Yes, I did runed combofix twiece, becouse the first time the log was empty. I will make an update on the system behavior in a few hours, I've just come home from some friends... Thank you again for the help
ComboFix 09-04-04.01 - Andu 2009-04-10 13:36:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2037.1604 [GMT 3:00]
Running from: c:\documents and settings\Andu\Desktop\ComboFix.exe
AV: Avira Premium Security Suite *On-access scanning disabled* (Outdated)
FW: Avira Firewall *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Andu\LOCALS~1\Temp\tmp2.tmp
.
((((((((((((((((((((((((( Files Created from 2009-03-10 to 2009-04-10 )))))))))))))))))))))))))))))))
.
2009-04-10 02:39 . 2009-04-10 02:46 <DIR> d-------- c:\program files\Boxen Die Championship Simulation
2009-04-06 00:05 . 2009-04-06 00:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\Seagate
2009-04-06 00:04 . 2009-04-06 00:04 441,760 --a------ c:\windows\system32\drivers\timntr.sys
2009-04-06 00:04 . 2009-04-06 00:04 368,480 --a------ c:\windows\system32\drivers\tdrpman.sys
2009-04-06 00:04 . 2009-04-06 00:04 132,224 --a------ c:\windows\system32\drivers\snapman.sys
2009-04-06 00:04 . 2009-04-06 00:04 44,384 --a------ c:\windows\system32\drivers\tifsfilt.sys
2009-04-06 00:01 . 2009-04-06 00:01 <DIR> d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2009-04-05 22:35 . 2009-04-05 22:36 <DIR> d-------- c:\program files\Bonjour
2009-04-05 22:25 . 2009-04-05 22:25 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2009-04-05 16:46 . 2009-04-05 16:46 <DIR> d-------- c:\documents and settings\Andu\Application Data\Avira
2009-04-02 01:10 . 2009-04-02 01:10 <DIR> d-------- c:\program files\EnRo Dictionary
2009-04-01 00:18 . 2009-04-06 01:00 <DIR> d-------- c:\program files\The KMPlayer
2009-03-31 21:25 . 2009-03-31 21:25 54,156 --ah----- c:\windows\QTFont.qfn
2009-03-31 21:25 . 2009-03-31 21:25 1,409 --a------ c:\windows\QTFont.for
2009-03-31 21:21 . 2009-03-31 21:21 172 --a------ c:\windows\wcx_ftp.ini
2009-03-31 21:12 . 2009-03-31 21:12 <DIR> d-------- C:\totalcmd
2009-03-31 21:12 . 2009-03-31 21:37 769 --a------ c:\windows\wincmd.ini
2009-03-31 21:12 . 2008-08-08 07:04 545 --a------ c:\windows\UC.PIF
2009-03-31 21:12 . 2008-08-08 07:04 545 --a------ c:\windows\RAR.PIF
2009-03-31 21:12 . 2008-08-08 07:04 545 --a------ c:\windows\PKZIP.PIF
2009-03-31 21:12 . 2008-08-08 07:04 545 --a------ c:\windows\PKUNZIP.PIF
2009-03-31 21:12 . 2008-08-08 07:04 545 --a------ c:\windows\NOCLOSE.PIF
2009-03-31 21:12 . 2008-08-08 07:04 545 --a------ c:\windows\LHA.PIF
2009-03-31 21:12 . 2008-08-08 07:04 545 --a------ c:\windows\ARJ.PIF
2009-03-30 21:11 . 2009-03-30 21:11 <DIR> d-------- c:\program files\Lavalys
2009-03-30 20:51 . 2009-03-30 21:10 <DIR> d-------- c:\program files\Everest
2009-03-30 17:01 . 2009-03-30 17:01 <DIR> d-------- c:\program files\Logitech
2009-03-30 17:01 . 2009-03-30 17:01 <DIR> d-------- c:\program files\Common Files\Logitech
2009-03-30 17:01 . 2003-03-18 22:20 1,060,864 --a------ c:\windows\system32\MFC71.dll
2009-03-30 17:01 . 2003-03-18 21:14 499,712 --a------ c:\windows\system32\msvcp71.dll
2009-03-30 17:01 . 2003-02-21 05:42 348,160 --a------ c:\windows\system32\Msvcr71.dll
2009-03-30 17:01 . 2002-01-05 04:38 54,784 --a------ c:\windows\system32\MSVCI70.DLL
2009-03-30 17:01 . 2004-03-03 09:50 37,887 --a------ c:\windows\system32\drivers\LHidUsb.sys
2009-03-30 17:01 . 2004-03-03 09:50 14,095 --a------ c:\windows\system32\drivers\LCcfltr.sys
2009-03-30 17:01 . 2004-03-10 13:42 12,953 --------- c:\windows\system32\drivers\itchfltr.sys
2009-03-30 17:01 . 2009-04-10 12:37 65 --a------ c:\windows\iTouch.ini
2009-03-30 16:11 . 2009-03-30 16:11 <DIR> d-------- c:\program files\Yahoo!
