combofix and hijackthis
I was able to re-run combo fix. It worked fine this time=) I had to post the hijackthis in a separate post. Thanks
ComboFix 07-09-21.2 - "Roberson" 2007-09-28 16:52:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.68 [GMT -4:00]
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\FindIt.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\FindItHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\findithotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\finditxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\Highlight.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\HighlightHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\highlighthotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\highlightxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\logo.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\logoxp.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\Reference.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\ReferenceHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\referencehotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\referencexp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\screensaver.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\Weather.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\weatherhotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\buttons\weatherxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\contexts\error.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\contexts\related.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\Starware316\contexts\travel.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\FindIt.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\FindItHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\findithotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\finditxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\Highlight.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\HighlightHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\highlighthotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\highlightxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\logo.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\logoxp.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\Reference.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\ReferenceHot.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\referencehotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\referencexp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\screensaver.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\Weather.bmp
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\weatherhotxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\buttons\weatherxp.png
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\contexts\error.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\contexts\related.xml
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Starware316\contexts\travel.xml
C:\Program Files\Starware316
C:\Program Files\Starware316\brand.bmp
C:\Program Files\Starware316\icons\star_16.ico
C:\Program Files\Starware316\Starware316Config.xml
C:\Temp\fse
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\codnrfkj.exe
C:\WINDOWS\system32\dxymldnl.exe
C:\WINDOWS\system32\dyaqjhgc.exe
C:\WINDOWS\system32\ebicrafn.exe
C:\WINDOWS\system32\f10WtR
C:\WINDOWS\system32\ffsoollo.exe
C:\WINDOWS\system32\fopiqtfp.exe
C:\WINDOWS\system32\gfqbxscx.exe
C:\WINDOWS\system32\ggmbunje.exe
C:\WINDOWS\system32\ghexduuj.exe
C:\WINDOWS\system32\gkojgeso.exe
C:\WINDOWS\system32\haixdvcu.exe
C:\WINDOWS\system32\hewhqvvs.exe
C:\WINDOWS\system32\hfdmjmpm.exe
C:\WINDOWS\system32\ijkmp.bak1
C:\WINDOWS\system32\ijkmp.bak2
C:\WINDOWS\system32\ijkmp.ini
C:\WINDOWS\system32\ijkmp.ini2
C:\WINDOWS\system32\ijkmp.tmp
C:\WINDOWS\system32\jrxqwvit.exe
C:\WINDOWS\system32\juqiidtd.exe
C:\WINDOWS\system32\lgrqvqte.exe
C:\WINDOWS\system32\libkicaa.exe
C:\WINDOWS\system32\lllrjbda.exe
C:\WINDOWS\system32\lmweevgc.exe
C:\WINDOWS\system32\ltyodbnu.exe
C:\WINDOWS\system32\lxlchiht.exe
C:\WINDOWS\system32\mbnsbfea.exe
C:\WINDOWS\system32\mebutruj.exe
C:\WINDOWS\system32\modmqaux.exe
C:\WINDOWS\system32\mpdqhaqf.exe
C:\WINDOWS\system32\nfffyukt.exe
C:\WINDOWS\system32\nnfgotfw.exe
C:\WINDOWS\system32\nwtgvoxl.exe
C:\WINDOWS\system32\oofddbse.exe
C:\WINDOWS\system32\oqfojewx.exe
C:\WINDOWS\system32\ouiemjch.exe
C:\WINDOWS\system32\pmkji.dll
C:\WINDOWS\system32\pmrpnytd.exe
C:\WINDOWS\system32\pqenovvg.exe
C:\WINDOWS\system32\pvkncrda.exe
C:\WINDOWS\system32\qdkuhrvf.exe
C:\WINDOWS\system32\quevoxqg.exe
C:\WINDOWS\system32\qvgkhhfo.exe
C:\WINDOWS\system32\remanoat.exe
C:\WINDOWS\system32\rngvphml.exe
C:\WINDOWS\system32\uxwbkqlj.exe
C:\WINDOWS\system32\vsdidcne.exe
C:\WINDOWS\system32\wgebxmvi.exe
C:\WINDOWS\system32\worfxdju.exe
C:\WINDOWS\system32\xdhhdhen.exe
C:\WINDOWS\system32\xjvesgna.exe
C:\WINDOWS\system32\xoxyvxvj.exe
C:\WINDOWS\system32\yemwqgox.exe
C:\WINDOWS\system32\ygbcrhnt.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_IPRIP
-------\DomainService
-------\Iprip
((((((((((((((((((((((((( Files Created from 2007-08-28 to 2007-09-28 )))))))))))))))))))))))))))))))
.
2007-09-28 10:07 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-28 09:56 83,008 --a------ C:\WINDOWS\system32\wabjgioc.dll
2007-09-28 09:45 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-09-28 09:38 83,008 --a------ C:\WINDOWS\system32\gnpukqck.dll
2007-09-28 09:22 <DIR> d-------- C:\VundoFix Backups
2007-09-27 10:56 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-25 21:13 7,467,056 --a------ C:\spybotsd15.exe
2007-09-18 11:20 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-09-15 11:25 <DIR> d-------- C:\Program Files\MSECache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-28 17:01 --------- d-------- C:\Program Files\Dl_cats
2007-09-28 09:28 --------- d-------- C:\Program Files\McAfee
2007-09-27 10:49 --------- d-------- C:\DOCUME~1\NETWOR~1\APPLIC~1\SiteAdvisor
2007-09-25 16:27 --------- d-------- C:\DOCUME~1\Roberson\APPLIC~1\SiteAdvisor
2007-09-23 09:17 --------- d-------- C:\Program Files\Common Files\Sonic Shared
2007-09-20 10:46 --------- d-------- C:\Program Files\Modem Helper
2007-09-15 22:10 308576 --a------ C:\mvtapp.exe
2007-09-15 11:35 --------- d-------- C:\Program Files\SiteAdvisor
2007-09-15 09:32 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SiteAdvisor
2007-09-14 10:38 --------- d-------- C:\Program Files\Google
2007-08-22 18:46 --------- d-------- C:\DOCUME~1\Roberson\APPLIC~1\McAfee
2007-08-22 18:46 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
2007-08-14 23:26 --------- d-------- C:\Program Files\MSXML 6.0
2007-08-09 22:32 --------- d-------- C:\DOCUME~1\Roberson\APPLIC~1\Viewpoint
2007-08-09 22:32 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
2007-07-31 08:02 --------- d-------- C:\Program Files\Common Files\McAfee
2007-04-03 04:58:08 56 --sh--r C:\WINDOWS\system32\F5EF825AE7.sys
2007-04-03 04:58:09 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 16:01]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 02:20 C:\WINDOWS\stsystra.exe]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 09:56]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 23:05]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 18:19]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-01-09 11:49]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 12:44]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 12:44]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2006-01-09 11:57]
"DLCDCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll" [2005-06-07 14:39]
"dlcdmon.exe"="C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe" [2005-07-22 15:45]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 944\memcard.exe" [2005-06-27 13:05]
"SprintModemUpdate"="javaw.exe" [2007-07-12 01:22 C:\WINDOWS\system32\javaw.exe]
"Motive SmartBridge"="C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe" [2006-12-19 01:17]
"IPInSightMonitor 01"="C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe" [2005-08-10 22:10]
"IPInSightLAN 01"="C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" [2005-08-10 22:10]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6172\SiteAdv.exe" [2007-01-17 15:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 05:33]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-04 02:33]
"SearchIndexer"="C:\WINDOWS\system32\wabjgioc.dll" [2007-09-28 09:56]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 20:04]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 11:09]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-01-09 11:45:19]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 13:59:36]
Virtual Assistant.lnk - C:\Program Files\Virtual Assistant\bin\matcli.exe [2006-06-30 00:37:14]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
R2 EarthLinkMonitor;EarthLink Monitor Service;"C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe"
R2 MSMQ;Message Queuing;C:\WINDOWS\system32\mqsvc.exe
R2 MSMQTriggers;Message Queuing Triggers;C:\WINDOWS\system32\mqtgsvc.exe
R2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\system32\inetsrv\inetinfo.exe
R3 dlcd_device;dlcd_device;C:\WINDOWS\system32\dlcdcoms.exe -service
R3 MQAC;Message Queuing access control;\??\C:\WINDOWS\system32\drivers\mqac.sys
R3 RMCAST;Reliable Multicast Protocol driver;\??\C:\WINDOWS\system32\drivers\RMCast.sys
S3 BW2NDIS5;BW2NDIS5;C:\WINDOWS\system32\Drivers\BW2NDIS5.sys
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe -k p2psvc
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe -k p2psvc
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe -k p2psvc
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe -k p2psvc
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
AutoRun\command- E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-08-15 05:00:00 C:\WINDOWS\Tasks\McDefragTask.job"
"2007-09-01 05:00:13 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-28 17:00:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-28 17:04:40 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-28 17:04
.
--- E O F ---