I couldn't turn off Malwarebytes Anti-Malware the first time I tried to run combo with it off it froze my computernot sure if this is a problem but just in case might as well let you know
ComboFix 13-03-12.02 - Josh 03/13/2013 10:16:12.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.3575.2887 [GMT -6:00]
Running from: c:\documents and settings\Josh\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Josh\Local Settings\Application Data\assembly\tmp
c:\windows\EventSystem.log
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\SET28.tmp
c:\windows\system32\SET86.tmp
c:\windows\system32\Thumbs.db
c:\windows\system32\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_NPF
.
.
((((((((((((((((((((((((( Files Created from 2013-02-13 to 2013-03-13 )))))))))))))))))))))))))))))))
.
.
2013-03-12 18:45 . 2013-02-08 00:45 6954968 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0EADC26B-7484-4B60-9CCE-682C604B2805}\mpengine.dll
2013-03-11 10:03 . 2013-03-11 10:03 -------- d-----w- c:\documents and settings\Josh\Application Data\Malwarebytes
2013-03-11 10:03 . 2013-03-11 10:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2013-03-11 10:03 . 2013-03-11 10:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-03-11 10:03 . 2012-12-14 22:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-03-11 09:43 . 2013-02-08 00:45 6954968 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-03-10 09:55 . 2013-03-10 14:34 -------- d-----w- c:\windows\Microsoft Antimalware
2013-03-10 03:38 . 2013-03-10 03:38 -------- d-----w- c:\windows\system32\wbem\Repository
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-01-30 10:53 . 2011-06-19 03:50 232336 ------w- c:\windows\system32\MpSigStub.exe
2012-12-30 07:05 . 2009-08-18 18:30 564632 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\wlidui.dll
2012-12-30 07:05 . 2009-08-18 18:24 19696 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-12-27 02:03 . 2012-07-21 19:46 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2012-12-27 02:03 . 2012-07-21 19:46 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2012-10-21 20:16 . 2011-07-28 02:27 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2011-04-20 . 9425B72F40257B45D45D24773273DAD0 . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
.
.
c:\windows\System32\spoolsv.exe ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BackgroundSwitcher"="e:\progams\New Folder\John's Background Switcher\BackgroundSwitcher.exe" [2011-06-02 119104]
"Mousotron"="e:\progams\Mousotron\Mousotron.exe" [2011-11-08 492032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LClock"="c:\program files\LClock\LClock.exe" [2004-09-19 65536]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"RTHDCPL"="RTHDCPL.EXE" [2010-01-29 18790432]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-06 421888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-10-08 16744256]
"NvMediaCenter"="NvMCTray.dll" [2011-10-08 203072]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2011-05-05 1632360]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-13 947176]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2011-04-20 128512]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2011-6-17 813584]
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 18:28 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders schannel.dll, digest.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
2012-08-29 18:03 1996200 ----a-w- e:\progams\Hamachi\hamachi-2-ui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Hamachi2Svc"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version6\\TeamViewer_Service.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"e:\\Progams\\Ustream\\rsrc\\Desktop Presenter.exe"=
"e:\\Games\\Steam\\steamapps\\common\\fable 3\\FableLauncher.exe"=
"e:\\Games\\Steam\\steamapps\\common\\darkspore\\DarksporeBin\\Darkspore.exe"=
"e:\\Games\\Steam\\steamapps\\common\\darkspore\\Support\\EA Help\\Electronic_Arts_Technical_Support.htm"=
"e:\\Games\\Steam\\Steam.exe"=
"e:\\Games\\Steam\\steamapps\\common\\amnesia the dark descent\\Launcher.exe"=
