Heya Sage, WOW, combofix got rid of those pesky files. And so refreshing!! My internet now goes, without any delay or hesitation to the destination I ask it, aaaaaah, such relief!!
Here are the logs:
COMBOFIX:
ComboFix 08-01-14.1 - Sharyn 2008-01-13 13:27:50.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.259 [GMT -9:00]
Running from: C:\Documents and Settings\Sharyn\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\3.tmp
C:\4.tmp
C:\WINDOWS\fnts~1
C:\WINDOWS\system32\comdlg32p.dll
C:\WINDOWS\system32\comreplp.dll
C:\WINDOWS\system32\drivers\cduqprxh.dat
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\koos.exe
C:\WINDOWS\system32\kprof
C:\WINDOWS\system32\msacm32.drv
C:\WINDOWS\system32\poof
C:\WINDOWS\system32\wnstssv32.exe
C:\WINDOWS\Tasks.\At1.job
C:\WINDOWS\wr.txt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_HCAAXOUP
-------\LEGACY_JKYYQJDD
-------\LEGACY_POOF
-------\hcaaxoup
-------\jkyyqjdd
((((((((((((((((((((((((( Files Created from 2007-12-14 to 2008-01-14 )))))))))))))))))))))))))))))))
.
2008-01-13 13:27 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-11 18:12 . 2008-01-11 18:12 741,632 --a------ C:\WINDOWS\system32\xoxchvsn.dat
2008-01-11 18:12 . 2008-01-11 18:12 120,576 --a------ C:\WINDOWS\system32\aruwkcyi.dat
2008-01-11 18:12 . 2008-01-11 18:12 42,240 --a------ C:\WINDOWS\system32\yfaopypm.dat
2008-01-11 18:12 . 2008-01-11 18:12 36,608 --a------ C:\WINDOWS\system32\muxhxwrb.dat
2008-01-11 18:12 . 2008-01-11 18:12 35,072 --a------ C:\WINDOWS\system32\thjhaxya.dat
2008-01-04 21:08 . 2008-01-04 21:08 <DIR> d-------- C:\Documents and Settings\Sharyn\Application Data\Watchtower
2008-01-01 11:16 . 2008-01-01 11:16 <DIR> d-------- C:\Documents and Settings\Sharyn\Application Data\Comodo
2008-01-01 11:16 . 2008-01-01 11:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comodo
2008-01-01 02:08 . 2008-01-01 02:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-01-01 02:04 . 2008-01-02 18:41 <DIR> d-------- C:\Program Files\Comodo
2008-01-01 01:39 . 2007-03-14 01:04 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-31 18:00 . 2007-12-31 18:00 <DIR> d-------- C:\Deckard
2007-12-30 10:35 . 2007-08-01 22:47 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-12-30 09:47 . 2008-01-14 13:32 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-30 09:47 . 2008-01-14 13:32 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-30 09:46 . 2007-12-30 09:46 0 --a------ C:\WINDOWS\system32\QuickTime.qtp
2007-12-29 13:09 . 2007-12-29 13:09 <DIR> d-------- C:\VundoFix Backups
2007-12-29 11:59 . 2007-12-30 10:42 <DIR> d-------- C:\Documents and Settings\Sharyn\.housecall6.6
2007-12-22 20:56 . 2007-12-22 20:56 <DIR> d-------- C:\Program Files\microsoft frontpage
2007-12-22 16:02 . 2007-12-22 16:02 <DIR> d-------- C:\Documents and Settings\Sharyn\Application Data\Yahoo!
2007-12-21 17:56 . 2007-12-22 20:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-03 03:28 --------- d-----w C:\Documents and Settings\Sharyn\Application Data\MSN6
2008-01-01 10:39 --------- d-----w C:\Program Files\Java
2007-12-23 05:21 --------- d-----w C:\Program Files\Yahoo!
2007-12-02 23:39 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2007-12-02 23:39 246,545 ----a-w C:\WINDOWS\system32\libssl32.dll
2007-12-02 23:39 1,188,375 ----a-w C:\WINDOWS\system32\libeay32.dll
2007-11-30 03:12 --------- d-----w C:\Program Files\AOL Games
2007-11-30 03:06 --------- d-----w C:\Program Files\Bookworm Deluxe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Camera Detector"="C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.exe" [2003-06-17 14:43 208896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-17 13:24 77824]
"mmtask"="c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-01-26 10:46 53248]
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2004-09-30 14:44 7957504]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-28 21:29 32768]
"DLCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-09-14 04:50 73728]
"dlccmon.exe"="C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-10-21 06:40 430080]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06 40048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 02:43 83608]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-11-17 17:29 7700480]
S3 pnicml;pnicml;C:\DOCUME~1\Sharyn\LOCALS~1\Temp\pnicml.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\run_cdviewer.exe
*Newly Created Service* - HTTPFILTER
.
Contents of the 'Scheduled Tasks' folder
"2008-01-12 12:00:00 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert.SharynWRuns AdwareAlert to scan your computer for malicious and potenially unwanted programs.
"2008-01-12 11:20:00 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-14 13:32:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\WINDOWS\system32\AppCert\prx93f_.dll
.
Completion time: 2008-01-14 13:34:25 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-14 22:34:23
HIJACK THIS:
Logfile of HijackThis v1.99.1
Scan saved at 1:37:07 PM, on 1/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Sharyn\Desktop\hijackthis\HijackThis.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (file missing)
O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.t...ivex/hcImpl.cabO23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Windows Defender (WinDefend) - Unknown owner - C:\Program Files\Windows Defender\MsMpEng.exe (file missing)
Sage, You ROCK, thanks soooo much for taking all this time to fix my computer, I will definately be recommending this site to others!!
Twistie
Edited by Twistie, 13 January 2008 - 04:51 PM.