Her er Combofix:
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\pskt.ini
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\OqBHOqru.ini
C:\WINDOWS\system32\OqBHOqru.ini2
C:\WINDOWS\system32\taskmgr.com
C:\WINDOWS\system32\yadKSvut.ini
C:\WINDOWS\system32\yadKSvut.ini2
.
((((((((((((((((((((((((( Files Created from 2008-04-04 to 2008-05-04 )))))))))))))))))))))))))))))))
.
2008-05-04 11:07 . 2008-05-04 11:07 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-05-04 10:40 . 2008-05-04 11:44 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-05-04 10:40 . 2008-05-04 10:40 <DIR> d-------- C:\Documents and Settings\Jakob\Application Data\SUPERAntiSpyware.com
2008-05-04 10:40 . 2008-05-04 10:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-05-04 09:55 . 2008-05-04 09:55 <DIR> d-a------ C:\WINDOWS\zts2.exe
2008-05-04 09:55 . 2008-05-04 09:55 <DIR> d-a------ C:\WINDOWS\system32\vcmgcd32.dll
2008-05-04 09:55 . 2008-05-04 09:55 <DIR> d-a------ C:\WINDOWS\system32\iifgfgf.dll
2008-05-04 09:55 . 2008-05-04 09:55 <DIR> d-a------ C:\WINDOWS\rundll16.exe
2008-05-04 09:55 . 2008-05-04 09:55 <DIR> d-a------ C:\WINDOWS\rundl132.dll
2008-05-04 09:55 . 2008-05-04 09:55 <DIR> d-a------ C:\WINDOWS\logo1_.exe
2008-05-04 09:51 . 2004-08-04 09:56 146,432 --a------ C:\WINDOWS\R.COM
2008-05-04 09:51 . 2004-08-04 09:56 135,680 --a------ C:\WINDOWS\system32\T.COM
2008-05-04 09:51 . 2008-05-04 09:55 50 --a------ C:\WINDOWS\Lic.xxx
2008-05-04 09:43 . 2008-05-04 09:45 <DIR> d-------- C:\Downloads
2008-05-04 09:43 . 2008-05-04 09:45 <DIR> d-------- C:\Bases
2008-05-04 08:50 . 2008-05-04 08:51 153 --a------ C:\WINDOWS\wininit.ini
2008-05-04 08:19 . 2008-05-04 08:18 691,545 --a------ C:\WINDOWS\unins000.exe
2008-05-04 08:19 . 2008-05-04 08:19 2,545 --a------ C:\WINDOWS\unins000.dat
2008-05-04 08:09 . 2008-05-04 08:44 109,802 --a------ C:\WINDOWS\BM337b5edc.xml
2008-05-03 18:38 . 2008-05-04 09:25 <DIR> d-------- C:\VundoFix Backups
2008-05-03 16:16 . 2008-05-03 16:15 147,456 --a------ C:\VundoFix.exe
2008-05-03 13:38 . 2003-09-22 17:01 11,520 --a------ C:\WINDOWS\system32\drivers\WDMSTUB.sys
2008-05-03 13:16 . 2008-05-03 13:16 <DIR> d-------- C:\Garmin
2008-05-03 13:16 . 2006-02-20 20:25 17,536 -ra------ C:\WINDOWS\system32\drivers\grmn0200.sys
2008-05-03 13:16 . 2006-04-11 21:51 16,512 -ra------ C:\WINDOWS\system32\drivers\grmn0400.sys
2008-05-03 13:16 . 2006-07-11 21:50 11,776 -ra------ C:\WINDOWS\system32\drivers\grmn1200.sys
2008-04-06 14:12 . 2008-05-04 12:12 <DIR> d-------- C:\Documents and Settings\Jakob\Application Data\OpenOffice.org2
2008-04-06 14:09 . 2008-04-06 14:10 <DIR> d-------- C:\Program Files\OpenOffice.org 2.4
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-04 10:12 --------- d-----w C:\Program Files\Microsoft AntiSpyware
2008-05-04 09:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-04 08:37 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-04 07:25 --------- d-----w C:\Program Files\PowerISO
2008-05-04 06:20 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-03 12:14 --------- d-----w C:\Documents and Settings\Jakob\Application Data\uTorrent
2008-05-03 11:46 --------- d-----w C:\Documents and Settings\Jakob\Application Data\ZipGenius
2008-04-21 17:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition classic
2008-04-10 06:27 --------- d-----w C:\Program Files\Java
2008-04-06 11:32 26,416 ----a-w C:\Documents and Settings\Jakob\Application Data\GDIPFONTCACHEV1.DAT
2007-10-19 17:43 30 ----a-w C:\Program Files\Exiferupdate.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{57976EAA-5B45-457C-8083-014C8DDE215D}]
C:\WINDOWS\system32\tuvSKday.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c65d096e-9808-41f7-a958-3cf65637947b}]
C:\WINDOWS\system32\hnuagihx.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:56 15360]
"NBJ"="D:\Programmer\Ahead\Nero BackItUp\NBJ.exe" [2004-09-07 21:55 1871872]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 16:03 1481968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-12-21 02:12 131072]
"ATIPTA"="d:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-24 21:05 344064]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 12:20 77824 C:\WINDOWS\SOUNDMAN.EXE]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 20:50 155648]
"gcasServ"="C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" [2005-11-15 13:12 473928]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-20 16:22 262401]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [ ]
"BM337b5edc"="C:\WINDOWS\system32\bsyekbqx.dll" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 09:56 15360]
C:\Documents and Settings\Jakob\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-08-23 02:04:00 98304]
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-03-16 17:54:44 393216]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04 83360]
Monitor Apache Servers.lnk - D:\Programmer\Apache Group\Apache2\bin\ApacheMonitor.exe [2005-02-10 15:12:16 41042]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{C1A8B6A1-2C81-1C3D-A3C6-A1CCDB10B47F}"= C:\WINDOWS\SYSTEM32\IOCTRL.DLL [ ]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"D:\\Programmer\\Apache Group\\Apache2\\bin\\Apache.exe"=
"D:\\Programmer\\Macromedia\\Flash MX\\Flash.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Age Of Empires II\\age2_x1.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1607:UDP"= 1607:UDP:Windows Media Format SDK (firefox.exe)
"1606:UDP"= 1606:UDP:Windows Media Format SDK (firefox.exe)
R0 avgntmgr;avgntmgr;C:\WINDOWS\system32\drivers\avgntmgr.sys [2008-04-20 16:22]
R1 avgntdd;avgntdd;C:\WINDOWS\system32\DRIVERS\avgntdd.sys [2008-04-20 16:22]
R2 devdpl;devdpl;C:\WINDOWS\system32\DRIVERS\devdpl.sys [2002-11-12 12:12]
R2 litdpl;litdpl;C:\WINDOWS\system32\DRIVERS\litdpl.sys [2002-11-12 12:12]
R2 P1C1394;Phase One 1394 Camera Driver;C:\WINDOWS\system32\Drivers\p1c1394.sys [2003-10-15 12:46]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6b71365e-119e-11da-be0e-806d6172696f}]
\Shell\AutoRun\command - H:\ASUSACPI.exe
*Newly Created Service* - SASDIFSV
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-04 12:19:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySQL]
"ImagePath"="\"C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt\" --defaults-file=\"C:\Program Files\MySQL\MySQL Server 4.1\my.ini\" MySQL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
Completion time: 2008-05-04 12:23:12
ComboFix-quarantined-files.txt 2008-05-04 10:22:09
Pre-Run: 4,932,218,880 bytes free
Post-Run: 4,921,286,656 bytes free