i've tried geting rid of it without posting, but alas, i was unable to..
here is my HJT log and my combofix log.
Logfile of HijackThis v1.99.1
Scan saved at 10:34:39 AM, on 8/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slmdmsr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\McAfee\McAfee VirusScan\Webscanx.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\McAfee\McAfee Firewall\CPDCLNT.EXE
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Documents and Settings\Alano\My Documents\Things for comp\hijackthis\HijackThis.exe
C:\WINDOWS\system32\cmd.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://files.member.yahoo.com/dl/installs/sbc/yinst.cab
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Networks Associates Technologies, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slmdmsr.exe
and my combofix:
ComboFix 07-08-09.3 - "Alano" 2007-08-10 10:19:39.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.45 [GMT -7:00]
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\dnb012d8f5.dat
C:\WINDOWS\system32\geeed.exe
C:\WINDOWS\system32\ipxrio.dll
C:\WINDOWS\system32\rqollji.dll
((((((((((((((((((((((((( Files Created from 2007-07-10 to 2007-08-10 )))))))))))))))))))))))))))))))
2007-08-09 18:42 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-09 18:16 <DIR> d-------- C:\VundoFix Backups
2007-08-09 16:34 <DIR> d-------- C:\{000040AC-0000-0000-6949-5C7BCC6D22C7}
2007-08-08 20:36 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-08-06 09:28 <DIR> d-------- C:\WINDOWS\system32\Panda Software
2007-08-06 09:26 <DIR> d-------- C:\Program Files\Panda Security
2007-08-05 16:31 78,569 --a------ C:\DOCUME~1\Dad\APPLIC~1\tmp8.tmp.exe
2007-08-05 16:31 58,798 --a------ C:\DOCUME~1\Dad\APPLIC~1\tmp7.tmp.exe
2007-08-05 16:28 124,683 --a------ C:\DOCUME~1\Dad\APPLIC~1\tmp6.tmp.exe
2007-08-05 16:13 25,664 --a------ C:\WINDOWS\system32\sbL8r776.exe
2007-07-17 13:25 <DIR> d-------- C:\Program Files\Microsoft Games
2007-07-13 16:04 <DIR> d-------- C:\Program Files\Guild Wars
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-10 10:27 24 --a------ C:\WINDOWS\system32\DVCStateBkp-{00000000-00000000-0000000F-00001102-00000002-80651102}.dat
2007-08-10 10:27 24 --a------ C:\WINDOWS\system32\DVCState-{00000000-00000000-0000000F-00001102-00000002-80651102}.dat
2007-08-06 12:41 --------- d-------- C:\Program Files\ewido anti-spyware 4.0
2007-08-06 09:26 4112 --a------ C:\WINDOWS\mozver.dat
2007-08-03 18:00 --------- d-------- C:\Program Files\Oni
2007-06-20 16:46 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-06-20 16:46 --------- d-------- C:\Program Files\PC Inspector File Recovery
2007-06-20 16:44 0 --a------ C:\Program Files\Common Files\dht342126
2006-09-11 23:14 144 --a------ C:\Program Files\RUpdate.log
2006-04-12 11:08 16768 --a------ C:\DOCUME~1\Alano\APPLIC~1\GDIPFONTCACHEV1.DAT
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alogserv"="C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe" [2002-05-28 06:02]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 17:56 C:\WINDOWS\system32\CTHELPER.EXE]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00]
"Jet Detection"="C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 01:00]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2005-08-02 16:35]
"nwiz"="nwiz.exe" [2005-08-02 16:35 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2005-08-02 16:35]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" [2006-10-12 04:10]
