by jan777 » Fri Jul 23, 2010 2:21 pm
ComboFix 10-07-22.06 - aileen 07/24/2010 3:33.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.117 [GMT 8:00]
Running from: c:\documents and settings\aileen\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\aileen\Desktop\CFscript.txt
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected
Restored copy from - Kitty had a snack :p
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :p
.
((((((((((((((((((((((((( Files Created from 2010-06-23 to 2010-07-23 )))))))))))))))))))))))))))))))
.
2010-07-23 00:32 . 2010-07-23 00:32 -------- d-----w- c:\documents and settings\aileen\DoctorWeb
2010-07-22 14:51 . 2010-07-22 14:51 69232 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-22 14:36 . 2010-07-22 14:36 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-07-21 21:49 . 2010-07-21 21:49 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-07-21 09:46 . 2010-07-21 09:47 -------- d-----w- c:\documents and settings\aileen\Application Data\PSPdisp
2010-07-21 09:42 . 2009-08-04 16:04 7808 ----a-w- c:\windows\system32\pspdisp.dll
2010-07-21 09:42 . 2009-08-04 16:04 3072 ----a-w- c:\windows\system32\drivers\pspdisp.sys
2010-07-21 01:33 . 2008-04-13 18:41 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-07-21 01:33 . 2008-04-13 18:41 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-07-21 01:33 . 2001-08-17 06:07 25952 -c--a-w- c:\windows\system32\dllcache\hpn.sys
2010-07-21 01:33 . 2001-08-17 06:07 25952 ----a-w- c:\windows\system32\drivers\hpn.sys
2010-07-21 00:46 . 2010-07-21 03:46 -------- d-----w- c:\program files\AA Antimalware
2010-07-20 21:27 . 2010-07-20 21:27 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-07-20 20:54 . 2010-07-20 20:54 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2010-07-20 20:54 . 2010-07-20 20:54 -------- d-----w- c:\documents and settings\LocalService\Application Data\Yahoo!
2010-07-20 20:54 . 2010-07-21 02:20 -------- d-----w- c:\documents and settings\LocalService\Application Data\HPAppData
2010-07-20 20:54 . 2010-07-20 20:54 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-07-20 16:11 . 2010-07-20 16:11 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-07-20 16:10 . 2010-07-21 00:57 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-07-20 10:29 . 2010-07-23 09:11 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-07-20 10:29 . 2010-07-23 09:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-20 09:13 . 2010-07-23 16:19 -------- d-----w- C:\Hjt
2010-07-19 07:20 . 2010-07-19 07:20 -------- d-----w- c:\documents and settings\aileen\Application Data\fofix
2010-07-17 06:18 . 2010-07-17 06:35 -------- d-----w- c:\documents and settings\aileen\Application Data\vlc
2010-07-17 06:14 . 2010-07-17 06:14 -------- d-----w- c:\program files\VideoLAN
2010-07-13 21:16 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-11 02:13 . 2010-07-11 02:13 -------- d-----w- c:\documents and settings\aileen\Local Settings\Application Data\tjnet
2010-07-10 04:10 . 2010-07-23 19:48 -------- d-----w- c:\documents and settings\aileen\Application Data\mjusbsp
2010-07-10 04:05 . 2008-04-13 18:45 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-07-04 08:43 . 2010-07-04 08:43 -------- d-----w- c:\program files\Chikka Messenger
2010-07-03 06:44 . 2009-10-17 04:17 324096 ----a-w- c:\windows\SDL.dll
2010-07-03 06:44 . 2008-01-26 07:59 53248 ----a-w- c:\windows\DsPad.dll
2010-06-30 04:35 . 2010-07-21 01:12 -------- d-----w- c:\program files\Mozilla Firefox 4.0 Beta 1
2010-06-30 03:57 . 2001-08-17 06:02 2688 -c--a-w- c:\windows\system32\dllcache\hidswvd.sys
2010-06-30 03:57 . 2001-08-17 06:02 2688 ----a-w- c:\windows\system32\drivers\HIDSwvd.sys
2010-06-30 03:57 . 2008-04-13 18:45 59136 -c--a-w- c:\windows\system32\dllcache\gckernel.sys
2010-06-30 03:57 . 2008-04-13 18:45 59136 ----a-w- c:\windows\system32\drivers\GcKernel.sys
2010-06-29 15:13 . 2010-07-22 09:40 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-06-29 09:17 . 2010-07-23 16:37 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-06-27 22:13 . 2010-07-21 09:46 -------- d-----w- c:\program files\PSPdisp
2010-06-27 21:56 . 2010-06-27 21:56 -------- d-----w- c:\program files\PPJoy Joystick Driver
2010-06-27 21:47 . 2010-06-27 21:47 -------- d-----w- c:\program files\Parallel Port Joystick
2010-06-27 21:37 . 2010-06-27 21:37 -------- d-----w- c:\documents and settings\aileen\Application Data\TightVNC
2010-06-27 21:09 . 2010-06-27 21:09 -------- d-----w- c:\documents and settings\LocalService\Application Data\TightVNC
2010-06-27 07:32 . 2010-06-27 07:32 -------- d-----w- c:\windows\Ubisoft
2010-06-27 07:30 . 2010-06-27 07:30 -------- d-----w- c:\program files\directx
2010-06-27 07:24 . 2010-06-27 07:24 -------- d-----w- c:\program files\Ubi Soft
2010-06-26 02:08 . 2010-06-26 02:08 -------- d-----w- c:\documents and settings\aileen\Local Settings\Application Data\GameTuts
2010-06-26 02:08 . 2010-06-26 02:08 -------- d-----w- c:\documents and settings\aileen\Application Data\GameTuts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-23 09:19 . 2009-12-08 09:16 -------- d-----w- c:\program files\Garena
2010-07-22 11:22 . 2010-06-12 05:54 -------- d-----w- c:\program files\Defraggler
2010-07-22 08:42 . 2008-05-04 09:51 -------- d-----w- c:\program files\uTorrent
2010-07-22 08:42 . 2008-08-28 14:03 -------- d-----w- c:\documents and settings\aileen\Application Data\uTorrent
2010-07-22 07:27 . 2008-12-27 14:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-07-20 15:55 . 2008-04-02 07:18 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-20 15:21 . 2009-03-17 15:00 -------- d-----w- c:\documents and settings\aileen\Application Data\LimeWire
2010-07-20 15:19 . 2008-08-28 14:03 -------- d-----w- c:\documents and settings\aileen\Application Data\Media Player Classic
2010-07-20 15:14 . 2010-06-12 04:39 -------- d-----w- c:\program files\CCleaner
2010-07-20 05:00 . 2009-01-27 09:51 -------- d-----w- c:\documents and settings\aileen\Application Data\HPAppData
2010-07-18 06:55 . 2010-06-04 20:27 -------- d-----w- c:\program files\JDownloader
2010-07-12 20:18 . 2010-04-07 16:21 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-12 20:18 . 2010-04-01 13:40 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-07-12 20:17 . 2010-07-12 20:17 56765 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-07-12 20:17 . 2010-04-07 16:12 -------- d-----w- c:\program files\DivX
2010-07-12 20:17 . 2010-07-12 20:17 57715 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-07-12 20:17 . 2010-07-12 20:17 84054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-07-12 20:16 . 2008-04-10 03:53 -------- d-----w- c:\program files\FlashGet
2010-07-12 20:15 . 2010-07-12 20:15 54153 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-07-12 20:15 . 2010-04-07 16:21 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-07-12 20:15 . 2010-04-07 16:21 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-07-02 06:02 . 2010-05-16 22:33 -------- d-----w- c:\program files\RocketDock
2010-07-02 06:01 . 2010-04-08 05:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2010-07-02 06:01 . 2009-01-23 09:59 -------- d-----w- c:\program files\Norton Security Scan
2010-07-02 06:01 . 2010-06-06 08:12 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-07-01 19:30 . 2010-06-15 04:30 -------- d-----w- c:\documents and settings\aileen\Application Data\Image Zone Express
2010-06-23 02:40 . 2010-06-05 19:44 -------- d-----w- c:\documents and settings\aileen\Application Data\DivX
2010-06-14 14:31 . 2008-04-02 07:08 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-12 05:58 . 2010-06-12 05:58 -------- d-----w- c:\program files\RAM Def
2010-06-12 04:41 . 2010-06-12 04:41 -------- d-----w- c:\program files\Speccy
2010-06-05 19:44 . 2010-06-05 19:44 56997 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-06-05 19:44 . 2010-06-05 19:44 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-06-05 19:43 . 2010-06-05 19:43 57054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-06-05 19:43 . 2010-06-05 19:43 54166 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-06-05 19:43 . 2010-06-05 19:43 57532 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-06-05 19:43 . 2010-06-05 19:43 56458 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-06-05 19:43 . 2010-06-05 19:43 54174 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-06-05 19:43 . 2010-06-05 19:43 54128 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe
2010-06-05 19:43 . 2010-06-05 19:43 54644 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-06-05 19:43 . 2010-06-05 19:43 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-06-05 19:43 . 2010-06-05 19:43 54101 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-05 19:43 . 2010-06-05 19:43 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-06-05 02:18 . 2010-06-01 02:29 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-03 03:26 . 2010-05-28 08:13 -------- d-----w- c:\program files\AeroSnap
2010-05-29 02:21 . 2010-05-21 17:26 -------- d-----w- c:\program files\FileZilla Server
2010-05-28 08:22 . 2010-05-28 08:22 -------- d-----w- c:\documents and settings\aileen\Application Data\AeroSnapApp
2010-05-28 04:48 . 2010-05-28 04:48 -------- d-----w- c:\documents and settings\aileen\Application Data\VitySoft
2010-05-15 22:32 . 2010-05-15 22:32 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-05-04 17:20 . 2006-02-28 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 17:20 . 2006-02-28 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:20 . 2006-02-28 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-05-02 05:22 . 2006-02-28 12:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 07:39 . 2010-05-01 23:22 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 07:39 . 2010-05-01 23:22 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-27 00:15 . 2009-12-08 11:58 36928 ----a-w- c:\windows\system32\drivers\pssdk41.sys
2008-06-25 14:17 . 2008-06-25 14:17 4736 -c--a-w- c:\program files\log467700245.txt
2006-05-03 10:06 . 2008-12-23 07:56 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 11:47 . 2008-12-23 07:56 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 13:30 . 2008-12-23 07:56 216064 --sh--r- c:\windows\system32\nbDX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\aileen\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-07-31 133104]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
"cdloader"="c:\documents and settings\aileen\Application Data\mjusbsp\cdloader2.exe" [2010-02-26 50520]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]
"QuickTime Task"="c:\program files\K-Lite Codec Pack\QuickTime\QTTask.exe" [2009-09-04 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"RAMDef"="c:\program files\RAM Def\ramdef.exe" [2002-10-28 122040]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-06-01 1093208]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
c:\documents and settings\aileen\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
PSPdisp.lnk - c:\program files\PSPdisp\bin\app\PSPdisp.exe [2010-6-1 608256]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
[BU]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^aileen^Start Menu^Programs^Startup^FrostWire On Startup.lnk]
path=c:\documents and settings\aileen\Start Menu\Programs\Startup\FrostWire On Startup.lnk
backup=c:\windows\pss\FrostWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^aileen^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\aileen\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^aileen^Start Menu^Programs^Startup^Multiply AutoUploader.lnk]
path=c:\documents and settings\aileen\Start Menu\Programs\Startup\Multiply AutoUploader.lnk
backup=c:\windows\pss\Multiply AutoUploader.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^aileen^Start Menu^Programs^Startup^WinShake Control.lnk]
path=c:\documents and settings\aileen\Start Menu\Programs\Startup\WinShake Control.lnk
backup=c:\windows\pss\WinShake Control.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-14 17:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AeroSnap]
2008-12-06 11:32 886784 ----a-w- c:\program files\AeroSnap\AeroSnap.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2009-07-31 22:58 133104 ----atw- c:\documents and settings\aileen\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-10-14 13:17 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
2007-08-22 08:31 80896 ----a-w- c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-21 08:36 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
2009-02-23 13:05 111856 ----a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-03-19 09:11 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
2009-02-23 13:05 111856 ----a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"e:\\Warcraft III 1.21 DotA 6.44b pack\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\WINDOWS\\system32\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\aileen\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"e:\\Warcraft III 1.21 DotA 6.44b pack\\Warcraft III\\war3.exe"=
"c:\\Program Files\\PSPdisp\\bin\\app\\PSPdisp.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Documents and Settings\\aileen\\Application Data\\mjusbsp\\magicJack.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"27985:TCP"= 27985:TCP:limewire
"8370:TCP"= 8370:TCP:League of Legends Launcher
"8370:UDP"= 8370:UDP:League of Legends Launcher
"8371:TCP"= 8371:TCP:League of Legends Launcher
"8371:UDP"= 8371:UDP:League of Legends Launcher
"8372:TCP"= 8372:TCP:League of Legends Launcher
"8372:UDP"= 8372:UDP:League of Legends Launcher
"6926:TCP"= 6926:TCP:League of Legends Launcher
"6926:UDP"= 6926:UDP:League of Legends Launcher
"6908:TCP"= 6908:TCP:League of Legends Launcher
"6908:UDP"= 6908:UDP:League of Legends Launcher
"6893:TCP"= 6893:TCP:League of Legends Launcher
"6893:UDP"= 6893:UDP:League of Legends Launcher
"8377:TCP"= 8377:TCP:League of Legends Launcher
"8377:UDP"= 8377:UDP:League of Legends Launcher
"8378:TCP"= 8378:TCP:League of Legends Launcher
"8378:UDP"= 8378:UDP:League of Legends Launcher
"2145:TCP"= 2145:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [5/2/2010 7:22 AM 304464]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [5/2/2010 7:22 AM 20952]
R3 PPJoyBus;Parallel Port Joystick Bus Enumerator;c:\windows\system32\drivers\PPJoyBus.sys [1/23/2004 4:33 PM 16056]
R3 PPortJoystick;Parallel Port Joystick Device Driver;c:\windows\system32\drivers\PPortJoy.sys [1/23/2004 4:32 PM 31928]
R3 pspdisp;pspdisp;c:\windows\system32\drivers\pspdisp.sys [7/21/2010 5:42 PM 3072]
S0 sptd;sptd;c:\windows\system32\Drivers\sptd.sys --> c:\windows\system32\Drivers\sptd.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS --> c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.SYS --> c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [?]
S2 d2cs;d2cs service;c:\documents and settings\aileen\Desktop\pvpgn-1.8.0\d2cs.exe --service --> c:\documents and settings\aileen\Desktop\pvpgn-1.8.0\d2cs.exe --service [?]
S2 d2dbs;d2dbs service;c:\documents and settings\aileen\Desktop\pvpgn-1.8.0\d2dbs.exe --service --> c:\documents and settings\aileen\Desktop\pvpgn-1.8.0\d2dbs.exe --service [?]
S2 pvpgn;PvPGN service;c:\documents and settings\aileen\Desktop\pvpgn-1.8.0\PvPGN.exe --service --> c:\documents and settings\aileen\Desktop\pvpgn-1.8.0\PvPGN.exe --service [?]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\aileen\LOCALS~1\Temp\LSH34.tmp --> c:\docume~1\aileen\LOCALS~1\Temp\LSH34.tmp [?]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys --> c:\windows\system32\DRIVERS\ewusbfake.sys [?]
S3 leafnets;Leaf Networks Adapter;c:\windows\system32\drivers\leafnets.sys [5/3/2007 7:48 AM 55296]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 PsSdk41;PsSdk41;c:\windows\system32\drivers\pssdk41.sys [12/8/2009 7:58 PM 36928]
S3 WPRO_40_1123;WinPcap Packet Driver (WPRO_40_1123);c:\windows\system32\drivers\WPRO_40_1123.sys --> c:\windows\system32\drivers\WPRO_40_1123.sys [?]
S3 ZSMC0305;Look 316;c:\windows\system32\drivers\usbVM305.sys [4/9/2008 9:45 PM 1466624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2010-07-23 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 03:20]
2010-07-23 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-27 13:13]
2010-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-152049171-725345543-1007Core.job
- c:\documents and settings\aileen\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-31 22:58]
2010-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1202660629-152049171-725345543-1007UA.job
- c:\documents and settings\aileen\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-31 22:58]
2010-07-23 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2010-03-25 13:40]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.garena.com/portal/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add Hyperlink iComment - c:\program files\iComment 2.0.2\iComment.dll/267
IE: Add Picture iComment - c:\program files\iComment 2.0.2\iComment.dll/267
IE: Add Text iComment - c:\program files\iComment 2.0.2\iComment.dll/267
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: kuaiche.com\software
FF - ProfilePath - c:\documents and settings\aileen\Application Data\Mozilla\Firefox\Profiles\bx42ntav.default\
FF - component: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin2.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin3.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin4.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin5.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin6.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin7.dll
FF - plugin: c:\program files\K-Lite Codec Pack\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox 4.0 Beta 1\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox 4.0 Beta 1\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox 4.0 Beta 1\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox 4.0 Beta 1\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox 4.0 Beta 1\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox 4.0 Beta 1\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-TrueTransparency - c:\documents and settings\aileen\My Documents\Downloads\truetransparency-crystalxp.net-en-5139\TrueTransparency\TrueTransparency.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-24 03:48
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8326BB4C]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf85f7f28
\Driver\ACPI -> ACPI.sys @ 0xf848acb8
\Driver\atapi -> atapi.sys @ 0xf841c852
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Realtek RTL8139 Family PCI Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf8329bd4
PacketIndicateHandler -> NDIS.sys @ 0xf8335a21
SendHandler -> NDIS.sys @ 0xf8329d44
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\aileen\LOCALS~1\Temp\LSH34.tmp"
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(388)
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(448)
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2352)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Security Essentials\MsMpEng.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\FileZilla Server\FileZilla Server.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\documents and settings\aileen\Application Data\mjusbsp\magicJack.exe
.
**************************************************************************
.
Completion time: 2010-07-24 03:59:54 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-23 19:59
ComboFix2.txt 2010-07-22 23:27
ComboFix3.txt 2010-07-22 08:07
ComboFix4.txt 2010-07-22 07:04
ComboFix5.txt 2010-07-23 19:21
Pre-Run: 14,768,353,280 bytes free
Post-Run: 14,785,736,704 bytes free
Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - 53C1E0AC475152C4811E5698209A3DF4