Ok, here is the combofix log:
ComboFix 08-01-10.2 - Lestat 2008-01-11 15:47:01.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.243 [GMT -8:00]
Running from: C:\Documents and Settings\Lestat\Desktop\ComboFix.exe
Command switches used :: and Settings\Lestat\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data.\mtmjmtuz.dll
C:\Documents and Settings\Lestat\Desktop\Progfangs\Temizle\2\AVG Anti-Spyware 7.5\avgas.exe
C:\Documents and Settings\Lestat\Desktop\Progfangs\Temizle\Comodo\BOC425 .EXE
C:\Documents and Settings\Lestat\Desktop\Progfangs\Unlocker\UnlockerAssistant .exe
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\gebyw.dll
C:\WINDOWS\system32\gebyw.exe
C:\WINDOWS\system32\ownbulqn.dll
C:\WINDOWS\system32\wybeg.ini
C:\WINDOWS\system32\wybeg.ini2
Code:
<pre>
C:\Documents and Settings\Lestat\Desktop\Progfangs\Temizle\Comodo\BOC425 .EXE ---> QooBox
C:\Documents and Settings\Lestat\Desktop\Progfangs\Unlocker\UnlockerAssistant .exe ---> QooBox
C:\Documents and Settings\Lestat\Desktop\Progfangs\Unlocker\UnlockerAssistant .exe ---> UnlockerAssistant.exe
C:\Documents and Settings\Lestat\Desktop\Progfangs\Unlocker\UnlockerAssistant .exe ---> UnlockerAssistant.exe
C:\Documents and Settings\Lestat\Desktop\Progfangs\Unlocker\UnlockerAssistant .exe ---> UnlockerAssistant.exe
</pre>
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-12-11 to 2008-01-11 )))))))))))))))))))))))))))))))
.
2008-01-11 05:00 . 2008-01-11 05:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-11 05:00 . 2007-05-30 04:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-11 04:55 . 2008-01-11 04:55 2,472 --a------ C:\clean.bat
2008-01-11 00:21 . 2008-01-11 06:34 354 --ahs---- C:\WINDOWS\system32\bdcjxnhm.ini
2008-01-10 18:00 . 2008-01-10 18:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-10 11:47 . 2007-04-01 21:58 546,304 --a------ C:\WINDOWS\system32\SETC8.tmp
2008-01-10 09:14 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-10 05:59 . 2008-01-10 05:59 1,158 --a------ C:\WINDOWS\mozver.dat
2008-01-10 05:53 . 2008-01-10 05:53 0 --a------ C:\WINDOWS\nsreg.dat
2008-01-09 15:40 . 2008-01-09 18:20 414 --ahs---- C:\WINDOWS\system32\juxmvpts.ini
2008-01-08 06:42 . 2008-01-08 06:42 183,808 --a------ C:\WINDOWS\system32\drivers\Nyhv71.sys.ren
2008-01-07 23:30 . 2008-01-08 06:42 183,808 --a------ C:\WINDOWS\system32\drivers\symavc32.sys.ren
2008-01-07 23:17 . 2008-01-07 23:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-07 23:16 . 2005-08-25 18:18 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2008-01-07 23:16 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-01-07 15:38 . 2008-01-07 15:38 294 --ahs---- C:\WINDOWS\system32\nblsvfhm.ini
2008-01-07 03:44 . 2008-01-07 03:55 250 --a------ C:\WINDOWS\gmer.ini
2008-01-07 03:03 . 2008-01-07 03:06 <DIR> d-------- C:\Program Files\Panda Security
2008-01-07 02:32 . 2008-01-10 17:59 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-06 22:14 . 2007-12-31 19:28 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-01-06 03:40 . 2008-01-06 03:40 294 --ahs---- C:\WINDOWS\system32\wnjohljb.ini
2008-01-06 03:37 . 2008-01-06 03:37 75,840 --a------ C:\WINDOWS\system32\kyeolesd.dll
2008-01-05 20:42 . 2001-05-11 13:18 420,240 --a------ C:\WINDOWS\system32\mpg4c32.dll
