ok.. tu je log...
co dalej?
ComboFix 09-08-18.04 - julius 08/19/2009 17:43.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.539 [GMT 2:00]
Running from: c:\documents and settings\julius\My Documents\Downloads\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ZoneAlarm Pro Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\177f80.msp
c:\windows\Installer\177f81.msp
c:\windows\Installer\5ef0a3.msi
c:\windows\Installer\6bfb8.msp
c:\windows\Installer\6bfb9.msp
c:\windows\Installer\6bfbc.msp
c:\windows\Installer\a2682.msp
c:\windows\Installer\a2683.msp
c:\windows\Installer\faf32.msp
c:\windows\Installer\faf33.msp
c:\windows\Installer\faf36.msp
c:\windows\struct~.ini
Infected copy of c:\windows\system32\mspmsnsv.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\MsPMSNSv.dll
.
((((((((((((((((((((((((( Files Created from 2009-07-19 to 2009-08-19 )))))))))))))))))))))))))))))))
.
2009-08-17 22:26 . 2009-08-18 00:41 -------- d-----w- c:\documents and settings\julius\Application Data\Winamp
2009-08-17 22:26 . 2009-08-17 22:28 -------- d-----w- c:\program files\Winamp
2009-07-26 21:28 . 2009-07-26 21:28 -------- d-----w- c:\documents and settings\julius\Application Data\InterVideo
2009-07-25 23:08 . 2009-07-25 23:09 -------- d-----w- c:\program files\Auto Shutdown
2009-07-23 10:07 . 2009-07-23 10:07 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-19 17:09 . 2008-10-25 09:56 -------- d-----w- c:\documents and settings\julius\Application Data\Skype
2009-08-19 15:50 . 2008-10-25 09:58 -------- d-----w- c:\documents and settings\julius\Application Data\skypePM
2009-08-19 15:49 . 2009-01-19 19:55 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-08-19 15:48 . 2008-10-27 23:15 12 ----a-w- c:\windows\bthservsdp.dat
2009-08-18 16:57 . 2009-07-10 09:35 -------- d-----w- c:\documents and settings\julius\Application Data\vlc
2009-08-18 16:40 . 2009-08-18 16:41 2813952 ----a-w- c:\windows\Internet Logs\xDB1A.tmp
2009-08-18 00:42 . 2009-08-18 01:53 326144 ----a-w- c:\windows\Internet Logs\xDB19.tmp
2009-08-12 13:00 . 2009-05-28 22:44 -------- d-----w- c:\program files\Advanced SystemCare 3
2009-08-11 01:28 . 2009-08-11 10:28 81920 ----a-w- c:\windows\Internet Logs\xDB18.tmp
2009-08-10 12:28 . 2009-08-10 12:28 163710 ----a-w- c:\windows\Internet Logs\vsmon_on_demand_crt_term_2009_08_10_14_22_50_small.dmp.zip
2009-08-10 12:23 . 2009-01-24 05:33 -------- d-----w- c:\documents and settings\julius\Application Data\uTorrent
2009-08-08 06:33 . 2009-08-08 18:47 2756608 ----a-w- c:\windows\Internet Logs\xDB17.tmp
2009-08-08 06:33 . 2009-08-08 18:47 51200 ----a-w- c:\windows\Internet Logs\xDB16.tmp
2009-08-07 18:49 . 2009-08-07 21:11 2755584 ----a-w- c:\windows\Internet Logs\xDB15.tmp
2009-08-07 18:48 . 2009-08-07 21:11 236544 ----a-w- c:\windows\Internet Logs\xDB14.tmp
2009-08-05 09:01 . 2008-04-15 03:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 21:16 . 2009-08-04 21:15 171555 ----a-w- c:\windows\Internet Logs\vsmon_on_demand_crt_term_2009_08_04_23_09_57_small.dmp.zip
2009-08-03 20:01 . 2009-08-03 20:03 38400 ----a-w- c:\windows\Internet Logs\xDB12.tmp
2009-08-03 20:01 . 2009-08-03 20:03 2744320 ----a-w- c:\windows\Internet Logs\xDB13.tmp
2009-08-03 11:52 . 2009-08-03 14:37 290816 ----a-w- c:\windows\Internet Logs\xDB11.tmp
2009-07-27 12:51 . 2009-07-27 20:18 72704 ----a-w- c:\windows\Internet Logs\xDB10.tmp
2009-07-26 22:16 . 2009-07-27 08:32 418816 ----a-w- c:\windows\Internet Logs\xDBF.tmp
2009-07-26 21:34 . 2008-10-25 09:13 -------- d-----w- c:\documents and settings\julius\Application Data\Apple Computer
2009-07-17 19:01 . 2008-04-15 03:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-15 19:18 . 2009-07-15 19:18 6051840 ----a-w- c:\documents and settings\julius\Application Data\GRETECH\GomPlayer\GrLauncherTempSetup.exe
2009-07-15 18:11 . 2009-07-15 18:11 -------- d-----w- c:\documents and settings\julius\Application Data\Uniblue
2009-07-14 15:12 . 2009-07-11 20:50 -------- d-----w- c:\program files\Common Files\Real
2009-07-14 03:36 . 2009-07-14 06:20 2669568 ----a-w- c:\windows\Internet Logs\xDBE.tmp
2009-07-14 03:36 . 2009-07-14 06:20 264704 ----a-w- c:\windows\Internet Logs\xDBD.tmp
2009-07-12 15:00 . 2009-07-12 14:59 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2009-07-12 14:59 . 2009-07-12 14:59 -------- d-----w- c:\program files\DVDVideoSoft
2009-07-12 10:21 . 2008-04-15 03:00 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-11 20:50 . 2008-10-25 10:24 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-07-11 20:50 . 2008-10-25 10:24 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-07-11 20:50 . 2009-07-11 20:50 -------- d-----w- c:\program files\Real
2009-07-11 20:46 . 2008-10-26 04:45 -------- d-----w- c:\program files\Google
2009-07-11 19:55 . 2009-07-11 19:55 -------- d-----w- c:\documents and settings\julius\Application Data\SharePod
2009-07-10 09:34 . 2009-01-27 02:54 -------- d-----w- c:\program files\VLC
2009-07-10 09:12 . 2008-10-25 19:10 -------- d-----w- c:\documents and settings\julius\Application Data\FastStone
2009-07-09 02:18 . 2009-07-09 02:19 59392 ----a-w- c:\windows\Internet Logs\xDBB.tmp
2009-07-09 02:18 . 2009-07-09 02:19 2598400 ----a-w- c:\windows\Internet Logs\xDBC.tmp
