John ... I didn't realize that there was a page two until this morning ... sorry about the last post. I did load ComboFix and have posted the current log below, and also the current Hijackthis log. Computer continues to show a strange program running at shutdown with strange names which change each shutdown. Other than that it works fine, but the shutdown problems continue to make me concerned about an infection. Thanks for working with me. JPB
PS ... found that the combo of the two logs was too long for the forum so I will add the Hijackthis log in a separate reply. Tks
ComboFix 10-04-28.04 - Jeffrey Benson 04/29/2010 8:35.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1502 [GMT -4:00]
Running from: d:\temp\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Jeffrey Benson\Application Data\inst.exe
C:\LOG2A6.tmp
.
((((((((((((((((((((((((( Files Created from 2010-03-28 to 2010-04-29 )))))))))))))))))))))))))))))))
.
2010-04-27 20:11 . 2010-04-29 03:32 0 ----a-w- c:\documents and settings\Jeffrey Benson\Local Settings\Application Data\prvlcl.dat
2010-04-25 04:49 . 2010-03-30 04:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-25 04:49 . 2010-04-25 04:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-25 04:49 . 2010-03-30 04:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-25 01:27 . 2010-04-25 01:27 -------- d-----w- C:\$AVG
2010-04-22 23:46 . 2010-04-22 23:46 -------- d-----w- c:\documents and settings\Jeffrey Benson\Application Data\Malwarebytes
2010-04-22 23:46 . 2010-04-22 23:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-22 12:19 . 2010-04-22 12:19 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-04-22 12:19 . 2010-04-22 12:19 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-22 12:19 . 2010-04-22 12:19 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-04-22 12:19 . 2010-04-22 12:19 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-22 12:19 . 2010-04-22 12:19 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-04-22 12:18 . 2010-04-29 11:57 -------- d-----w- c:\windows\system32\drivers\Avg
2010-04-22 12:18 . 2010-04-22 12:18 -------- d-----w- c:\program files\AVG
2010-04-22 12:18 . 2010-04-22 12:18 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-04-21 01:30 . 2010-04-21 01:30 -------- d-----w- c:\windows\system32\log
2010-04-21 01:29 . 2010-04-22 12:13 -------- d-----w- c:\program files\Trend Micro
2010-04-20 20:39 . 2010-04-20 20:39 -------- d-----w- c:\documents and settings\Jeffrey Benson\Application Data\AVP 2009
2010-04-20 20:14 . 2010-04-20 20:14 -------- d-----w- c:\windows\system32\wbem\Repository
2010-04-10 01:11 . 2010-04-10 01:11 3116520 ----a-w- c:\documents and settings\All Users\Application Data\TaxCut\2009\Downloads\HRBlockCT.exe
2010-04-10 00:12 . 2010-04-10 00:12 21195208 ----a-w- c:\documents and settings\All Users\Application Data\TaxCut\2009\Update\US65016901xupd.exe
2010-04-09 16:44 . 2010-04-09 16:44 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-04-09 16:44 . 2010-04-09 16:44 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-04-09 16:44 . 2010-04-09 16:44 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-04-09 16:44 . 2010-04-09 16:44 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-04-09 16:44 . 2010-04-09 16:44 49152 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-04-09 16:44 . 2010-04-09 16:44 40960 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-04-09 16:44 . 2010-04-09 16:44 341600 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-04-09 16:44 . 2010-04-09 16:44 308808 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-04-09 16:44 . 2010-04-09 16:44 14848 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-04-05 20:39 . 2008-05-16 23:50 258352 ----a-w- c:\windows\system32\unicows.dll
2010-04-05 20:39 . 1997-11-04 17:11 3146 ----a-w- c:\windows\system32\vsort.com
2010-04-05 00:38 . 2010-04-05 00:38 503808 ----a-w- c:\documents and settings\Jeffrey Benson\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6a4a13a3-n\msvcp71.dll
2010-04-05 00:38 . 2010-04-05 00:38 499712 ----a-w- c:\documents and settings\Jeffrey Benson\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6a4a13a3-n\jmc.dll
2010-04-05 00:38 . 2010-04-05 00:38 348160 ----a-w- c:\documents and settings\Jeffrey Benson\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-6a4a13a3-n\msvcr71.dll
2010-04-05 00:38 . 2010-04-05 00:38 61440 ----a-w- c:\documents and settings\Jeffrey Benson\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-4680a15e-n\decora-sse.dll
