found a way to crank up IE so here's the combofix log ComboFix 10-03-23.01 - heather 23/03/2010 18:21:09.1.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.2046.1330 [GMT 0:00] Running from: c:\documents and settings\heather\Desktop\ComboFix.exe AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\heather\Local Settings\Application Data\{F476E718-F83B-4BEE-A8B7-2016291C0745} c:\documents and settings\heather\Local Settings\Application Data\{F476E718-F83B-4BEE-A8B7-2016291C0745}\chrome.manifest c:\documents and settings\heather\Local Settings\Application Data\{F476E718-F83B-4BEE-A8B7-2016291C0745}\chrome\content\_cfg.js c:\documents and settings\heather\Local Settings\Application Data\{F476E718-F83B-4BEE-A8B7-2016291C0745}\chrome\content\overlay.xul c:\documents and settings\heather\Local Settings\Application Data\{F476E718-F83B-4BEE-A8B7-2016291C0745}\install.rdf c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc100.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc101.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc102.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc103.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc104.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc105.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc106.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc107.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc108.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc109.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc10A.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc10B.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc10C.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc10D.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc10E.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc10F.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc110.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc111.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc112.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc113.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc114.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc115.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc116.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc117.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc118.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc119.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc11A.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc11B.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc11C.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc11D.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc11E.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc11F.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc120.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc121.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc122.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc123.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc124.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc125.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc126.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc127.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc128.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc12A.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc12D.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc13.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc132.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc134.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc135.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc136.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc13D.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc141.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc142.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc15.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc150.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc170.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc171.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc18.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc19.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc199.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc19B.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc1B.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc1BB.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc1C.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc1D.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc1E.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc1F.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc20.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc202.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc21.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc22.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc23.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc24.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc249.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc25.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc26.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc27.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc28.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc29.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc2A.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc2B.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc2C.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc2D.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc2E.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc2F.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc30.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc31.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc32.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc33.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc34.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc35.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc36.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc37.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc38.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc39.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc3A.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc3B.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc3C.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc3D.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc3E.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc3F.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc40.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc40E.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc41.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc411.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc42.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc43.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc44.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc45.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc46.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc47.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc48.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc49.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc4A.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc4B.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc4C.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc4D.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc4E.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc4F.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc50.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc51.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc52.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc53.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc54.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc55.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc56.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc57.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc58.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc59.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc5A.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc5B.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc5C.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc5D.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc5E.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc5F.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc60.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc61.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc62.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc63.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc64.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc65.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc66.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc67.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc68.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc69.