ComboFix 10-03-14.04 - 03/15/2010 1:08.1.2 - x86
Microsoft Windows 7 Ultimate [GMT -7:00]
Running from: c:\users\Toshiba1\Downloads\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {}
SP: AVG Anti-Virus *enabled* (Updated) }
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Toshiba1\AppData\Roaming\NP.sys
D:\lsass.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_GoogleUpdateBeta
((((((((((((((((((((((((( Files Created from 2010-02-15 to 2010-03-15 )))))))))))))))))))))))))))))))
.
2010-03-15 08:03 . 2010-03-15 08:06 -------- d-----w- C:\32788R22FWJFW
2010-03-15 07:47 . 2010-03-15 07:51 -------- d-----w- c:\users\Toshiba1\AppData\Roaming\QuickScan
2010-03-15 06:45 . 2010-03-15 06:45 -------- d-----w- c:\users\Toshiba1\AppData\Roaming\Palo Alto Software
2010-03-15 06:40 . 2010-03-15 06:40 -------- d-----w- c:\program files\Common Files\Intuit
2010-03-15 06:39 . 2010-03-15 06:39 -------- d-----w- c:\programdata\Palo Alto Software
2010-03-15 06:39 . 2010-03-15 06:39 -------- d-----w- c:\program files\Common Files\Palo Alto Software
2010-03-15 06:39 . 2010-03-15 06:39 -------- d-----w- c:\program files\Palo Alto Software
2010-03-15 05:52 . 2010-03-15 05:52 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-03-15 05:47 . 2010-03-15 08:21 -------- d-----w- c:\programdata\NOS
2010-03-15 05:29 . 2010-03-15 05:29 -------- d-----w- C:\PAS
2010-03-15 05:29 . 2010-03-15 05:30 -------- d-----w- c:\program files\Common Files\InstallShield
2010-03-15 03:46 . 2010-03-15 03:46 -------- d-----w- c:\windows\Start Menu
2010-03-15 03:46 . 2010-03-15 03:44 286720 ----a-w- c:\windows\iun505.exe
2010-03-15 03:45 . 2010-03-15 03:46 -------- d-----w- C:\nightlite
2010-03-14 21:57 . 2010-03-14 21:57 -------- d-----w- c:\users\Toshiba1\AppData\Local\Google
2010-03-14 21:50 . 2010-03-15 06:43 -------- d-----w- c:\users\Toshiba1\AppData\Roaming\LimeWire
2010-03-14 21:49 . 2010-03-14 21:49 -------- d-----w- c:\program files\Common Files\Java
2010-03-14 21:48 . 2010-03-14 21:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-14 21:48 . 2010-03-14 21:48 -------- d-----w- c:\program files\Java
2010-03-14 21:47 . 2010-03-14 21:49 -------- d-----w- c:\program files\LimeWire
2010-03-13 23:58 . 2010-03-14 02:02 -------- d-----w- c:\programdata\FLEXnet
2010-03-13 22:49 . 2010-03-13 22:49 -------- d-----w- c:\program files\Adobe Media Player
2010-03-13 22:44 . 2010-03-15 05:54 -------- d-----w- c:\users\Toshiba1\AppData\Local\Adobe
2010-03-13 22:31 . 2010-03-15 05:53 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-13 21:57 . 2010-03-13 21:57 199168 --sha-r- c:\windows\system32\KBDMLT479.dll
2010-03-12 04:16 . 2010-03-12 04:16 -------- d-----w- c:\users\Toshiba1\AppData\Local\IsolatedStorage
2010-03-11 15:04 . 2010-03-11 15:04 -------- d-----w- c:\program files\BitLord
2010-03-11 07:17 . 2010-03-11 07:21 -------- d-----w- c:\users\Toshiba1\AppData\Roaming\SmartDraw
2010-03-11 07:07 . 2010-03-11 07:17 -------- d-----w- c:\program files\SmartDraw 2008
2010-03-11 06:13 . 2010-03-11 07:03 -------- d-----w- c:\program files\Hardscape Imaging Software
2010-03-11 06:13 . 2010-03-11 06:13 -------- d-----w- c:\windows\Hardscape Imaging Software
2010-03-09 07:19 . 2010-03-09 07:19 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-03-09 06:43 . 2010-03-09 06:43 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2010-03-09 06:41 . 2010-03-09 06:43 -------- d-----w- c:\program files\DivX
2010-03-09 06:41 . 2010-03-09 06:41 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-03-09 06:37 . 2009-12-08 11:40 3955288 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-03-09 06:37 . 2009-12-08 11:40 3899464 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-03-09 06:37 . 2009-12-08 11:32 292864 ----a-w- c:\windows\system32\apphelp.dll
2010-03-09 01:52 . 2010-02-24 17:16 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-03-08 07:27 . 2010-03-08 07:27 1301854 ----a-w- c:\windows\XSitePro2 Uninstaller.exe
2010-03-08 07:21 . 2010-03-08 07:21 -------- d-----w- c:\program files\Common Files\Thraex Software
2010-03-08 07:21 . 2010-03-08 07:23 -------- d-----w- c:\program files\XSitePro2
