Trevuren, here are the results:
Combofix log:
ComboFix 08-01-17.1 - Nikola Cobic 2008-01-17 22:12:15.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.44.1033.18.670 [GMT 0:00]
Running from: C:\Documents and Settings\Nikola Cobic\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Nikola Cobic\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE
C:\WINDOWS\system32\drvnum.dll
C:\WINDOWS\system32\vtuts.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drvnum.dll
C:\WINDOWS\system32\vtuts.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SSI
-------\SSI
((((((((((((((((((((((((( Files Created from 2007-12-17 to 2008-01-17 )))))))))))))))))))))))))))))))
.
2008-01-16 20:48 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-16 20:17 . 2008-01-16 20:17 145 --a------ C:\WINDOWS\system32\winver.bat
2008-01-16 19:53 . 2008-01-16 19:53 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-16 18:03 . 2008-01-16 18:03 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-16 18:02 . 2008-01-16 18:02 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-16 15:57 . 2008-01-16 17:32 580 --a------ C:\WINDOWS\wininit.ini
2008-01-13 12:27 . 2008-01-16 14:15 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-13 12:27 . 2008-01-13 12:27 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-06 15:14 . 2008-01-06 15:14 <DIR> d-------- C:\Program Files\CRON-O-METER
2008-01-06 15:14 . 2008-01-06 17:28 <DIR> d-------- C:\Documents and Settings\Nikola Cobic\Application Data\cronometer
2007-12-29 19:58 . 2007-12-29 19:58 100,989 --a------ C:\gallery.php
2007-12-29 19:13 . 2007-12-29 19:13 <DIR> d-------- C:\party_7
2007-12-17 17:39 . 2005-05-09 20:08 33,792 --a------ C:\WINDOWS\system32\drivers\cledx.sys
2007-12-17 16:50 . 2007-12-17 16:50 <DIR> d-------- C:\Documents and Settings\Nikola Cobic\Application Data\Steinberg
2007-12-17 16:47 . 2005-06-04 09:08 487,936 --a------ C:\WINDOWS\system32\rmbe3260.dll
2007-12-17 16:47 . 2005-06-04 09:09 352,768 --a------ C:\WINDOWS\system32\pngu3263.dll
2007-12-17 16:47 . 2005-06-04 09:09 131,072 --a------ C:\WINDOWS\system32\pneng50.dll
2007-12-17 16:47 . 2005-06-04 09:09 130,560 --a------ C:\WINDOWS\system32\pnc3250.dll
2007-12-17 16:47 . 2005-06-04 09:08 87,040 --a------ C:\WINDOWS\system32\ra32sipr.dll
2007-12-17 16:47 . 2005-06-04 09:11 85,504 --a------ C:\WINDOWS\system32\encdnet.dll
2007-12-17 16:47 . 2005-06-04 09:09 81,920 --a------ C:\WINDOWS\system32\ra3214_4.dll
2007-12-17 16:47 . 2005-06-04 09:09 72,704 --a------ C:\WINDOWS\system32\ra3228_8.dll
2007-12-17 16:47 . 2005-06-04 09:09 61,952 --a------ C:\WINDOWS\system32\decdnet.dll
2007-12-17 16:47 . 2005-06-04 09:09 21,504 --a------ C:\WINDOWS\system32\ra32dnet.dll
2007-12-17 16:44 . 2007-12-17 16:44 <DIR> d-------- C:\Program Files\Syncrosoft
2007-12-17 16:44 . 2005-10-17 09:35 704,512 --a------ C:\WINDOWS\system32\SYNSOACC.dll
2007-12-17 16:44 . 2004-05-10 15:58 147,456 --a------ C:\WINDOWS\system32\SynsoLChk.dll
2007-12-17 16:44 . 2003-07-31 20:28 147,425 --a------ C:\WINDOWS\system32\SYNSOACC-Aide.chm
2007-12-17 16:44 . 2003-05-26 15:29 120,468 --a------ C:\WINDOWS\system32\SYNSOACC-Hilfe.chm
2007-12-17 16:44 . 2003-05-26 15:29 114,279 --a------ C:\WINDOWS\system32\SYNSOACC-Help.chm
2007-12-17 16:44 . 2002-11-25 08:36 45,056 --a------ C:\WINDOWS\system32\Synsopos.exe
2007-12-17 16:44 . 2002-11-25 05:46 16,896 --a------ C:\WINDOWS\system32\drivers\synasUSB.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-16 19:45 --------- d-----w C:\Program Files\QuickTime
2008-01-16 19:45 --------- d-----w C:\Program Files\iTunes
2008-01-16 18:50 --------- d-----w C:\Documents and Settings\Nikola Cobic\Application Data\AVG7
2008-01-16 18:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\AVG7
2008-01-16 18:03 --------- d-----w C:\Program Files\Lavasoft
2008-01-16 18:03 --------- d-----w C:\Documents and Settings\Nikola Cobic\Application Data\Lavasoft
2008-01-16 16:02 --------- d-----w C:\Documents and Settings\Nikola Cobic\Application Data\Skype
