Belahzur
Combofix / uninstall did a re-scan, see log below
When I tried to run eset online scan using IE I got the following message 'The requested lookup key was not found in any active activation context'. So I ran eset online scan on another PC and took the .exe to my PC. Then it ran OK, downloaded stuff etc. Log output below.
ComboFix 10-08-07.02 - Rob 13/08/2010 14:27:49.4.1 - x86
Running from: c:\documents and settings\Rob\Desktop\Combo-Fix.exe
Command switches used :: / uninstall
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2010-07-13 to 2010-08-13 )))))))))))))))))))))))))))))))
.
2010-08-08 15:52 . 2010-08-08 16:01 -------- d-----w- C:\Combo-Fix
2010-08-08 14:12 . 2010-08-08 14:12 -------- d-----w- c:\windows\dell
2010-08-08 13:38 . 2004-08-04 10:00 70144 -c--a-w- c:\windows\system32\dllcache\pintlphr.exe
2010-08-08 13:37 . 2004-08-04 10:00 18944 -c--a-w- c:\windows\system32\dllcache\cprofile.exe
2010-08-08 13:34 . 2004-08-04 10:00 7680 -c--a-w- c:\windows\system32\dllcache\migregdb.exe
2010-08-08 13:25 . 2004-08-04 10:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2010-08-08 13:25 . 2004-08-04 10:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2010-08-08 13:25 . 2004-08-04 10:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2010-08-08 13:25 . 2004-08-04 10:00 13312 ----a-w- c:\windows\system32\irclass.dll
2010-08-04 02:05 . 2010-08-04 02:05 -------- d-----w- c:\windows\system32\SeaPort
2010-08-03 23:50 . 2010-08-03 23:50 -------- d-----w- c:\windows\system32\InstallShield Installation Information
2010-08-02 04:38 . 2010-07-23 16:22 1496064 ----a-w- c:\documents and settings\Rob\Application Data\Mozilla\Firefox\Profiles\xa62z737.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-08-02 04:38 . 2010-07-23 16:22 43008 ----a-w- c:\documents and settings\Rob\Application Data\Mozilla\Firefox\Profiles\xa62z737.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-08-02 04:38 . 2010-07-23 16:22 338944 ----a-w- c:\documents and settings\Rob\Application Data\Mozilla\Firefox\Profiles\xa62z737.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-08-02 04:38 . 2010-07-23 16:22 346112 ----a-w- c:\documents and settings\Rob\Application Data\Mozilla\Firefox\Profiles\xa62z737.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-07-23 18:52 . 2010-08-01 16:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-07-23 18:52 . 2010-07-23 18:52 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-07-23 15:45 . 2010-07-23 15:45 56765 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-07-23 15:45 . 2010-07-23 15:45 57715 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-07-23 15:45 . 2010-07-23 15:45 84054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-07-23 15:44 . 2010-07-23 15:44 54153 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-07-23 15:27 . 2010-07-23 15:28 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-13 13:25 . 2007-09-06 20:32 -------- d-----w- c:\program files\Steam
2010-08-13 13:25 . 2007-02-13 10:44 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-08-13 13:24 . 2008-12-30 04:36 -------- d--h--w- c:\documents and settings\Rob\Application Data\DNA
2010-08-13 13:24 . 2008-12-30 04:36 -------- d-----w- c:\program files\DNA
2010-08-08 14:58 . 2006-09-29 18:32 43576 ----a-w- c:\documents and settings\Rob\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-03 19:02 . 2010-04-07 22:57 -------- d-----w- c:\documents and settings\Rob\Application Data\Xoik
2010-08-01 16:39 . 2006-09-27 13:30 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-07-23 18:52 . 2006-09-27 13:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-07-23 16:18 . 2010-06-24 11:02 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-23 16:18 . 2010-06-24 01:34 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-07-23 15:45 . 2007-05-10 15:41 -------- d-----w- c:\program files\DivX
2010-07-23 15:27 . 2010-06-24 02:24 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-07-23 15:27 . 2010-06-24 02:24 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-07-23 02:35 . 2008-05-29 01:52 -------- d-----w- c:\documents and settings\Rob\Application Data\uTorrent
2010-07-08 23:06 . 2010-07-08 23:06 4096 ----a-w- c:\windows\system32\drivers\nocashio.sys
2010-07-04 20:08 . 2006-09-27 13:37 -------- d-----w- c:\program files\Google
2010-06-28 04:52 . 2010-06-28 04:52 -------- d-----w- c:\program files\directx
2010-06-26 18:00 . 2009-06-11 15:36 64 ----a-w- c:\windows\popcinfot.dat
2010-06-24 02:24 . 2010-06-24 02:24 56997 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-06-24 02:24 . 2010-06-24 02:24 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-06-24 02:24 . 2007-11-10 20:51 -------- d--h--w- c:\documents and settings\Rob\Application Data\DivX
