ComboFix 10-08-18.04 - Mengsk 08/19/2010 23:45:06.1.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3326.2123 [GMT -5:00]
Running from: c:\users\Mengsk\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 72 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Mengsk\AppData\Local\Windows Server
c:\users\Mengsk\AppData\Local\Windows Server\admin.txt
c:\users\Mengsk\AppData\Local\Windows Server\flags.ini
c:\users\Mengsk\AppData\Local\Windows Server\hlp.dat
c:\users\Mengsk\AppData\Local\Windows Server\server.dat
c:\users\Mengsk\AppData\Local\Windows Server\uses32.dat
c:\users\Mengsk\AppData\Roaming\5D9D82DF7469F71EBD1AFDEC4BC901CE
c:\users\Mengsk\AppData\Roaming\5D9D82DF7469F71EBD1AFDEC4BC901CE\enemies-names.txt
c:\users\Mengsk\AppData\Roaming\5D9D82DF7469F71EBD1AFDEC4BC901CE\local.ini
c:\users\Mengsk\AppData\Roaming\5D9D82DF7469F71EBD1AFDEC4BC901CE\newsecureapp70700.exe
c:\users\Mengsk\AppData\Roaming\inst.exe
c:\users\Mengsk\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Antimalware Doctor.lnk
c:\users\Mengsk\AppData\Roaming\Microsoft\Windows\Start Menu\Antimalware Doctor.lnk
c:\users\Mengsk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antimalware Doctor
c:\users\Mengsk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antimalware Doctor\Antimalware Doctor.lnk
c:\users\Mengsk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Antimalware Doctor\Uninstall.lnk
c:\users\Mengsk\AppData\Roaming\Microsoft\Windows\Templates\memory.tmp
c:\users\Mengsk\Desktop\Antimalware Doctor.lnk
D:\install.exe
.
((((((((((((((((((((((((( Files Created from 2010-07-20 to 2010-08-20 )))))))))))))))))))))))))))))))
.
2010-08-20 04:51 . 2010-08-20 04:51 -------- d-----w- c:\users\Mengsk\AppData\Local\temp
2010-08-20 04:41 . 2010-08-20 04:41 -------- d-----w- C:\32788R22FWJFW
2010-08-19 22:44 . 2010-08-20 03:55 -------- d-----w- c:\users\Mengsk\AppData\Local\Windows
2010-08-15 01:41 . 2010-08-15 01:41 -------- d-----w- c:\windows\LastGood
2010-08-12 20:14 . 2010-06-16 16:04 905088 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-06 03:57 . 2010-08-06 03:57 47364 ----a-w- c:\programdata\Blizzard Entertainment\Battle.net\Cache\Download\Scan.dll
2010-08-05 03:49 . 2010-08-05 03:52 -------- d-----w- C:\Starcraft2_Video_Touchup
2010-08-04 07:27 . 2010-08-05 22:30 -------- d-----w- C:\Fraps
2010-07-31 18:26 . 2010-07-31 18:31 -------- d-----w- c:\users\Mengsk\AppData\Roaming\gtk-2.0
2010-07-31 18:17 . 2010-07-31 18:17 -------- d-----w- c:\program files\SystemRequirementsLab
2010-07-31 18:17 . 2010-07-31 18:17 85504 ----a-w- c:\users\Mengsk\AppData\Roaming\SystemRequirementsLab\srlproxy_cyri_4.1.71.0A.dll
2010-07-31 18:17 . 2010-07-31 18:17 -------- d-----w- c:\users\Mengsk\AppData\Roaming\SystemRequirementsLab
2010-07-29 05:20 . 2010-07-29 05:20 -------- d-----w- c:\program files\iPod
2010-07-29 05:17 . 2010-07-29 05:17 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-07-27 20:53 . 2010-07-27 20:53 -------- d-----w- c:\users\Mengsk\SC2-WingsOfLiberty-enUS-Installer
2010-07-27 20:28 . 2010-08-17 16:53 -------- d-----w- c:\program files\StarCraft II
2010-07-23 22:36 . 2010-07-23 22:36 2863 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp [Tag From Filename] Codec.dat
2010-07-23 22:36 . 2010-07-23 22:36 2894 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp [ReplayGain] Codec.dat
2010-07-23 22:36 . 2010-07-23 22:36 2996 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp [Multi Encoder] Codec.dat
2010-07-23 22:36 . 2010-07-23 22:36 2856 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp [Length Split] Codec.dat
2010-07-23 22:36 . 2010-07-23 22:36 2830 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp [ID Tag Update] Codec.dat
2010-07-23 22:36 . 2010-07-23 22:36 2993 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp [Channel Split] Codec.dat
2010-07-23 22:35 . 2010-07-23 22:35 2865 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp [Audio Info] Codec.dat
2010-07-23 22:35 . 2010-07-23 22:35 2873 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp [Arrange Audio] Codec.dat
2010-07-23 22:34 . 2010-07-23 22:34 10999 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp DSP Effects.dat
2010-07-23 22:34 . 2010-07-23 22:34 14639 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2010-07-23 22:33 . 2010-07-23 22:33 -------- d-----w- c:\program files\Illustrate
2010-07-23 22:27 . 2002-07-17 21:23 45056 ----a-w- c:\windows\system32\WNASPI32.DLL
2010-07-23 22:27 . 2002-07-17 21:20 84832 ----a-w- c:\windows\system32\drivers\ASPI32.SYS
2010-07-22 19:56 . 2010-07-22 19:56 -------- d-----w- C:\starcraftmaps
2010-07-22 05:48 . 2010-08-03 10:19 -------- d-----w- c:\program files\Common Files\Steam
