Hi Belahzur,
Virus not removed at all... here is the combifix log:
ComboFix 09-09-25.01 - Rose Hall 27/09/2009 17:21.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.654 [GMT 1:00]
Running from: c:\documents and settings\Rose Hall\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090926-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\aoqwlrag.exe
c:\documents and settings\All Users\Application Data\byfytihe.dll
c:\documents and settings\All Users\Application Data\danedoz._sy
c:\documents and settings\All Users\Documents\mewuni.reg
c:\documents and settings\Rose Hall\Application Data\fikucavi.scr
c:\documents and settings\Rose Hall\Application Data\gebowezak.scr
c:\documents and settings\Rose Hall\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk
c:\documents and settings\Rose Hall\Application Data\ybiqados.exe
c:\documents and settings\Rose Hall\Desktop\AntivirusPro_2010.lnk
c:\documents and settings\Rose Hall\Local Settings\Application Data\ewawytu.ban
c:\documents and settings\Rose Hall\Local Settings\Temporary Internet Files\jewexu.inf
c:\documents and settings\Rose Hall\Local Settings\Temporary Internet Files\pine.bin
c:\documents and settings\Rose Hall\Start Menu\Programs\AntivirusPro_2010
c:\documents and settings\Rose Hall\Start Menu\Programs\AntivirusPro_2010\AntivirusPro_2010.lnk
c:\documents and settings\Rose Hall\Start Menu\Programs\AntivirusPro_2010\Uninstall.lnk
C:\eopmjm.exe
C:\hxlqib.exe
C:\pkusq.exe
c:\program files\AntivirusPro_2010
c:\program files\AntivirusPro_2010\AntivirusPro_2010.cfg
c:\program files\AntivirusPro_2010\AntivirusPro_2010.exe
c:\program files\Common Files\arehygun.bin
c:\program files\Common Files\asolilagu.vbs
c:\program files\Common Files\oducula.scr
c:\recycler\S-1-5-21-1123561945-1757981266-1606980848-1003
c:\windows\etyjamapev.bat
c:\windows\Installer\2d298.msp
c:\windows\Installer\3c777.msp
c:\windows\Installer\3cce8d.msp
c:\windows\Installer\44e0d.msp
c:\windows\Installer\6b42f.msp
c:\windows\msetup
c:\windows\msetup\MSetup.exe
c:\windows\syru.bat
c:\windows\system32\_scui.cpl
c:\windows\system32\~.exe
c:\windows\system32\drivers\gasfkyuttmpfqx.sys
c:\windows\system32\drivers\smss.exe
c:\windows\system32\gasfkybphesdpq.dat
c:\windows\system32\gasfkyehrqtklv.dll
c:\windows\system32\gasfkyfvaftqsn.dll
c:\windows\system32\gasfkynpfulwfd.dat
c:\windows\system32\gasfkyxjettarm.dll
c:\windows\system32\quferyxi.reg
c:\windows\system32\sipuh.reg
c:\windows\system32\wbem\proquota.exe
c:\windows\ycyzajeco.scr
C:\yhjj.exe
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\system volume information\_restore{873C7E92-AC34-446B-A7FB-8EDA951B8E6A}\RP201\A0015749.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gasfkyvoakyxww
-------\Legacy_gasfkyvoakyxww
((((((((((((((((((((((((( Files Created from 2009-08-27 to 2009-09-27 )))))))))))))))))))))))))))))))
.