2010-06-24 02:23 . 2010-06-24 02:23 57054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-06-24 02:23 . 2010-06-24 02:23 54166 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-06-24 02:23 . 2010-06-24 02:23 57532 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-06-24 02:23 . 2010-06-24 02:23 56458 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-06-24 02:23 . 2010-06-24 02:23 54174 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-06-24 02:23 . 2010-06-24 02:23 54128 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe
2010-06-24 02:23 . 2010-06-24 02:23 54644 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-06-24 02:23 . 2010-06-24 02:23 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-06-24 02:23 . 2010-06-24 02:23 54101 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-24 02:23 . 2010-06-24 02:23 52963 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-06-24 02:22 . 2010-06-24 02:22 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-06-24 02:22 . 2010-06-24 02:22 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-06-24 02:22 . 2010-06-24 02:22 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-06-21 17:21 . 2010-03-20 21:41 -------- d-----w- c:\program files\SSPRO
2010-06-21 17:21 . 2002-08-01 15:35 35328 ----a-w- c:\windows\system32\wavmix32.dll
2007-01-01 14:25 . 2007-01-01 14:25 283960 -c--a-w- c:\program files\dxwebsetup.exe
2006-12-19 19:17 . 2006-12-19 19:17 0 ----a-w- c:\program files\pspbrwse.jbf
2009-04-18 21:22 . 2006-12-19 19:13 56 --sh--r- c:\windows\system32\0371BCE00C.sys
2009-03-04 13:10 . 2006-12-29 20:11 88 --sh--r- c:\windows\system32\0CE0BC7103.sys
2009-04-18 21:22 . 2006-10-01 13:44 6580 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
(((((((((((((((((((((((((((((
SnapShot@2010-08-08_15.59.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-13 13:22 . 2010-08-13 13:22 16384 c:\windows\temp\Perflib_Perfdata_780.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-28 68856]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"Steam"="c:\program files\steam\steam.exe" [2010-05-07 1238352]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2009-04-09 228808]
"Rainlendar2"="c:\program files\Rainlendar2\Rainlendar2.exe" [2009-08-22 5148672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2004-11-09 497240]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-09-27 26112]
"AOL Spyware Protection"="c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-03-19 78960]
"VSOCheckTask"="c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 151552]
"OASClnt"="c:\program files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 53248]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2005-09-22 303104]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 212992]
"MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [2006-11-07 1121280]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"MSKAGENTEXE"="c:\progra~1\McAfee\SPAMKI~1\MskAgent.exe" [2005-09-26 110592]
"VirusScan Online"="c:\program files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 163840]
"MPFExe"="c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-11-11 1005096]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-22 28160]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-13 177472]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 487424]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 282624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 53760]
c:\documents and settings\Rob\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2010-1-6 3450608]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2006-9-27 7168]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-12-29 528384]
NETGEAR WPN111 Smart Wizard.lnk - c:\program files\NETGEAR\WPN111\wpn111.exe [2007-4-12 884838]
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2009-11-1 119296]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{1984DD45-52CF-49cd-AB77-18F378FEA264}"= "c:\program files\Stardock\Fences\FencesMenu.dll" [2009-10-02 128360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\Steam\\steamapps\\rob399\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\VentSrv\\ventrilo_srv.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Tortun\\gui.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Rob\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\peggle deluxe\\Peggle.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\peggle extreme\\PeggleExtreme.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Age Of Empires 2 & The Conquerors Expansion - Full Game\\age2_x1.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Documents and Settings\\Rob\\My Documents\\utorrent.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-07-08 721904]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-14 135664]
R2 RPCER;Remote Procedure Call (HNM);c:\program files\NetMeeting\comp.exe [2007-03-28 12798152]
R3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.SYS [2003-07-24 17149]
R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\DRIVERS\WPN111.sys [2005-09-26 362944]
.
