----------------------
ComboFix 09-08-21.02 - HP_Administrator 08/25/2009 16:44.4.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1485 [GMT -5:00]
Running from: c:\documents and settings\HP_Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Administrator\Desktop\CFScript.txt
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\drv
c:\program files\drv\drv.dll
.
((((((((((((((((((((((((( Files Created from 2009-07-25 to 2009-08-25 )))))))))))))))))))))))))))))))
.
2009-08-23 08:17 . 2009-08-23 08:17 -------- d-----w- C:\14e452c7e955f665f1aa565f32
2009-08-23 08:17 . 2009-08-23 14:56 -------- d-----w- c:\windows\SxsCaPendDel
2009-08-22 15:45 . 2009-03-06 14:22 284160 ------w- c:\windows\system32\dllcache\pdh.dll
2009-08-22 15:45 . 2009-02-09 12:10 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2009-08-22 15:45 . 2009-02-09 12:10 729088 ------w- c:\windows\system32\dllcache\lsasrv.dll
2009-08-22 15:45 . 2009-02-09 12:10 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
2009-08-22 15:45 . 2009-02-09 12:10 617472 ------w- c:\windows\system32\dllcache\advapi32.dll
2009-08-22 15:45 . 2009-02-09 12:10 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2009-08-22 15:45 . 2009-02-09 12:10 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-08-22 15:45 . 2009-02-06 11:11 110592 ------w- c:\windows\system32\dllcache\services.exe
2009-08-22 15:45 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2009-08-22 15:44 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-08-22 15:40 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-08-22 15:40 . 2008-04-21 12:08 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2009-08-22 15:23 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-08-22 15:23 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
2009-08-21 23:18 . 2008-12-04 13:17 627072 ----a-r- c:\windows\system32\drivers\WUSB54GCv3.sys
2009-08-21 23:18 . 2008-12-04 13:17 221184 ----a-w- c:\windows\system32\RaCoInst.dll
2009-08-21 23:18 . 2008-12-04 13:17 15312 ----a-r- c:\windows\system32\RaCoInst.dat
2009-08-21 23:14 . 2009-08-21 23:14 -------- d-----w- c:\program files\Pure Networks
2009-08-21 23:13 . 2009-08-21 23:13 -------- d-----w- c:\program files\WebEx
2009-08-21 23:13 . 2009-04-07 20:33 23984 ----a-w- c:\windows\system32\drivers\pnarp.sys
2009-08-21 23:13 . 2009-04-07 20:33 25264 ----a-w- c:\windows\system32\drivers\purendis.sys
2009-08-21 23:13 . 2009-08-21 23:13 -------- d-----w- c:\program files\Common Files\Pure Networks Shared
2009-08-21 23:12 . 2009-08-21 23:19 -------- d-----w- c:\program files\Linksys
2009-08-21 23:12 . 2009-04-29 15:16 34276400 ----a-r- c:\documents and settings\All Users\Application Data\Pure Networks\Setup\nmsetup.exe
2009-08-21 23:12 . 2009-08-21 23:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Pure Networks
2009-08-20 22:00 . 2009-08-20 22:00 -------- d-----w- c:\program files\TweetDeck
2009-08-17 05:38 . 2009-08-17 05:38 -------- d-----w- c:\program files\Trend Micro
2009-08-05 09:01 . 2009-08-05 09:01 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-29 04:37 . 2009-07-29 04:37 81920 ------w- c:\windows\system32\dllcache\fontsub.dll
2009-07-29 04:37 . 2009-07-29 04:37 119808 ------w- c:\windows\system32\dllcache\t2embed.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-25 15:00 . 2007-10-03 02:46 -------- d-----w- c:\program files\Steam
2009-08-24 22:25 . 2008-09-25 04:15 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-23 14:58 . 2006-02-09 00:37 63448 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-23 14:56 . 2008-03-20 06:18 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-23 08:09 . 2008-02-27 15:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-08-22 19:52 . 2009-02-05 23:28 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-21 23:13 . 2009-08-21 23:13 8892928 ----a-w- c:\documents and settings\All Users\Application Data\atscie.msi
2009-08-19 00:02 . 2008-08-17 21:08 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\U3
2009-08-05 09:01 . 2004-08-09 21:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:37 . 2004-08-09 21:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-29 04:37 . 2004-08-09 21:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-23 00:27 . 2009-07-23 00:26 -------- d-----w- c:\program files\iTunes
2009-07-23 00:26 . 2006-05-20 23:13 -------- d-----w- c:\program files\iPod
2009-07-23 00:26 . 2007-07-02 03:55 -------- d-----w- c:\program files\Common Files\Apple
2009-07-23 00:15 . 2009-07-23 00:15 75040 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-17 19:01 . 2004-08-09 21:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-16 23:28 . 2009-07-16 23:28 34226736 ----a-w- c:\documents and settings\All Users\Application Data\Pure Networks\Platform\1033\Update\nm\nmsetup.exe
2009-07-14 04:43 . 2004-08-09 21:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-05 19:04 . 2009-07-05 19:04 0 ----a-w- c:\documents and settings\HP_Administrator\ntuser.tmp
2009-07-05 16:11 . 2008-09-25 04:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-02 06:57 . 2006-05-27 22:15 -------- d-----w- c:\program files\DivX
2009-07-02 06:57 . 2009-05-21 20:58 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-06-29 16:12 . 2004-08-09 21:00 827392 ------w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-09 21:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-09 21:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-17 05:36 . 2009-06-17 05:38 38208 ----a-w- c:\documents and settings\HP_Administrator\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-06-12 12:31 . 2004-08-09 21:00 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2004-08-10 04:00 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:19 . 2004-08-09 21:00 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2004-08-09 21:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2004-08-09 21:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2004-08-09 21:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2004-08-09 21:00 . 2006-05-20 14:47 28672 ----a-w- c:\program files\mozilla firefox\plugins\custsat.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2006-05-06 16:42 . 2006-08-10 20:13 7260160 ----a-w- c:\program files\mozilla firefox\plugins\libvlc.dll
