Hey!
Here is the log:
ComboFix 09-12-07.01 - Matt 07/12/2009 23:13.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.159 [GMT 0:00]
Running from: c:\documents and settings\Matt\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Matt\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 091207-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\All Users\Application Data\Microsoft\WLSetup
c:\documents and settings\All Users\Application Data\Microsoft\WLSetup\Logs\2009-07-07_14-10_b14-daj8qfb3.log
c:\documents and settings\All Users\Application Data\Microsoft\WLSetup\Logs\2009-11-12_11-08_c9c-t9jq2t2p.log
c:\documents and settings\All Users\Application Data\Microsoft\WLSetup\Logs\2009-11-20_17-31_a64-0n1ysqh8.log
c:\documents and settings\All Users\Application Data\Microsoft\WLSetup\wltF5.tmp
.
--------------- FCopy ---------------
c:\windows\$NtServicePackUninstall$\eventlog.dll --> c:\windows\System32\eventlog.dll
.
((((((((((((((((((((((((( Files Created from 2009-11-07 to 2009-12-07 )))))))))))))))))))))))))))))))
.
2009-12-07 23:13 . 2004-08-04 05:00 55808 ----a-w- c:\windows\system32\eventlog.dll
2009-12-07 23:13 . 2004-08-04 05:00 55808 ----a-w- c:\windows\system32\dllcache\eventlog.dll
2009-11-30 21:06 . 2009-11-30 21:11 -------- d-----w- c:\documents and settings\Matt\Application Data\Movie Torrent
2009-11-30 21:06 . 2009-11-30 21:06 -------- d-----w- c:\documents and settings\Matt\Local Settings\Application Data\Conduit
2009-11-30 21:06 . 2009-11-30 21:06 -------- d-----w- c:\program files\Conduit
2009-11-30 21:06 . 2009-11-30 21:06 -------- d-----w- c:\documents and settings\Matt\Local Settings\Application Data\P2P_Energy
2009-11-30 21:06 . 2009-11-30 21:06 -------- d-----w- c:\program files\P2P_Energy
2009-11-30 21:04 . 2009-11-30 21:55 -------- d-----w- c:\program files\Movie Torrent
2009-11-30 16:53 . 2009-12-07 11:42 34160 ----a-w- c:\documents and settings\Malc\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-30 16:15 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-30 16:15 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-30 16:15 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-30 16:15 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-30 16:15 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-30 16:15 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-30 16:15 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-30 16:15 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-30 16:14 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-30 16:14 . 2009-11-30 16:14 -------- d-----w- c:\program files\Alwil Software
2009-11-30 15:34 . 2009-11-30 15:34 -------- d-----w- C:\AVGTemp
2009-11-29 19:40 . 2009-11-29 19:40 4045528 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-11-29 19:39 . 2009-09-10 14:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-29 19:39 . 2009-11-29 19:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-29 19:39 . 2009-09-10 14:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-29 16:32 . 2009-11-29 16:32 -------- d-----w- c:\windows\system32\wbem\Repository
2009-11-27 23:15 . 2009-11-27 23:15 -------- d-----w- c:\documents and settings\LocalService\IETldCache
2009-11-27 15:33 . 2009-11-27 15:33 -------- d-----w- c:\documents and settings\Ann\Application Data\Apple Computer
2009-11-25 23:27 . 2009-11-25 23:27 -------- d-----w- c:\documents and settings\Ann\Local Settings\Application Data\Temp
2009-11-25 10:40 . 2009-11-25 10:40 -------- d-----w- C:\found.000
2009-11-22 20:08 . 2009-11-22 20:08 4286 ----a-r- c:\documents and settings\Matt\Application Data\Microsoft\Installer\{D2D1CFB2-1B70-451C-AD66-3193368B7683}\_B9F43533A67D917C3D3CFD.exe
2009-11-22 20:08 . 2009-11-22 20:08 4286 ----a-r- c:\documents and settings\Matt\Application Data\Microsoft\Installer\{D2D1CFB2-1B70-451C-AD66-3193368B7683}\_377F621D98CD78E4DC325F.exe
