the resulting log:
ComboFix 09-02-24.02 - usr 2009-02-25 21:41:43.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1254.1.1055.18.511.195 [GMT 2:00]
Running from: c:\documents and settings\usr\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\usr\Desktop\CFscript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
c:\documents and settings\usr\7l3m4x8d6.exe
c:\documents and settings\usr\asdsdsd.exe
c:\documents and settings\usr\deleteme.exe
c:\documents and settings\usr\explode.exe
c:\documents and settings\usr\Exredr.exe
c:\documents and settings\usr\Exredr2.exe
c:\documents and settings\usr\Exrexdr.exe
c:\documents and settings\usr\Exxrxedr.exe
c:\documents and settings\usr\h4d7l3m4x8d6.exe
c:\documents and settings\usr\kdjods.exe
c:\documents and settings\usr\kjodxs.exe
c:\documents and settings\usr\lpe.exe
c:\documents and settings\usr\lpex.exe
c:\documents and settings\usr\Rkhaa.exe
c:\documents and settings\usr\sd4dshd.exe
c:\documents and settings\usr\sdsdsd.exe
c:\documents and settings\usr\sdsdshd.exe
c:\documents and settings\usr\sdsxdshd.exe
c:\documents and settings\usr\sdsxxdshd.exe
c:\documents and settings\usr\Setup.exe
c:\documents and settings\usr\Setxup.exe
c:\documents and settings\usr\sfddshd.exe
c:\documents and settings\usr\srdshd.exe
c:\documents and settings\usr\ssddshd.exe
c:\documents and settings\usr\ssdswe.exe
c:\documents and settings\usr\sxdsdshd.exe
c:\documents and settings\usr\sxdsxdshd.exe
c:\documents and settings\usr\taskmger.exe
c:\documents and settings\usr\xsdsdsd.exe
c:\recycle\D-0-060-0000000000-1111111-2222222\fix.exe
c:\recycler\k-1-3542-4232123213-7676767-8888886\root.exe
c:\restore\c-1-3-64-8794238531-8742492-9897532\Sys32.exe
c:\restore\k-1-3542-4232123213-7676767-8888886\JUZZ.exe
c:\system\S-1-5-21-1482476501-1644491937-682003330-1013\Perfume.exe
c:\windows\sxdsxdshd.exe
c:\windows\system32\drivers\WinMgmt.exe
f:\system\S-1-5-21-1482476501-1644491937-682003330-1013\Perfume.exe
F:\win32s.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\GamesBar
c:\documents and settings\All Users\Application Data\GamesBar\about.gif
c:\documents and settings\All Users\Application Data\GamesBar\action.gif
c:\documents and settings\All Users\Application Data\GamesBar\arcade.gif
c:\documents and settings\All Users\Application Data\GamesBar\buy.gif
c:\documents and settings\All Users\Application Data\GamesBar\call_of_atlantis16x16.gif
c:\documents and settings\All Users\Application Data\GamesBar\cards.gif
c:\documents and settings\All Users\Application Data\GamesBar\deals.gif
c:\documents and settings\All Users\Application Data\GamesBar\download.gif
c:\documents and settings\All Users\Application Data\GamesBar\dream_day_wedding_216x16.gif
c:\documents and settings\All Users\Application Data\GamesBar\feedback.gif
c:\documents and settings\All Users\Application Data\GamesBar\help.gif
c:\documents and settings\All Users\Application Data\GamesBar\highlight.gif
c:\documents and settings\All Users\Application Data\GamesBar\holly_a_christmas_tale_deluxe16x16.gif
c:\documents and settings\All Users\Application Data\GamesBar\house_of_wonders_bch16x16.gif
c:\documents and settings\All Users\Application Data\GamesBar\interpol_2_most_wanted16x16.gif
c:\documents and settings\All Users\Application Data\GamesBar\miss_teri_tale_2_vote_4_me16x16.gif
c:\documents and settings\All Users\Application Data\GamesBar\multiplayer.gif
c:\documents and settings\All Users\Application Data\GamesBar\mygames.gif
c:\documents and settings\All Users\Application Data\GamesBar\newGames.gif
c:\documents and settings\All Users\Application Data\GamesBar\oberonconfig.xm_
c:\documents and settings\All Users\Application Data\GamesBar\obSearchHistory.dat
c:\documents and settings\All Users\Application Data\GamesBar\onload\loading.gif
c:\documents and settings\All Users\Application Data\GamesBar\partner.gif
c:\documents and settings\All Users\Application Data\GamesBar\puzzle.gif
c:\documents and settings\All Users\Application Data\GamesBar\search.gif
c:\documents and settings\All Users\Application Data\GamesBar\search_yahoo.gif
c:\documents and settings\All Users\Application Data\GamesBar\season_match_216x16.gif
c:\documents and settings\All Users\Application Data\GamesBar\sendafriend.gif
c:\documents and settings\All Users\Application Data\GamesBar\trial.gif
c:\documents and settings\All Users\Application Data\GamesBar\Turbo_Fiesta16x16.gif
c:\documents and settings\All Users\Application Data\GamesBar\uninstall.gif
c:\documents and settings\All Users\Application Data\GamesBar\update.gif
c:\documents and settings\All Users\Application Data\GamesBar\webgame.gif
c:\documents and settings\usr\7l3m4x8d6.exe
c:\documents and settings\usr\asdsdsd.exe
c:\documents and settings\usr\deleteme.exe
c:\documents and settings\usr\explode.exe
c:\documents and settings\usr\Exredr.exe
c:\documents and settings\usr\Exredr2.exe
c:\documents and settings\usr\Exrexdr.exe
c:\documents and settings\usr\Exxrxedr.exe
c:\documents and settings\usr\h4d7l3m4x8d6.exe
c:\documents and settings\usr\kdjods.exe
c:\documents and settings\usr\kjodxs.exe
c:\documents and settings\usr\lpe.exe
c:\documents and settings\usr\lpex.exe
c:\documents and settings\usr\Rkhaa.exe
c:\documents and settings\usr\sd4dshd.exe
c:\documents and settings\usr\sdsdsd.exe
c:\documents and settings\usr\sdsdshd.exe
c:\documents and settings\usr\sdsxdshd.exe
c:\documents and settings\usr\sdsxxdshd.exe
c:\documents and settings\usr\Setup.exe
c:\documents and settings\usr\Setxup.exe
c:\documents and settings\usr\sfddshd.exe
c:\documents and settings\usr\srdshd.exe
c:\documents and settings\usr\ssddshd.exe
c:\documents and settings\usr\ssdswe.exe
c:\documents and settings\usr\sxdsdshd.exe
c:\documents and settings\usr\sxdsxdshd.exe
c:\documents and settings\usr\taskmger.exe
c:\documents and settings\usr\xsdsdsd.exe
c:\program files\Viewpoint
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\recycle\D-0-060-0000000000-1111111-2222222\fix.exe
c:\restore
c:\restore\c-1-3-64-8794238531-8742492-9897532\Desktop.ini
c:\restore\c-1-3-64-8794238531-8742492-9897532\Sys32.exe
c:\restore\k-1-3542-4232123213-7676767-8888886\Desktop.ini
c:\restore\k-1-3542-4232123213-7676767-8888886\JUZZ.exe
c:\restore\k-1-3542-4232123213-7676767-8888886\X0R.exe
c:\windows\sxdsxdshd.exe
c:\windows\system32\drivers\WinMgmt.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_VIEWPOINT_MANAGER_SERVICE
-------\Legacy_WINSOFT_SERVICE_CONTROLER
-------\Service_Viewpoint Manager Service
-------\Service_WinSoft Service Controler
((((((((((((((((((((((((( Files Created from 2009-01-25 to 2009-02-25 )))))))))))))))))))))))))))))))
.
2009-02-24 22:12 . 2009-02-24 22:39
d-------- C:\Lop SD
2009-02-24 17:08 . 2009-02-25 20:54 d-------- c:\program files\ESET
2009-02-24 17:08 . 2009-02-24 17:08 0 --a------ c:\windows\system32\mapisvc.inf
2009-02-07 17:30 . 2009-02-18 20:33 d-------- C:\quarantine
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-23 19:54 --------- d-----w c:\program files\Common Files\AOL
2009-02-06 16:30 --------- d-----w c:\program files\Messenger Plus! Live
2009-01-21 15:51 --------- d-----w c:\documents and settings\usr\Application Data\PlayFirst
2009-01-21 15:51 --------- d-----w c:\documents and settings\All Users\Application Data\Reflexive
2009-01-21 15:50 --------- d-----w c:\program files\PlayFirst
2009-01-21 15:24 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2009-01-18 17:59 --------- d-----w c:\program files\PhotoScape
2006-11-21 16:38 18,096 ----a-w c:\documents and settings\usr\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((( SnapShot@2009-02-25_21.08.15,79 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 18:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-10 7311360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-12-10 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Remote"="c:\program files\LifeView TVR\Remote.exe" [2006-05-09 212992]
"RecSche"="c:\program files\LifeView TVR\RecSche.exe" [2006-01-04 454656]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2004-12-20 33792]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"SMCWCU"="c:\program files\SMC\SMCWPCIT-G\SMCWCU.exe" [2006-03-14 303104]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"NodLogin"="c:\program files\Eset\nodlogin.exe" [2008-07-29 358448]
"nwiz"="nwiz.exe" [2005-12-10 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [2002-08-07 54936]
c:\documents and settings\All Users\Start Menu\Programlar\BaÅølangĀ‡\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-09-22 184320]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 18:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:35 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R3 LVHybrid;LVHybrid service;c:\windows\system32\drivers\LVHybrid.sys [2006-10-02 892032]
S3 bDMusicb;bDMusicb;\??\c:\docume~1\usr\LOCALS~1\Temp\bDMusicb.sys --> c:\docume~1\usr\LOCALS~1\Temp\bDMusicb.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-02-25 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2002-08-07 08:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.tr/
uInternet Settings,ProxyOverride =
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
FF - ProfilePath - c:\documents and settings\usr\Application Data\Mozilla\Firefox\Profiles\oyyj043w.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-25 21:44:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Remote = c:\program files\LifeView TVR\Remote.exe???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OMSCAN]
"ImagePath"="\Sys"
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\acs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2009-02-25 21:47:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-25 19:47:20
ComboFix2.txt 2009-02-25 19:09:03
Pre-Run: 54.549.286.912 bayt boş
Post-Run: 54,490,476,544 bayt boş
234 --- E O F --- 2009-01-16 16:27:44