Combofix log posted:
ComboFix 09-08-30.01 - Djordje 30/08/2009 19:46.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1642 [GMT -4:00]
Running from: c:\documents and settings\Djordje\Desktop\Combo-Fix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Start Menu\Programs\Internet Explorer.lnk
C:\vvv.exe
c:\windows\Fonts\AcadEref.ttf
c:\windows\Installer\106a98.msi
c:\windows\Installer\10b328c.msp
c:\windows\Installer\10b328f.msp
c:\windows\Installer\11dfbe.msp
c:\windows\Installer\1423b3.msp
c:\windows\Installer\1499cd.msp
c:\windows\Installer\1499d0.msp
c:\windows\Installer\17e966.msp
c:\windows\Installer\17e969.msp
c:\windows\Installer\26922a.msi
c:\windows\Installer\284f9b5.msp
c:\windows\Installer\3b0038.msp
c:\windows\Installer\3b003b.msp
c:\windows\Installer\3b003e.msp
c:\windows\Installer\3b0041.msp
c:\windows\Installer\3b0044.msp
c:\windows\Installer\3b0047.msp
c:\windows\Installer\3b004a.msp
c:\windows\Installer\3b004d.msp
c:\windows\Installer\3b0050.msp
c:\windows\Installer\7a97aa.msp
c:\windows\Installer\8c37f1.msi
c:\windows\Installer\d1379.msp
c:\windows\Installer\d137c.msp
c:\windows\Installer\ea0fcc.msp
c:\windows\run.log
c:\windows\system32\drivers\kbiwkmvtuebwkt.sys
c:\windows\system32\kbiwkmdtfnsdoq.dat
c:\windows\system32\kbiwkmfnmnaoex.dat
c:\windows\system32\kbiwkmpxmjutpq.dll
c:\windows\system32\kbiwkmqwhxvmtk.dat
c:\windows\system32\kbiwkmrnsbruem.dat
c:\windows\system32\kbiwkmrxyhorgi.dll
c:\windows\system32\kbiwkmwnstlnkl.dat
c:\windows\system32\kbiwkmxboeyanr.dat
c:\windows\system32\prunnet.exe
c:\windows\system32\s2
c:\windows\system32\sX3i19
C:\winlogon.exe
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_kbiwkmkaomyndo
-------\Legacy_kbiwkmkaomyndo
-------\Legacy_CMDSERVICE
-------\Legacy_NETWORK_MONITOR
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-31 )))))))))))))))))))))))))))))))
.
2009-08-30 21:28 . 2009-08-30 21:28 -------- d-----w- c:\documents and settings\Djordje\Application Data\Malwarebytes
2009-08-30 21:28 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-30 21:28 . 2009-08-30 21:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-30 21:28 . 2009-08-30 21:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-30 21:28 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-30 21:07 . 2005-02-16 15:06 218112 ----a-w- c:\documents and settings\All Users\jack.exe
2009-08-30 13:01 . 2009-08-30 23:44 -------- d-----w- c:\program files\NoAdware
2009-08-30 12:55 . 2009-08-30 12:55 -------- d-----w- C:\!KillBox
2009-08-29 12:34 . 2008-06-19 21:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-08-29 12:33 . 2009-08-29 12:33 -------- d-----w- c:\program files\Panda Security
2009-08-28 19:10 . 2009-08-28 19:10 -------- d-----w- C:\spoolerlogs
2009-08-21 02:27 . 2009-08-21 02:27 -------- d-sh--w- c:\documents and settings\LocalService\PrivacIE
2009-08-21 02:27 . 2009-08-21 02:27 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-08-19 11:16 . 2009-08-19 11:16 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-12 11:42 . 2009-08-12 11:42 -------- d-sh--w- c:\documents and settings\Djordje\IECompatCache
2009-08-12 11:01 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-08-08 15:08 . 2009-08-08 15:08 70656 ----a-w- c:\windows\system32\drivers\bcxrvdbvtnxrquqs.sys
2009-08-08 13:53 . 2009-08-08 13:53 -------- d-----w- c:\windows\system32\IOSUBSYS
2009-08-05 09:01 . 2009-08-05 09:01 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-28 19:07 . 2008-02-07 16:50 -------- d-----w- c:\program files\Symantec AntiVirus
2009-08-14 16:25 . 2008-05-08 03:35 -------- d-----w- c:\documents and settings\Djordje\Application Data\FileZilla
2009-08-12 11:21 . 2009-06-11 16:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-10 20:05 . 2006-09-22 11:05 128144 ----a-w- c:\documents and settings\Djordje\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-10 17:19 . 2007-02-16 14:05 -------- d-----w- c:\documents and settings\Djordje\Application Data\Azureus
2009-08-08 13:53 . 2007-04-09 22:42 -------- d-----w- c:\program files\Google
2009-08-05 09:01 . 2004-08-10 17:51 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2004-08-10 17:50 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-10 17:51 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-12 13:23 . 2009-04-01 13:58 70920 ----a-w- c:\documents and settings\All Users\Application Data\CA-SupportBridge\Customer_rc.dll
2009-07-12 13:23 . 2009-04-01 13:58 -------- d-----w- c:\documents and settings\All Users\Application Data\CA-SupportBridge
2009-07-12 03:00 . 2008-02-28 16:34 805952 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-07-11 16:23 . 2009-03-06 14:07 -------- d-----w- c:\program files\TransAM CC2
2009-07-11 15:55 . 2009-07-11 15:55 34 ----a-w- c:\program files\TRAN.RAT
2009-07-11 15:55 . 2009-07-11 15:55 25 ----a-w- c:\program files\TRAN.SYM
