Hi! I would just like you to know that 2 of the 3 pairs of the rundll.exe errors were gone. Thank you so much. Here's my new log.
ComboFix 09-07-09.07 - MISantos 07/11/2009 20:18.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.959.561 [GMT 8:00]
Running from: c:\documents and settings\misantos.PBCOM_MAIL\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\misantos.PBCOM_MAIL\Desktop\CFScript.txt
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}
FILE ::
"c:\windows\S0ADEF405.tmp"
"c:\windows\system32\akbpto.dll"
"c:\windows\system32\amqrijju.tmp"
"c:\windows\system32\aulhkxca.tmp"
"c:\windows\system32\j3201439.dll"
"c:\windows\system32\jwvtdawy.tmp"
"c:\windows\system32\lhhrihnq.tmp"
"c:\windows\system32\voiypneg.tmp"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\S0ADEF405.tmp
c:\windows\system32\amqrijju.tmp
c:\windows\system32\aulhkxca.tmp
c:\windows\system32\j3201439.dll
c:\windows\system32\jwvtdawy.tmp
c:\windows\system32\lhhrihnq.tmp
c:\windows\system32\voiypneg.tmp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_EWQWEEKG
-------\Legacy_GKMSIWGUJ
-------\Legacy_IXRSKKVJ
-------\Legacy_JPJUM
-------\Legacy_MZJSUY
-------\Legacy_PODCUP
-------\Legacy_TQWKYVF
-------\Service_ewqweekg
-------\Service_gkmsiwguj
-------\Service_ixrskkvj
-------\Service_jpjum
-------\Service_mzjsuy
-------\Service_podcup
-------\Service_tqwkyvf
((((((((((((((((((((((((( Files Created from 2009-06-11 to 2009-07-11 )))))))))))))))))))))))))))))))
.
2009-07-10 03:26 . 2009-07-10 03:26 -------- d-----w- c:\documents and settings\ernestine\Local Settings\Application Data\AVG Security Toolbar
2009-07-07 12:44 . 2009-07-07 12:45 -------- d-----w- C:\32788R22FWJFW.0.tmp
2009-07-07 12:22 . 2009-07-06 14:44 103424 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\Mozilla\Firefox\Profiles\84uqmbtl.default\extensions\piclens@cooliris. com\libs\pixomatic.dll
2009-07-07 12:22 . 2009-07-06 14:44 937984 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\Mozilla\Firefox\Profiles\84uqmbtl.default\extensions\piclens@cooliris. com\libs\PicLensHelper.exe
2009-07-07 12:22 . 2009-07-06 14:44 65536 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\Mozilla\Firefox\Profiles\84uqmbtl.default\extensions\piclens@cooliris. com\components\coolirisstub.dll
2009-07-07 12:22 . 2009-07-06 14:44 106496 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\Mozilla\Firefox\Profiles\84uqmbtl.default\extensions\piclens@cooliris. com\plugins\npcoolirisplugin.dll
2009-07-07 12:22 . 2009-07-06 14:44 4722688 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\Mozilla\Firefox\Profiles\84uqmbtl.default\extensions\piclens@cooliris. com\libs\cooliris19.dll
2009-07-07 12:22 . 2009-07-06 14:44 344064 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\Mozilla\Firefox\Profiles\84uqmbtl.default\extensions\piclens@cooliris. com\libs\LaunchCooliris.exe
2009-07-07 11:39 . 2009-06-11 02:23 327688 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgldx86.sys
2009-07-07 11:39 . 2009-06-11 02:23 3402008 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-07-07 11:39 . 2009-06-11 02:23 1204504 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgabout.dll
2009-07-07 11:39 . 2009-06-11 02:23 493336 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtbapi.dll
2009-07-07 11:39 . 2009-06-11 02:23 1368952 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgfws8.exe
2009-07-07 11:37 . 2009-06-11 02:22 1085208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-07-06 09:50 . 2009-07-06 09:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-07-01 10:50 . 2009-07-11 12:14 0 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Local Settings\Application Data\prvlcl.dat
2009-06-20 13:13 . 2009-06-20 13:12 2052376 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-06-17 02:23 . 2009-06-17 02:22 3298072 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-06-17 02:23 . 2009-06-17 02:21 829208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-06-17 02:23 . 2009-06-11 02:23 1261344 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwd.dll
2009-06-17 02:20 . 2009-06-17 02:20 1454360 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-06-12 13:28 . 2009-06-12 13:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-06-12 13:27 . 2009-06-12 13:27 -------- d-----w- c:\program files\Electronic Arts
2009-06-12 13:27 . 2008-09-04 18:22 447752 ----a-r- c:\windows\system32\vp6vfw.dll
2009-06-12 13:27 . 2009-06-12 13:27 10134 ----a-r- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-12 13:27 . 2009-06-12 13:27 -------- d-----w- c:\program files\Microsoft WSE
2009-06-12 13:26 . 2006-09-28 08:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2009-06-12 13:26 . 2009-06-12 13:26 -------- d-----w- c:\windows\Logs
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-07 11:38 . 2009-03-28 09:25 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-17 09:55 . 2008-10-21 10:54 -------- d-----w- c:\program files\Total Video Converter
