Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ComboFix 10-08-12.02 - Administrator 12.08.2010 22:01:42.1.1 - x86
- Microsoft Windows XP Professional 5.1.2600.3.1250.385.1033.18.511.107 [GMT 2:00]
- Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
- AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- c:\documents and settings\Administrator\Application Data\020000007828957f982C.manifest
- c:\documents and settings\Administrator\Application Data\020000007828957f982O.manifest
- c:\documents and settings\Administrator\Application Data\020000007828957f982P.manifest
- c:\documents and settings\Administrator\Application Data\020000007828957f982S.manifest
- c:\documents and settings\Administrator\Application Data\GabPath
- c:\documents and settings\Administrator\Application Data\GabPath\config.cfg
- c:\documents and settings\Administrator\Application Data\GabPath\gabpath.exe
- c:\documents and settings\Administrator\Application Data\GabPath\GPUninstall.exe
- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\8z7mqzyu.default\extensions\{c0692f31-7181-4d31-a893-c594aaa55b44}
- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\8z7mqzyu.default\extensions\{c0692f31-7181-4d31-a893-c594aaa55b44}\chrome.manifest
- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\8z7mqzyu.default\extensions\{c0692f31-7181-4d31-a893-c594aaa55b44}\chrome\xulcache.jar
- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\8z7mqzyu.default\extensions\{c0692f31-7181-4d31-a893-c594aaa55b44}\defaults\preferences\xulcache.js
- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\8z7mqzyu.default\extensions\{c0692f31-7181-4d31-a893-c594aaa55b44}\install.rdf
- c:\documents and settings\Administrator\Application Data\SystemProc
- c:\documents and settings\Administrator\Application Data\SystemProc\lsass.exe
- c:\documents and settings\Administrator\Application Data\SystemProc\upd.exe
- c:\windows\GnuHashes.ini
- c:\windows\system32\1381209302
- c:\windows\system32\5078.dll
- c:\windows\system32\CABVIEW32.DLL
- c:\windows\system32\devmgr32.dll
- c:\windows\system32\SysWoW32
- c:\windows\system32\SysWoW32\mu976988651v4
- c:\windows\system32\SysWoW32\mu976988651v4.kwd
- c:\windows\system32\SysWoW32\mu976988651v5
- c:\windows\system32\SysWoW32\mu976988651v5.kwd
- c:\windows\system32\SysWoW32\mu976988651v6
- c:\windows\system32\SysWoW32\mu976988651v6.kwd
- c:\windows\system32\SysWoW32\mu976988651v7
- c:\windows\system32\SysWoW32\mu976988651v7.kwd
- c:\windows\system32\SysWoW32\wu976988651v0
- c:\windows\system32\SysWoW32\wu976988651v0.kwd
- c:\windows\system32\SysWoW32\wu976988651v1
- c:\windows\system32\SysWoW32\wu976988651v1.kwd
- c:\windows\system32\SysWoW32\wu976988651v2
- c:\windows\system32\SysWoW32\wu976988651v2.kwd
- c:\windows\system32\SysWoW32\wu976988651v3
- c:\windows\system32\SysWoW32\wu976988651v3.kwd
- c:\windows\system32\unrar.exe
- .
- ((((((((((((((((((((((((( Files Created from 2010-07-12 to 2010-08-12 )))))))))))))))))))))))))))))))
- .
