grr… i KNOW! but i do feel like my computer is so much better! the clock doesn't say VIRUS ALERT next to it anymore (though it's still in military time that i can't seem to get rid of), AND, i can access this site from my computer, which i hadn't been able to do. YAY!
below is my latest hijackthis log.
THANK YOU!
ComboFix 08-09-05.12 - Jessica 2008-09-09 19:46:45.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.581 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\a
C:\Documents and Settings\TEMP\Cookies\[removed][1].txt
C:\Documents and Settings\TEMP\Cookies\[removed][3].txt
C:\Documents and Settings\TEMP\Cookies\jessica@revsci[2].txt
C:\Program Files\SpyShredder
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.dll
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\sys1.exe
C:\WINDOWS\Sys6.exe
C:\WINDOWS\Sys7.exe
C:\WINDOWS\Sys8.exe
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\aukvarwt.ini
C:\WINDOWS\system32\awkvofgk.ini
C:\WINDOWS\system32\axuekq.dll
C:\WINDOWS\system32\bvheex.dll
C:\WINDOWS\system32\clbdll.dll
C:\WINDOWS\system32\clbinit.dll
C:\WINDOWS\system32\derxsl.dll
C:\WINDOWS\system32\dhkgmvyh.ini
C:\WINDOWS\system32\dnoeqkex.ini
C:\WINDOWS\system32\drivers\clbdriver.sys
C:\WINDOWS\system32\ewuadako.ini
C:\WINDOWS\system32\fqansrqx.dll
C:\WINDOWS\system32\gchegfsf.dll
C:\WINDOWS\system32\grriwpcw.ini
C:\WINDOWS\system32\hhrfiysu.ini
C:\WINDOWS\system32\ihkmp.bak1
C:\WINDOWS\system32\ihkmp.bak2
C:\WINDOWS\system32\jadshn.dll
C:\WINDOWS\system32\jpripmca.dll
C:\WINDOWS\system32\jqtmdhov.ini
C:\WINDOWS\system32\jrkdfm.dll
C:\WINDOWS\system32\kkmbkh.dll
C:\WINDOWS\system32\lanmandrv.sys
C:\WINDOWS\system32\lxncvj.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mfkkeqcj.dll
C:\WINDOWS\system32\mlJDwWPG.dll
C:\WINDOWS\system32\mrtxpatu.ini
C:\WINDOWS\system32\nfswlnmr.dll
C:\WINDOWS\system32\nhetjxuq.ini
C:\WINDOWS\system32\npAJPXbc.ini
C:\WINDOWS\system32\npAJPXbc.ini2
C:\WINDOWS\system32\npmrhgld.dll
C:\WINDOWS\system32\ofiqyfqt.ini
C:\WINDOWS\system32\pbpkaupj.dll
C:\WINDOWS\system32\pmkhi.dll
C:\WINDOWS\system32\qfkmrr.dll
C:\WINDOWS\system32\qqevhsjr.dll
C:\WINDOWS\system32\qyogcywo.ini
C:\WINDOWS\system32\rraibtoy.dll
C:\WINDOWS\system32\slktuebg.ini
C:\WINDOWS\system32\srhrui.dll
C:\WINDOWS\system32\tacyiofe.dll
C:\WINDOWS\system32\tjevlusy.ini
C:\WINDOWS\system32\tvhzcr.dll
C:\WINDOWS\system32\tzslcn.dll
C:\WINDOWS\system32\udhuxeuo.dll
C:\WINDOWS\system32\vpykfg.dll
C:\WINDOWS\system32\wcpwirrg.dll
C:\WINDOWS\system32\wqyrai.dll
C:\WINDOWS\system32\xgchswpk.dll
C:\WINDOWS\system32\xhlvowff.ini
C:\WINDOWS\system32\xiihucaw.ini
C:\WINDOWS\system32\xltriggj.dll
C:\WINDOWS\system32\yewbxwjr.ini
C:\WINDOWS\system32\yfhirloa.dll
C:\WINDOWS\system32\yhcyuj.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_CLBDRIVER
——-\Legacy_LANMANDRV
——-\Service_clbdriver
((((((((((((((((((((((((( Files Created from 2008-08-09 to 2008-09-09 )))))))))))))))))))))))))))))))
.
