Thank you for the quick reply! After the ComboFix scan I am still unable to connect to the websites.
Here's the new updated HiJackThis Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:36:32 PM, on 4/23/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
D:\Program Files\AdAware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\AVG\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
D:\Program Files\AdAware\AAWTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
D:\Program Files\WinAmp\winampa.exe
D:\Program Files\DAEMON\daemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Mike\Desktop\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AAWTray] D:\Program Files\AdAware\AAWTray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [WinampAgent] "D:\Program Files\WinAmp\winampa.exe"
O4 - HKLM\..\Run: [hgdaxxwxur] Rundll32.exe "C:\WINDOWS\System32\sstttrsq.dll",s
O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\Program Files\DAEMON\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [BM13618375] Rundll32.exe "C:\WINDOWS\System32\vtbdqhyo.dll",s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] "D:\Program Files\Steam\Steam.exe" -silent
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] D:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] D:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: wjlm.exe
O8 - Extra context menu item: &Search -
http://edits.mywebse...html?p=ZJfox000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace....ploader1006.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1203567704609O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\AdAware\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\AVG\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\System32\ZoneLabs\isafe.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
--
End of file - 5130 bytes
And the ComboFix Log:
ComboFix 08-04-22.1 - DJ MIKE A 2008-04-23 3:27:11.6 -
FAT32x86
Running from: C:\Documents and Settings\DJ MIKE A\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\accasrxt.dll
C:\WINDOWS\system32\agrmecfh.ini
C:\WINDOWS\system32\amcwjurs.dll
C:\WINDOWS\system32\aqbyttgf.ini
C:\WINDOWS\system32\awtqr.dll
C:\WINDOWS\system32\awtsp.dll
C:\WINDOWS\system32\awvtr.dll
C:\WINDOWS\system32\awvts.dll
C:\WINDOWS\system32\awvtt.dll
C:\WINDOWS\system32\awvvt.dll
C:\WINDOWS\system32\bgxlbcbw.dll
C:\WINDOWS\system32\bicinabc.ini
C:\WINDOWS\system32\biildrkf.dll
C:\WINDOWS\system32\bjetuxot.dll
C:\WINDOWS\system32\blpbfguh.ini
C:\WINDOWS\system32\bmpiynbw.dll
C:\WINDOWS\system32\bnrwfjvn.dll
C:\WINDOWS\system32\bpttglnq.ini
C:\WINDOWS\system32\brrmdfiv.ini
C:\WINDOWS\system32\bsvujwie.dll
C:\WINDOWS\system32\btrxjhga.dll
C:\WINDOWS\system32\btyfybij.dll
C:\WINDOWS\system32\bxiojwui.dll
C:\WINDOWS\system32\cfnhwfpg.dll
C:\WINDOWS\system32\cipsosnx.dll
C:\WINDOWS\system32\davwfgkf.ini