- 2010-08-12 09:02 . 2010-08-12 09:02 325632 ----a-w- c:\windows\system32\cscdll32.dll
- 2010-08-12 09:01 . 2010-08-12 09:01 318976 ----a-w- c:\windows\system32\bootvid32.dll
- 2010-08-12 09:00 . 2010-08-12 09:00 220672 ----a-w- c:\windows\system32\deployJava132.dll
- 2010-08-11 14:09 . 2010-08-11 14:09 -------- d-----w- c:\windows\Sun
- 2010-08-08 11:50 . 2010-08-08 11:50 50608 ---ha-w- c:\windows\system32\mlfcache.dat
- 2010-08-08 11:28 . 2010-08-09 08:45 -------- d-----w- c:\documents and settings\Administrator\Application Data\Apple Computer
- 2010-08-08 11:28 . 2009-05-18 11:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
- 2010-08-08 11:28 . 2008-04-17 10:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
- 2010-08-08 11:26 . 2010-08-08 11:26 -------- d-----w- c:\program files\iPod
- 2010-08-08 11:26 . 2010-08-09 12:38 -------- d-----w- c:\program files\iTunes
- 2010-08-08 11:26 . 2010-08-08 11:28 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
- 2010-08-08 11:23 . 2010-08-08 11:23 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Apple
- 2010-08-08 11:23 . 2010-08-08 11:23 -------- d-----w- c:\program files\Apple Software Update
- 2010-08-08 11:22 . 2010-08-08 11:28 -------- dc----w- c:\windows\system32\DRVSTORE
- 2010-08-08 11:22 . 2010-04-19 18:47 3062048 ----a-w- c:\windows\system32\usbaaplrc.dll
- 2010-08-08 11:22 . 2010-04-19 18:47 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
- 2010-08-08 11:22 . 2010-08-08 11:22 -------- d-----w- c:\program files\Bonjour
- 2010-08-08 11:21 . 2010-08-08 11:26 -------- d-----w- c:\program files\Common Files\Apple
- 2010-08-08 11:21 . 2010-08-08 11:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
- 2010-08-08 11:10 . 2010-08-08 11:10 -------- d-----w- c:\documents and settings\Administrator\Application Data\Media Player Classic
- 2010-08-08 09:45 . 2010-08-06 15:01 57608 ----a-w- c:\documents and settings\All Users\Application Data\ResultDns\resultdns111.exe
- 2010-08-08 09:43 . 2010-08-08 10:34 -------- d-----w- c:\program files\ResultDns
- 2010-08-08 09:43 . 2010-08-08 09:45 -------- d-----w- c:\documents and settings\All Users\Application Data\ResultDns
- 2010-08-08 09:43 . 2010-08-08 09:43 532480 ----a-w- c:\documents and settings\Administrator\Application Data\Microsoft\Windows\jnipmo.exe
- 2010-08-07 12:28 . 2010-08-12 18:08 -------- d-----w- c:\documents and settings\Administrator\Application Data\LimeWire
- 2010-08-07 12:28 . 2010-08-07 12:28 503808 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1bbc36a6-n\msvcp71.dll
- 2010-08-07 12:28 . 2010-08-07 12:28 499712 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1bbc36a6-n\jmc.dll
- 2010-08-07 12:28 . 2010-08-07 12:28 348160 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1bbc36a6-n\msvcr71.dll
- 2010-08-07 12:28 . 2010-08-07 12:28 61440 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-3915499f-n\decora-sse.dll
- 2010-08-07 12:28 . 2010-08-07 12:28 12800 ----a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-3915499f-n\decora-d3d.dll
- 2010-08-07 12:28 . 2010-08-07 12:28 -------- d-----w- c:\program files\Common Files\Java
- 2010-08-07 12:27 . 2010-08-07 12:27 423656 ----a-w- c:\windows\system32\deployJava1.dll
- 2010-08-07 12:27 . 2010-08-07 12:27 -------- d-----w- c:\program files\Java
- 2010-08-07 12:24 . 2010-08-07 12:25 -------- d-----w- c:\program files\LimeWire
- 2010-07-24 07:29 . 2010-07-24 07:29 -------- d-----w- c:\documents and settings\Administrator\Application Data\GRETECH
- 2010-07-22 20:28 . 2008-04-14 04:00 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
- 2010-07-21 14:30 . 2010-07-21 14:30 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
- 2010-07-21 09:25 . 2010-07-21 09:25 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nero
- 2010-07-21 06:03 . 2010-07-21 06:03 -------- d-----w- c:\program files\Common Files\SWF Studio
