ComboFix 10-04-07.04 - jessc0125 04/08/2010 8:52.3.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.735.493 [GMT -4:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\jessc0125\Desktop\CFScript.txt FILE :: "c:\documents and settings\jessc0125\Local Settings\Application Data\128822158.dll" "c:\documents and settings\jessc0125\Local Settings\Application Data\4288942400.dll" "c:\windows\system32\clipac32.dll.vir" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\5ea4257 c:\documents and settings\jessc0125\Local Settings\Application Data\128822158.dll c:\documents and settings\jessc0125\Local Settings\Application Data\4288942400.dll c:\windows\system32\clipac32.dll.vir . ((((((((((((((((((((((((( Files Created from 2010-03-08 to 2010-04-08 ))))))))))))))))))))))))))))))) . 2010-04-08 07:20 . 2010-04-08 07:20 -------- d-----w- c:\windows\LastGood 2010-04-08 07:01 . 2010-04-08 07:01 -------- d-----w- c:\windows\system32\bits 2010-04-08 07:00 . 2010-04-08 07:39 -------- d--h--w- c:\windows\$hf_mig$ 2010-04-08 02:43 . 2004-07-01 22:08 7680 -c--a-w- c:\windows\system32\dllcache\bitsprx2.dll 2010-04-08 02:43 . 2004-07-01 22:08 7680 ----a-w- c:\windows\system32\bitsprx2.dll 2010-04-08 02:43 . 2004-07-01 22:08 7168 -c--a-w- c:\windows\system32\dllcache\bitsprx3.dll 2010-04-08 02:43 . 2004-07-01 22:08 7168 ----a-w- c:\windows\system32\bitsprx3.dll 2010-04-08 02:43 . 2004-07-01 22:08 331776 -c--a-w- c:\windows\system32\dllcache\winhttp.dll 2010-04-08 02:43 . 2004-07-01 22:08 331776 ----a-w- c:\windows\system32\winhttp.dll 2010-04-08 02:43 . 2004-07-01 22:08 17408 -c--a-w- c:\windows\system32\dllcache\qmgrprxy.dll 2010-04-08 02:43 . 2004-07-01 22:08 17408 ----a-w- c:\windows\system32\qmgrprxy.dll 2010-04-08 02:43 . 2004-06-30 23:59 158720 ----a-w- c:\windows\system32\xpob2res.dll 2010-04-08 02:29 . 2009-08-06 23:23 274288 ----a-w- c:\windows\system32\mucltui.dll 2010-04-08 02:28 . 2009-08-06 23:24 327896 ----a-w- c:\windows\system32\wucltui.dll 2010-04-08 02:28 . 2009-08-06 23:24 44768 ----a-w- c:\windows\system32\wups2.dll 2010-04-08 02:28 . 2009-08-06 23:24 35552 ----a-w- c:\windows\system32\wups.dll 2010-04-08 02:28 . 2009-08-06 23:23 575704 ----a-w- c:\windows\system32\wuapi.dll 2010-04-07 12:43 . 2010-04-07 12:43 503808 ----a-w- c:\documents and settings\jessc0125\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-46c7edcb-n\msvcp71.dll 2010-04-07 12:43 . 2010-04-07 12:43 499712 ----a-w- c:\documents and settings\jessc0125\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-46c7edcb-n\jmc.dll 2010-04-07 12:43 . 2010-04-07 12:43 348160 ----a-w- c:\documents and settings\jessc0125\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-46c7edcb-n\msvcr71.dll 2010-04-07 12:43 . 2010-04-07 12:43 -------- d-----w- c:\program files\Common Files\Java 2010-04-07 12:43 . 2010-04-07 12:43 61440 ----a-w- c:\documents and settings\jessc0125\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-32742fe7-n\decora-sse.dll 2010-04-07 12:43 . 2010-04-07 12:43 12800 ----a-w- c:\documents and settings\jessc0125\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-32742fe7-n\decora-d3d.dll 2010-04-07 12:33 . 2010-04-07 12:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage 2010-04-01 14:26 . 2010-04-06 21:21 -------- d-----w- c:\documents and settings\jessc0125\Local Settings\Application Data\avG 2010-03-31 23:14 . 2010-03-31 23:14 388096 ----a-r- c:\documents and settings\jessc0125\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe 2010-03-31 23:14 . 2010-03-31 23:14 -------- d-----w- c:\program files\TrendMicro 2010-03-31 21:28 . 2010-03-31 21:28 -------- d-----w- c:\documents and settings\jessc0125\Application Data\Malwarebytes 2010-03-31 21:28 . 2010-03-29 20:24 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-31 21:28 . 2010-03-31 21:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-03-31 21:28 . 2010-03-31 21:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-03-31 21:28 . 