C:\WINDOWS\system32\dbcvpxvf.ini
C:\WINDOWS\system32\dcffsnio.dll
C:\WINDOWS\system32\dcwnfxeo.dll
C:\WINDOWS\system32\ddabb.dll
C:\WINDOWS\system32\ddabx.dll
C:\WINDOWS\system32\ddaby.dll
C:\WINDOWS\system32\ddaya.dll
C:\WINDOWS\system32\ddayw.dll
C:\WINDOWS\system32\ddccd.dll
C:\WINDOWS\system32\ddccy.dll
C:\WINDOWS\system32\ddcyy.dll
C:\WINDOWS\system32\dgxaymul.ini
C:\WINDOWS\system32\dqgrvkyi.ini
C:\WINDOWS\system32\dqtqhuow.dll
C:\WINDOWS\system32\drtjmnin.dll
C:\WINDOWS\system32\dwpgnrxn.dll
C:\WINDOWS\system32\eapfwikp.ini
C:\WINDOWS\system32\eaphjkyn.ini
C:\WINDOWS\system32\edncnrre.dll
C:\WINDOWS\system32\eflwbdca.ini
C:\WINDOWS\system32\egwxeder.ini
C:\WINDOWS\system32\elaibvra.dll
C:\WINDOWS\system32\elgyrwqf.ini
C:\WINDOWS\system32\emyjjnkl.ini
C:\WINDOWS\system32\eplqpkoy.dll
C:\WINDOWS\system32\farpjdym.dll
C:\WINDOWS\system32\fawnmnqv.dll
C:\WINDOWS\system32\fdxetegj.dll
C:\WINDOWS\system32\fevnojrw.dll
C:\WINDOWS\system32\fgttybqa.dll
C:\WINDOWS\system32\fjdocjvo.dll
C:\WINDOWS\system32\fnneartr.dll
C:\WINDOWS\system32\fntxqvmj.ini
C:\WINDOWS\system32\frnpafnj.ini
C:\WINDOWS\system32\ftijgsrm.ini
C:\WINDOWS\system32\ftlfebkv.dll
C:\WINDOWS\system32\ftxicrue.dll
C:\WINDOWS\system32\fvybfpch.dll
C:\WINDOWS\system32\fwneumef.dll
C:\WINDOWS\system32\gebca.dll
C:\WINDOWS\system32\gebcy.dll
C:\WINDOWS\system32\geeba.dll
C:\WINDOWS\system32\ggexjnsq.ini
C:\WINDOWS\system32\halxyiem.dll
C:\WINDOWS\system32\hgjyjlow.dll
C:\WINDOWS\system32\hhkmp.bak1
C:\WINDOWS\system32\hhkmp.bak2
C:\WINDOWS\system32\hhkmp.ini
C:\WINDOWS\system32\hhkmp.ini2
C:\WINDOWS\system32\hmaxytnv.dll
C:\WINDOWS\system32\hmftsunq.dll
C:\WINDOWS\system32\hngvqgmr.dll
C:\WINDOWS\system32\htkhnhrp.dll
C:\WINDOWS\system32\hugfbplb.dll
C:\WINDOWS\system32\hvhhtkhd.dll
C:\WINDOWS\system32\ichrwllp.ini
C:\WINDOWS\system32\ifnunkqe.ini
C:\WINDOWS\system32\ihggwqrk.dll
C:\WINDOWS\system32\iishbilg.dll
C:\WINDOWS\system32\irubymon.dll
C:\WINDOWS\system32\iwbvurjs.ini
C:\WINDOWS\system32\iykvrgqd.dll
C:\WINDOWS\system32\jcwkahea.dll
C:\WINDOWS\system32\jfujivap.dll
C:\WINDOWS\system32\jhphbfgc.dll
C:\WINDOWS\system32\jibyfytb.ini
C:\WINDOWS\system32\jkhfc.dll
C:\WINDOWS\system32\jkhff.dll
C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\jkhhh.dll
C:\WINDOWS\system32\jkkjj.dll
C:\WINDOWS\system32\jkkli.dll
C:\WINDOWS\system32\jknortbp.dll
C:\WINDOWS\system32\jmtfaryf.ini
C:\WINDOWS\system32\jnsjkgca.ini
C:\WINDOWS\system32\jpewsoqg.dll
C:\WINDOWS\system32\jrsjhcnt.dll
C:\WINDOWS\system32\jwyfwugy.dll
C:\WINDOWS\system32\jxrgqqbi.ini
C:\WINDOWS\system32\jygbwvfu.dll
C:\WINDOWS\system32\kbloghmn.dll
C:\WINDOWS\system32\kkrwjcve.ini
C:\WINDOWS\system32\kmd.exe
C:\WINDOWS\system32\kpgwqixt.dll
C:\WINDOWS\system32\kppnrmxw.dll
C:\WINDOWS\system32\krqwgghi.ini
C:\WINDOWS\system32\ktqljaaf.dll
C:\WINDOWS\system32\kuyhvgpr.dll
C:\WINDOWS\system32\kwvnlavc.dll