2010-04-05 00:38 . 2010-04-05 00:38 12800 ----a-w- c:\documents and settings\Jeffrey Benson\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-4680a15e-n\decora-d3d.dll
2010-04-03 19:03 . 2010-03-09 08:28 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-04-03 19:03 . 2010-04-03 19:03 152576 ----a-w- c:\documents and settings\Jeffrey Benson\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2010-04-01 21:13 . 2010-04-01 21:21 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2010-04-01 20:33 . 2010-04-01 20:33 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-04-01 20:32 . 2010-04-01 20:32 -------- d-----w- c:\program files\Common Files\Macrovision Shared
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-29 11:54 . 2007-07-29 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-04-28 12:50 . 2007-04-05 01:18 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-04-22 20:40 . 2008-10-23 13:28 -------- d-----w- c:\program files\Bonjour
2010-04-22 12:11 . 2007-07-20 16:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Trend Micro
2010-04-21 19:09 . 2007-04-04 02:51 105928 ----a-w- c:\documents and settings\Jeffrey Benson\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-20 21:10 . 2006-09-07 17:23 -------- d-----w- c:\program files\Google
2010-04-10 01:40 . 2007-04-06 18:40 118 ----a-w- c:\windows\wpd99.drv
2010-04-10 01:40 . 2007-04-06 18:40 51716 ----a-w- c:\windows\system32\pdf995mon.dll
2010-04-10 01:40 . 2007-04-06 18:40 249856 ----a-w- c:\windows\system32\pdfmona.dll
2010-04-10 00:33 . 2007-04-08 16:40 -------- d-----w- c:\documents and settings\Jeffrey Benson\Application Data\AdobeUM
2010-04-09 16:44 . 2006-09-07 17:18 -------- d-----w- c:\program files\Common Files\Real
2010-04-09 16:43 . 2009-11-22 12:44 -------- d-----w- c:\program files\Real
2010-04-05 00:38 . 2006-09-07 17:07 -------- d-----w- c:\program files\Common Files\Java
2010-04-05 00:38 . 2006-09-07 17:07 -------- d-----w- c:\program files\Java
2010-04-01 20:40 . 2006-09-07 17:25 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-24 18:17 . 2010-03-24 08:04 952768 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\406\AdobeARM.exe
2010-03-24 18:17 . 2010-03-24 08:04 70584 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\406\AdobeExtractFiles.dll
2010-03-24 18:17 . 2010-03-24 08:04 326056 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\406\ReaderUpdater.exe
2010-03-24 18:17 . 2010-03-24 08:04 326056 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\406\AcrobatUpdater.exe
2010-03-17 01:04 . 2010-03-17 01:04 19486488 ----a-w- c:\documents and settings\All Users\Application Data\TaxCut\2009\Update\US30026501xupd.exe
2010-03-17 01:03 . 2009-04-03 23:51 -------- d-----w- c:\documents and settings\Jeffrey Benson\Application Data\TaxCut
2010-03-17 00:57 . 2009-04-03 23:49 -------- d-----w- c:\documents and settings\All Users\Application Data\TaxCut
2010-03-11 15:22 . 2008-07-13 19:28 -------- d-----w- c:\documents and settings\Jeffrey Benson\Application Data\U3
2010-03-11 12:38 . 2005-08-16 09:18 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2005-08-16 09:18 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2005-08-16 09:18 17408 ------w- c:\windows\system32\corpol.dll
2010-03-09 11:09 . 2005-08-16 09:18 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-03-08 05:16 . 2007-04-04 02:27 -------- d-----w- c:\documents and settings\Jeffrey Benson\Application Data\Creative
2010-03-03 12:55 . 2010-03-03 12:55 -------- d-----w- c:\program files\Common Files\xing shared
2010-03-03 12:52 . 2010-03-03 12:52 33558 ----a-w- c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\Firefox_Toolbar_Uninstaller.exe
2010-03-02 12:30 . 2009-07-09 00:20 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-24 13:11 . 2006-09-07 16:47 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 14:08 . 2005-08-16 09:18 2146304 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2004-08-04 03:59 2024448 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2005-08-16 09:18 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2005-08-16 09:18 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoshopElements8SyncAgent"="d:\program files\Adobe\Elements Organizer 8.0\ElementsOrganizerSyncAgent.exe" [2009-09-06 1893728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-16 7323648]
