Thanks for your help!!!
Here is my ComboFix log:
ComboFix 08-02.05.3 - Sivan 2008-02-08 23:48:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1255.972.1033.18.465 [GMT 2:00]
Running from: C:\Documents and Settings\Sivan\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\byxwvtu.dll
C:\WINDOWS\system32\jkhfd.dll
C:\WINDOWS\system32\qpwdener.dll
C:\Documents and Settings\Sivan\Application Data\macromedia\Flash Player\#SharedObjects\VZ272JGE\iforex.com
C:\Documents and Settings\Sivan\Application Data\macromedia\Flash Player\#SharedObjects\VZ272JGE\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\Sivan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\Sivan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\byxwvtu.dll
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\cbxyywx.dll
C:\WINDOWS\system32\dfhkj.ini
C:\WINDOWS\system32\dfhkj.ini2
C:\WINDOWS\system32\eadwuvdh.ini
C:\WINDOWS\system32\filtrnap.ini
C:\WINDOWS\system32\ihtnanet.ini
C:\WINDOWS\system32\jkhfd.dll
C:\WINDOWS\system32\kpybfttu.ini
C:\WINDOWS\system32\lyweeaxp.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mftxjdye.ini
C:\WINDOWS\system32\mtwjveyg.ini
C:\WINDOWS\system32\qjfvrphk.ini
C:\WINDOWS\system32\qpwdener.dll
C:\WINDOWS\system32\qpwdener.dllbox
C:\WINDOWS\system32\tcsekiuo.ini
C:\WINDOWS\system32\vtusqnk.dll
C:\WINDOWS\system32\wwokhnbh.dll
.
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
2008-02-08 13:56 . 2006-07-07 16:41 14,848 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-02-08 12:55 . 2008-02-08 12:55 163,904 --a------ C:\WINDOWS\system32\imgzfjfn.dll.vir
2008-02-08 11:48 . 2008-02-08 11:48 38,400 --a------ C:\WINDOWS\system32\pmnkjgd.dll.vir
2008-02-08 10:21 . 2008-02-08 23:37 <DIR> d-------- C:\VundoFix Backups
2008-02-08 08:47 . 2008-02-08 08:47 <DIR> d-------- C:\Program Files\ESET
2008-02-08 08:42 . 2008-02-08 17:40 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-08 08:42 . 2008-02-08 08:42 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-05 20:57 . 2008-02-05 20:57 268 --ah----- C:\sqmdata02.sqm
2008-02-05 20:57 . 2008-02-05 20:57 244 --ah----- C:\sqmnoopt02.sqm
2008-02-05 20:52 . 2008-02-05 20:52 268 --ah----- C:\sqmdata01.sqm
2008-02-05 20:52 . 2008-02-05 20:52 244 --ah----- C:\sqmnoopt01.sqm
2008-01-30 12:37 . 2008-01-30 12:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2008-01-30 12:32 . 2008-02-08 09:03 <DIR> d-------- C:\Program Files\Common Files\Logishrd
2008-01-30 12:32 . 2008-01-30 12:32 <DIR> d-------- C:\Documents and Settings\Sivan\Application Data\InstallShield
2008-01-30 12:32 . 2008-01-30 12:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-01-30 12:27 . 2007-12-17 13:53 159,458 --a------ C:\WINDOWS\system32\nvapps.nvb
2008-01-30 12:26 . 2007-12-05 02:53 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-01-30 00:28 . 2008-01-07 14:29 352 --ah----- C:\WINDOWS\nod32fixtemdono.reg
2008-01-29 12:56 . 2008-02-03 21:52 37,888 --a------ C:\WINDOWS\system32\rar.exe
2008-01-29 11:26 . 2008-01-29 11:26 <DIR> d-------- C:\Documents and Settings\Sivan\Application Data\ESET
2008-01-29 11:25 . 2008-01-29 11:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-01-26 13:26 . 2008-01-26 13:26 115,415,432 --a------ C:\BackupRegistry(20080126).reg
2008-01-26 13:11 . 2008-01-26 13:11 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-01-26 13:11 . 2007-12-20 10:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-01-22 16:19 . 2008-01-22 16:19 <DIR> d-------- C:\Program Files\iPod
2008-01-22 16:16 . 2008-01-22 16:17 <DIR> d-------- C:\Program Files\QuickTime
2008-01-14 22:10 . 2008-02-08 09:36 <DIR> d-------- C:\Downloads
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 21:57 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-08 08:14 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-02-08 08:14 --------- d-----w C:\Program Files\A1Click Ultra PC Cleaner
