Before you post i search and find avg remover tool from avg site and uninstall it.
So here ComboFix Log:
ComboFix 11-05-30.08 - ΚΩΝΣΤΑΝΤΙΝΟΣ 31/05/2011 16:24:05.1.1 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1253.30.1032.18.3326.3017 [GMT 3:00]
Running from: c:\documents and settings\ΚΩΝΣΤΑΝΤΙΝΟΣ\Τα έγγραφά μου\Ληφθέντα αρχεία\ComboFix.exe
AV: AVG Anti-Virus *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\ΚΩΝΣΤΑΝΤΙΝΟΣ\Application Data\inst.exe
c:\documents and settings\ΚΩΝΣΤΑΝΤΙΝΟΣ\WINDOWS
C:\hosts
c:\program files\Mozilla Firefox\extensions\{3CABE98B-AD76-4EFE-B0AD-9DFB07E93AF3}
c:\program files\Mozilla Firefox\extensions\{3CABE98B-AD76-4EFE-B0AD-9DFB07E93AF3}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{3CABE98B-AD76-4EFE-B0AD-9DFB07E93AF3}\chrome\content\overlay.xul
c:\program files\Mozilla Firefox\extensions\{3CABE98B-AD76-4EFE-B0AD-9DFB07E93AF3}\install.rdf
c:\windows\msettings.ini
D:\autorun.inf
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ovfsthrprxvkosvviwtrdntbqhwbdipmbcjwti
-------\Service_ovfsthrprxvkosvviwtrdntbqhwbdipmbcjwti
.
.
((((((((((((((((((((((((( Files Created from 2011-04-28 to 2011-05-31 )))))))))))))))))))))))))))))))
.
.
2011-05-30 17:57 . 2011-05-30 17:57 388096 ----a-r- c:\documents and settings\ΚΩΝΣΤΑΝΤΙΝΟΣ\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-30 17:57 . 2011-05-30 17:57 -------- d-----w- c:\program files\Trend Micro
2011-05-29 22:21 . 2011-05-29 22:21 -------- d-----w- c:\documents and settings\ΚΩΝΣΤΑΝΤΙΝΟΣ\Application Data\Malwarebytes
2011-05-29 22:21 . 2011-05-29 22:21 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2011-05-29 22:21 . 2010-12-20 15:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-29 22:21 . 2011-05-29 22:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-29 22:21 . 2010-12-20 15:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-29 21:05 . 2011-05-29 21:05 1152 ----a-w- c:\windows\system32\windrv.sys
2011-05-29 18:40 . 2010-09-18 06:52 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2011-05-29 18:40 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2011-05-29 18:38 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2011-05-29 10:08 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2011-05-29 02:47 . 2011-05-29 02:47 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2011-05-29 01:12 . 2011-05-29 01:44 -------- d-----w- c:\documents and settings\swan
2011-05-27 13:13 . 2011-05-27 13:13 83348328 ----a-w- c:\program files\Common Files\Windows Live\.cache\wlc25.tmp
2011-05-26 12:59 . 2011-05-26 12:59 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-08 13:10 . 2011-05-08 13:10 781272 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-05-08 13:10 . 2011-05-08 13:10 1874904 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-05-08 13:10 . 2011-05-08 13:10 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-05-08 13:10 . 2011-05-08 13:10 465880 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-05-08 13:10 . 2011-05-08 13:10 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-05-08 13:10 . 2011-05-08 13:10 1892184 ----a-w- c:\program files\Mozilla Firefox\d3dx9_42.dll
2011-05-08 13:10 . 2011-05-08 13:10 142296 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-05-08 13:10 . 2011-05-08 13:10 1974616 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_42.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-18 19:01 . 2011-04-18 19:01 189248 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-04-18 19:01 . 2011-04-18 19:01 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-03-07 05:33 . 2007-05-29 10:25 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:36 . 2004-09-04 06:45 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:53 . 2009-08-29 20:25 1858176 ----a-w- c:\windows\system32\win32k.sys
2011-05-08 13:10 . 2011-05-08 13:10 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ---ha-w- c:\documents and settings\ΚΩΝΣΤΑΝΤΙΝΟΣ\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ---ha-w- c:\documents and settings\ΚΩΝΣΤΑΝΤΙΝΟΣ\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ---ha-w- c:\documents and settings\ΚΩΝΣΤΑΝΤΙΝΟΣ\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ---ha-w- c:\documents and settings\ΚΩΝΣΤΑΝΤΙΝΟΣ\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-10-23 202024]
"bluebirds"="c:\documents and settings\ΚΩΝΣΤΑΝΤΙΝΟΣ\Bluebirds\BlueBirds.exe" [2009-04-29 270336]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"RGSC"="c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" [2008-11-14 305064]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-24 7311360]
"nwiz"="nwiz.exe" [2006-01-24 1519616]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2008-06-10 1442888]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-01-24 86016]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"Family Tree Builder Update"="c:\program files\MyHeritage\Bin\FTBCheckUpdates.exe" [2009-11-02 222736]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-06-22 98304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgRemover"="c:\documents and settings\ΚΩΝΣΤΑΝΤΙΝΟΣ\Τα έγγραφά μου\Ληφθέντα αρχεία\avg_remover_stf_x86_2011_1322.exe" [2011-05-31 1163104]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\‰—‘’€’‘\Start Menu\¨¦¨α££«\„΅΅ε¤©\
Dropbox.lnk - c:\documents and settings\‰—‘’€’‘\Application Data\Dropbox\bin\Dropbox.exe [2011-3-31 23360040]
.
c:\documents and settings\All Users.WINDOWS\Start Menu\¨¦¨α££«\„΅΅ε¤©\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPM3f706dfe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-04-16 19:12 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 12:57 153136 -c--a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
2007-08-07 00:05 200704 ----a-w- c:\program files\PowerISO\PWRISOVM.EXE
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\XP Repair Pro 4.0\\RegistryRepair.exe"=
"c:\\Program Files\\XP Repair Pro 4.0\\ControlCenter.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Documents and Settings\\ΚΩΝΣΤΑΝΤΙΝΟΣ\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2011\\fm.exe"=
"c:\\Program Files\\Ubisoft\\Ubisoft Game Launcher\\UbisoftGameLauncher.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed Brotherhood\\ACBSP.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed Brotherhood\\ACBMP.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed Brotherhood\\AssassinsCreedBrotherhood.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed Brotherhood\\UPlayBrowser.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\GTAIV.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
.
