ComboFix 10-12-22.04 - HP_Administrator 12/22/2010 22:29:38.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.673 [GMT -8:00]
Running from: c:\documents and settings\HP_Administrator\My Documents\Downloads\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HP_Administrator\Application Data\Local
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\10.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\11.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\12.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\13.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\14.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\15.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\16.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\17.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\18.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\19.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\20.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\21.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\22.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\23.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\24.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\25.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\26.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\27.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\28.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\29.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\30.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\31.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\32.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\33.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\34.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\35.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\36.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\acqhhqqpdjae.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\ctlrxfoukbdz.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\dquasgtrlbnl.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\fdxuutdxlacg.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\goumcxjtterh.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\gruqcqtfotix.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\hkfvmzijvszv.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\hruumdwjremy.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\hymtzzeriyoi.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\khcjwbsztwyb.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\kqrxrmaixhno.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\kvcarofpfebx.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\lrfjgykdbohn.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\lzxuizwmfmbh.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\mmrfjyjodaal.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\mtdbypnasqdx.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\rrogfjwindkf.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\settings.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\srxczceyewyq.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\acqhhqqpdjae.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\ctlrxfoukbdz.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\ddxjdiyytzku.avi(2).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\ddxjdiyytzku.avi(3).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\ddxjdiyytzku.avi(4).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\ddxjdiyytzku.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\dquasgtrlbnl.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\fdxuutdxlacg.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\goumcxjtterh.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\gruqcqtfotix.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\hkfvmzijvszv.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\hruumdwjremy.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\hymtzzeriyoi.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\khcjwbsztwyb.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\kqrxrmaixhno.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\kvcarofpfebx.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\lihqvpgugbsw.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\lititjetgokw.avi(2).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\lititjetgokw.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\lrfjgykdbohn.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\lzxuizwmfmbh.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\mmrfjyjodaal.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\mtdbypnasqdx.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\mtdbypnasqdx.avi(2).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\mtdbypnasqdx.avi(3).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\mtdbypnasqdx.avi(4).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\mtdbypnasqdx.avi(5).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\mtdbypnasqdx.avi(6).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\mtdbypnasqdx.avi(7).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\mtdbypnasqdx.avi(8).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\mtdbypnasqdx.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\pyxzrxzjxvxp.avi(2).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\pyxzrxzjxvxp.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\rrogfjwindkf.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\srxczceyewyq.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\t(2).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\t(3).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\t(4).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\t.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\tvbszyfvclpo(2).avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\tvbszyfvclpo(3).avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\tvbszyfvclpo.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\ujlbelzwsjtv.avi(2).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\ujlbelzwsjtv.avi(3).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\ujlbelzwsjtv.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\uyoqoqnyehld.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\vkohpvxirjae.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\vpfzwmowhejm.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\vqifydiffvee.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\wbrdamgheywo.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\xlgdpxtlzpgh.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\zrexnmsexdko.avi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\tvbszyfvclpo.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\ujlbelzwsjtv.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\uyoqoqnyehld.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\vkohpvxirjae.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\vpfzwmowhejm.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\vqifydiffvee.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\wbrdamgheywo.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\xlgdpxtlzpgh.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\zrexnmsexdko.avi.ddr
c:\windows\system32\Oeminfo.ini
c:\windows\system32\ps2.bat
.
((((((((((((((((((((((((( Files Created from 2010-11-23 to 2010-12-23 )))))))))))))))))))))))))))))))
.
2010-12-23 06:09 . 2010-07-12 18:36 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2010-12-23 06:09 . 2010-07-12 18:36 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2010-12-23 06:09 . 2010-07-12 18:36 133616 ------w- c:\windows\system32\pxafs.dll
2010-12-23 06:09 . 2010-12-23 06:09 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-12-23 06:07 . 2010-12-23 06:10 -------- d-----w- c:\program files\DivX
2010-12-23 06:03 . 2010-12-23 06:03 -------- d-----w- c:\windows\system32\wbem\Repository
2010-12-23 06:02 . 2010-12-23 06:10 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-12-22 11:44 . 2010-12-22 11:44 -------- d-----w- c:\windows\system32\LogFiles
2010-12-18 08:41 . 2010-12-18 08:41 -------- d-----w- C:\Riot Games
2010-12-18 07:25 . 2010-12-23 06:03 -------- d-----w- c:\documents and settings\HP_Administrator
2010-12-18 07:24 . 2005-11-11 00:44 -------- d-----w- c:\windows\system32\config\systemprofile\WINDOWS
2010-12-18 07:19 . 2001-08-17 21:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-12-18 07:18 . 2004-08-04 06:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2010-12-18 07:18 . 2001-08-17 22:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-12-18 05:55 . 2010-12-18 07:27 -------- d-sh--r- c:\windows\system32\dllcache
2010-12-17 22:13 . 2010-12-18 07:50 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-12-17 22:13 . 2010-12-17 22:13 -------- d-----w- c:\program files\Pando Networks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 00:44 . 2010-11-12 00:44 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-11-08 22:57 . 2010-11-08 22:57 353592 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl
2010-10-13 06:08 . 2010-01-22 12:23 249856 ------w- c:\windows\Setup1.exe
2010-10-13 06:08 . 2009-11-26 03:28 73216 ----a-w- c:\windows\ST6UNST.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-09-16 136176]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Updates from HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2005-11-10 36903]
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2005-11-10 27136]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"57938:TCP"= 57938:TCP:Pando Media Booster
"57938:UDP"= 57938:UDP:Pando Media Booster
S3 PCD5SRVC{085326CB-51A3560A-05010003};PCD5SRVC{085326CB-51A3560A-05010003} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\PC-DOC~1\PCD5SRVC.pkms [9/7/2005 11:23 PM 21120]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - NORMANDY
*Deregistered* - Normandy
.
