this is my combofix log
ComboFix 07-08-14.4 - "user" 2008-02-23 23:36:12.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.904 [GMT 8:00]
((((((((((((((((((((((((( Files Created from 2008-01-23 to 2008-02-23 )))))))))))))))))))))))))))))))
2008-02-23 22:15 <DIR> d-------- C:\WINDOWS\LastGood
2008-02-23 22:15 <DIR> d-------- C:\2ec193cf7ab944320119d0c660621e
2008-02-23 17:59 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-02-22 14:09 86,016 --a------ C:\WINDOWS\unvise32qt.exe
2008-02-22 14:08 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2008-02-22 14:08 <DIR> d-------- C:\Program Files\QuickTime
2008-02-22 14:07 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
2008-02-22 13:01 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2008-02-21 21:48 195,080 --ahs---- C:\WINDOWS\system32\ybadd.ini2
2008-02-12 22:31 <DIR> d-------- C:\BackUpMsnCleaner
2008-01-28 20:32 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab Setup Files
2008-01-28 20:04 <DIR> d-------- C:\Program Files\NovaLogic
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-02-23 20:31 --------- d-------- C:\DOCUME~1\user\APPLIC~1\Skype
2008-02-23 18:42 --------- d-------- C:\Program Files\Winamp Remote
2008-02-22 14:09 --------- d-------- C:\Program Files\Opera
2008-01-31 23:12 --------- d-------- C:\DOCUME~1\user\APPLIC~1\U3
2008-01-28 20:22 --------- d--h----- C:\Program Files\InstallShield Installation Information
2008-01-11 13:53 44544 --a--c--- C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-01-06 18:11 --------- d-------- C:\Program Files\Nanny Mania
2008-01-06 16:58 --------- d-------- C:\Program Files\Common Files\Sandlot Shared
2008-01-05 00:04 --------- d-------- C:\Program Files\Sushi Frenzy
2007-12-20 07:01 347136 --a--c--- C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-18 17:51 179584 --a--c--- C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-08 13:21 3592192 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-07 10:21 824832 --a--c--- C:\WINDOWS\system32\dllcache\wininet.dll
2007-12-07 10:21 671232 --a--c--- C:\WINDOWS\system32\dllcache\mstime.dll
2007-12-07 10:21 63488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2007-12-07 10:21 6066176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-07 10:21 52224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-07 10:21 478208 --a--c--- C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-12-07 10:21 459264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-07 10:21 44544 --a--c--- C:\WINDOWS\system32\dllcache\iernonce.dll
2007-12-07 10:21 384512 --a--c--- C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-12-07 10:21 383488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-07 10:21 27648 --a--c--- C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-12-07 10:21 267776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-07 10:21 233472 --a--c--- C:\WINDOWS\system32\dllcache\webcheck.dll
2007-12-07 10:21 230400 --a--c--- C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-12-07 10:21 214528 --a--c--- C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-12-07 10:21 193024 --a--c--- C:\WINDOWS\system32\dllcache\msrating.dll
2007-12-07 10:21 153088 --a--c--- C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-12-07 10:21 133120 --a--c--- C:\WINDOWS\system32\dllcache\extmgr.dll
2007-12-07 10:21 124928 --a--c--- C:\WINDOWS\system32\dllcache\advpack.dll
2007-12-07 10:21 1159680 --a--c--- C:\WINDOWS\system32\dllcache\urlmon.dll
2007-12-07 10:21 105984 --a--c--- C:\WINDOWS\system32\dllcache\url.dll
2007-12-07 10:21 102912 --a--c--- C:\WINDOWS\system32\dllcache\occache.dll
2007-12-06 19:01 625664 --a--c--- C:\WINDOWS\system32\dllcache\iexplore.exe
2007-12-06 19:00 70656 --a--c--- C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-12-06 19:00 13824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-06 12:59 161792 --a--c--- C:\WINDOWS\system32\dllcache\ieakui.dll
2007-12-05 02:38 550912 --a--c--- C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-12-05 02:38 550912 --a------ C:\WINDOWS\system32\oleaut32.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{98663E21-9CCE-4CF6-863C-911A9523A66F}]
C:\WINDOWS\system32\efcaxuv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c7e6dd45-62ee-42af-aecc-aaa607380f41}]
C:\WINDOWS\system32\howcaoqv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F754FB01-7C9D-4F7F-B59C-A0703B19BB52}]
C:\WINDOWS\system32\ddaby.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-06-13 09:57]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-06-13 09:57]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-06-13 09:57]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-19 09:42 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-07-19 09:42 C:\WINDOWS\SkyTel.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-13 21:50 C:\WINDOWS\AGRSMMSG.exe]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2006-07-19 09:41]
"BroadcomWireless"="C:\Program Files\Broadcom\Wireless\Utility\WlanUtil.exe" []
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-29 07:13]
"NWEReboot"="" []
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 01:56 C:\WINDOWS\system32\bthprops.cpl]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 13:36]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"LManager"="C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE" [2006-07-14 12:13]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-10 01:56]
"ScheduleTV"="C:\Program Files\GADMEI TVHome Media\ScheduleTV.exe" [2006-12-12 15:57]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 13:28]
"5015bad3"="C:\WINDOWS\system32\vlbfgjrv.dll" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-22 14:09]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-22 22:35]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 14:32]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:56]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:54]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-06-07 15:08]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 17:21]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-05-18 14:14]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-17 13:15]
"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2007-10-23 08:47]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 02:19:50]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-11-14 15:31:44]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-06-04 18:50:03]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{98663E21-9CCE-4CF6-863C-911A9523A66F}"= C:\WINDOWS\system32\efcaxuv.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efcaxuv]
efcaxuv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hmuwdvoq]
hmuwdvoq.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\ddaby.dll
R3 DKbFltr;Dritek Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\DKbFltr.sys
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC);C:\WINDOWS\system32\DRIVERS\snp2uvc.sys
S3 MSControlService;Microsoft cache control;C:\WINDOWS\system32\windows
S3 USB28xxBGA;USB 2861 Device;C:\WINDOWS\system32\DRIVERS\emBDA.sys
S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3b2161ab-5564-11dc-9e83-0019d275c81b}]
Auto\command- dllcache32.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL dllcache32.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6302c8df-6a85-11dc-9ecd-0019d275c81b}]
Auto\command- dllcache32.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL dllcache32.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ccb67a76-3b72-11dc-9e29-0019d275c81b}]
Auto\command- dllcache32.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL dllcache32.exe e
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-23 23:37:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2008-02-23 23:37:49
--- E O F ---
thx so much