2010-03-08 07:06 . 2008-11-10 19:41 32656 ----a-w- c:\windows\system32\msonpmon.dll
2010-03-08 07:06 . 2006-10-27 03:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-03-08 07:03 . 2010-03-08 07:14 -------- d-----w- c:\program files\Microsoft Works
2010-03-08 07:02 . 2010-03-08 07:02 -------- d-----w- c:\program files\Microsoft.NET
2010-03-08 06:59 . 2010-03-08 06:59 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-03-08 06:57 . 2010-03-08 06:57 -------- d-----w- c:\users\Toshiba1\AppData\Local\Microsoft Help
2010-03-08 06:57 . 2010-03-13 00:25 -------- d-----w- c:\programdata\Microsoft Help
2010-03-08 06:51 . 2010-03-08 07:26 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2010-03-08 06:51 . 2010-03-08 07:26 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-03-08 06:51 . 2010-03-08 07:26 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-08 06:51 . 2010-03-08 07:26 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-08 06:51 . 2010-03-08 07:26 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-03-08 06:51 . 2010-03-15 02:59 -------- d-----w- c:\windows\system32\drivers\Avg
2010-03-08 06:50 . 2010-03-08 06:50 -------- d-----w- c:\program files\AVG
2010-03-08 06:50 . 2010-03-08 06:50 -------- d-----w- c:\programdata\avg8
2010-03-08 05:01 . 2010-03-08 05:01 0 ----a-w- c:\windows\ativpsrm.bin
2010-03-08 04:51 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-03-08 04:15 . 2009-10-31 05:45 2614272 ----a-w- c:\windows\explorer.exe
2010-03-08 04:15 . 2009-10-28 06:17 285696 ----a-w- c:\windows\system32\winlogon.exe
2010-03-08 04:15 . 2009-08-29 06:57 34816 ----a-w- c:\windows\system32\msasn1.dll
2010-03-08 04:15 . 2009-10-02 04:06 728648 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2010-03-08 04:15 . 2009-09-03 07:04 1320960 ----a-w- c:\windows\system32\CertEnroll.dll
2010-03-08 04:15 . 2009-08-19 07:20 442920 ----a-w- c:\windows\system32\winresume.exe
2010-03-08 04:15 . 2009-08-19 07:20 507568 ----a-w- c:\windows\system32\winload.exe
2010-03-08 04:15 . 2009-08-29 06:54 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-03-08 03:34 . 2010-03-08 03:34 -------- d-----w- c:\users\Toshiba1\AppData\Local\DND
2010-03-08 03:34 . 2010-03-08 03:34 -------- d-----w- c:\programdata\DND
2010-03-08 03:30 . 2010-03-08 03:30 -------- d-----w- c:\users\Toshiba1\AppData\Local\Apps
2010-03-08 03:30 . 2010-03-15 05:32 -------- d-----w- c:\users\Toshiba1\AppData\Local\Deployment
2010-03-08 01:16 . 2010-03-08 01:16 -------- d-----w- c:\program files\Digital Integration Ltd
2010-03-08 01:12 . 2010-03-14 00:53 -------- d-----w- c:\users\Toshiba1\Tracing
2010-03-07 23:39 . 2010-03-07 23:39 -------- d-----w- c:\program files\Microsoft
2010-03-07 23:38 . 2010-03-07 23:38 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-03-07 23:38 . 2010-03-07 23:39 -------- d-----w- c:\program files\Windows Live
2010-03-07 23:37 . 2010-03-07 23:37 -------- d-----w- c:\windows\PCHEALTH
2010-03-07 23:37 . 2010-03-15 06:41 -------- d-sh--w- c:\windows\Installer
2010-03-07 23:32 . 2010-03-07 23:32 -------- d-----w- c:\program files\Common Files\Windows Live
2010-03-07 23:31 . 2010-03-08 07:52 108824 ----a-w- c:\users\Toshiba1\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-07 21:42 . 2010-03-07 21:42 -------- d-----w- c:\windows\system32\Macromed
2010-03-07 21:42 . 2010-03-07 21:42 -------- d-----w- c:\programdata\McAfee
2010-03-07 21:36 . 2010-03-07 21:36 -------- d-----w- c:\users\Toshiba1\AppData\Local\Mozilla
2010-03-07 21:04 . 2010-03-07 21:04 -------- d-----w- c:\users\Toshiba1\AppData\Local\Diagnostics
2010-03-07 20:22 . 2010-03-15 02:12 -------- d-----w- c:\windows\system32\wbem\Performance
2010-03-07 19:43 . 2010-03-07 20:20 -------- d-----w- c:\windows\Panther
2010-03-07 19:29 . 2010-03-07 19:29 -------- d-----w- C:\Windows.old
1601-01-01 00:00 . 1601-01-01 00:00 -------- d-----w- c:\program files\NOS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-15 05:30 . 2010-03-15 05:30 -------- d-----w- c:\programdata\PAS
2010-03-11 01:50 . 2010-03-11 01:50 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-03-08 07:03 . 2009-07-14 04:52 -------- d-----w- c:\program files\MSBuild
