Here is ComboFix's log
ComboFix 10-05-02.02 - Owner 05/03/2010 1:45.2.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3583.3080 [GMT -7:00]
Running from: c:\downloads\ComboFix.exe
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\WindowsUpdate
C:\Thumbs.db
Infected copy of c:\windows\system32\drivers\serial.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((( Files Created from 2010-04-03 to 2010-05-03 )))))))))))))))))))))))))))))))
.
2010-05-02 17:33 . 2010-02-28 03:46 3691384 —-a-w- c:\documents and settings\Owner\Application Data\Simply Super Software\Trojan Remover\pcqE8.exe
2010-04-30 09:02 . 2010-04-30 09:03 ——– d—–w- C:\browser problems
2010-04-30 05:32 . 2010-04-30 05:32 ——– d-sh–w- c:\documents and settings\Owner\IECompatCache
2010-04-30 05:31 . 2010-04-30 05:31 ——– d-sh–w- c:\documents and settings\Owner\PrivacIE
2010-04-30 05:27 . 2010-04-30 05:27 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-04-30 05:17 . 2010-04-30 05:17 ——– d-sh–w- c:\documents and settings\Owner\IETldCache
2010-04-30 05:16 . 2010-04-30 05:16 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-04-30 05:13 . 2010-04-30 05:14 ——– dc-h–w- c:\windows\ie8
2010-04-30 04:14 . 2006-06-19 19:01 69632 —-a-w- c:\windows\system32\ztvcabinet.dll
2010-04-30 04:14 . 2006-05-25 21:52 162304 —-a-w- c:\windows\system32\ztvunrar36.dll
2010-04-30 04:14 . 2005-08-26 07:50 77312 —-a-w- c:\windows\system32\ztvunace26.dll
2010-04-30 04:14 . 2003-02-03 02:06 153088 —-a-w- c:\windows\system32\UNRAR3.dll
2010-04-30 04:14 . 2002-03-06 07:00 75264 —-a-w- c:\windows\system32\unacev2.dll
2010-04-30 04:14 . 2010-04-30 04:14 ——– d—–w- c:\program files\Trojan Remover
2010-04-30 04:14 . 2010-04-30 04:14 ——– d—–w- c:\documents and settings\Owner\Application Data\Simply Super Software
2010-04-30 04:14 . 2010-04-30 04:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Simply Super Software
2010-04-30 04:13 . 2010-04-30 04:13 6153352 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-04-30 02:02 . 2010-04-30 02:02 360584 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-04-30 02:02 . 2010-04-30 02:02 74760 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\UniversalDD.sys
2010-04-30 02:02 . 2010-04-30 02:02 28424 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2010-04-30 02:02 . 2010-04-30 02:02 25608 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\AVGIDSxx.sys
2010-04-30 02:02 . 2010-04-30 02:02 333192 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
2010-04-30 02:02 . 2010-04-30 02:02 30216 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\AVGIDSFilter.sys
2010-04-30 02:02 . 2010-04-30 02:02 25736 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\AVGIDSShim.sys
2010-04-30 02:02 . 2010-04-30 02:02 122376 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\AVGIDSDriver.sys
2010-04-30 02:02 . 2010-04-30 02:02 161800 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgrkx86.sys
2010-04-30 02:01 . 2010-04-30 02:01 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-04-28 22:45 . 2010-04-28 22:45 ——– d—–w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2010-04-28 22:45 . 2010-04-03 22:55 61440 —-a-w- c:\windows\system32\OpenCL.dll
2010-04-28 22:45 . 2010-04-03 22:55 11647592 —-a-w- c:\windows\system32\nvcompiler.dll
2010-04-28 22:44 . 2010-04-28 22:44 ——– d—–w- C:\NVIDIA
2010-04-28 22:38 . 2010-04-28 22:38 ——– d—–w- c:\program files\SystemRequirementsLab
2010-04-28 22:38 . 2010-04-28 22:38 290816 —-a-w- c:\documents and settings\Owner\Application Data\SystemRequirementsLab\SRLProxy_nvd_4.dll
2010-04-28 22:38 . 2010-04-28 22:38 290816 —-a-w- c:\documents and settings\Owner\Application Data\SystemRequirementsLab\SRLProxy_nvd_3.dll
2010-04-28 22:38 . 2010-04-28 22:38 290816 —-a-w- c:\documents and settings\Owner\Application Data\SystemRequirementsLab\SRLProxy_nvd_2.dll
2010-04-28 22:38 . 2010-04-28 22:38 290816 —-a-w- c:\documents and settings\Owner\Application Data\SystemRequirementsLab\SRLProxy_nvd_1.dll
2010-04-28 22:38 . 2010-04-28 22:38 ——– d—–w- c:\documents and settings\Owner\Application Data\SystemRequirementsLab