C:\WINDOWS\system32\kxemhlfr.dll
C:\WINDOWS\system32\lcscgmat.ini
C:\WINDOWS\system32\ljnptece.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\melqhywa.dll
C:\WINDOWS\system32\mficgrcf.dll
C:\WINDOWS\system32\mhqbsmjp.dll
C:\WINDOWS\system32\mljgd.dll
C:\WINDOWS\system32\mljge.dll
C:\WINDOWS\system32\mljgh.dll
C:\WINDOWS\system32\mljjg.dll
C:\WINDOWS\system32\mllmk.dll
C:\WINDOWS\system32\nawhfhef.ini
C:\WINDOWS\system32\ncenqwat.dll
C:\WINDOWS\system32\ngqvkxii.dll
C:\WINDOWS\system32\njjqgfav.ini
C:\WINDOWS\system32\njpljqui.dll
C:\WINDOWS\system32\nmoseesw.dll
C:\WINDOWS\system32\nnwnymgd.dll
C:\WINDOWS\system32\nosdlxip.dll
C:\WINDOWS\system32\nqmmponn.dll
C:\WINDOWS\system32\nqphvbij.dll
C:\WINDOWS\system32\nsomgxnd.ini
C:\WINDOWS\system32\nubytjbj.ini
C:\WINDOWS\system32\nyagjvld.dll
C:\WINDOWS\system32\obldgwpl.dll
C:\WINDOWS\system32\oievlxet.ini
C:\WINDOWS\system32\oipdprmc.dll
C:\WINDOWS\system32\oonvvrsp.ini
C:\WINDOWS\system32\orpgdrxi.dll
C:\WINDOWS\system32\osomqwgp.ini
C:\WINDOWS\system32\oyervitp.dll
C:\WINDOWS\system32\pbtronkj.ini
C:\WINDOWS\system32\pemaqwly.dll
C:\WINDOWS\system32\pennlnwk.ini
C:\WINDOWS\system32\pllwrhci.dll
C:\WINDOWS\system32\pmkjh.dll
C:\WINDOWS\system32\pmkjj.dll
C:\WINDOWS\system32\pmnlj.dll
C:\WINDOWS\system32\pmnnm.dll
C:\WINDOWS\system32\pmnnn.dll
C:\WINDOWS\system32\poiiaerp.dll
C:\WINDOWS\system32\ppmsmtyr.dll
C:\WINDOWS\system32\pptvjwgt.ini
C:\WINDOWS\system32\prhnhkth.ini
C:\WINDOWS\system32\psrvvnoo.dll
C:\WINDOWS\system32\pxiuqwah.dll
C:\WINDOWS\system32\qdsmqkmg.ini
C:\WINDOWS\system32\qgtsxrvj.ini
C:\WINDOWS\system32\qneeifkf.dll
C:\WINDOWS\system32\qnnlygsb.dll
C:\WINDOWS\system32\qnodvpbe.dll
C:\WINDOWS\system32\qnustfmh.ini
C:\WINDOWS\system32\qtstv.ini
C:\WINDOWS\system32\qtstv.ini2
C:\WINDOWS\system32\qullrusp.dll
C:\WINDOWS\system32\quxthbqg.ini
C:\WINDOWS\system32\qvaxhblx.dll
C:\WINDOWS\system32\qyqdnyah.dll
C:\WINDOWS\system32\rfomxabd.dll
C:\WINDOWS\system32\rjhmjgpn.dll
C:\WINDOWS\system32\rmgqvgnh.ini
C:\WINDOWS\system32\rnaeyctr.dll
C:\WINDOWS\system32\roxxiriw.dll
C:\WINDOWS\system32\roxxlrac.dll
C:\WINDOWS\system32\rsfjuhme.ini
C:\WINDOWS\system32\savsdjfr.ini
C:\WINDOWS\system32\segvxbdq.ini
C:\WINDOWS\system32\soiqtfus.dll
C:\WINDOWS\system32\ssqro.dll
C:\WINDOWS\system32\sstts.dll
C:\WINDOWS\system32\tdxjivsb.ini
C:\WINDOWS\system32\tlencosd.ini
C:\WINDOWS\system32\tllihtyq.ini
C:\WINDOWS\system32\tmgucwac.ini
C:\WINDOWS\system32\tpuwvasc.ini
C:\WINDOWS\system32\tvbtkbxa.dll
C:\WINDOWS\system32\twuyyius.ini
C:\WINDOWS\system32\twygrqop.dll
C:\WINDOWS\system32\tycfuefu.dll
C:\WINDOWS\system32\tyglydtr.ini
C:\WINDOWS\system32\tynymwrb.dll
C:\WINDOWS\system32\uedtmawp.ini
C:\WINDOWS\system32\uhefcsqs.dll
C:\WINDOWS\system32\umfarrbt.dll
C:\WINDOWS\system32\urlpgprl.dll
C:\WINDOWS\system32\utglsbyt.dll
C:\WINDOWS\system32\vebnwlty.dll
