Computer and internet runs better, but gadget box search comes up for my homepage instead of google chrome.
ComboFix 12-08-09.01 - Greg 08/09/2012 18:25:05.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.441 [GMT -7:00]
Running from: c:\documents and settings\Greg\My Documents\Downloads\ComboFix.exe
AV: Webroot SecureAnywhere *Enabled/Updated* {D486329C-1488-4CEB-9CC8-D662B732D904}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\drvrtmp
c:\windows\system32\SET86A.tmp
c:\windows\system32\SET86E.tmp
c:\windows\system32\SET86F.tmp
c:\windows\system32\SET876.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-07-10 to 2012-08-10 )))))))))))))))))))))))))))))))
.
.
2012-08-09 22:05 . 2012-07-06 05:07 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-08-09 22:01 . 2012-08-09 22:01 -------- d-----w- c:\program files\Common Files\Java
2012-08-09 21:59 . 2012-08-09 21:59 -------- d-----w- c:\program files\Oracle
2012-08-09 21:58 . 2012-08-09 21:58 -------- d-----w- c:\documents and settings\Greg\Application Data\Oracle
2012-08-09 02:03 . 2012-08-09 02:03 -------- d-----w- c:\windows\Sun
2012-08-08 22:30 . 2012-07-06 05:06 772544 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-08-08 22:30 . 2012-07-06 05:06 687544 ----a-w- c:\windows\system32\deployJava1.dll
2012-08-08 22:29 . 2012-08-09 22:06 -------- d-----w- c:\program files\Java
2012-08-08 22:19 . 2012-08-08 22:19 -------- d-----w- c:\documents and settings\Greg\Application Data\Malwarebytes
2012-08-08 22:19 . 2012-08-08 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-08-08 22:19 . 2012-08-08 22:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-08 22:19 . 2012-07-03 20:46 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-08 21:19 . 2012-08-08 21:19 -------- d-----w- c:\documents and settings\Greg\Application Data\SUPERAntiSpyware.com
2012-08-08 21:19 . 2012-08-08 21:19 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-08-08 21:19 . 2012-08-08 21:19 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2012-08-08 19:45 . 2012-08-08 19:45 -------- d-----w- c:\windows\system32\wbem\Repository
2012-08-08 19:43 . 2012-08-08 19:43 -------- d-----w- c:\documents and settings\All Users\Application Data\{C243CCC8-5474-45FC-A546-7FBC284A692E}
2012-08-08 19:43 . 2012-08-08 19:43 -------- d-----w- c:\program files\PokerStars
2012-08-08 19:43 . 2012-08-08 19:43 -------- d-----w- c:\program files\Full Tilt Poker
2012-08-08 19:17 . 2012-08-08 19:17 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2012-08-08 19:14 . 2012-08-08 19:14 -------- d-----w- c:\documents and settings\Greg\Local Settings\Application Data\Mozilla
2012-08-08 19:14 . 2012-08-08 19:43 -------- d-----w- c:\program files\Mozilla Firefox(2)
2012-08-04 22:54 . 2012-08-08 19:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Codecv
2012-08-04 22:53 . 2012-08-08 19:43 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallMate
2012-07-31 01:11 . 2012-08-08 19:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Tarma Installer
2012-07-31 00:52 . 2012-08-08 19:44 -------- d-----w- c:\program files\Windows Media Connect 2
2012-07-31 00:50 . 2012-08-08 19:44 -------- d-----w- c:\windows\system32\drivers\UMDF
2012-07-26 20:34 . 2012-07-26 20:34 -------- d-----w- c:\documents and settings\All Users\Application Data\LogiShrd
2012-07-26 20:32 . 2012-07-26 20:32 -------- d-----w- c:\documents and settings\Greg\Local Settings\Application Data\LogiShrd
2012-07-26 19:51 . 2012-07-26 19:51 -------- d-----w- c:\documents and settings\Greg\Application Data\Leadertech
2012-07-26 19:49 . 2012-07-26 19:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Logitech
2012-07-26 19:49 . 2012-07-26 19:49 -------- d-----w- c:\program files\Common Files\LWS
2012-07-26 19:48 . 2012-08-08 19:45 -------- d-----w- c:\program files\Common Files\LogiShrd
2012-07-26 19:48 . 2012-08-08 19:45 -------- d-----w- c:\program files\Logitech
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-20 03:19 . 2011-12-31 01:05 111632 ----a-w- c:\windows\system32\drivers\WRkrn.sys
2012-10-20 03:19 . 2011-12-31 01:05 148664 ----a-w- c:\windows\system32\WRusr.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GoogleChromeAutoLaunch_36A077139B0C249A
1D0302CB4777E5A0"="c:\documents and settings\Greg\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" [2012-08-07 1229848]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-25 339968]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"WRSVC"="c:\program files\Webroot\WRSA.exe" [2012-07-07 688360]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDevMgrUpdate"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R0 WRkrn;WRkrn;c:\windows\system32\drivers\WRkrn.sys [12/30/2011 6:05 PM 111632]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 9:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 2:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 4:38 PM 116608]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/8/2012 3:19 PM 655944]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/8/2012 3:19 PM 22344]
S2 WRSVC;WRSVC;c:\program files\Webroot\WRSA.exe [12/30/2011 6:05 PM 688360]
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-448539723-1770027372-682003330-1003Core.job
- c:\documents and settings\Greg\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-08-08 19:55]
.
2012-08-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-448539723-1770027372-682003330-1003UA.job
- c:\documents and settings\Greg\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-08-08 19:55]
.
2012-08-09 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task a7bdb93d-80e0-4164-a618-c70a8b0ffdac.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
2012-08-09 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task eb5ec252-fc1b-42cf-93ce-dd8192c608dc.job
- c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 24.159.64.23 24.217.201.67 66.189.0.100
.
.
------- File Associations -------
.
JSEFile="%SystemRoot%\System32\WScript.exe" "%1" %*
.
- - - - ORPHANS REMOVED - - - -
.
ShellExecuteHooks-{4F07DA45-8170-4859-9B5F-037EF2970034} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-08-09 18:28
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5
977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2f,5d,7b,c1,93,0f,c4,4a,af,69,55,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839
E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2f,5d,7b,c1,93,0f,c4,4a,af,69,55,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(532)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2012-08-09 18:30:23
ComboFix-quarantined-files.txt 2012-08-10 01:30
.
Pre-Run: 63,127,326,720 bytes free
Post-Run: 63,090,126,848 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 5720FBBBD1130975F49B13C43763530B