2008-01-16 14:17 --------- d-----w C:\Documents and Settings\Nikola Cobic\Application Data\LimeWire
2008-01-16 14:09 --------- d-----w C:\Program Files\Sony Setup
2008-01-16 14:09 --------- d-----w C:\Program Files\Sony
2008-01-16 12:50 --------- d-----w C:\Program Files\VSTplugins
2008-01-12 19:39 --------- d-----w C:\Program Files\Soulseek-Test
2007-12-17 16:47 --------- d-----w C:\Program Files\Steinberg
2007-12-14 11:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-11 08:00 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-11-24 22:28 --------- d-----w C:\Program Files\Image-Line
2007-11-23 00:28 --------- d-----w C:\Documents and Settings\Nikola Cobic\Application Data\uTorrent
2007-11-20 23:45 --------- d-----w C:\Program Files\RapidLeecher Ultimate 2007
2007-11-20 14:37 --------- d-----w C:\Program Files\Java
2007-10-20 00:56 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-10-20 00:56 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-10-20 00:56 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-10-20 00:56 129,784 ----a-w C:\WINDOWS\system32\pxafs.dll
2007-10-20 00:56 120,056 ----a-w C:\WINDOWS\system32\pxcpyi64.exe
2007-10-20 00:56 118,520 ----a-w C:\WINDOWS\system32\pxinsi64.exe
2007-10-20 00:56 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-10-20 00:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-10-20 00:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-10-20 00:54 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-10-20 00:54 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-10-20 00:54 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-10-20 00:54 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-10-18 09:06 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-10-18 09:03 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-10-18 09:03 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-10-18 09:03 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-10-18 09:03 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-10-18 09:03 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-10-18 09:03 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-10-18 09:02 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-04-06 11:42 3,001 --sh--w C:\Documents and Settings\Nikola Cobic\ppUser.dat
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\party_7 ----
2007-12-29 18:30 395264 --ahs---- C:\party_7\Thumbs.db
2007-12-29 18:29 15810 --a------ C:\party_7\
040_th.jpg
2007-12-29 18:28 47286 --a------ C:\party_7\
040.jpg
2007-12-29 18:25 22336 --a------ C:\party_7\
039_th.jpg
2007-12-29 18:24 60276 --a------ C:\party_7\
039.jpg
2007-12-29 18:23 58450 --a------ C:\party_7\
038.jpg
2007-12-29 18:23 22282 --a------ C:\party_7\
038_th.jpg
2007-12-29 18:22 64526 --a------ C:\party_7\
037.jpg
2007-12-29 18:22 22173 --a------ C:\party_7\
037_th.jpg
2007-12-29 18:21 67969 --a------ C:\party_7\
036.jpg
2007-12-29 18:21 22849 --a------ C:\party_7\
036_th.jpg
2007-12-29 18:20 58270 --a------ C:\party_7\
035.jpg
2007-12-29 18:20 22175 --a------ C:\party_7\
035_th.jpg
2007-12-29 18:19 22412 --a------ C:\party_7\
034_th.jpg
2007-12-29 18:18 62642 --a------ C:\party_7\
034.jpg
2007-12-29 18:17 62691 --a------ C:\party_7\
033.jpg
2007-12-29 18:17 22341 --a------ C:\party_7\
033_th.jpg
2007-12-29 18:16 79371 --a------ C:\party_7\
032.jpg
2007-12-29 18:16 23422 --a------ C:\party_7\
032_th.jpg
2007-12-29 18:15 59065 --a------ C:\party_7\
031.jpg
2007-12-29 18:15 22643 --a------ C:\party_7\
031_th.jpg
2007-12-29 18:14 68594 --a------ C:\party_7\
030.jpg
2007-12-29 18:14 23151 --a------ C:\party_7\
030_th.jpg
2007-12-29 18:13 59627 --a------ C:\party_7\
029.jpg
2007-12-29 18:13 23324 --a------ C:\party_7\
028_th.jpg
2007-12-29 18:13 22343 --a------ C:\party_7\
029_th.jpg
2007-12-29 18:12 67631 --a------ C:\party_7\
028.jpg
2007-12-29 18:12 66094 --a------ C:\party_7\
027.jpg
2007-12-29 18:12 22800 --a------ C:\party_7\
027_th.jpg
2007-12-29 18:11 70084 --a------ C:\party_7\
026.jpg
2007-12-29 18:11 23509 --a------ C:\party_7\
026_th.jpg
2007-12-29 18:09 63238 --a------ C:\party_7\
