Things are working a bit more smooth. I rebooted the computer and I got notepad to work. This is the Combo-fix.txt you said I would get:
ComboFix 09-10-07.02 - Kelner 10/08/2009 6:47.1.2 - NTFSx86
Running from: c:\documents and settings\Kelner\Desktop\Combo-Fix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\92372124
c:\documents and settings\All Users\Application Data\92372124\92372124.bat
c:\documents and settings\All Users\Application Data\92372124\92372124.exe
c:\documents and settings\Kelner\Local Settings\Temporary Internet Files\iwudag.com
c:\documents and settings\Kelner\Local Settings\Temporary Internet Files\ozejus.dll
c:\documents and settings\Kelner\Local Settings\Temporary Internet Files\pijilonygu.bat
c:\documents and settings\Kelner\Local Settings\Temporary Internet Files\uwemewu.sys
c:\program files\Common
c:\program files\Common\_helper.sig
c:\recycler\S-1-5-21-105366467-982144795-1367911678-500
c:\recycler\S-1-5-21-1166309277-1596028747-264381209-1003
c:\recycler\S-1-5-21-1166309277-1596028747-264381209-500
c:\recycler\S-1-5-21-1260548629-2456617093-748441295-500
c:\recycler\S-1-5-21-2098939454-3982083151-582432542-500
c:\recycler\S-1-5-21-231806994-526144396-314847941-500
c:\recycler\S-1-5-21-2471874882-1742013197-23779851-500
c:\recycler\S-1-5-21-2723234792-4289631594-398738960-500
c:\recycler\S-1-5-21-2799450225-1403549518-2432291109-500
c:\recycler\S-1-5-21-2995828153-448149318-1095471116-500
c:\recycler\S-1-5-21-3145035839-3996446948-2437272773-500
c:\recycler\S-1-5-21-472568965-2156924117-990862072-500
c:\windows\desktop
c:\windows\Installer\1533e.msi
c:\windows\Installer\262084.msi
c:\windows\Installer\2aff2b.msi
c:\windows\system32\bajujami.dll
c:\windows\system32\divosimu.dll
c:\windows\system32\fidebage.dll
c:\windows\system32\guporobe.dll
c:\windows\system32\jadikure.dll
c:\windows\system32\keneluga.dll
c:\windows\system32\pihenedo.dll
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tojayeku.dll
c:\windows\system32\yokowefu.dll
C:\xcrashdump.dat
.
((((((((((((((((((((((((( Files Created from 2009-09-08 to 2009-10-08 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-08 10:58 . 2009-09-23 19:08 -------- d-----w- c:\documents and settings\Kelner\Application Data\Skype
2009-10-07 23:52 . 2009-10-07 23:52 -------- dc----w- c:\documents and settings\All Users\Application Data\69123425
2009-10-06 14:19 . 2009-10-06 14:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-05 18:00 . 2009-10-05 18:00 -------- d-----w- c:\program files\Trend Micro
2009-10-05 11:48 . 2009-10-05 11:48 -------- d-----w- c:\documents and settings\Kelner\Application Data\5647909830
2009-10-04 16:46 . 2008-09-09 16:05 10752 ----a-w- c:\windows\DCEBoot.exe
2009-10-04 14:02 . 2009-10-04 14:02 -------- d-----w- c:\documents and settings\Kelner\Application Data\7875163248
2009-09-25 19:10 . 2009-09-25 18:42 -------- dc----w- c:\documents and settings\All Users\Application Data\NOS
2009-09-23 19:08 . 2009-09-23 19:08 -------- d-----r- c:\program files\Skype
2009-09-23 19:08 . 2009-09-23 19:08 -------- dc----w- c:\documents and settings\All Users\Application Data\Skype
2009-09-10 18:54 . 2009-10-06 14:18 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 18:53 . 2009-10-06 14:17 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-09 23:01 . 2007-02-27 22:49 -------- dc----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-08-24 23:01 . 2009-08-24 23:01 -------- d-----w- c:\program files\MSBuild
2009-08-24 23:01 . 2009-08-24 23:01 -------- d-----w- c:\program files\Reference Assemblies
