[color="#800080"]Upon running Combofix, it detected a rootkit and rebooted my machine before running a full scan on start-up. Kitty had a snack

http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/tongue.gif\' class=\'bbc_emoticon\' alt=\'

\' /> <---that made me laugh

http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/biggrin.gif\' class=\'bbc_emoticon\' alt=\'

\' />[/color]
ComboFix 10-07-06.05 - Morgan 07/07/2010 17:41:53.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1587 [GMT -4:00]
Running from: c:\documents and settings\Morgan\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100707-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Morgan\Recent\Thumbs.db
Infected copy of c:\windows\system32\drivers\afd.sys was found and disinfected
Restored copy from - Kitty had a snack

http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/tongue.gif\' class=\'bbc_emoticon\' alt=\'

\' />
.
((((((((((((((((((((((((( Files Created from 2010-06-07 to 2010-07-07 )))))))))))))))))))))))))))))))
.
2010-07-07 21:38 . 2010-07-07 21:38 -------- d-s---w- c:\documents and settings\NetworkService\UserData
2010-07-06 21:35 . 2010-07-06 21:35 388096 ----a-r- c:\documents and settings\Morgan\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-01 05:31 . 2010-07-01 05:31 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-01 05:31 . 2010-07-01 05:31 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-01 05:30 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-01 05:30 . 2010-07-01 05:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-01 05:30 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-01 04:37 . 2010-07-01 06:05 -------- d-----w- c:\documents and settings\Morgan\Local Settings\Application Data\ojppmnwnn
2010-06-23 22:18 . 2010-06-23 22:18 -------- d-----w- c:\documents and settings\Morgan\Local Settings\Application Data\Yahoo
2010-06-23 22:18 . 2010-06-23 22:18 -------- d-----w- c:\program files\Yahoo!
2010-06-14 20:46 . 2010-06-14 20:46 50354 ----a-w- c:\documents and settings\Morgan\Application Data\Facebook\uninstall.exe
2010-06-14 20:46 . 2010-06-14 20:46 -------- d-----w- c:\documents and settings\Morgan\Application Data\Facebook
2010-06-10 16:24 . 2010-06-10 16:24 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-10 16:20 . 2010-06-10 16:20 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-06-10 16:20 . 2010-02-04 15:53 2954656 -c--a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-06-10 01:35 . 2010-06-10 01:35 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-06-10 01:35 . 2010-06-10 01:26 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-06-10 01:35 . 2010-06-10 01:25 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-06-10 01:35 . 2010-06-10 01:35 56765 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-06-10 01:35 . 2010-06-10 01:35 56997 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-06-10 01:35 . 2010-06-10 01:35 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-06-10 01:34 . 2010-06-10 01:34 57715 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-06-10 01:34 . 2010-06-10 01:34 84062 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-06-10 01:34 . 2010-06-10 01:34 57054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-06-10 01:34 . 2010-06-10 01:34 54166 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-06-10 01:34 . 2010-06-10 01:34 57532 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-06-10 01:34 . 2010-06-10 01:34 56458 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-06-10 01:34 . 2010-06-10 01:34 54174 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-06-10 01:34 . 2010-06-10 01:34 54153 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-06-10 01:34 . 2010-06-10 01:34 54128 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe
2010-06-10 01:34 . 2010-06-10 01:34 54644 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-06-10 01:34 . 2010-06-10 01:34 54101 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-10 01:33 . 2010-06-10 01:33 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-06-10 01:33 . 2010-06-10 01:33 52963 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-06-10 01:33 . 2010-06-10 01:33 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-06-10 01:33 . 2010-06-10 01:33 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-06-10 01:25 . 2010-06-10 01:44 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-06-09 10:45 . 2010-06-09 10:45 5591040 ----a-w- c:\documents and settings\Morgan\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-06-08 22:03 . 2010-06-08 22:03 503808 ----a-w- c:\documents and settings\Morgan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5b168309-n\msvcp71.dll
2010-06-08 22:03 . 2010-06-08 22:03 499712 ----a-w- c:\documents and settings\Morgan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5b168309-n\jmc.dll
2010-06-08 22:03 . 2010-06-08 22:03 348160 ----a-w- c:\documents and settings\Morgan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-5b168309-n\msvcr71.dll
2010-06-08 22:03 . 2010-06-08 22:03 61440 ----a-w- c:\documents and settings\Morgan\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-64c34fb8-n\decora-sse.dll
2010-06-08 22:03 . 2010-06-08 22:03 12800 ----a-w- c:\documents and settings\Morgan\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-64c34fb8-n\decora-d3d.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-07 21:40 . 2008-05-30 23:07 16608 ----a-w- c:\windows\gdrv.sys
2010-07-07 21:40 . 2008-07-02 02:54 -------- d-----w- c:\documents and settings\Morgan\Application Data\DNA
2010-07-07 21:28 . 2009-05-29 19:28 117760 ----a-w- c:\documents and settings\Morgan\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-07 21:26 . 2008-07-02 02:54 -------- d-----w- c:\program files\DNA
2010-07-06 21:35 . 2009-03-06 23:18 -------- d-----w- c:\program files\Trend Micro
2010-07-01 17:59 . 2009-08-19 00:55 -------- d-----w- c:\program files\NCSoft
2010-07-01 06:07 . 2008-05-30 23:43 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-01 05:31 . 2008-05-30 23:02 1100 ----a-w- c:\windows\system32\d3d8caps.dat
2010-07-01 00:36 . 2008-07-02 02:54 -------- d-----w- c:\documents and settings\Morgan\Application Data\BitTorrent
2010-06-23 00:47 . 2008-07-02 03:25 -------- d-----w- c:\documents and settings\Morgan\Application Data\dvdcss
2010-06-10 16:24 . 2009-03-06 16:30 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-06-10 16:24 . 2009-03-06 03:21 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-06-10 16:20 . 2009-03-06 03:19 -------- d-----w- c:\program files\Lavasoft
