I had to rename the exe to get it to run but It worked in the end, here's the log:
ComboFix 09-08-02.04 - Hapgood 2007 03/08/2009 17:51.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1022.631 [GMT 1:00]
Running from: c:\documents and settings\Hapgood 2007\Desktop\mnm.exe
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-2613712753-1050240633-3494479008-500
c:\recycler\S-1-5-21-3353877780-138415203-3492020910-500
c:\windows\Installer\WMEncoder.msi
c:\windows\kb913800.exe
c:\windows\run.log
c:\windows\system32\_000024_.tmp.dll
c:\windows\system32\_000025_.tmp.dll
c:\windows\system32\_000026_.tmp.dll
c:\windows\system32\_000027_.tmp.dll
c:\windows\system32\drivers\UACpkkjbaiftl.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\UACaayijiiske.dll
c:\windows\system32\UACcvxmxeyxbi.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UAClxfmqpuxvy.log
c:\windows\system32\UACnjmmqswrcg.dll
c:\windows\system32\UACnvvrgkgobh.dll
c:\windows\system32\UACvlvpxnkdla.dll
c:\windows\system32\UACyevjlqpmyb.db
c:\windows\system32\UACynskaoettk.dat
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-07-03 to 2009-08-03 )))))))))))))))))))))))))))))))
.
2009-08-02 23:25 . 2009-08-02 23:25 -------- d-----w- c:\program files\Trend Micro
2009-08-02 22:13 . 2009-07-03 14:49 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-08-02 21:59 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-02 21:57 . 2009-08-02 21:57 -------- dc-h--w- c:\docume~1\ALLUSE~1\APPLIC~1\{EF63305C-BAD7-4144-9208-D65528260864}
2009-08-02 21:57 . 2009-08-02 21:57 -------- d-----w- c:\program files\Lavasoft
2009-08-02 21:18 . 2008-06-19 16:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-08-02 21:17 . 2009-08-02 21:17 -------- d-----w- c:\program files\Panda Security
2009-08-02 15:24 . 2009-08-02 15:24 -------- d-----w- c:\documents and settings\Hapgood 2007\Application Data\Malwarebytes
2009-08-02 15:20 . 2009-07-13 12:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-02 15:20 . 2009-08-02 15:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-02 15:20 . 2009-08-02 15:20 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Malwarebytes
2009-08-02 15:20 . 2009-07-13 12:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-02 13:14 . 2009-08-02 13:14 -------- d-----w- c:\documents and settings\Hapgood 2007\Local Settings\Application Data\AVG Security Toolbar
2009-08-02 13:12 . 2009-08-02 13:14 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\AVG Security Toolbar
2009-08-02 13:12 . 2009-08-02 13:12 -------- d-----w- c:\program files\AVG
2009-08-02 11:12 . 2009-08-02 11:12 -------- d-----w- c:\program files\Alwil Software
2009-08-02 01:27 . 2009-08-02 01:27 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-07-31 14:10 . 2009-07-31 14:58 -------- d-----w- c:\program files\Genius Move
2009-07-26 22:41 . 2009-07-26 22:40 737280 ----a-w- c:\windows\iun6002.exe
2009-07-26 22:41 . 2009-07-26 22:41 -------- d-----w- c:\program files\AndreaMosaic
2009-07-26 20:58 . 2009-07-26 20:58 128682 ----a-w- c:\documents and settings\Hapgood 2007\Application Data\Yamb\Uninstall.exe
2009-07-26 20:58 . 2009-07-26 21:00 -------- d-----w- c:\documents and settings\Hapgood 2007\Application Data\Yamb
2009-07-22 02:16 . 2009-08-03 00:03 -------- d-----w- c:\documents and settings\Hapgood 2007\Application Data\vlc
2009-07-21 15:12 . 2009-07-21 15:12 20747 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-21 14:53 . 2006-08-15 10:42 200704 ----a-w- c:\windows\system32\UpdateDriver.exe
2009-07-21 14:39 . 2009-07-21 15:12 -------- d-----w- c:\program files\Belkin
2009-07-21 01:14 . 2009-07-21 01:14 -------- d-sh--w- c:\documents and settings\Hapgood 2007\IECompatCache
2009-07-21 01:14 . 2009-07-21 01:14 -------- d-sh--w- c:\documents and settings\Hapgood 2007\PrivacIE
2009-07-20 14:26 . 2009-07-20 14:26 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-07-20 13:34 . 2009-07-20 13:34 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-07-20 13:33 . 2009-07-20 13:33 -------- d-sh--w- c:\documents and settings\Hapgood 2007\IETldCache
2009-07-20 00:28 . 2009-06-02 10:12 102912 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-07-20 00:28 . 2009-07-20 00:28 -------- d-----w- c:\windows\ie8updates
2009-07-20 00:27 . 2009-07-03 17:09 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-07-20 00:27 . 2009-07-03 17:09 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-20 00:25 . 2009-07-20 00:27 -------- dc-h--w- c:\windows\ie8
2009-07-19 09:24 . 2009-07-19 09:24 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-19 09:24 . 2009-07-19 09:24 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\McAfee
2009-07-19 09:23 . 2009-07-19 09:23 152576 ----a-w- c:\documents and settings\Hapgood 2007\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-11 08:58 . 2009-07-11 09:01 -------- d-----w- c:\documents and settings\Hapgood 2007\Local Settings\Application Data\FullTiltPoker
2009-07-11 08:57 . 2009-07-11 09:18 -------- d-----w- c:\program files\Full Tilt Poker
2009-07-11 08:43 . 2009-07-11 08:43 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Boss Media
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-03 14:33 . 2007-10-28 11:17 -------- d---a-w- c:\docume~1\ALLUSE~1\APPLIC~1\TEMP
2009-08-02 21:57 . 2008-03-08 11:45 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Lavasoft
2009-08-02 16:03 . 2007-03-28 16:03 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-02 15:11 . 2007-03-28 16:03 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-08-02 01:33 . 2007-06-06 19:26 -------- d-----w- c:\program files\Spyware Doctor
2009-08-01 12:34 . 2008-05-05 15:50 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-30 16:16 . 2009-03-08 16:25 -------- d-----w- c:\documents and settings\Hapgood 2007\Application Data\Spotify
2009-07-28 22:23 . 2007-01-14 15:05 -------- d-----w- c:\documents and settings\Hapgood 2007\Application Data\Azureus
2009-07-28 21:15 . 2007-01-14 15:05 -------- d-----w- c:\program files\Azureus
2009-07-24 18:12 . 2007-01-11 12:51 8340 ----a-w- c:\documents and settings\Hapgood 2007\Application Data\wklnhst.dat
2009-07-24 13:50 . 2008-03-17 19:11 -------- d-----w- c:\program files\mkv2vob
2009-07-22 02:14 . 2007-01-14 17:29 -------- d-----w- c:\program files\VideoLAN
2009-07-21 15:12 . 2006-11-19 15:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-21 14:18 . 2008-06-18 11:36 -------- d-----w- c:\program files\Kontiki
2009-07-21 14:18 . 2008-06-18 11:36 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Kontiki
2009-07-19 09:24 . 2006-11-19 15:54 -------- d-----w- c:\program files\Java
2009-07-11 08:44 . 2008-04-09 00:23 -------- d-----w- c:\documents and settings\Hapgood 2007\Application Data\Skype
2009-07-11 08:43 . 2008-05-03 00:09 -------- d-----w- c:\program files\Poker Heaven
2009-07-11 08:29 . 2008-04-09 00:24 -------- d-----w- c:\documents and settings\Hapgood 2007\Application Data\skypePM
2009-07-03 17:09 . 2004-09-10 13:57 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 12:15 . 2009-06-29 12:15 2424832 ----a-w- c:\documents and settings\Hapgood 2007\Application Data\Yamb\Yamb.exe
2009-06-29 06:26 . 2009-06-29 06:26 235764 ----a-w- c:\documents and settings\Hapgood 2007\Application Data\Yamb\MP4Box.exe
2009-06-29 06:26 . 2009-06-29 06:26 4248467 ----a-w- c:\documents and settings\Hapgood 2007\Application Data\Yamb\libgpac.dll
2009-06-22 11:46 . 2009-06-22 11:46 1824256 ----a-w- c:\documents and settings\Hapgood 2007\Application Data\Yamb\MediaInfo.dll
2009-06-16 14:55 . 2009-04-04 17:53 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2009-04-04 17:53 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:24 . 2009-04-04 17:53 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-07 15:44 . 2009-04-04 17:53 344064 ----a-w- c:\windows\system32\localspl.dll
2008-03-27 14:25 . 2008-03-27 14:25 0 ----a-w- c:\program files\temp01
2009-07-20 12:49 . 2008-11-26 17:33 137208 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2007-01-23 13:07 . 2007-07-05 00:57 1847296 ----a-w- c:\program files\mozilla firefox\plugins\Seadragon.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 842584]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"F5D7050v3"="c:\program files\Belkin\F5D7050v3\Belkinwcui.exe" [2007-10-30 1654784]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-27 7573504]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-05-18 16207872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-10 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher 2.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Exif Launcher 2.lnk
backup=c:\windows\pss\Exif Launcher 2.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Exif Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
backup=c:\windows\pss\Exif Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Extender Resource Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Extender Resource Monitor.lnk
backup=c:\windows\pss\Extender Resource Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\APPS\\skype\\Phone\\Skype.exe"=
"c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
"42123:TCP"= 42123:TCP:tversity
"42123:UDP"= 42123:UDP:tv
"35623:TCP"= 35623:TCP:azu
"35623:UDP"= 35623:UDP:azu2
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [02/08/2009 22:59 64160]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [02/08/2009 22:18 28544]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [03/07/2009 15:49 1029456]
S3 bdacap;PC-DTV Receiver;c:\windows\system32\drivers\bdacap.sys [11/01/2007 14:04 217728]
S3 GLHIDKBFILTER;GLHIDKBFILTER;c:\windows\system32\drivers\GLKbFilter.sys [11/01/2007 14:04 11264]
S3 StreamSurge;StreamSurge Driver (miniport);c:\windows\system32\DRIVERS\ss.sys --> c:\windows\system32\DRIVERS\ss.sys [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
HKU-Default-Run-Spyware Doctor - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &Search
IE: {{08E730A4-FB02-45BD-A900-01E4AD8016F6} -
http://www.skybroadband.comTCP: {65E1DC51-5E45-4BEC-AD76-F80D4862752B} = 192.168.0.1
DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} - hxxp://magnet.2020.net/virtualplanner/Core/Player/2020PlayerAX_Win32.cab
FF - ProfilePath - c:\docume~1\HAPGOO~1\APPLIC~1\Mozilla\Firefox\Profiles\9gjb6iol.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - www.google.co.uk
FF - prefs.js: keyword.URL - hxxp://uk.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_uk&p=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppsynth.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\windows\system32\Photosynth\nppsynth.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-03 18:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\windows\TEMP\mc21.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(5740)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\ehome\RMSvc.exe
c:\program files\Spyware Doctor\sdhelp.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
c:\windows\ehome\McrdSvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2009-08-03 18:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-03 17:07
Pre-Run: 90,703,347,712 bytes free
Post-Run: 92,958,879,744 bytes free
316 --- E O F --- 2009-08-03 08:19