Contents of the 'Scheduled Tasks' folder
2010-12-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-12-18 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-09 03:23]
2010-12-18 c:\windows\Tasks\HPCeeSchedule.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2005-09-09 03:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-12-22 22:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCD5SRVC{085326CB-51A3560A-05010003}]
"ImagePath"="\??\c:\progra~1\PC-DOC~1\PCD5SRVC.pkms"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(576)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-12-22 22:34:18
ComboFix-quarantined-files.txt 2010-12-23 06:34
Pre-Run: 154,701,312,000 bytes free
Post-Run: 154,692,497,408 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
- - End Of File - - 6DCDD9445B702396E5426B109EDBF7FA
ComboFix 10-12-30.01 - HP_Administrator 12/30/2010 16:21:43.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.614 [GMT -8:00]
Running from: c:\documents and settings\HP_Administrator\My Documents\Downloads\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\HP_Administrator\Application Data\Local
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\0.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\1.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\2.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\5.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\7.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\9.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\aqclajrlixoy.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\hymtzzeriyoi.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\lbvfpqxlzqrq.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\rahyubpkvrho.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\settings.ddi
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\aqclajrlixoy.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\hymtzzeriyoi.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\lbvfpqxlzqrq.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\rahyubpkvrho.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\thmpkcjxgtjd.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\vgegnxbfbgij.avi(2).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\vgegnxbfbgij.avi(3).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\vgegnxbfbgij.avi(4).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\vgegnxbfbgij.avi(5).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\vgegnxbfbgij.avi(6).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\vgegnxbfbgij.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\xebslpiwokev.avi(2).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\xebslpiwokev.avi(3).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\xebslpiwokev.avi(4).ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\xebslpiwokev.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\yhcaxggnfslv.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\zknqaygfdmhh.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\Temporary Downloaded Files\zlkdhbnlkynx.avi.ddp
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\thmpkcjxgtjd.avi.ddr
c:\documents and settings\HP_Administrator\Application Data\Local\Temp\DDM\Settings\zlkdhbnlkynx.avi.ddr
c:\documents and settings\HP_Administrator\Local Settings\Temp\IadHide5.dll
c:\windows\system32\Oeminfo.ini
c:\windows\system32\ps2.bat
.
((((((((((((((((((((((((( Files Created from 2010-11-28 to 2010-12-31 )))))))))))))))))))))))))))))))
.
2010-12-28 21:25 . 2010-12-28 21:25 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-12-23 09:34 . 2010-12-23 09:34 -------- d-----w- C:\Riot Games
2010-12-23 08:43 . 2010-12-23 08:43 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-12-23 08:42 . 2010-12-23 08:42 -------- d-----w- c:\program files\Pando Networks
2010-12-23 08:31 . 2008-07-31 18:41 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2010-12-23 08:31 . 2008-07-31 18:40 509448 ----a-w- c:\windows\system32\XAudio2_2.dll
2010-12-23 08:31 . 2008-07-12 16:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-12-23 08:31 . 2008-07-12 16:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-12-23 08:31 . 2008-07-12 16:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-12-23 08:22 . 2010-04-29 23:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-23 08:22 . 2010-04-29 23:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-23 07:19 . 2010-07-12 18:36 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2010-12-23 07:19 . 2010-07-12 18:36 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2010-12-23 07:19 . 2010-07-12 18:36 133616 ------w- c:\windows\system32\pxafs.dll
2010-12-23 07:06 . 2010-12-28 19:20 -------- d-----w- c:\documents and settings\HP_Administrator
2010-12-23 07:05 . 2005-11-11 00:44 -------- d-----w- c:\windows\system32\config\systemprofile\WINDOWS
2010-12-23 07:01 . 2001-08-17 21:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-12-23 07:01 . 2004-08-04 06:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2010-12-23 07:01 . 2001-08-17 22:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-12-23 05:38 . 2010-12-23 07:07 -------- d-sh--r- c:\windows\system32\dllcache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 00:44 . 2010-11-12 00:44 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-10-13 06:08 . 2010-01-22 12:23 249856 ------w- c:\windows\Setup1.exe
2010-10-13 06:08 . 2009-11-26 03:28 73216 ----a-w- c:\windows\ST6UNST.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-09-16 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 1605740]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-05-12 14:12 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Riot Games\\League of Legends\\air\\LolClient.exe"=
"c:\\Riot Games\\League of Legends\\game\\League of Legends.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"57066:TCP"= 57066:TCP:Pando Media Booster
"57066:UDP"= 57066:UDP:Pando Media Booster
"6951:TCP"= 6951:TCP:League of Legends Launcher
"6951:UDP"= 6951:UDP:League of Legends Launcher
"6980:TCP"= 6980:TCP:League of Legends Launcher
"6980:UDP"= 6980:UDP:League of Legends Launcher
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 10:41 AM 67656]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - SASDIFSV
.
