ComboFix 09-01-21.04 - Mom 2009-01-23 19:57:29.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.646 [GMT -5:00]
Running from: c:\documents and settings\Mom\Desktop\ComboFix.exe
AV: AT&T Internet Security Suite AT&T Anti-Virus *On-access scanning disabled* (Updated)
FW: AT&T Internet Security Suite AT&T Firewall *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - system32: deleted 1031 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Charlie\Favorites\Download programs.url
c:\documents and settings\Charlie\Favorites\Games.url
c:\documents and settings\Charlie\Favorites\Translator.url
c:\documents and settings\Charlie\Favorites\Videos.url
c:\documents and settings\Charlie\Start Menu\Programs\Download programs.url
c:\documents and settings\Charlie\Start Menu\Programs\Games.url
c:\documents and settings\Charlie\Start Menu\Programs\Translator.url
c:\documents and settings\Charlie\Start Menu\Programs\Videos.url
c:\windows\dat.txt
c:\windows\search_res.txt
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\kujonuva.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tagetega.dll
c:\windows\system32\tb.dr
c:\windows\system32\tmp.reg
c:\windows\system32\ujozimug.ini
c:\windows\system32\uydympqm.ini
c:\windows\system32\VCCLSID.exe
c:\windows\system32\vinelewe.dll
c:\windows\system32\WS2Fix.exe
c:\windows\system32\xiqkwvpu.ini
c:\windows\Tasks\owuhvlpg.job
c:\windows\Tasks\wnqgpdeb.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ISEXENG
-------\Legacy_SVCPROC
-------\Legacy_ZESOFT
((((((((((((((((((((((((( Files Created from 2008-12-24 to 2009-01-24 )))))))))))))))))))))))))))))))
.
2009-01-23 19:44 . 2009-01-23 19:46 <DIR> d-------- C:\32788R22FWJFW
2009-01-21 20:24 . 2009-01-21 20:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-01-21 16:10 . 2009-01-21 16:12 <DIR> d-------- c:\program files\Executive Software
2009-01-19 17:31 . 2009-01-19 17:31 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-01-19 13:44 . 2009-01-19 13:44 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-19 13:44 . 2009-01-19 13:44 <DIR> d-------- c:\documents and settings\Mom\Application Data\Malwarebytes
2009-01-19 13:44 . 2009-01-19 13:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-19 13:44 . 2009-01-14 16:11 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-01-19 13:44 . 2009-01-14 16:11 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys
2009-01-17 13:20 . 2009-01-17 13:20 <DIR> d-------- c:\program files\PCPitstop
2009-01-16 18:13 . 2009-01-16 18:13 <DIR> d-------- c:\program files\Trend Micro
2009-01-15 03:37 . 2009-01-15 03:37 42,320 --a------ c:\windows\SYSTEM32\xfcodec.dll
2009-01-14 20:31 . 2009-01-23 19:52 <DIR> d-------- c:\documents and settings\Administrator\Application Data\AVG7
2009-01-14 20:23 . 2009-01-14 20:23 <DIR> d-------- c:\documents and settings\Mom\Application Data\acccore
2009-01-14 20:13 . 2009-01-14 20:13 <DIR> d-------- c:\documents and settings\Administrator\Application Data\acccore
2009-01-14 20:11 . 2009-01-14 20:11 <DIR> d-------- c:\program files\Viewpoint
2009-01-14 20:11 . 2009-01-14 20:11 <DIR> d-------- c:\program files\Common Files\Software Update Utility
2009-01-14 20:11 . 2009-01-14 20:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\AIM Toolbar
2009-01-14 20:11 . 2009-01-14 20:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\acccore
2009-01-14 20:10 . 2009-01-14 20:10 <DIR> d-------- c:\documents and settings\All Users\Application Data\AOL OCP
2009-01-14 20:09 . 2009-01-14 20:12 <DIR> d-------- c:\program files\AIM6
2009-01-14 19:54 . 2009-01-23 20:10 <DIR> d-------- c:\program files\Xfire
2009-01-12 22:21 . 2009-01-12 22:21 57,270 --a------ c:\windows\RGI19D.tmp
2009-01-01 04:15 . 2009-01-01 04:15 <DIR> d-------- c:\documents and settings\Mom\Application Data\Eltima Software
2008-12-28 00:39 . 2008-12-28 00:39 <DIR> d-------- c:\documents and settings\Mom\.narya
2008-12-28 00:30 . 2008-12-28 00:39 <DIR> d-------- c:\documents and settings\Mom\Application Data\bang
2008-12-24 12:31 . 2008-12-24 12:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Freedom
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-01-24 00:53 --------- d-----w c:\documents and settings\All Users\Application Data\Avg7
2009-01-24 00:52 --------- d-----w c:\documents and settings\Mom\Application Data\AVG7
2009-01-24 00:52 --------- d-----w c:\documents and settings\Charlie\Application Data\AVG7
2009-01-24 00:52 --------- d-----w c:\documents and settings\All Users\Application Data\Grisoft
2009-01-23 21:22 --------- d-----w c:\documents and settings\Mom\Application Data\Xfire
2009-01-23 01:06 --------- d-----w c:\documents and settings\Mom\Application Data\Apple Computer
2009-01-22 01:33 --------- d-----w c:\program files\HP
