- ComboFix 10-03-10.04 - Aks-admin 03/15/2010 14:50:21.1.2 - x86
- Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.478.267 [GMT 6:00]
- Running from: c:\documents and settings\Aks-admin\Desktop\ComboFix.exe
- AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
- FW: Kaspersky Anti-Virus *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
- WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
- .
- ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
- .
- c:\documents and settings\Aks-admin\Application Data\logs.dat
- c:\documents and settings\Aks-admin\Application Data\SQLite3.dll
- c:\documents and settings\Aks-admin\Local Settings\Application Data\Bron.tok-16-14
- c:\documents and settings\Aks-admin\Local Settings\Application Data\Bron.tok-16-15
- c:\documents and settings\Aks-admin\Local Settings\Application Data\csrss.exe
- c:\documents and settings\Aks-admin\Local Settings\Application Data\inetinfo.exe
- c:\documents and settings\Aks-admin\Local Settings\Application Data\Kosong.Bron.Tok.txt
- c:\documents and settings\Aks-admin\Local Settings\Application Data\ListHost16.txt
- c:\documents and settings\Aks-admin\Local Settings\Application Data\smss.exe
- c:\documents and settings\common\Application Data\logs.dat
- c:\documents and settings\common\Application Data\Server.exe
- c:\documents and settings\common\Application Data\SQLite3.dll
- c:\documents and settings\common\Local Settings\Application Data\br5007on.exe
- c:\documents and settings\common\Local Settings\Application Data\Bron.tok-16-14
- c:\documents and settings\common\Local Settings\Application Data\Bron.tok-16-15
- c:\documents and settings\common\Local Settings\Application Data\csrss.exe
- c:\documents and settings\common\Local Settings\Application Data\inetinfo.exe
- c:\documents and settings\common\Local Settings\Application Data\Kosong.Bron.Tok.txt
- c:\documents and settings\common\Local Settings\Application Data\ListHost16.txt
- c:\documents and settings\common\Local Settings\Application Data\lsass.exe
- c:\documents and settings\common\Local Settings\Application Data\services.exe
- c:\documents and settings\common\Local Settings\Application Data\smss.exe
- c:\documents and settings\common\Local Settings\Application Data\winlogon.exe
- c:\documents and settings\common\Start Menu\Programs\Startup\systemID.pif
- c:\documents and settings\common\Templates\8196-NendangBro.com
- c:\documents and settings\NetworkService\Local Settings\Application Data\Bron.tok-16-15
- c:\documents and settings\NetworkService\Local Settings\Application Data\BronFoldNetDomList.txt
- c:\documents and settings\NetworkService\Local Settings\Application Data\csrss.exe
- c:\documents and settings\NetworkService\Local Settings\Application Data\inetinfo.exe
- c:\documents and settings\NetworkService\Local Settings\Application Data\Kosong.Bron.Tok.txt
- c:\documents and settings\NetworkService\Local Settings\Application Data\ListHost16.txt
- c:\documents and settings\NetworkService\Local Settings\Application Data\lsass.exe
- c:\documents and settings\NetworkService\Local Settings\Application Data\services.exe
- c:\documents and settings\NetworkService\Local Settings\Application Data\smss.exe
- c:\documents and settings\NetworkService\Local Settings\Application Data\winlogon.exe
- C:\explorer.exe
- c:\program files\{17350501621331}.exe
- c:\program files\explorer.exe
- c:\windows\apocalyps32.exe
- c:\windows\BackUp
- c:\windows\BackUp\autorun.inf
- c:\windows\system32\Explorer
- c:\windows\system32\i1Iefmfi8l.txt
- c:\windows\system32\lowsec
- c:\windows\system32\lowsec\local.ds
- c:\windows\system32\lowsec\user.ds
- c:\windows\system32\lowsec\user.ds.lll
- c:\windows\system32\system32
- c:\windows\system32\system32\iexplorerupdate.exe
- c:\windows\system32\uZQEtNDuIS.dll
- c:\windows\WINDOWS
- .
- ((((((((((((((((((((((((( Files Created from 2010-02-15 to 2010-03-15 )))))))))))))))))))))))))))))))
- .