2010-04-27 08:41 . 2009-11-25 20:02 1230080 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-04-25 15:38 . 2010-04-29 02:26 ——– d—–w- c:\program files\Steam
2010-04-24 04:55 . 2010-04-24 04:55 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\AVG Security Toolbar
2010-04-24 04:47 . 2010-04-30 01:50 613656 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2010-04-24 04:47 . 2010-04-30 01:50 800536 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avginet.dll
2010-04-24 04:37 . 2010-04-27 08:41 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-04-23 20:27 . 2010-04-23 20:27 ——– d—–w- c:\windows\system32\NtmsData
2010-04-23 08:25 . 2010-04-23 08:25 ——– d—–w- c:\program files\ESET
2010-04-23 07:09 . 2010-04-23 07:09 ——– d-s—w- c:\documents and settings\LocalService\UserData
2010-04-23 04:18 . 2010-04-23 04:18 ——– d—–w- c:\windows\system32\wbem\Repository
2010-04-22 07:27 . 2010-04-22 07:27 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-04-22 07:27 . 2010-04-29 22:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-22 07:27 . 2010-04-30 04:13 ——– d—–w- C:\Malwarebytes' Anti-Malware
2010-04-22 07:27 . 2010-04-29 22:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-22 07:27 . 2010-04-22 07:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-22 05:26 . 2010-04-22 05:29 ——– d—–w- C:\Combat Arms hack pics
2010-04-21 07:37 . 2010-04-21 07:37 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Identities
2010-04-21 06:20 . 2010-04-21 06:20 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-04-21 06:20 . 2010-04-28 09:51 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-21 03:54 . 2010-04-21 03:54 ——– d-sh–w- c:\documents and settings\NetworkService\UserData
2010-04-19 21:37 . 2010-04-19 21:40 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\spbirtcrr
2010-04-19 16:55 . 2010-04-30 01:50 1658136 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-04-17 18:53 . 2010-04-17 18:53 ——– d—–w- C:\.jagex_cache_32
2010-04-16 20:26 . 2010-04-16 20:26 41872 —-a-w- c:\windows\system32\xfcodec.dll
2010-04-11 10:10 . 2010-04-11 10:10 ——– d—–w- c:\documents and settings\Owner\Application Data\Unity
2010-04-11 10:08 . 2010-04-11 10:08 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Unity
2010-04-05 23:48 . 2010-04-05 23:54 ——– d—–w- c:\documents and settings\Owner\Application Data\TeamViewer
2010-04-05 23:47 . 2010-04-28 07:36 ——– d—–w- c:\program files\TeamViewer
2010-04-05 04:44 . 2010-04-29 00:19 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\ArmA
2010-04-05 03:31 . 2010-04-05 03:38 ——– d—–w- c:\program files\Reimage
2010-04-05 02:52 . 2010-04-05 02:52 ——– d—–w- C:\ARMAUpdate_1_14
2010-04-05 02:21 . 2010-04-05 02:21 ——– d—–w- C:\Nsasoft
2010-04-05 02:08 . 2010-04-05 02:08 ——– d—–w- C:\keyfinder.2.0.1
2010-04-04 03:55 . 2010-04-04 03:55 ——– d—–w- c:\documents and settings\Owner\Application Data\ArmA II Launcher
2010-04-04 03:55 . 2010-03-31 22:36 1835198 —-a-w- C:\ArmA II Launcher.exe
2010-04-04 02:23 . 2010-04-04 02:23 278120 —-a-w- c:\windows\system32\nvmccs.dll
2010-04-04 02:23 . 2010-04-04 02:23 154216 —-a-w- c:\windows\system32\nvsvc32.exe
2010-04-04 02:23 . 2010-04-04 02:23 145000 —-a-w- c:\windows\system32\nvcolor.exe
2010-04-04 02:23 . 2010-04-04 02:23 13670504 —-a-w- c:\windows\system32\nvcpl.dll
2010-04-04 02:23 . 2010-04-04 02:23 110696 —-a-w- c:\windows\system32\nvmctray.dll
2010-04-04 02:22 . 2010-04-04 02:22 81920 —-a-w- c:\windows\system32\nvwddi.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-03 08:33 . 2009-01-26 08:06 ——– d—–w- c:\documents and settings\Owner\Application Data\Skype
2010-05-03 05:08 . 2008-12-09 06:30 36496 -c–a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-03 04:20 . 2009-01-26 08:08 ——– d—–w- c:\documents and settings\Owner\Application Data\skypePM
2010-05-03 04:13 . 2009-11-28 05:35 0 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\prvlcl.dat
2010-05-03 01:39 . 2008-04-14 12:00 64512 —-a-w- c:\windows\system32\drivers\serial.sys
2010-05-02 17:34 . 2009-10-27 08:39 ——– d—a-w- c:\documents and settings\All Users\Application Data\Temp
