ComboFix 10-11-21.01 - Debbie 22/11/2010 12:53:57.1.2 - x86
Running from: c:\documents and settings\Debbie\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Debbie\LOCALS~1\Temp\IE172.tmp\sp2gdr\msctf.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE172.tmp\sp2qfe\msctf.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE172.tmp\update\spcustom.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE172.tmp\update\update.exe
c:\docume~1\Debbie\LOCALS~1\Temp\IE172.tmp\update\updspapi.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\ie4uinit.exe
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\iedkcs32.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\iedvtool.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\ieframe.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\iepeers.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\ieproxy.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\iertutil.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\inetcpl.cpl
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\jsproxy.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\msfeeds.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\msfeedsbs.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\mshtml.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\mstime.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\occache.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\urlmon.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\wininet.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3GDR\xpshims.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\ie4uinit.exe
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\iedkcs32.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\iedvtool.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\ieframe.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\iepeers.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\ieproxy.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\iertutil.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\inetcpl.cpl
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\jsproxy.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\msfeeds.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\msfeedsbs.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\mshtml.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\mstime.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\occache.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\urlmon.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\wininet.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\SP3QFE\xpshims.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\update\spcustom.dll
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\update\update.exe
c:\docume~1\Debbie\LOCALS~1\Temp\IE7B2.tmp\update\updspapi.dll
c:\documents and settings\Debbie\Application Data\Adobe\AdobeUpdate .exe
c:\documents and settings\Debbie\Application Data\Adobe\AdobeUpdate.exe
c:\documents and settings\Debbie\Application Data\Adobe\plugs
c:\documents and settings\Debbie\Local Settings\Temp\IE172.tmp\sp2gdr\msctf.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE172.tmp\sp2qfe\msctf.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE172.tmp\update\spcustom.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE172.tmp\update\update.exe
c:\documents and settings\Debbie\Local Settings\Temp\IE172.tmp\update\updspapi.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\ie4uinit.exe
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\iedkcs32.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\iedvtool.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\ieframe.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\iepeers.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\ieproxy.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\iertutil.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\inetcpl.cpl
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\jsproxy.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\msfeeds.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\msfeedsbs.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\mshtml.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\mstime.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\occache.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\urlmon.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\wininet.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3GDR\xpshims.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\ie4uinit.exe
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\iedkcs32.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\iedvtool.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\ieframe.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\iepeers.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\ieproxy.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\iertutil.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\inetcpl.cpl
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\jsproxy.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\msfeeds.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\msfeedsbs.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\mshtml.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\mstime.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\occache.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\urlmon.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\wininet.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\SP3QFE\xpshims.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\update\spcustom.dll
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\update\update.exe
c:\documents and settings\Debbie\Local Settings\Temp\IE7B2.tmp\update\updspapi.dll
c:\windows\explorer(2).exe
c:\windows\explorer(3).exe
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job
Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe
Infected copy of c:\windows\explorer.exe was found and disinfected
Restored copy from - c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\explorer.exe
.
((((((((((((((((((((((((( Files Created from 2010-10-22 to 2010-11-22 )))))))))))))))))))))))))))))))
.
2010-11-20 08:26 . 2010-11-20 08:26 -------- d-----w- c:\program files\MozBackup
2010-11-20 07:42 . 2010-11-20 07:42 -------- d-----w- c:\program files\ESET
2010-11-20 06:17 . 2010-11-20 06:17 -------- d-----w- c:\windows\system32\wbem\Repository
2010-11-20 05:50 . 2010-11-20 06:16 -------- d-----w- c:\program files\AutorunRemover