2010-06-10 16:11 . 2009-05-29 19:27 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-06-10 01:34 . 2008-05-31 01:48 -------- d-----w- c:\documents and settings\Morgan\Application Data\DivX
2010-06-10 01:33 . 2009-03-26 16:35 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-05-02 05:22 . 2004-08-04 12:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-27 18:40 . 2008-05-30 23:41 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2010-04-27 18:40 . 2008-05-30 23:41 45648 ----a-w- c:\windows\system32\drivers\PxHelp20.sys
2010-04-27 18:40 . 2008-05-30 23:41 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2010-04-27 18:40 . 2008-05-30 23:41 133616 ------w- c:\windows\system32\pxafs.dll
2010-04-27 18:40 . 2008-05-30 23:41 126448 ------w- c:\windows\system32\pxinsi64.exe
2010-04-27 18:40 . 2008-05-30 23:41 123888 ------w- c:\windows\system32\pxcpyi64.exe
2010-04-20 05:30 . 2004-08-04 12:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-16 22:02 . 2010-04-16 22:02 503808 ----a-w- c:\documents and settings\Morgan\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-1d68242a-n\msvcp71.dll
2010-04-16 22:02 . 2010-04-16 22:02 499712 ----a-w- c:\documents and settings\Morgan\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-1d68242a-n\jmc.dll
2010-04-16 22:02 . 2010-04-16 22:02 348160 ----a-w- c:\documents and settings\Morgan\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-1d68242a-n\msvcr71.dll
2010-04-16 22:02 . 2010-04-16 22:02 61440 ----a-w- c:\documents and settings\Morgan\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-2eaaffde-n\decora-sse.dll
2010-04-16 22:02 . 2010-04-16 22:02 12800 ----a-w- c:\documents and settings\Morgan\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-2eaaffde-n\decora-d3d.dll
2010-04-16 16:09 . 2004-08-04 12:00 667136 ----a-w- c:\windows\system32\wininet.dll
2010-04-16 16:09 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-04-12 21:29 . 2010-04-16 22:02 411368 ----a-w- c:\windows\system32\deployJava1.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-06-20 451872]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-12 323392]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-04-01 2012912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="c:\program files\GIGABYTE\GEST\RUN.exe" [2008-08-10 236040]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-03 13508608]
"nwiz"="nwiz.exe" [2008-01-03 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-03 86016]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-07-07 864112]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-01-16 181544]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"Diamondback"="c:\program files\Razer\Diamondback 3G\razerhid.exe" [2007-08-01 147456]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
c:\documents and settings\Morgan\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2010-1-21 3450608]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-18 4742184]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-2-20 113664]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-10-21 20:39 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\World of Warcraft\\Repair.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\WoW-0.1.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft Public Test\\WoW-0.1.0.9637-to-0.1.0.9658-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft Public Test2\\WoW-0.2.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft Public Test2\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft Public Test2\\WoW-0.2.0.10048-to-0.2.0.10072-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\WINDOWS\\system32\\wbem\\unsecapp.exe"=
"c:\\Program Files\\World of Warcraft Public Test3\\WoW-0.3.0.10522-enUS-ptr-downloader.exe"=
"c:\\Program Files\\World of Warcraft Public Test3\\Launcher.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/5/2009 11:21 PM 64288]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5/30/2008 9:50 PM 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [5/26/2009 10:05 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 10:05 AM 66632]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5/30/2008 9:50 PM 20560]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [1/16/2009 4:31 PM 161064]
R3 Razerlow;Diamondback 3G USB Filter Driver;c:\windows\system32\drivers\DB3G.sys [12/25/2009 12:24 PM 13225]
S3 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\gsvr.exe [5/30/2008 7:08 PM 55816]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 11:52 AM 1352832]
S3 LycoFltr;Lycosa Keyboard;c:\windows\system32\Drivers\Lycosa.sys --> c:\windows\system32\Drivers\Lycosa.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 10:05 AM 12872]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - GTNDIS5
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-06-20 16:47 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-07-07 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 21:32]
2010-02-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-07-07 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-06 02:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = http=127.0.0.1:5577
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
FF - ProfilePath - c:\documents and settings\Morgan\Application Data\Mozilla\Firefox\Profiles\t942hgel.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.goodsearch.com/Default.aspx
FF - plugin: c:\documents and settings\Morgan\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Morgan\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\Morgan\Application Data\Mozilla\Firefox\Profiles\t942hgel.default\extensions\
[email protected]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\Magic Video Converter\codec\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\Magic Video Converter\codec\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-DivXUpdate - c:\program files\DivX\DivX Update\DivXUpdate.exe
AddRemove-{7585478E9D9B42108671C12F8714CEFE} - c:\program files\DivX\DivXConverterUninstall.exe
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe
AddRemove-{B13A7C41581B411290FBC0395694E2A9} - c:\program files\DivX\DivXConverterUninstall.exe
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(912)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
Completion time: 2010-07-07 17:46:41
ComboFix-quarantined-files.txt 2010-07-07 21:46
Pre-Run: 42,114,334,720 bytes free
Post-Run: 42,334,908,416 bytes free
- - End Of File - - DD1FCEACE796888F672ECDC89054FAB1