2010-05-02 16:29 . 2009-10-27 08:41 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-04-30 02:01 . 2008-12-09 07:40 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-30 02:01 . 2008-12-09 07:40 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-04-30 02:01 . 2009-10-27 08:42 25096 —-a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-04-30 02:01 . 2008-12-09 07:40 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-30 02:01 . 2008-12-09 07:40 52872 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-04-30 01:50 . 2010-04-07 15:57 1007896 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2010-04-28 22:46 . 2009-12-23 16:16 ——– d—–w- c:\program files\AGEIA Technologies
2010-04-28 09:50 . 2009-07-22 08:19 1324 —-a-w- c:\windows\system32\d3d9caps.dat
2010-04-28 07:33 . 2010-01-15 00:06 ——– d—–w- c:\documents and settings\LocalService\Application Data\GameTracker
2010-04-25 01:13 . 2010-01-27 05:43 ——– d—–w- c:\program files\Microsoft
2010-04-24 19:41 . 2009-07-01 05:47 ——– d—–w- c:\documents and settings\Owner\Application Data\Xfire
2010-04-24 18:07 . 2009-04-26 21:55 138664 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-04-24 18:07 . 2009-04-26 21:54 214864 —-a-w- c:\windows\system32\PnkBstrB.exe
2010-04-23 20:31 . 2008-12-10 13:14 765952 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMDll.dll
2010-04-23 20:27 . 2008-12-12 19:45 ——– d—–w- c:\program files\HP
2010-04-23 20:24 . 2008-12-09 05:46 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-23 14:08 . 2009-12-01 23:44 ——– d—–w- c:\program files\spamGamevance
2010-04-22 23:49 . 2009-09-15 22:59 ——– d—–w- c:\program files\LucasArts
2010-04-21 22:48 . 2009-04-26 21:54 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2010-04-18 18:13 . 2010-03-26 04:12 ——– d—–w- c:\documents and settings\All Users\Application Data\ArcSoft
2010-04-18 18:13 . 2010-03-26 04:11 ——– d—–w- c:\documents and settings\Owner\Application Data\ArcSoft
2010-04-18 18:13 . 2009-09-11 00:30 75 -c–a-w- c:\documents and settings\Owner\jagex_runescape_preferences2.dat
2010-04-18 18:13 . 2009-01-25 21:23 41 -c–a-w- c:\documents and settings\Owner\jagex_runescape_preferences.dat
2010-04-12 15:47 . 2009-04-18 18:29 ——– d—–w- c:\documents and settings\Owner\Application Data\Canon
2010-04-11 19:33 . 2010-02-10 06:07 50354 —-a-w- c:\documents and settings\Owner\Application Data\Facebook\uninstall.exe
2010-04-11 19:33 . 2010-02-10 06:07 ——– d—–w- c:\documents and settings\Owner\Application Data\Facebook
2010-04-10 12:23 . 2008-12-10 14:09 ——– d—–w- c:\program files\Google
2010-04-06 22:21 . 2009-01-12 09:03 65 -c–a-w- c:\windows\popcinfot.dat
2010-04-03 22:55 . 2009-07-20 15:58 4075520 —-a-w- c:\windows\system32\nvcuda.dll
2010-04-03 22:55 . 2009-07-20 15:58 2646632 —-a-w- c:\windows\system32\nvcuvenc.dll
2010-04-03 22:55 . 2009-07-20 15:58 2183470 —-a-w- c:\windows\system32\nvdata.bin
2010-04-03 22:55 . 2009-07-20 15:58 2030184 —-a-w- c:\windows\system32\nvcuvid.dll
2010-04-03 22:55 . 2008-12-09 05:41 600680 -c–a-w- c:\windows\system32\nvudisp.exe
2010-04-03 22:55 . 2008-02-25 04:29 6432128 —-a-w- c:\windows\system32\nv4_disp.dll
2010-04-03 22:55 . 2008-02-25 04:29 227944 —-a-w- c:\windows\system32\nvcodins.dll
2010-04-03 22:55 . 2008-02-25 04:29 227944 —-a-w- c:\windows\system32\nvcod.dll
2010-04-03 22:55 . 2008-02-25 04:29 14757888 —-a-w- c:\windows\system32\nvoglnt.dll
2010-04-03 22:55 . 2008-02-25 04:29 1097728 —-a-w- c:\windows\system32\nvapi.dll
2010-04-03 22:55 . 2008-02-25 04:29 10232128 —-a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-04-02 23:54 . 2008-12-09 05:39 600680 —-a-w- c:\windows\system32\NVUNINST.EXE
2010-04-01 04:53 . 2010-04-01 04:53 33824 —-a-w- c:\windows\system32\drivers\oreans32.sys
2010-03-31 08:07 . 2010-03-31 08:07 ——– d—–w- c:\documents and settings\All Users\Application Data\PCPitstop
2010-03-31 07:39 . 2010-03-31 07:39 ——– d—–w- c:\documents and settings\All Users\Application Data\PassMark
2010-03-27 06:15 . 2010-01-15 00:06 ——– d—–w- c:\documents and settings\Owner\Application Data\GameTracker
2010-03-26 07:34 . 2010-01-28 01:06 ——– d—–w- c:\program files\Common Files\Adobe
