ComboFix Log:
ComboFix 10-01-28.05 - HP_Administrator 01/29/2010 0:11.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.135 [GMT -5:00]
Running from: c:\documents and settings\HP_Administrator\My Documents\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\HP_Administrator\Local Settings\Temp\IadHide5.dll
.
---- Previous Run -------
.
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\HP_Administrator\Application Data\inst.exe
c:\documents and settings\HP_Administrator\Local Settings\Temp\IadHide5.dll
c:\program files\Internet Explorer\SET346.tmp
c:\program files\Internet Explorer\SET347.tmp
c:\program files\Internet Explorer\SET349.tmp
C:\Thumbs.db
c:\windows\system32\ps2.bat
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-29 )))))))))))))))))))))))))))))))
.
2010-01-29 04:07 . 2010-01-29 04:07 -------- d-----w- c:\program files\Trend Micro
2010-01-29 03:36 . 2010-01-29 03:36 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2010-01-29 03:36 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-29 03:36 . 2010-01-29 03:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-29 03:36 . 2010-01-29 03:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-29 03:36 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-28 00:05 . 2010-01-28 00:05 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-01-28 00:05 . 2010-01-28 00:05 -------- d-----w- c:\program files\NOS
2010-01-24 21:09 . 2010-01-24 21:20 69 ----a-w- c:\documents and settings\HP_Administrator\jagex_runescape_preferences2.dat
2010-01-24 21:07 . 2010-01-24 21:41 39 ----a-w- c:\documents and settings\HP_Administrator\jagex_runescape_preferences.dat
2010-01-19 21:12 . 2010-01-05 10:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-19 21:12 . 2010-01-05 10:00 78336 ----a-w- c:\windows\system32\dllcache\ieencode.dll
2010-01-19 06:17 . 2010-01-19 06:17 -------- d-----w- c:\windows\system32\XPSViewer
2010-01-19 06:17 . 2010-01-19 06:17 -------- d-----w- c:\program files\MSBuild
2010-01-19 06:17 . 2010-01-19 06:17 -------- d-----w- c:\program files\Reference Assemblies
2010-01-19 06:03 . 2010-01-19 06:03 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\PCHealth
2010-01-19 05:40 . 2010-01-19 05:40 -------- d-----w- c:\program files\Drug Lord 2
2010-01-19 05:25 . 2010-01-19 05:25 -------- d-sh--w- c:\documents and settings\HP_Administrator\IECompatCache
2010-01-19 05:01 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-01-19 05:01 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-01-19 05:01 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-01-19 05:01 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-01-19 05:01 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-01-19 05:00 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-01-19 05:00 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-01-19 05:00 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-01-19 05:00 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2010-01-19 05:00 . 2010-01-19 05:01 -------- d-----w- C:\7456fae64d2703008ce29891e4
2010-01-19 04:59 . 2010-01-19 04:59 -------- d-----w- C:\e223ee57ef465f2ed1aa7d
2010-01-19 04:59 . 2010-01-19 05:05 -------- d-----w- C:\ab395b3ade1fce835126333e
2010-01-18 23:34 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-01-18 23:33 . 2009-10-15 16:28 81920 ------w- c:\windows\system32\dllcache\fontsub.dll
2010-01-18 23:33 . 2009-10-15 16:28 119808 ------w- c:\windows\system32\dllcache\t2embed.dll
2010-01-18 23:32 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2010-01-18 23:30 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2010-01-18 19:36 . 2010-01-18 19:36 -------- d-sh--w- c:\documents and settings\Tom.YOUR-B27FB1C401\IECompatCache
2010-01-05 10:00 . 2010-01-05 10:00 17408 ------w- c:\windows\system32\dllcache\corpol.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-25 04:13 . 2005-12-03 21:26 -------- d-----w- c:\program files\Yahoo!
