ComboFix 10-03-15.06 - T 03/16/2010 14:12:49.1.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.247.18 [GMT -4:00] Running from: c:\downloads\ComboFix.exe AV: Norton Security Suite *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Security Suite *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\recycler\S-1-5-21-1327433279-555313921-1828105305-1003 . ((((((((((((((((((((((((( Files Created from 2010-02-16 to 2010-03-16 ))))))))))))))))))))))))))))))) . 2010-03-15 17:25 . 2010-03-15 20:12 -------- d-----w- C:\Energy 2010-03-14 13:12 . 2010-03-14 13:12 -------- d-----w- c:\program files\trend micro 2010-03-14 13:11 . 2010-03-14 13:12 -------- d-----w- C:\rsit 2010-03-13 14:43 . 2010-03-13 14:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec 2010-03-13 12:39 . 2010-03-13 12:39 -------- d-----w- c:\documents and settings\T\Application Data\ArcSoft 2010-03-13 12:39 . 2010-03-13 12:39 -------- d-----w- c:\documents and settings\T\Application Data\HP SimpleSave Application 2010-03-12 16:38 . 2010-03-12 16:35 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys 2010-03-12 16:38 . 2010-03-12 16:35 107368 ----a-r- c:\windows\system32\GEARAspi.dll 2010-03-12 16:36 . 2010-03-12 16:35 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys 2010-03-12 16:36 . 2010-03-12 16:36 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL 2010-03-12 16:36 . 2010-03-12 16:36 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2010-03-12 16:36 . 2010-03-12 17:04 -------- d-----w- c:\program files\Common Files\Symantec Shared 2010-03-12 16:36 . 2010-03-12 16:36 -------- d-----w- c:\program files\Symantec 2010-03-12 16:34 . 2010-03-12 22:05 -------- d-----w- c:\windows\system32\drivers\N360 2010-03-12 16:34 . 2010-03-12 16:35 -------- d-----w- c:\program files\Norton Security Suite 2010-03-12 16:34 . 2010-03-12 16:34 -------- d-----w- c:\program files\Windows Sidebar 2010-03-12 16:34 . 2010-03-12 16:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton 2010-03-12 16:32 . 2010-03-12 16:32 -------- d-----w- c:\program files\NortonInstaller 2010-03-12 13:31 . 2010-03-12 13:31 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller 2010-03-12 12:17 . 2010-03-12 12:17 -------- d-----w- c:\documents and settings\T\Local Settings\Application Data\Sunbelt Software 2010-03-10 16:32 . 2010-03-10 16:32 -------- d-----w- c:\documents and settings\DVG\Local Settings\Application Data\Yahoo 2010-03-10 16:30 . 2010-03-10 16:30 -------- d-----w- c:\documents and settings\DVG\Application Data\Yahoo! 2010-03-10 16:12 . 2009-10-23 15:28 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe 2010-03-10 01:10 . 2010-03-10 01:18 -------- d-----w- c:\documents and settings\T\Local Settings\Application Data\Yahoo 2010-03-10 00:46 . 2010-03-10 01:09 -------- d-----w- c:\documents and settings\T\Application Data\Yahoo! 2010-03-10 00:43 . 2010-03-11 22:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! 2010-03-10 00:34 . 2010-03-12 00:23 -------- d-----w- c:\program files\Yahoo! 2010-03-09 21:26 . 2010-03-09 22:03 -------- d-----w- c:\documents and settings\DVG\Application Data\mIRC 2010-03-09 18:49 . 2010-03-09 18:49 -------- d-----w- c:\documents and settings\T\Application Data\mIRC 2010-03-09 18:46 . 2010-03-09 18:46 -------- d-----w- c:\program files\Dream Sudoku Trial 2010-03-06 19:07 . 2010-03-06 19:08 -------- d-----w- c:\documents and settings\DVG\Application Data\webex 2010-03-06 19:04 . 2010-03-06 19:08 -------- d-----w- c:\documents and settings\DVG\Local Settings\Application Data\WebEx 2010-03-03 21:04 . 2004-06-10 14:34 53693 ----a-r- c:\windows\UNDPX2A.sys 2010-03-03 21:04 . 2004-06-10 14:31 135168 ----a-r- c:\windows\UNDPX2A.exe 2010-03-03 21:04 . 2004-06-09 23:42 15429 ----a-r- c:\windows\system32\drivers\Sacm2A.sys 2010-02-23 18:28 . 2010-03-11 18:09 -------- d-----w- C:\GM591 2010-02-20 00:26 . 2010-03-05 19:34 -------- d-----w- c:\documents and settings\T\Application Data\Move Networks . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-16 01:17 . 2009-09-14 22:56 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-03-15 14:20 . 2010-01-05 16:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2010-03-13 02:01 . 2010-01-05 14:06 -------- d-----w- c:\documents and settings\DVG\Application Data\MyScribe 2010-03-12 16:36 . 2010-03-12 16:36 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF 2010-03-12 16:36 . 2010-03-12 16:36 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT 2010-03-12 15:27 . 2009-12-02 18:44 -------- d-----w- c:\program files\COMODO 2010-03-12 15:16 . 2009-09-15 21:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft 2010-03-12 12:26 . 2009-11-03 13:12 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys 2010-03-12 00:23 . 2010-01-26 13:47 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2010-03-12 00:23 . 