combofix logg:
ComboFix 07-08-30.3 - "" 2007-08-30 22:39:38.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1053.18.145 [GMT 2:00]
* Created a new restore point
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\components
((((((((((((((((((((((((( Files Created from 2007-07-28 to 2007-08-30 )))))))))))))))))))))))))))))))
2007-08-30 22:38 51,200 --a------ C:\Windows\nircmd.exe
2007-08-30 20:47 <KAT> d-------- C:\Windows\ERUNT
2007-08-30 15:02 <KAT> d-------- C:\Rustbfix
2007-08-28 21:24 <KAT> d-------- C:\Program\Trend Micro
2007-08-28 18:07 <KAT> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-08-28 18:06 <KAT> d-------- C:\Program\SUPERAntiSpyware
2007-08-28 18:06 <KAT> d-------- C:\Program\Delade filer\Wise Installation Wizard
2007-08-28 18:06 <KAT> d-------- C:\DOCUME~1\SALIMG~1\APPLIC~1\SUPERAntiSpyware.com
2007-08-14 20:27 <KAT> d-------- C:\Program\iPod
2007-08-14 20:21 <KAT> d-------- C:\Program\Apple Software Update
2007-08-14 20:21 <KAT> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-07-31 15:24 <KAT> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-07-30 19:19 203,096 --a------ C:\Windows\system32\wuweb.dll
2007-07-30 19:18 207,736 --a------ C:\Windows\system32\muweb.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
2007-08-30 22:30 --------- d-------- C:\Program\Soulseek
2007-08-30 20:14 --------- d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\NPF
2007-08-30 17:10 --------- d-------- C:\DOCUME~1\SALIMG~1\APPLIC~1\uTorrent
2007-08-27 23:55 --------- d-------- C:\Program\MyWay
2007-08-14 20:27 --------- d-------- C:\Program\iTunes
2007-08-14 20:24 --------- d-------- C:\Program\QuickTime
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SynTPLpr"="C:\Program\Synaptics\SynTP\SynTPLpr.ex e" []
"SoundMan"="SOUNDMAN.EXE" [2004-08-30 23:48 C:\Windows\SOUNDMAN.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-21 15:00 C:\Windows\AGRSMMSG.exe]
"TkBellExe"="C:\Program\Delade filer\Real\Update_OB\realsched.exe" []
"QuickTime Task"="C:\Program\QuickTime\qttask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program\iTunes\iTunesHelper.exe " [2007-07-31 18:44]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-09-11 14:00]
"SUPERAntiSpyware"="C:\Program\SUPERAntiSpyware\SU PERAntiSpyware.exe" [2007-06-21 14:06]
C:\DOCUME~1\SALIMG~1\START-~1\Program\AUTOST~1\
Microsoft Office Snabbskning.lnk - C:\Program\Microsoft Word 97\Office\FINDFAST.EXE [1997-02-10]
Office-autostart.lnk - C:\Program\Microsoft Word 97\Office\OSA.EXE [1997-02-10]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program\SUPERAntiSpyware\SASWINLO.dll
R0 avgntmgr;avgntmgr;C:\WINDOWS\System32\drivers\avgn tmgr.sys
R0 NDIS_RD;Firewall Engine Type-R2;C:\WINDOWS\System32\drivers\NDIS_RD.sys
R1 avgntdd;avgntdd;C:\WINDOWS\System32\DRIVERS\avgntd d.sys
R1 sdcplh;sdcplh;C:\WINDOWS\System32\drivers\sdcplh.s ys
R1 TDI_RD;Firewall Engine Type-R;\??\C:\WINDOWS\System32\drivers\tdi_rd.sys
R2 Ndiskio;Ndiskio;\??\C:\NORMAN\Nvc\NSE\NDISKIO.SYS
R3 nvcfsr;nvcfsr;\??\C:\NORMAN\Nvc\BIN\nvcfsr.sys
R3 nvcoafl51;nvcoafl51;\??\C:\NORMAN\Nvc\BIN\nvcoafl5 1.sys
R3 nvcoaft51;nvcoaft51;\??\C:\NORMAN\Nvc\BIN\nvcoaft5 1.sys
R3 nvcoarc51;nvcoarc51;\??\C:\NORMAN\Nvc\BIN\nvcoarc5 1.sys
R3 nvcoas;Norman Virus Control on-access component;C:\NORMAN\Nvc\BIN\nvcoas.exe
R3 NVCScheduler;Norman Virus Control Scheduler;C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
R3 PRISM_A00;PRISM 802.11 Driver;C:\WINDOWS\System32\DRIVERS\PRISMA00.sys
S3 55cce156-0eee-4ad4-9977-f6c6ed53497f;55cce156-0eee-4ad4-9977-f6c6ed53497f;\??\E:\Player\cds300.dll
*Newly Created Service* - ALG
*Newly Created Service* - CATCHME
*Newly Created Service* - IPNAT
*Newly Created Service* - SHAREDACCESS
Contents of the 'Scheduled Tasks' folder
2007-08-16 18:03:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program\Apple Software Update\SoftwareUpdate.exe
2007-08-28 22:00:00 C:\WINDOWS\Tasks\At1.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-27 13:39:51 C:\WINDOWS\Tasks\At10.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-29 08:00:00 C:\WINDOWS\Tasks\At11.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-27 13:39:51 C:\WINDOWS\Tasks\At12.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-29 10:00:00 C:\WINDOWS\Tasks\At13.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-27 13:39:51 C:\WINDOWS\Tasks\At14.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-30 12:00:00 C:\WINDOWS\Tasks\At15.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-30 13:00:00 C:\WINDOWS\Tasks\At16.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-30 14:00:00 C:\WINDOWS\Tasks\At17.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-30 15:00:00 C:\WINDOWS\Tasks\At18.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-30 16:00:00 C:\WINDOWS\Tasks\At19.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-27 23:01:00 C:\WINDOWS\Tasks\At2.job
2007-08-28 17:00:00 C:\WINDOWS\Tasks\At20.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-30 17:59:59 C:\WINDOWS\Tasks\At21.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-30 19:00:00 C:\WINDOWS\Tasks\At22.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-30 20:00:00 C:\WINDOWS\Tasks\At23.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-28 21:00:00 C:\WINDOWS\Tasks\At24.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-27 13:39:51 C:\WINDOWS\Tasks\At3.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-27 13:39:51 C:\WINDOWS\Tasks\At4.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-27 13:39:51 C:\WINDOWS\Tasks\At5.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-27 13:39:51 C:\WINDOWS\Tasks\At6.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-27 13:39:51 C:\WINDOWS\Tasks\At7.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-27 13:39:51 C:\WINDOWS\Tasks\At8.job - C:\WINDOWS\System32\k1qnIhv5.exe
2007-08-27 13:39:51 C:\WINDOWS\Tasks\At9.job - C:\WINDOWS\System32\k1qnIhv5.exe
************************************************** ************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-30 22:41:50
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
Completion time: 2007-08-30 22:42:34
C:\ComboFix-quarantined-files.txt ... 2007-08-30 22:42
--- E O F ---