2010-01-25 02:53 . 2009-02-17 04:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-01-25 02:44 . 2005-08-09 17:00 -------- d-----w- c:\program files\Google
2010-01-25 02:44 . 2007-04-22 21:57 -------- d-----w- c:\program files\FreeRIP2
2010-01-25 02:43 . 2005-08-09 16:57 -------- d-----w- c:\program files\Easy Internet signup
2010-01-25 02:42 . 2008-12-07 02:49 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Vso
2010-01-25 02:42 . 2008-12-07 02:49 47360 ----a-w- c:\documents and settings\HP_Administrator\Application Data\pcouffin.sys
2010-01-25 02:42 . 2008-12-07 02:49 47360 ----a-w- c:\documents and settings\HP_Administrator\Application Data\pcouffin.sys
2010-01-25 02:39 . 2009-04-06 03:13 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Any Video Converter Professional
2010-01-25 02:22 . 2005-11-14 03:34 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-01-25 02:20 . 2005-08-09 17:03 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-25 02:20 . 2005-08-09 17:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-25 02:13 . 2005-11-16 19:43 67360 ----a-w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-25 02:12 . 2006-10-12 22:07 -------- d-----w- c:\program files\LimeWire
2010-01-23 21:30 . 2007-05-05 01:12 -------- d-----w- c:\program files\World of Warcraft
2010-01-21 03:36 . 2010-01-25 03:01 209056 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
2010-01-19 21:05 . 2008-11-08 17:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-01-19 21:05 . 2006-01-13 16:01 -------- d-----w- c:\program files\Norton AntiVirus
2010-01-05 10:00 . 2004-08-10 19:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-10 19:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-11-21 15:51 . 2004-08-10 19:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-06-08 17:59 . 2009-06-08 17:59 5632 --sha-w- c:\program files\Thumbs.db
2006-10-09 17:53 . 2006-10-09 17:53 277504 ----a-w- c:\program files\EE_CE_Presentation.ppt
2005-12-04 00:20 . 2005-12-04 00:18 947510784 ----a-w- c:\program files\armyops250.exe
2005-12-04 00:14 . 2005-12-04 00:14 776783 ----a-w- c:\program files\texasdemo.exe
2005-11-17 19:49 . 2005-11-17 19:49 3055906 ----a-w- c:\program files\ptabe1_7.zip
2007-08-17 14:16 . 2007-06-10 00:56 66672 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2007-08-17 14:16 . 2007-06-10 00:56 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2007-08-17 14:16 . 2007-06-10 00:56 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2007-08-17 14:16 . 2007-06-10 00:56 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2007-08-17 14:16 . 2007-06-10 00:56 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"igndlm.exe"="c:\program files\IGN\Download Manager\DLM.exe" [2007-03-05 1103480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-14 68856]
"cdloader"="c:\documents and settings\HP_Administrator\Application Data\mjusbsp\cdloader2.exe" [2008-12-17 50520]
"rty"="c:\windows\tempie\rty.exe" [2009-05-02 65536]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-09 98304]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-11 253952]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-11 59392]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-19 185872]
"InetCntrl"="c:\windows\system32\InetCntrl\InetCntrl.exe" [2009-01-26 841048]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Kodak EasyShare software.lnk - c:\program files\KODAK\Kodak EasyShare software\bin\EasyShare.exe [2002-6-26 290816]
KODAK Software Updater.lnk - c:\program files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe [2002-3-13 16384]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-12 83360]
Updates from HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2005-8-9 36903]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\KODAK\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Documents and Settings\\Tom.YOUR-B27FB1C401\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Documents and Settings\\HP_Administrator\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\America's Army\\System\\ArmyOps.exe"=
"c:\\WINDOWS\\system32\\InetCntrl\\InetCntrl.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"43594:TCP"= 43594:TCP:rune
"43595:TCP"= 43595:TCP:rune
"5060:UDP"= 5060:UDP:MJ1
"5070:UDP"= 5070:UDP:MJ2
"3724:TCP"= 3724:TCP:WoW Servers
"1119:TCP"= 1119:TCP:Wow