2008-01-05 20:42 . 2001-03-26 04:41 245,760 --a------ C:\WINDOWS\system32\mp4sds32.ax
2008-01-05 20:40 . 2008-01-05 20:41 <DIR> d-------- C:\WINDOWS\system32\RMBin
2008-01-05 06:04 . 2008-01-05 06:06 <DIR> d-------- C:\My Documents
2008-01-04 18:16 . 2004-08-03 23:56 135,680 --a------ C:\taskmgr.exe
2008-01-04 18:13 . 2008-01-04 18:13 583 --a------ C:\Shortcut to taskmgr.lnk
2008-01-04 16:55 . 2007-02-28 01:08 2,136,064 --a------ C:\WINDOWS\system32\ntoskrnl.exe
2008-01-04 16:55 . 2007-02-28 01:08 2,136,064 --a--c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-01-04 04:26 . 2008-01-04 11:52 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-01-04 04:21 . 2008-01-04 04:21 474 --a------ C:\WINDOWS\otstuk.tmp
2008-01-04 04:20 . 2008-01-04 04:20 2 --a------ C:\WINDOWS\uid.tmp
2008-01-04 03:37 . 2008-01-05 05:23 594 --ahs---- C:\WINDOWS\system32\xhkygacd.ini
2008-01-03 21:46 . 2008-01-07 23:30 <DIR> d-------- C:\Program Files\Anti-Malware
2008-01-03 21:15 . 2008-01-03 21:15 354 --ahs---- C:\WINDOWS\system32\shrxcrmt.ini
2008-01-03 18:43 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-01-03 18:38 . 2004-08-03 23:56 22,528 --a------ C:\WINDOWS\system32\wsock32.dlb
2008-01-03 18:37 . 2008-01-03 21:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BOC425
2008-01-03 18:37 . 2007-11-26 10:38 238,848 --a------ C:\WINDOWS\UNBOC.EXE
2008-01-03 18:37 . 2007-05-08 17:01 208,896 --a------ C:\WINDOWS\CMDLIC.DLL
2008-01-03 18:37 . 2008-01-07 02:56 941 --a------ C:\WINDOWS\BOC425.INI
2008-01-02 08:53 . 2008-01-02 08:53 294 --ahs---- C:\WINDOWS\system32\xjwrbgoj.ini
2008-01-01 15:49 . 2008-01-10 05:50 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-01 15:49 . 2008-01-10 05:50 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-01 15:49 . 2008-01-10 05:50 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-01 15:49 . 2008-01-10 05:50 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-01 13:29 . 2008-01-01 13:29 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-01 13:29 . 2008-01-01 13:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-01 03:52 . 2008-01-05 07:28 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-01-01 00:36 . 2008-01-01 00:36 <DIR> d-------- C:\WINDOWS\McAfee.com
2007-12-31 19:27 . 2007-12-31 19:27 <DIR> d-------- C:\WINDOWS\Sun
2007-12-31 19:27 . 2008-01-07 23:05 <DIR> d-------- C:\Documents and Settings\Lestat\.housecall6.6
2007-12-31 16:57 . 2008-01-07 23:30 <DIR> d-------- C:\Program Files\ewido anti-malware
2007-12-31 15:55 . 2007-12-31 15:55 <DIR> d-------- C:\WINDOWS\tsqwqcfw
2007-12-31 15:55 . 2008-01-03 07:33 <DIR> d-------- C:\WINDOWS\KB628926
2007-12-31 05:45 . 2007-12-31 05:51 <DIR> d-------- C:\Program Files\Play65
2007-12-29 23:14 . 2007-12-29 23:14 <DIR> d-------- C:\Program Files\Common Files\Adobe
2007-12-28 02:59 . 2007-12-28 02:59 <DIR> d-------- C:\Program Files\InstallPlay65
2007-12-25 13:11 . 2004-08-03 23:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-12-25 02:15 . 2007-12-25 02:15 <DIR> d-------- C:\Program Files\Vstplugins
2007-12-24 17:27 . 2007-12-24 17:27 <DIR> d-------- C:\WINDOWS\uninstall\Qabalah Trainer V 2.00
2007-12-24 17:27 . 2007-12-24 17:27 <DIR> d-------- C:\WINDOWS\uninstall
2007-12-24 17:27 . 2007-12-24 17:27 0 --a------ C:\WINDOWS\system32\kabbtree.reg
2007-12-24 17:26 . 2000-12-06 00:00 209,608 --a------ C:\WINDOWS\system32\Tabctl32.ocx
