Still can't run rootrepeal it seems like it is about to finish but, that translucent window pops up and locks it up or it just shuts down... I disabled my anti virus and I'm not running any emulators or cd emulators I do have that "Tuneup Utilities"program but, really thats the only thing I got running? I dunno? here is the combofix log though
ComboFix 10-07-30.01 - Grimace 07/30/2010 21:32:02.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2045.1026 [GMT -7:00]
Running from: c:\users\Grimace\Downloads\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\%appdata%
.
---- Previous Run -------
.
c:\windows\system32\%appdata%\Microsoft\Windows\IETldCache\index.dat . . . . failed to delete
.
MBR is infected with the Whistler Bootkit !!
((((((((((((((((((((((((( Files Created from 2010-06-28 to 2010-07-31 )))))))))))))))))))))))))))))))
.
2010-07-31 04:38 . 2010-07-31 04:40 -------- d-----w- c:\users\Grimace\AppData\Local\temp
2010-07-31 04:38 . 2010-07-31 04:38 -------- d-----w- c:\users\test\AppData\Local\temp
2010-07-31 04:38 . 2010-07-31 04:38 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-07-31 04:38 . 2010-07-31 04:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-21 04:36 . 2010-07-21 04:36 -------- d-----w- c:\users\Grimace\AppData\Roaming\Malwarebytes
2010-07-21 04:36 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-21 04:36 . 2010-07-21 04:36 -------- d-----w- c:\programdata\Malwarebytes
2010-07-21 04:36 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-21 04:36 . 2010-07-21 06:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-20 05:55 . 2010-07-20 05:55 -------- d-----w- c:\program files\iPod
2010-07-13 22:44 . 2010-07-13 22:44 -------- d-----w- c:\program files\ERUNT
2010-07-13 04:13 . 2010-07-13 06:08 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-07-13 04:13 . 2010-07-13 04:13 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-07-12 05:37 . 2010-07-12 05:37 -------- d-----w- c:\users\test\AppData\Roaming\Avira
2010-07-12 05:29 . 2010-07-12 05:29 -------- d-----w- c:\users\test\AppData\Roaming\TuneUp Software
2010-07-12 04:06 . 2010-07-12 04:06 0 ----a-w- c:\windows\nsreg.dat
2010-07-05 22:32 . 2010-02-12 20:36 836384 ----a-w- c:\windows\system32\drivers\ae1000va.sys
2010-07-05 22:31 . 2010-07-05 22:31 -------- d-----w- c:\programdata\Cisco Systems
2010-07-03 10:08 . 2009-10-30 22:08 29512 ----a-w- c:\windows\system32\TURegOpt.exe
2010-07-03 10:08 . 2009-10-30 22:01 21320 ----a-w- c:\windows\system32\authuitu.dll
2010-07-03 10:08 . 2009-10-30 22:01 30024 ----a-w- c:\windows\system32\uxtuneup.dll
2010-07-03 10:08 . 2010-07-03 10:08 -------- d-----w- c:\users\Grimace\AppData\Roaming\TuneUp Software
2010-07-03 10:07 . 2010-07-03 10:08 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-07-03 10:06 . 2010-07-03 10:07 -------- d-----w- c:\programdata\TuneUp Software
2010-07-03 10:06 . 2010-07-03 10:06 -------- d-sh--w- c:\programdata\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2010-07-01 06:47 . 2010-07-01 06:53 -------- d-----w- c:\users\Grimace\.BayPhoto
2010-07-01 06:46 . 2010-07-01 06:53 -------- d-----w- c:\users\Grimace\.roescache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-23 22:23 . 2010-01-26 20:24 -------- d-----w- c:\users\Grimace\AppData\Roaming\gtk-2.0
2010-07-21 06:26 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-07-21 04:02 . 2010-01-07 04:07 -------- d-----w- c:\programdata\avg9
2010-07-21 03:54 . 2010-07-21 03:54 1615200 ----a-w- c:\programdata\avg9\update\backup\avgssie.dll
2010-07-21 03:53 . 2010-07-21 03:53 1373536 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2010-07-21 03:53 . 2010-07-21 03:53 1107296 ----a-w- c:\programdata\avg9\update\backup\avgxpl.dll
2010-07-21 03:53 . 2010-07-21 03:53 921440 ----a-w- c:\programdata\avg9\update\backup\avgemc.exe
2010-07-21 03:53 . 2010-07-21 03:53 4368224 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-07-20 05:55 . 2010-05-22 18:30 -------- d-----w- c:\program files\iTunes