2010-03-26 04:21 . 2010-03-26 04:12 ——– d—–w- c:\program files\ArcSoft
2010-03-26 04:14 . 2010-03-26 04:11 ——– d—–w- c:\program files\Common Files\ArcSoft
2010-03-25 16:18 . 2010-03-25 16:18 ——– d—–w- c:\program files\Common Files\Skype
2010-03-24 17:21 . 2010-03-24 17:21 0 —-a-w- c:\documents and settings\Owner\jagex__preferences3.dat
2010-03-24 00:26 . 2010-03-24 00:26 ——– d—–w- c:\documents and settings\Owner\Application Data\Down Under Woot woot
2010-03-11 14:39 . 2008-12-14 04:57 ——– d—–w- c:\program files\RegCure
2010-03-11 09:17 . 2010-03-11 09:17 25088 —-a-w- c:\windows\system32\drivers\teamviewervpn.sys
2010-03-06 05:30 . 2010-03-06 05:30 5582848 —-a-w- c:\documents and settings\Owner\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-03-03 01:14 . 2009-08-09 02:21 444952 —-a-w- c:\windows\system32\wrap_oal.dll
2010-03-03 01:14 . 2009-08-09 02:21 109080 —-a-w- c:\windows\system32\OpenAL32.dll
2010-02-27 16:41 . 2010-02-27 16:39 352 —-a-w- c:\documents and settings\All Users\Application Data\MecSoft Corporation\AlibreCAM 2.0\WinAC200prdlc.dll
2010-02-24 13:11 . 2008-04-14 12:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-24 05:35 . 2010-02-24 05:35 14846 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{857CBF4A-192C-44B0-86A5-6281FCEFA1FE}\FileOpenNew.exe
2010-02-16 14:08 . 2008-04-14 12:00 2146304 ——w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2008-04-14 00:01 2024448 ——w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2008-04-14 12:00 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 20:31 . 2010-02-12 07:30 210432 —-a-w- c:\documents and settings\Owner\Application Data\ArmA II Launcher\gslist.exe
2010-02-11 12:02 . 2008-04-14 12:00 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 -c–a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 -c–a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 20:02 1230080 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2009-10-08 818288]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-10 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-10-28 17331200]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-04-04 110696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-04-04 13670504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
"WUAppSetup"="c:\program files\Common Files\logishrd\WUApp32.exe" [2007-02-03 430080]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Wireless Configuration Utility.lnk - c:\program files\TRENDnet\TEW-641PC_TEW-643PI\WlanCU.exe [2009-12-23 344064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-04-30 02:01 12464 —-a-w- c:\windows\system32\avgrsstx.dll
path=
backup=
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Xfire.lnk]
backup=c:\windows\pss\Xfire.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiveUpdate
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-04 05:42 36272 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-06-19 08:20 57344 —-a-w- c:\windows\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-04-30 02:01 2064736 —-a-w- c:\progra~1\AVG\AVG9\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-06-01 18:21 153136 -c–a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2007-09-14 01:50 1603152 —-a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2007-10-26 01:10 652624 —-a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 21:39 1289000 —-a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2004-09-13 23:49 49152 -c–a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IJNetworkScanUtility]
2007-05-21 08:37 124512 —-a-w- c:\program files\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-13 00:33 141600 —-a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-07-19 01:55 451872 -c–a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2002-07-16 20:21 28672 -c–a-w- c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 13:42 1695232 ——w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 23:57 153136 -c–a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2010-04-04 02:23 13670504 —-a-w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2010-04-04 02:23 110696 —-a-w- c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
2007-06-13 17:39 73728 -c–a-w- c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 07:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-10-28 09:18 17331200 —-a-w- c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2010-03-09 18:49 26100520 —-a-r- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
2006-10-25 16:03 210472 -c–a-w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2008-01-21 20:17 61440 -c–a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2010-04-26 23:27 1238352 —-a-w- c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-03-09 12:19 148888 -c–a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-12-10 14:09 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"gusvc"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"TapiSrv"=3 (0x3)
"LightScribeService"=2 (0x2)
"IJPLMSVC"=2 (0x2)
"IDriverT"=3 (0x3)
"ATI Smart"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"npggsvc"=3 (0x3)
"gupdate1c9e872c7752ed2"=2 (0x2)
"SCardSvr"=3 (0x3)
"AVGIDSAgent"=2 (0x2)
"avgfws9"=2 (0x2)
"avg9wd"=2 (0x2)
"avg9emc"=2 (0x2)
"TeamViewer5"=2 (0x2)
"SeaPort"=2 (0x2)
"Pml Driver HPZ12"=2 (0x2)
"NBService"=3 (0x3)
"ClipSrv"=3 (0x3)
"nSvcIp"=2 (0x2)
"NMIndexingService"=3 (0x3)
"idsvc"=3 (0x3)
"GS In-Game Service"=2 (0x2)
"ForceWare Intelligent Application Manager (IAM)"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"ACDaemon"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Battlefield 2142 Deluxe Edition\\BF2142.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Age of Empires III\\age3x.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Battlefield 2\\BF2.exe"=
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War Forces of Corruption\\swfoc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Atari\\ArmA\\arma.exe"=
"c:\\Atari\\ArmA\\arma_server.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57676:TCP"= 57676:TCP:Pando Media Booster
"57676:UDP"= 57676:UDP:Pando Media Booster
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [10/27/2009 1:42 AM 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [12/9/2008 12:40 AM 52872]
R0 sonyhcb;Sony Digital Imaging Base;c:\windows\system32\drivers\sonyhcb.sys [2/8/2009 1:17 AM 6097]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/9/2008 12:40 AM 216200]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/9/2008 12:40 AM 242896]
R1 oreans32;oreans32;c:\windows\system32\drivers\oreans32.sys [3/31/2010 9:53 PM 33824]
R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [4/29/2010 7:01 PM 916760]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [4/29/2010 7:01 PM 308064]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [4/29/2010 7:01 PM 2325816]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [12/23/2009 10:05 AM 38144]
R2 WLNdis50;WLan NDIS 5.0 I/O Control;c:\windows\system32\drivers\WLNdis50.sys [12/23/2009 10:05 AM 20480]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [12/9/2008 12:40 AM 30104]
R3 Mach3;Mach3 Pulseing Service;c:\windows\system32\drivers\Mach3.sys [5/9/2007 7:26 PM 109856]
R3 RTL819xp;Realtek RTL8190\RTL8192E 802.11n Wireless LAN (Mini-)PCI NIC NT Driver;c:\windows\system32\drivers\rtl819xp.sys [12/7/2009 11:07 AM 521856]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [12/9/2008 12:40 AM 30104]
S3 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [4/29/2010 7:01 PM 5888008]
S3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [4/23/2010 9:40 PM 122376]
S3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [10/27/2009 1:41 AM 30216]
S3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [10/27/2009 1:41 AM 26120]
S3 cpuz130;cpuz130;\??\c:\docume~1\Owner\LOCALS~1\Temp\cpuz130\cpuz_x32.sys –> c:\docume~1\Owner\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [12/9/2008 12:05 AM 175872]
S3 sonyhcs;Sony Digital Imaging Video;c:\windows\system32\drivers\sonyhcs.sys [2/8/2009 1:17 AM 299923]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys [3/11/2010 2:17 AM 25088]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [6/7/2009 3:02 PM 25704]
S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [1/21/2010 8:12 PM 25704]
S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [1/21/2010 8:12 PM 25704]
S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [1/21/2010 8:12 PM 25704]
S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [1/21/2010 8:12 PM 25704]
S4 GS In-Game Service;GS In-Game Service;c:\atari\ArmA\GameTracker\GSInGameService.exe [1/14/2010 5:06 PM 1643872]
S4 gupdate1c9e872c7752ed2;Google Update Service (gupdate1c9e872c7752ed2);c:\program files\Google\Update\GoogleUpdate.exe [6/8/2009 12:53 PM 133104]
S4 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-07-19 01:53 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-04-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
2010-05-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-08 19:53]
2010-05-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-08 19:53]
2010-05-03 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2010-02-23 23:20]
2009-08-25 c:\windows\Tasks\RegCure Startup.job
- c:\program files\RegCure\RegCure.exe [2010-02-23 23:20]
2010-05-02 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2010-02-23 23:20]
2010-05-03 c:\windows\Tasks\User_Feed_Synchronization-{B11DC94C-FC32-41C0-8CBD-5411DC48E10A}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.ebay.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Read EXIF - c:\program files\ArcSoft\RAW Thumbnail Viewer\ArcEXIFM.htm
LSP: %SYSTEMROOT%\system32\nvLsp.dll
TCP: {818D6D19-1E5F-4D4E-B4E2-E94F07CD6866} = 209.237.84.13,209.237.84.14
DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} - hxxp://216.105.79.223:5000/VatDec.cab
DPF: {495DEA80-49C2-4891-94CD-C2016615D16F} - hxxp://www.catalogds.com/dtd/pvcadview.cab
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\bx3hhr5a.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.ebay.com/
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\ArcSoft\RAW Thumbnail Viewer\FireFox Extension\components\FirefoxMenu.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\divx\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: c:\divx\DivX Web Player\npdivx32.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Owner\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMFireLauncher.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Messenger (Yahoo!) - c:\program files\Yahoo!\Messenger\YahooMessenger.exe
MSConfigStartUp-Microsoft Default Manager - c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe
MSConfigStartUp-MSN Toolbar - c:\program files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe
MSConfigStartUp-nwiz - nwiz.exe
AddRemove-Yahoo! Messenger - c:\progra~1\Yahoo!\MESSEN~1\UNWISE.EXE
AddRemove-Yahoo! Toolbar - c:\progra~1\Yahoo!\Common\UNYT_W~1.EXE
AddRemove-UnityWebPlayer - c:\documents and settings\Owner\Local Settings\Application Data\Unity\WebPlayer\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-03 01:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-57989841-1580818891-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-57989841-1580818891-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:d7,a0,25,49,aa,b7,47,1b,8d,a9,06,75,c6,37,16,d7,8d,5f,94,e5,d3,44,6b,
da,cf,b3,2a,34,a5,5a,ce,18,7c,ca,f6,a7,8c,be,ea,65,b1,c8,5a,9b,b0,8a,ac,67,\
"??"=hex:38,75,d6,96,1b,f0,33,56,98,85,93,1b,de,32,4b,f4
[HKEY_USERS\S-1-5-21-57989841-1580818891-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:7f,14,1d,86,1e,18,ba,57,a7,10,e1,0b,2b,ec,1e,35,90,fd,6e,70,de,
fd,e9,58,6b,e5,69,65,89,7c,a1,bf,be,95,3a,1f,f2,10,35,ea,48,ec,28,bd,37,03,\
"rkeysecu"=hex:17,0c,8b,a8,75,cb,05,56,56,b0,06,85,72,9c,ba,40
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1276)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(1332)
c:\windows\system32\nvLsp.dll
.
Completion time: 2010-05-03 01:53:29
ComboFix-quarantined-files.txt 2010-05-03 08:53
ComboFix2.txt 2009-12-23 17:56
Pre-Run: 348,729,344,000 bytes free
Post-Run: 351,069,097,984 bytes free
- - End Of File - - EB8E245743E5C68BBB7E91AE9705214D

No problems encountered during Combo's run.

Not sure yet if the viruses are still there. I will let you know.