"3724:UDP"= 3724:UDP:Wow2
R1 bsofrwl;bsofrwl;c:\windows\system32\drivers\bsofrwl.sys [2/1/2009 11:42 AM 29024]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/20/2007 8:55 PM 24652]
--- Other Services/Drivers In Memory ---
*Deregistered* - BSafeFilter
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2009-11-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-03-24 17:32]
2009-12-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-03-24 17:32]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uInternet Settings,ProxyOverride = localhost
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Search
LSP: InetCntrl0012.dll
Trusted Zone: magicjack.com\my
Trusted Zone: talk4free.com\reg
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\z2zm9zfa.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=&query=
FF - component: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\z2zm9zfa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll
FF - component: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\z2zm9zfa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
HKCU-Run-Aim6 - (no file)
HKLM-Run-PCDrProfiler - (no file)
SafeBoot-svcWRSSSDK
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-29 00:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\QTFont.for
c:\windows\QTFont.qfn
scan completed successfully
hidden files: 2
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2849324024-808117622-1438292021-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(616)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\NavLogon.dll
- - - - - - - > 'lsass.exe'(672)
c:\windows\system32\InetCntrl0012.dll
- - - - - - - > 'explorer.exe'(2836)
c:\windows\system32\WININET.dll
c:\docume~1\HP_ADM~1\LOCALS~1\TempIadHide5.dll
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\Ink\SKCHUI.DLL
c:\program files\Microsoft Office\Office10\msohev.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\drivers\dcfssvc.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\MPF\MPFSrv.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\eHome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2010-01-29 00:31:54 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-29 05:31
Pre-Run: 93,339,271,168 bytes free
Post-Run: 93,324,926,976 bytes free
- - End Of File - - F53E6233662B1ACB75FE8388DD09469F
ComboFix 10-01-28.05 - HP_Administrator 01/29/2010 0:11.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.135 [GMT -5:00]
Running from: c:\documents and settings\HP_Administrator\My Documents\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\HP_Administrator\Local Settings\Temp\IadHide5.dll
.
---- Previous Run -------
.
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\HP_Administrator\Application Data\inst.exe
c:\documents and settings\HP_Administrator\Local Settings\Temp\IadHide5.dll
c:\program files\Internet Explorer\SET346.tmp
c:\program files\Internet Explorer\SET347.tmp
c:\program files\Internet Explorer\SET349.tmp
C:\Thumbs.db
c:\windows\system32\ps2.bat
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-29 )))))))))))))))))))))))))))))))
.
2010-01-29 04:07 . 2010-01-29 04:07 -------- d-----w- c:\program files\Trend Micro
2010-01-29 03:36 . 2010-01-29 03:36 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2010-01-29 03:36 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-29 03:36 . 2010-01-29 03:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-29 03:36 . 2010-01-29 03:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-29 03:36 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-28 00:05 . 2010-01-28 00:05 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-01-28 00:05 . 2010-01-28 00:05 -------- d-----w- c:\program files\NOS
2010-01-24 21:09 . 2010-01-24 21:20 69 ----a-w- c:\documents and settings\HP_Administrator\jagex_runescape_preferences2.dat
2010-01-24 21:07 . 2010-01-24 21:41 39 ----a-w- c:\documents and settings\HP_Administrator\jagex_runescape_preferences.dat
2010-01-19 21:12 . 2010-01-05 10:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-19 21:12 . 2010-01-05 10:00 78336 ----a-w- c:\windows\system32\dllcache\ieencode.dll
2010-01-19 06:17 . 2010-01-19 06:17 -------- d-----w- c:\windows\system32\XPSViewer
2010-01-19 06:17 . 2010-01-19 06:17 -------- d-----w- c:\program files\MSBuild
2010-01-19 06:17 . 2010-01-19 06:17 -------- d-----w- c:\program files\Reference Assemblies