2009-06-17 02:22 . 2009-03-28 09:25 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-12 13:28 . 2006-12-21 07:48 49264 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-12 13:02 . 2006-12-21 05:00 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-11 06:20 . 2007-11-18 14:42 -------- d-----w- c:\program files\IrfanView
2009-06-11 06:01 . 2009-06-11 06:01 -------- d-----w- c:\program files\MSBuild
2009-06-11 06:00 . 2009-06-11 06:00 -------- d-----w- c:\program files\Reference Assemblies
2009-06-11 05:55 . 2009-06-11 05:55 -------- d-----w- c:\program files\MSXML 6.0
2009-06-11 05:50 . 2009-06-11 05:50 -------- d-----w- c:\program files\MSXML 4.0
2009-06-11 04:05 . 2009-06-11 02:24 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-11 02:24 . 2009-06-11 02:24 -------- d-----w- c:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-06-11 02:23 . 2009-06-11 02:24 826344 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\AVGToolbarInstall.exe
2009-06-09 15:15 . 2008-06-11 15:05 -------- d-----w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\Uniblue
2009-06-09 12:22 . 2009-06-09 12:22 -------- d-----w- c:\program files\Trend Micro
2009-06-06 15:52 . 2009-06-06 15:52 -------- d-----w- c:\program files\SystemRequirementsLab
2009-06-06 15:52 . 2009-06-06 15:49 -------- d-----w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\SystemRequirementsLab
2009-06-06 15:49 . 2009-06-06 15:49 207872 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\SystemRequirementsLab\SRLProxy_srl_4.dll
2009-06-06 15:49 . 2009-06-06 15:49 207872 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\SystemRequirementsLab\SRLProxy_srl_3.dll
2009-06-06 15:49 . 2009-06-06 15:49 207872 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\SystemRequirementsLab\SRLProxy_srl_2.dll
2009-06-06 15:49 . 2009-06-06 15:49 207872 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\SystemRequirementsLab\SRLProxy_srl_1.dll
2009-06-06 12:57 . 2006-12-22 15:08 -------- d-----w- c:\documents and settings\All Users\Application Data\yahoo!
2009-06-06 12:26 . 2006-12-21 04:16 86327 ----a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-06-03 07:17 . 2006-12-23 03:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-06-02 05:38 . 2009-06-11 04:05 1004800 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-05-15 07:20 . 2007-03-15 12:48 -------- d-----w- c:\program files\Java
2009-05-15 07:19 . 2009-05-15 07:19 152576 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-07 15:44 . 2009-06-03 08:27 344064 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:52 . 2003-03-31 12:00 659456 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:52 . 2006-12-21 05:53 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-26 14:09 . 2009-04-26 14:09 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-04-24 09:34 . 2009-03-28 09:25 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-04-24 09:34 . 2009-03-28 09:25 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-04-24 09:34 . 2009-03-28 09:24 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2009-04-24 09:34 . 2009-03-28 09:24 29208 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2009-04-24 09:34 . 2009-03-28 09:25 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-04-17 09:58 . 2009-06-03 08:27 1846656 ----a-w- c:\windows\system32\win32k.sys
2009-04-17 08:58 . 2009-05-07 06:48 65536 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\Mozilla\Firefox\Profiles\84uqmbtl.default\extensions\piclens@cooliris. com-trash\components\coolirisstub.dll
2009-04-17 08:58 . 2009-05-07 06:48 4534272 ----a-w- c:\documents and settings\misantos.PBCOM_MAIL\Application Data\Mozilla\Firefox\Profiles\84uqmbtl.default\extensions\piclens@cooliris. com-trash\libs\cooliris19.dll
2009-04-16 08:20 . 2009-04-16 08:09 156672 ----a-w- c:\windows\system32\rmc_fixasf.exe
2009-04-16 08:19 . 2009-04-16 08:09 237568 ----a-w- c:\windows\system32\rmc_rtspdl.dll
2009-04-16 08:19 . 2009-04-16 08:08 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL
2009-04-15 15:11 . 2003-03-31 12:00 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2007-12-01 14:15 . 2007-12-01 14:16 774144 ----a-w- c:\program files\RngInterstitial.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-10_11.10.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-11 12:24 . 2009-07-11 12:24 16384 c:\windows\Temp\Perflib_Perfdata_204.dat
+ 2003-03-31 12:00 . 2009-07-11 12:14 68354 c:\windows\system32\perfc009.dat
- 2003-03-31 12:00 . 2009-07-10 10:36 68354 c:\windows\system32\perfc009.dat
+ 2003-03-31 12:00 . 2009-07-11 12:14 435498 c:\windows\system32\perfh009.dat
- 2003-03-31 12:00 . 2009-07-10 10:36 435498 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-02 05:38 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-05 68856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-08-22 94208]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-03-28 3325952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-06-14 7573504]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-01-06 81920]