2009-03-30 16:11 . 2009-03-30 16:11 <DIR> d-------- c:\documents and settings\LocalService\Application Data\PeerNetworking
2009-03-30 16:11 . 2009-03-30 16:11 <DIR> d-------- c:\documents and settings\Andu\Application Data\Yahoo!
2009-03-30 16:11 . 2009-03-30 16:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-03-30 16:11 . 2009-03-30 16:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2009-03-30 16:00 . 2009-03-30 16:00 <DIR> d-------- c:\documents and settings\Andu\Application Data\Realtime Soft
2009-03-30 15:40 . 2009-03-30 15:40 <DIR> d-------- c:\documents and settings\Andu\Application Data\DAEMON Tools
2009-03-30 15:39 . 2009-03-30 16:37 <DIR> d-------- c:\documents and settings\Andu\Application Data\DisplayTune
2009-03-30 15:37 . 2009-03-30 15:37 <DIR> d-------- c:\program files\DAEMON Tools Toolbar
2009-03-30 15:37 . 2009-03-30 15:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-03-30 15:36 . 2009-03-30 15:39 <DIR> d-------- c:\program files\DAEMON Tools Lite
2009-03-30 15:36 . 2009-03-30 19:11 <DIR> d-------- c:\documents and settings\Andu\Application Data\DAEMON Tools Lite
2009-03-30 15:33 . 2004-08-04 01:56 1,392,671 --a------ c:\windows\msvbvm60.dll
2009-03-30 15:33 . 2002-01-05 04:40 487,424 --a------ c:\windows\msvcp70.dll
2009-03-30 15:33 . 2002-01-05 04:37 344,064 --a------ c:\windows\msvcr70.dll
2009-03-30 15:27 . 2006-11-10 08:25 319,456 --a------ c:\windows\system32\difxapi.dll
2009-03-30 15:27 . 2007-09-05 17:13 170,520 --a------ c:\windows\system32\igfxzoom.exe
2009-03-30 15:27 . 2007-08-24 11:29 147,456 --a------ c:\windows\system32\igfxCoIn_v4864.dll
2009-03-30 15:26 . 2009-04-06 00:37 <DIR> d-------- c:\windows\RaidTool
2009-03-30 15:26 . 2009-03-30 15:26 <DIR> d-------- C:\RaidTool
2009-03-30 15:26 . 2007-11-19 11:28 1,966,080 --a------ c:\windows\system32\xRaidSetup.exe
2009-03-30 15:26 . 2008-03-19 10:54 151,552 --a------ c:\windows\system32\xRaidAPI.dll
2009-03-30 15:26 . 2008-10-01 14:32 82,272 --a------ c:\windows\system32\drivers\jraid.sys
2009-03-30 15:20 . 2009-03-30 16:51 <DIR> d----c--- c:\windows\system32\DRVSTORE
2009-03-30 15:20 . 2009-03-30 21:24 <DIR> d-------- c:\program files\Intel
2009-03-30 15:20 . 2009-03-30 15:20 <DIR> d-------- C:\Intel
2009-03-30 15:20 . 2007-07-26 16:15 53,248 --a------ c:\windows\system32\CSVer.dll
2009-03-30 15:19 . 2008-08-05 20:10 1,684,736 --a------ c:\windows\system32\drivers\Ambfilt.sys
2009-03-30 15:19 . 2006-01-04 15:41 1,389,056 --a------ c:\windows\system32\drivers\Monfilt.sys
2009-03-30 15:19 . 2008-10-23 17:42 290,816 --a------ c:\windows\vncutil.exe
2009-03-30 15:19 . 2008-06-24 14:46 104,992 --a------ c:\windows\RtkAudioService.exe
2009-03-30 15:19 . 2009-02-09 14:34 35,840 --a------ c:\windows\system32\RtkCoInstXP.dll
2009-03-30 15:18 . 2009-03-23 11:13 <DIR> d-------- c:\program files\HD_Audio
2009-03-30 14:55 . 2009-03-30 14:55 1,148 --a------ c:\windows\mozver.dat
2009-03-30 14:43 . 2009-03-30 14:43 <DIR> d-------- c:\windows\Sun
2009-03-30 14:43 . 2009-03-30 14:43 <DIR> d-------- c:\program files\SystemRequirementsLab