2010-01-19 06:03 . 2010-01-19 06:03 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\PCHealth
2010-01-19 05:40 . 2010-01-19 05:40 -------- d-----w- c:\program files\Drug Lord 2
2010-01-19 05:25 . 2010-01-19 05:25 -------- d-sh--w- c:\documents and settings\HP_Administrator\IECompatCache
2010-01-19 05:01 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-01-19 05:01 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-01-19 05:01 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2010-01-19 05:01 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-01-19 05:01 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-01-19 05:00 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2010-01-19 05:00 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2010-01-19 05:00 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2010-01-19 05:00 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2010-01-19 05:00 . 2010-01-19 05:01 -------- d-----w- C:\7456fae64d2703008ce29891e4
2010-01-19 04:59 . 2010-01-19 04:59 -------- d-----w- C:\e223ee57ef465f2ed1aa7d
2010-01-19 04:59 . 2010-01-19 05:05 -------- d-----w- C:\ab395b3ade1fce835126333e
2010-01-18 23:34 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-01-18 23:33 . 2009-10-15 16:28 81920 ------w- c:\windows\system32\dllcache\fontsub.dll
2010-01-18 23:33 . 2009-10-15 16:28 119808 ------w- c:\windows\system32\dllcache\t2embed.dll
2010-01-18 23:32 . 2009-06-21 21:44 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2010-01-18 23:30 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2010-01-18 19:36 . 2010-01-18 19:36 -------- d-sh--w- c:\documents and settings\Tom.YOUR-B27FB1C401\IECompatCache
2010-01-05 10:00 . 2010-01-05 10:00 17408 ------w- c:\windows\system32\dllcache\corpol.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-25 04:13 . 2005-12-03 21:26 -------- d-----w- c:\program files\Yahoo!
2010-01-25 02:53 . 2009-02-17 04:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-01-25 02:44 . 2005-08-09 17:00 -------- d-----w- c:\program files\Google
2010-01-25 02:44 . 2007-04-22 21:57 -------- d-----w- c:\program files\FreeRIP2
2010-01-25 02:43 . 2005-08-09 16:57 -------- d-----w- c:\program files\Easy Internet signup
2010-01-25 02:42 . 2008-12-07 02:49 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Vso
2010-01-25 02:42 . 2008-12-07 02:49 47360 ----a-w- c:\documents and settings\HP_Administrator\Application Data\pcouffin.sys
2010-01-25 02:42 . 2008-12-07 02:49 47360 ----a-w- c:\documents and settings\HP_Administrator\Application Data\pcouffin.sys
2010-01-25 02:39 . 2009-04-06 03:13 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Any Video Converter Professional
2010-01-25 02:22 . 2005-11-14 03:34 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2010-01-25 02:20 . 2005-08-09 17:03 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-25 02:20 . 2005-08-09 17:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-25 02:13 . 2005-11-16 19:43 67360 ----a-w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-25 02:12 . 2006-10-12 22:07 -------- d-----w- c:\program files\LimeWire
2010-01-23 21:30 . 2007-05-05 01:12 -------- d-----w- c:\program files\World of Warcraft
2010-01-21 03:36 . 2010-01-25 03:01 209056 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
2010-01-19 21:05 . 2008-11-08 17:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-01-19 21:05 . 2006-01-13 16:01 -------- d-----w- c:\program files\Norton AntiVirus
2010-01-05 10:00 . 2004-08-10 19:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-10 19:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-11-21 15:51 . 2004-08-10 19:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-06-08 17:59 . 2009-06-08 17:59 5632 --sha-w- c:\program files\Thumbs.db
2006-10-09 17:53 . 2006-10-09 17:53 277504 ----a-w- c:\program files\EE_CE_Presentation.ppt
2005-12-04 00:20 . 2005-12-04 00:18 947510784 ----a-w- c:\program files\armyops250.exe
2005-12-04 00:14 . 2005-12-04 00:14 776783 ----a-w- c:\program files\texasdemo.exe
2005-11-17 19:49 . 2005-11-17 19:49 3055906 ----a-w- c:\program files\ptabe1_7.zip
