ComboFix 10-04-18.04 - Becci 19/04/2010 14:14:00.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.1917.1151 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\hyjpqtr.sys
.
—- Previous Run ——-
.
c:\$recycle.bin\S-1-5-21-1328440706-3271999302-2197091657-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-725377992-1576560995-444256179-500
c:\program files\Search Settings
c:\program files\Search Settings\SearchSettings.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_hyjpqtr
——-\Service_hyjpqtr
((((((((((((((((((((((((( Files Created from 2010-03-19 to 2010-04-19 )))))))))))))))))))))))))))))))
.
2010-04-19 13:27 . 2010-04-19 13:27 ——– d—–w- c:\users\Guest\AppData\Local\temp
2010-04-19 13:27 . 2010-04-19 13:27 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-04-17 09:59 . 2010-04-17 09:59 ——– d-sh–w- c:\windows\system32\%APPDATA%
2010-04-17 09:20 . 2010-04-17 19:13 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-04-17 09:20 . 2010-04-17 09:54 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-04-17 01:14 . 2010-04-17 01:14 ——– d—–w- c:\users\Becci\AppData\Roaming\CheckPoint
2010-04-17 01:13 . 2010-04-17 01:13 ——– d—–w- c:\program files\CheckPoint
2010-04-17 01:13 . 2009-11-22 14:42 69000 —-a-w- c:\windows\system32\zlcomm.dll
2010-04-17 01:13 . 2009-11-22 14:42 103816 —-a-w- c:\windows\system32\zlcommdb.dll
2010-04-17 01:13 . 2009-11-22 14:42 1238408 —-a-w- c:\windows\system32\zpeng25.dll
2010-04-17 01:12 . 2009-11-22 14:44 446664 —-a-w- c:\windows\system32\drivers\vsdatant.sys
2010-04-17 01:12 . 2010-04-17 01:13 ——– d—–w- c:\windows\system32\ZoneLabs
2010-04-17 01:12 . 2010-04-17 01:12 ——– d—–w- c:\program files\Zone Labs
2010-04-17 01:11 . 2010-04-17 01:11 ——– d—–w- c:\programdata\CheckPoint
2010-04-17 01:11 . 2010-04-19 13:31 ——– d—–w- c:\windows\Internet Logs
2010-04-16 21:42 . 2010-04-16 21:52 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-04-16 21:22 . 2010-03-29 23:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-16 21:22 . 2010-03-29 23:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-16 21:22 . 2010-04-16 21:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-16 21:06 . 2010-04-16 21:06 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-04-16 21:06 . 2010-04-16 21:06 242696 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-16 21:06 . 2010-04-16 21:06 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-16 21:06 . 2010-04-16 21:06 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-04-16 21:06 . 2010-04-19 07:31 ——– d—–w- c:\windows\system32\drivers\Avg
2010-04-16 19:43 . 2010-04-16 19:45 207 –s-a-w- c:\users\Becci\AppData\Local\546284047.dat
2010-04-16 19:42 . 2010-04-17 19:28 ——– d—–w- c:\users\Becci\AppData\Roaming\810B2EE900A9C119620FA311C28C2B26
2010-04-13 21:49 . 2010-02-23 11:10 79360 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-13 21:49 . 2010-02-23 11:10 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-13 21:49 . 2010-02-23 11:10 106496 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-13 21:49 . 2010-02-18 14:07 3548040 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-04-13 21:49 . 2010-02-18 14:07 3600776 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-13 21:48 . 2010-03-05 14:01 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-04-13 21:48 . 2010-02-18 14:07 904576 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-13 21:48 . 2010-02-18 13:30 200704 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-04-13 21:48 . 2010-02-18 11:28 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-13 21:46 . 2009-12-23 11:33 172032 —-a-w- c:\windows\system32\wintrust.dll
2010-04-13 21:46 . 2010-01-13 17:34 98304 —-a-w- c:\windows\system32\cabview.dll
2010-03-24 13:12 . 2010-03-24 13:12 ——– d—–w- C:\$AVG
2010-03-22 22:02 . 2009-05-18 14:17 26600 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-03-22 22:02 . 2008-04-17 13:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2010-03-22 22:00 . 2010-03-22 22:00 ——– d—–w- c:\program files\iPod
2010-03-22 21:59 . 2010-03-22 22:02 ——– d—–w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-03-22 21:54 . 2010-03-22 21:54 ——– d—–w- c:\program files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-19 13:28 . 2007-12-25 17:35 12 —-a-w- c:\windows\bthservsdp.dat
2010-04-18 20:50 . 2009-08-11 12:17 ——– d—–w- c:\users\Becci\AppData\Roaming\Spotify
2010-04-18 17:04 . 2010-04-18 17:04 784136 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-04-17 23:04 . 2009-09-17 17:20 ——– d—–w- c:\program files\Wimba
