Here you go:
ComboFix 09-10-25.02 - Catman 10/26/2009 10:27.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1606 [GMT -7:00]
Running from: c:\documents and settings\Catman\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\components
c:\windows\system32\efhkj.bak1
c:\windows\system32\efhkj.bak2
c:\windows\system32\Ijl11.dll
c:\windows\system32\jozuzuna.dll
c:\windows\system32\logon.exe
c:\windows\system32\manujusa.dll
c:\windows\system32\mcrh.tmp
c:\windows\system32\PCLECoInst.dll
c:\windows\system32\Process.exe
c:\windows\system32\QpssYJlm.ini
c:\windows\system32\QpssYJlm.ini2
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tirobuse.dll
c:\windows\system32\vesejafu.dll
Infected copy of c:\windows\system32\drivers\vaxscsi.sys was found and disinfected
Restored copy from - Kitty ate it :p
.
((((((((((((((((((((((((( Files Created from 2009-09-26 to 2009-10-26 )))))))))))))))))))))))))))))))
.
2009-10-26 06:49 . 2009-10-26 06:49 -------- d-----w- c:\program files\Trend Micro
2009-10-26 05:41 . 2009-10-26 05:41 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-17 02:00 . 2009-10-17 02:00 -------- d-----w- c:\documents and settings\Catman\Local Settings\Application Data\Unity
2009-10-17 02:00 . 2009-10-17 02:00 -------- d-----w- c:\program files\Unity
2009-10-05 06:58 . 2009-10-05 06:58 -------- d-----w- c:\temp\MTGOInstall
2009-10-05 06:56 . 2009-10-05 06:59 -------- d-----w- c:\documents and settings\Catman\Application Data\Wizards of the Coast
2009-10-05 06:56 . 2009-10-05 06:56 -------- d-----w- c:\program files\Wizards of the Coast
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-26 06:19 . 2008-12-24 06:33 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-10-26 05:52 . 2006-10-25 22:03 -------- d-----w- c:\documents and settings\Catman\Application Data\Skype
2009-10-25 23:04 . 2008-06-08 00:22 -------- d-----w- c:\documents and settings\Catman\Application Data\skypePM
2009-10-08 06:02 . 2008-12-08 06:34 -------- d-----w- c:\documents and settings\Catman\Application Data\uTorrent
2009-10-05 06:56 . 2006-08-31 01:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-05 06:55 . 2007-09-25 05:16 -------- d-----w- c:\documents and settings\Catman\Application Data\InstallShield
2009-09-20 06:03 . 2006-11-01 02:15 -------- d-----w- c:\program files\Steam
2009-09-11 14:18 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 10:08 . 2009-03-23 04:30 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-05 08:20 . 2006-11-08 03:49 39736 ----a-w- c:\documents and settings\Catman\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-04 21:03 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-09-01 03:36 . 2009-09-01 01:57 -------- d-----w- c:\documents and settings\Catman\Application Data\Magic Set Editor
2009-09-01 01:57 . 2009-09-01 01:57 -------- d-----w- c:\program files\Magic Set Editor 2
2009-09-01 01:52 . 2009-09-01 01:52 -------- d-----w- c:\program files\CCG Maker
2009-08-29 08:08 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-04 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-17 16:00 . 2009-03-25 20:44 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-17 16:00 . 2009-03-25 20:44 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-17 16:00 . 2007-03-12 19:58 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-07 02:24 . 2006-08-31 01:40 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-07 02:24 . 2006-08-31 01:40 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-07 02:24 . 2006-08-31 05:42 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-07 02:24 . 2006-08-31 01:40 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-07 02:24 . 2006-08-31 01:40 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-07 02:24 . 2004-08-04 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-07 02:23 . 2006-08-31 01:40 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-07 02:23 . 2007-03-13 14:33 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-07 02:23 . 2006-08-31 01:40 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-07 02:23 . 2005-05-26 11:19 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 02:52 . 2009-08-05 02:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-04 15:13 . 2004-08-04 12:00 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-03 22:59 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2002-07-27 00:02 . 2008-03-24 21:39 153088 ----a-w- c:\program files\UNWISE.EXE
2007-08-13 01:37 . 2007-08-13 00:55 56 --sh--r- c:\windows\system32\4BCABED75D.sys
2008-11-15 07:54 . 2008-03-25 05:36 11690 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 23:07 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-10-24 2000112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-10-26 185896]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 77824]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-17 2025752]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-02-18 1657376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-10-24 00:30 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-17 16:00 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"=evolusbn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Autodesk\\3dsMax8\\3dsmax.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\steamapps\\wizzie55\\counter-strike\\hl.exe"=