2009-07-08 04:33 . 2009-07-08 15:17 53248 ----a-w- c:\windows\Internet Logs\xDBA.tmp
2009-07-08 02:45 . 2009-07-08 02:47 357888 ----a-w- c:\windows\Internet Logs\xDB9.tmp
2009-07-07 14:47 . 2009-07-07 15:06 2591744 ----a-w- c:\windows\Internet Logs\xDB8.tmp
2009-07-04 17:37 . 2008-10-25 18:00 -------- d-----w- c:\documents and settings\julius\Application Data\ICQ
2009-07-03 18:56 . 2009-07-03 18:56 -------- d-----w- c:\program files\AviSynth 2.5
2009-07-03 18:47 . 2009-07-03 18:47 -------- d-----w- c:\program files\eRightSoft
2009-07-02 01:06 . 2009-07-02 01:06 -------- d-----w- c:\documents and settings\julius\Application Data\MXSkypeRec
2009-07-02 01:06 . 2009-07-02 01:06 51470 ----a-w- c:\documents and settings\julius\Application Data\MXSkypeRec\Uninstall.exe
2009-06-29 16:12 . 2007-08-14 01:54 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2008-04-15 03:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2008-04-15 03:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-26 06:42 . 2009-06-26 11:12 110592 ----a-w- c:\windows\Internet Logs\xDB7.tmp
2009-06-25 08:25 . 2008-04-15 03:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2008-04-15 03:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2008-04-15 03:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2008-04-15 03:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2008-04-15 03:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2008-04-15 03:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2008-04-15 03:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2008-04-15 03:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2008-04-15 03:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-13 00:46 . 2009-06-13 00:47 2970624 ----a-w- c:\windows\Internet Logs\xDB6.tmp
2009-06-12 12:31 . 2008-04-15 03:00 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2008-04-15 03:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 07:19 . 2008-04-15 03:00 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2008-04-15 03:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2008-05-07 05:12 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-31 11:13 . 2009-05-31 11:44 2523648 ----a-w- c:\windows\Internet Logs\xDB5.tmp
2009-05-28 14:41 . 2009-05-28 14:41 163226 ----a-w- c:\windows\Internet Logs\vsmon_on_demand_crt_term_2009_05_28_16_35_14_small.dmp.zip
2006-05-03 09:06 . 2009-07-03 18:55 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2009-07-03 18:55 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2009-07-03 18:55 216064 --sh--r- c:\windows\system32\nbDX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-30 21755688]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-03-01 172792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1044480]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-15 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-15 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-05-14 821768]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-05-22 425984]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"ZoneAlarm Client"="c:\program files\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-16 16862720]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-15 110592]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-8-3 2760704]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [5/14/2009 3:47 PM 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [5/14/2009 3:49 PM 94360]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [5/14/2009 3:47 PM 731840]
R3 M3000Srv;Acer Crystal Eye webcam Driver;c:\windows\system32\drivers\M3000KNT.sys [5/5/2008 6:01 PM 254976]
S2 gupdate1ca02689e787d12;Google Update Service (gupdate1ca02689e787d12);c:\program files\Google\Update\GoogleUpdate.exe [7/11/2009 10:46 PM 133104]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [10/26/2008 6:49 AM 96856]
.
Contents of the 'Scheduled Tasks' folder
2009-08-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2009-08-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-11 20:45]
2009-08-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-11 20:45]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-M3000Mnt - M3000Rmv.dll
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://homepage.acer.com/rdr.aspx?b=ACA ... 8&m=aoa150
mStart Page =
hxxp://homepage.acer.com/rdr.aspx?b=ACA ... 8&m=aoa150
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\julius\Application Data\Mozilla\Firefox\Profiles\2h7nkz2q.default\
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\VLC\npvlc.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-19 19:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2956)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\FolderSize\FolderSizeSvc.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\igfxext.exe
c:\docume~1\julius\LOCALS~1\Temp\RtkBtMnt.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2009-08-19 19:14 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-19 17:14
Pre-Run: 4,027,686,912 bytes free
Post-Run: 3,980,779,520 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
299 --- E O F --- 2009-08-14 11:39