"e:\\Games\\Steam\\steamapps\\common\\vampire the masquerade - bloodlines\\vampire.exe"=
"e:\\Games\\Steam\\steamapps\\common\\the witcher 2\\Launcher.exe"=
"e:\\Games\\Steam\\steamapps\\common\\dungeon defenders\\Binaries\\Win32\\DunDefGame.exe"=
"e:\\Games\\Steam\\steamapps\\common\\stalker call of pripyat\\Stalker-COP.exe"=
"e:\\Games\\Steam\\steamapps\\common\\STALKER Shadow of Chernobyl\\bin\\XR_3DA.exe"=
"e:\\Games\\Steam\\steamapps\\common\\recettear\\recettear.exe"=
"e:\\Games\\Steam\\steamapps\\common\\recettear\\custom.exe"=
"e:\\Games\\Steam\\steamapps\\common\\sanctum\\Binaries\\Win32\\SanctumGame-Win32-Shipping.exe"=
"c:\\Program Files\\Diablo III\\Diablo III.exe"=
"e:\\Games\\Steam\\steamapps\\common\\payday the heist\\payday_win32_release.exe"=
"e:\\Games\\Steam\\steamapps\\common\\dungeon defenders\\Binaries\\Win32\\DungeonDefenders.exe"=
"e:\\Games\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"e:\\Games\\Steam\\steamapps\\common\\pineapple smash crew\\PineappleSmashCrew.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"e:\\Games\\Steam\\steamapps\\common\\TheBaconing\\TheBaconing.exe"=
"e:\\Games\\Steam\\steamapps\\common\\lone survivor\\LoneSurvivor\\LoneSurvivor.exe"=
"e:\\Games\\Steam\\steamapps\\common\\edge\\edge.exe"=
"e:\\Games\\Steam\\steamapps\\common\\the binding of isaac\\Isaac.exe"=
"e:\\Games\\Steam\\steamapps\\common\\bit.trip beat\\beat.exe"=
"e:\\Games\\Steam\\steamapps\\common\\chantelise\\chantelise.exe"=
"e:\\Games\\Steam\\steamapps\\common\\chantelise\\custom.exe"=
"e:\\Games\\Steam\\steamapps\\common\\bit.trip runner\\runner.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Splinter Cell\\system\\splintercell.exe"=
"e:\\Games\\Steam\\steamapps\\common\\insanely twisted shadow planet\\FCEngine-GFWL.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Tom Clancy's Splinter Cell Conviction\\src\\system\\conviction_game.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Splintercell Chaos Theory\\System\\splintercell3.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Splinter Cell - Double Agent\\SCDALauncher.exe"=
"e:\\Games\\Steam\\steamapps\\common\\world of goo\\WorldOfGoo.exe"=
"e:\\Games\\Steam\\steamapps\\common\\ys the oath in felghana\\ysf_win_dx9.exe"=
"e:\\Games\\Steam\\steamapps\\common\\ys the oath in felghana\\config_dx9.exe"=
"e:\\Games\\Steam\\steamapps\\common\\ys the oath in felghana\\ysf_win.exe"=
"e:\\Games\\Steam\\steamapps\\common\\ys the oath in felghana\\config.exe"=
"e:\\Games\\Steam\\steamapps\\common\\dead island\\DeadIslandGame.exe"=
"e:\\Progams\\Hamachi\\hamachi-2-ui.exe"=
"c:\\Program Files\\KudosChatSearchAgent\\KudosChatSearchAgent.exe"=
"e:\\Games\\StarCraft II\\StarCraft II.exe"=
"e:\\Games\\StarCraft II\\StarCraft II Public Test.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Borderlands 2\\Binaries\\Win32\\Borderlands2.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Shatter\\Shatter.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Shatter\\ShatterSettingsEditor.exe"=
"e:\\Games\\Steam\\steamapps\\common\\space pirates and zombies\\SpazGame.exe"=
"e:\\Games\\Steam\\steamapps\\common\\vessel\\Vessel.exe"=
"e:\\Games\\Steam\\steamapps\\common\\torchlight\\TorchED\\Editor.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Battle.net\\Agent\\Agent.1363\\Agent.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Dustforce\\dustforce.exe"=
"e:\\Games\\Steam\\steamapps\\common\\dungeons of dredmor\\Dungeons of Dredmor.exe"=
"e:\\Games\\Steam\\steamapps\\common\\skyrim\\SkyrimLauncher.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Prototype\\prototypef.exe"=
"e:\\Games\\Steam\\steamapps\\common\\L.A.Noire\\LANLauncher.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Battle.net\\Agent\\Agent.1544\\Agent.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Titan Quest\\Titan Quest.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Wizorb\\Wizorb.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Dawn of War Gold\\W40k.exe"=
"e:\\Games\\Steam\\steamapps\\common\\company of heroes\\RelicCOH.exe"=
"e:\\Games\\Steam\\steamapps\\common\\red faction armageddon\\rf4_launcher.exe"=