2009-03-30 14:43 . 2009-03-30 14:43 <DIR> d-------- c:\documents and settings\Andu\Application Data\SystemRequirementsLab
2009-03-30 14:41 . 2009-03-30 14:41 <DIR> d-------- c:\program files\Java
2009-03-30 14:41 . 2009-03-30 14:41 410,984 --a------ c:\windows\system32\deploytk.dll
2009-03-30 14:41 . 2009-03-30 14:41 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-03-26 11:54 . 2009-04-09 11:39 <DIR> d-------- c:\program files\oDC
2009-03-26 01:31 . 2009-03-26 01:31 <DIR> d-------- c:\documents and settings\Andu\Application Data\vlc
2009-03-26 01:22 . 2009-03-26 01:22 940,794 --a------ c:\windows\system32\LoopyMusic.wav
2009-03-26 01:22 . 2009-03-26 01:22 146,650 --a------ c:\windows\system32\BuzzingBee.wav
2009-03-26 01:19 . 2009-03-26 01:19 <DIR> d-------- c:\program files\Realtek
2009-03-26 01:19 . 2009-04-08 22:19 <DIR> d--h----- c:\program files\InstallShield Installation Information
2009-03-26 01:19 . 2009-03-30 17:00 <DIR> d-------- c:\program files\Common Files\InstallShield
2009-03-26 01:19 . 2009-02-17 15:50 17,508,864 --a------ c:\windows\RTHDCPL.EXE
2009-03-26 01:19 . 2008-06-19 16:27 9,715,200 --a------ c:\windows\RTLCPL.EXE
2009-03-26 01:19 . 2009-02-17 16:55 5,026,816 --a------ c:\windows\system32\drivers\RtkHDAud.sys
2009-03-26 01:19 . 2008-06-19 16:42 2,808,832 --a------ c:\windows\ALCWZRD.EXE
2009-03-26 01:19 . 2008-09-30 16:38 2,168,320 --a------ c:\windows\MicCal.exe
2009-03-26 01:19 . 2007-11-20 18:15 1,826,816 --a------ c:\windows\SkyTel.exe
2009-03-26 01:19 . 2009-01-21 15:54 1,206,816 --a------ c:\windows\RtlUpd.exe
2009-03-26 01:19 . 2008-08-25 16:17 528,384 --a------ c:\windows\RtlExUpd.dll
2009-03-26 01:19 . 2008-06-19 16:24 278,528 --a------ c:\windows\system32\ALSNDMGR.CPL
2009-03-26 01:19 . 2008-03-13 14:52 266,240 --a------ c:\windows\system32\RTSndMgr.CPL
2009-03-26 01:19 . 2008-08-19 13:26 77,824 --a------ c:\windows\SOUNDMAN.EXE
2009-03-26 01:19 . 2008-06-19 16:20 57,344 --a------ c:\windows\ALCMTR.EXE
2009-03-26 01:18 . 2009-03-26 01:18 <DIR> d-------- c:\documents and settings\Andu\Application Data\InstallShield
2009-03-26 00:48 . 2009-03-26 00:48 <DIR> d-------- c:\program files\Common Files\xing shared
2009-03-26 00:47 . 2009-03-26 00:47 <DIR> d-------- c:\windows\system32\QuickTime
2009-03-26 00:47 . 2009-03-26 00:47 <DIR> d-------- c:\program files\Real
2009-03-26 00:47 . 2009-03-26 00:47 <DIR> d-------- c:\program files\QuickTime
2009-03-26 00:47 . 2009-03-26 00:48 <DIR> d-------- c:\program files\Common Files\Real
2009-03-26 00:47 . 1999-11-10 10:35 86,016 --a------ c:\windows\unvise32qt.exe
2009-03-26 00:46 . 2009-03-26 00:46 <DIR> d-------- c:\program files\VideoLAN
2009-03-26 00:46 . 2009-03-26 00:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\QuickTime
2009-03-26 00:43 . 2009-03-26 00:43 <DIR> d-------- c:\program files\uTorrent
2009-03-26 00:43 . 2009-04-10 02:49 <DIR> d-------- c:\documents and settings\Andu\Application Data\uTorrent
2009-03-26 00:38 . 2009-03-26 00:38 <DIR> d-------- c:\program files\Avira
