ComboFix 09-09-22.03 - VIC 09/24/2009 12:24.2.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1683 [GMT -4:00]
Running from: c:\documents and settings\VIC\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\VIC\Desktop\CFScript.txt
AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FILE ::
"C:\GAME.EXE"
"c:\windows\svohost.exe"
"c:\windows\system32\as.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\VIC\LOCALS~1\Temp\E_4
c:\docume~1\VIC\LOCALS~1\Temp\E_4\krnln.fnr
c:\docume~1\VIC\LOCALS~1\Temp\E_4\shell.fne
C:\GAME.EXE
c:\windows\svohost.exe
c:\windows\system32\as.exe
.
((((((((((((((((((((((((( Files Created from 2009-08-24 to 2009-09-24 )))))))))))))))))))))))))))))))
.
2009-09-17 19:18 . 2009-09-17 19:18 -------- d-----w- c:\documents and settings\VIC\Application Data\DivX
2009-09-12 03:54 . 2009-09-12 03:54 -------- d-----w- C:\Nexon
2009-09-12 02:29 . 2009-09-12 05:11 -------- d-----w- c:\documents and settings\VIC\Local Settings\Application Data\PMB Files
2009-09-12 02:29 . 2009-09-12 02:30 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2009-09-12 02:28 . 2009-09-12 02:28 -------- d-----w- c:\program files\Pando Networks
2009-09-06 17:40 . 2009-09-06 17:41 -------- d-----w- c:\documents and settings\VIC\.gimp-2.6
2009-09-06 17:40 . 2009-09-06 17:40 -------- d-----w- c:\program files\GIMP-2.0
2009-09-06 17:33 . 2009-09-06 17:33 -------- d-----w- c:\documents and settings\VIC\Application Data\NJStar
2009-09-06 17:33 . 2009-09-06 17:33 -------- d-----w- c:\program files\NJStar Chinese WP
2009-09-05 22:01 . 2009-09-18 19:42 -------- d-----w- c:\program files\ZillaTube
2009-09-05 18:33 . 2009-09-12 20:38 45 ----a-w- c:\documents and settings\VIC\jagex_runescape_preferences2.dat
2009-09-05 15:04 . 2009-09-05 15:04 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-08-30 15:49 . 2009-08-30 15:49 -------- d-----w- c:\program files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-24 16:13 . 2009-07-06 11:27 -------- d-----w- c:\program files\Steam
2009-09-24 02:26 . 2009-07-06 12:45 2020 ----a-w- c:\documents and settings\VIC\Application Data\wklnhst.dat
2009-09-21 22:26 . 2009-07-06 15:28 -------- d-----w- c:\program files\Starcraft
2009-09-13 02:21 . 2009-07-07 04:03 37 ----a-w- c:\documents and settings\VIC\jagex_runescape_preferences.dat
2009-08-21 21:50 . 2009-08-21 21:50 -------- d-----w- c:\program files\iTunes
2009-08-21 21:50 . 2009-08-21 21:50 -------- d-----w- c:\program files\iPod
2009-08-21 21:50 . 2009-07-06 11:31 -------- d-----w- c:\program files\Common Files\Apple
2009-08-21 19:29 . 2009-08-21 19:29 -------- d-----w- c:\program files\Dialsoft
2009-08-19 22:07 . 2009-08-19 23:04 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-08-19 22:04 . 2009-07-06 13:53 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-05 09:11 . 2004-08-04 10:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 18:55 . 2004-08-04 10:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 06:18 . 2004-08-04 10:00 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-06 15:32 . 2009-07-06 15:28 32930 ----a-w- c:\windows\scunin.dat
2009-07-06 15:32 . 2009-07-06 15:28 967 ----a-w- c:\windows\ScUnin.pif
2009-07-06 15:32 . 2009-07-06 15:28 94208 ----a-w- c:\windows\ScUnin.exe
2009-07-06 14:08 . 2009-07-06 14:08 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-06 13:23 . 2009-07-06 11:29 30112 ----a-w- c:\documents and settings\VIC\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-06 12:48 . 2009-07-06 12:48 50 ----a-w- c:\windows\system32\bridf06a.dat
2009-07-06 11:22 . 2009-07-06 11:22 0 ----a-w- c:\windows\nsreg.dat
2009-07-06 04:00 . 2009-07-06 04:00 21640 ----a-w- c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2009-07-06 1217784]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-06-28 622592]
"SetDefPrt"="c:\program files\Brother\Brmfl06a\BrStDvPt.exe" [2005-01-26 49152]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2006-06-29 77824]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-08-19 520024]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-06 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-20 282624]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Steam\\steamapps\\theloserpunk69@yahoo.com\\counter-strike\\hl.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56834:TCP"= 56834:TCP:Pando Media Booster
"56834:UDP"= 56834:UDP:Pando Media Booster
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/6/2009 9:53 AM 64160]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456]
.