Contents of the 'Scheduled Tasks' folder
2010-12-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-12-23 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-09 03:23]
2010-12-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008Core.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2010-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008UA.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2010-12-23 c:\windows\Tasks\HPCeeSchedule.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2005-09-09 03:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-PCDrProfiler - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-12-30 16:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(576)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\arservice.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\wscntfy.exe
c:\windows\ARPWRMSG.EXE
c:\windows\eHome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2010-12-30 16:31:20 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-31 00:31
ComboFix2.txt 2010-12-23 06:34
Pre-Run: 155,374,620,672 bytes free
Post-Run: 155,671,048,192 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
- - End Of File - - 3B64CE66CC125A657D5EEF6C9F53AAE5
ComboFix 10-12-31.01 - HP_Administrator 12/31/2010 11:59:03.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.568 [GMT -8:00]
Running from: c:\documents and settings\HP_Administrator\My Documents\Downloads\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2010-11-28 to 2010-12-31 )))))))))))))))))))))))))))))))
.
2010-12-23 09:34 . 2010-12-23 09:34 -------- d-----w- C:\Riot Games
2010-12-23 08:43 . 2010-12-23 08:43 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-12-23 08:42 . 2010-12-23 08:42 -------- d-----w- c:\program files\Pando Networks
2010-12-23 08:31 . 2008-07-31 18:41 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2010-12-23 08:31 . 2008-07-31 18:40 509448 ----a-w- c:\windows\system32\XAudio2_2.dll
2010-12-23 08:31 . 2008-07-12 16:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-12-23 08:31 . 2008-07-12 16:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-12-23 08:31 . 2008-07-12 16:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-12-23 08:22 . 2010-04-29 23:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-23 08:22 . 2010-04-29 23:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-23 07:19 . 2010-07-12 18:36 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2010-12-23 07:19 . 2010-07-12 18:36 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2010-12-23 07:19 . 2010-07-12 18:36 133616 ------w- c:\windows\system32\pxafs.dll
2010-12-23 07:06 . 2010-12-28 19:20 -------- d-----w- c:\documents and settings\HP_Administrator
2010-12-23 07:05 . 2005-11-11 00:44 -------- d-----w- c:\windows\system32\config\systemprofile\WINDOWS
2010-12-23 07:01 . 2001-08-17 21:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-12-23 07:01 . 2004-08-04 06:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2010-12-23 07:01 . 2001-08-17 22:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-12-23 05:38 . 2010-12-23 07:07 -------- d-sh--r- c:\windows\system32\dllcache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 00:44 . 2010-11-12 00:44 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-10-13 06:08 . 2010-01-22 12:23 249856 ------w- c:\windows\Setup1.exe
2010-10-13 06:08 . 2009-11-26 03:28 73216 ----a-w- c:\windows\ST6UNST.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-09-16 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 1605740]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-05-12 14:12 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Riot Games\\League of Legends\\air\\LolClient.exe"=
"c:\\Riot Games\\League of Legends\\game\\League of Legends.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"57066:TCP"= 57066:TCP:Pando Media Booster
"57066:UDP"= 57066:UDP:Pando Media Booster
"6951:TCP"= 6951:TCP:League of Legends Launcher
"6951:UDP"= 6951:UDP:League of Legends Launcher
"6980:TCP"= 6980:TCP:League of Legends Launcher
"6980:UDP"= 6980:UDP:League of Legends Launcher
"6937:TCP"= 6937:TCP:League of Legends Launcher
"6937:UDP"= 6937:UDP:League of Legends Launcher
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 10:41 AM 67656]
.
Contents of the 'Scheduled Tasks' folder
2010-12-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-12-23 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-09 03:23]
2010-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008Core.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2010-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008UA.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2010-12-23 c:\windows\Tasks\HPCeeSchedule.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2005-09-09 03:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-12-31 12:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(576)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-12-31 12:05:37
ComboFix-quarantined-files.txt 2010-12-31 20:05
ComboFix2.txt 2010-12-31 00:31
ComboFix3.txt 2010-12-23 06:34
Pre-Run: 155,671,080,960 bytes free
Post-Run: 155,663,814,656 bytes free
- - End Of File - - CFC6D43EECA8CA319116864A34982A67
ComboFix 11-01-02.03 - HP_Administrator 01/03/2011 1:49.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.586 [GMT -8:00]
Running from: c:\documents and settings\HP_Administrator\My Documents\Downloads\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2010-12-03 to 2011-01-03 )))))))))))))))))))))))))))))))
.
2011-01-03 06:01 . 2011-01-03 06:01 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-12-23 09:34 . 2010-12-23 09:34 -------- d-----w- C:\Riot Games
2010-12-23 08:43 . 2010-12-23 08:43 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-12-23 08:42 . 2010-12-23 08:42 -------- d-----w- c:\program files\Pando Networks
2010-12-23 08:31 . 2008-07-31 18:41 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2010-12-23 08:31 . 2008-07-31 18:40 509448 ----a-w- c:\windows\system32\XAudio2_2.dll
2010-12-23 08:31 . 2008-07-12 16:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-12-23 08:31 . 2008-07-12 16:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-12-23 08:31 . 2008-07-12 16:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-12-23 08:22 . 2010-04-29 23:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-23 08:22 . 2010-04-29 23:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-23 07:19 . 2010-07-12 18:36 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2010-12-23 07:19 . 2010-07-12 18:36 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2010-12-23 07:19 . 2010-07-12 18:36 133616 ------w- c:\windows\system32\pxafs.dll
2010-12-23 07:06 . 2010-12-31 22:33 -------- d-----w- c:\documents and settings\HP_Administrator
2010-12-23 07:05 . 2005-11-11 00:44 -------- d-----w- c:\windows\system32\config\systemprofile\WINDOWS
2010-12-23 07:01 . 2001-08-17 21:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-12-23 07:01 . 2004-08-04 06:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2010-12-23 07:01 . 2001-08-17 22:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-12-23 05:38 . 2010-12-23 07:07 -------- d-sh--r- c:\windows\system32\dllcache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 00:44 . 2010-11-12 00:44 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-10-13 06:08 . 2010-01-22 12:23 249856 ------w- c:\windows\Setup1.exe
2010-10-13 06:08 . 2009-11-26 03:28 73216 ----a-w- c:\windows\ST6UNST.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-09-16 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 1605740]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-05-12 14:12 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Riot Games\\League of Legends\\air\\LolClient.exe"=
"c:\\Riot Games\\League of Legends\\game\\League of Legends.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"57066:TCP"= 57066:TCP:Pando Media Booster
"57066:UDP"= 57066:UDP:Pando Media Booster
"6951:TCP"= 6951:TCP:League of Legends Launcher
"6951:UDP"= 6951:UDP:League of Legends Launcher
"6980:TCP"= 6980:TCP:League of Legends Launcher
"6980:UDP"= 6980:UDP:League of Legends Launcher
"6937:TCP"= 6937:TCP:League of Legends Launcher
"6937:UDP"= 6937:UDP:League of Legends Launcher
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 10:41 AM 67656]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - KLMD25
*Deregistered* - klmd25
.