2010-04-17 22:18 . 2007-05-29 16:04 ——– d—–w- c:\program files\myphotobook
2010-04-17 20:00 . 2009-03-25 16:28 ——– d—–w- c:\program files\SpywareGuard
2010-04-17 01:20 . 2010-03-14 18:56 ——– d—–w- c:\programdata\avg9
2010-04-17 01:15 . 2010-04-17 01:12 422437 —ha-w- c:\windows\system32\drivers\vsconfig.xml
2010-04-16 23:08 . 2008-08-23 22:12 ——– d—–w- c:\program files\CCleaner
2010-04-16 21:44 . 2007-05-29 14:48 ——– d—–w- c:\program files\Common Files\Java
2010-04-16 21:42 . 2007-05-29 14:48 ——– d—–w- c:\program files\Java
2010-04-16 09:47 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-04-13 22:47 . 2007-06-04 11:38 ——– d—–w- c:\programdata\Microsoft Help
2010-04-09 11:52 . 2009-04-12 12:39 ——– d—–w- c:\users\Becci\AppData\Roaming\foobar2000
2010-03-26 14:26 . 2007-09-23 18:49 ——– d—–w- c:\users\Becci\AppData\Roaming\Apple Computer
2010-03-24 12:44 . 2009-03-07 22:09 ——– d—–w- c:\program files\Opera
2010-03-22 22:00 . 2007-09-23 18:44 ——– d—–w- c:\program files\Common Files\Apple
2010-03-22 21:41 . 2010-03-22 21:41 72488 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-03-20 21:49 . 2008-12-25 12:38 ——– d—–w- c:\users\Becci\AppData\Roaming\Teleca
2010-03-20 21:48 . 2008-12-25 11:33 ——– d—–w- c:\program files\Common Files\Teleca Shared
2010-03-17 10:47 . 2010-03-17 10:47 ——– d—–w- c:\users\Becci\AppData\Roaming\AVG9
2010-03-15 01:26 . 2010-03-15 01:26 ——– d—–w- c:\users\Guest\AppData\Roaming\Skype
2010-03-15 01:18 . 2009-10-26 16:17 84064 —-a-w- c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-14 19:16 . 2007-05-29 15:52 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-03-14 19:16 . 2007-05-29 15:52 ——– d—–w- c:\programdata\Symantec
2010-03-14 18:57 . 2010-03-14 18:57 ——– d—–w- c:\program files\AVG
2010-03-14 18:32 . 2010-03-14 18:15 ——– d—–w- c:\programdata\COMODO
2010-03-14 17:39 . 2010-03-14 17:31 ——– d—–w- c:\programdata\Comodo Downloader
2010-03-14 17:05 . 2009-12-09 20:30 ——– d—–w- c:\programdata\Norton
2010-03-06 11:02 . 2007-08-24 19:32 ——– d—–w- c:\program files\Google
2010-02-25 16:01 . 2007-08-24 17:36 84064 —-a-w- c:\users\Becci\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 09:16 . 2009-10-03 15:22 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-02-23 06:39 . 2010-04-01 10:30 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-04-01 10:30 109056 —-a-w- c:\windows\system32\iesysprep.dll
2010-02-23 06:33 . 2010-04-01 10:30 71680 —-a-w- c:\windows\system32\iesetup.dll
2010-02-23 04:55 . 2010-04-01 10:30 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:06 . 2010-03-10 13:45 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-10 13:45 30720 —-a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-10 13:45 411648 —-a-w- c:\windows\system32\drivers\http.sys
2010-02-12 10:32 . 2010-03-16 20:48 293376 —-a-w- c:\windows\system32\browserchoice.exe
2010-02-10 11:27 . 2010-02-10 11:27 680 —-a-w- c:\users\Guest\AppData\Local\d3d9caps.dat
2010-01-25 12:00 . 2010-02-24 16:52 471552 —-a-w- c:\windows\system32\secproc_isv.dll
2010-01-25 12:00 . 2010-02-24 16:52 152576 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 12:00 . 2010-02-24 16:52 152064 —-a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:00 . 2010-02-24 16:52 471552 —-a-w- c:\windows\system32\secproc.dll
2010-01-25 11:58 . 2010-02-24 16:51 332288 —-a-w- c:\windows\system32\msdrm.dll
2010-01-25 08:21 . 2010-02-24 16:52 526336 —-a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-25 08:21 . 2010-02-24 16:52 346624 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 08:21 . 2010-02-24 16:52 518144 —-a-w- c:\windows\system32\RMActivate.exe
2010-01-25 08:21 . 2010-02-24 16:52 347136 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-23 09:26 . 2010-02-24 16:51 2048 —-a-w- c:\windows\system32\tzres.dll
2009-04-07 08:30 . 2009-05-28 16:42 1839 —-a-w- c:\program files\Windows Live Messenger .lnk
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\opera\program\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\opera\program\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{474597C5-AB09-49d6-A4D5-2E8D7341384E}]
2008-09-02 14:04 398768 —-a-w- c:\program files\iMesh Applications\iMesh MediaBar\iMeshIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2008-10-01 07:40 192960 ——w- c:\program files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-25 4444160]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-05-23 509496]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-06 34352]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-22 438272]