2008-02-08 07:28 --------- d-----w C:\Program Files\RegVac Registry Cleaner
2008-02-08 07:14 --------- d-----w C:\Program Files\Logitech
2008-02-06 16:44 --------- d-----w C:\Documents and Settings\Sivan\Application Data\Babylon
2008-02-06 16:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Babylon
2008-02-06 12:00 --------- d-----w C:\Documents and Settings\Sivan\Application Data\U3
2008-02-06 11:02 --------- d-----w C:\Program Files\Java
2008-02-06 10:52 --------- d-----w C:\Program Files\Notepad++
2008-01-30 20:13 --------- d-----w C:\Program Files\IsoBuster
2008-01-30 10:42 --------- d-----w C:\Program Files\Google
2008-01-30 10:33 --------- d-----w C:\Program Files\Common Files\Logitech
2008-01-30 10:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-30 10:18 --------- d-----w C:\Documents and Settings\Sivan\Application Data\Skype
2008-01-30 10:16 --------- d-----w C:\Program Files\Winamp
2008-01-28 05:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-25 09:08 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-01-22 14:20 --------- d-----w C:\Program Files\iTunes
2008-01-15 15:17 --------- d-----w C:\Program Files\Encore
2008-01-05 09:23 --------- d-----w C:\Program Files\RealVNC
2007-12-28 08:35 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-25 09:06 --------- d-----w C:\Program Files\BSplayerPro
2007-12-22 13:44 --------- d-----w C:\Program Files\Windows Live
2007-12-22 13:42 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2007-12-22 13:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-21 06:21 71,176 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2007-12-21 06:21 53,768 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2007-12-21 06:21 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2007-12-21 06:20 30,216 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2007-12-21 06:19 39,944 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2007-12-15 11:27 --------- d-----w C:\Program Files\WinXP Manager
2007-12-15 11:25 --------- d-----w C:\Program Files\Your Uninstaller 2008
2007-12-15 11:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\BVRP Software
2007-12-15 11:00 --------- d-----w C:\Documents and Settings\Sivan\Application Data\URSoft
2007-07-26 08:50 92,064 ----a-w C:\Documents and Settings\Sivan\mqdmmdm.sys
2007-07-26 08:50 9,232 ----a-w C:\Documents and Settings\Sivan\mqdmmdfl.sys
2007-07-26 08:50 79,328 ----a-w C:\Documents and Settings\Sivan\mqdmserd.sys
2007-07-26 08:50 66,656 ----a-w C:\Documents and Settings\Sivan\mqdmbus.sys
2007-07-26 08:50 6,208 ----a-w C:\Documents and Settings\Sivan\mqdmcmnt.sys
2007-07-26 08:50 5,936 ----a-w C:\Documents and Settings\Sivan\mqdmwhnt.sys
2007-07-26 08:50 4,048 ----a-w C:\Documents and Settings\Sivan\mqdmcr.sys
2007-07-26 08:50 25,600 ----a-w C:\Documents and Settings\Sivan\usbsermptxp.sys
2007-07-26 08:50 22,768 ----a-w C:\Documents and Settings\Sivan\usbsermpt.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7478B4A7-B79F-4011-AB71-F09EC8905B40}]
C:\WINDOWS\system32\ddcya.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Active Desktop Calendar"="C:\Program Files\Active Desktop Calendar\ADC.exe" [2006-06-07 09:42 2322432]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 20:18 68856]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-10-13 18:48 160592]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 14:00 33280 C:\WINDOWS\system32\rundll32.exe]
"Cmaudio"="cmicnfg.cpl" []
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"Babylon Client"="C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" [2007-12-20 07:20 3116768]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-04 14:00 33280 C:\WINDOWS\system32\rundll32.exe]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2007-12-21 08:21 1443072]
"8c69b460"="rundll32.exe" [2004-08-04 14:00 33280 C:\WINDOWS\system32\rundll32.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-02-08 09:14:11 450560]
Rupsmon Daemon.lnk - C:\Program Files\UPSilon 2000\Monw32.exe [2007-07-19 17:14:30 32768]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 11 (0xb)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"NTSpool"= NTSpool.exe
"WinUpdating"= WinUpdating.exe
"Windows Printing Driver"= WinSpooler.exe
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{42A44A09-3A1E-4BA2-B14C-D8398E0C3317}"= C:\WINDOWS\system32\opnljge.dll [2008-02-08 23:58 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnljge]
opnljge.dll 2008-02-08 23:58 45056 C:\WINDOWS\system32\opnljge.dll
R2 LF30FS;LF30FS;C:\Program Files\Lock Folder XP 3.5\LF30XP.sys [2004-11-19 17:07]
R2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\system32\inetsrv\inetinfo.exe [2004-08-04 14:00]
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 14:00]
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys [2006-11-10 18:23]
S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys [2006-11-10 18:23]
S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys [2006-11-10 18:23]
S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys [2006-11-10 18:23]
S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS);C:\WINDOWS\system32\DRIVERS\se2End5.sys [2006-11-10 18:23]
S3 SE2Eobex;Sony Ericsson Device 046 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Eobex.sys [2006-11-10 18:23]
S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM);C:\WINDOWS\system32\DRIVERS\se2Eunic.sys [2006-11-10 18:24]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-01-26 13:11]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" [2005-09-23 07:01]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2008-02-08 15:21:52 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
"2008-02-05 12:25:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-08 23:56:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\opnljge.dll
-> C:\WINDOWS\system32\pmnopnl.dll
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\Program Files\Active Desktop Calendar\MouseHook.dll
-> C:\WINDOWS\system32\opnljge.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\UPSilon 2000\RupsMon.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2008-02-09 0:00:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-08 22:00:08
.
2008-01-10 21:04:04 --- E O F ---
And Here is my Hijack Log:
ComboFix 08-02.05.3 - Sivan 2008-02-08 23:48:07.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1255.972.1033.18.465 [GMT 2:00]
Running from: C:\Documents and Settings\Sivan\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\byxwvtu.dll
C:\WINDOWS\system32\jkhfd.dll
C:\WINDOWS\system32\qpwdener.dll
C:\Documents and Settings\Sivan\Application Data\macromedia\Flash Player\#SharedObjects\VZ272JGE\iforex.com
C:\Documents and Settings\Sivan\Application Data\macromedia\Flash Player\#SharedObjects\VZ272JGE\iforex.com\Emerp\Events\flash_object.swf\user_data.sol
C:\Documents and Settings\Sivan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com
C:\Documents and Settings\Sivan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#iforex.com\settings.sol
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\byxwvtu.dll
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\cbxyywx.dll
C:\WINDOWS\system32\dfhkj.ini
C:\WINDOWS\system32\dfhkj.ini2
C:\WINDOWS\system32\eadwuvdh.ini
C:\WINDOWS\system32\filtrnap.ini
C:\WINDOWS\system32\ihtnanet.ini
C:\WINDOWS\system32\jkhfd.dll
C:\WINDOWS\system32\kpybfttu.ini
C:\WINDOWS\system32\lyweeaxp.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mftxjdye.ini
C:\WINDOWS\system32\mtwjveyg.ini
C:\WINDOWS\system32\qjfvrphk.ini
C:\WINDOWS\system32\qpwdener.dll
C:\WINDOWS\system32\qpwdener.dllbox
C:\WINDOWS\system32\tcsekiuo.ini
C:\WINDOWS\system32\vtusqnk.dll
C:\WINDOWS\system32\wwokhnbh.dll
.
((((((((((((((((((((((((( Files Created from 2008-01-08 to 2008-02-08 )))))))))))))))))))))))))))))))
.