2010-07-22 05:48 . 2010-08-13 10:33 -------- d-----w- c:\program files\Steam
2010-07-21 14:21 . 2010-07-21 14:21 4368224 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-07-21 14:21 . 2010-07-21 14:21 1615200 ----a-w- c:\programdata\avg9\update\backup\avgssie.dll
2010-07-21 14:21 . 2010-07-21 14:21 1373536 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2010-07-21 14:21 . 2010-07-21 14:21 1107296 ----a-w- c:\programdata\avg9\update\backup\avgxpl.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-20 04:40 . 2010-03-01 06:52 -------- d-----w- c:\program files\PeerGuardian2
2010-08-20 04:32 . 2009-12-03 02:47 -------- d-----w- c:\program files\Common Files\Akamai
2010-08-20 04:21 . 2010-02-14 03:58 0 ----a-w- c:\users\Mengsk\AppData\Local\prvlcl.dat
2010-08-20 04:10 . 2008-08-31 23:05 -------- d-----w- c:\users\Mengsk\AppData\Roaming\BitTorrent
2010-08-20 02:51 . 2009-04-07 17:04 -------- d-----w- c:\programdata\Google Updater
2010-08-17 16:52 . 2010-03-04 19:36 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-08-13 10:11 . 2009-02-10 18:22 -------- d-----w- c:\programdata\Microsoft Help
2010-08-13 10:01 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-10 05:21 . 2009-01-30 20:25 1 ----a-w- c:\users\Mengsk\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-07-29 05:20 . 2009-01-13 23:58 -------- d-----w- c:\program files\iTunes
2010-07-29 05:20 . 2008-07-19 02:11 -------- d-----w- c:\program files\Common Files\Apple
2010-07-27 20:42 . 2010-05-13 19:39 -------- d-----w- c:\programdata\Blizzard Entertainment
2010-07-26 04:01 . 2010-06-10 00:58 -------- d-----w- c:\program files\DVDFab 7
2010-07-26 04:01 . 2008-12-31 05:43 -------- d-----w- c:\users\Mengsk\AppData\Roaming\Vso
2010-07-20 05:09 . 2008-12-26 08:05 -------- d-----w- c:\program files\AVS4YOU
2010-07-20 02:18 . 2010-07-20 02:18 -------- d-----w- c:\program files\YouTube Downloader
2010-07-16 08:11 . 2009-12-07 02:20 -------- d-----w- c:\program files\Cheat Engine
2010-07-15 13:23 . 2010-02-10 03:22 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-15 13:23 . 2010-07-15 13:23 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-15 13:23 . 2010-02-10 03:22 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-06 05:42 . 2009-02-20 05:07 -------- d-----w- c:\programdata\DVD Shrink
2010-07-06 04:11 . 2010-07-06 04:11 -------- d-----w- c:\users\Mengsk\AppData\Roaming\ImgBurn
2010-07-06 02:55 . 2010-07-06 02:54 -------- d-----w- c:\program files\ImgBurn
2010-07-05 17:56 . 2008-07-19 02:13 -------- d-----w- c:\users\Mengsk\AppData\Roaming\Apple Computer
2010-07-05 05:08 . 2010-07-05 05:07 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-05 05:06 . 2010-07-05 05:05 -------- d-----w- c:\program files\QuickTime
2010-07-05 05:01 . 2008-07-19 02:13 -------- d-----w- c:\program files\Bonjour
2010-06-29 15:47 . 2010-08-12 20:15 834048 ----a-w- c:\windows\system32\wininet.dll
2010-06-28 16:13 . 2010-08-12 20:15 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-06-25 10:01 . 2009-02-10 18:25 -------- d-----w- c:\program files\Microsoft.NET
2010-06-21 13:37 . 2010-08-12 20:15 2037760 ----a-w- c:\windows\system32\win32k.sys
2010-06-18 17:31 . 2010-08-12 20:15 36864 ----a-w- c:\windows\system32\rtutils.dll
2010-06-18 15:04 . 2010-08-12 20:15 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-18 15:04 . 2010-08-12 20:15 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-06-11 16:16 . 2010-08-12 20:15 274944 ----a-w- c:\windows\system32\schannel.dll
2010-06-11 16:15 . 2010-08-12 20:15 1248768 ----a-w- c:\windows\system32\msxml3.dll
2010-06-08 17:35 . 2010-08-12 20:15 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-06-08 17:35 . 2010-08-12 20:15 3600768 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-06-02 13:28 . 2010-02-10 03:22 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-27 20:08 . 2010-08-12 20:15 81920 ----a-w- c:\windows\system32\iccvid.dll
2010-05-26 17:06 . 2010-06-10 00:07 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:47 . 2010-06-10 00:07 289792 ----a-w- c:\windows\system32\atmfd.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 15:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"Google Update"="c:\users\Mengsk\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-10-31 135664]
"Steam"="c:\program files\Steam\Steam.exe" [2010-07-27 1238352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2008-02-19 170528]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-19 13507104]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-19 92704]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"razer"="c:\program files\Razer\razerhid.exe" [2005-05-17 147456]
