I was searching for some files on torrents and get Trojan.When running the exe I get Trojan.Dropper and some rootkit activity on my system.
People on forums told me this--This virus is designed to force advertising upon you and send information on your searches. Run ComboFix.exe and Super Anti-Spyware to remove it completely.
So I run COmbo fix and get this:
ComboFix 09-01-21.04 - User 2009-01-25 15:03:22.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.1.1033.18.2047.1293 [GMT 1:00]
Running from: c:\users\User\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-12-25 to 2009-01-25 )))))))))))))))))))))))))))))))
.
2009-01-25 14:13 . 2009-01-25 14:13 <DIR> d-------- c:\users\All Users\SUPERAntiSpyware.com
2009-01-25 14:13 . 2009-01-25 14:13 <DIR> d-------- c:\programdata\SUPERAntiSpyware.com
2009-01-25 14:12 . 2009-01-25 14:12 <DIR> d-------- c:\users\User\AppData\Roaming\SUPERAntiSpyware.com
2009-01-25 14:12 . 2009-01-25 14:12 <DIR> d-------- c:\program files\SUPERAntiSpyware
2009-01-25 13:14 . 2009-01-25 13:14 <DIR> d-------- c:\program files\Xvid
2009-01-25 13:14 . 2009-01-25 13:15 1,158,357 --a------ c:\windows\GPS 2008 ENGLISH DL Uninstaller.exe
2009-01-25 13:14 . 2006-11-01 14:52 765,952 --a------ c:\windows\System32\xvidcore.dll
2009-01-25 13:14 . 2006-11-01 14:54 180,224 --a------ c:\windows\System32\xvidvfw.dll
2009-01-25 13:14 . 2006-11-01 15:26 77,824 --a------ c:\windows\System32\xvid.ax
2009-01-25 13:13 . 2009-01-25 13:15 <DIR> d-------- c:\program files\Geo-Political Simulator
2009-01-25 13:13 . 2009-01-25 13:13 <DIR> d-------- c:\program files\Common Files\Thraex Software
2009-01-23 20:57 . 2009-01-23 20:57 <DIR> d-------- c:\program files\WBGames
2009-01-23 20:40 . 2008-10-10 04:52 4,379,984 --a------ c:\windows\System32\D3DX9_40.dll
2009-01-23 20:40 . 2008-10-27 10:04 514,384 --a------ c:\windows\System32\XAudio2_3.dll
2009-01-23 20:40 . 2008-10-27 10:04 70,992 --a------ c:\windows\System32\XAPOFX1_2.dll
2009-01-23 20:40 . 2008-10-27 10:04 23,376 --a------ c:\windows\System32\X3DAudio1_5.dll
2009-01-23 17:27 . 2009-01-23 17:27 376 --a------ c:\windows\ODBC.INI
2009-01-23 17:27 . 2009-01-23 17:27 35 --a------ c:\windows\vbaddin.ini
2009-01-23 17:26 . 2009-01-23 17:26 <DIR> d-------- c:\program files\Microsoft FrontPage
2009-01-23 17:25 . 2009-01-23 17:25 <DIR> d-------- c:\users\User\AppData\Roaming\Microsoft Web Folders
2009-01-21 17:59 . 2009-01-21 17:59 <DIR> dr-h----- c:\users\User\AppData\Roaming\SecuROM
2009-01-21 17:36 . 2009-01-21 17:36 <DIR> d-------- c:\users\User\AppData\Roaming\Spore
2009-01-19 22:09 . 2009-01-25 14:44 65,536 --------- c:\windows\System32\Ikeext.etl
2009-01-18 17:02 . 2009-01-23 12:16 <DIR> d-------- c:\users\All Users\WinZip
2009-01-18 17:02 . 2009-01-23 12:16 <DIR> d-------- c:\programdata\WinZip
2009-01-16 17:07 . 2009-01-16 17:07 <DIR> d--hs---- c:\windows\ftpcache
2009-01-16 15:35 . 2009-01-25 14:12 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-01-15 00:23 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-14 17:30 . 2009-01-14 17:30 <DIR> d-------- c:\users\User\AppData\Roaming\Imperium Romanum
2009-01-14 00:01 . 2009-01-14 00:01 <DIR> d-------- c:\program files\Activision
2009-01-12 15:28 . 2009-01-12 15:28 <DIR> d-------- c:\users\All Users\ICQ
