Hi!
Here's combofix log and HJT after combofix-do
hope it helped, I didn't really inspect it
Let me know if I have to go run a regular Combofix...
Thx
PB&J
"PJ" - 2007-07-15 10:23:54 - ComboFix 07-07-10.1 - Service Pack 2
Command switches used :: C:\Documents and Settings\PJ\Desktop\Combofix-Do.txt.txt
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\ggjlm.ini
C:\WINDOWS\system32\mljgg.dll
C:\WINDOWS\system32\mljjife.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Temp
C:\WINDOWS\system32\drivers\ApiMon.sys
C:\WINDOWS\system32\mljgg.dll
C:\WINDOWS\system32\mljjife.dll
C:\WINDOWS\system32\X2
C:\WINDOWS\system32\X2\mwspasrt83122.exe
C:\WINDOWS\system32\X3
C:\WINDOWS\system32\X3\w73r.exe
C:\WINDOWS\system32\X4
C:\WINDOWS\system32\X4\wen22.exe
C:\WINDOWS\system32\X9
((((((((((((((((((((((((( Files Created from 2007-06-15 to 2007-07-15 )))))))))))))))))))))))))))))))
2007-07-14 08:38 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-06 16:42 652 --ah----- C:\aaw7boot.cmd
2007-07-04 23:07 <DIR> d-------- C:\WINDOWS\McAfee.com
2007-06-29 21:18 0 --a------ C:\WINDOWS\mozver.dat
2007-06-26 20:08 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-06-22 23:13 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-06-22 21:08 <DIR> d-------- C:\Program Files\Lavasoft
2007-06-22 21:08 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-06-22 21:07 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-06-20 11:30 0 --a------ C:\WINDOWS\nsreg.dat
2007-06-19 23:35 995,056 --a------ C:\WINDOWS\system\MSAJT200.DLL
2007-06-19 23:35 95,200 --a------ C:\WINDOWS\system\VBDB300.DLL
2007-06-19 23:35 935,632 --a------ C:\WINDOWS\system\VB40016.DLL
2007-06-19 23:35 721,168 --a------ C:\WINDOWS\system\VB40032.DLL
2007-06-19 23:35 68,444 --a------ C:\WINDOWS\system\TCLASS31.DLL
2007-06-19 23:35 398,416 --a------ C:\WINDOWS\system\VBRUN300.DLL
2007-06-19 23:35 356,992 --a------ C:\WINDOWS\system\VBRUN200.DLL
2007-06-19 23:35 271,264 --a------ C:\WINDOWS\system\VBRUN100.DLL
2007-06-19 23:35 17,424 --a------ C:\WINDOWS\system\MSAJT112.DLL
2007-06-19 23:35 154,240 --a------ C:\WINDOWS\system\OWL31.DLL
2007-06-19 23:35 143,802 --a------ C:\WINDOWS\system\BC30RTL.DLL
2007-06-19 23:35 13,410 --a------ C:\WINDOWS\system\LMITOOLS.DLL
2007-06-19 23:35 12,800 --a------ C:\WINDOWS\system\WING32.DLL
2007-06-19 23:35 <DIR> d-------- C:\SOFTKEY
2007-06-19 23:35 <DIR> d-------- C:\DOCUME~1\PJ\WINDOWS
2007-06-19 22:07 <DIR> d--hs---- C:\RECYCLER
2007-06-19 21:58 <DIR> d-------- C:\WINDOWS\ShellNew
2007-06-19 21:57 <DIR> d-------- C:\DOCUME~1\PJ\APPLIC~1\Microsoft Web Folders
2007-06-18 21:08 <DIR> d-------- C:\Program Files\Hewlett-Packard
2007-06-18 21:08 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Hewlett-Packard
2007-06-18 21:07 82,432 -ra------ C:\WINDOWS\system32\MSXML4r.dll
2007-06-18 21:07 626,960 -ra------ C:\WINDOWS\system32\hpvaut32.dll
2007-06-18 21:07 487,424 -ra------ C:\WINDOWS\system32\hpvcp70.dll
2007-06-18 21:07 44,544 -ra------ C:\WINDOWS\system32\MSXML4a.dll
2007-06-18 21:07 344,064 -ra------ C:\WINDOWS\system32\hpvcr70.dll
2007-06-18 21:07 1,230,336 -ra------ C:\WINDOWS\system32\MSXML4.dll
2007-06-18 21:06 <DIR> d-------- C:\WINDOWS\system32\URTTemp
2007-06-18 21:05 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll
2007-06-18 21:05 65,536 --a------ C:\WINDOWS\system32\HPZipm12.exe
2007-06-18 21:05 61,440 --a------ C:\WINDOWS\system32\HPZinw12.exe
2007-06-18 21:05 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll
2007-06-18 21:05 278,584 --a------ C:\WINDOWS\system32\HPZidr12.dll
2007-06-18 21:05 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll
2007-06-18 21:04 94,263 --a------ C:\WINDOWS\HPHins03.dat
2007-06-18 21:04 51,088 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2007-06-18 21:04 2,655 --------- C:\WINDOWS\hphmdl03.dat
2007-06-18 21:04 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2007-06-18 21:04 <DIR> d-------- C:\Program Files\HP
2007-06-18 21:03 270,336 -ra------ C:\WINDOWS\system32\HPZc3212.dll
2007-06-18 21:03 21,744 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2007-06-18 20:57 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2007-06-18 20:57 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-06-18 20:55 <DIR> d---s---- C:\DOCUME~1\PJ\UserData
2007-06-18 20:35 941,516 -ra------ C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2007-06-18 20:35 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2007-06-18 20:35 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-06-18 20:35 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2007-06-18 20:35 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-06-18 20:35 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2007-06-18 20:35 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2007-06-18 20:35 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2007-06-18 20:35 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-06-18 20:35 46,592 -ra------ C:\WINDOWS\SOUNDMAN.EXE
2007-06-18 20:35 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2007-06-18 20:35 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-06-18 20:35 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2007-06-18 20:35 171,776 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2007-06-18 20:35 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2007-06-18 20:35 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2007-06-18 20:32 99,328 -ra------ C:\WINDOWS\system32\drivers\e1000325.sys
2007-06-18 20:32 53,248 -ra------ C:\WINDOWS\system32\Prounstl.exe
2007-06-18 20:32 23,040 -ra------ C:\WINDOWS\system32\IntelNic.dll
2007-06-18 20:05 <DIR> d-------- C:\WINDOWS\system32\ReinstallBackups
2007-06-18 20:05 <DIR> d-------- C:\Program Files\Intel
2007-06-18 20:04 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2007-06-18 20:04 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2007-06-17 18:12 18,944 --a------ C:\WINDOWS\system32\simptcp.dll
2007-06-16 20:36 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-06-16 20:36 <DIR> d-------- C:\WINDOWS\Profiles
2007-06-16 20:36 <DIR> d-------- C:\DOCUME~1\PJ\APPLIC~1\InterTrust
2007-06-16 20:18 1,835,008 --ah----- C:\DOCUME~1\PJ\NTUSER.DAT
2007-06-16 20:15 <DIR> d-------- C:\WINDOWS\SoftwareDistribution
2007-06-16 20:15 <DIR> d-------- C:\WINDOWS\Prefetch
2007-06-16 20:14 262,144 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT
2007-06-16 20:14 262,144 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT
2007-06-16 20:11 225,280 ---h----- C:\DOCUME~1\DEFAUL~1\NTUSER.DAT
2007-06-16 20:11 0 -rahs---- C:\MSDOS.SYS
2007-06-16 20:11 0 -rahs---- C:\IO.SYS
2007-06-16 20:11 0 --a------ C:\CONFIG.SYS
2007-06-16 20:11 0 --a------ C:\AUTOEXEC.BAT
2007-06-16 20:11 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-06-16 20:11 <DIR> d-------- C:\WINDOWS\system32\xircom
2007-06-16 20:11 <DIR> d-------- C:\Program Files\microsoft frontpage
2007-06-16 20:10 112,128 --a------ C:\WINDOWS\system32\mapi32.dll
2007-06-16 20:10 <DIR> dr------- C:\WINDOWS\Offline Web Pages
2007-06-16 20:10 <DIR> d--hs---- C:\DOCUME~1\ALLUSE~1\DRM
2007-06-16 20:10 <DIR> d---s---- C:\WINDOWS\Downloaded Program Files
2007-06-16 20:09 64,512 --a------ C:\WINDOWS\system32\acctres.dll
2007-06-16 20:09 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll
2007-06-16 20:09 11,264 --a------ C:\WINDOWS\system32\atrace.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-04 19:18:48 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 19:17:02 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 19:14:56 6,272 ----a-w C:\WINDOWS\system32\drivers\AWRTPD.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2001-03-02 12:02 37808 --------- C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"zzGBK"="D:\setup.exe" []
"SoundMan"="SOUNDMAN.EXE" [2002-09-10 22:57 C:\WINDOWS\SOUNDMAN.EXE]
"HPHUPD06"="C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 00:53]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 13:38]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 04:06]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-15 10:26:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-15 10:26:47 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-15 10:26
C:\ComboFix2.txt ... 2007-07-14 08:55
--- E O F ---
Logfile of HijackThis v1.99.1
Scan saved at 10:35:23 AM, on 7/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\PJ\Desktop\scanner.exe.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [zzGBK] D:\setup.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/...067/mcfscan.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe