ComboFix 09-08-01.09 - Taylor 08/05/2009 0:42:54.1.2 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.3070.2572 [GMT -4:00]
Running from: C:\Users\Taylor\Desktop\Combo-Fix.exe
AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}
SP: AVG Internet Security *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
/wow section not completed
((((((((((((((((((((((((( Files Created from 2009-07-05 to 2009-08-05 )))))))))))))))))))))))))))))))
.
2009-07-26 02:37:25 . 2009-07-26 02:37:25 0 d-----w- C:\Program Files\iPod
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-05 04:40:15 . 2008-10-24 00:26:07 0 d-----w- C:\Program Files\Minefield
2009-08-05 04:21:36 . 2007-11-26 07:21:25 12 ----a-w- C:\Windows\bthservsdp.dat
2009-08-04 05:23:11 . 2008-04-18 21:29:35 0 d-----w- C:\PROGRA~2\Google Updater
2009-08-03 17:31:44 . 2007-12-27 19:35:46 0 d-----w- C:\Users\Taylor\AppData\Roaming\Azureus
2009-08-02 06:11:23 . 2007-11-26 07:31:11 0 d-----w- C:\Program Files\Trend Micro
2009-08-02 06:05:46 . 2008-09-03 19:57:49 0 d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2009-08-01 06:08:12 . 2009-01-04 03:10:45 0 d-----w- C:\Users\Taylor\AppData\Roaming\FrostWire
2009-07-28 20:53:33 . 2007-12-27 19:36:37 182 ----a-w- C:\Users\Taylor\AppData\Roaming\Azureus\restart.bat
2009-07-28 20:52:43 . 2007-12-27 19:32:33 0 d-----w- C:\Program Files\Azureus
2009-07-26 02:38:07 . 2008-08-02 01:00:53 0 d-----w- C:\Program Files\iTunes
2009-07-26 02:37:24 . 2007-12-26 20:05:12 0 d-----w- C:\Program Files\Common Files\Apple
2009-07-14 03:02:27 . 2008-10-21 01:10:33 0 d-----w- C:\PROGRA~2\Avg8
2009-06-29 17:57:13 . 2009-06-29 17:57:13 0 d-----w- C:\Program Files\HDQuality
2009-06-28 18:14:36 . 2009-06-28 18:14:16 0 d-----w- C:\Users\Taylor\AppData\Roaming\MozillaControl
2009-06-28 18:13:14 . 2009-06-28 18:11:54 0 d-----w- C:\Program Files\Graboid
2009-06-28 18:13:05 . 2009-06-28 18:13:02 0 d-----w- C:\Program Files\Mozilla ActiveX Control v1.7.12
2009-06-17 15:27:56 . 2008-09-03 19:57:50 38160 ----a-w- C:\Windows\system32\drivers\mbamswissarmy.sys
2009-06-17 15:27:44 . 2008-09-03 19:57:50 19096 ----a-w- C:\Windows\system32\drivers\mbam.sys
2009-06-16 19:25:18 . 2008-10-21 02:09:39 27784 ----a-w- C:\Windows\system32\drivers\avgmfx86.sys
2009-06-15 04:15:20 . 2007-12-25 23:51:30 0 d-----w- C:\Program Files\AIM6
2009-06-15 04:15:16 . 2009-06-15 04:15:15 0 d-----w- C:\Program Files\AIMTunes
2009-06-15 04:14:31 . 2007-12-25 23:52:33 0 d-----w- C:\PROGRA~2\Viewpoint
2009-06-15 04:12:55 . 2008-05-15 23:53:31 0 d-----w- C:\PROGRA~2\AOL Downloads
2009-06-10 17:21:35 . 2008-10-21 02:09:41 327688 ----a-w- C:\Windows\system32\drivers\avgldx86.sys
2009-06-10 17:17:27 . 2008-02-25 20:46:14 0 d-----w- C:\PROGRA~2\NVIDIA
2009-06-07 02:39:58 . 2008-03-19 23:03:25 0 d-----w- C:\Users\Taylor\AppData\Roaming\DivX
2009-06-06 17:36:17 . 2007-12-25 22:22:26 97840 ----a-w- C:\Users\Taylor\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-29 17:36:16 . 2009-05-29 17:36:16 39424 ----a-w- C:\Windows\system32\drivers\usbaapl.sys
2009-05-29 17:36:16 . 2009-05-29 17:36:16 2060288 ----a-w- C:\Windows\system32\usbaaplrc.dll
2009-05-14 21:55:38 . 2009-05-14 21:55:38 245408 ----a-w- C:\Windows\system32\unicows.dll
2008-12-29 04:44:55 . 2008-05-18 00:42:45 134656 ----a-w- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
2008-08-08 19:35:29 . 2008-08-08 19:35:31 122880 ----a-w- C:\Program Files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-05-01 21:02:48 . 2009-05-01 21:02:48 1044480 ----a-w- C:\Program Files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02:48 . 2009-05-01 21:02:48 200704 ----a-w- C:\Program Files\mozilla firefox\plugins\ssldivx.dll