- 2010-03-15 05:10 . 2010-03-15 05:10 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Ok-SendMail-Bron-tok
- 2010-03-15 05:09 . 2010-03-15 05:19 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Loc.Mail.Bron.Tok
- 2010-03-15 02:00 . 2010-03-15 02:00 -------- d-----w- c:\documents and settings\Aks-admin\Local Settings\Application Data\Loc.Mail.Bron.Tok
- 2010-03-15 01:54 . 2010-03-11 05:48 3885832 ----a-r- C:\ComboFix.exe
- 2010-03-14 05:56 . 2010-03-14 05:56 -------- d-----w- c:\documents and settings\common\Local Settings\Application Data\Ok-SendMail-Bron-tok
- 2010-03-14 05:33 . 2010-03-14 07:58 -------- d-----w- c:\documents and settings\common\Local Settings\Application Data\Loc.Mail.Bron.Tok
- 2010-03-14 00:43 . 2010-02-05 07:51 44401 ----a-w- C:\7668-NendangBro.com
- 2010-03-10 09:57 . 2010-03-10 09:57 -------- d-----w- c:\documents and settings\common\Application Data\CyberLink
- 2010-03-10 03:31 . 2010-03-10 03:31 57456 ----a-w- c:\documents and settings\common\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
- 2010-03-09 02:23 . 2010-03-09 02:23 -------- d-----w- c:\documents and settings\Aks-admin\Application Data\CyberLink
- 2010-03-09 02:23 . 2010-03-09 02:23 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
- 2010-03-09 02:23 . 2010-03-09 02:23 -------- d-----w- c:\program files\CyberLink
- 2010-03-09 01:56 . 2010-03-09 01:56 -------- d-----w- c:\program files\Trend Micro
- 2010-03-08 05:29 . 2010-03-08 05:29 0 ----a-w- c:\windows\nsreg.dat
- 2010-03-08 05:29 . 2010-03-08 05:29 -------- d-----w- c:\documents and settings\common\Local Settings\Application Data\Mozilla
- 2010-03-07 01:56 . 2010-03-07 01:56 67372 ----a-w- c:\documents and settings\common\Application Data\IDM\DwnlData\common\mybot_18\mybot.exe
- 2010-03-07 01:52 . 2010-03-15 08:49 2959376 ----a-w- C:\dotnetfx35setup.exe
- 2010-03-04 08:25 . 2010-03-04 08:40 -------- d--h--w- c:\windows\system32\498A46
- 2010-03-04 08:25 . 2010-03-04 08:40 -------- d--h--w- c:\windows\system32\F7D46D
- 2010-03-04 08:25 . 2010-03-04 08:40 -------- d--h--w- c:\windows\system32\9D3562
- 2010-03-04 08:25 . 2010-03-04 08:40 -------- d--h--w- c:\windows\system32\0C3017
- 2010-03-01 01:47 . 2010-03-01 01:50 -------- d-sh--r- c:\windows\rootserveyn
- 2010-02-28 01:55 . 2010-03-03 07:31 1878888 ----a-w- c:\windows\install_flash_player.exe
- 2010-02-28 01:54 . 2010-03-15 05:03 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
- 2010-02-28 01:53 . 2010-03-03 07:33 -------- d-sh--r- c:\windows\system32\WindowsUpdate
- 2010-02-28 01:53 . 2010-02-28 01:53 -------- d-----w- c:\windows\admin_F4C1976F
- 2010-02-25 06:36 . 2010-02-25 06:36 198064 ----a-w- c:\documents and settings\common\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
- 2010-02-25 06:35 . 2010-03-04 01:44 -------- d-----w- c:\documents and settings\common\Application Data\IDM
- 2010-02-25 06:35 . 2010-03-15 04:06 -------- d-----w- c:\documents and settings\common\Application Data\DMCache
- 2010-02-25 06:35 . 2010-03-04 05:26 -------- d-----w- c:\program files\Internet Download Manager
- 2010-02-25 03:26 . 2010-02-25 03:26 1108 ----a-w- c:\windows\system32\ealregsnapshot1.reg
- 2010-02-25 03:26 . 2010-02-25 03:26 -------- d-----w- c:\documents and settings\common\Local Settings\Application Data\Downloaded Installations
- 2010-02-25 03:26 . 2010-02-25 03:26 -------- d-----w- c:\documents and settings\common\Application Data\Leadertech
- 2010-02-25 01:56 . 2010-02-25 01:56 -------- d-----w- C:\fontsss
- 2010-02-24 02:40 . 2010-02-24 02:40 -------- d-s---w- c:\documents and settings\common\UserData
- 2010-02-24 02:39 . 2010-02-24 02:39 -------- d-----w- c:\documents and settings\common\Application Data\IObit