2009-03-26 00:38 . 2009-03-26 00:39 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2009-03-26 00:38 . 2008-03-06 10:45 71,464 --a------ c:\windows\system32\drivers\avfwim.sys
2009-03-26 00:38 . 2008-02-07 08:30 66,176 --a------ c:\windows\system32\drivers\avfwot.sys
2009-03-26 00:33 . 2009-04-09 22:53 116 --a------ c:\windows\NeroDigital.ini
2009-03-26 00:30 . 2009-03-26 00:30 0 --a------ c:\windows\nsreg.dat
2009-03-26 00:25 . 2009-03-26 00:25 <DIR> d-------- c:\program files\Nero
2009-03-26 00:25 . 2009-03-26 00:25 <DIR> d-------- c:\program files\Common Files\Ahead
2009-03-26 00:25 . 2009-03-26 00:25 <DIR> d-------- c:\documents and settings\Andu\Application Data\Ahead
2009-03-26 00:15 . 2001-08-23 15:00 18,944 --a------ c:\windows\system32\simptcp.dll
2009-03-26 00:15 . 2001-08-23 15:00 18,944 --a--c--- c:\windows\system32\dllcache\simptcp.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-09 07:28 --------- d-----w c:\documents and settings\Andu\Application Data\U3
2009-04-08 17:59 --------- d-----w c:\documents and settings\Andu\Application Data\Winamp
2009-04-05 19:35 --------- d-----w c:\program files\Common Files\Adobe
2009-04-01 20:50 --------- d-----w c:\program files\Winamp
2009-03-30 12:40 --------- d-----w c:\documents and settings\Andu\Application Data\DAEMON Tools Pro
2009-03-25 22:03 --------- d-----w c:\program files\DAEMON Tools Pro
2009-03-23 19:00 --------- d-----w c:\program files\Common Files\Adobe AIR
2009-03-23 18:53 --------- d-----w c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2009-03-23 18:52 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2009-03-23 18:39 --------- d-----w c:\program files\microsoft frontpage
2009-03-23 18:35 --------- d-----w c:\program files\Windows Media Connect 2
2009-01-29 07:12 993,816 ----a-w c:\windows\system32\igxpun.exe
2009-01-21 08:52 155,648 ----a-w c:\windows\system32\igfxCoIn_v5029.dll
2009-01-21 08:44 3,773,440 ----a-w c:\windows\system32\igxpdx32.dll
2009-01-21 08:44 2,686,368 ----a-w c:\windows\system32\igxpdv32.dll
2009-01-21 08:43 57,344 ----a-w c:\windows\system32\igxprd32.dll
2009-01-21 08:43 183,808 ----a-w c:\windows\system32\igxpgd32.dll
2009-01-21 08:32 294,912 ----a-w c:\windows\system32\igldev32.dll
2009-01-21 08:32 2,342,912 ----a-w c:\windows\system32\iglicd32.dll
2009-01-21 08:20 645,632 ----a-w c:\windows\system32\igfxcfg.exe
2009-01-21 08:20 23,552 ----a-w c:\windows\system32\igfxexps.dll
2009-01-21 08:20 166,912 ----a-w c:\windows\system32\hkcmd.exe
2009-01-21 08:20 165,888 ----a-w c:\windows\system32\igfxext.exe
2009-01-21 08:20 134,656 ----a-w c:\windows\system32\igfxtray.exe
2009-01-21 08:18 51,712 ----a-w c:\windows\system32\igfxsrvc.dll
2009-01-21 08:18 243,712 ----a-w c:\windows\system32\igfxsrvc.exe
2009-01-21 08:18 199,168 ----a-w c:\windows\system32\igfxpph.dll
2009-01-21 08:18 134,656 ----a-w c:\windows\system32\igfxpers.exe
2009-01-21 08:18 130,048 ----a-w c:\windows\system32\igfxdo.dll
2009-01-21 08:17 93,696 ----a-w c:\windows\system32\hccutils.dll
2009-01-21 08:17 5,702,656 ----a-w c:\windows\system32\igfxress.dll
2009-01-21 08:17 205,824 ----a-w c:\windows\system32\igfxdev.dll