2010-11-20 05:46 . 2010-11-20 06:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-11-20 05:46 . 2010-11-20 06:16 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-11-19 06:30 . 2010-11-20 06:17 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-11-19 06:27 . 2010-11-20 06:17 -------- d-----w- C:\d83227922bd7e19fbd
2010-11-19 06:17 . 2010-11-20 06:17 -------- d-----w- c:\windows\system32\NtmsData
2010-11-17 03:54 . 2010-11-17 03:54 -------- d-----w- c:\windows\system32\CatRoot_bak
2010-11-17 03:18 . 2010-11-22 01:59 -------- d-----w- c:\windows\system32\CatRoot2
2010-11-17 03:10 . 2010-11-17 03:53 -------- d-----w- c:\windows\system32\Adobe
2010-11-17 03:02 . 2010-11-17 03:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-11-17 01:58 . 2010-11-17 01:58 -------- d-----w- C:\BJPrinter
2010-11-17 01:42 . 2010-11-17 01:42 -------- d-----w- c:\documents and settings\All Users\Application Data\SlySoft
2010-11-17 01:42 . 2010-11-17 01:42 -------- d-----w- c:\program files\SlySoft
2010-11-16 22:36 . 2010-11-17 07:36 -------- d-----w- c:\program files\DVD Shrink
2010-11-16 06:36 . 2010-11-17 03:59 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-11-16 05:47 . 2000-06-26 00:45 106496 ----a-w- c:\windows\system32\TwnLib20.dll
2010-11-16 05:47 . 2004-07-20 06:24 471040 ------w- c:\windows\system32\ImagXRA7.dll
2010-11-16 05:47 . 2004-07-08 22:43 364544 ------w- c:\windows\system32\TwnLib4.dll
2010-11-16 05:47 . 2004-07-20 06:24 476320 ------w- c:\windows\system32\ImagXpr7.dll
2010-11-16 05:47 . 2004-07-20 06:24 262144 ------w- c:\windows\system32\ImagXR7.dll
2010-11-16 05:47 . 2004-07-20 06:24 1568768 ------w- c:\windows\system32\ImagX7.dll
2010-11-16 05:47 . 2001-06-25 21:15 38912 ------w- c:\windows\system32\picn20.dll
2010-11-16 05:47 . 2010-11-16 05:48 -------- d-----w- c:\program files\Common Files\Ahead
2010-11-16 05:47 . 2001-07-09 00:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
2010-11-16 05:47 . 2010-11-16 05:47 -------- d-----w- c:\program files\Ahead
2010-11-16 05:40 . 2010-11-20 08:27 -------- d-----w- c:\documents and settings\Debbie\Application Data\ImgBurn
2010-11-16 05:33 . 2010-11-16 05:33 -------- d-----w- c:\program files\ImgBurn
2010-11-13 01:53 . 2010-11-13 01:53 -------- d-----w- c:\documents and settings\Debbie\Application Data\Malwarebytes
2010-11-13 01:53 . 2010-04-29 04:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-13 01:53 . 2010-11-13 01:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-11-13 01:53 . 2010-04-29 04:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-13 01:53 . 2010-11-13 01:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-11-13 01:49 . 2010-11-13 01:49 -------- d-----w- c:\documents and settings\Debbie\Application Data\Avira
2010-11-06 06:44 . 2010-05-06 10:41 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-11-06 06:44 . 2010-05-06 10:41 599040 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-11-06 06:44 . 2010-05-06 10:41 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-11-06 06:44 . 2010-05-06 10:41 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-11-06 06:44 . 2010-05-06 10:41 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-11-06 06:44 . 2010-05-06 10:41 11076096 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-11-06 06:44 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2010-11-06 06:21 . 2006-12-28 19:01 19569 ----a-w- c:\windows\006203_.tmp
2010-11-06 03:03 . 2010-11-06 03:03 -------- d-----w- c:\windows\Sun
2010-11-04 10:22 . 2010-11-04 10:22 -------- d-----w- c:\program files\MSXML 6.0
2010-11-04 09:59 . 2010-02-24 12:31 454016 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-11-04 09:43 . 2010-02-16 13:19 2181376 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-11-04 09:43 . 2010-02-16 13:17 2137088 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-11-04 09:43 . 2010-02-16 12:39 2058368 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-11-04 09:43 . 2010-02-16 12:39 2016768 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-11-04 09:42 . 2008-06-13 13:10 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-11-04 09:32 . 2010-10-27 06:10 16856 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2010-11-04 09:32 . 2010-10-27 06:10 719832 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2010-10-30 03:25 . 2010-11-04 09:18 -------- d-s---w- c:\documents and settings\Brodie
2010-10-29 03:48 . 2010-10-29 03:48 -------- d-----w- c:\documents and settings\Debbie\Local Settings\Application Data\Identities
2010-10-28 03:53 . 2010-11-04 09:19 -------- d-----w- c:\documents and settings\Debbie\Application Data\vlc
2010-10-28 03:52 . 2010-10-28 03:52 -------- d-----w- c:\program files\VideoLAN
2010-10-27 04:49 . 2010-10-27 04:49 -------- d-----w- c:\documents and settings\Debbie\IECompatCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-04 10:32 . 2010-05-27 00:32 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-11-04 10:32 . 2010-05-27 00:32 126856 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-09-30 21:25 . 2010-09-30 21:25 30376 ----a-w- c:\windows\system32\drivers\ElbyCDIO.sys
2010-09-30 11:18 . 2010-09-30 11:18 89256 ----a-w- c:\windows\system32\ElbyCDIO.dll
2010-09-14 13:16 . 2010-09-14 13:16 108480 ----a-w- c:\windows\system32\drivers\AnyDVD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"Mobile Partner"="c:\program files\3 MobileBroadband\3 MobileBroadband.exe" [2010-10-04 110592]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2010-11-15 4676544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-04 281768]
"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2009-10-23 827904]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-02-28 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-11-04 135336]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Debbie\Application Data\Mozilla\Firefox\Profiles\49ff8s4f.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=4&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=59033&p=
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-11-22 12:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1772)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\browselc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\wscntfy.exe
c:\windows\SOUNDMAN.EXE
.
**************************************************************************
.
Completion time: 2010-11-22 13:04:38 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-22 02:04
Pre-Run: 31,060,086,784 bytes free
Post-Run: 31,050,489,856 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 9A0E00B468385528485433DA8EE14F23