2009-11-20 17:37 . 2009-11-20 17:37 -------- d-----w- c:\program files\Microsoft
2009-11-15 12:01 . 2009-11-15 12:01 -------- d-----w- c:\documents and settings\Malc\Application Data\DivX
2009-11-15 12:01 . 2009-11-15 12:01 -------- d-----w- c:\documents and settings\Malc\Application Data\Media Player Classic
2009-11-14 22:20 . 2009-12-06 22:34 -------- d-----w- c:\documents and settings\Matt\Local Settings\Application Data\Temp
2009-11-14 22:20 . 2009-11-14 22:20 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-11-14 22:19 . 2009-12-06 22:35 -------- d-----w- c:\program files\Google
2009-11-14 22:19 . 2009-11-14 22:24 -------- d-----w- c:\documents and settings\Matt\Local Settings\Application Data\Google
2009-11-14 19:57 . 2009-11-14 19:58 -------- d-----w- c:\documents and settings\Matt\Application Data\Media Player Classic
2009-11-14 19:46 . 2009-11-14 19:46 -------- d-----w- c:\documents and settings\Matt\Application Data\DivX
2009-11-14 19:43 . 2009-09-25 16:42 9464 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-11-14 19:43 . 2009-09-25 16:42 9336 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-11-14 19:43 . 2009-09-25 16:42 129784 ------w- c:\windows\system32\pxafs.dll
2009-11-14 19:42 . 2009-11-14 19:52 -------- d-----w- c:\program files\DivX
2009-11-14 19:42 . 2009-11-14 19:43 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-11-14 19:39 . 2001-11-09 00:19 53248 ----a-w- c:\windows\system32\MMTray.exe
2009-11-14 19:39 . 2002-01-16 13:45 224256 ----a-w- c:\windows\system32\MMIJG32.dll
2009-11-14 19:39 . 2009-11-14 19:39 -------- d-----w- c:\program files\Morgan
2009-11-14 19:24 . 2009-11-14 19:24 -------- d-----w- c:\program files\4Videosoft Studio
2009-11-08 11:20 . 2009-11-27 15:33 -------- d-----w- c:\documents and settings\Ann\Local Settings\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-07 23:07 . 2006-01-06 11:25 -------- d-----w- c:\program files\Java
2009-12-07 23:06 . 2009-07-14 16:20 -------- d-----w- c:\documents and settings\Matt\Application Data\uTorrent
2009-12-06 21:45 . 2009-07-14 22:11 -------- d-----w- c:\documents and settings\Matt\Application Data\vlc
2009-12-05 18:50 . 2009-07-05 23:45 34160 ----a-w- c:\documents and settings\Matt\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-03 00:46 . 2006-01-06 11:04 872064 ----a-w- c:\windows\system32\drivers\iastor.sys
2009-12-01 19:54 . 2009-07-27 17:50 -------- d-----w- c:\documents and settings\Matt\Application Data\AdobeUM
2009-11-22 20:10 . 2009-10-09 13:37 -------- d-----w- c:\program files\FriendAdderElite
2009-11-18 14:15 . 2009-08-30 00:37 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-14 19:57 . 2009-11-14 19:54 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-11-14 19:53 . 2006-01-06 11:31 -------- d-----w- c:\program files\Common Files\Real
2009-11-09 18:00 . 2009-11-14 19:54 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-11-05 15:27 . 2009-10-19 23:28 -------- d-----w- c:\documents and settings\Matt\Application Data\Apple Computer
2009-11-04 17:07 . 2009-11-04 17:07 -------- d-----w- c:\program files\iTunes
2009-11-04 17:07 . 2009-11-04 17:07 -------- d-----w- c:\program files\iPod
2009-11-04 17:07 . 2009-10-19 23:23 -------- d-----w- c:\program files\Common Files\Apple
2009-11-04 17:01 . 2009-11-04 17:01 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-03 21:20 . 2009-11-03 21:20 152576 ----a-w- c:\documents and settings\Matt\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-02 18:37 . 2009-11-02 14:05 -------- d-----w- c:\program files\Yahoo!
2009-11-02 16:09 . 2009-11-02 14:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-11-02 14:07 . 2009-11-02 14:07 -------- d-----w- c:\documents and settings\Matt\Application Data\Yahoo!