2009-01-12 15:28 . 2009-01-12 15:28 <DIR> d-------- c:\programdata\ICQ
2009-01-10 18:53 . 2009-01-10 18:53 <DIR> d-------- c:\users\User\AppData\Roaming\Red Alert 3 Demo
2009-01-05 14:36 . 2009-01-07 10:56 <DIR> d-------- c:\program files\Common Files\Real
2009-01-05 14:15 . 2009-01-05 14:15 <DIR> d-------- c:\program files\VideoLAN
2009-01-05 10:02 . 2009-01-25 14:43 <DIR> d-------- c:\users\User\AppData\Roaming\BitTorrent
2009-01-01 17:41 . 2009-01-01 17:41 <DIR> d-------- c:\program files\Common Files\Adobe
2009-01-01 17:40 . 2009-01-02 11:01 <DIR> d-------- c:\users\All Users\NOS
2009-01-01 17:40 . 2009-01-02 11:01 <DIR> d-------- c:\programdata\NOS
2009-01-01 17:40 . 2009-01-02 11:01 <DIR> d-------- c:\program files\NOS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-23 19:57 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-23 11:28 --------- d-----w c:\program files\Electronic Arts
2009-01-23 11:11 --------- d-----w c:\programdata\Media Center Programs
2009-01-23 11:09 --------- d-----w c:\program files\AGEIA Technologies
2009-01-16 10:35 --------- d-----w c:\program files\Windows Mail
2008-12-23 05:34 --------- d-----w c:\program files\Google
2008-12-22 19:41 --------- d-----w c:\program files\Microsoft Games
2008-12-20 19:55 --------- d-----w c:\users\User\AppData\Roaming\Electronic Arts
2008-12-19 14:05 --------- d-----w c:\program files\BitTorrent
2008-12-19 14:04 --------- d-----w c:\program files\DNA
2008-12-15 17:56 --------- d-----w c:\program files\Nobilis
2008-12-15 14:32 --------- d-----w c:\users\User\AppData\Roaming\ProtectDisc
2008-12-15 14:09 --------- d-----w c:\program files\Windows Sidebar
2008-12-15 14:09 --------- d-----w c:\program files\Windows Photo Gallery
2008-12-15 14:09 --------- d-----w c:\program files\Windows Defender
2008-12-15 14:09 --------- d-----w c:\program files\Windows Collaboration
2008-12-15 14:09 --------- d-----w c:\program files\Windows Calendar
2008-12-13 22:50 --------- d-----w c:\programdata\Age of Empires 3 YPack Trial
2008-12-08 20:00 174 --sha-w c:\program files\desktop.ini
2008-12-08 19:54 --------- d-----w c:\program files\Windows Journal
2008-12-08 19:42 82,432 ----a-w c:\windows\System32\axaltocm.dll
2008-12-08 19:42 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2008-12-08 18:40 269,312 ----a-w c:\windows\System32\es.dll
2008-12-08 16:40 --------- d-----w c:\programdata\NVIDIA
2008-12-08 16:14 61,440 ----a-w c:\windows\System32\winipsec.dll
2008-12-08 16:14 361,984 ----a-w c:\windows\System32\IPSECSVC.DLL
2008-12-08 16:14 28,672 ----a-w c:\windows\System32\FwRemoteSvr.dll
2008-12-08 16:14 272,896 ----a-w c:\windows\System32\polstore.dll
2008-12-08 16:13 94,720 ----a-w c:\windows\System32\PortableDeviceClassExtension.dll
2008-12-08 16:13 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
2008-12-08 16:13 160,768 ----a-w c:\windows\System32\PortableDeviceTypes.dll
2008-12-08 16:12 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2008-12-08 16:12 1,695,744 ----a-w c:\windows\System32\gameux.dll
2008-12-08 16:08 428,544 ----a-w c:\windows\System32\EncDec.dll
2008-12-08 16:08 293,376 ----a-w c:\windows\System32\psisdecd.dll
2008-12-08 16:04 212,480 ----a-w c:\windows\system32\drivers\mrxsmb10.sys