"CTHelper"="CTHELPER.EXE" [2005-11-08 16384]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-03-02 18944]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 122880]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-02-16 1169776]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-02-16 1945960]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-02-16 149024]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-09-09 110592]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-04-09 202256]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RealUpgradeHelper"="c:\program files\Common Files\Real\Update_OB\upgrdhlp.exe" [2010-04-09 136744]
c:\documents and settings\Jeffrey Benson\Start Menu\Programs\Startup\
Dialog Helper.lnk - c:\program files\Avanquest\PowerDesk\pddlghlp.exe [2008-2-14 46336]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - d:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-4-7 113664]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-9-7 24576]
HotSync Manager.lnk - d:\program files\palmOne\Hotsync.exe [2004-6-9 471040]
Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-5-3 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-04-22 12:19 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-03-14 02:01 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Adobe\\Photoshop Elements 5.0\\AdobePhotoshopElementsMediaServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\Adobe\\Elements Organizer 8.0\\AdobePhotoshopElementsMediaServer.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP

HCP Discovery Service
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [4/22/2010 8:19 AM 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/22/2010 8:19 AM 216200]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/22/2010 8:19 AM 242896]
R2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;d:\program files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [9/6/2009 6:06 AM 169312]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [4/22/2010 8:18 AM 308064]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/22/2009 11:54 AM 691696]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/3/2010 8:53 AM 135664]
S3 yeddef;YEDDEF driver;c:\windows\system32\Drivers\yeddef.sys --> c:\windows\system32\Drivers\yeddef.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-04-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 19:42]
2010-04-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-04-04 20:28]
2010-04-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-03 12:53]
2010-04-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-03 12:53]
2010-04-29 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-3135458590-3166219386-4122233783-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
2010-04-29 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-3135458590-3166219386-4122233783-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:09]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.nytimes.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\documents and settings\Jeffrey Benson\Application Data\Mozilla\Firefox\Profiles\5oh59zcs.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage -
www.nytimes.com
FF - component: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - plugin: d:\program files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
FF - plugin: d:\program files\DivX\DivX Content Uploader\npUpload.dll
FF - plugin: d:\program files\DivX\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: d:\program files\DivX\DivX Web Player\npdivx32.dll
FF - plugin: d:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\program files\Netscape6\nppl3260.dll
FF - plugin: d:\program files\Netscape6\nprjplug.dll
FF - plugin: d:\program files\Netscape6\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
.
------- File Associations -------
.
.scr=AutoCADScript
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-PMA_ENT - d:\program files\AntiMalware Pro\AntiMalwarePro.exe
AddRemove-Dell Game Console - c:\program files\WildTangent\Apps\Dell Game Console\Uninstall.exe
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-29 08:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1024)
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
- - - - - - - > 'lsass.exe'(1080)
c:\windows\system32\relog_ap.dll
.
Completion time: 2010-04-29 08:39:53
ComboFix-quarantined-files.txt 2010-04-29 12:39
Pre-Run: 77,483,376,640 bytes free
Post-Run: 77,441,966,080 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
- - End Of File - - A1847331291EC89A727506250FDF31DF