ComboFix 10-01-17.02 - HP_Administrator 01/18/2010 7:29.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1982.1449 [GMT -8:00]
Running from: n:\mware\ComboFix.exe
AV: a-squared Anti-Malware *On-access scanning enabled* (Outdated) {0F8591BB-342B-4493-91C3-4E948ED21255}
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HP_Administrator\Favorites\Online Security Test.url
c:\program files\PandoBar
c:\program files\PandoBar\bar\1.bin\NPPANDBR.DLL
c:\program files\PandoBar\bar\1.bin\P4FFXTBR.JAR
c:\program files\PandoBar\bar\1.bin\P4FFXTBR.MANIFEST
c:\program files\PandoBar\bar\1.bin\P4HIGHIN.EXE
c:\program files\PandoBar\bar\1.bin\P4NTSTBR.JAR
c:\program files\PandoBar\bar\1.bin\P4NTSTBR.MANIFEST
c:\program files\PandoBar\bar\1.bin\P4PLUGIN.DLL
c:\program files\PandoBar\bar\1.bin\PANDOBAR.DLL
c:\program files\PandoBar\bar\Cache\00A0714D
c:\program files\PandoBar\bar\Cache\00A077C5.bin
c:\program files\PandoBar\bar\Cache\00A07D24.bin
c:\program files\PandoBar\bar\Cache\00A07F67.bin
c:\program files\PandoBar\bar\Cache\00A0812C.bin
c:\program files\PandoBar\bar\Cache\00A082C2.bin
c:\program files\PandoBar\bar\Cache\00A085DF.bin
c:\program files\PandoBar\bar\Cache\00A08821.bin
c:\program files\PandoBar\bar\Cache\files.ini
c:\program files\PandoBar\bar\History\search2
c:\program files\PandoBar\bar\Settings\prevcfg2.htm
c:\program files\video activex object
c:\program files\video activex object\ot.ico
c:\program files\video activex object\ts.ico
c:\recycler\S-1-5-21-527237240-179605362-725345543-500
c:\windows\kb913800.exe
c:\windows\system32\drivers\H8SRTrebdnolfum.sys
c:\windows\system32\h8srtkrl32mainweq.dll
c:\windows\system32\H8SRTmxmjvawjhu.dll
c:\windows\system32\H8SRTnnspkrddtj.dat
c:\windows\system32\H8SRTrmetlypffu.dll
c:\windows\system32\H8SRTrsdwjxiodl.dll
c:\windows\system32\h8srtshsyst.dll
c:\windows\system32\H8SRTxirpruxnrn.log
c:\windows\system32\H8SRTxujghgkkah.dll
c:\windows\Temp\tmp3.tmp
Z:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_H8SRTd.sys
-------\Legacy_H8SRTd.sys
((((((((((((((((((((((((( Files Created from 2009-12-18 to 2010-01-18 )))))))))))))))))))))))))))))))
.
2010-01-18 13:07 . 2010-01-18 13:07 -------- d-----w- c:\program files\SAS
2010-01-18 06:04 . 2010-01-18 14:34 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\wonehw
2010-01-18 01:06 . 2010-01-18 01:06 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2010-01-18 01:01 . 2010-01-08 00:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-18 01:01 . 2010-01-18 01:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-18 01:01 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-18 01:00 . 2010-01-18 01:00 -------- d-----w- C:\MWare
2010-01-17 23:26 . 2010-01-17 23:26 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-01-17 23:08 . 2010-01-17 23:08 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-17 23:07 . 2010-01-17 23:14 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-01-17 23:07 . 2010-01-17 23:07 -------- d-----w- c:\program files\NOS
2010-01-17 18:41 . 2010-01-18 13:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-16 22:08 . 2010-01-18 13:20 -------- d-----w- c:\program files\a-squared Anti-Malware
2010-01-16 20:14 . 2010-01-16 20:14 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Windows Search
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-18 15:47 . 2009-12-11 20:10 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Dropbox
2010-01-18 15:46 . 2008-12-14 13:42 7 ----a-w- c:\windows\sbacknt.bin
2010-01-18 15:13 . 2007-03-30 02:26 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\U3
2010-01-18 14:08 . 2006-11-01 01:14 89000 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-18 13:07 . 2008-05-20 23:24 -------- d-----w- c:\program files\0-360 UnWrapper 3.2
2010-01-18 12:51 . 2006-11-05 03:26 -------- d-----w- c:\program files\Google
2010-01-18 06:03 . 2007-05-21 07:31 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-18 00:16 . 2007-03-01 15:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Borland
2010-01-18 00:10 . 2006-11-01 01:34 -------- d-----w- c:\program files\Symantec
2010-01-18 00:10 . 2006-11-01 01:34 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-17 23:10 . 2007-01-17 00:14 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-17 18:48 . 2009-09-30 11:56 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\vlc
2010-01-16 21:56 . 2008-05-26 19:49 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-12-15 12:33 . 2007-03-24 18:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-15 12:23 . 2006-11-01 01:16 -------- d-----w- c:\program files\Microsoft Works
2009-12-10 21:02 . 2009-12-10 20:46 -------- d-----w- c:\program files\Boxee
2009-12-10 20:47 . 2009-12-10 20:47 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\BOXEE