Contents of the 'Scheduled Tasks' folder
2010-07-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 11:34]
2010-08-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-14 03:53]
2010-08-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-14 03:53]
2010-08-13 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (ROBS_PC-Rob).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe [2006-09-27 17:18]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/uSearch Page =
hxxp://www.google.comuSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uSearch Bar =
hxxp://www.google.com/ieuSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Rob\Application Data\Mozilla\Firefox\Profiles\xa62z737.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com/webhp?hl=enFF - component: c:\documents and settings\Rob\Application Data\Mozilla\Firefox\Profiles\xa62z737.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-08-13 14:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-147038334-2158946348-2334436982-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-147038334-2158946348-2334436982-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:5e,3c,da,7b,39,6f,7f,b3,a4,e5,e1,c0,14,5f,93,01,18,dc,11,1c,85,19,a3,
ce,b2,85,42,49,fe,49,98,de,dd,51,fd,4c,11,2d,71,a6,f4,5e,f2,bf,ee,dd,ae,67,\
"??"=hex:5d,2e,bc,00,9b,07,bc,9c,34,34,87,88,c9,ab,ca,0d
[HKEY_USERS\S-1-5-21-147038334-2158946348-2334436982-1006\Software\SecuROM\License information*]
"datasecu"=hex:e1,4d,2d,b6,16,e7,39,57,ab,55,5e,d8,87,ef,02,3e,9d,af,39,29,ab,
0d,62,cf,b5,b7,e4,f8,ee,43,8b,62,17,d2,54,64,dc,72,22,1b,6f,cd,0d,a6,72,62,\
"rkeysecu"=hex:5b,b1,f1,96,e6,e7,05,7e,0c,23,86,99,20,fc,03,4c
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2212)
c:\program files\Stardock\ObjectDock\DockShellHook.dll
c:\progra~1\McAfee\SPAMKI~1\mskoeplg.dll
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\windows\system32\ieframe.dll
c:\progra~1\mcafee.com\vso\McVSSkt.dll
c:\program files\Stardock\Fences\FencesMenu.dll
c:\program files\stardock\fences\DesktopDock.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-08-13 14:36:19
ComboFix-quarantined-files.txt 2010-08-13 13:36
ComboFix2.txt 2010-08-09 21:02
ComboFix3.txt 2010-08-08 16:01
ComboFix4.txt 2010-08-08 15:47
Pre-Run: 5,807,132,672 bytes free
Post-Run: 5,792,796,672 bytes free
Current=3 Default=3 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 02FFBC80CEA5F7EE0B5DDC4DB5FBDF80
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internetCan not open internetESETSmartInstaller@High as downloader log:
Can not open internet# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=eb5c47f58ec9364695d2e7e20eb00a6f
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-08-13 03:16:56
# local_time=2010-08-13 04:16:56 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=2057
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=crash
# scanned=93739
# found=40
# cleaned=40
# scan_time=4034
C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Desktop.htt Win32/TrojanDownloader.FakeAlert.ATP trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\Administrator\Local Settings\Application Data\av.exe a variant of Win32/Kryptik.CJV trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\Rob\Desktop\GooredFix Backups\C\Documents and Settings\Administrator\Local Settings\Application Data\{3D8B6F79-97D7-40A1-85BB-DD2902F64883}\chrome\content\overlay.xul probably a variant of Win32/Agent.NVQFFQI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\Rob\My Documents\Nero 7.10.1.0\Nero-7.10.1.0_eng_full.exe Win32/Toolbar.AskSBar application (deleted - quarantined) 00000000000000000000000000000000 C
C:\Program Files\Hotspot Shield\bin\openvpnas.exe a variant of Win32/HotSpotShield application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Program Files\NetMeeting\comp.exe probably a variant of Win32/Genetik trojan (cleaned by deleting (after the next restart) - quarantined) 00000000000000000000000000000000 C