2010-03-29 20:24 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-03-29 23:04 . 2010-03-29 23:04 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\AdobeUM 2010-03-28 17:14 . 2010-03-28 17:14 664 ----a-w- c:\windows\system32\d3d9caps.dat 2010-03-24 15:37 . 2010-03-24 15:37 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe 2010-03-23 16:31 . 2010-03-28 17:29 146304 ----a-w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-03-23 16:26 . 2010-03-29 23:04 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe 2010-03-23 14:55 . 2010-03-23 14:55 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Threat Expert 2010-03-23 14:55 . 2010-03-23 14:56 -------- d-----w- c:\documents and settings\LocalService\Application Data\ATTTOOLBAR 2010-03-23 14:55 . 2010-03-23 14:55 -------- d-----w- c:\windows\Favorites 2010-03-22 04:32 . 2010-03-22 04:32 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Yahoo! 2010-03-22 04:31 . 2010-03-22 04:31 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Threat Expert 2010-03-22 04:31 . 2010-03-23 02:36 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\ATTTOOLBAR 2010-03-22 04:31 . 2010-03-22 04:31 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Mozilla 2010-03-21 16:15 . 2010-03-21 16:15 50354 ----a-w- c:\documents and settings\jessc0125\Application Data\Facebook\uninstall.exe 2010-03-21 16:15 . 2010-03-21 16:15 -------- d-----w- c:\documents and settings\jessc0125\Application Data\Facebook 2010-03-20 12:56 . 2010-03-20 12:56 -------- d-s---w- c:\documents and settings\LocalService\UserData 2010-03-20 07:16 . 2010-03-20 07:16 -------- d-s---w- c:\windows\system32\config\systemprofile\UserData . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-04-07 12:43 . 2005-06-06 21:57 -------- d-----w- c:\program files\Java 2010-04-07 12:38 . 2005-05-14 19:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint 2010-04-07 12:37 . 2008-05-01 19:15 -------- d-----w- c:\program files\Coupons 2010-04-06 00:10 . 2008-06-11 22:36 -------- d-----w- c:\documents and settings\All Users\Application Data\HP 2010-03-29 01:30 . 2005-05-14 22:18 86912 ----a-w- c:\windows\system32\drivers\atapi.sys 2010-03-28 16:04 . 2009-11-26 21:08 -------- d-----w- c:\program files\Spyware Doctor 2010-03-28 16:04 . 2009-11-26 21:17 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-03-28 15:40 . 2005-06-29 03:14 -------- d-----w- c:\documents and settings\jessc0125\Application Data\Lavasoft 2010-03-28 15:39 . 2007-02-05 02:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer 2010-03-28 15:37 . 2005-08-18 11:02 -------- d-----w- c:\program files\Common Files\AOL 2010-03-28 15:36 . 2005-07-07 01:35 -------- d-----w- c:\program files\Google 2010-03-28 15:33 . 2009-01-21 22:56 -------- d-----w- c:\documents and settings\jessc0125\Application Data\Move Networks 2010-03-28 15:32 . 2005-06-29 03:51 -------- d-----w- c:\program files\Mozilla Thunderbird 2010-03-28 15:31 . 2003-07-08 04:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec 2010-03-28 15:31 . 2003-07-08 04:48 -------- d-----w- c:\program files\Common Files\Symantec Shared 2010-03-28 15:30 . 2003-07-08 04:48 -------- d-----w- c:\program files\Symantec 2010-03-28 15:29 . 2005-06-29 03:07 -------- d-----w- c:\program files\Spybot - Search & Destroy 2010-03-28 15:29 . 2005-06-29 03:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2010-03-28 15:21 . 2009-10-10 18:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! 2010-03-28 15:21 . 2005-06-09 00:08 -------- d-----w- c:\program files\Yahoo! 2010-03-28 15:20 . 2005-10-14 15:16 -------- d-----w- c:\documents and settings\jessc0125\Application Data\Yahoo! 2010-03-28 15:09 . 2009-10-31 15:07 -------- d-----w- c:\documents and settings\All Users\Application Data\ATTToolbar 2010-03-28 13:34 . 2005-06-15 03:08 -------- d-----w- c:\program files\AIM 2010-03-28 13:33 . 2005-06-29 04:12 -------- d---a-w- c:\documents and settings\jessc0125\Application Data\AVG7 2010-03-28 13:32 . 