"Ink Monitor"="C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe" [2001-10-16 11:10]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 07:03]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 07:03]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-15 15:51]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
EPSON Status Monitor 3 Environment Check 2.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2005-09-14 23:39:46]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
R0 RecAgent;RecAgent;C:\WINDOWS\system32\DRIVERS\SLDRV\RecAgent.sys
R2 AvSynMgr;AVSync Manager;"C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe"
R2 UMAXPCLS;Print Port Scanner Driver;C:\WINDOWS\system32\DRIVERS\umaxpcls.sys
R3 Eplpdx02;Eplpdx02;\??\C:\WINDOWS\System32\Drivers\EPLPDX02.SYS
R3 McAfeePF;McAfee Firewall Network Filter Miniport;C:\WINDOWS\system32\DRIVERS\fw220.sys
R3 Mtlmnt5;Mtlmnt5;C:\WINDOWS\system32\DRIVERS\SLDRV\Mtlmnt5.sys
R3 NaiFiltr;NaiFiltr;C:\WINDOWS\system32\DRIVERS\NaiFiltr.sys
R3 Slntamr;SmartLink AMR_PCI Driver;C:\WINDOWS\system32\DRIVERS\SLDRV\slntamr.sys
R3 SlWdmSup;SlWdmSup;C:\WINDOWS\system32\DRIVERS\SLDRV\SlWdmSup.sys
S3 MR97310_USB_DUAL_CAMERA;CIF Dual-Mode Camera;C:\WINDOWS\system32\DRIVERS\mr97310c.sys
S3 msloop;Microsoft Loopback Adapter Driver;C:\WINDOWS\system32\DRIVERS\loop.sys
S3 Mtlstrm;Mtlstrm;C:\WINDOWS\system32\DRIVERS\SLDRV\Mtlstrm.sys
S3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\system32\DRIVERS\NtApm.sys
S3 SlNtHal;SlNtHal;C:\WINDOWS\system32\DRIVERS\SLDRV\Slnthal.sys
S3 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
S4 SQLBrowser;SQL Server Browser;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
Contents of the 'Scheduled Tasks' folder
2007-08-10 07:01:04 C:\WINDOWS\Tasks\At1.job
2007-08-10 16:01:00 C:\WINDOWS\Tasks\At10.job
2007-08-10 17:01:02 C:\WINDOWS\Tasks\At11.job
2007-08-09 18:01:04 C:\WINDOWS\Tasks\At12.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-09 19:01:03 C:\WINDOWS\Tasks\At13.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-09 20:01:23 C:\WINDOWS\Tasks\At14.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-09 21:01:05 C:\WINDOWS\Tasks\At15.job
2007-08-09 22:01:03 C:\WINDOWS\Tasks\At16.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-09 23:01:06 C:\WINDOWS\Tasks\At17.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-10 00:01:01 C:\WINDOWS\Tasks\At18.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-10 01:00:04 C:\WINDOWS\Tasks\At19.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-10 08:01:02 C:\WINDOWS\Tasks\At2.job
2007-08-10 02:01:00 C:\WINDOWS\Tasks\At20.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-10 03:01:00 C:\WINDOWS\Tasks\At21.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-10 04:01:07 C:\WINDOWS\Tasks\At22.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-10 05:01:03 C:\WINDOWS\Tasks\At23.job
2007-08-10 06:01:02 C:\WINDOWS\Tasks\At24.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-10 09:01:06 C:\WINDOWS\Tasks\At3.job
2007-08-10 10:01:04 C:\WINDOWS\Tasks\At4.job
2007-08-10 11:01:05 C:\WINDOWS\Tasks\At5.job
2007-08-10 12:01:04 C:\WINDOWS\Tasks\At6.job
2007-08-10 13:01:05 C:\WINDOWS\Tasks\At7.job
2007-08-10 14:01:04 C:\WINDOWS\Tasks\At8.job
2007-08-10 15:01:02 C:\WINDOWS\Tasks\At9.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-10 10:28:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-10 10:32:59 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-10 10:31
C:\ComboFix2.txt ... 2007-08-09 18:58
--- E O F ---
here is my HJT log and my combofix log.
Logfile of HijackThis v1.99.1
Scan saved at 10:34:39 AM, on 8/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slmdmsr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\McAfee\McAfee VirusScan\Webscanx.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\McAfee\McAfee Firewall\CPDCLNT.EXE
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Documents and Settings\Alano\My Documents\Things for comp\hijackthis\HijackThis.exe
C:\WINDOWS\system32\cmd.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://files.member.yahoo.com/dl/installs/sbc/yinst.cab
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testgen/installers/TestGenXInstall.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} (Pearson MathXL Player) - http://asp.mathxl.com/books/_Players/MathPlayer.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AVSync Manager (AvSynMgr) - Networks Associates Technologies, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slmdmsr.exe
and my combofix:
ComboFix 07-08-09.3 - "Alano" 2007-08-10 10:19:39.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.45 [GMT -7:00]
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\dnb012d8f5.dat
C:\WINDOWS\system32\geeed.exe
C:\WINDOWS\system32\ipxrio.dll
C:\WINDOWS\system32\rqollji.dll
((((((((((((((((((((((((( Files Created from 2007-07-10 to 2007-08-10 )))))))))))))))))))))))))))))))
2007-08-09 18:42 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-09 18:16 <DIR> d-------- C:\VundoFix Backups
2007-08-09 16:34 <DIR> d-------- C:\{000040AC-0000-0000-6949-5C7BCC6D22C7}
2007-08-08 20:36 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-08-06 09:28 <DIR> d-------- C:\WINDOWS\system32\Panda Software
2007-08-06 09:26 <DIR> d-------- C:\Program Files\Panda Security
2007-08-05 16:31 78,569 --a------ C:\DOCUME~1\Dad\APPLIC~1\tmp8.tmp.exe
2007-08-05 16:31 58,798 --a------ C:\DOCUME~1\Dad\APPLIC~1\tmp7.tmp.exe
2007-08-05 16:28 124,683 --a------ C:\DOCUME~1\Dad\APPLIC~1\tmp6.tmp.exe
2007-08-05 16:13 25,664 --a------ C:\WINDOWS\system32\sbL8r776.exe
2007-07-17 13:25 <DIR> d-------- C:\Program Files\Microsoft Games
2007-07-13 16:04 <DIR> d-------- C:\Program Files\Guild Wars
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-10 10:27 24 --a------ C:\WINDOWS\system32\DVCStateBkp-{00000000-00000000-0000000F-00001102-00000002-80651102}.dat
2007-08-10 10:27 24 --a------ C:\WINDOWS\system32\DVCState-{00000000-00000000-0000000F-00001102-00000002-80651102}.dat
2007-08-06 12:41 --------- d-------- C:\Program Files\ewido anti-spyware 4.0
2007-08-06 09:26 4112 --a------ C:\WINDOWS\mozver.dat
2007-08-03 18:00 --------- d-------- C:\Program Files\Oni
2007-06-20 16:46 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-06-20 16:46 --------- d-------- C:\Program Files\PC Inspector File Recovery
2007-06-20 16:44 0 --a------ C:\Program Files\Common Files\dht342126
2006-09-11 23:14 144 --a------ C:\Program Files\RUpdate.log
2006-04-12 11:08 16768 --a------ C:\DOCUME~1\Alano\APPLIC~1\GDIPFONTCACHEV1.DAT
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Alogserv"="C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe" [2002-05-28 06:02]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 17:56 C:\WINDOWS\system32\CTHELPER.EXE]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00]
"Jet Detection"="C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 01:00]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2005-08-02 16:35]
"nwiz"="nwiz.exe" [2005-08-02 16:35 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2005-08-02 16:35]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" [2006-10-12 04:10]
"Ink Monitor"="C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe" [2001-10-16 11:10]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 07:03]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 07:03]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-15 15:51]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]
EPSON Status Monitor 3 Environment Check 2.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2005-09-14 23:39:46]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]
R0 RecAgent;RecAgent;C:\WINDOWS\system32\DRIVERS\SLDRV\RecAgent.sys
R2 AvSynMgr;AVSync Manager;"C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe"
R2 UMAXPCLS;Print Port Scanner Driver;C:\WINDOWS\system32\DRIVERS\umaxpcls.sys
R3 Eplpdx02;Eplpdx02;\??\C:\WINDOWS\System32\Drivers\EPLPDX02.SYS
R3 McAfeePF;McAfee Firewall Network Filter Miniport;C:\WINDOWS\system32\DRIVERS\fw220.sys
R3 Mtlmnt5;Mtlmnt5;C:\WINDOWS\system32\DRIVERS\SLDRV\Mtlmnt5.sys
R3 NaiFiltr;NaiFiltr;C:\WINDOWS\system32\DRIVERS\NaiFiltr.sys
R3 Slntamr;SmartLink AMR_PCI Driver;C:\WINDOWS\system32\DRIVERS\SLDRV\slntamr.sys
R3 SlWdmSup;SlWdmSup;C:\WINDOWS\system32\DRIVERS\SLDRV\SlWdmSup.sys
S3 MR97310_USB_DUAL_CAMERA;CIF Dual-Mode Camera;C:\WINDOWS\system32\DRIVERS\mr97310c.sys
S3 msloop;Microsoft Loopback Adapter Driver;C:\WINDOWS\system32\DRIVERS\loop.sys
S3 Mtlstrm;Mtlstrm;C:\WINDOWS\system32\DRIVERS\SLDRV\Mtlstrm.sys
S3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\system32\DRIVERS\NtApm.sys
S3 SlNtHal;SlNtHal;C:\WINDOWS\system32\DRIVERS\SLDRV\Slnthal.sys
S3 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
S4 SQLBrowser;SQL Server Browser;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe"
Contents of the 'Scheduled Tasks' folder
2007-08-10 07:01:04 C:\WINDOWS\Tasks\At1.job
2007-08-10 16:01:00 C:\WINDOWS\Tasks\At10.job
2007-08-10 17:01:02 C:\WINDOWS\Tasks\At11.job
2007-08-09 18:01:04 C:\WINDOWS\Tasks\At12.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-09 19:01:03 C:\WINDOWS\Tasks\At13.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-09 20:01:23 C:\WINDOWS\Tasks\At14.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-09 21:01:05 C:\WINDOWS\Tasks\At15.job
2007-08-09 22:01:03 C:\WINDOWS\Tasks\At16.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-09 23:01:06 C:\WINDOWS\Tasks\At17.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-10 00:01:01 C:\WINDOWS\Tasks\At18.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-10 01:00:04 C:\WINDOWS\Tasks\At19.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-10 08:01:02 C:\WINDOWS\Tasks\At2.job
2007-08-10 02:01:00 C:\WINDOWS\Tasks\At20.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-10 03:01:00 C:\WINDOWS\Tasks\At21.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-10 04:01:07 C:\WINDOWS\Tasks\At22.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-10 05:01:03 C:\WINDOWS\Tasks\At23.job
2007-08-10 06:01:02 C:\WINDOWS\Tasks\At24.job - C:\WINDOWS\system32\sbL8r776.exe
2007-08-10 09:01:06 C:\WINDOWS\Tasks\At3.job
2007-08-10 10:01:04 C:\WINDOWS\Tasks\At4.job
2007-08-10 11:01:05 C:\WINDOWS\Tasks\At5.job
2007-08-10 12:01:04 C:\WINDOWS\Tasks\At6.job
2007-08-10 13:01:05 C:\WINDOWS\Tasks\At7.job
2007-08-10 14:01:04 C:\WINDOWS\Tasks\At8.job
2007-08-10 15:01:02 C:\WINDOWS\Tasks\At9.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-10 10:28:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-10 10:32:59 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-10 10:31
C:\ComboFix2.txt ... 2007-08-09 18:58
--- E O F ---