Scotty, found a workable combofix download, here is resultant log with cfscript.txt, will post a new hijack log next. Renee6
ComboFix 07-11-08.3 - Renee Loiselle 2007-11-18 21:22:29.5 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Renee Loiselle\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Qekbrqbk
C:\Program Files\Qekbrqbk\bsxlgesz.dll
C:\Program Files\rizmxabe
C:\Program Files\rizmxabe\nixizuhe.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_UNPR
——-\UNPR
((((((((((((((((((((((((( Files Created from 2007-10-19 to 2007-11-19 )))))))))))))))))))))))))))))))
.
2007-11-16 09:52 58,368 –a—— C:\WINDOWS\NirCmd.exe
2007-11-16 09:26 81,984 –a—— C:\WINDOWS\system32\mcsvjxhj.dll
2007-11-16 09:23 85,056 –a—— C:\WINDOWS\system32\agxdvnma.dll
2007-11-16 08:54 d——– C:\WINDOWS\ERUNT
2007-11-15 19:31 3,094 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-15 09:12 79,936 –a—— C:\WINDOWS\system32\tjckgrif.dll
2007-11-15 09:09 85,056 –a—— C:\WINDOWS\system32\lthcwgnv.dll
2007-11-14 09:10 79,424 –a—— C:\WINDOWS\system32\jeoeoubq.dll
2007-11-14 09:07 85,056 –a—— C:\WINDOWS\system32\lxpnamqn.dll
2007-11-14 03:00 d——– C:\c57117a9cd66be78a498213d1341
2007-11-13 21:34 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-13 18:31 d——– C:\Documents and Settings\Renee Loiselle\Application Data\AdwareAlert
2007-11-13 18:25 20,480 ——— C:\Program Files\xloader10181.exe
2007-11-13 18:16 36,352 –a—— C:\WINDOWS\system32\jkkjjgh.dll
2007-11-13 11:24 d——– C:\Program Files\Comodo
2007-11-13 11:24 242,688 –a—— C:\WINDOWS\UNBOC.EXE
2007-11-13 11:24 208,896 –a—— C:\WINDOWS\CMDLIC.DLL
2007-11-13 09:16 80,448 –a—— C:\WINDOWS\system32\ptrrqqfs.dll
2007-11-13 09:13 88,128 –a—— C:\WINDOWS\system32\baqjfpcm.dll
2007-11-13 09:10 144,480 –a—— C:\WINDOWS\system32\vmdbpxrg.dll
2007-11-13 04:24 31,622 –a—— C:\WINDOWS\system32\ifvnptyk.exe
2007-11-12 22:48 d——– C:\Program Files\Virtual Earth 3D
2007-11-12 09:12 81,472 –a—— C:\WINDOWS\system32\tctisssh.dll
2007-11-11 20:26 d——– C:\e16f3d14460a32527faa
2007-11-11 09:06 79,936 –a—— C:\WINDOWS\system32\mwvhqyqr.dll
2007-11-11 04:10 2,432 –a—— C:\WINDOWS\system32\unpr.sys
2007-11-10 19:04 285,184 –a—— C:\WINDOWS\system32\LexBceS.exe
2007-11-10 19:04 201,728 –a—— C:\WINDOWS\system32\Lexp2p32.dll
2007-11-10 19:04 190,976 –a—— C:\WINDOWS\system32\lexlmpm.dll
2007-11-10 19:04 176,128 –a—— C:\WINDOWS\system32\Lexpps.exe
2007-11-10 19:04 175,104 –a—— C:\WINDOWS\system32\lex2kusb.dll
2007-11-10 19:04 135,168 –a—— C:\WINDOWS\system32\LexBce.dll
2007-11-10 19:04 79,872 –a—— C:\WINDOWS\system32\lex_psu.exe
2007-11-10 19:04 55,808 –a—— C:\WINDOWS\system32\Lexunst1.exe
2007-11-10 19:04 41,472 –a—— C:\WINDOWS\system32\ldeei.dll
2007-11-10 09:09 81,472 –a—— C:\WINDOWS\system32\ucvimryo.dll
2007-11-09 09:14 77,888 –a—— C:\WINDOWS\system32\mhynwqpc.dll
2007-11-09 09:11 88,128 –a—— C:\WINDOWS\system32\sxnonqay.dll
2007-11-08 09:08 86,080 –a—— C:\WINDOWS\system32\lodvpcac.dll
2007-11-07 09:11 79,936 –a—— C:\WINDOWS\system32\xqhcupsp.dll
2007-11-07 09:08 86,080 –a—— C:\WINDOWS\system32\fabmydeg.dll
2007-11-05 22:42 1,430,048 –a—— C:\WINDOWS\system32\AutoPartNt.exe
2007-11-05 22:36 d——– C:\Documents and Settings\All Users\Application Data\Seagate
2007-11-02 11:00 d——– C:\WINDOWS\SHELLNEW
2007-11-02 10:45 452,096 –a—— C:\WINDOWS\system32\fxsapi.dll
2007-11-02 10:45 452,096 –a–c— C:\WINDOWS\system32\dllcache\fxsapi.dll
2007-10-27 12:15 d——– C:\Program Files\Common Files\Wise Installation Wizard
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-15 20:31 ——— d—–w C:\Program Files\Linksys EasyLink Advisor
2007-11-10 22:04 ——— d—–w C:\Program Files\Windows Media Connect 2
2007-11-07 04:18 ——— d—–w C:\Documents and Settings\All Users\Application Data\WinZip
2007-10-07 01:54 392,320 —-a-w C:\WINDOWS\system32\drivers\timntr.sys
2007-10-07 01:54 32,768 —-a-w C:\WINDOWS\system32\drivers\tifsfilt.sys
2007-10-07 01:54 120,992 —-a-w C:\WINDOWS\system32\drivers\snapman.sys
2007-10-07 01:54 ——— d—–w C:\Program Files\Common Files\Seagate
2007-10-07 01:53 ——— d—–w C:\Program Files\Seagate
2007-10-01 03:35 ——— d—–w C:\Program Files\BMCentral
2007-10-01 02:48 9,728 —-a-w C:\WINDOWS\_MSRSTRT.EXE
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2001-07-12 12:09 61,440 -c–a-w C:\WINDOWS\inf\i386\onetUSD.dll
2001-06-05 12:11 32,768 -c–a-w C:\WINDOWS\inf\i386\Wiamicro.dll
2001-05-14 14:19 51,984 -c–a-w C:\WINDOWS\inf\i386\Wiafbdrv.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\c57117a9cd66be78a498213d1341 —-
2007-11-14 03:00 788 –ah—– C:\c57117a9cd66be78a498213d1341\$shtdwn$.req
2007-11-02 00:19 801152 –a—— C:\c57117a9cd66be78a498213d1341\mrt.exe._p
2007-11-02 00:12 95864 –a—— C:\c57117a9cd66be78a498213d1341\mrtstub.exe
—- Directory of C:\e16f3d14460a32527faa —-
2007-09-27 22:19 95864 –a—— C:\e16f3d14460a32527faa\mrtstub.exe
2007-09-27 22:19 18089592 –a—— C:\e16f3d14460a32527faa\mrt.exe
((((((((((((((((((((((((((((( snapshot@2007-11-18_21.03.35.84 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-03-13 15:57:10 174,080 —-a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2007-11-17 02:37:48 16,384 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-11-19 02:26:29 16,384 -c–a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-11-17 02:37:48 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-11-19 02:26:29 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-11-17 02:37:48 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-11-19 02:26:29 32,768 -c–a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 12:03]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 07:50]
"HostManager"="C:\Program Files\Common Files\AOL\1152415670\ee\AOLSoftware.exe" [2007-04-12 16:23]
"Motive SmartBridge"="C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe" [2006-07-08 23:13]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-07-08 22:30]
"OneTouch Monitor"="C:\PROGRA~1\VISION~1\ONETOU~2.EXE" [2001-07-12 07:08]
"DiscWizardMonitor.exe"="C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2007-04-19 21:24]
"AcronisTimounterMonitor"="C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe" [2007-04-19 21:38]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe" [2007-04-19 21:29]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe" [2000-03-08 12:09]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PPWebCap"="C:\PROGRA~1\ScanSoft\PAPERP~1\PPWebCap.exe" [2000-09-06 11:14]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-15 17:16]
"AdwareAlert"="C:\Program Files\AdwareAlert\AdwareAlert.exe" []
"AOL Fast Start"="C:\Program Files\AOL 9.0\AOL.exe" [2007-04-18 01:49]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2003-12-13 14:28:04]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-08-03 11:10:00]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 nwprovau relog_ap
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Broadband Support Center.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Broadband Support Center.lnk
backup=C:\WINDOWS\pss\Broadband Support Center.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EmailScan]
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]
C:\Program Files\mcafee.com\antivirus\oasclnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sscRun]
C:\Program Files\Common Files\AOL\1152415670\ee\services\sscFirewallPlugin\ver1_205_1_1\SSCRun.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"aolavupd"=2 (0x2)
"AOL TopSpeedMonitor"=2 (0x2)
"AOL ACS"=2 (0x2)
"TermService"=3 (0x3)
"TapiSrv"=3 (0x3)
"SCardSvr"=3 (0x3)
"SCardDrv"=3 (0x3)
R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys
R2 elagopro;GoProto Protocol Driver for LELA;C:\WINDOWS\system32\DRIVERS\elagopro.sys
R2 elaunidr;UniDriver for LELA;C:\WINDOWS\system32\DRIVERS\elaunidr.sys
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
S3 BOCDRIVE;BOClean Kernel Monitor.;\??\C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-18 08:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-18 21:27:43
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-18 21:29:47 - machine was rebooted
C:\ComboFix2.txt … 2007-11-18 21:04
C:\ComboFix3.txt … 2007-11-16 21:32
.
— E O F —