ComboFix 08-03-01.3 - HP_Administrator 2008-03-01 7:16:51.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.973 [GMT -8:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\HP_Administrator\Application Data\inst.exe C:\Program Files\Common Files\Yazzle1281OinAdmin.exe C:\WINDOWS\system32\awtqrol.dll C:\WINDOWS\system32\drpogahp.dll C:\WINDOWS\system32\ghkmp.ini C:\WINDOWS\system32\ghkmp.ini2 C:\WINDOWS\system32\hwvwnyam.ini C:\WINDOWS\system32\maynwvwh.dll C:\WINDOWS\system32\ndwqrmxw.dll C:\WINDOWS\system32\pmkhg.dll C:\WINDOWS\system32\vpjcdfkb.ini C:\WINDOWS\system32\vtutsrs.dll C:\WINDOWS\system32\xqrghckt.dll C:\WINDOWS\system32\xshxjqwd.dll D:\Autorun.inf . ((((((((((((((((((((((((( Files Created from 2008-02-01 to 2008-03-01 ))))))))))))))))))))))))))))))) . 2008-03-01 07:21 . 2008-03-01 07:21 1,282,048 --a------ C:\WINDOWS\system32\hwvwnyam.tmp 2008-03-01 06:30 . 2008-03-01 06:40 d-------- C:\xpsp2 2008-03-01 06:30 . 2008-03-01 06:30 d-------- C:\xpcd 2008-02-29 04:55 . 2004-08-04 05:00 388,608 --a------ C:\kmd.exe 2008-02-28 17:46 . 2008-03-01 07:21 21 --a------ C:\WINDOWS\pskt.ini 2008-02-28 05:11 . 2008-02-28 05:11 d-------- C:\Documents and Settings\HP_Administrator\Application Data\skypePM 2008-02-28 05:11 . 2008-02-28 05:11 32 --a------ C:\Documents and Settings\All Users\Application Data\ezsid.dat 2008-02-28 05:10 . 2008-02-28 07:05 d-------- C:\Documents and Settings\HP_Administrator\Application Data\Skype 2008-02-28 05:09 . 2008-02-28 05:09 d-------- C:\Program Files\Skype 2008-02-28 05:09 . 2008-02-28 05:09 d-------- C:\Program Files\Common Files\Skype 2008-02-28 05:08 . 2008-02-28 05:09 d-------- C:\Documents and Settings\All Users\Application Data\Skype 2008-02-25 02:12 . 2008-02-25 02:12 d-------- C:\Program Files\iTunes 2008-02-25 02:12 . 2008-02-25 02:12 d-------- C:\Program Files\iPod 2008-02-08 06:15 . 2008-02-08 06:15 d-------- C:\Documents and Settings\HP_Administrator\Application Data\eFax for U3 2008-02-02 20:38 . 2008-02-14 21:09 d-------- C:\Program Files\Quicken WillMaker Plus 2008 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-02-29 13:06 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\U3 2008-02-27 13:21 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Intuit 2008-02-27 13:14 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-02-27 13:14 --------- d-----w C:\Program Files\Quicken 2008-02-27 13:14 --------- d-----w C:\Program Files\Common Files\AnswerWorks 4.0 2008-02-27 13:11 --------- d-----w C:\Program Files\TurboTax 2008-02-25 10:10 --------- d-----w C:\Program Files\QuickTime 2008-02-05 15:17 --------- d-----w C:\Program Files\MSECache 2008-02-01 07:52 --------- d-----w C:\Program Files\Notepad++ 2008-02-01 07:52 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Notepad++ 2008-01-24 05:28 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\Motive 2008-01-20 02:27 --------- d-----w C:\Documents and Settings\Guest\Application Data\Talkback 2008-01-20 02:26 --------- d-----w C:\Documents and Settings\Guest\Application Data\Teleca 2008-01-20 02:26 --------- d-----w C:\Documents and Settings\Guest\Application Data\Logitech 2008-01-20 02:26 --------- d-----w C:\Documents and Settings\Guest\Application Data\HP 2008-01-20 02:25 --------- d-----w C:\Documents and Settings\Guest\Application Data\Sony Ericsson 2008-01-16 02:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer 2008-01-03 05:17 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\vlc 2008-01-03 05:16 --------- d-----w C:\Program Files\vlc 2007-12-04 17:46 2,194 ----a-w C:\r2007b_license.dat 2007-10-28 02:46 47,360 ----a-w C:\Documents and Settings\HP_Administrator\Application Data\pcouffin.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360] "Sonic RecordNow!"="" [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 15:04 52736] "HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 17:53 49152] "HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 17:42 659456] "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 19:43 233472] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-07-01 22:12 4112384] "nwiz"="nwiz.exe" [2004-07-01 22:12 843776 C:\WINDOWS\system32\nwiz.exe] "VTTimer"="VTTimer.exe" [] "AlcWzrd"="ALCWZRD.EXE" [2004-07-06 00:05 2550272 C:\WINDOWS\ALCWZRD.EXE] "D-Link AirPlus XtremeG"="C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [2005-03-28 14:25 1011712] "ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 17:49 49152] "AutoTBar"="c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE" [ ] "AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE] "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2006-01-12 22:46 196608] "KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44 61440] "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 13:48 479232] "eFax 4.2"="C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe" [2006-07-14 12:36 107008] "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 12:03 94208 C:\WINDOWS\KHALMNPR.Exe] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 12:03 94208 C:\WINDOWS\KHALMNPR.Exe] "Poopli Updater"="C:\Program Files\Poopli Updater\Poopli GUI.exe" [2006-05-31 11:24 188416] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 05:00 79224] "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 05:00 110592 C:\WINDOWS\system32\bthprops.cpl] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496] "Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-05-28 09:14 528384] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 15:24 54840] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 17:17 443968] C:\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\ No-IP DUC.lnk - C:\Program Files\No-IP\DUC20.exe [2006-12-17 10:35:23 1172992] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2003-09-19 14:46:14 503869] HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 20:40:10 210520] Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-12-21 19:16:21 671744] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 12:05:56 65588] VPN Client.lnk - C:\WINDOWS\Installer\{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}\Icon3E5562ED7.ico [2006-12-16 23:45:32 6144] WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-12-16 11:45:28 118784] ZDWLan Utility.lnk - C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2007-09-30 15:37:07 483328] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\Skype\\Phone\\Skype.exe"= R2 LBeepKE;LBeepKE;C:\WINDOWS\system32\Drivers\LBeepKE.sys [2006-09-01 12:32] R2 PoopliService;Poopli Updater Service;C:\Program Files\Poopli Updater\Poopli Service.exe [2006-05-31 11:24] S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2005-03-22 19:17] S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2006-02-10 17:34] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\M] \Shell\AutoRun\command - M:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2485742e-8d50-11db-a230-0011d80057fd}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{694591fa-8de9-11db-a236-0011d80057fd}] \Shell\AutoRun\command - M:\LaunchU3.exe -a . Contents of the 'Scheduled Tasks' folder "2008-02-23 22:53:58 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-03-01 07:28:08 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\Common Files\Teleca Shared\Generic.exe . ************************************************************************** . Completion time: 2008-03-01 7:33:37 - machine was rebooted [HP_Administrator] ComboFix-quarantined-files.txt 2008-03-01 15:33:33 . 2008-02-13 11:02:17 --- E O F ---