"NDSTray.exe"="c:\program files\TOSHIBA\ConfigFree\NDSTray.exe" [2006-11-14 1372160]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-04-02 577536]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2007-05-04 571024]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-07-27 204800]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-11-22 1037192]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2009-10-14 730480]
c:\users\Becci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 —-a-w- c:\program files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-19 07:33 202240 —-a-w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(

:90,79,19,06,49,35,ca,01
R0 hyjpqtr;hyjpqtr; [x]
R2 gupdate1c9614180b8900;Google Update Service (gupdate1c9614180b8900);c:\program files\Google\Update\GoogleUpdate.exe [2008-12-18 133104]
R3 TpChoice;Touch Pad Detection Filter driver;c:\windows\system32\DRIVERS\TpChoice.sys [x]
R3 vsdatant7;vsdatant7;c:\windows\system32\drivers\vsdatant.win7.sys [x]
R4 CplIR;Embedded IR Driver;c:\windows\system32\DRIVERS\CplIR.SYS [2007-03-06 14848]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2010-04-16 216200]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2010-04-16 242696]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-04-16 916760]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-04-16 308064]
S2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2008-10-28 156968]
S2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [2009-10-14 25208]
S2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\IswSvc.exe [2009-10-14 476528]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-04-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-18 18:46]
2010-04-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-18 18:46]
2010-04-19 c:\windows\Tasks\User_Feed_Synchronization-{98B4D3FA-96AD-4C4C-8323-3134BF644091}.job
- c:\windows\system32\msfeedssync.exe [2010-04-01 04:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.facebook.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Save YouTube Video as MP3 - c:\program files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/710-44557-9400-3/4
IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} -
http://www.amazon.co.uk/exec/obidos/redire…1&site;=home
TCP: {7F7FF71C-9324-4B28-A9A7-1A7AC1CAE9D8} = 192.168.0.1
FF - ProfilePath - c:\users\Becci\AppData\Roaming\Mozilla\Firefox\Profiles\ofo4zr6x.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - prefs.js: keyword.URL - hxxp://www.sicto.com/search/?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&rls;=byWFBQnW&q;=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\CheckPoint\ZAForceField\TrustChecker\components\TrustCheckerMozillaPlugin.dll
FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff36\gears.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Becci\Music\Mozilla Plugins\npitunes.dll
FF - plugin: c:\users\Becci\Program Files\DNA\plugins\npbtdna.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: keyword.URL - hxxp://www.sicto.com/search/?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&rls;=byWFBQnW&q;=
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-19 14:31
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'lsass.exe'(668)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
- - - - - - - > 'Explorer.exe'(1768)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTJBNS2.dll
c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTIntrfc.dll
c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\CTConfig.DLL
c:\program files\Creative\Creative Zen Micro\Zen Micro Media Explorer\JBNSRES.DLL
.
———————— Other Running Processes ————————
.
c:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\windows\system32\TODDSrv.exe
c:\program files\TOSHIBA\Power Saver\TosCoSrv.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\RtHDVCpl.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Synaptics\SynTP\SynToshiba.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\SpywareGuard\sgbhp.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2010-04-19 14:44:38 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-19 13:44
Pre-Run: 16,573,919,232 bytes free
Post-Run: 16,265,617,408 bytes free
- - End Of File - - 2B2114AFC38DFD4E035560E68278F3D0