C:\Program1\EA GAMES\Command & Conquer Generals\Zero Hour\generals.exe probably unknown NewHeur_PE virus (deleted - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\Rob\autorun.inf.vir INF/Autorun virus (deleted - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\Rob\Application Data\Heriih\toup.exe.vir Win32/Spy.Zbot.YW trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\Rob\Local Settings\Application Data\MSASCui.exe.vir a variant of Win32/Kryptik.CSB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\Rob\Local Settings\Application Data\jqyuwnusn\xexcfqitssd.exe.vir Win32/Adware.SpywareProtect2009 application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\Documents and Settings\Rob\Local Settings\Application Data\{6502847E-AD16-4D91-867A-4009295CF7C6}\chrome\content\overlay.xul.vir probably a variant of Win32/Agent.NVQFFQI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\DOCUME~1\Rob\LOCALS~1\Temp\oggdw96sx.dll.vir probably a variant of Win32/TrojanDownloader.Agent.HYQTCNO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\ajovupoqoxevuqa.dll.vir a variant of Win32/Cimag.BQ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\asmcu4fbq.dll.vir a variant of Win32/TrojanDownloader.Small.NFD trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\bri5b913.dll.vir probably a variant of Win32/TrojanDownloader.Agent.HYQTCNO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\d5ytv35.dll.vir a variant of Win32/TrojanDownloader.Small.NFD trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ho4ndjbsu.dll.vir probably a variant of Win32/TrojanDownloader.Agent.HYQTCNO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\kwok5s.dll.vir probably a variant of Win32/TrojanDownloader.Agent.HYQTCNO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\lmvji.dll.vir probably a variant of Win32/TrojanDownloader.Agent.HYQTCNO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\mcuuxpbs.dll.vir probably a variant of Win32/TrojanDownloader.Agent.HYQTCNO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\msls51.dll.vir a variant of Win32/Kryptik.CMD trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\niqscu.dll.vir a variant of Win32/TrojanDownloader.Small.NFD trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\q7032w.dll.vir probably a variant of Win32/TrojanDownloader.Agent.HYQTCNO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\qvedt7.dll.vir probably a variant of Win32/Agent.BUEJTQ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\rk67xrw.dll.vir probably a variant of Win32/TrojanDownloader.Agent.HYQTCNO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\rrh7v.dll.vir probably a variant of Win32/TrojanDownloader.Agent.HYQTCNO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\smqdzle.dll.vir probably a variant of Win32/TrojanDownloader.Agent.HYQTCNO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\t6ymgwvuzk.dll.vir probably a variant of Win32/TrojanDownloader.Agent.HYQTCNO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\tc5d5.dll.vir a variant of Win32/TrojanDownloader.Small.NFD trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\va7jms3j75.dll.vir a variant of Win32/TrojanDownloader.Small.NFD trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\warning.html.vir Win32/TrojanDownloader.FakeAlert.ATP trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\x8bwdetn3x.dll.vir probably a variant of Win32/TrojanDownloader.Agent.HYQTCNO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\xlt89.dll.vir probably a variant of Win32/TrojanDownloader.Agent.HYQTCNO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\y0azio.dll.vir probably a variant of Win32/TrojanDownloader.Agent.HYQTCNO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000385.exe a variant of Win32/Kryptik.CJV trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000388.exe a variant of Win32/HotSpotShield application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000389.exe probably a variant of Win32/Genetik trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1\A0000390.exe probably unknown NewHeur_PE virus (deleted - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\hlp.dat Win32/Bamital.DP trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C