2010-02-14 17:56 -------- d-----w- c:\program files\PicLensIE 2010-03-05 21:53 . 2009-09-13 20:55 -------- d-----w- c:\program files\CCleaner 2010-03-03 20:25 . 2009-06-17 01:20 -------- d-----w- c:\documents and settings\DVG\Application Data\U3 2010-02-28 20:51 . 2010-01-04 18:57 -------- d-----w- c:\documents and settings\T\Application Data\MyScribe 2010-02-28 16:22 . 2010-02-03 20:51 54 ----a-w- c:\windows\system32\rp_stats.dat 2010-02-28 16:22 . 2010-02-03 20:51 39 ----a-w- c:\windows\system32\rp_rules.dat 2010-02-07 20:12 . 2009-02-05 11:36 -------- d-----w- c:\program files\Google 2010-02-07 16:12 . 2010-01-23 20:09 -------- d-----w- c:\program files\LogMeIn 2010-02-01 11:07 . 2009-12-16 07:25 1474832 ----a-w- c:\windows\system32\drivers\sfi.dat 2010-01-29 21:19 . 2010-01-29 21:19 -------- d-----w- c:\program files\TrendMicro 2010-01-29 19:52 . 2009-10-25 23:23 -------- d-----w- c:\program files\Windows Live 2010-01-29 18:55 . 2009-03-01 20:04 -------- d-----w- c:\documents and settings\T\Application Data\StumbleUpon 2010-01-29 14:52 . 2009-02-05 11:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater 2010-01-28 16:34 . 2006-02-28 18:05 -------- d-----w- c:\program files\Common Files\Java 2010-01-28 16:00 . 2006-02-28 18:05 -------- d-----w- c:\program files\Java 2010-01-24 00:45 . 2010-01-24 00:45 -------- d-----w- c:\program files\Belarc 2010-01-23 23:29 . 2010-01-23 23:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Grisoft 2010-01-20 21:27 . 2010-01-20 21:26 -------- d-----w- c:\program files\Common Files\Adobe 2010-01-20 20:56 . 2006-02-28 18:18 -------- d-----w- c:\program files\Common Files\Real 2010-01-20 20:24 . 2010-01-20 20:16 -------- d-----w- c:\program files\QuickTime 2010-01-20 20:15 . 2010-01-20 20:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer 2010-01-20 00:07 . 2009-03-14 19:14 -------- d-----w- c:\program files\Microsoft Silverlight 2010-01-14 16:12 . 2009-10-16 23:14 181120 ------w- c:\windows\system32\MpSigStub.exe 2010-01-07 11:53 . 2009-03-20 00:17 80368 ----a-w- c:\documents and settings\T\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-01-06 19:22 . 2009-08-01 22:32 80368 ----a-w- c:\documents and settings\DVG\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-12-31 16:50 . 2006-02-28 17:44 353792 ----a-w- c:\windows\system32\drivers\srv.sys 2009-12-21 19:14 . 2004-08-10 18:51 916480 ----a-w- c:\windows\system32\wininet.dll 2009-12-17 22:14 . 2009-02-05 11:29 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-12-16 18:43 . 2008-04-14 00:12 343040 ----a-w- c:\windows\system32\mspaint.exe 2010-01-08 21:08 . 2010-01-08 21:08 28472 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll 2010-01-08 21:08 . 2010-01-08 21:08 185224 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll 2010-01-08 21:08 . 2010-01-08 21:08 99208 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll 2009-02-14 17:22 . 2009-02-14 17:22 56 --sh--r- c:\windows\system32\398F75844F.sys 2009-02-14 17:22 . 2009-02-14 17:22 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SigmatelSysTrayApp"="stsystra.exe" [2005-09-10 393216] "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-15 94208] "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-15 114688] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-15 77824] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit] 2009-09-29 00:34 87352 ----a-w- c:\windows\system32\LMIinit.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ \0SsiEfr.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys] @="FSFilter Activity Monitor" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2009-12-11 20:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2009-12-22 06:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter] 2007-09-14 01:50 1603152 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu] 2007-10-26 01:10 652624 ----a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet] 2005-12-15 16:44 839680 ----a-w- c:\program files\Dell\QuickSet\quickset.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor] 2008-10-25 16:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] 2004-07-27 22:50 221184 ----a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] 2004-07-27 22:50 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2009-11-11 04:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2010-01-11 20:21 246504 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] 2005-11-29 10:56 761947 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] 2010-01-20 20:39 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "RDSessMgr"=3 (0x3) "RasMan"=3 (0x3) "RasAuto"=3 (0x3) "LogMeIn"=2 (0x2) "LMIMaint"=2 (0x2) "TapiSrv"=3 (0x3) "StumbleUponUpdateService"=3 (0x3) "mnmsrvc"=3 (0x3) "Microsoft Office Groove