2009-10-28 15:14 . 2009-07-11 13:32 30984 ----a-w- c:\documents and settings\Ann\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-21 13:28 . 2009-10-19 23:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-10-19 23:28 . 2009-10-19 23:27 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-19 23:27 . 2009-10-19 23:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-10-19 23:27 . 2009-10-19 23:27 -------- d-----w- c:\program files\Bonjour
2009-10-19 23:27 . 2006-01-06 11:32 -------- d-----w- c:\program files\QuickTime
2009-10-19 23:24 . 2009-10-19 23:24 -------- d-----w- c:\program files\Apple Software Update
2009-10-11 04:17 . 2009-08-28 12:36 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-09 13:29 . 2009-10-09 13:29 -------- d-----w- c:\program files\Myspace Marketing Manager
2009-10-09 12:55 . 2009-10-09 12:49 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-10-09 12:26 . 2009-10-09 12:26 -------- d-----w- c:\program files\DAMN NFO Viewer
2009-10-09 11:43 . 2009-10-08 09:30 -------- d-----w- c:\program files\FriendBlasterPro
2009-09-29 12:23 . 2009-09-29 12:23 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-09-25 16:42 . 2009-07-01 22:54 120056 ------w- c:\windows\system32\pxcpyi64.exe
2009-09-25 16:42 . 2009-07-01 22:54 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-09-25 16:42 . 2005-04-25 02:03 43528 ------w- c:\windows\system32\drivers\pxhelp20.sys
2009-09-19 21:59 . 2009-09-19 21:56 52770576 ----a-w- c:\documents and settings\Matt\Application Data\Sony Setup\64993CD0-67D1-4244-A2BC-FD73F4DA5B62\dotnetfx3.exe
2009-09-11 14:18 . 2004-08-10 12:51 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-11-30_01.52.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-07 23:24 . 2009-12-07 23:24 16384 c:\windows\Temp\Perflib_Perfdata_5d4.dat
+ 2009-12-07 10:59 . 2009-12-07 10:59 16384 c:\windows\Temp\Perflib_Perfdata_5a0.dat
+ 2009-12-07 23:24 . 2009-12-07 23:24 16384 c:\windows\Temp\Perflib_Perfdata_3ec.dat
- 2009-07-01 22:49 . 2009-11-30 00:45 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-01 22:49 . 2009-12-05 14:59 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-01 22:49 . 2009-12-05 14:59 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-07-01 22:49 . 2009-11-30 00:45 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-07-01 22:49 . 2009-11-30 00:45 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-07-01 22:49 . 2009-12-05 14:59 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-12-01 19:54 . 2009-12-01 19:54 25214 c:\windows\Installer\{AC76BA86-7AD7-1033-7B44-A70000000000}\SC_Reader.exe
+ 2009-12-06 22:36 . 2009-12-06 22:36 25214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2009-12-06 22:36 . 2009-12-06 22:36 25214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-06 22:36 . 2009-12-06 22:36 25214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2009-12-06 22:36 . 2009-12-06 22:36 25214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2009-12-06 22:36 . 2009-12-06 22:36 25214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\googleearth.exe1_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-06 22:36 . 2009-12-06 22:36 25214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\googleearth.exe_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2009-12-06 22:36 . 2009-12-06 22:36 25214 c:\windows\Installer\{9074AFC0-CFDA-11DE-B484-005056806466}\ARPPRODUCTICON.exe
+ 2009-07-04 11:43 . 2009-12-05 14:59 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2009-07-04 11:43 . 2009-11-30 00:45 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2004-08-10 12:57 . 2009-12-05 21:42 2037320 c:\windows\system32\FNTCACHE.DAT
+ 2009-12-01 19:54 . 2009-12-01 19:54 2727936 c:\windows\Installer\cc826.msi
+ 2009-12-06 22:36 . 2009-12-06 22:36 1258496 c:\windows\Installer\2475a86.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{2bae58c2-79f9-45d1-a286-81f911301c3a}"= "c:\program files\P2P_Energy\tbP2P_.dll" [2009-10-27 2325528]
[HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
2009-10-27 11:45 2325528 ----a-w- c:\program files\P2P_Energy\tbP2P_.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2bae58c2-79f9-45d1-a286-81f911301c3a}"= "c:\program files\P2P_Energy\tbP2P_.dll" [2009-10-27 2325528]
[HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2004-07-19 306688]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-07-08 160592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-28 141600]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-1-6 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [03/08/2009 16:20 5248]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [30/11/2009 16:15 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/11/2009 16:15 20560]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [14/11/2009 22:20 135664]
S4 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [03/08/2009 16:20 160640]
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://search.conduit.com?SearchSource=10&ctid=CT1269415uInternet Connection Wizard,ShellNext = "c:\program files\Outlook Express\msimn.exe" //mailurl:mailto:?body=http%3A%2F%2Fimg004.lazygirls.info%2Fpeople%2Fmiley_cyrus%2Fmiley_cyrus_miley_wonder_world_concert_3__lJSPbXY.jpg&subject=
uInternet Settings,ProxyOverride = *.local
IE: Customize Menu -
file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Fill Forms -
file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar -
file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms -
file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
FF - ProfilePath - c:\documents and settings\Matt\Application Data\Mozilla\Firefox\Profiles\r7hezc8q.default\
FF - component: c:\program files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_31.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
Notify-avgrsstarter - avgrsstx.dll
AddRemove-Microsoft Interactive Training - c:\windows\IsUninst.exe -fc:\windows\orun32.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-07 23:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3288)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\stsystra.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-12-07 23:39 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-07 23:39
ComboFix2.txt 2009-11-30 02:01
Pre-Run: 171,498,233,856 bytes free
Post-Run: 171,455,713,280 bytes free
- - End Of File - - 5D84116C67B5DFB98CD6E3676E0EE2E8