ComboFix 10-08-21.06 - Theo 22/08/2010 15:47:02.4.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3325.2215 [GMT 1:00]
Running from: c:\users\Theo\Desktop\ComboFix.exe
SP: Spyware Terminator *disabled* (Updated) {55EE49A8-16BE-4601-BBE6-607B7F7317DE}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
Infected copy of c:\windows\System32\wininit.exe was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-wininit_31bf3856ad364e35_6.0.6001.18000_none_30f2b8cf0450a6a2\wininit.exe
.
((((((((((((((((((((((((( Files Created from 2010-07-22 to 2010-08-22 )))))))))))))))))))))))))))))))
.
2010-08-22 14:52 . 2010-08-22 14:54 -------- d-----w- c:\users\Theo\AppData\Local\temp
2010-08-22 14:52 . 2010-08-22 14:52 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-21 17:33 . 2010-08-21 17:35 -------- d-----w- c:\users\Theo\AppData\Roaming\Spyware Terminator
2010-08-21 17:33 . 2010-08-21 17:33 6144 ----a-w- c:\programdata\Spyware Terminator\sp_rsdel.exe
2010-08-21 17:33 . 2010-08-21 17:33 5632 ----a-w- c:\programdata\Spyware Terminator\fileobjinfo.sys
2010-08-21 17:33 . 2010-08-21 17:33 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2010-08-21 17:33 . 2010-08-22 03:29 -------- d-----w- c:\program files\Spyware Terminator
2010-08-21 17:33 . 2010-08-22 03:26 -------- d-----w- c:\programdata\Spyware Terminator
2010-08-21 15:43 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-08-21 15:43 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-21 15:43 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-21 15:43 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-21 15:43 . 2010-06-28 20:32 50256 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-08-21 15:42 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-08-21 15:42 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-08-21 14:48 . 2010-08-21 14:52 35 ----a-w- c:\users\Theo\AppData\Roaming\SetValue.bat
2010-08-21 13:56 . 2010-08-21 13:56 -------- d-----w- c:\programdata\Alwil Software
2010-08-21 13:56 . 2010-08-21 13:56 -------- d-----w- c:\program files\Alwil Software
2010-08-21 13:35 . 2010-08-21 14:29 -------- d-----w- c:\users\Theo\AppData\Local\Temp(149)
2010-08-21 12:41 . 2010-08-21 13:22 -------- d-----w- c:\users\Theo\AppData\Local\Temp(148)
2010-08-20 23:24 . 2010-08-21 22:31 -------- d-----w- C:\$RECYCLE(0).BIN
2010-08-20 23:11 . 2009-04-11 04:45 185856 ----a-w- c:\windows\system32\drivers\netbt.sys
2010-08-19 14:58 . 2010-08-19 16:25 -------- d-----w- c:\users\Theo\AppData\Local\ixiejwtcn
2010-08-19 14:58 . 2010-08-19 16:25 -------- d-----w- c:\users\Theo\AppData\Local\rxcfjetjl
2010-08-19 14:07 . 2010-08-19 14:07 54153 ----a-w- c:\programdata\DivX\DFXPlugin\Uninstaller.exe
2010-08-19 14:07 . 2010-08-19 14:07 54128 ----a-w- c:\programdata\DivX\Converter\Uninstaller.exe
2010-08-19 14:07 . 2010-08-19 14:07 54644 ----a-w- c:\programdata\DivX\TranscodeEngine\Uninstaller.exe
2010-08-19 14:07 . 2010-08-19 14:07 57409 ----a-w- c:\programdata\DivX\ControlPanel\Uninstaller.exe
2010-08-19 14:07 . 2010-08-19 14:07 54101 ----a-w- c:\programdata\DivX\MPEG2Plugin\Uninstaller.exe
2010-08-19 14:07 . 2010-08-19 14:07 52963 ----a-w- c:\programdata\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-08-19 14:07 . 2010-08-19 14:07 54073 ----a-w- c:\programdata\DivX\Qt4.5\Uninstaller.exe
2010-08-19 14:07 . 2010-08-21 23:41 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-08-19 14:07 . 2010-08-19 14:07 56969 ----a-w- c:\programdata\DivX\ASPEncoder\Uninstaller.exe
2010-08-19 14:06 . 2010-08-21 23:41 -------- d-----w- c:\program files\DivX
2010-08-19 14:06 . 2010-08-19 14:09 -------- d-----w- c:\programdata\DivX
2010-08-18 16:59 . 2010-08-21 23:41 -------- d-----w- c:\users\Theo\AppData\Roaming\ProfitUI Reborn Updater
2010-08-12 23:44 . 2010-06-18 17:31 36864 ----a-w- c:\windows\system32\rtutils.dll
2010-08-12 23:44 . 2010-06-08 17:35 3600768 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-08-12 23:44 . 2010-06-08 17:35 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-08-12 23:44 . 2010-06-11 16:15 1248768 ----a-w- c:\windows\system32\msxml3.dll
2010-08-12 23:44 . 2010-06-18 15:04 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-12 23:44 . 2010-06-18 15:04 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-08-12 23:44 . 2010-06-16 16:04 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-08 16:21 . 2010-08-21 23:38 -------- d-----w- c:\users\Theo\AppData\Local\Progvo_Software
2010-08-04 23:57 . 2010-08-05 00:10 -------- d-----w- c:\users\Theo\AppData\Local\osouudblj