2010-07-20 05:55 . 2010-01-06 07:12 -------- d-----w- c:\program files\Common Files\Apple
2010-07-20 05:51 . 2010-07-20 05:51 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.4\SetupAdmin.exe
2010-07-17 22:13 . 2010-01-07 05:35 -------- d-----w- c:\users\Grimace\AppData\Roaming\uTorrent
2010-07-17 02:35 . 2010-07-17 02:35 242896 ----a-w- c:\programdata\avg9\update\backup\avgtdix.sys
2010-07-17 02:35 . 2010-07-17 02:35 216200 ----a-w- c:\programdata\avg9\update\backup\avgldx86.sys
2010-07-17 02:34 . 2010-07-17 02:34 1038688 ----a-w- c:\programdata\avg9\update\backup\avgupd.exe
2010-07-17 02:34 . 2010-07-17 02:34 813336 ----a-w- c:\programdata\avg9\update\backup\avginet.dll
2010-07-17 02:34 . 2010-07-17 02:34 624920 ----a-w- c:\programdata\avg9\update\backup\avgiproxy.exe
2010-07-17 02:34 . 2010-07-17 02:34 1690464 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
2010-07-12 05:28 . 2010-07-12 05:28 49168 ----a-w- c:\users\test\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-03 10:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2010-07-01 05:26 . 2010-01-06 06:50 -------- d-----w- c:\users\Grimace\AppData\Roaming\vlc
2010-06-24 06:05 . 2010-06-24 06:05 -------- d-----w- c:\program files\Microsoft.NET
2010-06-23 07:26 . 2010-01-10 07:27 -------- d-----w- c:\users\Grimace\AppData\Roaming\LimeWire
2010-06-18 07:09 . 2010-06-18 07:09 -------- d-----w- c:\program files\Bonjour
2010-06-14 00:57 . 2010-01-09 03:19 -------- d-----w- c:\program files\Google
2010-06-13 23:57 . 2010-01-10 10:57 -------- d-----w- c:\program files\Yahoo!
2010-06-13 23:54 . 2010-06-13 23:53 -------- d-----w- c:\users\Grimace\AppData\Roaming\GetRightToGo
2010-06-13 21:14 . 2010-05-07 06:06 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-06-13 21:14 . 2010-05-07 06:02 -------- d-----w- c:\programdata\DivX
2010-06-13 21:14 . 2010-06-13 21:14 56997 ----a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe
2010-06-13 21:14 . 2010-06-13 21:14 56765 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-06-13 21:14 . 2010-01-09 03:19 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-06-13 21:14 . 2010-01-09 03:19 -------- d-----w- c:\program files\DivX
2010-06-13 21:14 . 2010-06-13 21:14 53600 ----a-w- c:\programdata\DivX\Update\Uninstaller.exe
2010-06-13 21:14 . 2010-06-13 21:14 57715 ----a-w- c:\programdata\DivX\Player\Uninstaller.exe
2010-06-13 21:13 . 2010-06-13 21:13 54153 ----a-w- c:\programdata\DivX\DFXPlugin\Uninstaller.exe
2010-06-13 21:13 . 2010-06-13 21:13 54128 ----a-w- c:\programdata\DivX\Converter\Uninstaller.exe
2010-06-13 21:13 . 2010-06-13 21:13 54644 ----a-w- c:\programdata\DivX\TranscodeEngine\Uninstaller.exe
2010-06-13 21:13 . 2010-06-13 21:13 54101 ----a-w- c:\programdata\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-13 21:12 . 2010-05-07 06:06 1062184 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-06-13 21:12 . 2010-05-07 06:06 895256 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-06-10 07:50 . 2010-02-04 07:56 -------- d-----w- c:\program files\DVDFab Platinum 4
2010-06-05 23:42 . 2010-01-22 04:57 -------- d-----w- c:\program files\Microsoft Silverlight
2010-05-26 17:06 . 2010-06-09 02:40 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-09 02:40 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-21 21:14 . 2010-01-05 06:36 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-18 23:35 . 2010-05-18 23:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 23:35 . 2010-05-18 23:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-07 06:05 . 2010-05-07 06:05 84040 ----a-w- c:\programdata\DivX\TransferWizard\Uninstaller.exe
2010-05-07 06:05 . 2010-05-07 06:05 57054 ----a-w- c:\programdata\DivX\DSDesktopComponents\Uninstaller.exe
2010-05-07 06:05 . 2010-05-07 06:05 54166 ----a-w- c:\programdata\DivX\DSAVCDecoder\Uninstaller.exe
2010-05-07 06:05 . 2010-05-07 06:05 57532 ----a-w- c:\programdata\DivX\DSASPDecoder\Uninstaller.exe