2009-12-10 20:41 . 2009-06-29 16:49 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-12-09 22:59 . 2006-11-07 20:32 -------- d-----w- c:\program files\DivX
2009-12-09 22:58 . 2009-06-04 22:23 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-12-07 05:04 . 2009-12-07 05:04 -------- d-----w- c:\program files\MovieToolbox
2009-12-06 21:23 . 2009-12-06 21:23 -------- d-----w- c:\program files\Microsoft Silverlight
2009-12-06 15:49 . 2009-12-06 15:49 -------- d-----w- c:\program files\Ask.com
2009-12-06 05:06 . 2009-12-06 05:05 -------- d-----w- c:\program files\iTunes
2009-12-06 05:05 . 2009-12-06 05:05 -------- d-----w- c:\program files\iPod
2009-12-06 05:05 . 2007-07-06 23:34 -------- d-----w- c:\program files\Common Files\Apple
2009-12-06 05:01 . 2006-11-11 18:48 -------- d-----w- c:\program files\QuickTime
2009-12-06 04:48 . 2009-12-06 04:47 -------- d-----w- c:\program files\Microsoft IntelliPoint
2009-12-06 04:46 . 2009-12-06 04:46 -------- d-----w- c:\program files\Microsoft IntelliType Pro
2009-12-05 14:46 . 2007-03-19 19:09 -------- d-----w- c:\program files\palmOne
2009-12-05 14:41 . 2006-11-08 02:01 -------- d-----w- c:\program files\DYMO Label
2009-12-05 14:24 . 2008-12-13 14:06 -------- d-----w- c:\program files\Xobni
2009-12-04 06:24 . 2009-12-04 06:23 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\HpUpdate
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47 . 2009-11-14 00:47 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47 . 2009-11-14 00:47 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47 . 2009-11-14 00:47 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47 . 2009-11-14 00:47 696320 ----a-w- c:\windows\system32\DivX.dll
2009-10-29 07:46 . 2004-08-09 21:00 832512 ----a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2004-08-09 21:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2004-08-09 21:00 17408 ----a-w- c:\windows\system32\corpol.dll
2006-11-04 02:27 . 2006-11-04 02:21 45465133 ----a-w- c:\program files\PartitionMagic805AllWin_English.ZIP
2006-11-04 02:25 . 2006-11-04 02:25 0 ----a-w- c:\program files\PM801EI1-371501.txt
2006-11-04 00:01 . 2006-11-04 00:01 22 --sha-w- c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2009-06-17 01:22 1144712 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-06-17 1144712]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-10-08 21:18 77824 ----a-w- c:\documents and settings\HP_Administrator\Application Data\Dropbox\bin\DropboxExt.3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-13 16239616]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 155648]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"WD Button Manager"="WDBtnMgr.exe" [2008-06-30 364544]
"DISCover"="c:\program files\DISC\DISCover.exe" [2007-10-31 1095256]
"Babylon Client"="c:\program files\Babylon\Babylon-Pro\Babylon.exe" [2008-02-27 3551456]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-11 2043160]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-04-10 2595792]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-04-10 909208]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-04-10 136472]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-28 198160]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2009-05-21 1501064]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-05-26 1468296]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-13 141600]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 69632]
"a-squared"="c:\program files\a-squared Anti-Malware\a2guard.exe" [2010-01-02 3280712]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 221184]
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-10-31 27136]
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-10-31 27136]
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
Data\Dropbox\bin\Dropbox.exe [2009-10-8 26805255]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Audible Download Manager.lnk - d:\audible downloads\Bin\AudibleDownloadHelper.exe [2007-4-11 845408]
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-10-31 36903]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-17 16:31 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NETGEAR\\sph101\\WiFiPhone Update.exe"=
"c:\\Program Files\\yProxy\\yProxy.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Participatory Culture Foundation\\Miro\\xulrunner\\python\\Miro_Downloader.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Pando Networks\\Pando\\Pando.exe"=
"c:\\Program Files\\Boxee\\BOXEE.exe"=
R0 hotcore2;hotcore2;c:\windows\system32\drivers\hotcore2.sys [3/3/2007 2:15 PM 30808]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/26/2008 11:49 AM 335240]
R2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared Anti-Malware\a2service.exe [1/16/2010 2:08 PM 1858144]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/29/2009 8:48 AM 297752]
R2 XobniService;XobniService;c:\program files\Xobni\XobniService.exe [11/20/2008 11:30 AM 46824]
R3 MusCAudio;MusCAudio;c:\windows\system32\drivers\MusCAudio.sys [7/3/2009 9:55 AM 23096]
R3 MusCVideo;MusCVideo;c:\windows\system32\drivers\MusCVideo.sys [7/3/2009 9:55 AM 3768]
S2 gupdate1c9e56327c9c6c0;Google Update Service (gupdate1c9e56327c9c6c0);c:\program files\Google\Update\GoogleUpdate.exe [6/4/2009 2:23 PM 133104]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [3/3/2007 11:42 AM 20760]
S3 SMServer;SMServer;c:\windows\system32\snmvtsvc.exe [7/3/2009 9:55 AM 245760]
S3 STVqx3;Intel Play QX3 Microscope;c:\windows\system32\drivers\STVqx3.SYS [4/12/2009 10:24 AM 131776]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [9/7/2006 8:16 PM 11520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-01-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-12 19:34]
2010-01-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-04 22:23]
2010-01-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-04 22:23]
2009-12-06 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2009-05-26 19:16]
2010-01-18 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-06-17 01:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PAVILION&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
Trusted Zone: trymedia.com
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\fcjiuckp.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.nytimes.com//?oref=login
FF - component: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\fcjiuckp.default\extensions\{16f796dd-a279-4548-9b3a-393d1eef31df}\platform\WINNT\components\imageassistant.dll
FF - component: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\fcjiuckp.default\extensions\
[email protected]\components\coolirisstub.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\fcjiuckp.default\extensions\
[email protected]\plugins\npcoolirisplugin.dll
FF - plugin: c:\documents and settings\HP_Administrator\Application Data\Mozilla\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPPandBr.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-StatBar - c:\program files\Globe Software\StatBar\StatBar.exe
HKCU-Run-LClock - c:\program files\LClock\LClock.exe
HKCU-Run-btgujnod - c:\documents and settings\HP_Administrator\Local Settings\Application Data\wonehw\rfupsysguard.exe
HKLM-Run-PCDrProfiler - (no file)
HKLM-Run-DeskMateAutoUpdate - c:\program files\DeskMates\DeskMateAutoUpdate.exe
HKLM-Run-btgujnod - c:\documents and settings\HP_Administrator\Local Settings\Application Data\wonehw\rfupsysguard.exe
AddRemove-AudibleDownloadManager - d:\audible downloads\Audible\Bin\AudibleDM_iTunesSetup(3).exe
AddRemove-AudibleManager - d:\audible downloads\Audible\Bin\Upgrade.exe
AddRemove-Internet Explorer Security Plugin 2006 - c:\program files\Video ActiveX Object\iesuninst.exe
AddRemove-Internet Security Add-On - c:\program files\Video ActiveX Object\isauninst.exe
AddRemove-Public Messenger ver 2.03 - c:\program files\Video ActiveX Object\pmuninst.exe
AddRemove-Safety Alerter 2006 - c:\docume~1\HP_ADM~1\LOCALS~1\Temp\lafB77.tmp
AddRemove-{E2883E8F-472F-4fb0-9522-AC9BF37916A7} - c:\program files\NOS\bin\getPlus_Helper.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-18 07:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
StatBar = c:\program files\Globe Software\StatBar\StatBar.exe???
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(944)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(1004)
c:\windows\system32\relog_ap.dll
- - - - - - - > 'explorer.exe'(5812)
c:\windows\system32\WININET.dll
c:\docume~1\HP_ADM~1\LOCALS~1\Temp\IadHide5.dll
c:\program files\ScanSoft\OmniPageSE4.0\OpHookSE4.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\arservice.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
c:\windows\system32\SearchIndexer.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\ARPWRMSG.EXE
c:\windows\eHome\ehmsas.exe
c:\windows\system32\WDBtnMgr.exe
c:\program files\DISC\DiscStreamHub.exe
c:\program files\Microsoft IntelliType Pro\dpupdchk.exe
c:\program files\iPod\bin\iPodService.exe
c:\hp\KBD\KBD.EXE
c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
c:\program files\Java\jre1.5.0_06\bin\jusched.exe
c:\windows\system32\SearchProtocolHost.exe
c:\windows\system32\SearchFilterHost.exe
.
**************************************************************************
.
Completion time: 2010-01-18 07:56:08 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-18 15:56
Pre-Run: 12,636,020,736 bytes free
Post-Run: 15,408,369,664 bytes free
- - End Of File - - ED141B32D80D4ACFA96FDD38F4CE020C