2007-12-24 17:26 . 2007-07-27 13:05 203,976 --a------ C:\WINDOWS\system32\Richtx32.ocx
2007-12-24 17:26 . 1999-05-07 00:00 140,288 --a------ C:\WINDOWS\system32\Comdlg32.ocx
2007-12-24 17:25 . 2007-12-24 17:28 98 --a------ C:\WINDOWS\ANS2000.INI
2007-12-24 17:25 . 2007-12-24 17:25 20 --ah----- C:\WINDOWS\akebook.ini
2007-12-24 17:25 . 2007-12-24 17:25 4 --ah----- C:\WINDOWS\a3kebook.ini
2007-12-24 12:24 . 2006-04-26 13:00 8,167,424 --a------ C:\WINDOWS\system32\ATLANTIS 3D SCREENSAVER.BAK
2007-12-24 12:22 . 2006-04-26 13:00 8,167,424 --a------ C:\WINDOWS\system32\Atlantis 3D Screensaver.scr
2007-12-24 12:22 . 2006-04-26 12:59 3,197 --a------ C:\WINDOWS\system32\Atlantis3DScreensaver.html
2007-12-23 04:06 . 2007-12-23 04:06 <DIR> d-------- C:\Documents and Settings\Lestat\Incomplete
2007-12-23 04:04 . 2008-01-04 01:58 <DIR> d-------- C:\Program Files\Java
2007-12-23 04:04 . 2007-12-23 04:04 <DIR> d-------- C:\Program Files\Common Files\Java
2007-12-23 04:04 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-23 03:10 . 2007-12-23 03:49 36 --a------ C:\Documents and Settings\Lestat\klextlock.dat
2007-12-23 03:01 . 2007-12-23 03:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kazaa Lite
2007-12-22 21:11 . 2008-01-11 14:36 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-22 21:11 . 2007-12-22 21:11 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-22 21:10 . 2007-12-22 21:10 <DIR> d-------- C:\Program Files\iPod
2007-12-22 21:08 . 2008-01-04 13:50 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-12-22 21:08 . 2008-01-01 06:09 <DIR> d-------- C:\Program Files\QuickTime
2007-12-22 21:08 . 2007-12-22 21:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-21 22:16 . 2004-08-20 14:56 57,151 --a------ C:\WINDOWS\system32\igfx.hlp
2007-12-21 21:18 . 2006-08-21 01:14 128,896 -----c--- C:\WINDOWS\system32\dllcache\fltmgr.sys
2007-12-21 21:18 . 2006-08-21 01:14 23,040 -----c--- C:\WINDOWS\system32\dllcache\fltmc.exe
2007-12-21 21:18 . 2006-08-21 04:21 16,896 -----c--- C:\WINDOWS\system32\dllcache\fltlib.dll
2007-12-21 21:09 . 2007-07-09 05:09 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-12-21 19:46 . 1998-09-02 00:02 194,320 --a------ C:\WINDOWS\system32\qcut.dll
2007-12-21 19:46 . 1998-08-26 20:51 182,032 --a------ C:\WINDOWS\system32\dxtmsft3.dll
2007-12-21 19:46 . 1998-08-20 03:02 140,800 --a------ C:\WINDOWS\system32\tm20dec.ax
2007-12-21 19:46 . 1998-09-02 00:28 63,488 --a------ C:\WINDOWS\system32\unam4ie.exe
2007-12-21 19:46 . 1998-09-02 00:28 38,160 --a------ C:\WINDOWS\system32\LMRTREND.dll
2007-12-21 19:46 . 1998-08-17 01:21 11,776 --a------ C:\WINDOWS\system32\mciqtz.drv
2007-12-21 19:46 . 1998-08-17 01:21 10,240 --a------ C:\WINDOWS\system32\vidx16.dll
2007-12-21 19:46 . 1998-08-17 01:21 5,672 --a------ C:\WINDOWS\system32\quartz.vxd
2007-12-21 19:46 . 2007-12-21 19:46 4,608 --a------ C:\WINDOWS\system32\w95inf32.dll
2007-12-21 19:46 . 2007-12-21 19:46 2,272 --a------ C:\WINDOWS\system32\w95inf16.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-21 23:59 315,392 ----a-w C:\WINDOWS\HideWin.exe
2007-12-19 02:49 --------- d-----w C:\Program Files\microsoft frontpage
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-25 18:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
.
