ComboFix 08-03-01.3 - HP_Administrator 2008-03-01 7:16:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.973 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\HP_Administrator\Application Data\inst.exe
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\WINDOWS\system32\awtqrol.dll
C:\WINDOWS\system32\drpogahp.dll
C:\WINDOWS\system32\ghkmp.ini
C:\WINDOWS\system32\ghkmp.ini2
C:\WINDOWS\system32\hwvwnyam.ini
C:\WINDOWS\system32\maynwvwh.dll
C:\WINDOWS\system32\ndwqrmxw.dll
C:\WINDOWS\system32\pmkhg.dll
C:\WINDOWS\system32\vpjcdfkb.ini
C:\WINDOWS\system32\vtutsrs.dll
C:\WINDOWS\system32\xqrghckt.dll
C:\WINDOWS\system32\xshxjqwd.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-02-01 to 2008-03-01 )))))))))))))))))))))))))))))))
.
2008-03-01 07:21 . 2008-03-01 07:21 1,282,048 --a------ C:\WINDOWS\system32\hwvwnyam.tmp
2008-03-01 06:30 . 2008-03-01 06:40
d-------- C:\xpsp2
2008-03-01 06:30 . 2008-03-01 06:30 d-------- C:\xpcd
2008-02-29 04:55 . 2004-08-04 05:00 388,608 --a------ C:\kmd.exe
2008-02-28 17:46 . 2008-03-01 07:21 21 --a------ C:\WINDOWS\pskt.ini
2008-02-28 05:11 . 2008-02-28 05:11 d-------- C:\Documents and Settings\HP_Administrator\Application Data\skypePM
2008-02-28 05:11 . 2008-02-28 05:11 32 --a------ C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-02-28 05:10 . 2008-02-28 07:05 d-------- C:\Documents and Settings\HP_Administrator\Application Data\Skype
2008-02-28 05:09 . 2008-02-28 05:09 d-------- C:\Program Files\Skype
2008-02-28 05:09 . 2008-02-28 05:09 d-------- C:\Program Files\Common Files\Skype
2008-02-28 05:08 . 2008-02-28 05:09 d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-02-25 02:12 . 2008-02-25 02:12 d-------- C:\Program Files\iTunes
2008-02-25 02:12 . 2008-02-25 02:12 d-------- C:\Program Files\iPod
2008-02-08 06:15 . 2008-02-08 06:15 d-------- C:\Documents and Settings\HP_Administrator\Application Data\eFax for U3
2008-02-02 20:38 . 2008-02-14 21:09 d-------- C:\Program Files\Quicken WillMaker Plus 2008
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-29 13:06 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\U3
2008-02-27 13:21 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Intuit
2008-02-27 13:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-27 13:14 --------- d-----w C:\Program Files\Quicken
2008-02-27 13:14 --------- d-----w C:\Program Files\Common Files\AnswerWorks 4.0
2008-02-27 13:11 --------- d-----w C:\Program Files\TurboTax
2008-02-25 10:10 --------- d-----w C:\Program Files\QuickTime
2008-02-05 15:17 --------- d-----w C:\Program Files\MSECache
2008-02-01 07:52 --------- d-----w C:\Program Files\Notepad++
2008-02-01 07:52 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Notepad++
2008-01-24 05:28 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Motive
2008-01-20 02:27 --------- d-----w C:\Documents and Settings\Guest\Application Data\Talkback
2008-01-20 02:26 --------- d-----w C:\Documents and Settings\Guest\Application Data\Teleca
2008-01-20 02:26 --------- d-----w C:\Documents and Settings\Guest\Application Data\Logitech
2008-01-20 02:26 --------- d-----w C:\Documents and Settings\Guest\Application Data\HP
2008-01-20 02:25 --------- d-----w C:\Documents and Settings\Guest\Application Data\Sony Ericsson
2008-01-16 02:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-03 05:17 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\vlc
2008-01-03 05:16 --------- d-----w C:\Program Files\vlc
2007-12-04 17:46 2,194 ----a-w C:\r2007b_license.dat
2007-10-28 02:46 47,360 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"Sonic RecordNow!"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 15:04 52736]
"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 17:53 49152]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 17:42 659456]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 19:43 233472]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-07-01 22:12 4112384]
"nwiz"="nwiz.exe" [2004-07-01 22:12 843776 C:\WINDOWS\system32\nwiz.exe]
"VTTimer"="VTTimer.exe" []
"AlcWzrd"="ALCWZRD.EXE" [2004-07-06 00:05 2550272 C:\WINDOWS\ALCWZRD.EXE]
"D-Link AirPlus XtremeG"="C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [2005-03-28 14:25 1011712]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 17:49 49152]
"AutoTBar"="c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE" [ ]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2006-01-12 22:46 196608]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44 61440]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 13:48 479232]
"eFax 4.2"="C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe" [2006-07-14 12:36 107008]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 12:03 94208 C:\WINDOWS\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 12:03 94208 C:\WINDOWS\KHALMNPR.Exe]
"Poopli Updater"="C:\Program Files\Poopli Updater\Poopli GUI.exe" [2006-05-31 11:24 188416]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 05:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-05-28 09:14 528384]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 15:24 54840]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 17:17 443968]
C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\
No-IP DUC.lnk - C:\Program Files\No-IP\DUC20.exe [2006-12-17 10:35:23 1172992]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2003-09-19 14:46:14 503869]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 20:40:10 210520]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-12-21 19:16:21 671744]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 12:05:56 65588]
VPN Client.lnk - C:\WINDOWS\Installer\{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}\Icon3E5562ED7.ico [2006-12-16 23:45:32 6144]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-12-16 11:45:28 118784]
ZDWLan Utility.lnk - C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2007-09-30 15:37:07 483328]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys [2006-09-01 12:32]
R2 PoopliService;Poopli Updater Service;C:\Program Files\Poopli Updater\Poopli Service.exe [2006-05-31 11:24]
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2005-03-22 19:17]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2006-02-10 17:34]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\M]
\Shell\AutoRun\command - M:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2485742e-8d50-11db-a230-0011d80057fd}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{694591fa-8de9-11db-a236-0011d80057fd}]
\Shell\AutoRun\command - M:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-02-23 22:53:58 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-01 07:28:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
.
**************************************************************************
.
Completion time: 2008-03-01 7:33:37 - machine was rebooted [HP_Administrator]
ComboFix-quarantined-files.txt 2008-03-01 15:33:33
.
2008-02-13 11:02:17 --- E O F ---