Here it is:
ComboFix 10-07-10.01 - R40 07/10/2010 15:23:26.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.145 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\R40\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FILE ::
"c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\jmc.dll"
"c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\msvcp71.dll"
"c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\msvcr71.dll"
"c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-333aa512-n\decora-d3d.dll"
"c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-333aa512-n\decora-sse.dll"
"c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\jmc.dll"
"c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\msvcp71.dll"
"c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\msvcr71.dll"
"c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3abf55e2-n\decora-d3d.dll"
"c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3abf55e2-n\decora-sse.dll"
"c:\progra~1\AVG\AVG8\avgemc.exe"
"c:\progra~1\AVG\AVG8\avgwdsvc.exe"
"c:\windows\system32\drivers\avgldx86.sys"
"c:\windows\system32\drivers\avgtdix.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\jmc.dll
c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\msvcp71.dll
c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-343e6c79-n\msvcr71.dll
c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-333aa512-n\decora-d3d.dll
c:\documents and settings\Guest\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-333aa512-n\decora-sse.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\jmc.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\msvcp71.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6c99deeb-n\msvcr71.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3abf55e2-n\decora-d3d.dll
c:\documents and settings\R40\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-3abf55e2-n\decora-sse.dll
c:\windows\system32\drivers\avgldx86.sys
c:\windows\system32\drivers\avgtdix.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_AVGLDX86
——-\Legacy_AVGTDIX
——-\Service_AvgLdx86
——-\Service_AvgTdiX
——-\Service_cerc6
——-\Legacy_avg8emc
——-\Legacy_avg8wd
——-\Service_avg8emc
——-\Service_avg8wd
((((((((((((((((((((((((( Files Created from 2010-06-10 to 2010-07-10 )))))))))))))))))))))))))))))))
.
2010-07-10 20:48 . 2009-08-07 02:23 215920 —-a-w- c:\windows\system32\muweb.dll
2010-07-10 20:48 . 2009-08-07 02:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-07-10 20:48 . 2010-07-10 20:48 ——– d—–w- c:\windows\LastGood.Tmp
2010-07-09 19:47 . 2010-07-09 19:47 ——– d—–w- c:\program files\Microsoft Silverlight
2010-07-09 18:57 . 2010-07-09 18:57 ——– d—–w- c:\documents and settings\All Users\Application Data\IObit
2010-07-09 18:57 . 2010-07-09 18:57 ——– d—–w- c:\program files\IObit
2010-07-09 18:06 . 2010-07-09 18:06 ——– d—–w- c:\documents and settings\R40\Application Data\Malwarebytes
2010-07-09 18:05 . 2010-04-29 22:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-09 18:05 . 2010-07-09 18:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-09 18:05 . 2010-07-10 18:15 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-09 18:05 . 2010-04-29 22:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-09 17:54 . 2010-07-09 17:54 ——– d—–w- c:\program files\CCleaner
2010-07-08 04:32 . 2010-07-08 04:32 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-07-07 21:28 . 2010-07-07 21:28 ——– d—–w- c:\program files\iPod
2010-07-07 21:27 . 2010-07-07 21:31 ——– d—–w- c:\program files\iTunes
2010-07-07 21:27 . 2010-07-07 21:31 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-07 21:20 . 2010-07-07 21:22 ——– d—–w- c:\program files\QuickTime
2010-07-07 21:12 . 2010-07-07 21:12 ——– d—–w- c:\program files\Bonjour
2010-07-07 21:09 . 2010-07-07 21:10 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\jcrcingip
2010-07-07 20:53 . 2010-07-07 20:53 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-04 16:49 . 2010-07-04 16:49 ——– d—–w- C:\spoolerlogs
2010-07-02 15:32 . 2010-07-02 15:32 ——– d–h–r- c:\documents and settings\R40\Application Data\SecuROM
2010-07-02 15:31 . 2010-07-02 15:31 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2010-07-01 22:57 . 2010-07-08 01:04 ——– d—–w- c:\program files\EA GAMES
2010-07-01 22:57 . 2007-04-04 22:39 442368 —-a-r- c:\windows\system32\vp6vfw.dll
2010-06-27 18:52 . 2010-06-27 18:52 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\HighAndes
2010-06-27 18:52 . 2010-06-27 18:52 ——– d—–w- c:\documents and settings\Guest\Application Data\HighAndes
2010-06-27 18:33 . 2010-06-27 22:29 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\WMTools Downloaded Files
2010-06-13 14:36 . 2010-06-13 14:36 ——– d—–w- c:\program files\Java
2010-06-13 14:20 . 2010-06-13 14:20 ——– d—–w- c:\program files\Common Files\Java
2010-06-13 14:10 . 2010-06-13 14:36 411368 —-a-w- c:\windows\system32\deployJava1.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-10 19:56 . 2008-04-14 12:00 36352 —-a-w- c:\windows\system32\drivers\intelppm.sys
2010-07-10 05:14 . 2010-02-20 19:40 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-07-09 18:03 . 2010-04-16 03:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-07 21:28 . 2010-01-06 04:20 ——– d—–w- c:\program files\Common Files\Apple
