i try the cox reset but didnt do anything it comes right back and computer running good so far =]
ComboFix 08-08-21.02 - keaton77 2008-08-23 18:28:46.4 -
FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.127 [GMT -8:00]
Running from: C:\Documents and Settings\keaton77\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\keaton77\Desktop\cfscript.txt
* Created a new restore point
FILE ::
C:\WINDOWS\system32\20.tmp
C:\WINDOWS\system32\21.tmp
C:\WINDOWS\system32\22.tmp
C:\WINDOWS\system32\23.tmp
C:\WINDOWS\system32\25.tmp
C:\WINDOWS\system32\26.tmp
C:\WINDOWS\system32\27.tmp
C:\WINDOWS\system32\28.tmp
C:\WINDOWS\system32\29.tmp
C:\WINDOWS\system32\2A.tmp
C:\WINDOWS\system32\2B.tmp
C:\WINDOWS\system32\2C.tmp
C:\WINDOWS\system32\2D.tmp
C:\WINDOWS\system32\2E.tmp
C:\WINDOWS\system32\2F.tmp
C:\WINDOWS\system32\30.tmp
C:\WINDOWS\system32\31.tmp
C:\WINDOWS\system32\32.tmp
C:\WINDOWS\system32\33.tmp
C:\WINDOWS\system32\34.tmp
C:\WINDOWS\system32\35.tmp
C:\WINDOWS\system32\36.tmp
C:\WINDOWS\system32\37.tmp
C:\WINDOWS\system32\38.tmp
C:\WINDOWS\system32\3A.tmp
C:\WINDOWS\system32\3C.tmp
C:\WINDOWS\system32\7CA.tmp
C:\WINDOWS\system32\jkkJabxV.dll
C:\windows\system32\lvwbnb.dll
C:\WINDOWS\system32\mlJDtrQI.dll
C:\WINDOWS\system32\ulgrxkaj.dll
C:\WINDOWS\system32\xxyywuRH.dll
C:\WINDOWS\system32\zgj.dll
C:\WINDOWS\Tasks\B8EEA5EA89AD5906.job
C:\WINDOWS\Tasks\rpc.job
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW
C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW\face info.exe
C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW\the license.exe
C:\Documents and Settings\All Users\Application Data\MPEG ELSE ONE VIEW\Third Mapi.exe
C:\WINDOWS\system32\20.tmp
C:\WINDOWS\system32\21.tmp
C:\WINDOWS\system32\22.tmp
C:\WINDOWS\system32\23.tmp
C:\WINDOWS\system32\25.tmp
C:\WINDOWS\system32\26.tmp
C:\WINDOWS\system32\27.tmp
C:\WINDOWS\system32\28.tmp
C:\WINDOWS\system32\29.tmp
C:\WINDOWS\system32\2A.tmp
C:\WINDOWS\system32\2B.tmp
C:\WINDOWS\system32\2C.tmp
C:\WINDOWS\system32\2D.tmp
C:\WINDOWS\system32\2E.tmp
C:\WINDOWS\system32\2F.tmp
C:\WINDOWS\system32\30.tmp
C:\WINDOWS\system32\31.tmp
C:\WINDOWS\system32\32.tmp
C:\WINDOWS\system32\33.tmp
C:\WINDOWS\system32\34.tmp
C:\WINDOWS\system32\35.tmp
C:\WINDOWS\system32\36.tmp
C:\WINDOWS\system32\37.tmp
C:\WINDOWS\system32\38.tmp
C:\WINDOWS\system32\3A.tmp
C:\WINDOWS\system32\3C.tmp
C:\WINDOWS\system32\7CA.tmp
C:\WINDOWS\system32\dpkpvwkm.ini
C:\WINDOWS\system32\erludhrw.dll
C:\WINDOWS\system32\jkkJabxV.dll
C:\WINDOWS\system32\mkwvpkpd.dll
C:\WINDOWS\system32\mlJDtrQI.dll
C:\WINDOWS\system32\VxbaJkkj.ini
C:\WINDOWS\system32\VxbaJkkj.ini2
C:\WINDOWS\system32\xgfvop.dll
C:\WINDOWS\system32\xxyywuRH.dll
C:\WINDOWS\system32\zgj.dll
C:\WINDOWS\Tasks\B8EEA5EA89AD5906.job
C:\WINDOWS\Tasks\rpc.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SABKUTIL
-------\Service_SABKUTIL
((((((((((((((((((((((((( Files Created from 2008-07-24 to 2008-08-24 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-17 05:34 --------- d-----w C:\Documents and Settings\keaton77\Application Data\acccore
2008-07-15 06:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-15 06:31 --------- d-----w C:\Program Files\Trend Micro
2008-07-14 05:07 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-14 05:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-14 01:47 --------- d-----w C:\Program Files\Opera
2008-07-13 18:35 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-07-12 01:04 96,520 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-12 01:04 76,040 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-12 01:04 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-06-28 02:26 --------- d-----w C:\Program Files\AIM6
2008-06-27 23:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\acccore
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 245,248 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-06 16:24 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-06-06 16:24 307,200 ------w C:\WINDOWS\Setup1.exe
2007-04-23 22:21 269,824 ----a-w C:\WINDOWS\inf\WG111v3\Vista64\wg111v3.sys
2007-04-23 22:11 224,896 ----a-w C:\WINDOWS\inf\WG111v3\wg111v3.sys
2006-12-15 19:30 98,304 ----a-w C:\WINDOWS\inf\WG111v3\UScanM.exe
2006-12-15 19:30 66,048 ----a-w C:\WINDOWS\inf\WG111v3\EAPPkt.sys
2006-12-15 19:30 315,392 ----a-w C:\WINDOWS\inf\WG111v3\InstallDriver.exe
2006-12-15 19:30 28,672 ----a-w C:\WINDOWS\inf\WG111v3\SetDrv.exe
2006-12-15 19:30 212,992 ----a-w C:\WINDOWS\inf\WG111v3\CopyWHQLDriver.exe
2006-12-15 19:30 20,480 ----a-w C:\WINDOWS\inf\WG111v3\RTWUPath.exe
2006-12-15 19:30 19,968 ----a-w C:\WINDOWS\inf\WG111v3\RTWREFU.EXE
.
