Maniac ще ти бъда благодарен, ако ми отговориш на моя анализ
ComboFix 10-05-03.06 - KRISO 05/04/2010 17:56:49.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1251.1.1033.18.2047.1479 [GMT 3:00]
Running from: c:\documents and settings\KRISO\Desktop\Tool.exe.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2010-04-04 to 2010-05-04 )))))))))))))))))))))))))))))))
.
2010-05-04 13:20 . 2010-05-04 13:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Autorun Eater
2010-05-04 13:20 . 2010-05-04 13:20 -------- d-----w- c:\program files\Autorun Eater
2010-05-03 19:26 . 2010-05-03 19:26 -------- d-----w- c:\documents and settings\KRISO\Local Settings\Application Data\Temp
2010-05-03 19:26 . 2010-05-03 19:26 -------- d-----w- c:\documents and settings\KRISO\Local Settings\Application Data\Google
2010-05-03 19:23 . 2010-05-03 19:23 57720 ---ha-w- c:\windows\system32\mlfcache.dat
2010-05-03 19:23 . 2010-05-03 19:23 -------- d-----w- c:\documents and settings\KRISO\Local Settings\Application Data\Apple Computer
2010-05-03 19:23 . 2010-05-03 19:23 -------- d-----w- c:\documents and settings\KRISO\Application Data\Apple Computer
2010-05-03 19:23 . 2010-05-03 19:23 -------- d-----w- c:\program files\Safari
2010-05-03 19:23 . 2010-05-03 19:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-05-03 19:23 . 2010-05-03 19:23 -------- d-----w- c:\program files\Bonjour
2010-05-03 19:23 . 2010-05-03 19:23 -------- d-----w- c:\program files\Common Files\Apple
2010-05-03 19:22 . 2010-05-03 19:22 -------- d-----w- c:\documents and settings\KRISO\Local Settings\Application Data\Apple
2010-05-03 19:22 . 2010-05-03 19:22 -------- d-----w- c:\program files\Apple Software Update
2010-05-03 19:22 . 2010-05-03 19:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-05-03 18:39 . 2010-05-04 14:28 407392 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-05-03 16:44 . 2010-05-03 16:44 -------- d-sh--w- c:\documents and settings\All Users\Application Data\SecuROM
2010-05-03 16:44 . 2009-03-16 11:18 69448 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2010-05-03 16:44 . 2009-03-16 11:18 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
2010-05-03 16:44 . 2009-03-09 12:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2010-05-03 16:44 . 2009-03-16 11:18 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
2010-05-03 16:44 . 2009-03-16 11:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
2010-05-03 15:33 . 2010-05-03 15:33 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-04-30 20:21 . 2010-04-30 20:21 -------- d-----w- c:\program files\Mp3 Knife
2010-04-30 20:21 . 2010-04-30 20:21 -------- d-----w- c:\program files\AMR to MP3 Converter
2010-04-26 12:48 . 2010-04-26 12:48 -------- d-----w- c:\windows\speech
2010-04-26 12:48 . 2010-05-02 19:02 -------- d-----w- c:\windows\system32\embedded
2010-04-21 12:49 . 2010-04-21 12:49 -------- d-----w- c:\program files\Common Files\Futuremark Shared
2010-04-20 19:53 . 2010-04-20 19:53 -------- d-----w- c:\program files\Skype
2010-04-20 19:53 . 2010-04-20 19:53 -------- d-----w- c:\program files\Common Files\Skype
2010-04-14 17:52 . 2010-04-14 17:52 -------- d-----w- c:\program files\CCleaner
2010-04-13 16:48 . 2010-04-13 16:48 -------- d-----w- c:\documents and settings\KRISO\Local Settings\Application Data\WMTools Downloaded Files
2010-04-10 23:47 . 2010-04-10 23:47 -------- d-----w- c:\program files\TeamViewer
2010-04-10 11:55 . 2010-04-10 11:56 -------- d-----w- c:\program files\PopCap Games
2010-04-10 11:55 . 2010-04-10 11:55 0 ----a-w- c:\windows\popcreg.dat
2010-04-10 11:55 . 2010-04-10 11:55 0 ----a-w- c:\windows\popcinfot.dat
2010-04-09 21:33 . 2010-04-09 22:16 -------- d-----w- c:\documents and settings\KRISO\Application Data\Bioshock2
2010-04-09 21:13 . 2009-09-04 14:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-04-09 21:13 . 2009-09-04 14:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-04-09 21:13 . 2010-04-09 21:13 -------- d-----w- c:\windows\system32\xlive
2010-04-09 21:13 . 2010-04-09 21:13 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-04 14:55 . 2010-01-17 13:13 -------- d-----w- c:\documents and settings\KRISO\Application Data\HPAppData
2010-05-04 14:38 . 2010-01-17 12:53 -------- d-----w- c:\documents and settings\KRISO\Application Data\Skype
2010-05-04 14:23 . 2010-01-17 12:30 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-04 13:04 . 2010-01-17 13:11 -------- d-----w- c:\documents and settings\KRISO\Application Data\skypePM
2010-05-04 06:32 . 2010-01-22 15:09 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-04-30 10:05 . 2010-04-30 09:20 -------- d-----w- c:\documents and settings\KRISO\Application Data\Winamp
2010-04-30 09:20 . 2010-04-30 09:20 -------- d-----w- c:\program files\Winamp
2010-04-30 09:20 . 2010-04-30 09:20 -------- d-----w- c:\program files\Winamp Detect
2010-04-20 19:53 . 2010-01-17 12:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-04-14 19:19 . 2010-01-17 12:43 69944 ----a-w- c:\documents and settings\KRISO\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-14 18:22 . 2010-01-17 20:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-10 23:48 . 2010-01-23 20:56 -------- d-----w- c:\documents and settings\KRISO\Application Data\TeamViewer
2010-04-01 10:07 . 2010-03-22 17:52 -------- d-----w- c:\program files\Common Files\Java
2010-04-01 10:07 . 2010-04-01 10:07 61440 ----a-w- c:\documents and settings\KRISO\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-43efa029-n\decora-sse.dll
2010-04-01 10:07 . 2010-04-01 10:07 503808 ----a-w- c:\documents and settings\KRISO\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-15c3bb34-n\msvcp71.dll
2010-04-01 10:07 . 2010-04-01 10:07 499712 ----a-w- c:\documents and settings\KRISO\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-15c3bb34-n\jmc.dll
2010-04-01 10:07 . 2010-04-01 10:07 348160 ----a-w- c:\documents and settings\KRISO\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-15c3bb34-n\msvcr71.dll
2010-04-01 10:07 . 2010-04-01 10:07 12800 ----a-w- c:\documents and settings\KRISO\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-43efa029-n\decora-d3d.dll
2010-04-01 10:07 . 2010-04-01 10:07 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-04-01 10:07 . 2010-03-22 17:53 -------- d-----w- c:\program files\Java
2010-03-26 18:39 . 2010-03-26 18:39 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee
2010-03-26 18:38 . 2010-03-23 18:10 -------- d-----w- c:\program files\McAfee Security Scan
2010-03-23 18:10 . 2010-03-23 18:10 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2010-03-23 18:10 . 2010-03-23 18:10 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2010-03-23 18:06 . 2010-03-23 18:06 0 ----a-w- c:\windows\nsreg.dat
2010-03-21 18:55 . 2010-03-21 18:55 53760 ----a-w- c:\windows\system32\gac.dll
2010-03-16 19:00 . 2010-03-16 19:00 -------- d-----w- c:\program files\SystemRequirementsLab
2010-03-10 06:15 . 2009-11-05 12:54 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-04 01:00 . 2010-03-04 01:00 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2010-02-25 06:19 . 2009-12-08 17:07 919040 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2009-11-05 12:53 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 19:02 . 2010-02-17 19:02 230454 ----a-w- C:\StiImg.dat
2010-02-17 06:10 . 2009-11-05 12:53 2189952 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2009-08-04 14:20 2066816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 10:03 . 2010-03-11 08:06 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-12 08:46 . 2010-02-12 08:46 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-02-12 08:46 . 2010-02-12 08:46 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-02-12 04:33 . 2008-04-14 11:00 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2009-11-05 12:53 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.
------- Sigcheck -------
[-] 2009-11-05 . 600D58665D16BFBB776EFEFB0E80532D . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"Google Update"="c:\documents and settings\KRISO\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-05-03 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Autorun Eater"="c:\program files\Autorun Eater\oldmcdonald.exe" [2009-05-26 549400]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"IE8"="advpack.dll" [2009-11-05 128512]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
FlexType 2K.lnk - c:\program files\Datecs\FlexType 2K\FType2K.exe [2010-1-17 95232]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-17 12:49 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMS by Jeko Ianev]
2009-12-29 19:14 13542912 ----a-w- c:\program files\sms\sms.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 08:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\GAME\\Counter-Strike 1.6 Perfect Edition\\hl.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"d:\\GAME\\CSS\\CSS\\hl2.exe"=
"d:\\GAME\\CSS\\CSS\\51149214604565533164.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7129:TCP"= 7129:TCP:BitComet 7129 TCP
"7129:UDP"= 7129:UDP:BitComet 7129 UDP
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [1/17/2010 3:46 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/17/2010 3:46 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/17/2010 3:46 PM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [1/17/2010 3:46 PM 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/17/2010 3:46 PM 297752]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1/17/2010 10:17 PM 611064]
S3 cpuz130;cpuz130;\??\c:\docume~1\KRISO\LOCALS~1\Temp\cpuz130\cpuz_x32.sys --> c:\docume~1\KRISO\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [?]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\KRISO\LOCALS~1\Temp\IEWF7.tmp --> c:\docume~1\KRISO\LOCALS~1\Temp\IEWF7.tmp [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 3:49 PM 227232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-05-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
2010-05-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1801674531-1326574676-682003330-1003Core.job
- c:\documents and settings\KRISO\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-03 19:26]
2010-05-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1801674531-1326574676-682003330-1003UA.job
- c:\documents and settings\KRISO\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-03 19:26]
2010-05-04 c:\windows\Tasks\User_Feed_Synchronization-{B7F20CEE-10BF-4C56-8894-AD4439AF8776}.job
- c:\windows\system32\msfeedssync.exe [2008-04-14 12:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.icq.com/
uInternet Settings,ProxyOverride = *.local
IE: &Експортиране към Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {73A6581D-1364-466C-A9D4-6C4773425295} = 208.67.220.220,208.67.222.222
TCP: {E4DF2436-03BF-423D-A3BA-F377E79DE0EE} = 213.240.244.5 213.240.244.2
DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} - hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.71.0.cab
FF - ProfilePath - c:\documents and settings\KRISO\Application Data\Mozilla\Firefox\Profiles\fpmp75wy.default\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-04 17:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\KRISO\LOCALS~1\Temp\IEWF7.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(616)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(4004)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-05-04 17:58:58
ComboFix-quarantined-files.txt 2010-05-04 14:58
ComboFix2.txt 2010-05-04 14:50
Pre-Run: 19,532,312,576 bytes free
Post-Run: 19,521,585,152 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 6B1DD177285AE07637EDA73D03F25028