025.jpg
2007-12-29 18:09 22931 --a------ C:\party_7\
025_th.jpg
2007-12-29 18:08 65114 --a------ C:\party_7\
024.jpg
2007-12-29 18:08 22481 --a------ C:\party_7\
024_th.jpg
2007-12-29 18:07 54364 --a------ C:\party_7\
023.jpg
2007-12-29 18:07 21721 --a------ C:\party_7\
023_th.jpg
2007-12-29 18:06 56217 --a------ C:\party_7\
022.jpg
2007-12-29 18:06 21992 --a------ C:\party_7\
022_th.jpg
2007-12-29 18:05 22471 --a------ C:\party_7\
021_th.jpg
2007-12-29 18:04 60167 --a------ C:\party_7\
021.jpg
2007-12-29 18:03 22081 --a------ C:\party_7\
020_th.jpg
2007-12-29 18:02 56450 --a------ C:\party_7\
020.jpg
2007-12-29 18:02 21633 --a------ C:\party_7\
019_th.jpg
2007-12-29 18:01 51659 --a------ C:\party_7\
019.jpg
2007-12-29 18:00 56189 --a------ C:\party_7\
018.jpg
2007-12-29 18:00 21890 --a------ C:\party_7\
018_th.jpg
2007-12-29 17:59 52177 --a------ C:\party_7\
017.jpg
2007-12-29 17:59 22036 --a------ C:\party_7\
017_th.jpg
2007-12-29 17:57 61090 --a------ C:\party_7\
016.jpg
2007-12-29 17:57 22393 --a------ C:\party_7\
016_th.jpg
2007-12-29 17:56 65502 --a------ C:\party_7\
015.jpg
2007-12-29 17:56 22751 --a------ C:\party_7\
015_th.jpg
2007-12-29 17:55 58442 --a------ C:\party_7\
014.jpg
2007-12-29 17:55 21707 --a------ C:\party_7\
014_th.jpg
2007-12-29 17:54 54900 --a------ C:\party_7\
013.jpg
2007-12-29 17:54 21675 --a------ C:\party_7\
013_th.jpg
2007-12-29 17:53 57843 --a------ C:\party_7\
012.jpg
2007-12-29 17:53 21923 --a------ C:\party_7\
012_th.jpg
2007-12-29 17:53 21841 --a------ C:\party_7\
011_th.jpg
2007-12-29 17:52 58478 --a------ C:\party_7\
010.jpg
2007-12-29 17:52 51343 --a------ C:\party_7\
011.jpg
2007-12-29 17:52 22179 --a------ C:\party_7\
010_th.jpg
2007-12-29 17:51 22262 --a------ C:\party_7\
09_th.jpg
2007-12-29 17:50 62024 --a------ C:\party_7\
09.jpg
2007-12-29 17:49 48699 --a------ C:\party_7\
08.jpg
2007-12-29 17:49 21814 --a------ C:\party_7\
08_th.jpg
2007-12-29 17:48 22306 --a------ C:\party_7\
07_th.jpg
2007-12-29 17:47 63171 --a------ C:\party_7\
07.jpg
2007-12-29 17:46 51221 --a------ C:\party_7\
06.jpg
2007-12-29 17:46 21628 --a------ C:\party_7\
06_th.jpg
2007-12-29 17:45 59341 --a------ C:\party_7\
05.jpg
2007-12-29 17:45 22664 --a------ C:\party_7\
05_th.jpg
2007-12-29 17:44 22260 --a------ C:\party_7\
04_th.jpg
2007-12-29 17:43 53064 --a------ C:\party_7\
04.jpg
2007-12-29 17:43 22611 --a------ C:\party_7\
03_th.jpg
2007-12-29 17:42 62248 --a------ C:\party_7\
03.jpg
2007-12-29 17:40 65816 --a------ C:\party_7\
02.jpg
2007-12-29 17:40 23019 --a------ C:\party_7\
02_th.jpg
2007-12-29 17:39 22517 --a------ C:\party_7\
01_th.jpg
2007-12-29 17:38 68788 --a------ C:\party_7\
01.jpg
((((((((((((((((((((((((((((( snapshot@2008-01-17_20.58.32.75 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-16 20:49:10 454,656 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\ntuser.dat
+ 2008-01-17 22:12:07 454,656 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\ntuser.dat
- 2008-01-16 20:49:10 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-17 22:12:07 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-16 20:49:10 454,656 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\ntuser.dat
+ 2008-01-17 22:12:07 454,656 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\ntuser.dat
- 2008-01-16 20:49:10 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-17 22:12:07 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-16 20:49:10 5,189,632 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\ntuser.dat
+ 2008-01-17 22:12:07 5,189,632 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000005\ntuser.dat
- 2008-01-16 20:49:10 393,216 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
+ 2008-01-17 22:12:07 393,216 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000006\UsrClass.dat
- 2008-01-16 20:49:27 471,040 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
+ 2008-01-17 22:12:11 471,040 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 03:41 13312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-01-17 20:49 1115136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-08-29 03:41 13312]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-24 14:30 219136]