C:\WINDOWS\system32\vgapdhhi.dll
C:\WINDOWS\system32\vofyexxe.dll
C:\WINDOWS\system32\vsipyuwh.dll
C:\WINDOWS\system32\vtsqq.dll
C:\WINDOWS\system32\vtstq.dll
C:\WINDOWS\system32\vtsts.dll
C:\WINDOWS\system32\vtutt.dll
C:\WINDOWS\system32\vwlsfwyt.dll
C:\WINDOWS\system32\wdqkkxda.dll
C:\WINDOWS\system32\wgapbrwk.ini
C:\WINDOWS\system32\wrjonvef.ini
C:\WINDOWS\system32\wsmapymm.dll
C:\WINDOWS\system32\wsqbctsh.dll
C:\WINDOWS\system32\xacyqsey.dll
C:\WINDOWS\system32\xhdpfvjn.dll
C:\WINDOWS\system32\xhsqlohp.dll
C:\WINDOWS\system32\xkoldyaj.ini
C:\WINDOWS\system32\xqvqwxwv.dll
C:\WINDOWS\system32\yqvemnms.dll
C:\WINDOWS\system32\ystwykdu.dll
.
((((((((((((((((((((((((( Files Created from 2008-03-23 to 2008-04-23 )))))))))))))))))))))))))))))))
.
2008-04-23 08:51 . 2008-04-23 08:51 272,384 --------- C:\WINDOWS\system32\awvts.dll
2008-04-23 08:51 . 2008-04-23 08:56 444 --ahs---- C:\WINDOWS\system32\stvwa.ini
2008-04-23 08:51 . 2008-04-23 08:55 345 --ahs---- C:\WINDOWS\system32\stvwa.ini2
2008-04-22 08:50 . 2008-04-22 08:50 <DIR> d---s---- C:\Documents and Settings\DJ MIKE A\UserData
2008-04-21 03:55 . 2008-04-21 03:55 <DIR> d-------- C:\Documents and Settings\DJ MIKE A\Application Data\Leadertech
2008-04-21 03:00 . 2004-08-22 16:31 155,136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys
2008-04-21 03:00 . 2004-08-22 16:31 5,248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys
2008-04-21 02:57 . 2008-04-21 02:57 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-04-20 16:46 . 2008-04-21 16:45 1,520,966 ---hs---- C:\WINDOWS\system32\ttdwhvty.ini
2008-04-20 13:03 . 2008-04-21 01:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-20 13:03 . 2008-04-20 13:03 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-20 11:56 . 2008-04-20 11:56 <DIR> d-------- C:\Documents and Settings\DJ MIKE A\Application Data\SystemRequirementsLab
2008-04-18 04:03 . 2008-04-18 04:03 <DIR> d-------- C:\Documents and Settings\DJ MIKE A\Application Data\WinAmp
2008-04-16 22:14 . 2008-04-16 22:14 <DIR> d-------- C:\Documents and Settings\DJ MIKE A\Application Data\AppDate
2008-04-15 02:52 . 2008-04-15 03:05 107,832 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-04-15 02:52 . 2008-04-15 03:05 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-04-15 02:51 . 2008-04-15 02:51 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-04-15 02:51 . 2008-04-15 02:51 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-04-14 19:21 . 2008-04-14 19:21 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\InstallShield
2008-04-13 12:46 . 2008-04-13 12:46 9,216 --ahs---- C:\WINDOWS\Thumbs.db
2008-04-10 21:05 . 2008-04-10 21:05 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\Nokia Multimedia Player
2008-03-29 02:29 . 2008-03-30 03:41 1,556,908 ---hs---- C:\WINDOWS\system32\qodmnedc.ini
2008-03-27 22:59 . 2008-03-29 02:27 1,749,577 ---hs---- C:\WINDOWS\system32\rufidkpu.ini
2008-03-26 22:55 . 2008-03-27 23:00 1,708,651 ---hs---- C:\WINDOWS\system32\kfrcnput.ini
2008-03-26 09:46 . 2008-03-26 19:04 2,149,203 ---hs---- C:\WINDOWS\system32\ukyjsxoj.ini
2008-03-26 07:27 . 2008-03-26 09:43 2,208,478 ---hs---- C:\WINDOWS\system32\ywhrfhnp.ini
2008-03-25 01:43 . 2008-03-26 07:24 2,438,221 ---hs---- C:\WINDOWS\system32\wqawnlvb.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-17 17:08 99,904 ----a-w C:\WINDOWS\system32\jtojhntd.dll
2008-03-17 17:03 95,296 ----a-w C:\WINDOWS\system32\ijgtojmo.dll
2008-03-17 13:14 99,904 ----a-w C:\WINDOWS\system32\untjcebf.dll
2008-03-17 13:11 95,296 ----a-w C:\WINDOWS\system32\ojmpnmip.dll
2008-03-17 12:14 99,904 ----a-w C:\WINDOWS\system32\daiscsde.dll
2008-03-17 12:11 95,296 ----a-w C:\WINDOWS\system32\jwkvupio.dll
2008-03-17 11:14 99,904 ----a-w C:\WINDOWS\system32\irvieedr.dll
2008-03-17 11:11 95,296 ----a-w C:\WINDOWS\system32\jxeipdho.dll
2008-03-17 10:17 99,904 ----a-w C:\WINDOWS\system32\ygyeumvy.dll
2008-03-17 10:11 95,296 ----a-w C:\WINDOWS\system32\jvkfcgpe.dll
2008-03-17 09:17 99,904 ----a-w C:\WINDOWS\system32\xmjghyas.dll
2008-03-17 09:11 95,296 ----a-w C:\WINDOWS\system32\japmishl.dll
2008-03-17 08:11 99,904 ----a-w C:\WINDOWS\system32\jasyfkyq.dll
2008-03-17 08:08 95,296 ----a-w C:\WINDOWS\system32\akrrvahw.dll
2008-03-17 07:14 99,904 ----a-w C:\WINDOWS\system32\nsyebqiv.dll
2008-03-17 07:09 95,296 ----a-w C:\WINDOWS\system32\ssbtyxws.dll
2008-03-17 05:04 99,904 ----a-w C:\WINDOWS\system32\qjrnhswr.dll
2008-03-17 04:59 95,296 ----a-w C:\WINDOWS\system32\mctshimr.dll
2008-03-17 00:36 99,904 ----a-w C:\WINDOWS\system32\cuyhmsdk.dll
2008-03-17 00:30 95,296 ----a-w C:\WINDOWS\system32\dqtjeoxt.dll
2008-03-16 23:33 99,904 ----a-w C:\WINDOWS\system32\xosmafrb.dll
2008-03-16 23:30 95,296 ----a-w C:\WINDOWS\system32\boasedts.dll
2008-03-16 22:33 99,904 ----a-w C:\WINDOWS\system32\wxbvlsrp.dll
2008-03-16 22:27 95,296 ----a-w C:\WINDOWS\system32\patyypoq.dll
2008-03-16 21:33 99,904 ----a-w C:\WINDOWS\system32\hodlbosa.dll
2008-03-16 21:27 95,296 ----a-w C:\WINDOWS\system32\vhhveqfs.dll
2008-03-16 20:30 99,904 ----a-w C:\WINDOWS\system32\wfnifaxf.dll
2008-03-16 20:27 95,296 ----a-w C:\WINDOWS\system32\fqusuprp.dll
2008-03-16 19:30 99,904 ----a-w C:\WINDOWS\system32\gphvtorb.dll
2008-03-16 19:27 95,296 ----a-w C:\WINDOWS\system32\gomruscp.dll
2008-03-16 18:33 99,904 ----a-w C:\WINDOWS\system32\iiygsrxn.dll
2008-03-16 18:28 95,296 ----a-w C:\WINDOWS\system32\cfmhvmib.dll
2008-03-16 17:30 99,904 ----a-w C:\WINDOWS\system32\cybxwioo.dll
2008-03-16 17:27 95,296 ----a-w C:\WINDOWS\system32\gqtmwbdg.dll
2008-03-16 16:29 99,904 ----a-w C:\WINDOWS\system32\qiwydgyq.dll
2008-03-16 16:26 95,296 ----a-w C:\WINDOWS\system32\oggksnlg.dll
2008-03-16 15:26 99,904 ----a-w C:\WINDOWS\system32\baxllhxb.dll
2008-03-16 15:23 95,296 ----a-w C:\WINDOWS\system32\csqrxnio.dll
2008-03-16 14:21 95,296 ----a-w C:\WINDOWS\system32\wjoarytk.dll
2008-03-15 18:08 98,368 ----a-w C:\WINDOWS\system32\ddstmahl.dll
2008-03-15 18:05 98,368 ----a-w C:\WINDOWS\system32\ikmxfcid.dll
2008-03-14 18:08 98,368 ----a-w C:\WINDOWS\system32\cnrjmkla.dll
2008-03-14 18:03 96,832 ----a-w C:\WINDOWS\system32\xcbfjmkj.dll
2008-03-12 22:47 --------- d-----w C:\Documents and Settings\DJ MIKE A\Application Data\acccore
2008-03-09 23:01 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-03-09 23:01 --------- d-----w C:\Documents and Settings\Mike\Application Data\SystemRequirementsLab
2008-03-05 22:11 96,832 ----a-w C:\WINDOWS\system32\mhvgboea.dll
2008-03-04 21:10 96,832 ----a-w C:\WINDOWS\system32\lxlelyta.dll
2008-03-03 21:13 95,296 ----a-w C:\WINDOWS\system32\epuyhtdu.dll
2008-03-01 18:17 294,400 ----a-w C:\WINDOWS\system32\geede.dll
2008-03-01 14:40 294,400 ----a-w C:\WINDOWS\system32\ddayv.dll
2008-02-24 06:27 --------- d-----w C:\Documents and Settings\Christine\Application Data\acccore
2008-02-17 07:41 22,016 ----a-w C:\WINDOWS\system32\sstttrsq.dll
2008-02-17 07:41 22,016 ----a-w C:\WINDOWS\ssqrsqrp.dll
2008-02-17 07:41 22,016 ----a-w C:\Documents and Settings\Mike\Application Data\mllmkjki.dll
2008-02-05 13:23 90,688 ----a-w C:\WINDOWS\system32\metqwyoe.dll
2008-02-01 08:21 245,408 ----a-w C:\WINDOWS\system32\unicows.dll
2007-07-07 00:12 784 ----a-w C:\Documents and Settings\DJ MIKE A\Application Data\mpauth.dat
2007-06-30 06:13 784 ----a-w C:\Documents and Settings\Candice\Application Data\mpauth.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6426ed86-81ea-4ae4-8e74-e027dfb74220}]
2008-04-23 08:57 97856 --a------ C:\WINDOWS\System32\lqdouhsf.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C196BF59-D6EC-491F-894A-A27DDFB43AE0}]
2008-02-17 02:41 22016 --a------ C:\WINDOWS\ssqrsqrp.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F1F1541C-A100-4BAB-8EEC-A9D43FFF14F2}]
2008-04-23 08:51 272384 --------- C:\WINDOWS\System32\awvts.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-11-15 16:18 1670144]
"Steam"="D:\Program Files\Steam\Steam.exe" [ ]
"Aim6"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AAWTray"="D:\Program Files\AdAware\AAWTray.exe" [2007-08-08 15:53 88024]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"WinampAgent"="D:\Program Files\WinAmp\winampa.exe" [2008-01-15 17:54 37376]
"hgdaxxwxur"="C:\WINDOWS\System32\sstttrsq.dll" [2008-02-17 02:41 22016]
"DAEMON Tools-1033"="D:\Program Files\DAEMON\daemon.exe" [2004-08-22 17:05 81920]
"1052b0e9"="C:\WINDOWS\System32\fhmpaues.dll" [2008-04-23 08:55 88640]
"BM13618375"="C:\WINDOWS\System32\vtbdqhyo.dll" [2008-04-23 08:54 95808]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="D:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 15:58 1744896]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
wjlm.exe [2008-02-17 02:41:40 22248]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.MJPG"= sonymjpg.dll
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\System32\awvts
Notification Packages REG_MULTI_SZ scecli C:\Documents and Settings\Mike\Application Data\mllmkjki.dll C:\Documents and Settings\Mike\Application Data\mllmkjki.dll C:\Documents and Settings\Mike\Application Data\mllmkjki.dll C:\Documents and Settings\Mike\Application Data\mllmkjki.dll C:\Documents and Settings\Mike\Application Data\mllmkjki.dll C:\Documents and Settings\Mike\Application Data\mllmkjki.dll C:\Documents and Settings\Mike\Application Data\mllmkjki.dll C:\Documents and Settings\Mike\Application Data\mllmkjki.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"!AVG Anti-Spyware"="D:\Program Files\AVG\AVG Anti-Spyware 7.5\avgas.exe" /minimized
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
"PCSuiteTrayApplication"=D:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
"NvCplDaemon"=RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
"Pop3trap.exe"="C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
"WebTrapNT.exe"="C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
R1 SonyFanC;FAN Control Device Service;C:\WINDOWS\System32\Drivers\SonyFanC.sys [2001-09-06 16:21]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2001-08-18 05:00]
S3 BCM42XX;Broadcom iLine10 Network Adapter Driver;C:\WINDOWS\System32\DRIVERS\bcm42xx5.sys [2001-08-17 12:11]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2008-04-16 12:48:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-18 22:15:02 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- D:\Program Files\Tune Up\SystemOptimizer.exe
"2008-02-15 01:04:06 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-04-15 03:46:02 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-23 08:53:11
Windows 5.1.2600 Service Pack 1 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\Documents and Settings\Mike\Application Data\mllmkjki.dll
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\System32\fhmpaues.dll
-> C:\WINDOWS\System32\sstttrsq.dll
-> C:\WINDOWS\System32\vtbdqhyo.dll
-> C:\WINDOWS\System32\awvts.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
D:\Program Files\AdAware\aawservice.exe
D:\Program Files\AVG\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\WINDOWS\SYSTEM32\PNKBSTRA.EXE
C:\PROGRAM FILES\TREND MICRO\PC-CILLIN 2000\TMNTSRV.EXE
C:\WINDOWS\SYSTEM32\WDFMGR.EXE
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\MOM.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI.ACE\CORE-STATIC\CCC.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Completion time: 2008-04-23 9:00:49 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-23 13:59:50
Pre-Run: 1,780,404,224 bytes free
Post-Run: 1,916,682,240 bytes free
426 --- E O F --- 2008-02-21 07:17:38
Cheers!