Followed instructions
ComboFix 08-01-29.1 - TIMOTHY COUTURE 2008-01-30 17:54:12.2 - NTFSx86
Running from: C:\Documents and Settings\TIMOTHY COUTURE\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\TIMOTHY COUTURE\Desktop\CFscript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\OneStepSearch
C:\Program Files\OneStepSearch\onestep.dll
C:\WINDOWS\system32\AppCert
C:\WINDOWS\system32\AppCert\filter.drv
C:\WINDOWS\system32\AppCert\options.dat
C:\WINDOWS\system32\AppCert\prx93f.dll
C:\WINDOWS\system32\AppCert\prx93f_.dll
C:\WINDOWS\system32\AppCert\wnl32.dll
C:\WINDOWS\system32\AppCert\wsil32.dll
.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-31 )))))))))))))))))))))))))))))))
.
2008-01-29 19:15 . 2008-01-29 19:15 <DIR> d-------- C:\Program Files\CCleaner
2008-01-28 15:52 . 2004-08-03 23:00 260,272 --a------ C:\cmldr
2008-01-28 15:52 . 2008-01-16 00:58 201 --a------ C:\Boot.bak
2008-01-21 20:33 . 2008-01-21 20:54 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-21 16:09 . 2008-01-21 16:09 <DIR> d-------- C:\Documents and Settings\TIMOTHY COUTURE\Application Data\WinPatrol
2008-01-21 16:07 . 2008-01-21 16:07 <DIR> d-------- C:\Program Files\BillP Studios
2008-01-21 16:04 . 2007-01-18 06:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-01-19 14:19 . 2008-01-19 14:19 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-19 09:22 . 2008-01-19 09:22 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-01-19 09:21 . 2008-01-19 09:21 <DIR> d-------- C:\KAV
2008-01-16 21:18 . 2008-01-16 22:29 <DIR> d-------- C:\Program Files\a-squared Anti-Malware
2008-01-15 22:33 . 2008-01-15 22:36 <DIR> d-------- C:\Documents and Settings\TIMOTHY COUTURE\Application Data\AdwareAlert
2008-01-15 21:02 . 2008-01-15 21:02 <DIR> d-------- C:\Program Files\IObit
2008-01-15 20:53 . 2003-04-24 14:37 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-01-15 20:53 . 2003-04-24 14:39 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\VERITAS
2008-01-14 19:49 . 2002-12-29 01:14 81,920 --a------ C:\WINDOWS\system32\Startup.cpl
2008-01-14 16:24 . 2007-12-04 06:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-01-14 16:24 . 2007-12-04 08:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-01-14 16:24 . 2007-12-04 08:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-01-14 16:24 . 2007-12-04 08:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-01-14 16:24 . 2007-12-04 08:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-01-14 16:24 . 2007-12-04 08:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-01-14 16:23 . 2007-12-04 07:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-01-14 16:23 . 2004-01-09 04:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-01-14 16:22 . 2008-01-14 16:22 <DIR> d-------- C:\Program Files\Alwil Software
2008-01-14 16:11 . 2008-01-14 16:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-14 16:07 . 2008-01-14 16:07 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-14 16:07 . 2008-01-14 16:07 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-14 16:07 . 2008-01-14 16:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-14 15:54 . 2008-01-21 15:53 <DIR> d-------- C:\Program Files\RegScrubXP
2008-01-14 15:12 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-01-14 15:12 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\dllcache\mouhid.sys
2008-01-14 15:11 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-01-14 15:11 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\system32\dllcache\hidusb.sys
2007-12-26 04:49 . 2008-01-14 15:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2007-12-26 04:36 . 2008-01-14 15:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2007-12-14 02:19 . 2008-01-21 20:16 <DIR> d-------- C:\Program Files\Google
2007-12-14 02:18 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-14 01:29 . 2007-10-10 17:55 6,065,664 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-14 01:29 . 2007-06-30 21:31 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-14 01:29 . 2007-06-30 21:36 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-14 01:29 . 2007-10-10 17:55 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-14 01:29 . 2007-10-10 17:55 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-14 01:29 . 2007-10-10 17:55 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-14 01:29 . 2007-10-10 17:55 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2007-12-14 01:29 . 2007-10-10 17:55 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-14 01:29 . 2007-10-10 04:59 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-14 01:21 . 2007-08-13 18:54 33,792 --a------ C:\WINDOWS\system32\dllcache\custsat.dll
2007-12-11 21:27 . 2007-12-11 21:27 1,188,375 --a------ C:\WINDOWS\system32\libeay32.dll
2007-12-11 21:27 . 2007-12-11 21:27 741,632 --a------ C:\WINDOWS\system32\bcghkqkb.dat
2007-12-11 21:27 . 2007-12-11 21:27 246,545 --a------ C:\WINDOWS\system32\libssl32.dll
2007-12-11 21:27 . 2007-12-18 22:21 42,240 --a------ C:\WINDOWS\system32\ixbtddbe.dat
2007-12-11 21:27 . 2008-01-14 09:24 36,608 --a------ C:\WINDOWS\system32\hvkacjll.dat
2007-12-11 21:27 . 2007-12-11 21:27 35,072 --a------ C:\WINDOWS\system32\dfentqsr.dat
2007-12-11 09:58 . 2007-12-11 09:58 <DIR> d-------- C:\WINDOWS\Sun
2007-12-11 09:50 . 2007-12-14 02:18 <DIR> d-------- C:\Program Files\Java
2007-12-11 09:49 . 2007-12-11 09:49 <DIR> d-------- C:\Program Files\Common Files\Java
2007-12-06 20:21 . 2007-12-25 22:59 120,576 --a------ C:\WINDOWS\system32\hvnzahqj.dat
2007-12-06 20:14 . 2006-12-12 10:32 16,384 --a------ C:\WINDOWS\system32\wifu.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-16 02:53 360,064 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-01-16 02:53 360,064 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-01-15 03:42 --------- d-----w C:\Program Files\Beston
2008-01-15 01:48 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-01-15 01:47 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-14 21:46 --------- d-----w C:\Program Files\Pure Networks
2008-01-14 21:46 --------- d-----w C:\Program Files\Common Files\AOL
2008-01-14 21:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-14 21:38 --------- d-----w C:\Program Files\Yahoo!
2008-01-14 21:36 --------- d-----w C:\Program Files\Common Files\Real
2008-01-14 21:27 --------- d-----w C:\Documents and Settings\TIMOTHY COUTURE\Application Data\AOL
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ------w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-31 19:03 245,408 ----a-w C:\WINDOWS\system32\unicows.dll
2007-10-31 11:12 3,590,656 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 23:39 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 23:39 230,912 ------w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-27 23:37 2,109,440 ------w C:\WINDOWS\system32\dllcache\wmvcore.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-11 06:13 474,112 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-10-11 06:13 151,040 ------w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-10-11 06:13 1,494,528 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-10-11 06:13 1,054,208 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
2007-10-11 06:13 1,023,488 ------w C:\WINDOWS\system32\dllcache\browseui.dll
2007-10-10 23:56 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-10-10 23:56 824,832 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-10 23:56 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-10-10 23:56 1,159,680 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-10 23:55 671,232 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-10 23:55 478,208 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-10 23:55 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-10-10 23:55 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-10-10 23:55 27,648 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-10 23:55 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-10-10 23:55 214,528 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-10 23:55 193,024 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-10 23:55 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-10-10 23:55 132,608 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-10 23:55 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
2007-10-10 23:55 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-10-10 23:55 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-10-10 10:59 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-10-10 10:59 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-10-10 05:46 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2004-04-28 19:12 0 -c-ha-w C:\Documents and Settings\TIMOTHY COUTURE\hpothb07.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-01-24 01:17 155648]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\Smtray.exe" [2002-06-26 17:36 90112]
"Tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [2001-11-07 04:50 1519616]
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [2002-06-18 02:01 155648]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2002-08-19 04:50 106551]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 07:00 79224]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-10-26 10:06 292152]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
hp psc 1000 series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 01:17:18 147456]
hpoddt01.exe.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 01:06:58 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)
S2 NMSSvc;Intel(R) NMS;C:\WINDOWS\System32\NMSSvc.exe [2002-05-03 13:36]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\System32\svchost.exe [2004-08-04 01:56]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\System32\svchost.exe [2004-08-04 01:56]
S3 p2psvc;Peer Networking;C:\WINDOWS\System32\svchost.exe [2004-08-04 01:56]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\System32\svchost.exe [2004-08-04 01:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
"2008-01-21 09:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.exe
- C:\Program Files\AdwareAlert
"2004-07-05 01:01:56 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1081042733.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-30 18:00:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
.
**************************************************************************
.
Completion time: 2008-01-30 18:04:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-31 00:03:58
ComboFix2.txt 2008-01-29 22:04:13
.
2008-01-15 03:41:07 --- E O F ---