2009-01-21 00:59 --------- d-----w c:\program files\CCleaner
2009-01-16 03:12 --------- d-----w c:\program files\Google
2009-01-15 01:11 --------- d-----w c:\program files\AIM Toolbar
2009-01-15 01:10 --------- d-----w c:\documents and settings\All Users\Application Data\AOL
2009-01-08 23:51 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-19 23:26 --------- d-----w c:\program files\TVersity Codec Pack
2008-12-14 21:08 --------- d-----w c:\documents and settings\Charlie\Application Data\BitTorrent
2008-12-09 00:21 --------- d-----w c:\documents and settings\Charlie\Application Data\Eltima Software
2008-12-09 00:19 --------- d-----w c:\program files\Eltima Software
2008-11-28 21:54 --------- d-----w c:\program files\MFInstall
2007-10-09 19:19 774,144 ----a-w c:\program files\RngInterstitial.dll
2007-08-22 21:03 84,200 ----a-w c:\documents and settings\Mom\Application Data\GDIPFONTCACHEV1.DAT
2005-03-29 01:28 32 ----a-r c:\documents and settings\All Users\hash.dat
1601-01-01 00:12 49,152 --sha-w c:\windows\SYSTEM32\nuyimuto.dll
2008-09-04 01:47 32,768 --sha-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012008090320080 904\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"NvMediaCenter"="c:\windows\system32\NvMcTray. dll" [2005-12-10 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-10 7311360]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2002-09-10 368706]
"ADUserMon"="c:\program files\Iomega\AutoDisk\ADUserMon.exe" [2002-09-24 147456]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 679936]
"HelpCenter4.1"="c:\program files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe" [2007-06-28 198184]
"ISW.exe"="c:\program files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 2061816]
"AT&T Internet Security Suite"="c:\program files\AT&T\AT&T Internet Security Suite\Rps.exe" [2007-06-28 310000]
"-FreedomNeedsReboot"="c:\program files\AT&T\AT&T Internet Security Suite\ZkRunOnceR.exe" [2007-06-28 13552]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"SearchSettings"="c:\program files\Search Settings\SearchSettings.exe" [2008-06-12 991584]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"nwiz"="nwiz.exe" [2005-12-10 c:\windows\SYSTEM32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2007-08-24 437160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.e xe" [2004-08-04 44544]
"RunNarrator"="Narrator.exe" [2008-04-13 c:\windows\SYSTEM32\narrator.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-05-12 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=qqlhcy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\
0autocheck autochk *\
0SsiEfr.e
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²#*Kh'þ9Óœ÷3rÅWC:
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²#*Kh'þ9Óœ÷3rÅWC:\Program Files
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Á²#*Kh'þ9Óœ÷3rÅWc:\program files\ISTsvc
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\È Ý8¿Ì*û]Mú*ÀaîžaaîC:
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\È Ý8¿Ì*û]Mú*ÀaîžaaîC:\Program Files
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\È Ý8¿Ì*û]Mú*Àaîžaaîc:\program files\ISTsvc
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\È Ý8Ý8¿Ì*û]Mú*ÀaîžaC:
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\È Ý8Ý8¿Ì*û]Mú*ÀaîžaC:\Program Files
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\È Ý8Ý8¿Ì*û]Mú*Àaîžac:\program files\ISTsvc
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\È Ý8Ý8Ý8¿Ì*ÀaîžaaûYC:
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\È Ý8Ý8Ý8¿Ì*ÀaîžaaûYC:\Program Files
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\È Ý8Ý8Ý8¿Ì*ÀaîžaaûYc:\program files\ISTsvc
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\È Ý8Ý8¿Ì*û]Mú*Àaîžac:\program files\ISTsvc\istsvc.exe]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\È Ý8Ý8Ý8¿Ì*ÀaîžaaûYc:\program files\ISTsvc\istsvc.exe]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\TVersity\\Media Server\\MediaServer.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1129949939\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\BellSouth\\HelpCenter40b\\bin\\sprtcmd.exe" =
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"c:\\Program Files\\TVersity\\Media Server\\web\\admin\\TVersity.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3724:TCP"= 3724:TCP:Blizzard Downloader
"41952:TCP"= 41952:TCP:TVersity
"<NO NAME>"=
R3 Envy24HFS;ICE Envy24 Family Audio Controller WDM;c:\windows\SYSTEM32\DRIVERS\Envy24HF.sys [2007-03-15 627840]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2009-01-14 24652]
R4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S0 mxubz;mxubz;c:\windows\system32\drivers\risgbi.sys --> c:\windows\system32\drivers\risgbi.sys [?]
S3 ati2mpaa;ati2mpaa;c:\windows\SYSTEM32\DRIVERS\ati2 mpaa.sys [2002-10-02 281856]
S3 MAUSBML;Service for M-Audio Producer USB (WDM);c:\windows\SYSTEM32\DRIVERS\mausbpr.sys [2007-12-27 124800]
S3 Radialpoint Security Services;AT&T Internet Security Suite;c:\windows\SYSTEM32\dllhost.exe [2002-08-29 5120]
S4 MAudioProducerService;M-Audio Producer USB Installer;c:\program files\M-Audio\Producer USB\MAUSBProducerInst.exe --> c:\program files\M-Audio\Producer USB\MAUSBProducerInst.exe [?]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{51d36da2-7501-11dc-b4ff-00c0a8890b0f}]
\Shell\AutoRun\command - E:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
2009-01-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-01-24 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
BHO-{1383D8A3-48B1-6708-0123-65C21E8FC287} - (no file)
BHO-{48402D05-D56F-6350-571A-7E24DA5A5A4B} - (no file)
Toolbar-{71AAC9BD-5B37-4279-AC9D-77805C6D9D6B} - (no file)
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-Microsoft Works Update Detection - c:\program files\Microsoft Works\WkDetect.exe
HKCU-Run-Aim6 - (no file)
SharedTaskScheduler-{FB153DCE-822E-47ec-8D00-2706E7864B37} - (no file)
MSConfigStartUp-istsvc - c:\windows\fxymdq.exe
MSConfigStartUp-istsvc - (no file)
.
------- Supplementary Scan -------
.
uStart Page = about
:blank
mSearch Bar = hxxp://websearch.drsnsrch.com/sidesearch.cgi?id=
uInternet Connection Wizard,ShellNext = iexplore
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
IE: &Search
IE: Ask Jeeves Search - c:\windows\System32\askbarAB.dll/cmd-search-selection
IE: Dictionary Search - c:\windows\System32\askbarAB.dll/cmd-search-selection-word
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {EA7F451B-94DD-4009-A8BF-8F977B0B2696} - hxxp://pbells.broadjump.com/wizlet/StandardInstall/static/controls/WebflowActiveXInstaller_4-2-0.cab
FF - ProfilePath - c:\documents and settings\Mom\Application Data\Mozilla\Firefox\Profiles\okdq0i01.default\
FF - prefs.
js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPJPI150_09.dll
FF - plugin: c:\program files\Java\jre1.5.0_09\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npBattlerapPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCID.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dl l
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDCE08D86 A-A41A-410A-943C-13BABB7DC474", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDA9EDC9E D-603A-4F3F-BBEA-59C8853A3236", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID90D1094 2-D952-4863-9DD6-A2BDBBAD456E", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID0ECEE74 4-7B69-4912-AB91-AE76D61ECB04", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDF25635B 2-1AB9-47B5-88D1-8877B22C86DE", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID27B7F81 2-4159-45B9-A389-B7A118A58DE4", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDF849DF2 9-393B-4F8B-99D1-117A70D66FC7", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDBF1E9C3 D-637C-4171-BD12-28A7360B879A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDDE1C060 1-7947-4D7F-A6E5-E68BF6BA1E37", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID4EA0DCC E-4D98-4876-9C6A-E5C563D0820A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID446462B A-2AAD-4C88-BC63-5210E2F31465", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID0862E36 8-A40E-4E55-83EB-FBC5571BABA4", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDD2A96E3 C-FFB3-4D38-9AC3-B127527BEA35", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID4B05B39 A-9DDC-4650-A7F8-D5B134E5FFE5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDC8E2574 A-7BCE-4B93-A22E-61831DFD6DB8", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID659796C 0-8B5D-48D7-A4EB-7E6874E26274", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID78071AB 5-E729-414E-8D02-9C1D034F82E7", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDCC3F71E 1-17F3-4C5B-997D-44CA56943197", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDE67D5C7 8-B2D4-4BA0-8D69-1C7AF4BB08B5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDFC5F3D7 A-D321-412C-8A5D-9AD0C8041941", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID6EC5CD1 6-81BC-4515-9EDD-9265C906F56E", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID67CFB2C 5-E491-4395-977B-CD45E4124655", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID7360056 9-52E6-4760-8BAB-B68202937D98", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDB02EBD4 2-6885-401A-9389-E089F7DDC872", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDBAE5CB8 