2005-06-29 04:12 -------- d-----w- c:\documents and settings\LocalService\Application Data\AVG7 2010-03-28 13:32 . 2005-06-29 04:11 -------- d-----w- c:\documents and settings\All Users\Application Data\avg7 2010-03-09 08:28 . 2009-01-25 21:54 411368 ----a-w- c:\windows\system32\deploytk.dll 2010-03-06 05:30 . 2010-03-06 05:30 847040 ----a-w- c:\documents and settings\jessc0125\Application Data\Facebook\axfbootloader.dll 2010-03-06 05:30 . 2010-03-06 05:30 5582848 ----a-w- c:\documents and settings\jessc0125\Application Data\Facebook\npfbplugin_1_0_3.dll 2010-02-25 03:54 . 2009-10-31 15:07 -------- d-----w- c:\documents and settings\jessc0125\Application Data\ATTToolbar 2010-02-14 02:47 . 2005-06-29 03:41 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-01-16 18:24 . 2010-01-16 18:24 28696928 ----a-w- c:\documents and settings\All Users\Application Data\Leapfrog\LeapFrog Connect\Updates\UPCInstaller.exe 2010-01-16 18:18 . 2010-01-16 18:18 3106632 ----a-w- c:\documents and settings\All Users\Application Data\Leapfrog\LeapFrog Connect\Updates\MyPalsPlugin.exe 2010-01-12 20:27 . 2010-01-15 14:16 52224 ----a-w- c:\documents and settings\jessc0125\Application Data\Mozilla\Firefox\Profiles\epyp8tj7.Default User\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\FFExternalAlert.dll 2010-01-12 20:27 . 2010-01-15 14:16 101376 ----a-w- c:\documents and settings\jessc0125\Application Data\Mozilla\Firefox\Profiles\epyp8tj7.Default User\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\RadioWMPCore.dll 2008-12-12 17:41 . 2007-01-03 21:22 168 --sha-r- c:\windows\system32\690A7241F3.sys 2008-12-12 17:41 . 2007-01-03 21:22 3662 --sha-w- c:\windows\system32\KGyGaAvL.sys . ------- Sigcheck ------- [-] 2004-08-04 . 49911DD39E023BB6C45E4E436CFBD297 . 13824 . . [5.1.2600.2180] . . c:\windows\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\wscntfy.exe [-] 2004-08-04 . EEF46DAB68229A14DA3D8E73C99E2959 . 129536 . . [5.1.2600.2180] . . c:\windows\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\xmlprov.dll c:\windows\System32\wscntfy.exe ... is missing !! c:\windows\System32\xmlprov.dll ... is missing !! . ((((((((((((((((((((((((((((( SnapShot@2010-04-06_21.24.24 ))))))))))))))))))))))))))))))))))))))))) . + 2010-04-08 07:17 . 2010-04-08 07:17 16384 c:\windows\Temp\Perflib_Perfdata_550.dat + 2005-05-14 22:22 . 2009-08-06 23:24 53472 c:\windows\system32\wuauclt.exe - 2003-07-08 04:19 . 2010-04-06 21:24 53608 c:\windows\system32\perfc009.dat + 2003-07-08 04:19 . 2010-04-07 01:36 53608 c:\windows\system32\perfc009.dat + 2005-05-14 22:22 . 2009-08-06 23:24 53472 c:\windows\system32\dllcache\wuauclt.exe + 2005-05-14 22:19 . 2009-08-06 23:24 96480 c:\windows\system32\dllcache\cdm.dll + 2005-05-14 22:19 . 2009-08-06 23:24 96480 c:\windows\system32\cdm.dll + 2009-08-06 23:23 . 2009-08-06 23:23 209624 c:\windows\system32\wuweb.dll + 2005-05-14 22:21 . 2004-07-01 22:08 361984 c:\windows\system32\qmgr.dll - 2003-07-08 04:19 . 2010-04-06 21:24 383254 c:\windows\system32\perfh009.dat + 2003-07-08 04:19 . 2010-04-07 01:36 383254 c:\windows\system32\perfh009.dat + 2009-08-06 23:23 . 2009-08-06 23:23 215904 c:\windows\system32\muweb.dll + 2010-04-07 12:43 . 2010-03-09 08:28 153376 c:\windows\system32\javaws.exe + 2010-04-07 12:43 . 2010-03-09 08:28 145184 c:\windows\system32\javaw.exe + 2010-04-07 12:43 . 2010-03-09 08:28 145184 c:\windows\system32\java.exe + 2003-07-11 22:36 . 2010-04-08 12:51 262144 c:\windows\system32\config\systemprofile\NTUSER.DAT - 2003-07-11 22:36 . 2010-04-06 21:08 262144 c:\windows\system32\config\systemprofile\NTUSER.DAT - 2005-05-14 22:36 . 2005-05-14 22:32 262144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat + 2005-05-14 22:36 . 2010-04-07 12:43 262144 c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat + 2010-04-08 02:43 . 2004-07-01 22:08 361984 c:\windows\system32\bits\qmgr.dll + 2010-04-07 12:43 . 2010-04-07 12:43 180224 c:\windows\Installer\25dd6d5.msi + 2005-05-14 22:22 . 