My fault that I didn’t copy the whole file here is the missing part…I think …Can’t post the whole thing as it exceeds 10000 characters
have a look at this
ComboFix 08-01-23.1B - Owner 2008-01-24 16:30:19.3 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
- Created a new restore point
FILE
C:\WINDOWS{6D6196E7-5EBD-4F4F-9466-E72126CB61BD}.dat
C:\WINDOWS{D90693EE-0F69-4672-B6DC-D0C46E4548FF}.dat
C:\WINDOWS\system32\yaywuvu.dll
.
The following files were disabled during the run:
C:\WINDOWS\system32\sockspy.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS{6D6196E7-5EBD-4F4F-9466-E72126CB61BD}.dat
C:\WINDOWS{D90693EE-0F69-4672-B6DC-D0C46E4548FF}.dat
.
((((((((((((((((((((((((( Files Created from 2007-12-24 to 2008-01-24 )))))))))))))))))))))))))))))))
.
30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-19 13:55 --------- d-----w C:\Program Files\Trend Micro
2008-01-17 20:10 --------- d-----w C:\Program Files\GetRight
2008-01-17 19:09 708,096 ----a-w C:\WINDOWS\system32\ntdll.dll
2008-01-16 15:42 --------- d-----w C:\Program Files\Logitech
2008-01-16 15:42 --------- d-----w C:\Program Files\Common Files\Logitech
2008-01-16 15:26 --------- d–h–w C:\Program Files\InstallShield Installation Information
2008-01-15 15:22 20,640 ----a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-01-15 13:18 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-09 12:29 --------- d-----w C:\Program Files\QuickTime
2008-01-01 23:45 --------- d-----w C:\Program Files\PokerStars.NET
2007-12-25 00:26 --------- d-----w C:\Program Files\EA SPORTS
2007-12-22 14:20 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-20 23:04 --------- d-----w C:\Program Files\Apple Software Update
2007-12-20 00:31 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2007-12-20 00:30 --------- d-----w C:\Program Files\Java
2007-12-19 23:47 --------- d-----w C:\Program Files\Microsoft ActiveSync
2007-12-18 23:15 --------- d-----w C:\Program Files\interMute
2007-12-18 23:04 --------- d-----w C:\Program Files\Easy Internet signup
2007-12-18 23:01 3,888 ----a-w C:\WINDOWS\viassary-hp.reg
2007-12-18 21:55 3,420 --sha-r C:\WINDOWS\system32\drivers\HP_DT076A-ABA S6200CL NA411_YC_Pres_QMXR414_E41NAheRED4_4_IKamet2_SASUSTek Computer INC._V2.01_B3.10_T041101_WXH1_L409_M512_J120_7AMD_8Athlon XP 2800+_92.07_111063044_N11063065_P_Z11C1044C_K_A11063059_U11063038_G.MRK
2007-12-16 23:04 --------- d-----w C:\Program Files\SpywareDetector
2007-12-11 20:48 --------- d-----w C:\Program Files\Windows Live Safety Center
2007-11-30 22:45 --------- d-----w C:\Program Files\Coupons
2007-11-29 22:01 --------- d-----w C:\Program Files\SmartDraw 2008
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-27 22:40 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2004-08-30 00:04 0 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“NVIEW”=“nview.dll” [2003-08-19 04:56 852038 C:\WINDOWS\system32\nview.dll]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2008-01-09 09:39 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“LTMSG”=“LTMSG.exe” [2003-07-14 19:52 40960 C:\WINDOWS\ltmsg.exe]
“BDMCon”=“C:\Program Files\Softwin\BitDefender10\bdmcon.exe” [2007-04-02 16:48 290816]
“BDAgent”=“C:\Program Files\Softwin\BitDefender10\bdagent.exe” [2007-03-26 15:49 69632]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 08:00 79224]
“!AVG Anti-Spyware”=“C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe” [2007-06-11 04:25 6731312]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
“{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}”= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yaywuvu]
yaywuvu.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“AppInit_DLLs”=sockspy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZSScheduler]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
“HPHmon05”=C:\WINDOWS\System32\hphmon05.exe
“TkBellExe”=“C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot
“Adobe Photo Downloader”=“C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe”
hidden files: 0
.