2009-09-27 16:26 . 2008-04-14 12:00 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2009-09-27 16:26 . 2008-04-14 12:00 50176 ----a-w- c:\windows\system32\proquota.exe
2009-09-27 13:21 . 2009-09-27 13:21 -------- d-----w- c:\documents and settings\Rose Hall\Application Data\MSNInstaller
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-27 11:44 . 2009-09-27 11:44 230000 ----a-w- c:\documents and settings\Rose Hall\Application Data\lizkavd.exe
2009-09-27 11:40 . 2009-09-27 11:40 295424 ----a-w- c:\documents and settings\Rose Hall\Application Data\svcst.exe
2009-09-27 11:40 . 2009-09-27 11:40 295424 ----a-w- c:\documents and settings\Rose Hall\Application Data\seres.exe
2009-09-26 05:56 . 2008-10-29 01:59 -------- d-----w- c:\program files\Java
2009-09-09 19:05 . 2009-03-08 21:01 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-27 21:03 . 2009-08-27 21:03 -------- d-----w- c:\documents and settings\All Users\Application Data\MSScanAppDataDir
2009-08-22 22:14 . 2009-08-22 22:07 -------- d-----w- c:\documents and settings\All Users\Application Data\OfficeGuardian
2009-08-17 16:10 . 2009-07-18 06:51 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2009-07-18 06:51 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2009-07-18 06:51 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2009-07-18 06:51 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2009-07-18 06:51 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2009-07-18 06:51 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2009-07-18 06:51 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2009-07-18 06:51 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2009-07-18 06:51 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-08-15 12:41 . 2009-08-15 12:41 -------- d-----w- c:\program files\Xvid
2009-08-12 11:59 . 2009-01-21 20:39 64176 ----a-w- c:\documents and settings\Rose Hall\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-07 07:02 . 2009-08-07 07:02 -------- d-----w- c:\program files\MSBuild
2009-08-07 07:01 . 2009-08-07 07:01 -------- d-----w- c:\program files\Reference Assemblies
2009-08-05 09:01 . 2008-10-28 22:05 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-25 04:23 . 2009-02-15 20:53 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2008-10-28 22:05 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 22:43 . 2008-10-28 22:06 286208 ----a-w- c:\windows\system32\wmpdxm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Rose Hall\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-28 133104]
"mserv"="c:\documents and settings\Rose Hall\Application Data\svcst.exe" [2009-09-27 295424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EDS"="c:\program files\Samsung\Samsung EDS\EDSAgent.exe" [2007-12-21 659456]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-28 1044480]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"DMHotKey"="c:\program files\Samsung\Easy dȋsplay Manager\DMLoader.exe" [2006-12-27 466944]
"BatteryManager"="c:\program files\Samsung\Samsung Battery Manager\BatteryManager.exe" [2008-10-08 2768896]
"MagicKeyboard"="c:\program files\SAMSUNG\MagicKBD\PreMKBD.exe" [2006-05-15 151552]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-10 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-17 1848648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-08-26 16851456]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-4-1 568176]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [18/07/2009 07:51 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [18/07/2009 07:51 20560]
R2 DOSMEMIO;MEMIO;c:\windows\system32\MEMIO.SYS [29/10/2008 03:00 4300]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [08/03/2009 22:00 55152]
R3 DNSeFilter;DNSeFilter;c:\windows\system32\drivers\SamsungEDS.SYS [15/01/2008 04:01 30208]
R3 VMC326;Vimicro Camera Service VMC326;c:\windows\system32\drivers\VMC326.sys [29/10/2008 03:04 238464]
S2 SNM WLAN Service;SNM WLAN Service;c:\program files\Samsung\Samsung Network Manager\SNMWLANService.exe [30/10/2006 23:29 36864]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19:08 533360]
S3 SUEPD;SUE NDIS Protocol Driver;c:\windows\system32\drivers\SUE_PD.sys [30/10/2006 23:29 19840]
.
Contents of the 'Scheduled Tasks' folder
2009-09-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2361762995-4024017499-4215913921-1005Core.job
- c:\documents and settings\Rose Hall\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-28 17:29]
2009-09-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2361762995-4024017499-4215913921-1005UA.job
- c:\documents and settings\Rose Hall\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-28 17:29]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.co.uk/IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} -
hxxp://game11.zylom.com/activex/zylomgamesplayer.cab.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DriverCure - c:\program files\ParetoLogic\DriverCure\DriverCure.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-27 17:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2009-09-27 17:29
ComboFix-quarantined-files.txt 2009-09-27 16:29
Pre-Run: 63,804,637,184 bytes free
Post-Run: 63,995,412,480 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
206 --- E O F --- 2009-09-26 05:53
Thanks!