Contents of the 'Scheduled Tasks' folder
2010-12-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-12-23 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-09 03:23]
2011-01-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008Core.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2011-01-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008UA.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2010-12-23 c:\windows\Tasks\HPCeeSchedule.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2005-09-09 03:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
.
- - - - ORPHANS REMOVED - - - -
AddRemove-ESET Online Scanner - c:\program files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-03 01:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(576)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2011-01-03 01:56:31
ComboFix-quarantined-files.txt 2011-01-03 09:56
ComboFix2.txt 2010-12-31 20:05
ComboFix3.txt 2010-12-31 00:31
ComboFix4.txt 2010-12-23 06:34
Pre-Run: 155,561,209,856 bytes free
Post-Run: 155,567,132,672 bytes free
- - End Of File - - 74C10B5D5ABA7221324D063C56C29DAF
ComboFix 11-01-11.01 - HP_Administrator 01/11/2011 21:29:18.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.573 [GMT -8:00]
Running from: c:\documents and settings\HP_Administrator\My Documents\Downloads\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2010-12-12 to 2011-01-12 )))))))))))))))))))))))))))))))
.
2011-01-10 08:14 . 2010-10-21 20:06 4208208 ----a-w- c:\windows\system32\GameMon.des
2011-01-10 08:14 . 2004-12-31 15:43 4682 ----a-w- c:\windows\system32\npptNT2.sys
2011-01-10 08:14 . 2003-07-17 00:17 5174 ----a-w- c:\windows\system32\nppt9x.vxd
2011-01-10 08:14 . 2011-01-10 08:14 -------- d-----w- c:\program files\Common Files\INCA Shared
2011-01-10 07:58 . 2011-01-10 09:01 -------- d-----w- c:\program files\REACTOR
2011-01-06 05:51 . 2011-01-06 05:51 -------- d-----w- c:\program files\Ventrilo
2011-01-06 05:51 . 2011-01-06 05:51 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2011-01-03 06:01 . 2011-01-03 06:01 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-12-23 09:34 . 2010-12-23 09:34 -------- d-----w- C:\Riot Games
2010-12-23 08:43 . 2010-12-23 08:43 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-12-23 08:42 . 2010-12-23 08:42 -------- d-----w- c:\program files\Pando Networks
2010-12-23 08:31 . 2008-07-31 18:41 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2010-12-23 08:31 . 2008-07-31 18:40 509448 ----a-w- c:\windows\system32\XAudio2_2.dll
2010-12-23 08:31 . 2008-07-12 16:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-12-23 08:31 . 2008-07-12 16:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-12-23 08:31 . 2008-07-12 16:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-12-23 08:22 . 2010-04-29 23:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-23 08:22 . 2010-04-29 23:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-23 07:19 . 2010-07-12 18:36 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2010-12-23 07:19 . 2010-07-12 18:36 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2010-12-23 07:19 . 2010-07-12 18:36 133616 ------w- c:\windows\system32\pxafs.dll
2010-12-23 07:06 . 2011-01-05 04:22 -------- d-----w- c:\documents and settings\HP_Administrator
2010-12-23 07:05 . 2005-11-11 00:44 -------- d-----w- c:\windows\system32\config\systemprofile\WINDOWS
2010-12-23 07:01 . 2001-08-17 21:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-12-23 07:01 . 2004-08-04 06:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2010-12-23 07:01 . 2001-08-17 22:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-12-23 05:38 . 2010-12-23 07:07 -------- d-sh--r- c:\windows\system32\dllcache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 00:44 . 2010-11-12 00:44 94208 ----a-w- c:\windows\system32\dpl100.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-12-31_00.27.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 10:19 . 2007-11-07 10:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 14:07 . 2008-07-29 14:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 14:07 . 2008-07-29 14:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 11:54 . 2008-07-29 11:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2011-01-10 07:59 . 2011-01-10 07:59 233936 c:\windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe
+ 2011-01-10 07:59 . 2011-01-10 07:59 311248 c:\windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.dll
+ 2011-01-06 05:51 . 2011-01-06 05:51 683520 c:\windows\Installer\38560c2.msi
+ 2011-01-11 07:03 . 2011-01-11 07:03 228352 c:\windows\Installer\1d88903b.msi
+ 2010-10-14 19:26 . 2010-05-12 01:28 173232 c:\windows\Downloaded Program Files\PubPlugin.dll
- 2010-10-14 19:26 . 2010-05-12 00:28 173232 c:\windows\Downloaded Program Files\PubPlugin.dll
- 2010-10-14 19:26 . 2010-03-24 23:56 143968 c:\windows\Downloaded Program Files\ijjiSetup1010.dll
+ 2010-10-14 19:26 . 2010-03-25 00:56 143968 c:\windows\Downloaded Program Files\ijjiSetup1010.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2010-10-22 04:04 . 2010-10-22 04:04 2827728 c:\windows\Downloaded Program Files\CONFLICT.82\FP_AX_CAB_INSTALLER.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-09-16 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 1605740]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-05-12 14:12 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Riot Games\\League of Legends\\air\\LolClient.exe"=
"c:\\Riot Games\\League of Legends\\game\\League of Legends.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\REACTOR\\REACTOR.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"57066:TCP"= 57066:TCP:Pando Media Booster
"57066:UDP"= 57066:UDP:Pando Media Booster
"6951:TCP"= 6951:TCP:League of Legends Launcher
"6951:UDP"= 6951:UDP:League of Legends Launcher
"6980:TCP"= 6980:TCP:League of Legends Launcher
"6980:UDP"= 6980:UDP:League of Legends Launcher
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 10:41 AM 67656]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - DUMP_WMIMMC
*Deregistered* - dump_wmimmc
.