- 2010-07-14 13:32 . 2010-08-04 13:38 -------- d-----w- C:\output
- 2010-07-14 08:42 . 2010-07-14 08:43 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2010-08-12 12:24 . 2010-08-12 12:24 0 ---ha-w- c:\documents and settings\Administrator\xfnaurfhbq.tmp
- 2010-08-12 09:00 . 2010-08-12 09:00 1154048 --sha-w- c:\windows\system32\6A.tmp
- 2010-08-08 11:26 . 2010-06-28 16:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
- 2010-08-08 11:25 . 2010-06-28 16:55 -------- d-----w- c:\program files\QuickTime Alternative
- 2010-07-21 05:25 . 2010-06-28 05:49 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
- 2010-07-06 11:08 . 2010-07-06 08:10 -------- d-----w- c:\documents and settings\Administrator\Application Data\PhotoScape
- 2010-07-06 08:10 . 2010-07-06 08:09 -------- d-----w- c:\program files\Google
- 2010-07-06 08:09 . 2010-07-06 08:09 -------- d-----w- c:\program files\PhotoScape
- 2010-07-05 12:01 . 2010-07-05 12:01 -------- d-----w- c:\documents and settings\Administrator\Application Data\FastStone
- 2010-06-29 14:32 . 2010-06-28 16:41 64368 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
- 2010-06-28 20:42 . 2010-06-28 20:42 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
- 2010-06-28 18:27 . 2010-06-28 17:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
- 2010-06-28 18:13 . 2010-06-28 17:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
- 2010-06-28 17:53 . 2010-06-28 17:53 -------- d-----w- c:\program files\Common Files\Nero
- 2010-06-28 17:53 . 2010-06-28 17:53 -------- d-----w- c:\program files\Nero
- 2010-06-28 17:39 . 2010-06-28 17:39 -------- d-----w- c:\program files\Common Files\L&H
- 2010-06-28 17:39 . 2010-06-28 17:39 -------- d-----w- c:\program files\Microsoft ActiveSync
- 2010-06-28 17:38 . 2010-06-28 17:38 -------- d-----w- c:\program files\Microsoft Works
- 2010-06-28 17:28 . 2010-06-28 17:28 -------- d-----w- c:\program files\Microsoft.NET
- 2010-06-28 17:22 . 2010-06-28 17:22 -------- d-----w- c:\program files\MSBuild
- 2010-06-28 17:03 . 2010-06-28 17:03 -------- d-----w- c:\program files\Micronet Wireless Network Utility
- 2010-06-28 17:03 . 2010-06-28 17:03 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
- 2010-06-28 17:03 . 2010-06-28 17:01 -------- d--h--w- c:\program files\InstallShield Installation Information
- 2010-06-28 17:01 . 2010-06-28 17:01 -------- d-----w- c:\program files\C-Media 3D Audio
- 2010-06-28 17:01 . 2010-06-28 17:01 -------- d-----w- c:\program files\Common Files\InstallShield
- 2010-06-28 17:01 . 2010-06-28 17:00 -------- d-----w- c:\program files\Winamp
- 2010-06-28 17:00 . 2010-06-28 17:00 -------- d-----w- c:\documents and settings\Administrator\Application Data\Winamp
- 2010-06-28 16:56 . 2010-06-28 16:56 -------- d-----w- c:\program files\Real Alternative
- 2010-06-28 16:46 . 2010-06-28 16:46 -------- d-----w- c:\program files\Paint.NET
- 2010-06-28 16:44 . 2010-06-28 16:44 -------- d-----w- c:\program files\Reference Assemblies
- 2010-06-28 16:41 . 2010-06-28 16:41 -------- d-----w- c:\program files\K-Lite Codec Pack
- 2010-06-28 16:40 . 2010-06-28 16:40 -------- d-----w- c:\program files\GRETECH
- 2010-06-28 16:39 . 2010-06-28 16:39 -------- d-----w- c:\program files\FastStone Image Viewer
- 2010-06-28 16:37 . 2010-06-28 16:37 0 ----a-w- c:\windows\nsreg.dat
- 2010-06-28 16:27 . 2010-06-28 16:27 -------- d-----w- c:\program files\Avira
- 2010-06-28 16:27 . 2010-06-28 16:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
- 2010-06-28 16:25 . 2010-06-28 16:25 -------- d-----w- c:\program files\CCleaner
- 2010-06-28 16:24 . 2010-06-28 16:24 -------- d-----w- c:\program files\7-Zip
- 2010-06-28 16:24 . 2010-06-28 16:24 -------- d-----w- c:\program files\Common Files\Adobe
- 2010-06-28 05:54 . 2010-06-28 05:54 -------- d-----w- c:\program files\microsoft frontpage