2010-02-02 07:45 . 2010-03-08 04:14 2048 ----a-w- c:\windows\system32\tzres.dll
2010-01-18 23:29 . 2010-03-08 04:14 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-18 23:29 . 2010-03-08 04:14 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-18 23:29 . 2010-03-08 04:14 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-18 23:29 . 2010-03-08 04:14 369152 ----a-w- c:\windows\system32\secproc.dll
2010-01-18 23:28 . 2010-03-08 04:14 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-18 23:28 . 2010-03-08 04:14 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-18 23:28 . 2010-03-08 04:14 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-18 23:28 . 2010-03-08 04:14 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-08 03:18 . 2010-03-08 04:14 221184 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-01-08 03:17 . 2010-03-08 04:14 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-19 09:02 . 2010-03-08 04:14 977920 ----a-w- c:\windows\system32\wininet.dll
2009-12-19 09:02 . 2010-03-08 04:14 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-19 09:02 . 2010-03-08 04:14 1328640 ----a-w- c:\windows\system32\quartz.dll
2009-12-19 09:02 . 2010-03-08 04:14 22016 ----a-w- c:\windows\system32\msyuv.dll
2009-12-19 09:02 . 2010-03-08 04:14 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-19 09:02 . 2010-03-08 04:14 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-19 09:02 . 2010-03-08 04:14 84480 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-19 09:02 . 2010-03-08 04:14 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-19 09:02 . 2010-03-08 04:14 91648 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-03-10 2043160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"NCInstallQueue"="netman.dll" [2009-07-14 280576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Palo Alto Software Update Manager 8.0.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Palo Alto Software Update Manager 8.0.lnk
backup=c:\windows\pss\Palo Alto Software Update Manager 8.0.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Toshiba1^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\users\Toshiba1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 22:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 08:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 19:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-27 00:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-11 22:21 246504 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2010-03-08 12552]
S1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-03-08 335240]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-03-08 108552]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2010-03-08 908056]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2010-03-10 297752]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
.
Contents of the 'Scheduled Tasks' folder
2010-03-15 c:\windows\Tasks\SDMsgUpdate (SD).job
- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2010-03-11 22:39]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Toshiba1\AppData\Roaming\Mozilla\Firefox\Profiles\lgoedzjb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\users\Toshiba1\AppData\Roaming\Mozilla\Firefox\Profiles\lgoedzjb.default\extensions\{7c5c0f58-e061-457d-9033-77307f5ed00c}\components\FFAlert.dll
FF - component: c:\users\Toshiba1\AppData\Roaming\Mozilla\Firefox\Profiles\lgoedzjb.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\users\Toshiba1\AppData\Roaming\Mozilla\Firefox\Profiles\lgoedzjb.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
HKCU-Run-MSWUpdate - c:\users\Toshiba1\AppData\Roaming\lsass.exe
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\rundll32.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\AVG\AVG8\avgtray.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Completion time: 2010-03-15 01:28:58 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-15 08:28
Pre-Run: 60,427,345,920 bytes free
Post-Run: 60,612,091,904 bytes free
- - End Of File - - 3724A573C281F17CB477FB22B9927EFF