- 2010-02-24 01:52 . 2010-02-24 01:52 -------- d-----w- c:\documents and settings\Aks-admin\Application Data\IObit
- 2010-02-24 01:52 . 2010-02-24 01:58 -------- d-----w- c:\program files\IObit
- 2010-02-23 06:17 . 2010-02-23 06:17 -------- d-s---w- c:\documents and settings\Aks-admin\UserData
- 2010-02-23 05:28 . 2010-02-23 05:28 -------- d-----w- c:\program files\EA Sports
- 2010-02-23 05:26 . 2005-02-25 03:35 22752 ----a-w- c:\windows\system32\spupdsvc.exe
- 2010-02-23 05:26 . 2010-02-23 06:57 -------- d--h--w- c:\windows\$hf_mig$
- 2010-02-23 03:31 . 2010-02-23 03:31 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
- 2010-02-23 01:51 . 2010-02-23 01:51 68456 ----a-w- c:\documents and settings\Aks-admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
- 2010-02-18 08:24 . 2010-03-04 05:26 -------- d-----w- c:\program files\Counter-Strike
- 2010-02-18 06:42 . 2010-02-18 06:42 -------- d-----w- c:\documents and settings\common\Local Settings\Application Data\Microsoft Help
- 2010-02-18 06:34 . 2010-02-28 07:44 -------- d-----w- c:\documents and settings\common\Local Settings\Application Data\Temp
- 2010-02-18 06:34 . 2010-02-18 06:47 -------- d-----w- c:\documents and settings\common\Local Settings\Application Data\Google
- 2010-02-16 10:02 . 2001-08-17 13:59 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
- 2010-02-16 10:01 . 2004-08-03 22:59 57472 ----a-w- c:\windows\system32\drivers\redbook.sys
- 2010-02-16 10:00 . 2004-08-04 00:56 74240 ----a-w- c:\windows\system32\usbui.dll
- .
- (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- 2010-03-15 08:55 . 2010-02-16 04:43 2464032 --sha-w- c:\windows\system32\drivers\fidbox.dat
- 2010-03-15 08:54 . 2010-02-16 04:43 237344 --sha-w- c:\windows\system32\drivers\fidbox2.dat
- 2010-03-15 08:54 . 2010-02-16 04:43 23312 --sha-w- c:\windows\system32\drivers\fidbox2.idx
- 2010-03-15 08:54 . 2010-02-16 04:43 37064 --sha-w- c:\windows\system32\drivers\fidbox.idx
- 2010-03-15 08:37 . 2010-02-16 04:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
- 2010-03-15 05:41 . 2006-06-28 20:39 124803 ---ha-w- c:\documents and settings\common\Application Data\cglogs.dat
- 2010-03-11 08:12 . 2010-02-16 04:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
- 2010-03-09 02:23 . 2010-02-16 04:28 -------- d--h--w- c:\program files\InstallShield Installation Information
- 2010-02-25 03:26 . 2010-02-16 04:27 -------- d-----w- c:\program files\Common Files\InstallShield
- 2010-02-18 02:16 . 2010-02-16 04:07 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
- 2010-02-16 05:05 . 2010-02-16 05:05 -------- d-----w- c:\program files\Microsoft Works
- 2010-02-16 05:04 . 2010-02-16 05:04 -------- d-----w- c:\program files\MSBuild
- 2010-02-16 05:03 . 2010-02-16 04:44 95259 ----a-w- c:\windows\system32\drivers\klick.dat
- 2010-02-16 05:03 . 2010-02-16 04:44 108059 ----a-w- c:\windows\system32\drivers\klin.dat
- 2010-02-16 05:03 . 2007-07-18 08:39 112144 ----a-w- c:\windows\system32\drivers\kl1.sys
- 2010-02-16 05:02 . 2010-02-16 05:02 715280 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP6\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\6.0.3.830\updater.dll
- 2010-02-16 05:02 . 2010-02-16 05:02 112144 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP6\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\6.0.3.830\X86\kl1.sys
- 2010-02-16 05:02 . 2010-02-16 05:02 158224 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP6\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\6.0.3.830\scrchpg.dll
- 2010-02-16 05:02 . 2010-02-16 05:02 201504 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP6\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\6.0.3.830\klif.sys