- 2010-06-28 05:45 . 2010-06-28 05:45 21640 ----a-w- c:\windows\system32\emptyregdb.dat
- 2010-06-28 05:44 . 2010-06-28 05:44 -------- d-----w- c:\program files\Windows Media Connect 2
- 2010-06-27 21:37 . 2010-06-27 21:37 -------- d-----w- c:\program files\MSXML 4.0
- 2010-05-18 14:35 . 2010-05-18 14:35 91424 ----a-w- c:\windows\system32\dnssd.dll
- 2010-05-18 14:35 . 2010-05-18 14:35 75040 ----a-w- c:\windows\system32\jdns_sd.dll
- 2010-05-18 14:35 . 2010-05-18 14:35 197920 ----a-w- c:\windows\system32\dnssdX.dll
- 2010-05-18 14:35 . 2010-05-18 14:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
- 2010-08-08 09:44 . 2010-08-08 09:44 211456 ----a-w- c:\program files\mozilla firefox\components\gpff.dll
- .
- ------- Sigcheck -------
- [-] 2010-03-15 . A02BF7E8C036A2A8587F70A038922449 . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys
- [-] 2010-03-15 . 305D4CF34FA3DCDB58525E90A9A793B9 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{186C1E3D-CEFA-49DE-B3CF-67921309A9B3}]
- 2010-08-12 09:02 325632 ----a-w- c:\windows\system32\cscdll32.dll
- [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83435B8D-1309-02CE-6B94-960D62A0E21C}]
- 2010-08-12 09:00 220672 ----a-w- c:\windows\system32\deployJava132.dll
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Google Update"="c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-07-06 135664]
- "SfKg6wIPuSp"="c:\documents and settings\Administrator\Application Data\Microsoft\Windows\jnipmo.exe" [2010-08-08 532480]
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "VistaDrive"="c:\windows\VistaDrive\VistaDrive.exe" [2006-10-06 280779]
- "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
- "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
- "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
- "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
- "nwiz"="nwiz.exe" [2006-10-22 1622016]
- "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
- "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
- "QuickTime Task"="c:\program files\QuickTime Alternative\qttask.exe" [2010-03-18 421888]
- "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
- [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
- [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
- "_nltide_3"="advpack.dll" [2009-09-13 128512]
- c:\documents and settings\Administrator\Start Menu\Programs\Startup\
- LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-9-18 147456]
- c:\documents and settings\All Users\Start Menu\Programs\Startup\
- Micronet Wireless Network Utility.lnk - c:\program files\Micronet Wireless Network Utility\RtWlan.exe [2010-6-28 675840]
- [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
- "NoSMHelp"= 1 (0x1)
- [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
- "ForceClassicControlPanel"= 1 (0x1)
- "NoSMHelp"= 1 (0x1)
- [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\e061f3b1982]
- 2010-08-12 09:00 220672 ----a-w- c:\windows\system32\deployJava132.dll
- [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
- "AppInit_DLLs"=c:\windows\system32\deployJava132.dll
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
- "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
- "%windir%\\system32\\sessmgr.exe"=
- "c:\\Program Files\\LimeWire\\LimeWire.exe"=
- "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
- "c:\\Program Files\\iTunes\\iTunes.exe"=
- R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [28.6.2010 18:27 135336]
- R2 ResultDns Service;ResultDns Service;c:\documents and settings\All Users\Application Data\ResultDns\resultdns111.exe [8.8.2010 11:45 57608]
- R3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [28.6.2010 19:03 13532]
- S2 gupdate;Usluga Google ažuriranje (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [6.7.2010 10:09 135664]
- .
