| Alright, I found it.
ComboFix 08-01-23.2 - HP_Owner 2008-01-24 4:51:45.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.258 [GMT -6:00] Running from: C:\Documents and Settings\HP_Owner.BETH.000\My Documents\ComboFix.exe * Created a new restore point .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
C:\Documents and Settings\HP_Owner.YOUR-27E1513D96\Application Data\macromedia\Flash Player\#SharedObjects\AVLYL4BA\www.broadcaster.com C:\Documents and Settings\HP_Owner.YOUR-27E1513D96\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com C:\Program Files\Common Files\{4B5CA~1 C:\Program Files\lsass.exe C:\Program Files\WinBudget C:\WINDOWS\system32\awtqo.dll C:\WINDOWS\system32\awvtu.dll C:\WINDOWS\system32\ddaby.dll C:\WINDOWS\system32\drvbehr.dll C:\WINDOWS\system32\drvdazr.dll C:\WINDOWS\system32\drvzetr.dll C:\WINDOWS\system32\gebcb.dll C:\WINDOWS\system32\geebb.dll C:\WINDOWS\system32\iifgfcy.dll C:\WINDOWS\system32\ljjhigh.dll C:\WINDOWS\system32\sstqr.dll C:\WINDOWS\system32\vtstr.dll C:\WINDOWS\system32\winzzc32.dll C:\WINDOWS\system32\yayvsro.dll D:\Autorun.inf
. ((((((((((((((((((((((((( Files Created from 2007-12-24 to 2008-01-24 ))))))))))))))))))))))))))))))) .
2008-01-24 04:48 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe 2008-01-24 03:27 . 2007-05-30 06:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys 2008-01-24 01:59 . 2008-01-24 01:59 18,944 --a------ C:\WINDOWS\system32\drvvad.dll 2008-01-24 01:09 . 2008-01-24 01:09 <DIR> d-------- C:\Program Files\CCleaner 2008-01-24 00:07 . 2008-01-24 00:07 145 --a------ C:\WINDOWS\system32\winver.bat 2008-01-22 19:18 . 2008-01-22 19:18 103,936 --a------ C:\WINDOWS\system32\drvbeh.dll 2008-01-22 02:18 . 2008-01-22 02:18 2,275,840 --a------ C:\WINDOWS\system32\TUKernel.exe 2008-01-22 02:17 . 2008-01-22 02:17 103,936 --a------ C:\WINDOWS\system32\drvdaz.dll 2008-01-22 01:36 . 2008-01-22 01:36 <DIR> d-------- C:\Program Files\TuneUp Utilities 2008 2008-01-22 01:36 . 2008-01-22 01:36 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe 2008-01-22 01:36 . 2007-12-20 10:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll 2008-01-22 01:35 . 2008-01-22 01:35 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard 2008-01-22 01:12 . 2008-01-22 01:12 103,936 --a------ C:\WINDOWS\system32\drvzet.dll 2008-01-20 03:54 . 2008-01-20 03:54 <DIR> d-------- C:\Program Files\shoutcASP 2008-01-20 03:54 . 2008-01-20 03:54 532,480 --a------ C:\WINDOWS\system32\ASPUtilityBelt.dll 2008-01-20 03:54 . 2008-01-20 03:54 353,280 --a------ C:\WINDOWS\system32\shoutcasp.dll 2008-01-19 22:54 . 2008-01-19 22:54 <DIR> d-------- C:\WINDOWS\system32\includes 2008-01-19 22:54 . 2008-01-19 22:54 1,056,768 --a------ C:\WINDOWS\system32\sppres.exe 2008-01-19 22:54 . 2008-01-19 22:54 20,480 --a------ C:\WINDOWS\system32\loaderybALT.exe 2008-01-19 22:53 . 2008-01-20 00:01 <DIR> d-------- C:\Program Files\iHabbix 2008-01-18 21:37 . 2008-01-18 21:37 6,279,168 --a------ C:\WINDOWS\system32\dwin.exe 2008-01-18 04:51 . 1998-06-17 00:00 385,100 --------- C:\WINDOWS\system32\MSVCRTD.DLL 2008-01-18 04:28 . 2008-01-20 00:08 <DIR> d-------- C:\Program Files\NewSoft 2008-01-18 04:28 . 2003-08-25 16:12 32,768 -ra------ C:\WINDOWS\system32\infcpy.dll 2008-01-08 22:17 . 2002-07-07 16:14 1,294,336 --a------ C:\WINDOWS\system32\vorbis.acm 2008-01-08 21:36 . 2008-01-15 22:44 <DIR> d-------- C:\Program Files\VstPlugins 2008-01-08 21:36 . 2006-06-20 02:56 225,280 --a------ C:\WINDOWS\system32\rewire.dll 2008-01-08 21:33 . 2008-01-15 22:44 <DIR> d-------- C:\Program Files\Image-Line 2007-12-25 06:13 . 2007-12-25 06:13 <DIR> d-------- C:\Program Files\Picasa2
. (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-01-24 07:58 --------- d-----w C:\Program Files\Free Offers from Freeze.com 2008-01-24 05:55 --------- d-----w C:\Program Files\ShortKeys2 2008-01-22 08:12 --------- d-----w C:\Program Files\Veo Digital Studio 2008-01-22 08:12 --------- d-----w C:\Program Files\Quicken 2008-01-22 08:12 --------- d-----w C:\Program Files\PC-Doctor 5 for Windows 2008-01-22 08:12 --------- d-----w C:\Program Files\MSN Encarta Standard 2008-01-22 08:12 --------- d-----w C:\Program Files\Microsoft Works 2008-01-22 08:12 --------- d-----w C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor 2008-01-22 08:12 --------- d-----w C:\Program Files\IntelliMover Data Transfer Demo 2008-01-22 08:12 --------- d-----w C:\Program Files\Easy Internet signup 2008-01-20 09:57 --------- d-----w C:\Program Files\Winamp 2008-01-20 06:11 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-01-04 11:27 --------- d-----w C:\Program Files\Common Files\Scanner 2007-12-29 08:11 --------- d-----w C:\Program Files\Corel 2007-12-29 08:11 --------- d-----w C:\Program Files\Common Files\Corel 2007-12-29 08:07 --------- d-----w C:\Program Files\BitLord 2007-12-17 04:32 --------- d-----w C:\Program Files\Yahoo! 2007-12-13 21:23 --------- d-----w C:\Program Files\Windows Media Connect 2 2007-12-12 09:10 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2 2007-12-12 06:28 --------- d-----w C:\Program Files\Windows Live Toolbar 2007-12-11 11:18 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller 2007-12-11 06:11 935,808 ----a-w C:\WINDOWS\system32\drivers\CamthWDM.sys 2007-11-27 12:10 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys 2007-11-25 09:47 --------- d-----w C:\Program Files\MSN Messenger 2007-11-25 09:46 --------- d-----w C:\Program Files\iTunes 2007-11-25 09:46 --------- d-----w C:\Program Files\iPod 2007-11-24 13:47 --------- d-----w C:\Program Files\QuickTime 2007-11-24 13:45 --------- d-----w C:\Program Files\Apple Software Update 2007-11-02 21:04 394 ----a-w C:\temp.dat 2006-01-04 00:17 774,144 ----a-w C:\Program Files\RngInterstitial.dll .
((((((((((((((((((((((((((((((((((((((((((((( AWF )))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ----a-w 253,952 2005-05-11 00:50:42 C:\hp\drivers\hplsbwatcher\bak\lsburnwatcher.exe ----a-w 253,952 2005-05-11 00:50:42 C:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe
----a-w 180,269 2005-11-01 23:52:52 C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe ----a-w 180,269 2005-11-01 23:52:52 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
----a-w 49,768 2007-01-09 01:03:20 C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe
----a-w 218,240 2004-11-03 07:59:52 C:\Program Files\Common Files\Symantec Shared\Security Center\bak\UsrPrmpt.exe
----a-w 171,448 2007-04-05 02:54:10 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\bak\GoogleToolbarNotifier.exe
----a-w 245,760 2005-02-26 06:34:02 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\bak\HPBootOp.exe ----a-w 245,760 2005-02-26 06:34:02 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
----a-w 49,152 2005-06-02 06:35:56 C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\bak\hphupd08.exe ----a-w 49,152 2005-06-02 06:35:56 C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
----a-w 49,152 2005-05-12 14:12:54 C:\Program Files\HP\HP Software Update\bak\HPwuSchd2.exe ----a-w 49,152 2005-05-12 14:12:54 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
----a-w 256,576 2006-10-30 17:36:36 C:\Program Files\iTunes\bak\iTunesHelper.exe
----a-w 1,694,208 2004-10-13 23:24:38 C:\Program Files\Messenger\bak\msmsgs.exe ----a-w 1,694,208 2004-10-13 23:24:38 C:\Program Files\Messenger\msmsgs.exe
----a-w 282,624 2006-10-26 02:58:18 C:\Program Files\QuickTime\bak\qttask.exe ----a-w 286,720 2007-11-15 05:43:10 C:\Program Files\QuickTime\QTTask.exe
----a-w 100,048 2007-03-29 20:53:09 C:\Program Files\SymNetDrv\bak\SNDMon.exe
----a-w 4,662,776 2006-12-01 05:49:04 C:\Program Files\Yahoo!\Messenger\bak\YahooMessenger.exe ----a-w 4,670,704 2007-08-30 23:43:18 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
. ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{89A1E40D-0254-4F99-B9AE-B60A2D8754A9}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360] "Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 15:17 50736] "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [ ] "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 00:34 245760] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-11-01 17:52 180269] "MSDrive"="C:\WINDOWS\system32\drvbeh.dll" [2008-01-22 19:18 103936] "MSDisp32"="C:\WINDOWS\system32\drvvad.dll" [2008-01-24 01:59 18944] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 03:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-15 14:09 219136]
C:\Documents and Settings\HP_Owner\Start Menu\Programs\Startup\ LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2007-09-17 08:19:14 147456]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableRegistryTools"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Aim6"="C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe "My Web Search Community Tools"="C:\Program Files\MyWebSearch\bar\1.bin\m3IMPipe.exe" "MyWebSearch Email Plugin"=C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe Photo Downloader"="C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.1\apdproxy.exe" "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime "AVG7_CC"=C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP "High Definition Audio Property Page Shortcut"=HDAShCut.exe "HPHUPD08"=c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe "HP Software Update"=C:\Program Files\HP\HP Software Update\HPwuSchd2.exe "HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe "HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0\bin\jusched.exe" "KBD"=C:\HP\KBD\KBD.EXE "KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k "MSDrive"=rundll32.exe C:\WINDOWS\system32\drvdaz.dll,startup "MyWebSearch Email Plugin"=C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe "My Web Search Bar Search Scope Monitor"="C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w "PCDrProfiler"= "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot "WinampAgent"="C:\Program Files\Winamp\winampa.exe"
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 06:00] R3 DCamUSBVeo532;Veo Stingray/Connect Web Camera;C:\WINDOWS\system32\Drivers\ubVeo532.sys [2002-07-01 18:30] R3 WlanUIG;2Wire 802.11g USB Driver;C:\WINDOWS\system32\DRIVERS\WlanUIG.sys [2004-05-16 18:46] S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-01-22 01:36]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}] \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
*Newly Created Service* - AVGASCLN . Contents of the 'Scheduled Tasks' folder "2008-01-22 07:37:04 C:\WINDOWS\Tasks\1-Click Maintenance.job" - C:\Program Files\TuneUp Utilities 2008\OneClick.exe "2008-01-18 13:10:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-01-23 06:00:00 C:\WINDOWS\Tasks\At1.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-23 15:00:02 C:\WINDOWS\Tasks\At10.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-23 16:00:00 C:\WINDOWS\Tasks\At11.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-23 17:00:00 C:\WINDOWS\Tasks\At12.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-21 18:00:00 C:\WINDOWS\Tasks\At13.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-21 19:00:00 C:\WINDOWS\Tasks\At14.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-21 20:00:03 C:\WINDOWS\Tasks\At15.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-20 21:00:00 C:\WINDOWS\Tasks\At16.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-20 22:00:00 C:\WINDOWS\Tasks\At17.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-20 23:00:03 C:\WINDOWS\Tasks\At18.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-23 00:00:00 C:\WINDOWS\Tasks\At19.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-24 07:00:00 C:\WINDOWS\Tasks\At2.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-23 01:00:00 C:\WINDOWS\Tasks\At20.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-23 02:00:00 C:\WINDOWS\Tasks\At21.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-23 03:00:00 C:\WINDOWS\Tasks\At22.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-23 04:00:00 C:\WINDOWS\Tasks\At23.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-24 05:00:02 C:\WINDOWS\Tasks\At24.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-24 08:00:00 C:\WINDOWS\Tasks\At3.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-24 09:00:00 C:\WINDOWS\Tasks\At4.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-24 10:00:03 C:\WINDOWS\Tasks\At5.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-24 11:00:00 C:\WINDOWS\Tasks\At6.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-23 12:00:00 C:\WINDOWS\Tasks\At7.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-23 13:00:00 C:\WINDOWS\Tasks\At8.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2008-01-23 14:00:00 C:\WINDOWS\Tasks\At9.job" - C:\WINDOWS\system32\GvkqAIkW.exe "2005-11-02 00:27:45 C:\WINDOWS\Tasks\Symantec NetDetect.job" - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE . **************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2008-01-24 05:03:01 Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully hidden files: 0
************************************************************************** . --------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156] -> C:\WINDOWS\system32\drvbeh.dll -> C:\WINDOWS\system32\drvvad.dll .
|