2008-12-08 16:01 303,616 ----a-w c:\windows\System32\wmpeffects.dll
2008-12-08 16:01 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-12-08 16:00 2,048 ----a-w c:\windows\System32\msxml3r.dll
2008-12-08 16:00 1,191,936 ----a-w c:\windows\System32\msxml3.dll
2008-12-08 15:51 988,216 ----a-w c:\windows\System32\winload.exe
2008-12-08 15:51 927,288 ----a-w c:\windows\System32\winresume.exe
2008-12-08 15:51 615,992 ----a-w c:\windows\System32\ci.dll
2008-12-08 15:51 6,656 ----a-w c:\windows\System32\kbd106n.dll
2008-12-08 15:51 46,592 ----a-w c:\windows\System32\setbcdlocale.dll
2008-12-08 15:51 40,960 ----a-w c:\windows\System32\srclient.dll
2008-12-08 15:51 378,368 ----a-w c:\windows\System32\srcore.dll
2008-12-08 15:51 318,464 ----a-w c:\windows\System32\rstrui.exe
2008-12-08 15:51 19,000 ----a-w c:\windows\System32\kd1394.dll
2008-12-08 15:51 14,848 ----a-w c:\windows\System32\srdelayed.exe
2008-12-08 15:47 712,704 ----a-w c:\windows\System32\WindowsCodecs.dll
2008-12-08 15:47 425,472 ----a-w c:\windows\System32\PhotoMetadataHandler.dll
2008-12-08 15:47 347,136 ----a-w c:\windows\System32\WindowsCodecsExt.dll
2008-12-08 15:45 443,392 ----a-w c:\windows\System32\win32spl.dll
2008-12-08 15:45 37,888 ----a-w c:\windows\System32\printcom.dll
2008-12-08 15:44 14,848 ----a-w c:\windows\System32\wshrm.dll
2008-12-08 15:44 113,664 ----a-w c:\windows\system32\drivers\rmcast.sys
2008-12-08 15:42 84,480 ----a-w c:\windows\System32\INETRES.dll
2008-12-08 15:42 738,304 ----a-w c:\windows\System32\inetcomm.dll
2008-12-08 15:42 1,645,568 ----a-w c:\windows\System32\connect.dll
2008-12-08 15:41 1,314,816 ----a-w c:\windows\System32\quartz.dll
2008-12-08 15:40 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe
2008-12-08 15:40 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe
2008-12-08 15:39 2,048 ----a-w c:\windows\System32\msxml6r.dll
2008-12-08 15:39 1,334,272 ----a-w c:\windows\System32\msxml6.dll
2008-12-08 15:01 51,224 ----a-w c:\windows\System32\wuauclt.exe
2008-12-08 15:01 43,544 ----a-w c:\windows\System32\wups2.dll
2008-12-08 15:01 1,809,944 ----a-w c:\windows\System32\wuaueng.dll
2008-12-08 15:01 1,524,736 ----a-w c:\windows\System32\wucltux.dll
2008-12-08 15:00 83,456 ----a-w c:\windows\System32\wudriver.dll
2008-12-08 15:00 561,688 ----a-w c:\windows\System32\wuapi.dll
2008-12-08 15:00 34,328 ----a-w c:\windows\System32\wups.dll
2008-12-08 15:00 31,232 ----a-w c:\windows\System32\wuapp.exe
2008-12-08 15:00 162,064 ----a-w c:\windows\System32\wuwebv.dll
2008-12-03 23:01 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-26 14:47 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2008-11-25 22:59 --------- d-----w c:\users\User\AppData\Roaming\Red Alert 3
2008-11-25 22:52 --------- d-----w c:\programdata\Electronic Arts
2008-11-10 16:52 319,456 ----a-w c:\windows\DIFxAPI.dll
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 28,672 ----a-w c:\windows\System32\Apphlpdm.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-11-01 01:21 4,240,384 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-29 06:29 2,927,104 ----a-w c:\windows\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2009-01-25_13.33.16,96 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-25 13:13:02 18,944 ----a-r c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2009-01-25 13:13:02 65,024 ----a-r c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