2009-08-06 23:24 . 2005-09-06 23:34 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 23:24 . 2005-09-06 23:34 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 23:24 . 2005-09-06 23:34 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 23:24 . 2005-09-06 20:47 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 23:24 . 2005-09-06 23:34 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 23:24 . 2004-08-04 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 23:23 . 2005-09-06 23:34 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 23:23 . 2006-08-17 17:22 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 23:23 . 2005-09-06 23:34 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-06 23:23 . 2005-05-26 09:19 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-05 11:38 . 2009-04-08 19:47 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-04 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-05 23:48 . 2009-07-05 23:48 1048611 --sha-w- c:\windows\system32\bokiluve.exe
2009-07-07 11:50 . 2009-07-07 11:50 1050659 --sha-w- c:\windows\system32\gimokajo.exe
2009-07-05 11:49 . 2009-07-05 11:49 50176 --sha-w- c:\windows\system32\guyuzera.dll.tmp
2009-07-07 11:50 . 2009-07-07 11:50 88576 --sha-w- c:\windows\system32\kehutosu.dll
2009-07-06 23:51 . 2009-07-06 23:51 51712 --sha-w- c:\windows\system32\morugawe.dll
2009-07-05 11:48 . 2009-07-05 11:48 50176 --sha-w- c:\windows\system32\panasoba.dll
2009-07-07 23:51 . 2009-07-07 23:51 1050659 --sha-w- c:\windows\system32\penotewi.exe
2009-07-06 23:50 . 2009-07-06 23:50 88064 --sha-w- c:\windows\system32\rojayefi.dll
2009-07-06 23:50 . 2009-07-06 23:50 51712 --sha-w- c:\windows\system32\tenoheze.dll
2009-07-05 11:48 . 2009-07-05 11:48 1047587 --sha-w- c:\windows\system32\vagazodi.exe
2009-07-06 11:49 . 2009-07-06 11:49 88064 --sha-w- c:\windows\system32\yibabofi.dll
2009-07-05 11:49 . 2009-07-05 11:49 50176 --sha-w- c:\windows\system32\yuworowe.dll.tmp
2009-07-05 23:48 . 2009-07-05 23:48 88576 --sha-w- c:\windows\system32\zurokawe.dll
.
c:\windows\system32\drivers\tcpip.sys ... is infected !!
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-08 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-08 114688]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-02-18 180269]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Motive SmartBridge"="c:\progra~1\ALLTEL~1\SMARTB~1\MotiveSB.exe" [2004-11-09 393216]
"V0350Mon.exe"="c:\windows\V0350Mon.exe" [2007-08-23 28672]
"FPCCSMiddleware"="c:\program files\Fisher-Price\Computer Cool School\FPCCSMiddleware.exe" [2008-10-10 538432]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"69123425"="c:\documents and settings\All Users\Application Data\69123425\69123425.exe" [2009-10-07 1050659]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-02-29 76304]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 07:42 72208 ----a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\ATTNaturalVoices\\TTS1.2\\Desktop\\bin\\ttsdesktopproxy.exe"=
"c:\\Program Files\\SightSpeed\\SightSpeed.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\Avira\\AntiVir Desktop\\guardgui.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
nkajjcgx
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.comuDefault_Search_URL =
hxxp://www.google.com/iemStart Page =
hxxp://www.google.comuInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath -
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
HKCU-Run-MsnMsgr - c:\program files\Windows Live\Messenger\MsnMsgr.Exe
HKLM-Run-igfxtray - c:\windows\system32\igfxtray.exe
HKLM-Run-92372124 - c:\documents and settings\All Users\Application Data\92372124\92372124.exe
HKLM-Run-vemulagok - c:\windows\system32\keneluga.dll
HKLM-Run-zosizifara - tojayeku.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-08 07:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Avira\AntiVir Desktop\guardgui.exe
c:\program files\CyberLink\PowerDVD\PDVDServ.exe
c:\program files\Avira\AntiVir Desktop\guardgui.exe
c:\program files\Skype\Phone\Skype.exe
c:\program files\Logitech\SetPoint\SetPoint.exe
c:\program files\ALLTEL DSL Check-up Center\bin\mpbtn.exe
.
**************************************************************************
.
Completion time: 2009-10-08 7:09 - machine was rebooted
Pre-Run: 29,173,428,224 bytes free
Post-Run: 29,978,972,160 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
187 --- E O F --- 2009-09-26 13:00