2009-08-06 23:23 1929952 c:\windows\system32\wuaueng.dll + 2005-05-14 22:21 . 2005-05-04 18:45 2890240 c:\windows\system32\msi.dll - 2005-05-14 22:21 . 2005-03-21 20:00 2890240 c:\windows\system32\msi.dll + 2009-06-25 17:20 . 2009-06-25 17:20 1485176 c:\windows\system32\LegitCheckControl.DLL + 2005-05-14 22:22 . 2009-08-06 23:23 1929952 c:\windows\system32\dllcache\wuaueng.dll - 2005-05-14 22:21 . 2005-03-21 20:00 2890240 c:\windows\system32\dllcache\msi.dll + 2005-05-14 22:21 . 2005-05-04 18:45 2890240 c:\windows\system32\dllcache\msi.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-05 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMan"="SOUNDMAN.EXE" [2003-02-11 47104] "BluetoothAuthenticationAgent"="irprops.cpl" [2002-09-25 111104] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152] "ATT-SST_McciTrayApp"="c:\program files\ATT-SST\McciTrayApp.exe" [2009-10-22 1577984] "ISW.exe"="c:\program files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 2061816] "Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2009-11-10 443728] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040] "riwituziyo"="rifojehu.dll" [BU] c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls] expacapp REG_SZ c:\windows\System32\clipac32.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) "DisableNotifications"= 1 (0x1) S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [5/30/2007 10:51 PM 17920] S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [5/30/2007 10:51 PM 7680] S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [5/30/2007 10:50 PM 40832] S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [5/30/2007 10:51 PM 21632] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder 2005-06-15 c:\windows\Tasks\Symantec NetDetect.job - c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2003-07-08 23:04] . . ------- Supplementary Scan ------- . uStart Page = hxxp://swagbucks.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mStart Page = hxxp://www.yahoo.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\System32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 TCP: {D52ABD80-4988-4C7D-84BF-E2D39090D0E1} = 217.23.14.75,4.2.2.1,192.168.1.254 DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab DPF: {0A7469E8-9D33-4386-90A5-705E0E55C8F8} - hxxp://healthyschools.net/HRMx/hrmctl.cab FF - ProfilePath - c:\documents and settings\jessc0125\Application Data\Mozilla\Firefox\Profiles\epyp8tj7.Default User\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2260173&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Swag Bucks Customized Web Search FF - prefs.js: browser.startup.homepage - swagbucks.com FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2260173&q= FF - component: c:\documents and settings\jessc0125\Application Data\Mozilla\Firefox\Profiles\epyp8tj7.Default User\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll FF - component: c:\documents and settings\jessc0125\Application Data\Mozilla\Firefox\Profiles\epyp8tj7.Default User\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\FFExternalAlert.dll FF - component: c:\documents and settings\jessc0125\Application Data\Mozilla\Firefox\Profiles\epyp8tj7.Default User\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\RadioWMPCore.dll FF - plugin: c:\documents and settings\jessc0125\Application Data\Facebook\npfbplugin_1_0_3.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPcol308.dll ---- FIREFOX POLICIES ---- FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-04-08 08:58 Windows 5.1.2600 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(488) c:\windows\System32\ODBC32.dll - - - - - - - > 'lsass.exe'(544) c:\windows\System32\dssenh.dll . Completion time: 2010-04-08 09:01:02 ComboFix-quarantined-files.txt 2010-04-08 13:00 ComboFix2.txt 2010-04-07 13:00 ComboFix3.txt 2010-04-06 21:32 Pre-Run: 16,329,109,504 bytes free Post-Run: 16,300,204,032 bytes free - - End Of File - - BB22C62FA867852D9E5864A88DAABEDA