2007-11-26 15:06:33 . 2007-11-26 14:55:26 8192 --sha-w- C:\Windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 22:32:40 206064]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 03:33:40 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-19 03:38:40 1008184]
"Windows Mobile Device Center"="C:\Windows\WindowsMobile\wmdc.exe" [2007-05-31 15:21:28 648072]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 17:37:04 81920]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-08-08 19:35:29 29744]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-10 00:57:14 16384]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 17:35:42 221184]
"dlcxmon.exe"="C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 16:57:28 292336]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 926\memcard.exe" [2006-11-03 22:04:46 304008]
"DLCXCATS"="C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 06:31:56 106496]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 22:32:40 206064]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 00:58:04 177472]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2009-06-10 17:21:29 1948440]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 06:04:34 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2009-05-26 21:18:30 413696]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2009-03-28 04:03:00 13687328]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2009-03-28 04:03:00 92704]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2009-07-13 18:03:10 292128]
"RtHDVCpl"="RtHDVCpl.exe" - C:\Windows\RtHDVCpl.exe [2008-01-17 11:22:20 4907008]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-11-26 50688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL,avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
SetupExecute REG_MULTI_SZ
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^Taylor^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
path=C:\Users\Taylor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk
backup=C:\Windows\pss\MagicDisc.lnk.Startup
backupExtension=.Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3D218756-9ADD-422F-B93E-8B0D106B2211}"= UDP:C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{D5E401BB-17F2-4FB6-AEAA-ACD3A5300AF6}"= TCP:C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{C1944503-7173-43FB-8512-E6CC22A4ED46}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{B7416332-A0FC-49F2-B9BA-545471C8F71C}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{6F1469E6-6C41-4507-9BBA-70717548F488}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{903AAA3A-7241-40B7-B834-ADEDB6A1935C}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"{87EA62BF-A5B6-4971-9040-3C9E6E1D967E}"= UDP:C:\Windows\System32\dlcxcoms.exe:Lexmark Communications System
"{4DD95A47-03CB-4135-AE33-01300FAAB84C}"= TCP:C:\Windows\System32\dlcxcoms.exe:Lexmark Communications System
"{2C992900-91DC-4CF4-A93A-FB6089327C95}"= UDP:C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe:Device Monitor
"{05FE3D30-767C-47CE-8EE4-9811FF4883EE}"= TCP:C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe:Device Monitor
"{F4492335-8D5B-4368-A39E-914F733303D6}"= UDP:C:\Program Files\Dell Photo AIO Printer 926\dlcxaiox.exe:All In One Center
"{A0B7ADAF-F987-4F77-A94A-DB9D01849979}"= TCP:C:\Program Files\Dell Photo AIO Printer 926\dlcxaiox.exe:All In One Center
"{FCB20782-78F5-4222-AFCB-AFB78FAEA78A}"= UDP:443:AIM1
"{11D932A9-26B4-4C00-8F45-DD3C585AE639}"= TCP:443:AIM2