- 2010-02-16 05:02 . 2010-02-16 05:02 41488 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP6\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\6.0.3.830\fssync.dll
- 2010-02-16 05:02 . 2010-02-16 05:02 342544 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP6\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\6.0.3.830\ckahum.dll
- 2010-02-16 05:02 . 2010-02-16 05:02 231952 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP6\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav6\6.0.3.830\avp.exe
- 2010-02-16 04:43 . 2010-02-16 04:43 -------- d-----w- c:\program files\Kaspersky Lab
- 2010-02-16 04:30 . 2010-02-16 04:30 -------- d-----w- c:\program files\ATI Technologies
- 2010-02-16 04:28 . 2010-02-16 04:28 -------- d-----w- c:\program files\Analog Devices
- 2010-02-16 04:26 . 2010-02-16 04:26 -------- d-----w- c:\program files\Broadcom
- 2010-02-16 04:24 . 2010-02-16 04:24 45056 ----a-r- c:\documents and settings\Aks-admin\Application Data\Microsoft\Installer\{2764CA82-DFB9-4498-AF85-719340BF5305}\NewShortcut1_2764CA82DFB94498AF85719340BF5305.exe
- 2010-02-16 04:24 . 2010-02-16 04:24 10134 ----a-r- c:\documents and settings\Aks-admin\Application Data\Microsoft\Installer\{2764CA82-DFB9-4498-AF85-719340BF5305}\ARPPRODUCTICON.exe
- 2010-02-16 04:24 . 2010-02-16 04:24 -------- d-----w- c:\program files\Dell
- 2010-02-16 04:08 . 2010-02-16 04:08 -------- d-----w- c:\program files\microsoft frontpage
- 2010-02-16 04:05 . 2010-02-16 04:05 21640 ----a-w- c:\windows\system32\emptyregdb.dat
- 2005-08-31 10:44 . 2005-08-31 10:44 581632 --sha-r- c:\windows\system32\WindowsUpdate\plugin.dat
- .
- ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
- .
- .
- *Note* empty entries & legit default entries are not shown
- REGEDIT4
- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-01-06 2335952]
- c:\documents and settings\common\Start Menu\Programs\Startup\
- Empty.pif [2010-2-5 44401]
- [HKLM\~\startupfolder\C:^Documents and Settings^common^Start Menu^Programs^Startup^32B35E.lnk]
- path=c:\documents and settings\common\Start Menu\Programs\Startup\32B35E.lnk
- backup=c:\windows\pss\32B35E.lnkStartup
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\32B35E]
- 2010-03-04 08:25 1477911 --sh--r- c:\windows\system32\498A46\32B35E.EXE
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
- 2004-08-04 04:56 15360 ------w- c:\windows\system32\ctfmon.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
- 2010-02-18 06:34 135664 ----atw- c:\documents and settings\common\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
- 2010-01-25 15:29 3179952 ----a-w- c:\program files\Internet Download Manager\IDMan.exe
- [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
- "ATI Smart"=2 (0x2)
- [HKEY_LOCAL_MACHINE\software\microsoft\security center]
- "AntiVirusOverride"=dword:00000001
- "FirewallOverride"=dword:00000001
- [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
- "DisableMonitoring"=dword:00000001
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
- "EnableFirewall"= 0 (0x0)
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
- "%windir%\\system32\\sessmgr.exe"=
- "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
- "4680:TCP"= 4680:TCP:ozavsps
- R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/30/2007 5:49 PM 24344]
- S2 fnkhqq;iuhle;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 10:56 AM 14336]
- S2 ppyxsjbx;Monitor Time;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 10:56 AM 14336]
- S2 xopaeh;Time Security;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 10:56 AM 14336]
- S3 kaklaq;kaklaq;\??\c:\windows\system32\06.tmp --> c:\windows\system32\06.tmp [?]