- 2009-01-25 10:51:18 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-01-25 13:44:34 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-01-25 13:44:34 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-01-25 10:52:45 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-01-25 13:46:16 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-01-25 13:46:16 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-01-25 10:52:50 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-01-25 13:46:11 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-01-25 13:46:11 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-01-25 10:55:48 101,052 ----a-w c:\windows\System32\perfc009.dat
+ 2009-01-25 13:52:03 101,052 ----a-w c:\windows\System32\perfc009.dat
- 2009-01-25 10:55:48 586,980 ----a-w c:\windows\System32\perfh009.dat
+ 2009-01-25 13:52:03 586,980 ----a-w c:\windows\System32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 c:\windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LWBMOUSE"="c:\program files\Mouse Driver\Mouse Driver\3.5\MOUSE32A.EXE" [2001-11-09 356352]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13580832]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 92704]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RtHDVCpl"="RtHDVCpl.exe" [2007-10-11 c:\windows\RtHDVCpl.exe]
"Skytel"="Skytel.exe" [2007-10-11 c:\windows\SkyTel.exe]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-03-22 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{E43AD8E6-3CAD-49EA-AA8B-501CD4A6BF2A}"= UDP:c:\program files\Stardock Games\Sins of a Solar Empire Demo\Sins of a Solar Empire.exe:Sins of a Solar Empire Demo
"{07CD06A4-E3DE-44FB-8C81-B01955C0837D}"= TCP:c:\program files\Stardock Games\Sins of a Solar Empire Demo\Sins of a Solar Empire.exe:Sins of a Solar Empire Demo
"TCP Query User{EEECBEE5-916E-45DB-BAC5-816FFB84617C}c:\\program files\\thq\\company of heroes\\bugreport\\bugreport.exe"= UDP:c:\program files\thq\company of heroes\bugreport\bugreport.exe:BugReport
"UDP Query User{7C16DA51-C0AA-4CC9-8142-42B8479317E4}c:\\program files\\thq\\company of heroes\\bugreport\\bugreport.exe"= TCP:c:\program files\thq\company of heroes\bugreport\bugreport.exe:BugReport
"TCP Query User{93CAFF5B-D26C-4562-9229-3C70B777E3BF}c:\\program files\\thq\\dawn of war - dark crusade demo\\darkcrusade.exe"= UDP:c:\program files\thq\dawn of war - dark crusade demo\darkcrusade.exe:DarkCrusade
"UDP Query User{6B93C22A-4FDA-4BBE-9F19-D9301F8C9A90}c:\\program files\\thq\\dawn of war - dark crusade demo\\darkcrusade.exe"= TCP:c:\program files\thq\dawn of war - dark crusade demo\darkcrusade.exe:DarkCrusade
"TCP Query User{D87C759C-D1C9-456E-8D2B-AF88377AC13C}c:\\program files\\g2 games\\enemy engaged 2\\cohokum\\ee2.exe"= UDP:c:\program files\g2 games\enemy engaged 2\cohokum\ee2.exe:ee2
"UDP Query User{9E79CED1-8C3E-4FE6-BE62-AA77B56B369C}c:\\program files\\g2 games\\enemy engaged 2\\cohokum\\ee2.exe"= TCP:c:\program files\g2 games\enemy engaged 2\cohokum\ee2.exe:ee2