Code:
<pre>
----a-w 1,318,912 2008-01-09 00:05:06 C:\Documents and Settings\Lestat\Desktop\Progfangs\Temizle\2\SUPERAntiSpyware\SUPERAntiSpyware .exe
----a-w 1,038,336 2008-01-11 12:49:41 C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{76ad6002-1dd2-11b2-9391-c40bb9df0f00}]
C:\WINDOWS\turgjyza.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nntime.exe"="nntime.exe" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [ ]
"SUPERAntiSpyware"="C:\Documents and Settings\Lestat\Desktop\Progfangs\Temizle\2\SUPERAntiSpyware\SUPERAntiSpyware.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 15:03 16125440 C:\WINDOWS\RTHDCPL.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [ ]
"iTunesHelper"="C:\Documents and Settings\Lestat\Desktop\Progfangs\iTunes\iTunesHelper.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [ ]
"drmsrv32"="C:\tshl.exe" [ ]
"UnlockerAssistant"="C:\Documents and Settings\Lestat\Desktop\Progfangs\Unlocker\UnlockerAssistant .exe" [ ]
"License"="locker.exe" []
"!AVG Anti-Spyware"="C:\Documents and Settings\Lestat\Desktop\Progfangs\Temizle\2\AVG Anti-Spyware 7.5\avgas.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingA1836"="command /c del C:\WINDOWS\SchedLgU.Txt_tobedeleted" [ ]
"SpybotDeletingC5923"="cmd /c del C:\WINDOWS\SchedLgU.Txt_tobedeleted" [ ]
"SpybotDeletingA2356"="command /c del C:\WINDOWS\system32\gebyw.dll_tobedeleted" [ ]
"SpybotDeletingC1994"="cmd /c del C:\WINDOWS\system32\gebyw.dll_tobedeleted" [ ]
"SpybotSnD"="C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" [2004-05-12 01:03 3948032]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Documents and Settings\Lestat\Desktop\Progfangs\Temizle\2\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Documents and Settings\Lestat\Desktop\Progfangs\Temizle\2\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Documents and Settings\Lestat\Desktop\Progfangs\Temizle\2\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dbgeng32]
dbgeng32.dll 2004-11-05 02:35 8192 C:\WINDOWS\system32\dbgeng32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hggedax]
hggedax.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrnt32]
winrnt32.dll
SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"
R1 ewido security suite driver;ewido security suite driver;C:\Program Files\ewido anti-malware\guard.sys [2005-12-30 03:12]
R3 BOCDRIVE;BOClean Kernel Monitor.;C:\Documents and Settings\Lestat\Desktop\Progfangs\Temizle\Comodo\BOCDRIVE.sys [2007-04-17 14:14]
*Newly Created Service* - AVGASCLN
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-11 15:55:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-11 16:03:34 - machine was rebooted [Lestat]
ComboFix-quarantined-files.txt 2008-01-12 00:03:14
.
2008-01-10 19:53:54 --- E O F ---