2009-01-13 22:16 122,880 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-03-09 37888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"avgnt"="c:\program files\Avira\Avira Premium Security Suite\avgnt.exe" [2008-02-12 262401]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-03-26 98304]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-26 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-30 148888]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-11-19 1966080]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-01-21 134656]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-01-21 166912]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-01-21 134656]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2004-03-18 892928]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-17 c:\windows\RTHDCPL.EXE]
c:\documents and settings\Andu\Start Menu\Programs\Startup\
Shortcut to iTouch.lnk - c:\program files\Logitech\iTouch\iTouch.exe [2009-03-30 892928]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"d:\\THQ\\MotoGP URT 3\\motogp.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP

eer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 avfwot;avfwot;c:\windows\system32\drivers\avfwot.sys [2009-03-26 66176]
R2 AntiVirFirewallService;Avira Premium Security Suite Firewall;c:\program files\Avira\Avira Premium Security Suite\avfwsvc.exe [2009-03-26 344321]
R2 AntiVirMailService;Avira Premium Security Suite MailGuard;c:\program files\Avira\Avira Premium Security Suite\avmailc.exe [2009-03-26 164097]
R2 antivirwebservice;Avira Premium Security Suite WebGuard;c:\program files\Avira\Avira Premium Security Suite\avwebgrd.exe [2009-03-26 254209]
R2 AVEService;Avira Premium Security Suite MailGuard helper service;c:\program files\Avira\Avira Premium Security Suite\avesvc.exe [2009-03-26 41217]
R3 avfwim;AvFw Packet Filter Miniport;c:\windows\system32\drivers\avfwim.sys [2009-03-26 71464]
R3 LCcfltr;Logitech USB Filter Driver;c:\windows\system32\drivers\LCcfltr.sys [2009-03-30 14095]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-03-30 1684736]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{63b956fb-17da-11de-bd23-db31aced8c58}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{63b956fc-17da-11de-bd23-db31aced8c58}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL J:\m.exe /s
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.daemon-search.com/startpage
uInternet Settings,ProxyOverride = *.local
LSP: avsda.dll
TCP: {6526CFEA-8F00-4C61-834C-2855AD97371D} = 193.19.192.15,193.19.192.16
FF - ProfilePath - c:\documents and settings\Andu\Application Data\Mozilla\Firefox\Profiles\udxb6omz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ro/
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-10 13:37:04
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(1232)
c:\windows\system32\avsda.dll
.
Completion time: 2009-04-10 13:37:31
ComboFix-quarantined-files.txt 2009-04-10 10:37:29
Pre-Run: 27,322,925,056 bytes free
Post-Run: 27,730,276,352 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
261