"{16AA50F4-A07B-4B68-BDE2-CF485696F0FD}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{D7B8FD2A-1173-4A70-B6EA-5047984306F3}C:\\games\\paintball2\\paintball2.exe"= UDP:C:\games\paintball2\paintball2.exe:paintball2
"UDP Query User{16B525A2-52A5-4B64-8E96-00987B7832FD}C:\\games\\paintball2\\paintball2.exe"= TCP:C:\games\paintball2\paintball2.exe:paintball2
"TCP Query User{E098B7DF-9199-4952-8EF4-EECBD66292B3}C:\\program files\\world of warcraft\\wow-2.3.0-enus-downloader.exe"= UDP:C:\program files\world of warcraft\wow-2.3.0-enus-downloader.exe:Blizzard Downloader
"UDP Query User{EDF070C0-8683-4B43-8EF0-C00F9B53C9AF}C:\\program files\\world of warcraft\\wow-2.3.0-enus-downloader.exe"= TCP:C:\program files\world of warcraft\wow-2.3.0-enus-downloader.exe:Blizzard Downloader
"TCP Query User{D956003D-0CD5-493B-A6F3-FDB7799824F7}C:\\program files\\world of warcraft\\wow-2.4.0-enus-downloader.exe"= UDP:C:\program files\world of warcraft\wow-2.4.0-enus-downloader.exe:Blizzard Downloader
"UDP Query User{A2EC3A39-1BE4-4869-B94E-DFCFA84AD024}C:\\program files\\world of warcraft\\wow-2.4.0-enus-downloader.exe"= TCP:C:\program files\world of warcraft\wow-2.4.0-enus-downloader.exe:Blizzard Downloader
"{AEFDD787-544E-4E07-B646-3CF7703DC728}"= UDP:C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:Age of Empires 3
"{01CE8C8B-15BF-4ECA-885A-2B8DBBA290F9}"= TCP:C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:Age of Empires 3
"TCP Query User{DB54FCFD-E8A5-45F2-85AB-9B59B9352AC2}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{943CD335-2B2D-40C5-8DC1-95299F06CFA6}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{4A063C38-8F7D-4168-8B26-03154AAD9E11}"= UDP:C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe:VoipStunt
"{7DDAC501-6EA2-4EAA-AD4F-80E8883047BF}"= TCP:C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe:VoipStunt
"{7133024F-C027-44A6-A9C5-FAFE3D9DB017}"= C:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe
"{618C6FF6-B1EB-4074-BD97-05B93E740FE1}"= C:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
"{E35128A5-C44F-4DAC-A305-50F5A6EE09A8}"= C:\Program Files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"{CAD7BFA1-B858-4883-B084-09B47458F1C3}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{4F126907-C50D-47A5-8A2F-D6EED846B3C5}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{07E5F75E-1602-46A6-9896-37E699023D0C}"= UDP:C:\Program Files\AIM6\aim6.exe:AIM
"{D836F5AE-3A5C-469F-B8CF-73188DC158F3}"= TCP:C:\Program Files\AIM6\aim6.exe:AIM
"{C3219416-6085-487A-90D2-CAF0A07F8335}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{D2C13626-11CB-4EB2-BA98-912DC55CA32F}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R0 AvgRkx86;avgrkx86.sys;C:\Windows\System32\drivers\avgrkx86.sys [10/20/2008 10:09:47 PM 12552]
S1 Avgfwfd;AVG network filter service;C:\Windows\System32\drivers\avgfwd6x.sys [10/23/2008 3:51:23 PM 23832]
S1 AvgLdx86;AVG AVI Loader Driver x86;C:\Windows\System32\drivers\avgldx86.sys [10/20/2008 10:09:41 PM 327688]
S1 AvgTdiX;AVG8 Network Redirector;C:\Windows\System32\drivers\avgtdix.sys [10/23/2008 3:51:23 PM 108552]
S2 AERTFilters;Andrea RT Filters Service;C:\Windows\System32\AERTSrv.exe [12/5/2007 6:17:24 AM 77824]
S2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [4/29/2009 3:13:11 PM 906520]
S2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [1/7/2009 4:36:43 PM 298776]
S2 avgfws8;AVG8 Firewall;C:\PROGRA~1\AVG\AVG8\avgfws8.exe [4/29/2009 3:12:44 PM 1368952]
S2 dlcx_device;dlcx_device;C:\Windows\system32\dlcxcoms.exe -service --> C:\Windows\system32\dlcxcoms.exe -service [?]
S2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [12/25/2007 7:53:06 PM 24652]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [11/26/2007 3:40:15 AM 29744]
S3 JZGTPPEIXO;JZGTPPEIXO;C:\Users\Taylor\AppData\Local\Temp\JZGTPPEIXO.exe --> C:\Users\Taylor\AppData\Local\Temp\JZGTPPEIXO.exe [?]
S3 motccgp;Motorola USB Composite Device Driver;C:\Windows\System32\drivers\motccgp.sys [8/21/2008 7:49:22 PM 18688]
S3 motccgpfl;MotCcgpFlService;C:\Windows\System32\drivers\motccgpfl.sys [8/21/2008 7:49:56 PM 8320]
S3 motport;Motorola USB Diagnostic Port;C:\Windows\System32\drivers\motport.sys [6/18/2007 2:18:26 PM 23680]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ECACHE
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Vidalia - C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe
HKCU-Run-VoipStunt - C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe
HKCU-Run-Aim6 - (no file)
HKLM-Run-<NO NAME> - (no file)
HKLM-RunOnce-<NO NAME> - (no file)
.
------- Supplementary Scan -------
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.windstream.net/
uWindow Title = Internet Explorer provided by Dell
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6071126
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
FF - ProfilePath - C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\hcriw13c.default\
FF - prefs.js: browser.search.selectedEngine - Project Playlist Music Search
FF - prefs.js: browser.startup.homepage - hxxp://uoflsports.cstv.com/
FF - component: C:\Program Files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\Program Files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\Program Files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\Program Files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\Program Files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\Program Files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\Program Files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: C:\Program Files\Minefield\plugins\npViewpoint.dll
FF - plugin: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: C:\Users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\hcriw13c.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
---- FIREFOX POLICIES ----
C:\Program Files\Minefield\greprefs\all.js - pref("media.enforce_same_site_origin", false);
C:\Program Files\Minefield\greprefs\all.js - pref("media.cache_size", 51200);
C:\Program Files\Minefield\greprefs\all.js - pref("media.ogg.enabled", true);
C:\Program Files\Minefield\greprefs\all.js - pref("media.wave.enabled", true);
C:\Program Files\Minefield\greprefs\all.js - pref("media.autoplay.enabled", true);
C:\Program Files\Minefield\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
C:\Program Files\Minefield\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
C:\Program Files\Minefield\greprefs\all.js - pref("dom.storage.default_quota", 5120);
C:\Program Files\Minefield\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
C:\Program Files\Minefield\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
C:\Program Files\Minefield\greprefs\all.js - pref("layout.css.dpi", -1);
C:\Program Files\Minefield\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
C:\Program Files\Minefield\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
C:\Program Files\Minefield\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
C:\Program Files\Minefield\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
C:\Program Files\Minefield\greprefs\all.js - pref("geo.enabled", true);
C:\Program Files\Minefield\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
C:\Program Files\Minefield\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "");
C:\Program Files\Minefield\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "");
C:\Program Files\Minefield\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-f-CN", "");
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
C:\Program Files\Minefield\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
.
------- File Associations -------
.
regedit=regedit.exe "%1"
regfile=regedit.exe "%1" %*
scrfile="%1" %*
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-05 00:52:03
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msiserver]
"ImagePath"="%systemroot%\system32\msiexec /V"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 00\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 01\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 02\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318} 03\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(1456)
C:\Program Files\Adobe\Reader 8.0\Reader\viewerps.dll
.
Completion time: 2009-08-05 0:55:15
ComboFix-quarantined-files.txt 2009-08-05 04:54:50
Pre-Run: 137,229,918,208 bytes free
Post-Run: 137,412,472,832 bytes free
348 --- E O F --- 2009-06-25 17:41:05