Contents of the 'Scheduled Tasks' folder
2011-01-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-12-23 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-09 03:23]
2011-01-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008Core.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2011-01-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008UA.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2010-12-23 c:\windows\Tasks\HPCeeSchedule.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2005-09-09 03:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
.
- - - - ORPHANS REMOVED - - - -
AddRemove-Gunz - c:\ijji\ENGLISH\Gunz\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-11 21:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(580)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2011-01-11 21:35:37
ComboFix-quarantined-files.txt 2011-01-12 05:35
ComboFix2.txt 2011-01-03 09:56
ComboFix3.txt 2010-12-31 20:05
ComboFix4.txt 2010-12-31 00:31
ComboFix5.txt 2011-01-12 05:28
Pre-Run: 154,924,498,944 bytes free
Post-Run: 154,956,804,096 bytes free
- - End Of File - - 1A55D25CF01EE69E29F4216A1F8039B4
ComboFix 11-01-13.01 - HP_Administrator 01/14/2011 2:04.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.593 [GMT -8:00]
Running from: c:\documents and settings\HP_Administrator\My Documents\Downloads\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2010-12-14 to 2011-01-14 )))))))))))))))))))))))))))))))
.
2011-01-13 04:31 . 2011-01-13 04:31 -------- d-----w- c:\program files\TeamSpeak 3 Client
2011-01-10 08:14 . 2010-10-21 20:06 4208208 ----a-w- c:\windows\system32\GameMon.des
2011-01-10 08:14 . 2004-12-31 15:43 4682 ----a-w- c:\windows\system32\npptNT2.sys
2011-01-10 08:14 . 2003-07-17 00:17 5174 ----a-w- c:\windows\system32\nppt9x.vxd
2011-01-10 08:14 . 2011-01-10 08:14 -------- d-----w- c:\program files\Common Files\INCA Shared
2011-01-10 07:58 . 2011-01-10 09:01 -------- d-----w- c:\program files\REACTOR
2011-01-06 05:51 . 2011-01-06 05:51 -------- d-----w- c:\program files\Ventrilo
2011-01-06 05:51 . 2011-01-06 05:51 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-12-23 09:34 . 2010-12-23 09:34 -------- d-----w- C:\Riot Games
2010-12-23 08:43 . 2010-12-23 08:43 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-12-23 08:42 . 2010-12-23 08:42 -------- d-----w- c:\program files\Pando Networks
2010-12-23 08:31 . 2008-07-31 18:41 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2010-12-23 08:31 . 2008-07-31 18:40 509448 ----a-w- c:\windows\system32\XAudio2_2.dll
2010-12-23 08:31 . 2008-07-12 16:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-12-23 08:31 . 2008-07-12 16:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-12-23 08:31 . 2008-07-12 16:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-12-23 08:22 . 2010-04-29 23:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-23 08:22 . 2010-04-29 23:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-23 07:19 . 2010-07-12 18:36 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2010-12-23 07:19 . 2010-07-12 18:36 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2010-12-23 07:19 . 2010-07-12 18:36 133616 ------w- c:\windows\system32\pxafs.dll
2010-12-23 07:06 . 2011-01-12 05:37 -------- d-----w- c:\documents and settings\HP_Administrator
2010-12-23 07:05 . 2005-11-11 00:44 -------- d-----w- c:\windows\system32\config\systemprofile\WINDOWS
2010-12-23 07:01 . 2001-08-17 21:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-12-23 07:01 . 2004-08-04 06:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2010-12-23 07:01 . 2001-08-17 22:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-12-23 05:38 . 2010-12-23 07:07 -------- d-sh--r- c:\windows\system32\dllcache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 00:44 . 2010-11-12 00:44 94208 ----a-w- c:\windows\system32\dpl100.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-12-31_00.27.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 10:19 . 2007-11-07 10:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 14:07 . 2008-07-29 14:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 14:07 . 2008-07-29 14:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 11:54 . 2008-07-29 11:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2011-01-10 07:59 . 2011-01-10 07:59 233936 c:\windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe
+ 2011-01-10 07:59 . 2011-01-10 07:59 311248 c:\windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.dll
+ 2011-01-06 05:51 . 2011-01-06 05:51 683520 c:\windows\Installer\38560c2.msi
+ 2011-01-11 07:03 . 2011-01-11 07:03 228352 c:\windows\Installer\1d88903b.msi
+ 2010-10-14 19:26 . 2010-05-12 01:28 173232 c:\windows\Downloaded Program Files\PubPlugin.dll
- 2010-10-14 19:26 . 2010-05-12 00:28 173232 c:\windows\Downloaded Program Files\PubPlugin.dll
- 2010-10-14 19:26 . 2010-03-24 23:56 143968 c:\windows\Downloaded Program Files\ijjiSetup1010.dll
+ 2010-10-14 19:26 . 2010-03-25 00:56 143968 c:\windows\Downloaded Program Files\ijjiSetup1010.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2010-10-22 04:04 . 2010-10-22 04:04 2827728 c:\windows\Downloaded Program Files\CONFLICT.82\FP_AX_CAB_INSTALLER.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-09-16 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 1605740]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-05-12 14:12 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Riot Games\\League of Legends\\air\\LolClient.exe"=
"c:\\Riot Games\\League of Legends\\game\\League of Legends.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\REACTOR\\REACTOR.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"57066:TCP"= 57066:TCP:Pando Media Booster