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc6A.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc6B.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc6C.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc6D.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc6E.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc6F.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc70.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc71.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc72.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc73.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc74.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc75.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc76.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc77.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc78.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc79.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc7A.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc7B.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc7C.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc7D.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc7E.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc7F.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc80.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc81.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc82.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc83.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc84.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc85.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc86.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc87.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc88.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc89.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc8A.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc8B.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc8C.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc8D.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc8E.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc8F.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc90.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc91.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc92.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc93.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc94.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc95.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc96.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc97.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc98.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc99.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc9A.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc9B.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc9C.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc9D.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc9E.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mcc9F.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccA0.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccA1.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccA2.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccA3.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccA4.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccA5.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccA6.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccA7.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccA8.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccA9.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccAA.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccAB.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccAC.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccAD.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccAE.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccAF.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccB0.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccB1.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccB2.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccB3.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccB4.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccB5.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccB6.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccB7.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccB8.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccB9.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccBA.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccBB.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccBC.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccBD.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccBE.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccBF.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccC0.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccC1.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccC2.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccC3.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccC4.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccC5.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccC6.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccC7.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccC8.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccC9.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccCA.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccCB.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccCC.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccCD.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccCE.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccCF.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccD0.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccD1.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccD2.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccD3.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccD4.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccD5.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccD6.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccD7.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccD8.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccD9.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccDA.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccDB.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccDC.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccDD.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccDE.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccDF.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccE0.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccE1.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccE2.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccE3.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccE4.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccE5.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccE6.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccE7.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccE8.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccE9.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccEA.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccEB.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccEC.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccED.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccEE.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccEF.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccF0.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccF1.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccF2.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccF3.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccF4.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccF5.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccF6.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccF7.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccF8.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccF9.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccFA.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccFB.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccFC.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccFD.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccFE.tmp c:\documents and settings\heather\Local Settings\Temporary Internet Files\mccFF.tmp c:\windows\Downloaded Program Files\popcaploader.inf c:\windows\system32\345022866.dat c:\windows\system32\bb1.dat c:\windows\system32\Data c:\windows\system32\hjgruihpmowpap.dat c:\windows\system32\hjgruivhfetchh.dat c:\windows\system32\ps1.dat c:\windows\system32\rc.dat . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_hjgruiijglkayb -------\Service_hjgruiijglkayb ((((((((((((((((((((((((( Files Created from 2010-02-24 to 2010-03-24 ))))))))))))))))))))))))))))))) . 