2008-02-08 13:56 . 2006-07-07 16:41 14,848 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-02-08 12:55 . 2008-02-08 12:55 163,904 --a------ C:\WINDOWS\system32\imgzfjfn.dll.vir
2008-02-08 11:48 . 2008-02-08 11:48 38,400 --a------ C:\WINDOWS\system32\pmnkjgd.dll.vir
2008-02-08 10:21 . 2008-02-08 23:37 <DIR> d-------- C:\VundoFix Backups
2008-02-08 08:47 . 2008-02-08 08:47 <DIR> d-------- C:\Program Files\ESET
2008-02-08 08:42 . 2008-02-08 17:40 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-08 08:42 . 2008-02-08 08:42 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-05 20:57 . 2008-02-05 20:57 268 --ah----- C:\sqmdata02.sqm
2008-02-05 20:57 . 2008-02-05 20:57 244 --ah----- C:\sqmnoopt02.sqm
2008-02-05 20:52 . 2008-02-05 20:52 268 --ah----- C:\sqmdata01.sqm
2008-02-05 20:52 . 2008-02-05 20:52 244 --ah----- C:\sqmnoopt01.sqm
2008-01-30 12:37 . 2008-01-30 12:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\LogiShrd
2008-01-30 12:32 . 2008-02-08 09:03 <DIR> d-------- C:\Program Files\Common Files\Logishrd
2008-01-30 12:32 . 2008-01-30 12:32 <DIR> d-------- C:\Documents and Settings\Sivan\Application Data\InstallShield
2008-01-30 12:32 . 2008-01-30 12:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Logitech
2008-01-30 12:27 . 2007-12-17 13:53 159,458 --a------ C:\WINDOWS\system32\nvapps.nvb
2008-01-30 12:26 . 2007-12-05 02:53 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-01-30 00:28 . 2008-01-07 14:29 352 --ah----- C:\WINDOWS\nod32fixtemdono.reg
2008-01-29 12:56 . 2008-02-03 21:52 37,888 --a------ C:\WINDOWS\system32\rar.exe
2008-01-29 11:26 . 2008-01-29 11:26 <DIR> d-------- C:\Documents and Settings\Sivan\Application Data\ESET
2008-01-29 11:25 . 2008-01-29 11:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-01-26 13:26 . 2008-01-26 13:26 115,415,432 --a------ C:\BackupRegistry(20080126).reg
2008-01-26 13:11 . 2008-01-26 13:11 306,432 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-01-26 13:11 . 2007-12-20 10:41 29,440 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-01-22 16:19 . 2008-01-22 16:19 <DIR> d-------- C:\Program Files\iPod
2008-01-22 16:16 . 2008-01-22 16:17 <DIR> d-------- C:\Program Files\QuickTime
2008-01-14 22:10 . 2008-02-08 09:36 <DIR> d-------- C:\Downloads
2008-01-10 15:27 . 2008-01-10 15:27 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-01-10 15:27 . 2008-01-10 15:27 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-08 21:57 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-08 08:14 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-02-08 08:14 --------- d-----w C:\Program Files\A1Click Ultra PC Cleaner
2008-02-08 07:28 --------- d-----w C:\Program Files\RegVac Registry Cleaner
2008-02-08 07:14 --------- d-----w C:\Program Files\Logitech
2008-02-06 16:44 --------- d-----w C:\Documents and Settings\Sivan\Application Data\Babylon
2008-02-06 16:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Babylon
2008-02-06 12:00 --------- d-----w C:\Documents and Settings\Sivan\Application Data\U3
2008-02-06 11:02 --------- d-----w C:\Program Files\Java
2008-02-06 10:52 --------- d-----w C:\Program Files\Notepad++
2008-01-30 20:13 --------- d-----w C:\Program Files\IsoBuster
2008-01-30 10:42 --------- d-----w C:\Program Files\Google
2008-01-30 10:33 --------- d-----w C:\Program Files\Common Files\Logitech
2008-01-30 10:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-30 10:18 --------- d-----w C:\Documents and Settings\Sivan\Application Data\Skype
2008-01-30 10:16 --------- d-----w C:\Program Files\Winamp
2008-01-28 05:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-25 09:08 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-01-22 14:20 --------- d-----w C:\Program Files\iTunes
2008-01-15 15:17 --------- d-----w C:\Program Files\Encore
2008-01-05 09:23 --------- d-----w C:\Program Files\RealVNC
2007-12-28 08:35 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-25 09:06 --------- d-----w C:\Program Files\BSplayerPro
2007-12-22 13:44 --------- d-----w C:\Program Files\Windows Live
2007-12-22 13:42 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2007-12-22 13:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-21 06:21 71,176 ----a-w C:\WINDOWS\system32\drivers\epfw.sys
2007-12-21 06:21 53,768 ----a-w C:\WINDOWS\system32\drivers\epfwtdi.sys
2007-12-21 06:21 30,728 ----a-w C:\WINDOWS\system32\drivers\epfwndis.sys
2007-12-21 06:20 30,216 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
2007-12-21 06:19 39,944 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