"e:\\Games\\Steam\\steamapps\\common\\saints row the third\\game_launcher.exe"=
"e:\\Games\\Steam\\steamapps\\common\\prototype 2\\prototype2.exe"=
"e:\\Games\\Steam\\steamapps\\common\\torchlight\\Torchlight.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Dark Souls Prepare to Die Edition\\DATA\\DARKSOULS.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Dark Souls Prepare to Die Edition\\DATA\\DATA.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Torchlight II\\Torchlight2.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Borderlands 2\\Binaries\\Win32\\Launcher.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Jamestown\\Jamestown.exe"=
"e:\\Games\\Steam\\steamapps\\common\\basement\\The Basement Collection.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\Games\\Steam\\steamapps\\common\\rage\\Rage.exe"=
"e:\\Games\\Steam\\steamapps\\common\\rage\\Rage64.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Legend of Grimrock\\grimrock.exe"=
"e:\\Games\\Steam\\steamapps\\common\\ys origin\\yso_win.exe"=
"e:\\Games\\Steam\\steamapps\\common\\ys origin\\config.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Rochard\\Rochard.exe"=
"e:\\Games\\Steam\\steamapps\\common\\The Walking Dead\\WalkingDead101.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Scribblenauts\\Scribble.exe"=
"e:\\Games\\Steam\\steamapps\\common\\Gratuitous Space Battles\\GSB.exe"=
"e:\\Games\\Steam\\steamapps\\common\\magicka\\Magicka.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58111:TCP"= 58111:TCP
ando Media Booster
"58111:UDP"= 58111:UDP
ando Media Booster
.
R0 mv61xxmm;mv61xxmm;c:\windows\system32\drivers\mv61xxmm.sys [2/3/2011 11:36 AM 13616]
R0 mv64xxmm;mv64xxmm;c:\windows\system32\drivers\mv64xxmm.sys [2/3/2011 11:36 AM 5632]
R0 mvxxmm;mvxxmm;c:\windows\system32\drivers\mvxxmm.sys [2/3/2011 11:36 AM 13616]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\asus.sys\config\DVMExportService.exe [10/16/2009 10:42 AM 319488]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [6/17/2011 5:12 PM 10384]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [3/11/2013 4:03 AM 398184]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [3/11/2013 4:03 AM 682344]
R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [8/9/2012 5:29 PM 14976]
R2 Skype C2C Service;Skype C2C Service;c:\documents and settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe [1/31/2013 11:38 AM 3289208]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\drivers\LEqdUsb.sys [6/17/2009 10:55 AM 40720]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\drivers\LHidEqd.sys [6/17/2009 10:55 AM 10384]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [1/14/2008 4:06 AM 21632]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [3/11/2013 4:03 AM 21104]
S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe --> c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [?]
S2 WSWNDA3100;WSWNDA3100;c:\program files\NETGEAR\WNDA3100v2\WifiSvc.exe [6/17/2011 10:49 AM 272864]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [6/17/2011 7:09 PM 1691480]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\drivers\bcmwlhigh5.sys [6/17/2011 10:50 AM 642432]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\ANDROIDUSB.sys [11/4/2011 7:12 PM 24576]
S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [6/22/2010 6:01 PM 21248]
S3 htcusbnet;HTC USB-NDIS miniport;c:\windows\system32\drivers\htcusbnet.sys [10/4/2011 6:48 PM 128512]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [12/30/2012 12:29 AM 33792]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;c:\windows\system32\drivers\MijXfilt.sys [1/2/2013 4:51 AM 95304]
S3 pneteth;PdaNet Broadband;c:\windows\system32\drivers\pneteth.sys [10/5/2011 3:58 PM 13312]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [7/28/2012 6:22 PM 27064]
S3 XPADFL02;XPAD Filter Service 02;c:\windows\system32\drivers\xPADFL02.sys [12/30/2011 3:37 AM 27904]
S4 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;e:\progams\Hamachi\hamachi-2.exe -s --> e:\progams\Hamachi\hamachi-2.exe -s [?]