C-4075-4743-B2E4-78DA8D8CDC64", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID28B07B0 4-DA99-4FD3-BF27-4972F2B8142B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID0D53448 F-D12B-4102-8CE2-697DAE8D6643", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDE3266A4 7-A141-47B8-AAA8-5F16FB4F8CCD", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDB33AB7A F-76D7-4B1C-B709-5D6BF9E7B1C7", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID153B745 1-0BB5-4B37-95C0-44D89E2F1F2B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID3BBE8E2 1-0D3D-4BAA-AC6F-C7BCEF750849", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID9B5B4F2 D-A7D9-4329-B0FE-92B301A8CAAD", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDA5C4292 1-8CD0-4924-97C3-01B5B0610BC6", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID0696925 2-F90F-4CF2-9074-33772EB64859", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDFBF3765 5-1236-4C0D-96C5-F94E1724841B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDC1A3F03 5-B68F-4B2B-9FD5-E36DAAAF26DD", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID368F368 5-543E-4812-9FDE-96E097E453FC", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID4396987 3-56AA-4113-84CB-4AB2AEB9AA31", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDA205DD8 0-63D4-4E41-B785-26EC3D90B97B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID068D43E 7-7551-4A2F-AE96-4A38A9AD1953", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDF443E9C B-9EEC-456E-8AE7-F3102D5CD47D", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDE36A7B1 6-645D-4261-BFF8-3A7E69C5F7A5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID379805E 3-E0E2-40DC-B51B-6DC1AE5802AA", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDF6240D6 9-A06D-44A1-8003-8496CCEF2C53", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID26C3113 D-5A71-4F1B-A2CB-BE59E1279DDA", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID92B97F2 B-7565-4CE9-9AC7-0598DFD731F8", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID2AA5E7C F-9696-42F0-B76A-8655296EADF2", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID0AAACE0 B-ACEF-4781-83F4-BFB52EEC995A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID0D56FF5 8-A39D-4E8C-A40B-2E3711251772", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID946121C 2-11F1-49DD-A7E3-CF793DE827A4", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CIDB853303 D-1BAB-43F3-9D7D-101D0DA8E7A5", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID9E57824 7-FE29-4F8C-8202-A24A5688CF2A", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID6D065A8 F-FFC0-4A0F-B863-1D724B8C786B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID4451D29 1-6940-42CE-9D3C-CA1D4C96549C", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID064B722 D-079D-4EBB-B3CF-9FCBF64FFF5D", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID38F8AB0 F-5DFB-43D9-889E-8717CC4AB59B", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID4EC68CD 1-0EF1-4CB9-9EF1-3D64AB266149", "AllAccess");
c:\program files\Mozilla Firefox\defaults\pref\activex.
js - pref("capability.policy.default.ClassID.CID44F96B2 7-CFAD-41E1-83A1-6B28040C3BDE", "AllAccess");
.
************************************************** ************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-23 20:11:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\I omega Activity Disk2]
"ImagePath"="\"\""
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AT&T\AT&T Internet Security Suite\Fws.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\SYSTEM32\CTSVCCDA.EXE
c:\program files\Executive Software\DiskeeperLite\DKService.exe
c:\program files\Common Files\Authentium\AntiVirus\dvpapi.exe
c:\progra~1\Iomega\System32\AppServices.exe
c:\program files\CA\PPRT\bin\ITMRTSVC.exe
c:\windows\SYSTEM32\nvsvc32.exe
c:\program files\Raxco\PerfectDisk\PDAgent.exe
c:\program files\TVersity\Media Server\MediaServer.exe
c:\windows\SYSTEM32\MsPMSPSv.exe
c:\program files\Iomega\AutoDisk\ADService.exe
c:\windows\SYSTEM32\wscntfy.exe
c:\windows\SYSTEM32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\AT&T\Internet Security Wizard\ISWComHandler.exe
c:\program files\AT&T\AT&T Internet Security Suite\rpsupdaterR.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
.
************************************************** ************************
.
Completion time: 2009-01-23 20:23:00 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-24 01:22:53
Pre-Run: 286,228,480 bytes free
Post-Run: 4,942,782,464 bytes free
342 --- E O F --- 2008-12-12 21:02:22