"c:\\Program Files\\Steam\\steamapps\\wizzie55\\condition zero\\hl.exe"=
"c:\\Program Files\\EA Games\\Command and Conquer Generals\\game.dat"=
"c:\\Program Files\\KaZaA Lite\\Kazaa.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\HLServer\\hlds.exe"=
"c:\\Program Files\\Unreal Tournament 2004\\System\\UT2004X.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Multi Theft Auto\\MTAServer.exe"=
"c:\\Program Files\\Red Storm Entertainment\\RavenShield\\system\\ravenshield.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto Vice City\\gta-vc.exe"=
"c:\\Program Files\\Steam\\steamapps\\wizzie55\\team fortress classic\\hl.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Red Storm Entertainment\\RavenShield\\system\\UCC.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\TmNationsForever\\TmForever.exe"=
"c:\\Program Files\\Steam\\steamapps\\wizzie55\\ricochet\\hl.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Electronic Arts\\Red Alert 3\\Data\\ra3_1.10.game"=
"c:\\Program Files\\Electronic Arts\\Red Alert 3\\Data\\WorldBuilder.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26000:TCP"= 26000:TCP:BitComet 26000 TCP
"26000:UDP"= 26000:UDP:BitComet 26000 UDP
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/25/2009 1:44 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/25/2009 1:44 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [12/4/2008 2:50 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/4/2008 2:50 PM 74480]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [3/25/2009 1:44 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/25/2009 1:44 PM 297752]
R2 UnoInstallerService;Uno Installer;c:\program files\M-Audio Uno\UnoInst.exe [2/28/2009 4:28 PM 106496]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/4/2008 2:50 PM 7408]
S3 EVOLUSB;%EVOL_USB_SvcDesc%;c:\windows\system32\drivers\evolusb.sys [2/28/2009 4:28 PM 21984]
S3 PciCon;PciCon;\??\d:\pcicon.sys --> d:\PciCon.sys [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-10-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-12 00:57]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/uInternet Connection Wizard,ShellNext = iexplore
IE: &Search -
http://edits.mywebsearch.com/toolbaredi ... xdm025YYUSIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {7557F5AA-D486-401D-BE55-0163FA78B5B8} -
hxxps://skyfex.com/download/SkyFexExpert.cabDPF: {F84E0B64-1E86-4640-8094-5B38CEB28C1E} -
hxxps://skyfex.com/download/SkyFexClient.cabFF - ProfilePath - c:\documents and settings\Catman\Application Data\Mozilla\Firefox\Profiles\jq6y3c08.default\
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com/FF - prefs.js: keyword.URL -
hxxp://toolbar.ask.com/toolbarv/askRedi ... t=&gc=1&q=FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Catman\Application Data\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
BHO-{71dbeaca-2333-4355-ac65-f73a5adf1ff9} - jozuzuna.dll
HKLM-Run-USB2Check - c:\windows\system32\PCLECoInst.dll
HKLM-Run-tukunuyar - c:\windows\system32\kalesere.dll
HKLM-Run-gewasiwuzu - vesejafu.dll
HKCU-Explorer_Run-{D4A8FC34-08A3-1033-0320-060317060001} - c:\program files\Common Files\{D4A8FC34-08A3-1033-0320-060317060001}\Update.exe
SharedTaskScheduler-{45ec4e67-7ca2-44da-b775-8a70bdd49bd3} - c:\windows\system32\kalesere.dll
SSODL-pinibafaw-{45ec4e67-7ca2-44da-b775-8a70bdd49bd3} - c:\windows\system32\kalesere.dll
AddRemove-V-Ray for 3dsmax R8 for x86 - c:\program files\Chaos Group\V-Ray\3dsmax R8 for x86\uninstall\wininstaller.exe-uninstall=c:\program files\Chaos Group\V-Ray\3dsmax R8 for x86\uninstall\install.log
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-26 10:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1417001333-1409082233-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:f0,a0,c1,9f,5c,c1,d7,7e,cd,a4,22,99,a8,83,a6,fa,75,6c,23,b7,7f,
d9,d1,60,fc,4a,d2,35,87,29,ac,fa,66,5c,1b,48,31,a8,6d,c5,e9,cb,50,2c,a9,2c,\
"rkeysecu"=hex:ea,d2,4e,af,bc,fa,40,dd,68,93,db,19,cf,4e,1d,38
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(840)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2984)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\windows\system32\nvsvc32.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\combofix\CF9249.exe
c:\windows\system32\RUNDLL32.EXE
c:\combofix\PEV.cfxxe
.
**************************************************************************
.
Completion time: 2009-10-26 10:44 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-26 17:44
Pre-Run: 171,182,555,136 bytes free
Post-Run: 171,010,039,808 bytes free
- - End Of File - - 157212DD4824C601DEA5712D412BB5A2