2007-08-17 14:16 . 2007-06-10 00:56 66672 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2007-08-17 14:16 . 2007-06-10 00:56 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2007-08-17 14:16 . 2007-06-10 00:56 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2007-08-17 14:16 . 2007-06-10 00:56 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2007-08-17 14:16 . 2007-06-10 00:56 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"igndlm.exe"="c:\program files\IGN\Download Manager\DLM.exe" [2007-03-05 1103480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-14 68856]
"cdloader"="c:\documents and settings\HP_Administrator\Application Data\mjusbsp\cdloader2.exe" [2008-12-17 50520]
"rty"="c:\windows\tempie\rty.exe" [2009-05-02 65536]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-09 98304]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2005-05-11 253952]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-11 59392]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-19 185872]
"InetCntrl"="c:\windows\system32\InetCntrl\InetCntrl.exe" [2009-01-26 841048]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Kodak EasyShare software.lnk - c:\program files\KODAK\Kodak EasyShare software\bin\EasyShare.exe [2002-6-26 290816]
KODAK Software Updater.lnk - c:\program files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe [2002-3-13 16384]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-12 83360]
Updates from HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2005-8-9 36903]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\KODAK\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Documents and Settings\\Tom.YOUR-B27FB1C401\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Documents and Settings\\HP_Administrator\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\America's Army\\System\\ArmyOps.exe"=
"c:\\WINDOWS\\system32\\InetCntrl\\InetCntrl.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"43594:TCP"= 43594:TCP:rune
"43595:TCP"= 43595:TCP:rune
"5060:UDP"= 5060:UDP:MJ1
"5070:UDP"= 5070:UDP:MJ2
"3724:TCP"= 3724:TCP:WoW Servers
"1119:TCP"= 1119:TCP:Wow
"3724:UDP"= 3724:UDP:Wow2
R1 bsofrwl;bsofrwl;c:\windows\system32\drivers\bsofrwl.sys [2/1/2009 11:42 AM 29024]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/20/2007 8:55 PM 24652]
--- Other Services/Drivers In Memory ---
*Deregistered* - BSafeFilter
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2009-11-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-03-24 17:32]
2009-12-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-03-24 17:32]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=desktop&parm1=seconduser
uInternet Settings,ProxyOverride = localhost
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &Search
LSP: InetCntrl0012.dll
Trusted Zone: magicjack.com\my
Trusted Zone: talk4free.com\reg
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\z2zm9zfa.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=&query=
FF - component: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\z2zm9zfa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll
FF - component: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\z2zm9zfa.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metrics.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
HKCU-Run-Aim6 - (no file)
HKLM-Run-PCDrProfiler - (no file)
SafeBoot-svcWRSSSDK
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-29 00:22
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\QTFont.for
c:\windows\QTFont.qfn
scan completed successfully
hidden files: 2
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2849324024-808117622-1438292021-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(616)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\NavLogon.dll
- - - - - - - > 'lsass.exe'(672)
c:\windows\system32\InetCntrl0012.dll
- - - - - - - > 'explorer.exe'(2836)
c:\windows\system32\WININET.dll
c:\docume~1\HP_ADM~1\LOCALS~1\TempIadHide5.dll
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\Ink\SKCHUI.DLL
c:\program files\Microsoft Office\Office10\msohev.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\drivers\dcfssvc.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\MPF\MPFSrv.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\windows\eHome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2010-01-29 00:31:54 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-29 05:31
Pre-Run: 93,339,271,168 bytes free
Post-Run: 93,324,926,976 bytes free
- - End Of File - - F53E6233662B1ACB75FE8388DD09469F