2010-05-07 06:05 . 2010-05-07 06:05 56458 ----a-w- c:\programdata\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-05-07 06:05 . 2010-05-07 06:05 54174 ----a-w- c:\programdata\DivX\DSAACDecoder\Uninstaller.exe
2010-05-07 06:05 . 2010-05-07 06:05 57409 ----a-w- c:\programdata\DivX\ControlPanel\Uninstaller.exe
2010-05-07 06:05 . 2010-05-07 06:05 52963 ----a-w- c:\programdata\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-05-07 06:05 . 2010-05-07 06:05 54073 ----a-w- c:\programdata\DivX\Qt4.5\Uninstaller.exe
2010-05-07 06:05 . 2010-05-07 06:05 56969 ----a-w- c:\programdata\DivX\ASPEncoder\Uninstaller.exe
2010-05-04 05:59 . 2010-06-09 02:39 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-06-09 02:39 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 05:55 . 2010-06-09 02:39 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 04:31 . 2010-06-09 02:39 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2007-02-21 19:49 . 2007-02-21 19:49 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10d.exe" [2009-11-03 257440]
c:\users\Grimace\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Grimace^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\users\Grimace\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Grimace^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Product Registration.lnk]
path=c:\users\Grimace\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
backup=c:\windows\pss\Logitech . Product Registration.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-07-16 14:41 141608 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Vid]
2009-07-16 23:35 5458704 ----a-w- c:\program files\Logitech\Logitech Vid\Vid.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2009-10-14 21:36 2793304 ----a-w- c:\program files\Logitech\Logitech WebCam Software\LWS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-11-10 23:39 5244216 ----a-w- c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-27 00:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-04-14 10:33 13687328 ----a-w- c:\windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-04-14 10:33 92704 ----a-w- c:\windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 04:53 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 12:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):50,24,0f,40,84,8f,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-896808877-2054827027-2505662573-1000]
"EnableNotificationsRef"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\DRIVERS\A5AGU.sys [2004-10-06 283904]
R3 ATHFMWDL;D-Link predator Bootloader driver;c:\windows\system32\Drivers\ATHFMWDL.sys [2005-03-16 43392]
R3 dhdusb.NTx86;Dynex Wireless G USB Network Adapter Service;c:\windows\system32\DRIVERS\bcmusbdhdlh.sys [2008-01-08 238072]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-02-24 135336]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2009-10-30 1021256]
S3 AE1000;Linksys AE1000 Driver;c:\windows\system32\DRIVERS\ae1000va.sys [2010-02-12 836384]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-07-30 c:\windows\Tasks\User_Feed_Synchronization-{3F263493-9286-4D04-9058-1926A0A96C40}.job
- c:\windows\system32\msfeedssync.exe [2010-06-09 04:30]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\users\Grimace\AppData\Roaming\Mozilla\Firefox\Profiles\0oy2l2qs.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/\r
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7a,be,f0,84,01,43,cb,49,b3,b4,14,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7a,be,f0,84,01,43,cb,49,b3,b4,14,\
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\WUDFHost.exe
c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2010-07-30 21:49:12 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-31 04:49
ComboFix2.txt 2010-07-21 07:14
Pre-Run: 753,043,050,496 bytes free
Post-Run: 752,917,868,544 bytes free
- - End Of File - - 3CAEAD951D3A455DA2F2666A34A8F271