Audit Service"=3 (0x3) "LMIRescue"=2 (0x2) "gusvc"=2 (0x2) "gupdate1c987866e79faa8"=2 (0x2) "CiSvc"=3 (0x3) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "24006:TCP"= 24006:TCP:*:Disabled:BitComet 24006 TCP "24006:UDP"= 24006:UDP:*:Disabled:BitComet 24006 UDP R0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [x] R3 getPlus(R) Installer;getPlus(R) Installer;c:\program files\NOS\bin\getPlus_HelperSvc.exe [x] R3 pctNDIS;PC Tools Driver;c:\windows\system32\DRIVERS\pctNdis.sys [2009-11-22 55208] R4 gupdate1c987866e79faa8;Google Update Service (gupdate1c987866e79faa8);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-05 133104] R4 LMIRescue;LogMeIn Rescue (e67ed0dd-2e10-409a-842d-fd9354bb38b3);c:\program files\LogMeIn Rescue Calling Card\CallingCard.exe [x] S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SYMEFA.SYS [2010-03-12 310320] S1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\Drivers\N360\0308000.029\BHDrvx86.sys [2010-03-12 259632] S1 ccHP;Symantec Hash Provider;c:\windows\System32\Drivers\N360\0308000.029\ccHPx86.sys [2010-03-12 482432] S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100312.001\IDSxpx86.sys [2009-10-28 329592] S1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [2010-03-12 95024] S2 N360;Norton Security Suite;c:\program files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe [2010-03-12 117640] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-03-12 102448] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] getPlusHelper REG_MULTI_SZ getPlusHelper . Contents of the 'Scheduled Tasks' folder 2010-03-10 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34] 2010-03-16 c:\windows\Tasks\User_Feed_Synchronization-{A1436AFE-2180-4C5F-A870-A156C3FC039E}.job - c:\windows\system32\msfeedssync.exe [2007-08-13 08:31] . . ------- Supplementary Scan ------- . uStart Page = hxxp://malwareremoval.com/forum/viewtopic.php?f=11&t=50086&p=511727&e=511727 uInternet Connection Wizard,ShellNext = iexplore DPF: {AD58C149-8AE2-4878-99DC-3A164E32F814} - hxxp://appsnet.bentley.com/myselectcd/SAXFileEE.cab FF - ProfilePath - c:\documents and settings\T\Application Data\Mozilla\Firefox\Profiles\4w9t11f6.default\ FF - prefs.js: browser.startup.homepage - hxxp://google.com FF - component: c:\documents and settings\T\Application Data\Mozilla\Firefox\Profiles\4w9t11f6.default\extensions\{5fb1186a-3398-4c47-b579-0f2eee222ad1}\platform\WINNT_x86-msvc\components\outwit-3.5.dll FF - component: c:\documents and settings\T\Application Data\Mozilla\Firefox\Profiles\4w9t11f6.default\extensions\{5fb1186a-3398-4c47-b579-0f2eee222ad1}\platform\WINNT_x86-msvc\components\outwit-3.6.dll FF - component: c:\documents and settings\T\Application Data\Mozilla\Firefox\Profiles\4w9t11f6.default\extensions\{5fb1186a-3398-4c47-b579-0f2eee222ad1}\platform\WINNT_x86-msvc\components\outwit.dll FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll FF - plugin: c:\documents and settings\T\Application Data\Move Networks\plugins\npqmp071502000008.dll FF - plugin: c:\documents and settings\T\Application Data\Mozilla\Firefox\Profiles\4w9t11f6.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1487.6512\npCIDetect13.dll FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); . - - - - ORPHANS REMOVED - - - - Toolbar-Locked - (no file) WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) MSConfigStartUp-00PCTFW - c:\program files\PC Tools Firewall Plus\FirewallGUI.exe MSConfigStartUp-AVG9_TRAY - c:\progra~1\AVG\AVG9\avgtray.exe MSConfigStartUp-COMODO Internet Security - c:\program files\COMODO\COMODO Internet Security\cfp.exe MSConfigStartUp-DellSupport - c:\program files\DellSupport\DSAgnt.exe MSConfigStartUp-ISTray - c:\program files\Spyware Doctor\pctsTray.exe MSConfigStartUp-LogMeIn GUI - c:\program files\LogMeIn\x86\LogMeInSystray.exe MSConfigStartUp-Microsoft Default Manager - c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe MSConfigStartUp-Windows Defender - c:\program files\Windows Defender\MSASCui.exe AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-03-16 14:22 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360] "ImagePath"="\"c:\program files\Norton Security Suite\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton Security Suite\Engine\3.8.0.41\diMaster.dll\" /prefetch:1" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(852) c:\windows\system32\LMIinit.dll - - - - - - - > 'explorer.exe'(536) c:\windows\system32\WININET.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll c:\windows\system32\LMIRfsClientNP.dll . Completion time: 2010-03-16 14:33:40 ComboFix-quarantined-files.txt 2010-03-16 18:33 Pre-Run: 14,646,517,760 bytes free Post-Run: 14,650,851,328 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptOut - - End Of File - - A7CDE54A374707E472B7051000E41C38