Below are the result copy of the ComboFix log:
ComboFix 08-08-03.03 - anton 2008-08-04 12:23:01.1 - NTFSx86
Microsoft(R) Windows(R) Server 2003, Standard Edition 5.2.3790.1.1252.1.1033.18.1414 [GMT 7:00]
Running from: C:\Documents and Settings\anton\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\dns.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DNS
-------\Service_DNS
((((((((((((((((((((((((( Files Created from 2008-07-04 to 2008-08-04 )))))))))))))))))))))))))))))))
.
2008-07-31 17:08 . 2008-07-31 17:08 <DIR> d-------- C:\WINDOWS\Sun
2008-07-31 17:05 . 2008-07-31 17:05 <DIR> d-------- C:\Program Files\Sun
2008-07-31 17:04 . 2008-06-10 02:32 73,728 --------- C:\WINDOWS\system32\javacpl.cpl
2008-07-31 17:03 . 2008-07-31 17:04 <DIR> d-------- C:\Program Files\Java
2008-07-31 16:47 . 2008-07-31 16:47 <DIR> d-------- C:\Program Files\Common Files\Java
2008-07-31 15:17 . 2008-07-31 15:17 <DIR> d-------- C:\Program Files\SlimBrowser
2008-07-31 15:17 . 2008-07-31 15:33 <DIR> d-------- C:\Documents and Settings\anton\Application Data\SlimBrowser
2008-07-31 13:25 . 2008-07-31 13:25 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-25 12:08 . 2008-07-25 12:08 34 --------- C:\null
2008-07-22 19:20 . 2008-07-22 19:20 <DIR> d-------- C:\Documents and Settings\teddy\Application Data\ESTsoft
2008-07-13 13:00 . 2008-07-13 13:00 69 --------- C:\WINDOWS\NeroDigital.ini
2008-07-12 09:18 . 2008-07-12 09:18 <DIR> d-------- C:\Documents and Settings\billy\Application Data\ESTsoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-01 06:27 --------- d-----w C:\Program Files\Radmin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Realtime Monitor"="C:\PROGRA~1\CA\ETRUST~1\realmon.exe" [2004-04-06 17:14 504080]
"NeroFilterCheck"="C:\Documents and Settings\Administrator\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"openvpn-gui"="C:\Program Files\OpenVPN\bin\openvpn-gui.exe" [2005-08-18 15:55 99328]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"CPQTEAM"="cpqteam.exe" [2006-07-19 04:43 90214 C:\WINDOWS\system32\cpqteam.exe]
C:\Documents and Settings\anton\Start Menu\Programs\Startup\
Karen's Replicator.lnk - C:\Program Files\Karen's Power Tools\Replicator\PTReplicator.exe [2005-11-19 16:17:39 976608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ShowSuperHidden"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,32,\
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, pwdssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]
@="Driver"
R0 cpqcissm;cpqcissm;C:\WINDOWS\system32\drivers\cpqcissm.sys [2006-05-19 12:12]
R0 DfsDriver;DfsDriver;C:\WINDOWS\system32\drivers\Dfs.sys [2006-03-22 19:00]
R2 DHCPServer;DHCP Server;C:\WINDOWS\system32\tcpsvcs.exe [2006-03-22 19:00]
R2 IsmServ;Intersite Messaging;C:\WINDOWS\System32\ismserv.exe [2006-03-22 19:00]
R2 kdc;Kerberos Key Distribution Center;C:\WINDOWS\System32\lsass.exe [2006-03-22 19:00]
R2 MSSEARCH;Microsoft Search;C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe [2004-10-12 22:10]
R2 NtFrs;File Replication Service;C:\WINDOWS\system32\ntfrs.exe [2006-03-22 19:00]
R2 r_server;Remote Administrator Service;C:\WINDOWS\system32\r_server.exe [2001-07-24 03:00]
R2 TermServLicensing;Terminal Server Licensing;C:\WINDOWS\system32\lserver.exe [2006-03-22 19:00]
R3 ati2mpad;ati2mpad;C:\WINDOWS\system32\DRIVERS\ati2mpad.sys [2005-03-25 00:55]
R3 cpqasm2;cpqasm2;C:\WINDOWS\system32\DRIVERS\cpqasm2.sys [2006-07-14 13:57]
R3 CpqCiDrv;HP iLO Management Channel Interface Driver;C:\WINDOWS\system32\DRIVERS\cpqcidrv.sys [2006-03-10 13:40]
R3 CPQCISSE;CPQCISSE;C:\WINDOWS\system32\DRIVERS\CPQCISSE.sys [2006-06-16 12:13]
R3 q57w2k;HP NC7782 Gigabit Server Adapter;C:\WINDOWS\system32\DRIVERS\q57xp32.sys [2006-08-16 00:47]
R3 sysmgmt;HP ProLiant System Management Interface Driver;C:\WINDOWS\system32\DRIVERS\sysmgmt.sys [2006-07-14 13:57]
R3 tap0801;TAP-Win32 Adapter V8;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2004-06-24 08:54]
S3 CPQTeam;HP Network Configuration Utility;C:\WINDOWS\system32\DRIVERS\cpqteam.sys [2006-07-19 04:00]
S3 RSoPProv;Resultant Set of Policy Provider;C:\WINDOWS\system32\RSoPProv.exe [2006-03-22 19:00]
S3 sacsvr;Special Administration Console Helper;C:\WINDOWS\System32\svchost.exe [2006-03-22 19:00]
S3 WLBS;Network Load Balancing;C:\WINDOWS\system32\DRIVERS\wlbs.sys [2006-03-22 19:00]
S4 ClusDisk;Cluster Disk Driver;C:\WINDOWS\system32\DRIVERS\ClusDisk.sys [2006-03-22 19:00]
S4 startdss;HP ProLiant Virtual Install Disk Support Driver;C:\WINDOWS\system32\drivers\startdss.sys []
S4 TrkSvr;Distributed Link Tracking Server;C:\WINDOWS\system32\svchost.exe [2006-03-22 19:00]
S4 Tssdis;Terminal Services Session Directory;C:\WINDOWS\System32\tssdis.exe [2006-03-22 19:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WinErr REG_MULTI_SZ ERsvc
DcomLaunch REG_MULTI_SZ DcomLaunch
tapisrv REG_MULTI_SZ Tapisrv
regsvc REG_MULTI_SZ RemoteRegistry
swprv REG_MULTI_SZ swprv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
AeLookupSvc
AppMgmt
AudioSrv
Browser
CryptSvc
DMServer
HidServ
LanmanServer
LanmanWorkstation
Messenger
Nla
NWCWorkstation
Sacsvr
Schedule
Seclogon
Themes
TrkWks
TrkSvr
Wmi
WmdmPmSp
winmgmt
xmlprov
BITS
wuauserv
ShellHWDetection
helpsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##200.200.200.32#c$#office2003]
\Shell\AutoRun\command - Z:\SETUP.EXE /AUTORUN
\Shell\configure\command - Z:\SETUP.EXE
\Shell\install\command - Z:\SETUP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1A7-37EF-4b3f-8CFC-4F3A74704073}]
%SystemRoot%\system32\rundll32.exe iesetup.dll,IEHardenAdmin
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1A8-37EF-4b3f-8CFC-4F3A74704073}]
%SystemRoot%\system32\rundll32.exe iesetup.dll,IEHardenUser
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = about:blank
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://royal2/
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O17 -: HKLM\CCS\Interface\{9B193DBD-1BC2-4AC0-B99B-5522A567F26A}: NameServer = 127.0.0.1
O17 -: HKLM\CCS\Interface\{9FFE5A69-055C-458D-9ACD-D481A72E732F}: NameServer = 192.168.8.1
O17 -: HKLM\CCS\Interface\{AE90BA15-9B3A-4E3C-A21C-E26E7904F1DA}: NameServer = 172.20.20.1
O18 -: Handler: hpapp - {24F45006-5BD9-41B7-9BD9-5F8921C8EBD1} - C:\Program Files\Compaq\Cpqacuxe\Bin\hpapp.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-04 12:31:35
Windows 5.2.3790 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\tsd32.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\system32\CpqRcmc.exe
C:\WINDOWS\system32\dfssvc.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\hp\hpsmh\bin\smhstart.exe
C:\hp\hpsmh\bin\hpsmhd.exe
C:\WINDOWS\system32\sysdown.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\hp\hpsmh\bin\hpsmhd.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\hp\hpsmh\bin\rotatelogs.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\rdpclip.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
.
**************************************************************************
.
Completion time: 2008-08-04 12:32:25 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-04 05:32:22
Pre-Run: 34,497,806,336 bytes free
Post-Run: 34,599,141,376 bytes free
178