Contents of the 'Scheduled Tasks' folder
2009-09-07 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 22:03]
2009-09-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\VIC\Application Data\Mozilla\Firefox\Profiles\ru5wlrsk.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-24 12:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2009-09-24 12:28
ComboFix-quarantined-files.txt 2009-09-24 16:28
ComboFix2.txt 2009-09-23 20:57
Pre-Run: 55,763,804,160 bytes free
Post-Run: 55,732,736,000 bytes free
148 --- E O F --- 2009-09-10 02:47
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, September 24, 2009
Operating system: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, September 24, 2009 18:41:41
Records in database: 2914331
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
Scan statistics:
Objects scanned: 43312
Threats found: 1
Infected objects found: 14
Suspicious objects found: 0
Scan duration: 00:57:29
File name / Threat / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\svchost.exe.vir Infected: Virus.Win32.ZloyFly.b 1
C:\Qoobox\Quarantine\[4]-Submit_2009-09-24_12.24.16.zip Infected: Virus.Win32.ZloyFly.b 3
C:\System Volume Information\_restore{5EFD8754-DCA6-44AC-B868-C633500548F2}\RP57\A0004136.EXE Infected: Virus.Win32.ZloyFly.b 1
C:\System Volume Information\_restore{5EFD8754-DCA6-44AC-B868-C633500548F2}\RP57\A0004142.EXE Infected: Virus.Win32.ZloyFly.b 1
C:\System Volume Information\_restore{5EFD8754-DCA6-44AC-B868-C633500548F2}\RP57\A0004143.EXE Infected: Virus.Win32.ZloyFly.b 1
C:\System Volume Information\_restore{5EFD8754-DCA6-44AC-B868-C633500548F2}\RP57\A0004144.EXE Infected: Virus.Win32.ZloyFly.b 1
C:\System Volume Information\_restore{5EFD8754-DCA6-44AC-B868-C633500548F2}\RP58\A0004280.EXE Infected: Virus.Win32.ZloyFly.b 1
C:\System Volume Information\_restore{5EFD8754-DCA6-44AC-B868-C633500548F2}\RP60\A0004328.EXE Infected: Virus.Win32.ZloyFly.b 1
C:\System Volume Information\_restore{5EFD8754-DCA6-44AC-B868-C633500548F2}\RP62\A0004425.EXE Infected: Virus.Win32.ZloyFly.b 1
C:\System Volume Information\_restore{5EFD8754-DCA6-44AC-B868-C633500548F2}\RP75\A0007843.exe Infected: Virus.Win32.ZloyFly.b 1
C:\System Volume Information\_restore{5EFD8754-DCA6-44AC-B868-C633500548F2}\RP75\A0007948.exe Infected: Virus.Win32.ZloyFly.b 1
F:\GAME.EXE Infected: Virus.Win32.ZloyFly.b 1
Selected area has been scanned.
DDS (Ver_09-07-30.01) - NTFSx86
Run by VIC at 13:08:20.87 on Thu 09/24/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1510 [GMT -4:00]
AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\VIC\My Documents\Downloads\dds.scr
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe
mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [SetDefPrt] c:\program files\brother\brmfl06a\BrStDvPt.exe
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1246882787671
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\vic\applic~1\mozilla\firefox\profiles\ru5wlrsk.default\
FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-7-6 64160]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1029456]
=============== Created Last 30 ================
2009-09-24 13:02 73,728 a------- c:\windows\system32\javacpl.cpl
2009-09-24 12:52 95 a------- c:\windows\system32\productregistry
2009-09-24 12:51 <DIR> --d----- C:\Sun
2009-09-24 12:34 <DIR> --d----- c:\documents and settings\vic\.SunDownloadManager
2009-09-23 16:53 <DIR> a-dshr-- C:\cmdcons
2009-09-23 16:53 229,888 a------- c:\windows\PEV.exe
2009-09-23 16:53 161,792 a------- c:\windows\SWREG.exe
2009-09-23 16:53 98,816 a------- c:\windows\sed.exe
2009-09-11 23:54 <DIR> --d----- C:\Nexon
2009-09-11 22:29 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PMB Files
2009-09-11 22:28 <DIR> --d----- c:\program files\Pando Networks
2009-09-06 13:40 <DIR> --d----- c:\documents and settings\vic\.gimp-2.6
2009-09-06 13:40 <DIR> --d----- c:\program files\GIMP-2.0
2009-09-06 13:33 <DIR> --d----- c:\docume~1\vic\applic~1\NJStar
2009-09-06 13:33 <DIR> --d----- c:\program files\NJStar Chinese WP
2009-09-05 18:01 <DIR> --d----- c:\program files\ZillaTube
2009-09-05 14:33 45 a------- c:\documents and settings\vic\jagex_runescape_preferences2.dat
2009-09-05 11:04 <DIR> --d----- c:\docume~1\alluse~1\applic~1\McAfee.com
2009-08-30 11:49 <DIR> --d----- c:\program files\Trend Micro
==================== Find3M ====================
2009-09-23 22:26 2,020 a------- c:\docume~1\vic\applic~1\wklnhst.dat
2009-09-12 22:21 37 a------- c:\documents and settings\vic\jagex_runescape_preferences.dat
2009-08-19 18:07 15,688 a------- c:\windows\system32\lsdelete.exe
2009-08-19 18:04 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-08-05 05:11 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-31 15:23 411,368 a------- c:\windows\system32\deploytk.dll
2009-07-17 14:55 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 02:18 233,472 a------- c:\windows\system32\wmpdxm.dll
2009-07-06 11:32 94,208 a------- c:\windows\ScUnin.exe
2009-07-06 11:32 32,930 a------- c:\windows\scunin.dat
2009-07-06 09:28 77,423 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-07-06 00:00 21,640 a------- c:\windows\system32\emptyregdb.dat
============= FINISH: 13:08:26.68 ===============