2009-07-11 13:34 . 2008-08-22 17:59 -------- d-----w- c:\program files\Seagate Software
2009-07-11 13:34 . 2009-07-11 13:34 -------- d-----w- c:\program files\ValMatic
2009-07-11 12:47 . 2008-06-13 14:54 -------- d-----w- c:\program files\TransAM
2009-07-03 17:09 . 2004-08-10 17:51 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-01 21:34 . 2009-07-01 21:34 99678 -c--a-r- c:\documents and settings\Djordje\Application Data\Microsoft\Installer\{E942407D-3261-476C-850B-9546BCA72499}\_1C13ED278AAF63E67C5DE6.exe
2009-07-01 21:34 . 2009-07-01 21:34 99678 -c--a-r- c:\documents and settings\Djordje\Application Data\Microsoft\Installer\{E942407D-3261-476C-850B-9546BCA72499}\_0BBC25476C38B6119E41D8.exe
2009-06-16 14:36 . 2004-08-10 17:51 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-10 17:51 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2004-08-10 17:51 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2004-08-10 17:50 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2004-08-10 18:01 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2008-05-08 00:16 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2004-08-10 17:51 1291264 ----a-w- c:\windows\system32\quartz.dll
2008-05-03 23:08 . 2008-05-03 23:08 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 1200128]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-18 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2009
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"RoxWatch9"=2 (0x2)
"RoxMediaDB9"=3 (0x3)
"Roxio Upnp Server 9"=2 (0x2)
"Roxio UPnP Renderer 9"=3 (0x3)
"MSSQL$VALMATIC8"=2 (0x2)
"GoogleDesktopManager-022208-143751"=3 (0x3)
"FileZilla Server"=3 (0x3)
"Fax"=2 (0x2)
"DefWatch"=2 (0x2)
"Adobe LM Service"=3 (0x3)
"CiSvc"=3 (0x3)
"Autodesk Licensing Service"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
"MDM"=2 (0x2)
"WDBtnMgrSvc.exe"=2 (0x2)
"usnjsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"Pml Driver HPZ12"=3 (0x3)
"gusvc"=3 (0x3)
"RasMan"=3 (0x3)
"SwPrv"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\lxcgcoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxcgpswx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Qameleon\\QViewPlus\\QViewPlus.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [29/08/2009 8:34 AM 28544]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [28/08/2009 11:30 AM 102448]
S3 EraserUtilDrv10821;EraserUtilDrv10821; [x]
S3 P0230BBK;Creative PC-CAM 750 (Still Image);c:\windows\system32\DRIVERS\P0230bbk.sys --> c:\windows\system32\DRIVERS\P0230bbk.sys [?]
S3 P0230BVD;Creative PC-CAM 750 (Video);c:\windows\system32\DRIVERS\P0230bVd.sys --> c:\windows\system32\DRIVERS\P0230bVd.sys [?]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [27/09/2006 9:33 PM 116464]
S3 SQLAgent$VALMATIC8;SQLAgent$VALMATIC8;c:\program files\Microsoft SQL Server\MSSQL$VALMATIC8\Binn\sqlagent.EXE -i VALMATIC8 --> c:\program files\Microsoft SQL Server\MSSQL$VALMATIC8\Binn\sqlagent.EXE -i VALMATIC8 [?]
S4 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [03/05/2008 7:08 PM 29744]
S4 MSSQL$VALMATIC8;MSSQL$VALMATIC8;c:\program files\Microsoft SQL Server\MSSQL$VALMATIC8\Binn\sqlservr.exe -sVALMATIC8 --> c:\program files\Microsoft SQL Server\MSSQL$VALMATIC8\Binn\sqlservr.exe -sVALMATIC8 [?]
S4 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [19/02/2008 2:15 AM 106496]
--- Other Services/Drivers In Memory ---
*Deregistered* - EraserUtilDrv10910
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-30 c:\windows\Tasks\HP Usg Daily.job
- c:\program files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\pexpress\hphped05.exe [2006-12-23 04:55]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uLocal Page =
mStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Djordje\Application Data\Mozilla\Firefox\Profiles\yg7pgu13.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPJPI150_11.dll
FF - plugin: c:\program files\Java\jre1.5.0_11\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
.
------- File Associations -------
.
inifile=%SystemRoot%\System32\NOTEPAD.EXE %1"
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-30 20:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(3848)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1433_x-ww_5cf844d2\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\progra~1\MICROS~3\rapimgr.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\windows\system32\searchindexer.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Adobe\Reader 8.0\Reader\AcroRd32.exe
.
**************************************************************************
.
Completion time: 2009-08-31 20:17 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-31 00:17
Pre-Run: 15,776,403,456 bytes free
Post-Run: 15,577,014,272 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
345 --- E O F --- 2009-08-26 19:51