2007-12-15 11:27 --------- d-----w C:\Program Files\WinXP Manager
2007-12-15 11:25 --------- d-----w C:\Program Files\Your Uninstaller 2008
2007-12-15 11:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\BVRP Software
2007-12-15 11:00 --------- d-----w C:\Documents and Settings\Sivan\Application Data\URSoft
2007-07-26 08:50 92,064 ----a-w C:\Documents and Settings\Sivan\mqdmmdm.sys
2007-07-26 08:50 9,232 ----a-w C:\Documents and Settings\Sivan\mqdmmdfl.sys
2007-07-26 08:50 79,328 ----a-w C:\Documents and Settings\Sivan\mqdmserd.sys
2007-07-26 08:50 66,656 ----a-w C:\Documents and Settings\Sivan\mqdmbus.sys
2007-07-26 08:50 6,208 ----a-w C:\Documents and Settings\Sivan\mqdmcmnt.sys
2007-07-26 08:50 5,936 ----a-w C:\Documents and Settings\Sivan\mqdmwhnt.sys
2007-07-26 08:50 4,048 ----a-w C:\Documents and Settings\Sivan\mqdmcr.sys
2007-07-26 08:50 25,600 ----a-w C:\Documents and Settings\Sivan\usbsermptxp.sys
2007-07-26 08:50 22,768 ----a-w C:\Documents and Settings\Sivan\usbsermpt.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7478B4A7-B79F-4011-AB71-F09EC8905B40}]
C:\WINDOWS\system32\ddcya.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Active Desktop Calendar"="C:\Program Files\Active Desktop Calendar\ADC.exe" [2006-06-07 09:42 2322432]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 20:18 68856]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-10-13 18:48 160592]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-04 14:00 33280 C:\WINDOWS\system32\rundll32.exe]
"Cmaudio"="cmicnfg.cpl" []
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"Babylon Client"="C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" [2007-12-20 07:20 3116768]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-04 14:00 33280 C:\WINDOWS\system32\rundll32.exe]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2007-12-21 08:21 1443072]
"8c69b460"="rundll32.exe" [2004-08-04 14:00 33280 C:\WINDOWS\system32\rundll32.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-02-08 09:14:11 450560]
Rupsmon Daemon.lnk - C:\Program Files\UPSilon 2000\Monw32.exe [2007-07-19 17:14:30 32768]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 11 (0xb)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"NTSpool"= NTSpool.exe
"WinUpdating"= WinUpdating.exe
"Windows Printing Driver"= WinSpooler.exe
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{42A44A09-3A1E-4BA2-B14C-D8398E0C3317}"= C:\WINDOWS\system32\opnljge.dll [2008-02-08 23:58 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnljge]
opnljge.dll 2008-02-08 23:58 45056 C:\WINDOWS\system32\opnljge.dll
R2 LF30FS;LF30FS;C:\Program Files\Lock Folder XP 3.5\LF30XP.sys [2004-11-19 17:07]
R2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\system32\inetsrv\inetinfo.exe [2004-08-04 14:00]
R2 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2007-02-10 05:29]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 14:00]
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys [2006-11-10 18:23]
S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys [2006-11-10 18:23]
S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys [2006-11-10 18:23]
S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys [2006-11-10 18:23]
S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS);C:\WINDOWS\system32\DRIVERS\se2End5.sys [2006-11-10 18:23]
S3 SE2Eobex;Sony Ericsson Device 046 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Eobex.sys [2006-11-10 18:23]
S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM);C:\WINDOWS\system32\DRIVERS\se2Eunic.sys [2006-11-10 18:24]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-01-26 13:11]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;"C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe" [2005-09-23 07:01]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2008-02-08 15:21:52 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe
"2008-02-05 12:25:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-08 23:56:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\opnljge.dll
-> C:\WINDOWS\system32\pmnopnl.dll
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\Program Files\Active Desktop Calendar\MouseHook.dll
-> C:\WINDOWS\system32\opnljge.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\UPSilon 2000\RupsMon.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2008-02-09 0:00:13 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-08 22:00:08
.
2008-01-10 21:04:04 --- E O F ---
Thanks for all of your help again