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-22 14:54 . 2007-01-01 00:12 36821 ----a-w- c:\programdata\nvModes.dat
2010-08-22 14:53 . 2007-01-01 00:10 -------- d-----w- c:\programdata\NVIDIA
2010-08-22 14:35 . 2010-06-29 12:53 8204 ----a-w- c:\users\Theo\AppData\Roaming\wklnhst.dat
2010-08-22 14:30 . 2010-04-22 18:16 -------- d-----w- c:\users\Theo\AppData\Roaming\Advanced Combat Tracker
2010-08-22 13:35 . 2009-12-26 20:36 -------- d-----w- c:\users\Theo\AppData\Roaming\vlc
2010-08-21 23:41 . 2010-04-13 15:12 -------- d-----w- c:\users\Theo\AppData\Roaming\Ventrilo
2010-08-21 23:41 . 2010-02-27 16:24 -------- d-----w- c:\program files\EQ2MAP Updater
2010-08-21 23:41 . 2009-12-26 19:52 -------- d-----w- c:\program files\Steam
2010-08-21 23:41 . 2009-07-04 09:02 -------- d-----w- c:\program files\Microsoft Works
2010-08-21 23:41 . 2009-12-26 19:52 -------- d-----w- c:\program files\Common Files\Steam
2010-08-21 23:41 . 2009-07-04 09:04 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-08-21 23:37 . 2010-04-27 23:42 -------- d-----w- c:\program files\Mohawk Voice
2010-08-21 14:52 . 2010-08-21 14:48 691 ----a-w- c:\users\Theo\AppData\Roaming\GetValue.vbs
2010-08-20 23:49 . 2009-12-26 23:31 117760 ----a-w- c:\users\Theo\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-08-20 22:55 . 2010-02-03 02:09 -------- d-----w- c:\users\Theo\AppData\Roaming\Irce
2010-08-19 23:31 . 2010-08-19 14:08 -------- d-----w- c:\users\Theo\AppData\Roaming\DivX
2010-08-16 09:03 . 2010-03-17 05:59 -------- d-----w- c:\users\Theo\AppData\Roaming\Mieb
2010-08-16 01:37 . 2010-06-12 20:21 -------- d-----w- c:\users\Theo\AppData\Roaming\Elgi
2010-08-13 17:32 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-05 02:33 . 2010-05-19 22:45 -------- d-----w- c:\users\Theo\AppData\Roaming\Cyzuy
2010-08-05 00:18 . 2010-02-27 17:33 1356 ----a-w- c:\users\Theo\AppData\Local\d3d9caps.dat
2010-08-04 23:57 . 2010-02-13 09:00 -------- d-----w- c:\users\Theo\AppData\Roaming\Imam
2010-07-04 17:56 . 2009-12-26 23:29 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-07-04 17:56 . 2007-01-01 00:09 -------- d-----w- c:\program files\NVIDIA Corporation
2010-07-04 17:55 . 2010-07-04 17:55 -------- d-----w- c:\programdata\NVIDIA Corporation
2010-07-04 03:45 . 2010-07-04 03:45 -------- d-----w- c:\programdata\TVU Networks
2010-06-29 12:53 . 2010-06-29 12:53 -------- d-----w- c:\users\Theo\AppData\Roaming\Template
2010-06-26 07:59 . 2009-12-26 23:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-26 06:05 . 2010-08-12 23:45 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-26 06:02 . 2010-08-12 23:45 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-06-26 06:02 . 2010-08-12 23:45 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-06-26 04:25 . 2010-08-12 23:45 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-06-26 02:02 . 2010-06-26 02:02 -------- d-----w- c:\program files\Microsoft.NET
2010-06-21 18:17 . 2010-06-21 18:17 50354 ----a-w- c:\users\Theo\AppData\Roaming\Facebook\uninstall.exe
2010-06-21 13:37 . 2010-08-12 23:45 2037760 ----a-w- c:\windows\system32\win32k.sys
2010-06-11 16:16 . 2010-08-12 23:45 274944 ----a-w- c:\windows\system32\schannel.dll
2010-06-09 23:01 . 2007-11-14 01:00 45648 ----a-w- c:\windows\system32\drivers\pxhelp20.sys
2010-06-09 10:45 . 2010-06-09 10:45 5591040 ----a-w- c:\users\Theo\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
2010-06-07 23:57 . 2010-07-04 17:53 56936 ----a-w- c:\windows\system32\OpenCL.dll
2010-06-07 23:57 . 2010-07-04 17:53 4967528 ----a-w- c:\windows\system32\nvwgf2um.dll
2010-06-07 23:57 . 2010-07-04 17:53 10888168 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-06-07 23:57 . 2010-07-04 17:53 4513384 ----a-w- c:\windows\system32\nvcuda.dll
2010-06-07 23:57 . 2010-07-04 17:53 2632296 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-06-07 23:57 . 2010-07-04 17:53 2145896 ----a-w- c:\windows\system32\nvcuvid.dll
2010-06-07 23:57 . 2010-07-04 17:53 15764072 ----a-w- c:\windows\system32\nvoglv32.dll
2010-06-07 23:57 . 2010-07-04 17:53 232040 ----a-w- c:\windows\system32\nvcod1921.dll
2010-06-07 23:57 . 2010-07-04 17:53 232040 ----a-w- c:\windows\system32\nvcod.dll
2010-06-07 23:57 . 2010-07-04 17:53 10263144 ----a-w- c:\windows\system32\nvcompiler.dll
2010-06-07 23:57 . 2007-01-01 00:08 9712744 ----a-w- c:\windows\system32\nvd3dum.dll
2010-06-07 23:57 . 2007-01-01 00:08 1592424 ----a-w- c:\windows\system32\nvapi.dll