C:\Documents and Settings\Nikola Cobic\Start Menu\Programs\Startup\
Pravoslavac 2007.lnk - C:\Program Files\Pravoslavac\Pravoslavac 2007.exe [2007-02-15 16:55:38]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-02-06 19:11:12]
ATI CATALYST System Tray.lnk - C:\Program Files\ATI Technologies\ATI.ACE\Load.exe [2005-08-06 01:07:30]
Status Monitor.lnk - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [2006-01-05 14:34:05]
R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\System32\DRIVERS\cledx.sys [2005-05-09 20:08]
R3 USB-100;Realtek RTL8150 USB 10/100 Fast Ethernet Adapter;C:\WINDOWS\System32\DRIVERS\RTL8150.SYS [2001-05-24 01:20]
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\System32\Drivers\BrScnUsb.sys [2003-12-19 21:15]
S3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;C:\WINDOWS\System32\Drivers\BrSerIf.sys [2004-06-12 05:27]
S3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\WINDOWS\System32\Drivers\BrUsbSer.sys [2004-01-10 04:28]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-10 10:55:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-17 22:19:37
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-17 22:22:02 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-17 22:22:00
ComboFix2.txt 2008-01-17 20:58:43
NEW HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:24:49, on 17.1.2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.grisoft.c...ng/us/tpl/tpl01
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 62.253.64.15:80
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Pravoslavac 2007.lnk = C:\Program Files\Pravoslavac\Pravoslavac 2007.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\Load.exe
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: YU-MP3.COM Account Login - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe
O9 - Extra 'Tools' menuitem: &YU-MP3.COM User Login - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Unknown owner - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe (file missing)
--
End of file - 5172 bytes
ESET Online Scanner Log:
# version=4
# OnlineScanner.ocx=1.0.0.56
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=2799 (20080116)
# vers_arch_module=1.062 (20080115)
# vers_adv_heur_module=1.060 (20070601)
# EOSSerial=91b81e9b74dfc7478eba3af25d3d8466
# end=finished
# remove_checked=false
# unwanted_checked=false
# utc_time=2008-01-18 12:03:11
# local_time=2008-01-18 12:03:11 (+0000, GMT Standard Time)
# country="Serbia"
# osver=5.1.2600 NT Service Pack 1
# scanned=519817
# found=7
# scan_time=5630
C:\Documents and Settings\Nikola Cobic\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-4ca23c9f Java/Exploit.Bytverify trojan DB45A3ABCBA0A662F627DCDD9AED8C96
C:\Documents and Settings\Nikola Cobic\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-4ca23c9f »ZIP »NewSecurityClassLoader.class Java/Exploit.Bytverify trojan 00000000000000000000000000000000
C:\Documents and Settings\Nikola Cobic\Application Data\Sun\Java\Deployment\cache\6.0\59\303ac5bb-4ca23c9f »ZIP »NewURLClassLoader.class Java/Exploit.Bytverify trojan 00000000000000000000000000000000
C:\Documents and Settings\Nikola Cobic\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-3e54e5a3.zip Java/Exploit.Bytverify trojan DB45A3ABCBA0A662F627DCDD9AED8C96
C:\Documents and Settings\Nikola Cobic\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-3e54e5a3.zip »ZIP »NewSecurityClassLoader.class Java/Exploit.Bytverify trojan 00000000000000000000000000000000
C:\Documents and Settings\Nikola Cobic\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0502b.jar-35851aee-3e54e5a3.zip »ZIP »NewURLClassLoader.class Java/Exploit.Bytverify trojan 00000000000000000000000000000000
C:\QooBox\Quarantine\C\WINDOWS\system32\vtuts.exe.vir Win32/TrojanDropper.Agent.DGO virus 00000000000000000000000000000000
Thanks so much once again for your help. I look forward to your next instructions.