2006-05-10 03:26 . 2006-05-20 14:47 345088 ----a-w- c:\program files\mozilla firefox\plugins\mpvis.dll
2005-08-04 02:29 . 2006-05-20 14:47 47616 ----a-w- c:\program files\mozilla firefox\plugins\msoobci.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2006-05-10 02:02 . 2006-05-20 14:47 146432 ----a-w- c:\program files\mozilla firefox\plugins\wmpnssci.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-08-24_22.43.30 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-25 14:58 . 2009-08-25 14:58 16384 c:\windows\Temp\Perflib_Perfdata_694.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\steam\steam.exe" [2009-06-10 1217784]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-04-05 344064]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2009-04-07 642856]
"Linksys Wireless Manager"="c:\program files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe" [2009-02-16 1358384]
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-2-8 27136]
c:\documents and settings\MCX1.AJ\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-2-8 27136]
c:\documents and settings\MCX2\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-2-8 27136]
c:\documents and settings\MCX3\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-2-8 27136]
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
Shortcut to iTunes.lnk - c:\program files\iTunes\iTunes.exe [2009-7-13 14074656]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJBQHaw]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NavLogon]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Viewpoint Manager Service"=2 (0x2)
"MDM"=2 (0x2)
"McTskshd.exe"=2 (0x2)
"McShield"=2 (0x2)
"LightScribeService"=2 (0x2)
"Bonjour Service"=2 (0x2)
"AresChatServer"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"mcupdmgr.exe"=3 (0x3)
"ppped"=2 (0x2)
"PnkBstrA"=2 (0x2)
"Pml Driver HPZ12"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"McDetect.exe"=2 (0x2)
"LiveUpdate"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"iPod Service"=3 (0x3)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"avg8wd"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\trackmania nations forever\\TmForever.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\trackmania nations forever\\TmForeverLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\peggle extreme\\PeggleExtreme.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dawn of war ii - spd\\DOW2.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe"= c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:LocalSubNet,0.0.0.0/255.255.255.255:Enabled:Pure Networks Platform Service
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
R3 WUSB54GCv3;Compact Wireless-G USB Network Adapter;c:\windows\system32\drivers\WUSB54GCv3.sys [8/21/2009 6:18 PM 627072]
S3 PsSdk30;PsSdk30;\??\c:\windows\system32\Drivers\PsSdk30.drv --> c:\windows\system32\Drivers\PsSdk30.drv [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
drv REG_MULTI_SZ drv
.
Contents of the 'Scheduled Tasks' folder
2009-08-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34]
.
- - - - ORPHANS REMOVED - - - -
BHO-{16F689D9-3CEB-478B-8E20-E39F50FF3173} - (no file)
BHO-{1963CD8E-E1C3-49D0-96AB-2912F4A1D53B} - (no file)
BHO-{29AB3C6A-81EE-4FCB-BF9C-C6C4814401C2} - (no file)
BHO-{7A0BB50B-0FC5-43CC-9876-21035D96CB6D} - (no file)
BHO-{8B2DD00E-A897-4569-BE3C-87A3B1FF2255} - (no file)
BHO-{905BAF2D-86B8-426D-B46D-536226F9C12C} - (no file)
BHO-{9F0DBE64-006F-48E3-90E2-1A1A6278C7C1} - (no file)
BHO-{A58E436F-CC58-469C-8798-66CEEED082B9} - (no file)
BHO-{A8CA3B1A-5478-4DA3-8ACA-71942A25AD65} - (no file)
BHO-{ADABB0C3-881F-4FA2-8EAC-802959513BE2} - (no file)
BHO-{CA310FBB-02AB-4DC8-AC71-DAA939550E29} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.neogaf.com/forum/
DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} - hxxps://webapps.saionline.com/AccountMa ... /setup.exe
DPF: {B991DA79-51F7-4011-98D2-1F2592E82A56} - hxxp://drm1.reelsurvey.com/ePlayer/V3_2 ... Player.cab
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\f2wjt8d4.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.neogaf.com/forum/
FF - plugin: c:\documents and settings\All Users\Application Data\id Software\QuakeLive\npquakezero.dll
FF - plugin: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\f2wjt8d4.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdrmv2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdsplay.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMGWRAP.DLL
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npvlc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npwmsdrm.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-25 16:54
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\catchme.dll 53248 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PsSdk30]
"ImagePath"="\??\c:\windows\system32\Drivers\PsSdk30.drv"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1000)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-08-25 16:57
ComboFix-quarantined-files.txt 2009-08-25 21:56
ComboFix2.txt 2009-08-24 22:46
ComboFix3.txt 2009-08-22 20:22
ComboFix4.txt 2009-08-22 15:42
Pre-Run: 104,267,210,752 bytes free
Post-Run: 104,220,749,824 bytes free
258 --- E O F --- 2009-08-24 06:52
--------------------------------