2010-03-22 17:35 . 2010-03-22 17:35 12464 ----a-w- c:\windows\system32\avgrsstx.dll 2010-03-21 15:34 . 2010-03-21 15:34 293376 ----a-w- c:\program files\ozi0x6xe.exe 2010-03-21 15:18 . 2010-03-21 15:18 525824 ----a-w- c:\program files\dds.scr 2010-03-21 15:00 . 2010-03-21 15:00 -------- d-----w- C:\$AVG 2010-03-21 15:00 . 2010-03-22 17:35 242696 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2010-03-21 15:00 . 2010-03-22 17:35 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2010-03-21 15:00 . 2010-03-22 17:34 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2010-03-21 15:00 . 2010-03-24 08:20 -------- d-----w- c:\windows\system32\drivers\Avg 2010-03-21 15:00 . 2010-03-21 15:00 -------- d-----w- c:\program files\AVG 2010-03-21 15:00 . 2010-03-21 15:00 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9 2010-03-21 14:31 . 2010-03-21 14:31 -------- d-----w- c:\windows\system32\wbem\Repository 2010-03-21 11:24 . 2010-03-21 11:24 55184 ----a-w- c:\windows\system32\PxSecure(2).dll 2010-03-21 11:24 . 2010-03-21 14:31 -------- d-----w- c:\program files\Prevx 2010-03-21 11:24 . 2010-03-21 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\PrevxCSI 2010-03-13 09:05 . 2010-03-13 09:05 -------- d-----w- c:\documents and settings\heather\Local Settings\Application Data\IRIS Software Ltd 2010-03-13 09:04 . 2010-03-13 09:04 -------- d-----w- c:\program files\Microsoft Visual Studio .NET 2003 2010-03-13 09:04 . 2010-03-13 09:04 -------- d-----w- c:\program files\Common Files\Crystal Decisions 2010-03-13 09:04 . 2010-03-18 18:22 -------- d-----w- c:\documents and settings\All Users\Application Data\IRIS Software Ltd 2010-03-13 09:04 . 2010-03-13 09:04 -------- d-----w- c:\program files\IRIS Software Ltd 2010-03-02 18:55 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-24 18:27 . 2008-04-13 16:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Kontiki 2010-03-24 18:24 . 2006-11-17 18:44 -------- d-----w- c:\program files\Dl_cats 2010-03-24 18:03 . 2004-08-10 12:03 78503 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2010-03-21 14:30 . 2009-02-07 15:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-03-19 17:29 . 2010-02-17 08:49 120 ----a-w- c:\windows\Hwupiholuracanar.dat 2010-03-19 08:45 . 2010-02-17 08:49 0 ----a-w- c:\windows\Ucenukururul.bin 2010-03-10 19:11 . 2009-08-06 17:51 -------- d-----w- c:\program files\LittlewoodsPoker 2010-03-10 19:11 . 2009-08-06 17:51 -------- d-----w- c:\documents and settings\heather\Application Data\LittlewoodsPoker 2010-03-08 18:36 . 2006-03-30 16:16 -------- d-----w- c:\program files\Java 2010-03-04 18:23 . 2009-01-27 18:52 -------- d-----w- c:\program files\InterPoker 2010-02-18 16:19 . 2009-01-18 19:01 -------- d-----w- c:\program files\McAfee 2007-06-25 19:18 . 2007-06-25 19:18 60526 -c--a-w- c:\program files\mozilla firefox\components\jar50.dll 2007-06-25 19:18 . 2007-06-25 19:18 49256 -c--a-w- c:\program files\mozilla firefox\components\jsd3250.dll 2007-06-25 19:18 . 2007-06-25 19:18 166000 -c--a-w- c:\program files\mozilla firefox\components\xpinstal.dll 2007-10-06 14:50 . 2007-10-06 14:50 56 -csh--r- c:\windows\system32\1B9E4B68C9.sys 2009-05-25 09:03 . 2007-02-11 11:19 56 -csh--r- c:\windows\system32\391C1D2BD4.sys 2009-05-25 09:03 . 2007-02-11 11:19 6372 -csha-w- c:\windows\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 24576] "Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400] "DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2004-07-19 306688] "kdx"="c:\program files\Kontiki\KHost.exe" [2008-02-27 1032376] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064] "DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208] "CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-09-15 57344] "MBMon"="CTMBHA.DLL" [2005-05-19 1345520] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "VoiceCenter"="c:\program files\Creative\VoiceCenter\AndreaVC.exe" [2005-09-19 1159168] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720] "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940] "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 110592] "DLCICATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCItime.dll" [2006-02-24 73728] "dlcimon.exe"="c:\program files\Dell AIO Printer 946\dlcimon.exe" [2006-02-14 430080] "YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536] "YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [2006-08-31 448040] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-09-26 267064] "btbb_McciTrayApp"="c:\program files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe" [2009-09-14 1584640] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-28 198160] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696] BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2005-6-15 1208320] Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2010-03-22 17:35 12464 ----a-w- c:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YPAGER.EXE"= "c:\\Program Files\\Yahoo!\\Messenger\\yserver.exe"= "c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Kontiki\\KService.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [21/03/2010 15:00 216200] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [21/03/2010 15:00 242696] R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [22/03/2010 17:35 308064] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [18/01/2009 20:30 203280] R3 dlci_device;dlci_device;c:\windows\system32\dlcicoms.exe -service --> c:\windows\system32\dlcicoms.exe -service [?] S2 gupdate1ca4020fd98a150;Google Update Service (gupdate1ca4020fd98a150);c:\program files\Google\Update\GoogleUpdate.exe [28/09/2009 09:49 133104] --- Other Services/Drivers In Memory --- *NewlyCreated* - UPLOADMGR [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}] 2009-03-08 03:32 128512 ----a-w- c:\windows\system32\advpack.dll . Contents of the 'Scheduled Tasks' folder 2010-02-18 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 12:34] 2010-03-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-09-28 09:49] 2010-03-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-09-28 09:49] 2009-11-15 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-18 11:22] 2009-10-01 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-01-18 11:22] . . ------- Supplementary Scan ------- . uStart Page = hxxp://bt.yahoo.com uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = 127.0.0.1 uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000 Trusted Zone: internet Trusted Zone: mcafee.com DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\heather\Application Data\Mozilla\Firefox\Profiles\juferj17.default\ FF - prefs.js: browser.search.selectedEngine - Google ---- FIREFOX POLICIES ---- FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties"); . - - - - ORPHANS REMOVED - - - - HKLM-Run-Stosuhuw - c:\windows\ufetokesiko.dll Notify-dimsntfy - (no file) SafeBoot-mferkdk AddRemove-sunpoker - c:\program files\SunPoker\_SetupPoker[1].exe AddRemove-William Hill Poker - c:\poker\William Hill Poker\_SetupPoker[1].exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-03-24 18:25 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run DLCICATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCItime.dll,_RunDLLEntry@16??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(4332) c:\windows\system32\WININET.dll c:\program files\McAfee\SiteAdvisor\saHook.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\program files\AVG\AVG9\avgchsvx.exe c:\program files\AVG\AVG9\avgrsx.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe c:\windows\system32\CTsvcCDA.exe c:\program files\Intel\Intel Matrix Storage Manager\iaantmon.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Kontiki\KService.exe c:\program files\AVG\AVG9\avgnsx.exe c:\program files\Common Files\Motive\McciCMService.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe c:\progra~1\McAfee\VIRUSS~1\mcshield.exe c:\program files\McAfee\MPF\MPFSrv.exe c:\program files\McAfee\MSK\MskSrver.exe c:\windows\system32\wdfmgr.exe c:\progra~1\mcafee.com\agent\mcagent.exe c:\windows\stsystra.exe c:\windows\system32\Rundll32.exe c:\docume~1\heather\LOCALS~1\Temp\clclean.0001 c:\windows\system32\rundll32.exe c:\progra~1\Yahoo!\browser\ycommon.exe c:\windows\system32\rundll32.exe c:\program files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe c:\windows\system32\dlcicoms.exe c:\program files\Common Files\InstallShield\UpdateService\agent.exe c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe c:\progra~1\Yahoo!\YOP\secstat.exe c:\program files\iPod\bin\iPodService.exe c:\windows\system32\taskmgr.exe . ************************************************************************** . Completion time: 2010-03-24 18:36:58 - machine was rebooted ComboFix-quarantined-files.txt 2010-03-24 18:36 Pre-Run: 137,947,705,344 bytes free Post-Run: 138,531,946,496 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect Current=3 Default=3 Failed=2 LastKnownGood=5 Sets=1,2,3,5 - - End Of File - - 64085F15912C70D4163206D5CA4D3AF8