------- Sigcheck -------
2002-12-31 12:00 17408 c9a2fa38b23562f3bb2153b33c95ea8f C:\WINDOWS\system32\svchost.exe
2002-12-31 12:00 506368 e6ffe7a15b04504a8a34d5b950e23f0e C:\WINDOWS\system32\winlogon.exe
2007-06-12 23:23 1035776 19f69b94e52b8d83c6889791dcae304b C:\WINDOWS\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_TEMP\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\VCP_SAVE\explorer.exe
2007-06-13 00:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2007-06-12 23:23 1033216 97bd6515465659ff8f3b7be375b2ea87 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2gdr\explorer.exe
2007-06-13 00:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\SoftwareDistribution\Download\44d74c37f0595a363bcec5e9229d8564\sp2qfe\explorer.exe
2002-12-31 12:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2002-12-31 12:00 110592 cb7a2c2b70518545a022025a92e9a77f C:\WINDOWS\system32\services.exe
2002-12-31 12:00 14848 1a074603db3751a4e77492433afabfca C:\WINDOWS\system32\lsass.exe
2005-06-10 16:53 58880 5305ef86e1dfb4b733438607b74e04d9 C:\WINDOWS\system32\spoolsv.exe
2005-06-10 17:17 57856 ad3d9d191aea7b5445fe1d82ffbb4788 C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
2002-12-31 13:00 57856 7435b108b935e42ea92ca94f59c8e717 C:\WINDOWS\$NtUninstallKB896423$\spoolsv.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-06-19 09:51 50528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIMWDInstallFilename"="C:\Program Files\AIM\AIMWDInstall.exe" [2004-01-12 09:29 102400]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 21:59 115816]
"IPHSend"="C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 08:59 124520]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v3 Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111v3\WG111v3.exe [2007-09-12 15:14:42 1527808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= jl_mjpg2.drv
"msacm.fraunhoferacm"= l3codecp.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Spybot - Search & Destroy\\SDShred.exe"=
"C:\\Program Files\\NETGEAR\\WG111v3\\WG111v3.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-11 17:04]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-11 17:04]
R3 ctlsb16;Creative SB16/AWE32/AWE64 Driver (WDM);C:\WINDOWS\system32\drivers\ctlsb16.sys [2004-12-24 11:15]
R3 es1969;ESS 1969 Audio Driver (WDM);C:\WINDOWS\system32\drivers\es1969.sys [2004-12-24 11:15]
R3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2004-12-24 11:15]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;C:\WINDOWS\system32\DRIVERS\wg111v3.sys [2007-04-23 14:11]
R3 S3SAVAGE4M;S3SAVAGE4M;C:\WINDOWS\system32\DRIVERS\s3sav4m.sys [2004-12-24 11:16]
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 09:05]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;C:\WINDOWS\system32\drivers\ScreamingBAudio.sys []
S3 USRTI;U.S. Robotics Faxmodem Driver TI;C:\WINDOWS\system32\DRIVERS\USRTI.SYS [2004-12-24 11:16]
.
Contents of the 'Scheduled Tasks' folder
2008-08-24 C:\WINDOWS\Tasks\AC43817194383B35.job
- c:\docume~1\keaton20\applic~1\defyop~1\that mode mags.exe []
2008-07-13 C:\WINDOWS\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe []
2008-08-24 C:\WINDOWS\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe []
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-23 19:24:17
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSVCHST.EXE
C:\WINDOWS\SYSTEM32\MSDTC.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\AIM6\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2008-08-23 19:26:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-24 03:26:42
ComboFix3.txt 2008-08-23 03:01:08
ComboFix2.txt 2008-08-23 19:22:38
Pre-Run: 7,672,954,880 bytes free
Post-Run: 7,617,593,344 bytes free
220 --- E O F --- 2008-06-27 21:26:32