ok i ran combofix then malwarebytes then hijack this again
ComboFix 09-03-02.03 - Jeremy 2009-03-03 21:31:27.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.210 [GMT -6:00]
Running from: c:\documents and settings\Jeremy\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Daniel McKee\Cookies\hpothb07.dat
c:\documents and settings\Daniel McKee\Cookies\hpothb07.tif
c:\documents and settings\LocalService.NT AUTHORITY\Application Data\NetMon
c:\documents and settings\LocalService.NT AUTHORITY\Application Data\NetMon\domains.txt
c:\documents and settings\LocalService.NT AUTHORITY\Application Data\NetMon\log.txt
c:\program files\Common Files\download
c:\program files\Common Files\inetget
c:\program files\Common Files\vcclient
c:\program files\Common Files\vcclient\ClientUpdater.bat
c:\program files\Common Files\vcclient\ICSharpCode.SharpZipLib.dll
c:\program files\Common Files\vcclient\temp.txt
c:\program files\Common Files\vcclient\VCClient.exe.config
c:\program files\Common Files\vcclient\VCUpdate.exe.config
c:\program files\Common Files\vcclient\Version.txt
c:\program files\Common Files\windows
c:\program files\Common Files\windows\AutoIt3.exe
c:\program files\Common Files\windows\autoitscript.au3
c:\program files\Common Files\windows\psapi.dll
c:\program files\inetget2
c:\program files\INSTALL.LOG
c:\program files\network monitor
c:\program files\whInstall
c:\program files\whInstall\license.txt
c:\program files\whInstall\readme.txt
c:\program files\whInstall\Sporder.dll
c:\program files\whInstall\whAgent.inf
c:\program files\whInstall\whAgent.ini
c:\program files\whInstall\whInstaller.ini
c:\windows\RGFuaWVsIE1jS2Vl\
c:\windows\RGFuaWVsIE1jS2Vl\\l3IRuqpPKHY3mZp5.vbs
c:\windows\system32\atmtd.dll
c:\windows\system32\atmtd.dll._
c:\windows\system32\azbxnz.dll
c:\windows\system32\eieugq.dll
c:\windows\system32\eraseme_14486.exe
c:\windows\system32\eraseme_72331.exe
c:\windows\system32\eyomehut.ini
c:\windows\system32\fogarese.dll
c:\windows\System32\gijeluhe.dll
c:\windows\system32\imkcwy.dll
c:\windows\system32\muhenali.dll
c:\windows\system32\nomuyalo.dll
c:\windows\system32\patayaru.dll
c:\windows\system32\poyiyele.dll
c:\windows\system32\sesukaje.dll
c:\windows\system32\tsuninst.exe
c:\windows\system32\tuhemoye.dll
c:\windows\system32\urayatap.ini
c:\windows\system32\volosejo.dll
c:\windows\system32\zilabivi.dll
c:\windows\uninstall_nmon.vbs
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
-------\Legacy_LSASS
-------\Legacy_MICROSOFT_MEDIA_TOOLS
-------\Legacy_NETWORK_MONITOR
-------\Legacy_RDRIV
-------\Legacy_SYSMGR64
-------\Service_cmdService
-------\Service_lsass
-------\Service_MicroSoft Media Tools
-------\Service_Network Monitor
-------\Service_rdriv
-------\Service_sysmgr64
((((((((((((((((((((((((( Files Created from 2009-02-04 to 2009-03-04 )))))))))))))))))))))))))))))))
.
2009-03-03 20:50 . 2008-04-14 05:42 218,624 --a------ c:\windows\SYSTEM32\uxtheme.uxtender
2009-03-03 20:50 . 2009-03-03 20:50 218,624 --a------ C:\uxtheme.uxtender
2009-03-03 20:30 . 2009-03-02 17:52 211 -rahs---- C:\BOOT.BKK
2009-03-03 02:50 . 2009-03-03 02:51 <DIR> d-------- c:\program files\Opera
2009-03-03 02:19 . 2009-03-03 07:52 <DIR> d-------- c:\program files\Mozilla Firefox 3.1 Beta 2
2009-03-02 20:52 . 2009-03-02 20:59 <DIR> d-------- C:\VIRUS
2009-03-02 20:35 . 2009-03-03 12:16 <DIR> d-------- C:\!KillBox
2009-03-02 20:29 . 2009-03-02 20:29 <DIR> d-------- c:\program files\Trend Micro
2009-03-02 18:49 . 2009-03-03 21:05 <DIR> d--h----- C:\$AVG8.VAULT$
2009-03-02 18:45 . 2009-03-02 18:45 <DIR> d-------- c:\documents and settings\Jeremy\Application Data\AVGTOOLBAR
2009-03-02 18:24 . 2009-03-02 18:24 325,128 --a------ c:\windows\SYSTEM32\DRIVERS\avgldx86.sys
2009-03-02 18:24 . 2009-03-02 18:24 107,272 --a------ c:\windows\SYSTEM32\DRIVERS\avgtdix.sys
2009-03-02 18:24 . 2009-03-02 18:24 10,520 --a------ c:\windows\SYSTEM32\avgrsstx.dll
2009-03-02 18:23 . 2009-03-03 19:16 <DIR> d-------- c:\windows\SYSTEM32\DRIVERS\Avg
2009-03-02 18:23 . 2009-03-02 18:23 <DIR> d-------- c:\program files\AVG
2009-03-02 18:23 . 2009-03-03 02:13 <DIR> d-------- c:\documents and settings\DANIEL MCKEE.DANIEL-T2P49JHI\Application Data\AVGTOOLBAR
2009-03-02 18:23 . 2009-03-03 21:37 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\avg8
2009-03-02 17:56 . 2009-03-02 17:57 6,503 --a------ c:\windows\SYSTEM32\spupdsvc.inf
2009-03-02 17:46 . 2009-03-02 17:46 <DIR> d-------- c:\windows\SYSTEM32\scripting
2009-03-02 17:40 . 2009-03-02 17:47 <DIR> d-------- c:\windows\ServicePackFiles
2009-03-02 17:38 . 2008-04-14 05:42 123,392 --------- c:\windows\SYSTEM32\mplay32.exe
2009-03-02 17:32 . 2006-12-29 00:31 19,569 --a------ c:\windows\
002460_.tmp
2009-03-02 17:31 . 2007-08-10 20:46 26,488 --a------ c:\windows\SYSTEM32\spupdsvc.exe
2009-03-02 17:25 . 2009-03-02 17:25 <DIR> d-------- c:\windows\EHome
2009-03-02 16:28 . 2009-03-02 16:28 <DIR> d---s---- c:\documents and settings\Jeremy\UserData
2009-03-02 09:24 . 2002-08-29 05:00 138,752 --a------ c:\windows\SNDVOL32.EXE
2009-02-28 20:11 . 2009-03-02 15:16 1,773 --a------ c:\windows\checkip.dat
2009-02-26 04:46 . 2009-02-26 04:46 32 --a------ c:\windows\basefx.INI
2009-02-26 04:31 . 2009-02-26 04:31 <DIR> d-------- c:\documents and settings\Jeremy\Application Data\Jasc
2009-02-26 04:11 . 2009-02-26 04:11 <DIR> d-------- c:\documents and settings\Jeremy\Application Data\Apple Computer
2009-02-26 04:04 . 2009-02-26 04:04 <DIR> d-------- c:\documents and settings\Jeremy\Application Data\Sonic
2009-02-26 04:03 . 2009-03-02 18:24 <DIR> d-------- c:\documents and settings\Jeremy
2009-02-25 21:55 . 2009-02-25 21:55 <DIR> d-------- c:\documents and settings\DANIEL MCKEE.DANIEL-T2P49JHI\Application Data\Jasc
2009-02-25 21:53 . 2009-02-25 21:53 21,840 --a------ c:\windows\SYSTEM32\SIntfNT.dll
2009-02-25 21:53 . 2009-02-25 21:53 17,212 --a------ c:\windows\SYSTEM32\SIntf32.dll
2009-02-25 21:53 . 2009-02-25 21:53 12,067 --a------ c:\windows\SYSTEM32\SIntf16.dll
2009-02-25 20:07 . 2009-02-25 20:07 <DIR> d-------- c:\documents and settings\DANIEL MCKEE.DANIEL-T2P49JHI\Application Data\Learn2.com
2009-02-25 14:41 . 2008-04-14 00:15 10,624 --a------ c:\windows\SYSTEM32\DRIVERS\gameenum.sys
2009-02-24 18:47 . 2009-02-25 21:13 <DIR> d-a------ c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-02-24 18:47 . 2007-06-19 22:35 24,096 --a------ c:\windows\SYSTEM32\DRIVERS\ts_lb.sys
2009-02-24 13:54 . 2009-02-24 13:54 444 --a------ c:\windows\SYSTEM32\d3d8caps.dat
2009-02-24 09:23 . 2009-02-24 09:23 0 --a------ c:\windows\nsreg.dat
2009-02-24 09:14 . 2002-08-28 22:59 36,224 --a------ c:\windows\SYSTEM32\DRIVERS\an983.sys
2009-02-24 09:14 . 2002-08-28 22:59 36,224 --a--c--- c:\windows\SYSTEM32\DLLCACHE\an983.sys
2009-02-24 08:23 . 2009-02-25 16:41 <DIR> d-------- c:\program files\iTunes
2009-02-24 08:23 . 2009-02-24 08:23 <DIR> d-------- c:\program files\iPod
2009-02-24 08:23 . 2009-02-24 14:05 <DIR> d-------- c:\documents and settings\DANIEL MCKEE.DANIEL-T2P49JHI\Application Data\Apple Computer
2009-02-24 08:20 . 2009-02-24 08:21 <DIR> d-------- c:\program files\Apple Software Update
2009-02-24 08:20 . 2009-02-24 08:23 <DIR> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-03-02 15:11 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-26 09:22 --------- d-----w c:\program files\My Organizer
2009-02-26 06:59 --------- d-----w c:\documents and settings\DANIEL MCKEE.DANIEL-T2P49JHI\Application Data\MSN6
2009-02-24 14:22 --------- d-----w c:\program files\QuickTime
2004-11-20 16:38 554 -c-ha-w c:\documents and settings\Daniel McKee\Application Data\hpothb07.dat
2004-11-20 16:38 353 -c-ha-w c:\documents and settings\Daniel McKee\hpothb07.dat
2004-11-20 16:38 164 -c-ha-w c:\documents and settings\All Users\hpothb07.dat
2004-07-16 02:23 255 -c-ha-w c:\program files\hpothb07.tif
2004-07-16 02:23 146 -c-ha-w c:\program files\hpothb07.dat
2004-07-16 02:23 0 -c-ha-w c:\documents and settings\NetworkService\hpothb07.dat
2004-07-16 02:23 0 -c-ha-w c:\documents and settings\LocalService\hpothb07.dat
2004-07-16 02:23 0 -c-ha-w c:\documents and settings\Default User\hpothb07.dat
2002-08-29 11:00 339,968 ----a-w c:\program files\MSPAINT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"CapFax"="c:\program files\Classic PhoneTools\CapFax.EXE" [2001-12-10 20739]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2002-06-19 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2002-06-19 114688]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2005-07-16 7110656]
"NvMediaCenter"="c:\windows\System32\NvMcTray. dll" [2005-07-16 86016]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2003-02-05 143360]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-24 282624]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-09-25 229952]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-02 1601304]
c:\documents and settings\Daniel McKee\Start Menu\Programs\Startup\
PowerReg Scheduler.exe [2003-06-07 256000]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2003-03-03 45056]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-02 18:24 10520 c:\windows\SYSTEM32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"= ctwdm32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [2009-03-02 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [2009-03-02 107272]
R1 ts_lb;ts_lb;c:\windows\SYSTEM32\DRIVERS\ts_lb.sys [2009-02-24 24096]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-02 298264]
R2 spupdsvc;Windows Service Pack Installer update service;c:\windows\SYSTEM32\spupdsvc.exe [2009-03-02 26488]
S2 CQUBVYLR;CQUBVYLR;\??\c:\windows\System32\cqubvylr .zgj --> c:\windows\System32\cqubvylr.zgj [?]
S2 Ndiskio;Ndiskio;\??\c:\norman\Nse\bin\NDISKIO.SYS --> c:\norman\Nse\bin\NDISKIO.SYS [?]
S2 Shell32Extender;Microsoft Windows Explorer Shell Subsystem;"c:\windows\system32\shell32.exe" --> c:\windows\system32\shell32.exe [?]
S3 CV2K1;CommView Network Monitor;c:\windows\SYSTEM32\DRIVERS\cv2k1.sys [2008-02-22 19240]
S3 nvcfsr;nvcfsr;\??\c:\norman\Nvc\bin\nvcfsr.sys --> c:\norman\Nvc\bin\nvcfsr.sys [?]
S3 nvcoafl51;nvcoafl51;\??\c:\norman\Nvc\bin\nvcoafl5 1.sys --> c:\norman\Nvc\bin\nvcoafl51.sys [?]
S3 nvcoaft51;nvcoaft51;\??\c:\norman\Nvc\bin\nvcoaft5 1.sys --> c:\norman\Nvc\bin\nvcoaft51.sys [?]
S3 nvcoarc51;nvcoarc51;\??\c:\norman\Nvc\bin\nvcoarc5 1.sys --> c:\norman\Nvc\bin\nvcoarc51.sys [?]
S3 nvcoas;Norman Virus Control on-access component;c:\norman\Nvc\bin\nvcoas.exe --> c:\norman\Nvc\bin\nvcoas.exe [?]
S3 NVCScheduler;Norman Virus Control Scheduler;c:\norman\Nvc\BIN\NVCSCHED.EXE --> c:\norman\Nvc\BIN\NVCSCHED.EXE [?]
S3 PsSdk30;PsSdk30;\??\c:\windows\System32\Drivers\Ps Sdk30.drv --> c:\windows\System32\Drivers\PsSdk30.drv [?]
S4 mcafeeWALLP;mcafeeWALLP;"c:\windows\mcafeeWALLX.ex e" --> c:\windows\mcafeeWALLX.exe [?]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\SetupWizard.exe
.
Contents of the 'Scheduled Tasks' folder
2009-03-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-09-19 17:36]
.
- - - - ORPHANS REMOVED - - - -
BHO-{d0a231a8-d82a-4751-9bfd-9501ff8b3d62} - c:\windows\System32\yipiwopa.dll
HKLM-Run-fumobigavu - c:\windows\System32\bokiluve.dll
.
------- Supplementary Scan -------
.
Trusted Zone: mirarsearch.com\click
Trusted Zone: mirarsearch.com\redirect
FF - ProfilePath - c:\documents and settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\ig66ysgi.default\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter ", false);
.
************************************************** ************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-03 21:40:45
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\C QUBVYLR]
"ImagePath"="\??\c:\windows\System32\cqubvylr. zgj"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\P sSdk30]
"ImagePath"="\??\c:\windows\System32\Drivers\PsSdk 30.drv"
.
------------------------ Other Running Processes ------------------------
.
c:\windows\SYSTEM32\spnpinst.exe
c:\windows\SYSTEM32\sysocmgr.exe
c:\windows\SYSTEM32\devldr32.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
.
************************************************** ************************
.
Completion time: 2009-03-03 21:44:26 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-04 03:44:20
Pre-Run: 11,812,872,192 bytes free
Post-Run: 12,046,061,568 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOW S
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Micro soft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
253