ComboFix 10-02-16.03 - Sharon 02/17/2010 13:58:38.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.686 [GMT -7:00]
Running from: c:\documents and settings\Sharon\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\rundll32 .exe
c:\windows\system32\twain.dll
c:\windows\system32\twain_32.dll
.
((((((((((((((((((((((((( Files Created from 2010-01-17 to 2010-02-17 )))))))))))))))))))))))))))))))
.
2010-02-16 20:20 . 2010-02-16 20:20 -------- d-----w- c:\program files\Common Files\Java
2010-02-16 20:20 . 2010-02-16 20:20 503808 ----a-w- c:\documents and settings\Sharon\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-157a94d2-n\msvcp71.dll
2010-02-16 20:20 . 2010-02-16 20:20 499712 ----a-w- c:\documents and settings\Sharon\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-157a94d2-n\jmc.dll
2010-02-16 20:20 . 2010-02-16 20:20 348160 ----a-w- c:\documents and settings\Sharon\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-157a94d2-n\msvcr71.dll
2010-02-16 20:20 . 2010-02-16 20:20 61440 ----a-w- c:\documents and settings\Sharon\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-793db118-n\decora-sse.dll
2010-02-16 20:20 . 2010-02-16 20:20 12800 ----a-w- c:\documents and settings\Sharon\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-793db118-n\decora-d3d.dll
2010-02-16 13:54 . 2010-02-16 13:54 -------- d-----w- C:\_OTM
2010-02-16 03:21 . 2010-02-16 03:21 -------- d-----w- C:\rsit
2010-02-14 00:38 . 2010-02-14 00:38 38784 ----a-w- c:\documents and settings\Sharon\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-14 00:38 . 2010-02-14 00:38 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-02-14 00:34 . 2010-02-14 00:35 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-02-13 23:39 . 2010-02-14 00:34 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-02-13 23:39 . 2010-02-13 23:39 -------- d-----w- c:\program files\NOS
2010-02-13 23:39 . 2010-01-25 17:02 31936 ----a-w- c:\documents and settings\Sharon\Application Data\Mozilla\Firefox\Profiles\aa101x97.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2010-02-13 23:39 . 2010-01-25 17:02 29344 ----a-w- c:\documents and settings\Sharon\Application Data\Mozilla\Firefox\Profiles\aa101x97.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2010-02-13 06:32 . 2010-02-13 06:32 -------- d-sh--w- c:\documents and settings\Sharon\IECompatCache
2010-02-12 21:56 . 2010-02-13 01:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-12 16:40 . 2010-02-12 16:40 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-02-10 19:59 . 2010-02-10 19:59 -------- d-----w- c:\program files\Trend Micro
2010-02-10 19:29 . 2010-02-10 20:01 -------- d-----w- c:\program files\ERUNT
2010-02-10 00:23 . 2010-01-07 23:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-10 00:23 . 2010-01-07 23:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-09 02:02 . 2010-02-09 02:02 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2010-02-09 02:02 . 2010-02-09 02:02 -------- d-sh--w- c:\documents and settings\NetworkService\PrivacIE
2010-01-28 22:53 . 2010-01-28 22:53 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-01-28 22:53 . 2009-11-22 22:42 69000 ----a-w- c:\windows\system32\zlcomm.dll
2010-01-28 22:53 . 2009-11-22 22:42 103816 ----a-w- c:\windows\system32\zlcommdb.dll
2010-01-28 22:53 . 2010-01-28 22:53 -------- d-----w- c:\windows\system32\ZoneLabs
2010-01-28 22:53 . 2009-11-22 22:42 1238408 ----a-w- c:\windows\system32\zpeng25.dll
2010-01-28 22:53 . 2010-01-28 22:53 -------- d-----w- c:\program files\Zone Labs
2010-01-28 22:50 . 2010-02-17 18:59 -------- d-----w- c:\windows\Internet Logs
2010-01-26 05:46 . 2010-02-13 02:27 -------- d-----w- c:\program files\AOL 9.5a
2010-01-25 23:28 . 2010-01-26 05:17 -------- d-----w- c:\program files\AOL 9.5
2010-01-25 23:17 . 2010-01-25 23:26 43732816 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol_single\4337.155.1.1\setup.exe
2010-01-25 23:17 . 2010-01-25 23:17 42960 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol_single\4337.155.1.1\noneCodesignFilesBundle.exe
2010-01-22 17:47 . 2010-01-22 17:47 -------- d-----w- c:\documents and settings\Sharon\Application Data\Malwarebytes
2010-01-22 17:47 . 2010-01-22 17:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-17 17:51 . 2010-01-29 13:18 5261146 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-02-16 20:19 . 2008-12-09 05:33 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-16 17:27 . 2005-07-16 16:52 -------- d-----w- c:\program files\Java
2010-02-16 04:56 . 2009-05-23 16:55 -------- d-----w- c:\program files\Fishdom
2010-02-15 03:35 . 2009-12-02 18:22 -------- d-----w- c:\documents and settings\Sharon\Application Data\Dofus 2
2010-02-14 00:42 . 2005-07-23 17:26 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-13 06:54 . 2005-07-27 19:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-13 05:38 . 2005-07-27 19:12 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-13 03:36 . 2009-12-19 16:57 -------- d-----w- c:\program files\QuickTime
2010-02-13 01:48 . 2009-12-19 17:00 -------- d-----w- c:\program files\iTunes
2010-02-12 21:36 . 2005-07-23 19:50 -------- d-----w- c:\program files\Maxis
2010-02-12 18:10 . 2005-12-05 18:44 -------- d-----w- c:\documents and settings\Sharon\Application Data\Apple Computer
2010-02-12 16:37 . 2007-04-08 08:37 -------- d-----w- c:\program files\Google
2010-02-09 22:16 . 2005-11-03 23:19 -------- d-----w- c:\program files\EA GAMES
2010-02-09 21:57 . 2008-11-17 16:04 -------- d-----w- c:\documents and settings\All Users\Application Data\HipSoft
2010-02-09 21:57 . 2007-01-08 23:08 -------- d-----w- c:\program files\AOL Games
2010-01-26 05:48 . 2005-07-24 16:33 -------- d-----w- c:\documents and settings\Sharon\Application Data\AOL
2010-01-26 05:47 . 2005-07-23 19:24 -------- d-----w- c:\program files\Common Files\AOL
2010-01-26 05:46 . 2005-12-31 20:25 -------- d-----w- c:\program files\Common Files\aolshare
2010-01-26 05:46 . 2005-07-24 16:31 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2010-01-25 23:17 . 2005-07-24 14:37 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2010-01-22 23:06 . 2002-01-23 14:37 70768 -c--a-w- c:\documents and settings\Sharon\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-15 17:14 . 2010-01-14 17:13 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-14 17:13 . 2010-01-14 17:13 -------- d-----w- c:\program files\Avira
2010-01-14 17:13 . 2010-01-14 17:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-01-04 18:41 . 2007-12-19 03:48 -------- d-----w- c:\program files\Dofus
2009-12-31 16:50 . 2005-07-16 16:37 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-08-10 17:51 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-19 16:48 . 2009-12-19 16:48 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-12-16 18:43 . 2008-09-04 17:24 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-10 17:50 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:26 . 2004-08-10 17:51 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-04 03:59 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2005-07-16 16:37 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:11 . 2004-08-10 17:51 1291776 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:11 . 2004-08-04 05:56 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2004-08-10 17:51 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-18 03:36 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2004-08-10 17:51 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2004-08-10 17:50 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2004-08-04 05:56 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-21 15:51 . 2004-08-10 17:50 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2007-02-15 18:25 . 2006-04-08 19:36 480624 -c--a-w- c:\program files\2005 Porter R Tax Return.tax
.