"SystemOptimizer"="c:\windows\system32\vqdawpim.dll" [2009-04-02 20]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-08 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-03 158208]
"AVGIDS"="c:\program files\AVG\AVG8\IdentityProtection\agent\bin\AVGIDSUI.exe" [2009-02-26 1579528]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-11 1948440]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" - c:\windows\system32\CHDAudPropShortcut.exe [2006-04-18 61952]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-13 581693]
KYESCAN.lnk - c:\progra~1\ScannerU\KYESCAN.EXE [2007-8-3 172032]
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-24 09:34 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^misantos.PBCOM_MAIL^Start Menu^Programs^Startup^Multiply AutoUploader.lnk]
path=c:\documents and settings\misantos.PBCOM_MAIL\Start Menu\Programs\Startup\Multiply AutoUploader.lnk
backup=c:\windows\pss\Multiply AutoUploader.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Zapu\\Zapu\\wDivi.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Intuwave\\Shared\\mRouterRuntime\\mRouterRuntime.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"6784:TCP"= 6784:TCP:eleeplkh
R0 AVGIDSErHr;AVGIDSErHr;c:\windows\system32\drivers\AVGIDSErHr.sys [2/26/2009 12:46 PM 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [3/28/2009 5:25 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/28/2009 5:25 PM 335752]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/28/2009 5:25 PM 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/28/2009 5:25 PM 298776]
R2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [4/24/2009 5:34 PM 1368952]
R2 AVGIDSWatcher;AVGIDSWatcher;c:\program files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSWatcher.exe [2/26/2009 12:46 PM 563720]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [3/28/2009 5:24 PM 29208]
R3 AVGIDSDriver;AVGIDSDriver;c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_XP\AVGIDSDriver.sys [2/26/2009 12:46 PM 121352]
R3 AVGIDSFilter;AVGIDSFilter;c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_XP\AVGIDSFilter.sys [2/26/2009 12:46 PM 30216]
R3 AVGIDSShim;AVGIDSShim;c:\program files\AVG\AVG8\IdentityProtection\agent\driver\platform_XP\AVGIDSShim.sys [2/26/2009 12:46 PM 27232]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSAgent.exe [2/26/2009 12:46 PM 5576712]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [3/28/2009 5:24 PM 29208]
.
Contents of the 'Scheduled Tasks' folder
2009-01-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 04:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyServer = 192.168.107.220:80
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search -
http://edits.mywebsearch.com/toolbar...tml?p=ZUfox000
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: getmirar.com\click
Trusted Zone: mirarsearch.com\click
Trusted Zone: mirarsearch.com\redirect
Trusted Zone: net-nucleus.com\awbeta
TCP: {AB7EFFA7-D66B-4FC6-8A3B-8E2D7DDBC0BB} = 192.168.1.1
FF - ProfilePath - c:\documents and settings\misantos.PBCOM_MAIL\Application Data\Mozilla\Firefox\Profiles\84uqmbtl.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www1.yoog.com/search.php?q=
FF - prefs.js: browser.search.selectedEngine - Yoog Search
FF - prefs.js: browser.startup.homepage - chrome://fastdial/content/fastdial.html
FF - prefs.js: keyword.URL - hxxp://www1.yoog.com/search.php?q=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\misantos.PBCOM_MAIL\Application Data\Mozilla\Firefox\Profiles\84uqmbtl.default\extensions\piclens@cooliris. com\components\coolirisstub.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils 2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils 3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils 35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\misantos.PBCOM_MAIL\Application Data\Mozilla\Firefox\Profiles\84uqmbtl.default\extensions\piclens@cooliris. com\plugins\npcoolirisplugin.dll
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: google.toolbar.linkdoctor.enabled - false
FF - user.js: browser.search.defaultenginename - Yoog Search
FF - user.js: browser.search.defaulturl - hxxp://www1.yoog.com/search.php?q=
FF - user.js: browser.search.selectedEngine - Yoog Search
FF - user.js: keyword.URL - hxxp://www1.yoog.com/search.php?q=
FF - user.js: keyword.enabled - true
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-11 20:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1715567821-436374069-839522115-2484\Software\SecuROM\License information*]
"datasecu"=hex:d8,e9,a4,7f,52,f5,21,e0,79,1e,87,11,8a,09,f1,a6,b0,74,50,de, 86,
bf,15,2c,22,da,33,ba,4f,23,50,a1,f7,b0,d1,0e,b5,1a,b1,23,3b,a6,26,de,8c,89, \
"rkeysecu"=hex:0a,a9,c9,5f,f1,ad,d2,47,6e,d9,a8,f9,f8,94,a3,bf
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\program files\WIDCOMM\Bluetooth Software\BTStackServer.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-07-11 20:28 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-11 12:28
Pre-Run: 12,395,548,672 bytes free
Post-Run: 12,371,976,192 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
287