- S3 rmvikqac;rmvikqac;\??\c:\windows\system32\07D.tmp --> c:\windows\system32\07D.tmp [?]
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
- ppyxsjbx
- [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4V85Q4NL-BOR5-282R-TT87-X5T45334W85I}]
- 2010-02-28 16:15 1241088 --sha-r- c:\windows\rootserveyn\svhost.exe
- .
- Contents of the 'Scheduled Tasks' folder
- 2010-03-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1123561945-839522115-1004UA.job
- - c:\documents and settings\common\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-18 06:34]
- .
- .
- ------- Supplementary Scan -------
- .
- uStart Page = hxxp://www.google.com/
- IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
- LSP: c:\windows\system32\idmmbc.dll
- Trusted Zone: microsoft.com\windowsupdate
- TCP: {0EB31EFF-1810-407A-A490-266899FE6433} = 202.53.160.6,202.53.160.7
- FF - ProfilePath -
- ---- FIREFOX POLICIES ----
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
- c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
- c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
- c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
- c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
- .
- - - - - ORPHANS REMOVED - - - -
- MSConfigStartUp-HKCU - c:\windows\system32\System32\iexplorerupdate.exe
- MSConfigStartUp-HKLM - c:\windows\system32\System32\iexplorerupdate.exe
- MSConfigStartUp-Server - c:\documents and settings\common\Application Data\Server.exe
- ActiveSetup-{825HQVO7-IJKC-FW3S-5V8L-JA8037Q8CV4O} - c:\windows\system32\System32\iexplorerupdate.exe
- ActiveSetup-{J11478O3-P45Q-18Q1-0YF8-554L3FH3EO6V} - c:\windows\system32\explorer\explorer.exe
- **************************************************************************
- catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
- Rootkit scan 2010-03-15 14:55
- Windows 5.1.2600 Service Pack 2 NTFS
- scanning hidden processes ...
- scanning hidden autostart entries ...
- scanning hidden files ...
- scan completed successfully
- hidden files: 0
- **************************************************************************
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kaklaq]
- "ImagePath"="\??\c:\windows\system32\06.tmp"
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\rmvikqac]
- "ImagePath"="\??\c:\windows\system32\07D.tmp"
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fnkhqq]
- "ServiceDll"="c:\windows\system32\uudxfvab.dll"
- --
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ppyxsjbx]
- "ServiceDll"="c:\windows\system32\uudxfvab.dll"
- --
- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\xopaeh]
- "ServiceDll"="c:\windows\system32\uudxfvab.dll"
- .
- --------------------- LOCKED REGISTRY KEYS ---------------------
- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
- @Denied: (Full) (Everyone)
- "scansk"=hex(0):8d,fe,d9,93,25,f8,17,83,1f,f9,4b,2f,e1,10,30,00,e0,60,4c,6c,e5,
- 51,a0,49,df,f4,2b,5a,e7,05,f4,43,58,35,29,e5,d4,2e,c9,12,00,00,00,00,00,00,\
- [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{d40da671-cd42-4b04-a650-6771070317ac}]
- @Denied: (Full) (Everyone)
- "Model"=dword:00000049
- "Therad"=dword:00000013
- .
- --------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - - > 'winlogon.exe'(1044)
- c:\windows\system32\Ati2evxx.dll
- c:\windows\system32\klogon.dll
- - - - - - - - > 'lsass.exe'(1100)
- c:\windows\system32\idmmbc.dll
- - - - - - - - > 'explorer.exe'(1908)
- c:\windows\system32\idmmbc.dll
- .
- ------------------------ Other Running Processes ------------------------
- .
- c:\windows\system32\Ati2evxx.exe
- c:\windows\system32\Ati2evxx.exe
- c:\windows\system32\wscntfy.exe
- .
- **************************************************************************
- .
- Completion time: 2010-03-15 14:57:05 - machine was rebooted
- ComboFix-quarantined-files.txt 2010-03-15 08:57
- Pre-Run: 21,002,465,280 bytes free
- Post-Run: 20,924,719,104 bytes free
- - - End Of File - - 0134CA7825632A10A23DAB1010C8A314