2010-07-07 20:49 . 2010-07-07 20:49 72504 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-07-02 00:05 . 2009-12-25 17:37 ——– d—–w- c:\documents and settings\R40\Application Data\Unity
2010-07-02 00:05 . 2009-12-25 16:56 ——– d—–w- c:\program files\Unity
2010-06-09 08:06 . 2010-06-09 08:06 976832 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13525\AdobeARM.exe
2010-06-09 08:06 . 2010-06-09 08:06 70584 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13525\AdobeExtractFiles.dll
2010-06-09 08:06 . 2010-06-09 08:06 331176 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13525\ReaderUpdater.exe
2010-06-09 08:06 . 2010-06-09 08:06 331176 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\13525\AcrobatUpdater.exe
2010-06-05 21:35 . 2010-06-05 21:35 ——– d—–w- c:\documents and settings\All Users\Application Data\PlayFirst
2010-06-05 21:34 . 2010-06-05 21:34 ——– d—–w- c:\documents and settings\R40\Application Data\PlayFirst
2010-06-05 21:32 . 2010-06-05 21:32 ——– d—–w- c:\program files\PlayFirst
2010-06-02 03:33 . 2010-06-02 03:33 ——– d—–w- c:\documents and settings\Guest\Application Data\SEGA
2010-05-31 18:17 . 2010-05-31 18:16 ——– d—–w- c:\program files\Canon Creative
2010-05-18 23:35 . 2010-05-18 23:35 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-05-18 23:35 . 2010-05-18 23:35 197920 —-a-w- c:\windows\system32\dnssdX.dll
2010-05-18 23:35 . 2010-05-18 23:35 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-05-15 17:16 . 2010-04-16 03:53 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-05-06 23:47 . 2010-05-06 23:47 355574 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_4030872FF57CBB7F004FA6.exe
2010-05-06 23:47 . 2010-05-06 23:47 7886 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_6FEFF9B68218417F98F549.exe
2010-05-06 23:47 . 2010-05-06 23:47 7886 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_21F3885A18D238E15AAE81.exe
2010-05-06 23:47 . 2010-05-06 23:47 355574 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_D707CE1C009F1381803C2C.exe
2010-05-06 23:47 . 2010-05-06 23:47 355574 -c–a-r- c:\documents and settings\R40\Application Data\Microsoft\Installer\{CAB81583-0310-43E1-8E33-0864985EDD67}\_27BA116C85EAB83CD5A215.exe
2010-05-06 10:41 . 2008-04-14 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2008-04-14 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2008-04-14 12:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-20 03:47 . 2010-03-06 15:16 3062048 —-a-w- c:\windows\system32\usbaaplrc.dll
2010-04-20 03:47 . 2010-03-06 15:16 41984 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2010-04-13 01:14 . 2010-02-23 23:27 664 -c–a-w- c:\documents and settings\Guest\Local Settings\Application Data\d3d9caps.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2003-06-27 88363]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-02-11 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-10-02 94208]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-12 1280344]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2002-11-7 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-21 21:11 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-06 04:45 28672 —-a-w- c:\windows\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-12-01 01:16 24576 —-a-w- c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2008-01-22 19:23 81920 ——w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 18:43 248040 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2003-06-24 19:33 561152 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
2003-06-24 19:34 126976 —-a-w- c:\program files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\konami\\Yu-Gi-Oh! ONLINE 3\\yo3.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [7/9/2010 11:57 AM 312152]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [4/15/2010 7:26 PM 93320]
R2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\NlsSrv32.exe [5/6/2010 4:47 PM 61440]
.
Contents of the 'Scheduled Tasks' folder
2010-04-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-04-16 19:22]
2010-04-15 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-04-16 19:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\R40\Application Data\Mozilla\Firefox\Profiles\vnz7idzn.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-07-10 15:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\000.fcl"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(900)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\tphklock.dll
- - - - - - - > 'explorer.exe'(4252)
c:\windows\system32\WININET.dll
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\S24EvMon.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\AGRSMMSG.exe
c:\program files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\windows\system32\rundll32.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\windows\system32\RegSrvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-07-10 15:42:00 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-10 22:41
ComboFix2.txt 2010-07-10 21:59
Pre-Run: 16,340,803,584 bytes free
Post-Run: 16,275,640,320 bytes free
- - End Of File - - 2737F4E9769DD2FD9C5003FFA3FD7A06