOWS\system32\javacpl.cpl
2010-09-10 05:58:08 . 2006-02-28 12:00:00 916480 —-a-w- C:\WINDOWS\system32\wininet.dll
2010-09-10 05:58:06 . 2006-02-28 12:00:00 43520 —-a-w- C:\WINDOWS\system32\licmgr10.dll
2010-09-10 05:58:06 . 2006-02-28 12:00:00 1469440 ——w- C:\WINDOWS\system32\inetcpl.cpl
2010-09-08 18:17:46 . 2010-09-08 18:17:46 94208 —-a-w- C:\WINDOWS\system32\QuickTimeVR.qtx
2010-09-08 18:17:46 . 2010-09-08 18:17:46 69632 —-a-w- C:\WINDOWS\system32\QuickTime.qts
.
——- Sigcheck ——-
[7] 2008-06-20 11:59:02 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)] . . C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 11:51:12 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] . . C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:51:12 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] . . C:\WINDOWS\system32\dllcache\tcpip.sys
[-] 2008-06-20 11:51:12 . 4AFB3B0919649F95C1964AA1FAD27D73 . 361600 . . [5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] . . C:\WINDOWS\system32\drivers\tcpip.sys
[7] 2008-06-20 10:45:13 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394 (xpsp_sp2_gdr.080620-1245)] . . C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
[7] 2008-06-20 10:44:42 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394 (xpsp_sp2_qfe.080620-1259)] . . C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-04-13 19:20:16 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
[7] 2008-04-13 19:20:16 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
[7] 2006-02-28 12:00:00 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] . . C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AutoStartNPSAgent"="C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-11-07 01:28:22 116056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PROMon.exe"="PROMon.exe" [2002-04-19 01:32:36 73728]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-04-05 06:22:32 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-04-05 06:19:18 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-04-05 06:23:14 114688]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-07-30 16:08:58 143360]
"Bing Bar"="C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe" [2010-04-27 23:39:38 243544]
"Microsoft Default Manager"="C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-12 00:43:04 288088]
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 18:44:46 248552]
"DivXUpdate"="C:\Program Files\DivX\DivX Update\DivXUpdate.exe" [2010-09-01 06:39:18 1164584]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 11:47:04 35760]
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 06:07:44 932288]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2010-09-08 18:17:42 421888]
"Norton Online Backup"="C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-08 19:25:10 968536]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe"=
"C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"=
"C:\\Program Files\\Symantec\\Norton Online Backup\\NOBuClient.exe"=
R0 Lbd;Lbd;C:\WINDOWS\system32\drivers\Lbd.sys [11/25/2010 2:19:34 AM 64288]
R0 SymDS;Symantec Data Store;C:\WINDOWS\system32\drivers\NAV\1201000.025\SymDS.sys [10/15/2010 3:10:14 AM 339504]
R0 SymEFA;Symantec Extended File Attributes;C:\WINDOWS\system32\drivers\NAV\1201000.025\SymEFA.sys [10/15/2010 3:10:14 AM 666672]
R1 BHDrvx86;BHDrvx86;C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20101104.001\BHDrvx86.sys [11/3/2010 4:07:06 PM 691248]
R1 SymIRON;Symantec Iron Driver;C:\WINDOWS\system32\drivers\NAV\1201000.025\Ironx86.sys [10/15/2010 3:10:14 AM 134704]
R2 Fabs;FABS - Helping agent for MAGIX media database;C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [8/27/2009 4:09:10 PM 1253376]
R2 FsUsbExService;FsUsbExService;C:\WINDOWS\system32\FsUsbExService.Exe [7/11/2010 7:02:54 PM 238952]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [9/22/2010 11:46:07 PM 1375992]
R2 NAV;Norton AntiVirus;C:\Program Files\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe [10/15/2010 3:10:05 AM 126904]
R2 NOBU;Norton Online Backup;C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe [6/8/2010 11:20:16 AM 2057560]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [11/26/2010 11:01:50 PM 102448]
R3 FsUsbExDisk;FsUsbExDisk;C:\WINDOWS\system32\FsUsbExDisk.Sys [7/11/2010 7:02:54 PM 36608]
R3 IDSxpx86;IDSxpx86;C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20101129.001\IDSXpx86.sys [10/19/2010 12:36:22 PM 341880]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys [9/22/2010 11:46:08 PM 15264]
S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [5/29/2010 9:55:30 AM 136176]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [8/7/2008 10:10:02 AM 3276800]
— Other Services/Drivers In Memory —
*NewlyCreated* - FSUSBEXDISK
*NewlyCreated* - NMSCFG
.
Contents of the 'Scheduled Tasks' folder
2010-11-28 C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
- C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-09-23 07:46:07 . 2010-11-28 10:44:51]
2010-11-30 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-29 17:55:30 . 2010-05-29 17:55:26]
2010-11-30 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-29 17:55:30 . 2010-05-29 17:55:26]
2010-11-30 C:\WINDOWS\Tasks\Norton Security Scan for MJR.job
- C:\Program Files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-06-05 12:26:53 . 2010-08-24 17:06:50]
2010-11-29 C:\WINDOWS\Tasks\Norton Security Scan for MJR_2.job
- C:\Program Files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-06-05 12:26:53 . 2010-08-24 17:06:50]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
Trusted Zone: pureplay.com\www
FF - ProfilePath - C:\Documents and Settings\MJR_2\Application Data\Mozilla\Firefox\Profiles\tlzdhnsi.default\
FF - component: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: C:\Documents and Settings\MJR_2\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files\MSN Toolbar\Platform\5.0.1449.0\npwinext.dll
FF - plugin: C:\Program Files\Veetle\Player\npvlc.dll
FF - plugin: C:\Program Files\Veetle\plugins\npVeetle.dll
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Extension: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - C:\Documents and Settings\MJR_2\Application Data\Mozilla\Firefox\Profiles\tlzdhnsi.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Extension: vShare Plugin: vshare@toolbar - C:\Documents and Settings\MJR_2\Application Data\Mozilla\Firefox\Profiles\tlzdhnsi.default\extensions\vshare@toolbar
FF - Extension: Java Quick Starter: [removed] - C:\Program Files\Java\jre6\lib\deploy\jqs\ff
FF - Extension: Norton IPS: {BBDA0591-3099-440a-AA10-41764D9DB4DB} - C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-NPSStartup - (no file)
HKLM-Run-Gamevance - C:\Program Files\Gamevance\gamevance32.exe
AddRemove-Adobe Flash Player Plugin - C:\WINDOWS\system32\Macromed\Flash\FlashUtil10k_Plugin.exe
AddRemove-Gamevance - C:\Program Files\Gamevance\gvun.exe
AddRemove-01_Simmental - C:\Program Files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - C:\Program Files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - C:\Program Files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - C:\Program Files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - C:\Program Files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - C:\Program Files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - C:\Program Files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - C:\Program Files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - C:\Program Files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - C:\Program Files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - C:\Program Files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - C:\Program Files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - C:\Program Files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - C:\Program Files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - C:\Program Files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - C:\Program Files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - C:\Program Files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe