here's the combofix log
ComboFix 08-11-22.02 - Admin 2008-11-23 23:18:55.1 - NTFSx86
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Admin\Cookies\anide.bin
c:\documents and settings\Admin\Cookies\anohez.scr
c:\documents and settings\Admin\Cookies\eges.dat
c:\documents and settings\Admin\Cookies\elilu.scr
c:\documents and settings\Admin\Cookies\exewylir.db
c:\documents and settings\Admin\Cookies\feme._dl
c:\documents and settings\Admin\Cookies\ihul.pif
c:\documents and settings\Admin\Cookies\inuhalixah.com
c:\documents and settings\Admin\Cookies\kamuti.reg
c:\documents and settings\Admin\Cookies\pemyhil._dl
c:\documents and settings\Admin\Cookies\ulonam.inf
c:\documents and settings\Admin\Cookies\welazaci.lib
c:\documents and settings\Admin\Cookies\wojik.vbs
c:\documents and settings\Admin\Cookies\yqyx.scr
c:\documents and settings\Admin\Cookies\yqyz.scr
c:\documents and settings\Admin\Favorites\Download programs.url
c:\documents and settings\Admin\Favorites\Games.url
c:\documents and settings\Admin\Favorites\Translator.url
c:\documents and settings\Admin\Favorites\Videos.url
c:\documents and settings\Admin\Local Settings\Temporary Internet Files\kezikapoxy.sys
c:\documents and settings\Admin\Local Settings\Temporary Internet Files\lolo._sy
c:\documents and settings\Admin\Local Settings\Temporary Internet Files\qubysev.pif
c:\program files\Antispyware
c:\program files\Antispyware\Antispyware.url
c:\program files\Antispyware\DataBase.ref
c:\program files\Antispyware\SpyCleaner.dll
c:\program files\Antispyware\TCL.dll
c:\program files\Antispyware\vistaCPtasks.xml
c:\program files\Antispyware\zlib.dll
c:\windows\brastk.exe
c:\windows\system32\abowdrhu.dll
c:\windows\system32\awllkank.ini
c:\windows\system32\awtsRiff.dll
c:\windows\system32\axquoq.dll
c:\windows\system32\bojntn.dll
c:\windows\system32\brastk.exe
c:\windows\system32\cgmjkjyi.dll
c:\windows\system32\cwfrxmus.dll
c:\windows\system32\deffluvc.dll
c:\windows\system32\DelSelf.bat
c:\windows\system32\drivers\ati4svxx.sys
c:\windows\system32\drivers\ati5dgxx.sys
c:\windows\system32\drivers\ati7bexx.sys
c:\windows\system32\drivers\tdssserv.sys
c:\windows\system32\dvrifjjh.ini
c:\windows\system32\ftuewe.dll
c:\windows\system32\fuptpoag.ini
c:\windows\system32\gehclmak.ini
c:\windows\system32\gnlpzv.dll
c:\windows\system32\grqeqq.dll
c:\windows\system32\gymfyw.dll
c:\windows\system32\hjjfirvd.dll
c:\windows\system32\irddkych.ini
c:\windows\system32\jimbkq.dll
c:\windows\system32\jogjkrbr.ini
c:\windows\system32\jsne87fidgf.dll
c:\windows\system32\knakllwa.dll
c:\windows\system32\krkmsxtc.ini
c:\windows\system32\ktyrflxc.dll
c:\windows\system32\ljgwzn.dll
c:\windows\system32\nehlhq.dll
c:\windows\system32\ntos.exe
c:\windows\system32\oqobssol.dll
c:\windows\system32\pediovmv.dll
c:\windows\system32\rs32net.exe
c:\windows\system32\rsbfjyhu.ini
c:\windows\system32\tdssadw.dll
c:\windows\system32\tdssl.dll
c:\windows\system32\tdsslog.dll
c:\windows\system32\tdssmain.dll
c:\windows\system32\tdssservers.dat
c:\windows\system32\txeyltbi.dll
c:\windows\system32\ubhvwvz.dll
c:\windows\system32\ubhvwvz32.dll
c:\windows\system32\vbyseymi.ini
c:\windows\system32\vtUolIcY.dll
c:\windows\system32\vtvdyqfr.dll
c:\windows\system32\wdnbcqgj.dll
c:\windows\system32\wini108023.exe
c:\windows\system32\wsnpoem
c:\windows\system32\wsnpoem\audio.dll
c:\windows\system32\wsnpoem\video.dll
c:\windows\system32\WvDLnUvw.ini
c:\windows\system32\wvUnMcyA.dll
c:\windows\system32\YcIloUtv.ini
c:\windows\system32\YcIloUtv.ini2
c:\windows\system32\yibdhcug.dll
c:\windows\system32\yvduru.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
-------\Legacy_ATI4SVXX
-------\Legacy_ATI5DGXX
-------\Legacy_ATI7BEXX
-------\Legacy_FCI
-------\Legacy_ICF
-------\Legacy_RESTORE
-------\Service_ati4svxx
-------\Service_ati5dgxx
-------\Service_ati7bexx
((((((((((((((((((((((((( Files Created from 2008-10-24 to 2008-11-24 )))))))))))))))))))))))))))))))
.
2008-11-23 23:38 . 2008-11-23 23:38 <DIR> d-------- c:\windows\system32\xircom
2008-11-23 23:38 . 2008-11-23 23:38 <DIR> d-------- c:\program files\microsoft frontpage
2008-11-22 12:50 . 2008-04-17 21:13 811,008 --a------ C:\gmer.exe
2008-11-20 16:14 . 2008-11-20 16:14 135,168 --a------ c:\windows\system32\drivers\ethtghgd.sys
2008-11-20 16:14 . 2008-11-20 16:14 3,584 --a------ c:\windows\xlpmohmr.exe
2008-11-20 13:56 . 2008-11-20 13:56 <DIR> d-------- c:\documents and settings\All Users\Application Data\nView_Profiles
2008-11-20 13:56 . 2008-11-20 13:56 41,472 --a------ c:\windows\system32\qoknuecr.dll
2008-11-20 13:53 . 2008-11-20 13:53 41,472 --a------ c:\windows\system32\cahyfmda.dll
2008-11-18 13:35 . 2008-11-18 13:35 41,472 --a------ c:\windows\system32\oqhleixe.dll
2008-11-17 21:13 . 2008-11-17 21:13 104,448 --a------ C:\jwwgtuh.exe
2008-11-17 21:13 . 2008-11-18 13:27 32,768 --a------ c:\windows\system32\drivers\ati2txxx.sys
2008-11-17 21:12 . 2008-11-17 21:12 50,688 --a------ C:\yjvmtaa.exe
2008-11-17 12:05 . 2008-11-17 12:05 41,472 --a------ c:\windows\system32\esdwwdfd.dll
2008-11-17 11:45 . 2008-11-17 11:45 <DIR> d-------- c:\documents and settings\Administrator\Application Data\DivX
2008-11-17 11:11 . 2008-11-17 11:20 140,288 --a------ C:\yvmkdwn.exe
2008-11-17 11:11 . 2008-11-17 11:20 50,688 --a------ C:\ruldmeb.exe
2008-11-16 20:26 . 2008-11-16 20:26 50,968 --a------ c:\windows\system32\avgfwdx.dll
2008-11-16 20:26 . 2008-11-16 20:26 29,208 --a------ c:\windows\system32\drivers\avgfwdx.sys
2008-11-16 20:17 . 2008-11-16 20:17 41,472 --a------ c:\windows\system32\bxchkbaj.dll
2008-11-16 16:27 . 2008-11-16 16:27 41,472 --a------ c:\windows\system32\bilrarhq.dll
2008-11-16 15:59 . 2008-11-16 15:59 41,472 --a------ c:\windows\system32\vjtuesyc.dll
2008-11-16 15:22 . 2008-11-16 15:22 41,472 --a------ c:\windows\system32\nwdebako.dll
2008-11-16 15:00 . 2008-11-16 15:00 19,922 --a------ c:\windows\system32\ragovemi.bin
2008-11-16 15:00 . 2008-11-16 15:00 19,776 --a------ c:\windows\safigywul._sy
2008-11-16 15:00 . 2008-11-16 15:00 19,748 --a------ c:\windows\safy._sy
2008-11-16 15:00 . 2008-11-16 15:00 18,728 --a------ c:\documents and settings\All Users\Application Data\qydoj.scr
2008-11-16 15:00 . 2008-11-16 15:00 17,721 --a------ c:\windows\system32\akohigepig._sy
2008-11-16 15:00 . 2008-11-16 15:00 15,865 --a------ c:\program files\Common Files\irudahi.exe
2008-11-16 15:00 . 2008-11-16 15:00 15,768 --a------ c:\windows\uciwemeg.dll
2008-11-16 15:00 . 2008-11-16 15:00 15,103 --a------ c:\program files\Common Files\eroj.bin
2008-11-16 15:00 . 2008-11-16 15:00 12,401 --a------ c:\documents and settings\All Users\Application Data\yhezocuwok.scr
2008-11-16 15:00 . 2008-11-16 15:00 11,665 --a------ c:\windows\system32\asomexel.reg
2008-11-16 15:00 . 2008-11-16 15:00 11,614 --a------ c:\windows\system32\fyqev.bat
2008-11-16 15:00 . 2008-11-16 15:00 10,550 --a------ c:\documents and settings\All Users\Application Data\atet.dat
2008-11-16 15:00 . 2008-11-16 15:00 10,152 --a------ c:\windows\yneko.com
2008-11-16 15:00 . 2008-11-16 15:00 10,007 --a------ c:\windows\system32\ozeji.ban
2008-11-16 14:32 . 2008-11-16 14:32 19,047 --a------ c:\program files\Common Files\ularetesy.sys
2008-11-16 14:32 . 2008-11-16 14:32 18,214 --a------ c:\windows\atyceni.pif
2008-11-16 14:32 . 2008-11-16 14:32 16,596 --a------ c:\program files\Common Files\jelanyb.vbs
2008-11-16 14:32 . 2008-11-16 14:32 16,262 --a------ c:\windows\system32\vycuvo.sys
2008-11-16 14:32 . 2008-11-16 14:32 14,287 --a------ c:\windows\wetopyqoq.reg
2008-11-16 14:32 . 2008-11-16 14:32 14,064 --a------ c:\windows\system32\ijixova.exe
2008-11-16 14:32 . 2008-11-16 14:32 13,668 --a------ c:\windows\system32\okynudaq.dat
2008-11-16 14:32 . 2008-11-16 14:32 12,587 --a------ c:\documents and settings\Admin\Application Data\ocati.dat
2008-11-16 14:32 . 2008-11-16 14:32 12,152 --a------ c:\windows\system32\imav._dl
2008-11-16 14:32 . 2008-11-16 14:32 12,035 --a------ c:\windows\system32\akorixyb.dl
2008-11-16 14:32 . 2008-11-16 14:32 11,927 --a------ c:\windows\system32\enyzy.exe
2008-11-16 14:32 . 2008-11-16 14:32 11,571 --a------ c:\program files\Common Files\olez.vbs
2008-11-16 14:32 . 2008-11-16 14:32 11,502 --a------ c:\windows\kylizulex.dll
2008-11-16 14:32 . 2008-11-16 14:32 11,141 --a------ c:\program files\Common Files\kexetuhy.scr
2008-11-16 14:32 . 2008-11-16 14:32 10,825 --a------ c:\windows\xihimyquq.sys
2008-11-16 14:27 . 2008-11-16 14:27 16,665 --a------ c:\windows\ilazobuf.reg
2008-11-16 14:27 . 2008-11-16 14:27 16,273 --a------ c:\documents and settings\All Users\Application Data\vytivyq.bat
2008-11-16 14:27 . 2008-11-16 14:27 15,538 --a------ c:\windows\system32\ydelybe.inf
2008-11-16 14:27 . 2008-11-16 14:27 15,434 --a------ c:\documents and settings\Admin\Application Data\ojypemavy.reg
2008-11-16 14:27 . 2008-11-16 14:27 15,232 --a------ c:\documents and settings\Admin\Application Data\humoly.dll
2008-11-16 14:27 . 2008-11-16 14:27 14,413 --a------ c:\documents and settings\Admin\Application Data\zafyhyqyxa.dat
2008-11-16 14:27 . 2008-11-16 14:27 14,202 --a------ c:\program files\Common Files\jamelix.bat
2008-11-16 14:27 . 2008-11-16 14:27 14,062 --a------ c:\program files\Common Files\aniw.pif
2008-11-16 14:27 . 2008-11-16 14:27 12,719 --a------ c:\windows\tyrujapabi.exe
2008-11-16 14:27 . 2008-11-16 14:27 12,569 --a------ c:\documents and settings\Admin\Application Data\dovyjir.bin
2008-11-16 14:27 . 2008-11-16 14:27 12,169 --a------ c:\windows\osuniro._sy
2008-11-16 14:27 . 2008-11-16 14:27 11,038 --a------ c:\windows\yguduki._sy
2008-11-16 14:27 . 2008-11-16 14:27 10,895 --a------ c:\documents and settings\Admin\Application Data\ysox.dll
2008-11-16 00:04 . 2008-11-16 00:04 <DIR> d-------- c:\documents and settings\Admin\Application Data\Antispyware
2008-11-15 20:07 . 2008-11-15 20:07 19,816 --a------ c:\program files\Common Files\kifak.vbs
2008-11-15 20:07 . 2008-11-15 20:07 14,845 --a------ c:\windows\system32\uwuzisihu.inf
2008-11-15 20:07 . 2008-11-15 20:07 14,655 --a------ c:\windows\yfesejyqe.inf
2008-11-15 20:07 . 2008-11-15 20:07 14,098 --a------ c:\program files\Common Files\edivyda.scr
2008-11-15 20:07 . 2008-11-15 20:07 13,903 --a------ c:\windows\ydiq.exe
2008-11-15 20:07 . 2008-11-15 20:07 12,418 --a------ c:\documents and settings\All Users\Application Data\tovyxup.sys
2008-11-15 20:07 . 2008-11-15 20:07 12,056 --a------ c:\documents and settings\All Users\Application Data\isotypokal.bin
2008-11-15 20:07 . 2008-11-15 20:07 11,390 --a------ c:\windows\system32\nysap.vbs
2008-11-15 20:07 . 2008-11-15 20:07 11,190 --a------ c:\windows\system32\ytanepype.com
2008-11-15 20:07 . 2008-11-15 20:07 10,749 --a------ c:\program files\Common Files\oqodypi.sys
2008-11-15 19:55 . 2008-11-15 20:04 73,728 --a------ c:\windows\system32\TDSScfum.dll
2008-11-15 19:55 . 2008-11-15 20:04 60,416 --a------ c:\windows\system32\drivers\TDSSpaxt.sys
2008-11-15 19:55 . 2008-11-15 20:04 35,840 --a------ c:\windows\system32\TDSSofxh.dll
2008-11-15 19:55 . 2008-11-15 20:04 31,232 --a------ c:\windows\system32\TDSSriqp.dll
2008-11-15 19:55 . 2008-11-15 20:04 29,696 --a------ c:\windows\system32\TDSSnrsr.dll
2008-11-15 19:55 . 2008-11-23 13:54 2,348 --a------ c:\windows\system32\TDSSfxmp.dll
2008-11-15 19:55 . 2008-11-15 20:04 527 --a------ c:\windows\system32\TDSSosvd.dat
2008-11-15 19:54 . 2008-11-15 19:54 104,448 --a------ C:\pqiuo.exe
2008-11-15 19:54 . 2008-11-17 21:12 2 --a------ C:\-1258302933
2008-11-15 19:29 . 2008-11-23 18:39 <DIR> d-------- c:\windows\system32\NtmsData
2008-11-15 13:27 . 2008-11-15 13:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\Nero
2008-11-14 13:12 . 2008-11-14 13:12 <DIR> d-------- c:\windows\system32\dumps
2008-11-13 23:14 . 2008-03-17 14:45 1,414,440 --a------ c:\windows\system32\ShellManager310E2D762.dll
2008-11-13 23:14 . 2008-03-11 19:30 774,144 --a------ c:\windows\system32\NEROINSTAEC43759.DB
2008-11-13 22:56 . 2008-11-13 22:56 <DIR> d-------- c:\program files\NeroInstall.bak
2008-11-13 22:47 . 2008-11-13 22:47 <DIR> d-------- c:\program files\Nero
2008-11-13 22:47 . 2008-11-15 12:55 <DIR> d-------- c:\program files\Common Files\Nero
2008-11-12 19:40 . 2008-11-12 19:40 <DIR> d-------- c:\documents and settings\Admin\Application Data\Nero
2008-11-09 17:01 . 2008-11-12 20:14 69 --a------ c:\windows\NeroDigital.ini
2008-11-09 14:35 . 2008-11-12 16:05 4,767 --a------ c:\windows\Irremote.ini
2008-11-09 14:01 . 2006-06-29 13:07 14,048 --a------ c:\windows\system32\spmsg2.dll
2008-11-08 20:35 . 2008-11-08 20:35 <DIR> d-------- c:\program files\MSXML 4.0
2008-11-08 20:35 . 2008-11-08 20:35 <DIR> d-------- c:\program files\Microsoft.NET
2008-11-08 20:20 . 2008-11-15 23:28 <DIR> d-------- c:\windows\system32\XPSViewer
2008-11-08 20:18 . 2008-11-08 20:18 <DIR> d-------- c:\program files\Reference Assemblies
2008-11-08 19:45 . 2008-11-08 20:35 <DIR> d-------- c:\documents and settings\Admin\Application Data\DNA
2008-11-06 17:18 . 2008-11-06 17:18 <DIR> d-------- c:\documents and settings\Admin\Application Data\NCH Swift Sound
2008-11-06 13:40 . 2008-11-08 20:43 <DIR> d-------- c:\program files\Yahoo!
2008-11-06 13:27 . 2001-07-06 13:41 569,344 --a------ c:\windows\system32\imagr5.dll
2008-11-06 13:27 . 2001-07-06 11:44 544,768 --a------ c:\windows\system32\imagx5.dll
2008-11-06 13:27 . 2001-07-06 17:24 283,920 --a------ c:\windows\system32\ImagXpr5.dll
2008-11-06 13:27 . 2001-06-26 07:15 38,912 --a------ c:\windows\system32\picn20.dll
2008-11-06 13:23 . 2003-03-18 21:12 1,047,552 --a------ c:\windows\system32\mfc71u.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-17 19:40 81,920 ----a-w c:\windows\DUMP2140.tmp
2008-11-17 04:24 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-11-16 23:00 15,716 ----a-w c:\program files\Common Files\ylexyheso.lib
2008-11-16 22:27 19,165 ----a-w c:\program files\Common Files\esozona.lib
2008-11-16 22:27 17,814 ----a-w c:\program files\Common Files\opaxegese.inf
2008-11-10 00:38 --------- d-----w c:\program files\EPSON Print CD
2008-11-09 01:38 --------- d-----w c:\program files\Java
2008-10-31 23:05 --------- d-----w c:\program files\CursorXP
2008-10-22 03:16 --------- d-----w c:\program files\Microsoft ActiveSync
2008-10-12 19:56 --------- d-----w c:\documents and settings\Kathleen\Application Data\CursorArts
2008-10-08 20:28 --------- d-----w c:\program files\Easy AVI Converter
2008-10-07 23:22 --------- d-----w c:\documents and settings\Admin\Application Data\CursorArts
2008-10-03 23:15 --------- d-----w c:\documents and settings\Admin\Application Data\U3
2008-09-29 05:07 2,560 -c--a-w c:\windows\_MSRSTRT.EXE
2008-09-29 05:05 --------- d-----w c:\program files\Panicware
2008-09-29 00:42 --------- d-----w c:\program files\Qimage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2006-12-07 1253376]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"CursorXP"="c:\program files\CursorXP\CursorXP.exe" [2002-06-18 78848]
"12CFG94-z641-2SF-N31P-5M1ER6H6L1"="c:\recycler\S-1-5-21-6823628786-6770986951-114503922-0511\winigon.exe" [2008-11-15 72704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"EnsoniqMixer"="c:\windows\System32\Starter.Exe" [2006-08-15 32768]
"EPSON Stylus Photo R220 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAIE.EXE" [2005-03-08 98304]
"WinampAgent"="c:\program files\Winamp\Winampa.exe" [2003-04-01 12288]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-10-22 c:\windows\system32\nvmctray.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2006-12-07 1253376]
"xlpmohmr.exe"="c:\windows\xlpmohmr.exe" [2008-11-20 3584]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2004-08-03 c:\windows\system32\advpack.dll]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
"StartMenuLogoff"= 1 (0x1)
"ForceStartMenuLogoff"= 0 (0x0)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=grqeqq.dll ftuewe.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2txxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Java\\jre1.6.0_06\\bin\\javaw.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\javaw.exe"=
"d:\\Download\\Azureus Download Client\\Azureus\\Azureus.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6881:TCP"= 6881:TCP:127.0.0.1
"49152:TCP"= 49152:TCP:BitTorrent
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-17 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-17 20560]
S0 ati2txxx;ati2txxx;c:\windows\system32\Drivers\ati2txxx.sys [2008-11-17 32768]
S1 ethtghgd;ethtghgd;c:\windows\system32\drivers\ethtghgd.sys [2008-11-20 135168]
S2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe []
S3 Avgfwdx;Avgfwdx;c:\windows\system32\DRIVERS\avgfwdx.sys [2008-11-16 29208]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwdx.sys [2008-11-16 29208]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{21066d00-919e-11dd-83f1-00105a3e9c13}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Windows Sidebar]
c:\windows\system32\hidec /W c:\vaio\Tools\REGTLIB.EXE "c:\program files\Windows Sidebar\sidebar.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{34A19196-274E-4D75-9D30-D7A45A0A4178}]
"c:\program files\Windows Sidebar\.\regsvr32.exe" /s wlsrvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6B9228DA-9C15-419e-856C-19E768A13BDC}]
"c:\program files\Windows Sidebar\.\regsvr32.exe" /s sbdrop.dll
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BADA65A0-86B7-462B-B720-CE66655C73F5}]
regsvr32 /s c:\vaio\.\vshellext.dll
.
Contents of the 'Scheduled Tasks' folder
2008-11-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe []
.
- - - - ORPHANS REMOVED - - - -
BHO-{0DF62760-B636-4CD1-907B-DA27833E9553} - c:\windows\system32\vtUolIcY.dll
BHO-{5600363C-B1A7-464C-9D48-B57A901A74FA} - c:\windows\system32\awtsRiff.dll
HKCU-Run-SureCleanProfessional - c:\progra~1\PANICW~1\SURECL~1\SRClean.exe
HKCU-Run-rs32net - c:\windows\System32\rs32net.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero BackItUp 4\NBKeyScan.exe
HKLM-Run-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
HKLM-Run-b4ffd284 - c:\windows\system32\ctxsmkrk.dll
HKU-Default-Run-brastk - c:\windows\system32\brastk.exe
ShellExecuteHooks-{5600363C-B1A7-464C-9D48-B57A901A74FA} - c:\windows\system32\awtsRiff.dll
Notify-WgaLogon - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\46u2dvfp.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US

fficial
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-23 23:38:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(804)
c:\windows\system32\rsaenh.dll
- - - - - - - > 'lsass.exe'(860)
c:\windows\system32\msprivs.dll
c:\windows\system32\rsaenh.dll
.
------------------------ Other Running Processes ------------------------
.
d:\avast 4\aswUpdSv.exe
d:\avast 4\ashServ.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
d:\avast 4\ashMaiSv.exe
d:\avast 4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-11-23 23:41:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-24 07:41:49
Pre-Run: 7,554,572,288 bytes free
Post-Run: 11,389,046,784 bytes free
371 --- E O F --- 2008-05-25 23:04:59