2010-06-07 16:48 . 2010-06-07 16:48 13917800 ----a-w- c:\windows\system32\nvcpl.dll
2010-06-07 16:48 . 2010-06-07 16:48 1331816 ----a-w- c:\windows\system32\nvsvc.dll
2010-06-07 16:48 . 2010-06-07 16:48 129640 ----a-w- c:\windows\system32\nvvsvc.exe
2010-06-07 16:48 . 2010-06-07 16:48 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-05-27 20:08 . 2010-08-12 23:45 81920 ----a-w- c:\windows\system32\iccvid.dll
2010-05-26 17:06 . 2010-06-11 14:00 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-11 14:00 289792 ----a-w- c:\windows\system32\atmfd.dll
2004-06-02 00:47 . 2009-02-28 19:25 1774540 ----a-w- c:\program files\Picture 005.jpg
2009-07-04 18:37 . 2009-04-11 17:43 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
------- Sigcheck -------
[-] 2009-04-11 . 83DE263963AC17119702EEB3E07464CA . 2923520 . . [6.0.6000.16386] . . c:\windows\explorer.exe
[7] 2009-04-11 . D07D4C3038F3578FFCE1C0237F2A1253 . 2926592 . . [6.0.6000.16386] . . c:\windows\ERDNT\cache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-26 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-01-13 6609440]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-01-13 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-01-13 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-01-13 141848]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-01-29 206064]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2010-08-21 2176512]
c:\users\Theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-12-27 576000]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NETGEAR WG111v2 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v2\WG111v2.exe [2010-1-10 1261568]
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
@="FSFilter System Recovery"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^Theo^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk]
path=c:\users\Theo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
backup=c:\windows\pss\Dell Dock.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 00:38 34672 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-06-03 00:50 1144104 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 14:39 1090952 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 16:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminator]
2010-08-21 17:33 2176512 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorShield.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareTerminatorUpdate]
2010-08-21 17:33 3037696 ----a-w- c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-12-26 22:27 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"VistaSp2"=hex(b):08,dc,b6,40,3a,8b,ca,01
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 135664]
R3 GarenaPEngine;GarenaPEngine;c:\users\Theo\AppData\Local\Temp\ZWM8A94.tmp [x]
R3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 22904]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys [2007-12-26 288768]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-11-23 7408]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 SCMNdisP;General NDIS Protocol Driver;c:\windows\system32\DRIVERS\scmndisp.sys [2007-01-19 21728]
S1 aswSP;aswSP; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-11-23 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-11-23 74480]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2010-08-21 142592]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSrv.exe [2009-01-13 81920]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-06-28 50256]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-06-07 240232]
S3 RTL8187;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\DRIVERS\wg111v2.sys [2007-12-26 288768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 15:18]
2010-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-04 15:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
uInternet Settings,ProxyServer = http=127.0.0.1:6522
uInternet Settings,ProxyOverride = <local>
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
FF - ProfilePath - c:\users\Theo\AppData\Roaming\Mozilla\Firefox\Profiles\q15h6s1j.default\
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: c:\program files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Theo\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\users\Theo\AppData\Roaming\Mozilla\Firefox\Profiles\q15h6s1j.default\extensions\
[email protected]\plugins\npTVUAx.dll
FF - plugin: c:\windows\system32\TVUAx\npTVUAx.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0