2008-09-08 22:20 . 2008-09-08 22:20 d——– C:\Program Files\Trend Micro
2008-09-02 22:17 . 2008-09-02 22:17 d——– C:\WINDOWS\ERUNT
2008-09-02 20:52 . 2008-09-02 20:52 34,304 –a—— C:\WINDOWS\system32\drivers\531lsf.exe
2008-09-02 20:28 . 2008-09-02 20:28 34,304 –a—— C:\WINDOWS\system32\drivers\187lsf.exe
2008-09-01 21:39 . 2008-09-01 21:39 124,544 –a—— C:\WINDOWS\system32\ueweeedd.dll
2008-09-01 21:39 . 2008-09-01 21:39 124,544 –a—— C:\WINDOWS\system32\blrhxo.dll
2008-08-29 02:33 . 2008-08-29 02:33 34,304 –a—— C:\WINDOWS\system32\drivers\281lsf.exe
2008-08-27 00:35 . 2008-08-27 00:35 34,304 –a—— C:\WINDOWS\system32\drivers\203lsf.exe
2008-08-27 00:08 . 2008-08-27 00:08 34,304 –a—— C:\WINDOWS\system32\drivers\718lsf.exe
2008-08-26 22:52 . 2008-08-26 22:52 34,304 –a—— C:\WINDOWS\system32\drivers\546lsf.exe
2008-08-26 07:43 . 2008-08-26 07:43 34,304 –a—— C:\WINDOWS\system32\drivers\437lsf.exe
2008-08-25 23:46 . 2008-08-25 23:46 34,304 –a—— C:\WINDOWS\system32\drivers\906lsf.exe
2008-08-24 03:09 . 2008-08-24 03:09 34,304 –a—— C:\WINDOWS\system32\drivers\468lsf.exe
2008-08-23 19:35 . 2008-08-23 19:35 d——– C:\Program Files\Bonjour
2008-08-23 19:17 . 2008-09-01 21:45 34,304 –a—— C:\WINDOWS\system32\drivers\640lsf.exe
2008-08-23 12:13 . 2008-08-23 12:13 34,304 –a—— C:\WINDOWS\system32\drivers\750lsf.exe
2008-08-23 02:58 . 2008-08-23 02:58 34,304 –a—— C:\WINDOWS\system32\drivers\828lsf.exe
2008-08-22 22:27 . 2008-08-22 22:27 34,304 –a—— C:\WINDOWS\system32\drivers\953lsf.exe
2008-08-20 00:02 . 2008-08-20 00:02 34,304 –a—— C:\WINDOWS\system32\drivers\31lsf.exe
2008-08-18 22:55 . 2008-09-02 20:19 34,304 –a—— C:\WINDOWS\system32\drivers\156lsf.exe
2008-08-18 00:06 . 2008-08-18 00:06 34,304 –a—— C:\WINDOWS\system32\drivers\812lsf.exe
2008-08-17 23:32 . 2008-08-17 23:32 34,304 –a—— C:\WINDOWS\system32\drivers\62lsf.exe
2008-08-17 23:18 . 2008-08-17 23:18 3,434 –a—— C:\WINDOWS\system32\tmp.reg
2008-08-17 23:16 . 2008-08-17 23:16 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-08-17 23:16 . 2008-08-17 23:16 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-08-17 23:16 . 2008-08-17 23:16 86,528 –a—— C:\WINDOWS\system32\VACFix.exe
2008-08-17 23:16 . 2008-08-17 23:16 82,944 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-08-17 23:16 . 2008-08-17 23:16 82,432 –a—— C:\WINDOWS\system32\IEDFix.C.exe
2008-08-17 23:16 . 2008-08-17 23:16 82,432 –a—— C:\WINDOWS\system32\404Fix.exe
2008-08-17 23:16 . 2008-08-17 23:16 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-08-17 23:16 . 2008-08-17 23:16 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-08-17 23:16 . 2008-08-17 23:16 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-08-17 23:00 . 2005-05-02 22:35 d——– C:\Documents and Settings\Administrator.JESSICAELKER.000\Application Data\Sonic
2008-08-17 23:00 . 2005-05-02 22:22 d——– C:\Documents and Settings\Administrator.JESSICAELKER.000\Application Data\Jasc Software Inc
2008-08-17 23:00 . 2008-08-17 23:01 d——– C:\Documents and Settings\Administrator.JESSICAELKER.000\Application Data\Intel
2008-08-17 23:00 . 2005-05-02 22:21 d–h—– C:\Documents and Settings\Administrator.JESSICAELKER.000\Application Data\Gtek
2008-08-17 23:00 . 2008-08-17 23:15 d——– C:\Documents and Settings\Administrator.JESSICAELKER.000
2008-08-14 00:49 . 2005-05-02 22:35 d——– C:\Documents and Settings\Administrator.JESSICAELKER\Application Data\Sonic
2008-08-14 00:49 . 2008-08-14 00:51 d——– C:\Documents and Settings\Administrator.JESSICAELKER\Application Data\Intel
2008-08-14 00:49 . 2008-08-14 00:53 d——– C:\Documents and Settings\Administrator.JESSICAELKER\Application Data\Gtek
2008-08-14 00:49 . 2008-08-14 00:53 d—s—- C:\Documents and Settings\Administrator.JESSICAELKER
2008-08-14 00:06 . 2005-05-02 22:35 d——– C:\Documents and Settings\Administrator\Application Data\Sonic
2008-08-14 00:06 . 2008-08-14 00:08 d——– C:\Documents and Settings\Administrator\Application Data\Intel
2008-08-14 00:06 . 2008-08-14 00:54 d——– C:\Documents and Settings\Administrator\Application Data\Gtek
2008-08-14 00:06 . 2008-08-14 00:54 d—s—- C:\Documents and Settings\Administrator
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-03 00:49 31,616 —-a-w C:\WINDOWS\system32\drivers\Winiq53.sys
2008-08-24 07:05 ——— d—–w C:\Program Files\Apple Software Update
2008-08-23 23:42 ——— d—–w C:\Program Files\iTunes
2008-08-23 23:41 ——— d—–w C:\Program Files\iPod
2008-07-30 12:00 ——— d—–w C:\Documents and Settings\TEMP\Application Data\Amazon
2008-07-25 05:14 ——— d—–w C:\Program Files\EvilLyrics
2008-07-12 01:34 ——— d—–w C:\Program Files\QuickTime
2006-12-25 21:39 20 —h–w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
2005-05-16 06:28 802 —-a-w C:\Documents and Settings\Jessica\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E515E5AB-F9FD-4DA0-BF9D-D5C6E4252087}]
2008-07-30 08:03 323840 –a—— C:\WINDOWS\system32\cbXPJApn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2004-07-19 306688]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 50736]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-21 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-03 344064]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"DLBTCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2004-11-09 69632]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"WD Button Manager"="WDBtnMgr.exe" [2007-09-04 C:\WINDOWS\system32\WDBtnMgr.exe]
C:\Documents and Settings\Jessica\Start Menu\Programs\Startup\
PictureProject In Touch.lnk - C:\Program Files\Nikon\PictureProject In Touch\PictureProjectInTouch.exe [2005-03-21 8384512]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [2006-07-16 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winiq53.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
–a—— 2004-09-13 17:33 155648 C:\Program Files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Photo AIO Printer 922]
–a—— 2004-11-10 20:36 290816 C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
–a—— 2004-07-19 08:51 306688 C:\Program Files\Dell Support\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
——— 2004-10-12 17:54 57344 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-07-30 10:47 289064 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 12:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QBReminderFlash]
–a—— 2004-11-11 11:26 26112 C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2005-05-02 22:29 26112 C:\Program Files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2003-11-19 18:48 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
–a—— 2004-01-07 02:01 110592 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R2 NkPtpEnumP2;NkPtpEnumP2;C:\Program Files\Nikon\Wireless Camera Setup Utility\NkPtpEnum.exe [2005-06-17 24064]
R3 VBus;Virtual Bus;C:\WINDOWS\system32\DRIVERS\NkVBus.sys [2005-06-17 17664]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
BHO-{8d3bc7bc-0893-4f40-8c71-53beff05deb1} - C:\WINDOWS\system32\kkmbkh.dll
HKCU-Run-\SUE24.exe - C:\Windows\SUE24.exe
HKCU-Run-\SUE25.exe - C:\Windows\SUE25.exe
HKCU-Run-\SUE26.exe - C:\Windows\SUE26.exe
HKLM-Run-\SUE24.exe - C:\Windows\SUE24.exe
HKLM-Run-\SUE25.exe - C:\Windows\SUE25.exe
HKLM-Run-\SUE26.exe - C:\Windows\SUE26.exe
MSConfigStartUp-AIM - C:\PROGRA~1\AIM\aim.exe
MSConfigStartUp-Dell QuickSet - C:\Program Files\Dell\QuickSet\quickset.exe
MSConfigStartUp-mmtask - C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
MSConfigStartUp-MMTray - C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
MSConfigStartUp-PCMService - C:\Program Files\Dell\Media Experience\PCMService.exe
MSConfigStartUp-Weather - C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE
.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: E&xport to Microsoft Office Excel - C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-09 19:55:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-09-09 20:01:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-10 00:01:17
Pre-Run: 23,201,792,000 bytes free
Post-Run: 23,807,610,880 bytes free
280 — E O F — 2008-07-25 04:54:44