"TCP Query User{E99FAB30-9A94-4219-8159-6979DBC371A1}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{96667D2A-893A-4B0D-A14C-56C55C6B6E8E}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"TCP Query User{A00C8AC7-2F10-4CDF-B9F0-BF2F5EA73360}e:\\sthiw\\stinstall.exe"= UDP:e:\sthiw\stinstall.exe:SpeedTouch Setup Wizard
"UDP Query User{EC433707-7C57-4548-84DE-2F6C98488873}e:\\sthiw\\stinstall.exe"= TCP:e:\sthiw\stinstall.exe:SpeedTouch Setup Wizard
"{4FF6F9E4-AB67-4598-A500-601C22227B5C}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{F68A7A13-192B-4FCC-80CE-75E43FFA0BA6}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{B0A8BA3C-CE55-425D-9C64-60F9FFFF4283}"= UDP:d:\\BitTorrent.exe:BitTorrent (TCP-In)
"{09472E6A-4336-4B8A-A693-43DF31281EA0}"= TCP:d:\\BitTorrent.exe:BitTorrent (UDP-In)
"TCP Query User{40DFCD3D-5CE0-421A-8FD3-C207F107005C}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:BitTorrent
"UDP Query User{30D6D464-26ED-4718-AC9E-94CAC0BFAEC3}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:BitTorrent
"TCP Query User{43529086-D00F-4791-A895-806A0DFC944E}c:\\program files\\icq6.5\\icq.exe"= UDP:c:\program files\icq6.5\icq.exe:ICQ Library
"UDP Query User{D51BF0D1-5C30-4289-9951-574362708114}c:\\program files\\icq6.5\\icq.exe"= TCP:c:\program files\icq6.5\icq.exe:ICQ Library
"{808EF82F-A56D-41F1-9556-02965F211857}"= UDP:c:\program files\Activision\Call of Duty - World at War\CoDWaWmp.exe:Call of Duty® - World at War
"{1A53986C-ECCE-4AEF-95C9-004EAC0C98EE}"= TCP:c:\program files\Activision\Call of Duty - World at War\CoDWaWmp.exe:Call of Duty® - World at War
"{17C5D5FC-9073-4D49-8120-0391091A6623}"= UDP:c:\program files\Activision\Call of Duty - World at War\CoDWaW.exe:Call of Duty® - World at War
"{BE06EDE5-C8D8-42E5-ACC2-EE71BBB7FA21}"= TCP:c:\program files\Activision\Call of Duty - World at War\CoDWaW.exe:Call of Duty® - World at War
"{78280016-E782-498A-B3D0-032A529D3E00}"= UDP:c:\program files\WBGames\Monolith Productions\F.E.A.R. 2 SP Demo\FEAR2SPDemo.exe:FEAR2SPDemo.exe
"{32D4FF74-1310-4FB1-BCFA-E926766646A7}"= TCP:c:\program files\WBGames\Monolith Productions\F.E.A.R. 2 SP Demo\FEAR2SPDemo.exe:FEAR2SPDemo.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 BIOS;BIOS;c:\windows\System32\drivers\BIOS.sys [2008-10-02 13696]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
R3 AVerBDA3x;AVerMedia SAA713x BDA Service;c:\windows\System32\drivers\AVerBDA3x.sys [2007-08-29 1183744]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
R3 UsbFltr;WayTech USB Filter Driver1;c:\windows\System32\drivers\UsbFltr.sys [2007-04-09 9600]
.
Contents of the 'Scheduled Tasks' folder
2009-01-25 c:\windows\Tasks\User_Feed_Synchronization-{20520944-4EB3-456A-90BE-8EB301B77C80}.job
- c:\windows\system32\msfeedssync.exe [2008-01-19 08:33]
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-25 15:04:44
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(2136)
c:\program files\Mouse Driver\Mouse Driver\3.5\MOUDL32A.DLL
.
Completion time: 2009-01-25 15:06:13
ComboFix-quarantined-files.txt 2009-01-25 14:06:10
ComboFix2.txt 2009-01-25 12:34:24
Pre-Run: 99.753.910.272 bytes free
Post-Run: 99,728,281,600 bytes free
242 --- E O F --- 2009-01-23 10:39:03
DO I need to do some aditional work or this is It?
Thank you very much ;)