Code:
<pre>
c:\program files\AOL 9.5a\aol .exe
c:\program files\Common Files\AOL\1105975379\EE\aolsoftware .exe
c:\program files\Common Files\InstallShield\UpdateService\issch .exe
c:\program files\Common Files\InstallShield\UpdateService\isuspm .exe
c:\program files\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
c:\program files\Intel\Intel Matrix Storage Manager\iaanotif .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Malwarebytes' Anti-Malware\mbam .exe
c:\program files\MouseWare\system\em_exec .exe
c:\program files\QuickTime\qttask .exe
c:\program files\Spybot - Search & Destroy\teatimer .exe
c:\windows\system32\dla\tfswctrl .exe
c:\windows\system32\spool\drivers\w32x86\3\hpztsb07 .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-02-12 39408]
"Flablt"="c:\documents and settings\Sharon\Application Data\Adobe\Update\wndcor.dat" [2010-02-05 18732]
"AOL Fast Start"="c:\program files\AOL 9.5a\AOL.EXE" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\quicktime\qttask .exe -atboottime" [X]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"EM_EXEC"="c:\progra~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [N/A]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-10-21 29696]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [N/A]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [N/A]
"Pure Networks Port Magic"="c:\progra~1\purene~1\portma~1\PORTAO~1.EXE" [N/A]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [N/A]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [N/A]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"HostManager"="c:\program files\Common Files\AOL\1105975379\ee\AOLSoftware.exe" [N/A]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-11-22 1037192]
"ISUSScheduler"="c:\progra~1\common~1\instal~1\update~1\issch.exe" [N/A]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Flablt"="c:\documents and settings\Sharon\Application Data\Adobe\Update\wndcor.dat" [2010-02-05 18732]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AmazonGSDownloaderTray]
2009-04-06 23:35 247296 ----a-w- c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 23:24 54840 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
c:\program files\Common Files\InstallShield\UpdateService\issch.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
2006-01-19 18:06 11776 ----a-w- c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Walgreens PhotoShow Media Manager]
2006-04-20 06:35 237568 ----a-w- c:\progra~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1105975379\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Maxis\\The Sims\\support\\The Sims Makin' Magic_eReg.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\MUSICMATCH\\Musicmatch Jukebox\\mmjb.exe"=
"c:\\psfonts\\ATMFM.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Infogrames Interactive\\Monopoly Tycoon\\mc.exe"=
"c:\\Documents and Settings\\Sharon\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\DofusUpdater\\DofusUpdater.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AOL 9.5\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\AOL 9.5a\\waol.exe"=
R2 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [5/23/2009 9:51 AM 319488]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [1/14/2010 10:13 AM 108289]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/12/2010 9:38 AM 135664]
S2 mrtRate;mrtRate; [x]
S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\Sharon\Desktop\SysProt\SysProtDrv.sys [2/16/2010 12:26 PM 44288]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-02-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2010-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 16:37]
2010-02-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-12 16:37]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com
uInternet Settings,ProxyOverride = 127.0.0.1;localhost;*.local
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
Trusted Zone: turbotax.com
Trusted Zone: musicmatch.com\online
DPF: {D40F5876-A494-4124-8161-82625BB28C06} - hxxp://aolsvc.aol.com/onlinegames/free-trial-chocolatier-2-secret-ingredients/Chocolatier2Web.1.0.0.14.cab
DPF: {EF148DBB-5B6D-4130-B2A1-661571E86260} - hxxp://aolsvc.aol.com/onlinegames/oberonmajongescape/PTGameLauncher.cab
FF - ProfilePath - c:\documents and settings\Sharon\Application Data\Mozilla\Firefox\Profiles\aa101x97.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
FF - plugin: c:\documents and settings\Sharon\Application Data\Mozilla\Firefox\Profiles\aa101x97.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CIDFE0BD779-44EE-4A4B-AA2E-743C63F2E5E6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
AddRemove-Port Magic - c:\program files\Pure Networks\Port Magic\PortAOL.exe
AddRemove-Quicken Financial Suite - c:\quickenw\DeIsL1.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-17 14:06
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,bd,d3,17,99,3b,08,83,47,8e,f6,6a,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,bd,d3,17,99,3b,08,83,47,8e,f6,6a,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(676)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-02-17 14:12:07
ComboFix-quarantined-files.txt 2010-02-17 21:12
Pre-Run: 38,173,761,536 bytes free
Post-Run: 38,051,131,392 bytes free
- - End Of File - - 280B830112916B60A1304638307462FC