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9/1/2008 5:51 πμ 691696]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/3/2010 1:16 μμ 130384]
S2 FAH@C:+Program Files+Ubisoft+Far Cry 2+bin+FAH.exe;FAH@C:+Program Files+Ubisoft+Far Cry 2+bin+FAH.exe;c:\program files\Ubisoft\Far Cry 2\bin\FAH.exe -svcstart --> c:\program files\Ubisoft\Far Cry 2\bin\FAH.exe -svcstart [?]
S3 mdxgthkn;mdxgthkn;\??\c:\docume~1\405A~1\LOCALS~1\Temp\mdxgthkn.sys --> c:\docume~1\405A~1\LOCALS~1\Temp\mdxgthkn.sys [?]
S3 MusCDriverV32;MusCDriverV32;c:\windows\system32\drivers\MusCDriverV32.sys [19/8/2007 7:53 μμ 513152]
S3 s816bus;Sony Ericsson Device 816 driver (WDM);c:\windows\system32\drivers\s816bus.sys [12/9/2008 3:05 μμ 81832]
S3 s816mdfl;Sony Ericsson Device 816 USB WMC Modem Filter;c:\windows\system32\drivers\s816mdfl.sys [12/9/2008 3:05 μμ 13864]
S3 s816mdm;Sony Ericsson Device 816 USB WMC Modem Driver;c:\windows\system32\drivers\s816mdm.sys [12/9/2008 3:05 μμ 107304]
S3 s816mgmt;Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s816mgmt.sys [12/9/2008 3:05 μμ 99112]
S3 s816nd5;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS);c:\windows\system32\drivers\s816nd5.sys [12/9/2008 3:06 μμ 21928]
S3 s816obex;Sony Ericsson Device 816 USB WMC OBEX Interface;c:\windows\system32\drivers\s816obex.sys [12/9/2008 3:05 μμ 97320]
S3 s816unic;Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM);c:\windows\system32\drivers\s816unic.sys [12/9/2008 3:05 μμ 97704]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/3/2010 1:16 μμ 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.gr/
IE: Ε&ξαγωγή στο Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\ΚΩΝΣΤΑΝΤΙΝΟΣ\Application Data\Mozilla\Firefox\Profiles\fv6o32s1.default\
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{729b5f8f-05d2-4487-b635-ed10fdb8263d} - (no file)
HKLM-Run-ISUSPM - c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
Notify-avgrsstarter - avgrsstx.dll
MSConfigStartUp-DAEMON Tools Lite - c:\program files\DAEMON Tools Lite\daemon.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
MSConfigStartUp-Veoh - c:\program files\Veoh Networks\Veoh\VeohClient.exe
MSConfigStartUp-VeohPlugin - c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
AddRemove-FIBA Basketball Manager 2008 Patch_is1 - c:\program files\FIBA Basketball Manager 2008\unins001.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-05-31 16:35
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
"ServiceDll"="c:\windows\system32\es.dll"
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FAH@C:+Program Files+Ubisoft+Far Cry 2+bin+FAH.exe]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,18,c2,c4,56,57,26,a5,4d,99,15,7a,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,18,c2,c4,56,57,26,a5,4d,99,15,7a,\
.
[HKEY_USERS\S-1-5-21-1390067357-1214440339-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-1390067357-1214440339-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:bc,26,0f,cf,5f,d9,a1,e6,6d,79,cc,3e,18,80,45,f3,c3,b7,f4,77,60,59,ac,
06,5b,11,41,2b,90,28,51,70,10,35,dd,45,2b,c5,28,ca,77,1a,0f,8b,bb,a4,6f,a2,\
"??"=hex:d7,a2,59,5c,8c,40,85,04,4e,09,3f,dc,f8,be,52,53
.
[HKEY_USERS\S-1-5-21-1390067357-1214440339-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:69,92,7c,d1,a2,1c,e8,6b,45,94,ba,e1,c5,cb,6b,a9,72,df,1a,32,12,
83,53,2a,16,3f,0c,05,6c,b7,3c,da,3a,26,be,de,c7,a0,b6,bb,15,9e,6d,80,8d,29,\
"rkeysecu"=hex:7d,eb,44,fa,83,1a,30,0e,02,ae,86,18,01,9c,36,da
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(580)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(364)
c:\documents and settings\ΚΩΝΣΤΑΝΤΙΝΟΣ\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\progra~1\WINDOW~3\wmpband.dll
.
Completion time: 2011-05-31 16:42:52 - machine was rebooted
ComboFix-quarantined-files.txt 2011-05-31 13:42
.
Pre-Run: 12 Κατάλογοι 11.405.832.192 διαθέσιμα byte
Post-Run: 15 Κατάλογοι 16.081.866.752 διαθέσιμα byte
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
Current=1 Default=1 Failed=0 LastKnownGood=8 Sets=1,2,3,4,5,6,7,8
- - End Of File - - 3CED3064576BC266780B0B8E85ED336C
thanks a lot!!