- Contents of the 'Scheduled Tasks' folder
- 2010-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- - c:\program files\Google\Update\GoogleUpdate.exe [2010-07-06 08:09]
- 2010-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- - c:\program files\Google\Update\GoogleUpdate.exe [2010-07-06 08:09]
- 2010-08-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-861567501-1645522239-1606980848-500Core.job
- - c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-17 08:09]
- 2010-08-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-861567501-1645522239-1606980848-500UA.job
- - c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-17 08:09]
- 2010-08-12 c:\windows\Tasks\User_Feed_Synchronization-{66554CD7-19E0-4662-9264-10C674AE06C3}.job
- - c:\windows\system32\msfeedssync.exe [2008-04-14 16:47]
- .
- .
- ------- Supplementary Scan -------
- .
- uStart Page = hxxp://home.tangotoolbar.com/
- mSearch Bar = hxxp://www.tangosearch.com/?useie5=1&q=
- uInternet Connection Wizard,ShellNext = iexplore
- uInternet Settings,ProxyOverride = *.local
- IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
- FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\8z7mqzyu.default\
- FF - prefs.js: browser.startup.homepage - hxxp://www.google.hr/
- FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
- FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
- FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
- ---- FIREFOX POLICIES ----
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
- .
- - - - - ORPHANS REMOVED - - - -
- Toolbar-{C320CC1E-D77A-4C06-A20E-D3D3DCA6D1D9} - c:\windows\system32\5078.dll
- WebBrowser-{C320CC1E-D77A-4C06-A20E-D3D3DCA6D1D9} - c:\windows\system32\5078.dll
- HKCU-Run-GabPath - c:\documents and settings\Administrator\Application Data\GabPath\gabpath.exe
- HKLM-Run-Cmaudio - cmicnfg.cpl
- HKLM-Explorer_Run-RTHDBPL - c:\documents and settings\Administrator\Application Data\SystemProc\lsass.exe
- AddRemove-GabPath - c:\documents and settings\Administrator\Application Data\GabPath\GPUninstall.exe
- **************************************************************************
- catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
- Rootkit scan 2010-08-12 22:09
- Windows 5.1.2600 Service Pack 3 NTFS
- scanning hidden processes ...
- scanning hidden autostart entries ...
- HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
- RTHDBPL = c:\documents and settings\Administrator\Application Data\SystemProc\lsass.exe???????????????????????????????????????????????????
- scanning hidden files ...
- scan completed successfully
- hidden files: 0
- **************************************************************************
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- [HKEY_USERS\S-1-5-21-861567501-1645522239-1606980848-500\Software\Microsoft\Internet Explorer\User Preferences]
- @Denied: (2) (Administrator)
- "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
- d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,32,56,c9,21,54,4a,aa,40,b4,27,c2,\
- "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
- d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,32,56,c9,21,54,4a,aa,40,b4,27,c2,\
- .
- --------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - - > 'winlogon.exe'(864)
- c:\windows\system32\deployJava132.dll
- - - - - - - - > 'lsass.exe'(928)
- c:\windows\system32\deployJava132.dll
- .
- Completion time: 2010-08-12 22:13:13
- ComboFix-quarantined-files.txt 2010-08-12 20:13
- Pre-Run: 52.225.269.760 bytes free
- Post-Run: 52.563.734.528 bytes free
- WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
- [boot loader]
- timeout=2
- default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
- [operating systems]
- c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
- multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - - End Of File - - B34FD35724547C18B940CB4042315498
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement