combofix log
none of those websites work that you giving me
ComboFix 08-08-21.02 -keaton77 2008-08-23 10:59:05.3 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.66 [GMT -8:00]
Running from: C:\Documents and Settings\keaton77\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\keaton77\Application Data\macromedia\Flash Player\#SharedObjects\FL6QBNRZ\interclick.com
C:\Documents and Settings\keaton77\Application Data\macromedia\Flash Player\#SharedObjects\FL6QBNRZ\interclick.com\ud.sol
C:\Documents and Settings\keaton77\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\keaton77\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\WINDOWS\system32\dynmkuoj.dll
C:\WINDOWS\system32\gtemxe.dll
C:\WINDOWS\system32\jakxrglu.ini
C:\WINDOWS\system32\ulgrxkaj.dll
C:\WINDOWS\system32\VxbaJkkj.ini
C:\WINDOWS\system32\VxbaJkkj.ini2
.
---- Previous Run -------
.
C:\WINDOWS\system32\fmjdoveu.dll
C:\WINDOWS\system32\lvwbnb.dll
C:\WINDOWS\system32\qhoseeiw.dll
C:\WINDOWS\system32\uevodjmf.ini
C:\WINDOWS\system32\VxbaJkkj.ini
C:\WINDOWS\system32\VxbaJkkj.ini2
.
((((((((((((((((((((((((( Files Created from 2008-07-23 to 2008-08-23 )))))))))))))))))))))))))))))))
.
2008-08-23 08:38 . 2008-08-23 08:45 220,176 --a------ C:\WINDOWS\system32\xxyywuRH.dll
2008-08-23 01:35 . 2008-08-23 01:35 323,328 --a------ C:\WINDOWS\system32\jkkJabxV.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-17 05:34 --------- d-----w C:\Documents and Settings\keaton77\Application Data\acccore
2008-07-15 06:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-15 06:31 --------- d-----w C:\Program Files\Trend Micro
2008-07-14 05:07 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-14 05:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-14 01:47 --------- d-----w C:\Program Files\Opera
2008-07-13 18:35 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-07-12 01:04 96,520 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-12 01:04 76,040 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-12 01:04 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\3C.tmp
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\3A.tmp
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\38.tmp
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\37.tmp
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\36.tmp
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\35.tmp
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\34.tmp
2008-07-01 18:35 94,208 ----a-w C:\WINDOWS\system32\2F.tmp
2008-07-01 08:46 94,208 ----a-w C:\WINDOWS\system32\33.tmp
2008-07-01 08:46 94,208 ----a-w C:\WINDOWS\system32\32.tmp
2008-07-01 08:46 94,208 ----a-w C:\WINDOWS\system32\31.tmp
2008-07-01 08:46 94,208 ----a-w C:\WINDOWS\system32\30.tmp
2008-07-01 08:46 94,208 ----a-w C:\WINDOWS\system32\2E.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\2D.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\2C.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\2B.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\2A.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\29.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\28.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\27.tmp
2008-07-01 08:45 94,208 ----a-w C:\WINDOWS\system32\26.tmp
2008-07-01 08:44 94,208 ----a-w C:\WINDOWS\system32\25.tmp
2008-07-01 08:44 94,208 ----a-w C:\WINDOWS\system32\23.tmp
2008-07-01 08:44 94,208 ----a-w C:\WINDOWS\system32\22.tmp
2008-07-01 08:44 94,208 ----a-w C:\WINDOWS\system32\21.tmp
2008-07-01 08:44 94,208 ----a-w C:\WINDOWS\system32\20.tmp
2008-07-01 08:15 94,208 ----a-w C:\WINDOWS\system32\7CA.tmp
2008-06-28 03:55 34,688 ------w C:\WINDOWS\system32\mlJDtrQI.dll
2008-06-28 02:26 --------- d-----w C:\Program Files\AIM6
2008-06-27 23:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\acccore
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-06 16:24 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-06-06 16:24 307,200 ------w C:\WINDOWS\Setup1.exe
2007-04-23 22:21 269,824 ----a-w C:\WINDOWS\inf\WG111v3\Vista64\wg111v3.sys
2007-04-23 22:11 224,896 ----a-w C:\WINDOWS\inf\WG111v3\wg111v3.sys
2006-12-15 19:30 98,304 ----a-w C:\WINDOWS\inf\WG111v3\UScanM.exe
2006-12-15 19:30 66,048 ----a-w C:\WINDOWS\inf\WG111v3\EAPPkt.sys
2006-12-15 19:30 315,392 ----a-w C:\WINDOWS\inf\WG111v3\InstallDriver.exe
2006-12-15 19:30 28,672 ----a-w C:\WINDOWS\inf\WG111v3\SetDrv.exe
2006-12-15 19:30 212,992 ----a-w C:\WINDOWS\inf\WG111v3\CopyWHQLDriver.exe
2006-12-15 19:30 20,480 ----a-w C:\WINDOWS\inf\WG111v3\RTWUPath.exe
2006-12-15 19:30 19,968 ----a-w C:\WINDOWS\inf\WG111v3\RTWREFU.EXE
.
------- Sigcheck -------
md5deep: C:\WINDOWS\system32\svchost.exe: error at offset 0: Permission denied
md5deep: C:\WINDOWS\system32\winlogon.exe: error at offset 0: Permission denied
md5deep: C:\WINDOWS\explorer.exe: error at offset 0: Permission denied
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_TEMP\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_SAVE\explorer.exe
2007-06-13 00:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2gdr\explorer.exe
2007-06-13 00:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2qfe\explorer.exe
2002-12-31 12:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
md5deep: C:\WINDOWS\system32\services.exe: error at offset 0: Permission denied
md5deep: C:\WINDOWS\system32\lsass.exe: error at offset 0: Permission denied
md5deep: C:\WINDOWS\system32\spoolsv.exe: error at offset 0: Permission denied
2005-06-10 17:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2002-12-31 13:00 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A596175D-BBC7-476A-A152-FBA652B64505}]
2008-06-27 19:55 34688 --------- C:\WINDOWS\system32\mlJDtrQI.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C9F706D6-B43A-4B64-AAD5-B37B1A749AFE}]
2008-08-23 01:35 323328 --a------ C:\WINDOWS\system32\jkkJabxV.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-06-19 09:51 50528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"One view global this"="C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW\Third Mapi.exe" [2008-08-23 11:54 21544448]
"AIMWDInstallFilename"="C:\Program Files\AIM\AIMWDInstall.exe" [2004-01-12 09:29 102400]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 21:59 115816]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 08:59 124520]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"643d5b23"="C:\WINDOWS\system32\ulgrxkaj.dll" [BU]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v3 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111v3\WG111v3.exe [2007-09-12 15:14:42 1527808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{A596175D-BBC7-476A-A152-FBA652B64505}"= "C:\WINDOWS\system32\mlJDtrQI.dll" [2008-06-27 19:55 34688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"mZUCnvnJwQdJ"= {643D5B8D-CE97-F127-8EAA-33AA7BB4B098} - C:\WINDOWS\system32\zgj.dll [2007-04-16 04:52 32768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlJDtrQI]
2008-06-27 19:55 34688 C:\WINDOWS\system32\mlJDtrQI.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=lvwbnb.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= jl_mjpg2.drv
"msacm.fraunhoferacm"= l3codecp.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Spybot - Search & Destroy\\SDShred.exe"=
"C:\\Program Files\\NETGEAR\\WG111v3\\WG111v3.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-11 17:04]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-11 17:04]
R3 ctlsb16;Creative SB16/AWE32/AWE64 Driver (WDM);C:\WINDOWS\system32\drivers\ctlsb16.sys [2004-12-24 11:15]
R3 es1969;ESS 1969 Audio Driver (WDM);C:\WINDOWS\system32\drivers\es1969.sys [2004-12-24 11:15]
R3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2004-12-24 11:15]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;C:\WINDOWS\system32\DRIVERS\wg111v3.sys [2007-04-23 14:11]
R3 S3SAVAGE4M;S3SAVAGE4M;C:\WINDOWS\system32\DRIVERS\s3sav4m.sys [2004-12-24 11:16]
S1 SABKUTIL;SABKUTIL;C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys []
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 09:05]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys []
S3 USRTI;U.S. Robotics Faxmodem Driver TI;C:\WINDOWS\system32\DRIVERS\USRTI.SYS [2004-12-24 11:16]
.
Contents of the 'Scheduled Tasks' folder
2008-07-03 C:\WINDOWS\Tasks\rpc.job
- C:\Program Files\Winferno\RegistryPowerCleaner\RegPowerClean.exe []
2008-08-23 C:\WINDOWS\Tasks\B8EEA5EA89AD5906.job
- c:\docume~1\keaton12\applic~1\defyop~1\that mode mags.exe []
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\keaton77\Application Data\Mozilla\Firefox\Profiles\c9zjcure.default\
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npunagi2.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava11.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava12.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava13.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava14.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjava32.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npjpi160_03.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\npoji610.dll
.
.
------- File Associations (Beta) -------
.
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-23 11:09:24
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\mlJDtrQI.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\jkkJabxV.dll
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSVCHST.EXE
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-08-23 11:22:29 - machine was rebooted [keaton77]
ComboFix-quarantined-files.txt 2008-08-23 19:21:50
ComboFix2.txt 2008-08-23 03:01:08
Pre-Run: 7,908,294,656 bytes free
Post-Run: 7,863,582,720 bytes free
228 --- E O F --- 2008-06-27 21:26:32