S4 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [1/8/2013 1:55 PM 161536]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{FC88681F-4735-4f2f-9514-C21BAC737CF8}]
2011-04-20 07:30 128512 ----a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2013-03-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-1035525444-682003330-1003Core.job
- c:\documents and settings\Josh\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-17 03:55]
.
2013-03-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1060284298-1035525444-682003330-1003UA.job
- c:\documents and settings\Josh\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-17 03:55]
.
2013-03-13 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-09-13 00:25]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://
www.google.com/
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Josh\Application Data\Mozilla\Firefox\Profiles\ka8msxxc.default\
FF - prefs.js: browser.startup.homepage - hxxp://
www.google.com/
FF - ExtSQL: 2013-03-09 19:42; {0AA9101C-D3C1-4129-A9B7-D778C6A17F82}; c:\documents and settings\Josh\Application Data\Mozilla\Firefox\Profiles\ka8msxxc.default\extensions\{0AA9101C-D3C1-4129-A9B7-D778C6A17F82}
FF - ExtSQL: 2013-03-09 19:44;
rikaichan-jpen@polarcloud.com; c:\documents and settings\Josh\Application Data\Mozilla\Firefox\Profiles\ka8msxxc.default\extensions\
rikaichan-jpen@polarcloud.com
FF - user.js: extensions.claro.tlbrSrchUrl -
FF - user.js: extensions.claro.id - 280b71aa000000000000f46d049be6a2
FF - user.js: extensions.claro.appId - {C3110516-8EFC-49D6-8B72-69354F332062}
FF - user.js: extensions.claro.instlDay - 15658
FF - user.js: extensions.claro.vrsn - 1.8.3.10
FF - user.js: extensions.claro.vrsni - 1.8.3.10
FF - user.js: extensions.claro_i.vrsnTs - 1.8.3.1021:47
FF - user.js: extensions.claro.prtnrId - claro
FF - user.js: extensions.claro.prdct - claro
FF - user.js: extensions.claro.aflt - babsst
FF - user.js: extensions.claro_i.smplGrp - none
FF - user.js: extensions.claro.tlbrId - claro
FF - user.js: extensions.claro.instlRef - sst
FF - user.js: extensions.claro.dfltLng - en
FF - user.js: extensions.claro.excTlbr - false
FF - user.js: extensions.claro.admin - false
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Steam App 105400 - c:\program files\Steam\steam.exe
AddRemove-Steam App 105600 - c:\program files\Steam\steam.exe
AddRemove-Steam App 20920 - c:\program files\Steam\steam.exe
AddRemove-Steam App 4000 - c:\program files\Steam\steam.exe
AddRemove-Steam App 42910 - c:\program files\Steam\steam.exe
AddRemove-{92606477-9366-4D3B-8AE3-6BE4B29727AB} - c:\program files\InstallShield Installation Information\{92606477-9366-4D3B-8AE3-6BE4B29727AB}\setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2013-03-13 10:25
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD740ADFD-00NLR5 rev.21.07QR5 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-8
.
device: opened successfully
user: MBR read successfully
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8B12C2E2
user & kernel MBR OK
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(716)
c:\windows\system32\WININET.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
- - - - - - - > 'lsass.exe'(776)
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(1764)
c:\windows\system32\WININET.dll
c:\program files\NVIDIA Corporation\nView\nview.dll
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\program files\LClock\LC.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Java\jre7\bin\jqs.exe
c:\windows\RTHDCPL.EXE
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2013-03-13 10:29:37 - machine was rebooted
ComboFix-quarantined-files.txt 2013-03-13 16:29
.
Pre-Run: 14,286,417,920 bytes free
Post-Run: 14,874,488,832 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 7E973916598FF8853DF8CFDE0D517F26