"57066:UDP"= 57066:UDP:Pando Media Booster
"6951:TCP"= 6951:TCP:League of Legends Launcher
"6951:UDP"= 6951:UDP:League of Legends Launcher
"6980:TCP"= 6980:TCP:League of Legends Launcher
"6980:UDP"= 6980:UDP:League of Legends Launcher
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 10:41 AM 67656]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - DUMP_WMIMMC
*Deregistered* - dump_wmimmc
.
Contents of the 'Scheduled Tasks' folder
2011-01-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-12-23 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-09 03:23]
2011-01-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008Core.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2011-01-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008UA.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2010-12-23 c:\windows\Tasks\HPCeeSchedule.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2005-09-09 03:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-14 02:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(580)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2011-01-14 02:10:37
ComboFix-quarantined-files.txt 2011-01-14 10:10
ComboFix2.txt 2011-01-12 05:35
ComboFix3.txt 2011-01-03 09:56
ComboFix4.txt 2010-12-31 20:05
ComboFix5.txt 2011-01-14 10:02
Pre-Run: 154,799,906,816 bytes free
Post-Run: 154,794,221,568 bytes free
- - End Of File - - 70094958FE0070B2234F8295744E9F32
ComboFix 11-01-16.02 - HP_Administrator 01/16/2011 20:50:20.6.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.572 [GMT -8:00]
Running from: c:\documents and settings\HP_Administrator\My Documents\Downloads\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2010-12-17 to 2011-01-17 )))))))))))))))))))))))))))))))
.
2011-01-14 18:15 . 2011-01-14 18:15 -------- d-----w- c:\windows\system32\LogFiles
2011-01-10 08:14 . 2010-10-21 20:06 4208208 ----a-w- c:\windows\system32\GameMon.des
2011-01-10 08:14 . 2004-12-31 15:43 4682 ----a-w- c:\windows\system32\npptNT2.sys
2011-01-10 08:14 . 2003-07-17 00:17 5174 ----a-w- c:\windows\system32\nppt9x.vxd
2011-01-10 08:14 . 2011-01-10 08:14 -------- d-----w- c:\program files\Common Files\INCA Shared
2011-01-10 07:58 . 2011-01-10 09:01 -------- d-----w- c:\program files\REACTOR
2011-01-06 05:51 . 2011-01-06 05:51 -------- d-----w- c:\program files\Ventrilo
2011-01-06 05:51 . 2011-01-06 05:51 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-12-23 09:34 . 2010-12-23 09:34 -------- d-----w- C:\Riot Games
2010-12-23 08:43 . 2010-12-23 08:43 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2010-12-23 08:42 . 2010-12-23 08:42 -------- d-----w- c:\program files\Pando Networks
2010-12-23 08:31 . 2008-07-31 18:41 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll
2010-12-23 08:31 . 2008-07-31 18:40 509448 ----a-w- c:\windows\system32\XAudio2_2.dll
2010-12-23 08:31 . 2008-07-12 16:18 467984 ----a-w- c:\windows\system32\d3dx10_39.dll
2010-12-23 08:31 . 2008-07-12 16:18 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll
2010-12-23 08:31 . 2008-07-12 16:18 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll
2010-12-23 08:22 . 2010-04-29 23:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-23 08:22 . 2010-04-29 23:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-12-23 07:19 . 2010-07-12 18:36 9200 ------w- c:\windows\system32\drivers\cdralw2k.sys
2010-12-23 07:19 . 2010-07-12 18:36 9072 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2010-12-23 07:19 . 2010-07-12 18:36 133616 ------w- c:\windows\system32\pxafs.dll
2010-12-23 07:06 . 2011-01-12 05:37 -------- d-----w- c:\documents and settings\HP_Administrator
2010-12-23 07:05 . 2005-11-11 00:44 -------- d-----w- c:\windows\system32\config\systemprofile\WINDOWS
2010-12-23 07:01 . 2001-08-17 21:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2010-12-23 07:01 . 2004-08-04 06:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2010-12-23 07:01 . 2001-08-17 22:02 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2010-12-23 05:38 . 2010-12-23 07:07 -------- d-sh--r- c:\windows\system32\dllcache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 00:44 . 2010-11-12 00:44 94208 ----a-w- c:\windows\system32\dpl100.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-12-31_00.27.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 10:19 . 2007-11-07 10:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 14:07 . 2008-07-29 14:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 14:07 . 2008-07-29 14:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 11:54 . 2008-07-29 11:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2011-01-10 07:59 . 2011-01-10 07:59 233936 c:\windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe
+ 2011-01-10 07:59 . 2011-01-10 07:59 311248 c:\windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.dll
+ 2011-01-06 05:51 . 2011-01-06 05:51 683520 c:\windows\Installer\38560c2.msi
+ 2011-01-11 07:03 . 2011-01-11 07:03 228352 c:\windows\Installer\1d88903b.msi
+ 2010-10-14 19:26 . 2010-05-12 01:28 173232 c:\windows\Downloaded Program Files\PubPlugin.dll
- 2010-10-14 19:26 . 2010-05-12 00:28 173232 c:\windows\Downloaded Program Files\PubPlugin.dll
- 2010-10-14 19:26 . 2010-03-24 23:56 143968 c:\windows\Downloaded Program Files\ijjiSetup1010.dll
+ 2010-10-14 19:26 . 2010-03-25 00:56 143968 c:\windows\Downloaded Program Files\ijjiSetup1010.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2010-10-22 04:04 . 2010-10-22 04:04 2827728 c:\windows\Downloaded Program Files\CONFLICT.82\FP_AX_CAB_INSTALLER.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-09-16 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 1605740]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-05-12 14:12 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Riot Games\\League of Legends\\air\\LolClient.exe"=
"c:\\Riot Games\\League of Legends\\game\\League of Legends.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\REACTOR\\REACTOR.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"57066:TCP"= 57066:TCP:Pando Media Booster
"57066:UDP"= 57066:UDP:Pando Media Booster
"6951:TCP"= 6951:TCP:League of Legends Launcher
"6951:UDP"= 6951:UDP:League of Legends Launcher
"6980:TCP"= 6980:TCP:League of Legends Launcher
"6980:UDP"= 6980:UDP:League of Legends Launcher
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 10:41 AM 67656]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - DUMP_WMIMMC
*Deregistered* - dump_wmimmc
.
Contents of the 'Scheduled Tasks' folder
2011-01-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-12-23 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Hewlett-Packard\SDP\HPSdpApp.exe [2005-09-09 03:23]
2011-01-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008Core.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2011-01-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008UA.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2010-12-23 c:\windows\Tasks\HPCeeSchedule.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2005-09-09 03:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
.
- - - - ORPHANS REMOVED - - - -
AddRemove-TeamSpeak 3 Client - c:\program files\TeamSpeak 3 Client\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-16 20:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(580)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2011-01-16 20:57:04
ComboFix-quarantined-files.txt 2011-01-17 04:56
ComboFix2.txt 2011-01-14 10:10
ComboFix3.txt 2011-01-12 05:35
ComboFix4.txt 2011-01-03 09:56
ComboFix5.txt 2011-01-17 04:49
Pre-Run: 154,740,961,280 bytes free
Post-Run: 154,735,587,328 bytes free
- - End Of File - - 1F4D2CC13071E25DD7C5F32197B3E788
ComboFix 11-01-22.02 - HP_Administrator 01/22/2011 23:53:40.7.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.597 [GMT -8:00]
Running from: c:\documents and settings\HP_Administrator\My Documents\Downloads\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2010-12-23 to 2011-01-23 )))))))))))))))))))))))))))))))
.
2011-01-17 04:59 . 2011-01-17 04:59 -------- d-----w- c:\program files\ESET
2011-01-14 18:15 . 2011-01-14 18:15 -------- d-----w- c:\windows\system32\LogFiles
2011-01-12 23:50 . 2011-01-12 23:50 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Identities
2011-01-10 08:14 . 2010-10-21 20:06 4208208 ----a-w- c:\windows\system32\GameMon.des
2011-01-10 08:14 . 2004-12-31 15:43 4682 ----a-w- c:\windows\system32\npptNT2.sys
2011-01-10 08:14 . 2003-07-17 00:17 5174 ----a-w- c:\windows\system32\nppt9x.vxd
2011-01-10 08:14 . 2011-01-10 08:14 -------- d-----w- c:\program files\Common Files\INCA Shared
2011-01-10 07:58 . 2011-01-10 09:01 -------- d-----w- c:\program files\REACTOR
2011-01-06 05:52 . 2011-01-13 00:40 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Ventrilo
2011-01-06 05:51 . 2011-01-06 05:51 -------- d-----w- c:\program files\Ventrilo
2011-01-06 05:51 . 2011-01-06 05:51 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 00:44 . 2010-11-12 00:44 94208 ----a-w- c:\windows\system32\dpl100.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-12-31_00.27.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 10:19 . 2007-11-07 10:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 14:07 . 2008-07-29 14:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 14:07 . 2008-07-29 14:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 11:54 . 2008-07-29 11:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2011-01-10 07:59 . 2011-01-10 07:59 233936 c:\windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe
+ 2011-01-10 07:59 . 2011-01-10 07:59 311248 c:\windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.dll
+ 2011-01-06 05:51 . 2011-01-06 05:51 683520 c:\windows\Installer\38560c2.msi
+ 2011-01-11 07:03 . 2011-01-11 07:03 228352 c:\windows\Installer\1d88903b.msi
+ 2010-10-14 19:26 . 2010-05-12 01:28 173232 c:\windows\Downloaded Program Files\PubPlugin.dll
- 2010-10-14 19:26 . 2010-05-12 00:28 173232 c:\windows\Downloaded Program Files\PubPlugin.dll
- 2010-10-14 19:26 . 2010-03-24 23:56 143968 c:\windows\Downloaded Program Files\ijjiSetup1010.dll
+ 2010-10-14 19:26 . 2010-03-25 00:56 143968 c:\windows\Downloaded Program Files\ijjiSetup1010.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 16:05 . 2008-07-29 16:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2010-10-22 04:04 . 2010-10-22 04:04 2827728 c:\windows\Downloaded Program Files\CONFLICT.82\FP_AX_CAB_INSTALLER.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-09-16 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 1605740]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-05-12 14:12 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Riot Games\\League of Legends\\air\\LolClient.exe"=
"c:\\Riot Games\\League of Legends\\game\\League of Legends.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\REACTOR\\REACTOR.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"57066:TCP"= 57066:TCP:Pando Media Booster
"57066:UDP"= 57066:UDP:Pando Media Booster
"6980:TCP"= 6980:TCP:League of Legends Launcher
"6980:UDP"= 6980:UDP:League of Legends Launcher
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 10:41 AM 67656]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - SASDIFSV
.
