Hi again!
Here it is the ComboFix log :
ComboFix 08-01-04.1 - pc 2008-01-05 19:16:33.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1251.1.1033.18.587 [GMT 2:00]
Running from: C:\Documents and Settings\pc\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-05 to 2008-01-05 )))))))))))))))))))))))))))))))
.
2008-01-05 18:31 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-05 10:52 . 2008-01-05 10:52 2,302 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-05 10:50 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-01-05 10:50 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-01-05 10:50 . 2007-12-20 23:11 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-01-05 10:50 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-01-05 10:50 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-01-05 10:50 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-01-05 00:22 . 2008-01-05 00:22 <DIR> d-------- C:\Documents and Settings\Chanka\Application Data\skypePM
2008-01-05 00:20 . 2008-01-05 00:22 <DIR> d-------- C:\Documents and Settings\Chanka\Application Data\Skype
2008-01-04 11:57 . 2008-01-04 12:04 91,492 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-01-04 11:57 . 2008-01-04 12:04 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-01-04 11:56 . 2008-01-04 11:56 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-01-04 11:56 . 2008-01-05 18:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-04 11:56 . 2008-01-05 19:21 2,860,064 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-04 11:56 . 2008-01-05 18:29 38,852 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-04 11:56 . 2008-01-05 19:21 14,880 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-04 11:56 . 2008-01-05 18:29 3,104 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-04 11:40 . 2008-01-04 11:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-01-04 01:48 . 2008-01-04 01:55 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-04 01:48 . 2008-01-04 01:55 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-04 01:46 . 2008-01-04 01:55 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-04 01:46 . 2008-01-04 02:07 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-03 11:04 . 2004-08-23 16:43 359,040 --a------ C:\WINDOWS\system32\drivers\tcpip.sys.ORIGINAL
2008-01-03 11:04 . 2004-08-23 16:43 359,040 --a--c--- C:\WINDOWS\system32\dllcache\tcpip.sys.ORIGINAL
2007-12-29 18:56 . 2007-12-29 18:58 1,328 --a------ C:\WINDOWS\desctemp.dat
2007-12-27 03:31 . 2007-12-27 03:31 <DIR> d-------- C:\Program Files\Stardock
2007-12-27 03:29 . 2007-12-27 03:29 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2007-12-24 19:05 . 2007-12-24 19:05 <DIR> d-------- C:\Documents and Settings\Chanka\Application Data\MiniLyrics
2007-12-24 18:54 . 2007-12-24 18:54 <DIR> d-------- C:\Documents and Settings\Chanka\Application Data\Winamp
2007-12-17 18:16 . 2007-12-17 18:16 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2007-12-16 19:45 . <DIR> C:\КурсѕІ°_р°±ѕт°
2007-12-16 16:18 . 164,076 C:\КурсѕІ°_р°±ѕт°.rar
2007-12-16 16:17 . 2007-12-16 16:17 15,376 --a------ C:\bg.abv.mail.htm
2007-12-16 14:43 . 2007-12-16 14:44 <DIR> d-------- C:\Documents and Settings\multiskype\Application Data\Winamp
2007-12-16 14:43 . 2007-12-16 14:43 <DIR> d-------- C:\Documents and Settings\multiskype\Application Data\MiniLyrics
2007-12-16 13:53 . 2007-12-16 13:53 <DIR> d-------- C:\Documents and Settings\multiskype\Application Data\ICQ Toolbar
2007-12-13 17:12 . 2007-12-13 17:12 <DIR> d-------- C:\Program Files\Nero
2007-12-13 17:12 . 2007-12-13 17:12 <DIR> d-------- C:\Program Files\Common Files\Nero
2007-12-13 17:12 . 2006-03-17 11:45 1,757,184 --a------ C:\WINDOWS\system32\imagX7.dll
2007-12-13 17:12 . 2006-03-17 11:45 802,816 --a------ C:\WINDOWS\system32\imagXRA7.dll
2007-12-13 17:12 . 2006-03-17 11:45 497,296 --a------ C:\WINDOWS\system32\imagXpr7.dll
2007-12-13 17:12 . 2006-03-17 14:49 368,640 --a------ C:\WINDOWS\system32\TwnLib4.dll
2007-12-13 17:12 . 2006-03-17 11:45 258,048 --a------ C:\WINDOWS\system32\imagXR7.dll
2007-12-13 17:10 . 2007-12-13 17:10 126,976 --a------ C:\keymaker.exe
2007-12-13 16:56 . 2007-12-13 17:10 45,595,104 --a------ C:\Nero-8.1.1.0_asian_lite.exe
2007-12-08 18:19 . 1999-02-16 12:09 759,427 --a------ C:\Heroes III Tutorial.pdf
2007-12-08 18:19 . 2006-01-08 22:43 1,519 --a------ C:\HOMM3.REG
2007-12-08 15:02 . 2007-12-08 15:02 <DIR> d-------- C:\Documents and Settings\Chanka\Application Data\Nero
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-05 17:06 --------- d-----w C:\Documents and Settings\multiskype\Application Data\Skype
2008-01-05 17:05 --------- d-----w C:\Documents and Settings\multiskype\Application Data\skypePM
2008-01-05 16:30 --------- d-----w C:\Program Files\Google
2008-01-05 16:23 --------- d-----w C:\Documents and Settings\pc\Application Data\Skype
2008-01-05 11:17 --------- d-----w C:\Program Files\ICQToolbar
2008-01-05 06:03 --------- d-----w C:\Documents and Settings\pc\Application Data\skypePM
2008-01-04 09:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-01-03 09:04 359,040 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-01-01 09:35 --------- d-----w C:\Documents and Settings\pc\Application Data\MiniLyrics
2007-12-13 15:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2007-12-09 18:26 --------- d-----w C:\Documents and Settings\pc\Application Data\Vso
2007-11-29 20:48 --------- d-----w C:\Program Files\Alwil Software
2007-11-29 18:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bluetooth
2007-11-29 18:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-29 18:10 --------- d-----w C:\Program Files\IVT Corporation
2007-11-29 18:10 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-11-28 15:54 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2007-11-28 15:54 47,360 ----a-w C:\Documents and Settings\pc\Application Data\pcouffin.sys
2007-11-28 15:53 --------- d-----w C:\Program Files\Common Files\Adobe
2007-11-28 15:41 --------- d-----w C:\Program Files\Replay Media Catcher
2007-11-28 15:41 --------- d-----w C:\Program Files\Replay Converter
2007-11-28 15:33 --------- d-----w C:\Documents and Settings\pc\Application Data\Nero
2007-11-28 15:21 --------- d-----w C:\Documents and Settings\pc\Application Data\Apple Computer
2007-11-28 15:19 --------- d-----w C:\Program Files\QuickTime
2007-11-28 15:19 --------- d-----w C:\Program Files\Apple Software Update
2007-11-28 15:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-28 15:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-11-28 15:08 --------- d-----w C:\Program Files\Ultra Mobile 3GP Video Converter
2007-11-28 14:34 --------- d-----w C:\Program Files\Xilisoft
2007-11-27 17:37 --------- d-----w C:\Documents and Settings\pc\Application Data\ICQ Toolbar
2007-11-27 11:24 --------- d-----w C:\Documents and Settings\pc\Application Data\GeoVid
2007-11-27 11:22 --------- d-----w C:\Program Files\Common Files\GeoVid
2007-11-27 11:21 --------- d-----w C:\Program Files\GeoVid
2007-11-27 11:01 2,293,848 ----a-w C:\Program Files\FLV PlayerFCSetup.exe
2007-11-27 10:58 3,928,264 ----a-w C:\Program Files\FLV PlayerRCATSetup.exe
2007-11-27 10:57 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-11-27 10:57 --------- d-----w C:\Documents and Settings\pc\Application Data\GetRightToGo
2007-11-27 10:51 411,248 ----a-w C:\Program Files\FLV PlayerRCSetup.exe
2007-11-27 10:51 --------- d-----w C:\Program Files\FLV Player
2007-11-26 13:47 2,198,525 ----a-w C:\WINDOWS\Lost Bird.scr