"USB2Check"="c:\windows\system32\PCLECoInst.dll" [2006-11-06 81920]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"DLCCCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2006-02-24 73728]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2009-07-07 647216]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-15 2065760]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2008-7-18 49220]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^Mengsk^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=c:\users\Mengsk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2006-01-12 19:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nmapp]
2009-07-08 08:53 472112 ----a-w- c:\program files\Pure Networks\Network Magic\nmapp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2008-11-02 08:38 167936 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2006-11-23 19:10 56928 ------w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vidalia]
2009-11-20 19:29 5262834 ----a-w- c:\program files\Vidalia Bundle\Vidalia\vidalia.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(

http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/cool.gif\' class=\'bbc_emoticon\' alt=\'B)\' />:58,a7,6c,dc,b8,64,ca,01
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1c912f4171e9450;Google Update Service (gupdate1c912f4171e9450);c:\program files\Google\Update\GoogleUpdate.exe [2008-09-10 133104]
R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys [2002-07-17 84832]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [2007-06-15 143256]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-06-30 28552]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-07-15 216400]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-07-15 243024]
S1 PStrip;PStrip;c:\windows\system32\drivers\pstrip.sys [2007-07-15 27992]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 atashost;WebEx Service Host for Support Center;c:\windows\system32\atashost.exe [2009-03-06 20376]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-07-15 308136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
2010-08-20 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-02-12 19:54]
2010-08-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-07 17:04]
2010-08-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-09-10 03:19]
2010-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-09-10 03:19]
2010-08-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3144074192-4086266024-1217872548-1000Core.job
- c:\users\Mengsk\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-26 06:45]
2010-08-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3144074192-4086266024-1217872548-1000UA.job
- c:\users\Mengsk\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-26 06:45]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.icq.com/
mStart Page = hxxp://www.alienware.com/mothership
uInternet Settings,ProxyOverride = *.local
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Mengsk\AppData\Roaming\Mozilla\Firefox\Profiles\nkn6p427.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - plugin: c:\users\Mengsk\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\Mengsk\AppData\Roaming\Move Networks\plugins\npqmp071502000008.dll
FF - plugin: c:\users\Mengsk\AppData\Roaming\Move Networks\plugins\npqmp071505000011.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-newsecureapp70700.exe - c:\users\Mengsk\AppData\Roaming\5D9D82DF7469F71EBD1AFDEC4BC901CE\newsecureapp70700.exe
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
MSConfigStartUp-ICQ - c:\program files\ICQ6.5\ICQ.exe
MSConfigStartUp-WinampAgent - c:\program files\Winamp\winampa.exe
AddRemove-Adobe_32fdd767b4383606e8168e834af5d90 - c:\program files\Common Files\Adobe\Installers\32fdd767b4383606e8168e834af5d90\Setup.exe
AddRemove-Adobe_85df662426fa6bb25f7d596f4d1b2a2 - c:\program files\Common Files\Adobe\Installers\85df662426fa6bb25f7d596f4d1b2a2\Setup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-08-19 23:51
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16?



























































?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3144074192-4086266024-1217872548-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5706BF73-D3AB-D393-33C1-3B24ACEE3136}*]
"hacchkokfpaiebnc"=hex:6a,61,6c,67,69,64,68,64,6e,61,63,61,6d,69,70,69,66,69,
6c,6c,00,3c
"iambnohfiaicbecbpj"=hex:6a,61,62,68,67,67,6f,63,65,6a,6d,70,63,6c,66,6a,6d,61,
6f,67,00,3c
.
Completion time: 2010-08-19 23:54:40
ComboFix-quarantined-files.txt 2010-08-20 04:54
Pre-Run: 80,543,137,792 bytes free
Post-Run: 80,966,254,592 bytes free
- - End Of File - - 5BC4D927CE646C2EF66EBBC45F09DF7A