Contents of the 'Scheduled Tasks' folder
2011-01-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2011-01-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008Core.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2011-01-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008UA.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2011-01-22 c:\windows\Tasks\HPCeeSchedule.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2005-09-09 03:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-22 23:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(576)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2011-01-23 00:00:11
ComboFix-quarantined-files.txt 2011-01-23 08:00
ComboFix2.txt 2011-01-17 04:57
ComboFix3.txt 2011-01-14 10:10
ComboFix4.txt 2011-01-12 05:35
ComboFix5.txt 2011-01-23 07:52
Pre-Run: 154,457,890,816 bytes free
Post-Run: 154,453,499,904 bytes free
- - End Of File - - BFD879D0D9D498060F193507613C8622
ComboFix 11-01-22.02 - HP_Administrator 01/24/2011 11:20:48.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.651 [GMT -8:00]
Running from: c:\documents and settings\HP_Administrator\My Documents\Downloads\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\HP_Administrator\Application Data\Local
c:\documents and settings\HP_Administrator\Local Settings\Temp\IadHide5.dll
c:\windows\system32\ps2.bat
.
((((((((((((((((((((((((( Files Created from 2010-12-24 to 2011-01-24 )))))))))))))))))))))))))))))))
.
2011-01-24 19:11 . 2011-01-24 19:11 -------- d-----w- c:\windows\system32\wbem\Repository
2011-01-23 10:00 . 2011-01-24 19:07 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Local(2)
2011-01-23 08:01 . 2011-01-24 19:07 -------- d-----w- C:\RECYCLER(2)
2011-01-17 04:59 . 2011-01-17 04:59 -------- d-----w- c:\program files\ESET(2)
2011-01-14 18:15 . 2011-01-14 18:15 -------- d-----w- c:\windows\system32\LogFiles
2011-01-12 23:50 . 2011-01-12 23:50 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Identities
2011-01-10 08:14 . 2011-01-10 08:14 -------- d-----w- c:\program files\Common Files\INCA Shared
2011-01-10 07:58 . 2011-01-24 19:09 -------- d-----w- c:\program files\REACTOR
2011-01-06 05:52 . 2011-01-24 19:09 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Ventrilo
2011-01-06 05:51 . 2011-01-24 19:09 -------- d-----w- c:\program files\Ventrilo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-12 00:44 . 2010-11-12 00:44 94208 ----a-w- c:\windows\system32\dpl100.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-09-16 136176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"PCDrProfiler"="c:\program files\PC-Doctor 5 for Windows\RunProfiler.exe" [2005-08-10 53248]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-09-21 1605740]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Updates from HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2005-11-10 36903]
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2005-11-10 27136]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"57066:TCP"= 57066:TCP:Pando Media Booster
"57066:UDP"= 57066:UDP:Pando Media Booster
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 10:41 AM 67656]
--- Other Services/Drivers In Memory ---
*Deregistered* - PCD5SRVC{085326CB-51A3560A-05010003}
.
Contents of the 'Scheduled Tasks' folder
2011-01-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2011-01-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008Core.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2011-01-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-469911042-1935599223-620547350-1008UA.job
- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-09-16 11:41]
2011-01-22 c:\windows\Tasks\HPCeeSchedule.job
- c:\program files\Hewlett-Packard\SDP\Ceement\HPCEE.exe [2005-09-09 03:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-DivXUpdate - c:\program files\DivX\DivX Update\DivXUpdate.exe
HKLM-Run-DivX Download Manager - c:\program files\DivX\DivX Plus Web Player\DDmService.exe
AddRemove-DivX Setup.divx.com - c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
AddRemove-{B7050CBDB2504B34BC2A9CA0A692CC29} - c:\program files\DivX\DivXWebPlayerUninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-24 11:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(580)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\arservice.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\Ati2evxx.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\ARPWRMSG.EXE
c:\windows\eHome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2011-01-24 11:29:56 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-24 19:29
ComboFix2.txt 2011-01-23 08:00
ComboFix3.txt 2011-01-17 04:57
ComboFix4.txt 2011-01-14 10:10
ComboFix5.txt 2011-01-24 19:16
Pre-Run: 152,810,532,864 bytes free
Post-Run: 152,809,664,512 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
- - End Of File - - 607880C4BD58A88BC80DA0E57A60953C