2007-11-25 14:51 --------- d-----w C:\Documents and Settings\pc\Application Data\ICQ
2007-11-25 09:54 --------- d-----w C:\Documents and Settings\pc\Application Data\InstallShield
2007-11-24 17:24 --------- d-----w C:\Program Files\SA Dictionary 2005 T2
2007-11-24 16:50 --------- d-----w C:\Program Files\Winamp Toolbar
2007-11-24 16:50 --------- d-----w C:\Documents and Settings\pc\Application Data\Winamp
2007-11-24 16:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2007-11-24 15:26 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-24 15:24 --------- d-----w C:\Program Files\Skype
2007-11-24 15:24 --------- d-----w C:\Program Files\Common Files\Skype
2007-11-24 15:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-11-05 13:11 --------- d-----w C:\Program Files\Microsoft.NET
2007-11-05 12:59 --------- d-----w C:\Documents and Settings\pc\Application Data\Lavasoft
2007-11-05 12:58 --------- d-----w C:\Program Files\Lavasoft
2007-11-05 12:54 --------- d-----w C:\Program Files\Crystal Player
2007-11-05 12:52 98,304 ----a-w C:\WINDOWS\system32\qttask.exe
2007-11-05 12:51 --------- d-----w C:\Program Files\ACE Mega CoDecS Pack
2007-11-05 12:30 --------- d-----w C:\Program Files\Realtek
2007-11-05 12:23 --------- d-----w C:\Documents and Settings\pc\Application Data\Eset
2007-11-05 12:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Eset
2007-11-05 11:52 --------- d-----w C:\Program Files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
2007-10-04 22:06 1135968 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
{855F3B16-6D32-4FE6-8A56-BBB695989046}
{7D1AD5EB-9902-4FF0-986F-CA498179A53B}
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CLASSES_ROOT\clsid\{7d1ad5eb-9902-4ff0-986f-ca498179a53b}]
[HKEY_CLASSES_ROOT\ensfolr.ToolBar.1]
[HKEY_CLASSES_ROOT\TypeLib\{9F4F2CDD-5D18-4342-87A4-DFD83CBDFB65}]
[HKEY_CLASSES_ROOT\ensfolr.ToolBar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 22:06 1135968]
[HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-02-07 10:39 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-02-07 10:36 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-02-07 10:40 118784]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-13 22:05 16239616 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 20:04 2879488 C:\WINDOWS\SkyTel.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2006-06-29 15:32 89541 C:\WINDOWS\AGRSMMSG.exe]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24 286720]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-28 12:51 218376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-23 16:28 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-11-29 20:10:46]
FlexType 2K.lnk - C:\WINDOWS\Datecs\Flex2K.exe [2007-11-05 14:56:40]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\
0]
Source= file:///C:\WINDOWS\privacy_danger\index.htm
FriendlyName= Privacy Protection
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"bklgvsf"= {19945AAD-FCEC-4579-B2BE-2E48B9E487EA} - C:\WINDOWS\bklgvsf.dll [ ]
"ampkfst"= {52463205-4E1E-475C-ADF6-231FDF9452C0} - C:\WINDOWS\ampkfst.dll [ ]
R0 O2MDRDR;O2MDRDR;C:\WINDOWS\system32\DRIVERS\o2media.sys [2006-11-20 17:14]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
S3 BTNetFilter;Bluetooth Network Filter;C:\WINDOWS\system32\drivers\BTNetFilter.sys [2004-12-16 16:32]
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2008-01-04 19:16:26 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-05 19:21:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.2180]
-> C:\WINDOWS\system32\newdll.dll
.
Completion time: 2008-01-05 19:22:38
ComboFix-quarantined-files.txt 2008-01-05 17:22:33
ComboFix2.txt 2008-01-05 16:46:52
Edited by nibelung_lgv, 05 January 2008 - 11:24 AM.