Hi Loophole
Here is the comboxfix log
ComboFix 08-01-20.1 - rik 2008-01-20 8:20:20.2 - NTFSx86
Running from: C:\Documents and Settings\rik\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOW\system32\iiiii.ini
C:\WINDOW\system32\iiiii.ini2
C:\WINDOW\system32\umfxipqr.ini
.
---- Previous Run -------
.
C:\Documents and Settings\All Users.WINDOW\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users.WINDOW\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\Rik.TRUDI.000\Application Data\MessengerSkinner
C:\Documents and Settings\Rik.TRUDI.000\Application Data\MessengerSkinner\Userdata\languages.xml
C:\Documents and Settings\Rik.TRUDI.000\Application Data\MessengerSkinner\Userdata\pack1.cab
C:\WINDOW\cookies.ini
C:\WINDOW\system32\aamwosff.dll
C:\WINDOW\system32\agnimtac.dll
C:\WINDOW\system32\alog.txt
C:\WINDOW\system32\conf.dat
C:\WINDOW\system32\ddprwges.ini
C:\WINDOW\system32\dovhwspl.ini
C:\WINDOW\system32\hrjeselj.dll
C:\WINDOW\system32\iiiii.ini
C:\WINDOW\system32\iiiii.ini2
C:\WINDOW\system32\jbalcbbk.ini
C:\WINDOW\system32\jdkppves.dll
C:\WINDOW\system32\jlesejrh.ini
C:\WINDOW\system32\kbbclabj.dll
C:\WINDOW\system32\knpoq.ini
C:\WINDOW\system32\knpoq.ini2
C:\WINDOW\system32\limevmhv.dll
C:\WINDOW\system32\lpswhvod.dll
C:\WINDOW\system32\mcrh.tmp
C:\WINDOW\system32\mpjsegsv.dll
C:\WINDOW\system32\njjtjdsu.dll
C:\WINDOW\system32\nnsaimvr.dll
C:\WINDOW\system32\ojjutxsw.dll
C:\WINDOW\system32\segwrpdd.dll
C:\WINDOW\system32\spbnhqpu.ini
C:\WINDOW\system32\upqhnbps.dll
C:\WINDOW\system32\vpwnnuek.dll
C:\WINDOW\system32\vsgesjpm.ini
C:\WINDOW\system32\wsxtujjo.ini
C:\WINDOW\system32\wvshiyoq.dll
.
((((((((((((((((((((((((( Files Created from 2007-12-20 to 2008-01-20 )))))))))))))))))))))))))))))))
.
2008-01-20 08:01 . 2000-08-31 08:00 51,200 --a------ C:\WINDOW\NirCmd.exe
2008-01-18 10:35 . 2008-01-18 10:35 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-16 19:09 . 2008-01-16 19:09 1 --a------ C:\WINDOW\system32\rc.dat
2008-01-16 19:09 . 2008-01-16 19:09 1 --a------ C:\WINDOW\system32\ps1.dat
2008-01-16 19:08 . 2008-01-16 19:08 52,224 --a------ C:\WINDOW\system32\halifax2.dll
2008-01-16 19:07 . 2008-01-16 19:07 5,499 --a------ C:\Documents and Settings\rik\957123845.exe
2008-01-16 19:07 . 2008-01-16 19:07 5,499 --a------ C:\Documents and Settings\rik\462.exe
2008-01-16 19:07 . 2008-01-16 19:07 5,499 --a------ C:\Documents and Settings\rik\440.exe
2008-01-12 10:51 . 2008-01-12 10:51 <DIR> d-------- C:\WINDOW\LastGood
2008-01-11 20:49 . 2008-01-11 20:49 51,712 --a------ C:\WINDOW\system32\halifax1.dll
2008-01-03 07:54 . 2002-08-29 03:41 286,720 --a------ C:\WINDOW\system32\msh263.drv
2008-01-03 07:54 . 2002-08-29 03:41 49,664 --a------ C:\WINDOW\system32\vfwwdm32.dll
2008-01-03 07:54 . 2001-08-17 22:36 45,568 --a------ C:\WINDOW\system32\iyuv_32.dll
2008-01-03 07:54 . 2001-08-17 22:36 8,192 --a------ C:\WINDOW\system32\tsbyuv.dll
2008-01-03 07:53 . 2004-11-24 11:29 647,333 --a------ C:\WINDOW\system32\drivers\Capt905c.sys
2008-01-03 07:53 . 2004-05-07 15:31 24,382 --a------ C:\WINDOW\system32\drivers\Camd905c.sys
2007-12-31 16:45 . 2007-12-31 16:45 93 --a------ C:\WINDOW\wininit.ini
2007-12-31 14:42 . 2008-01-15 13:10 <DIR> d-------- C:\Documents and Settings\All Users.WINDOW\Application Data\Spybot - Search & Destroy
2007-12-31 09:51 . 2007-12-31 09:51 <DIR> d-------- C:\Documents and Settings\rik\Application Data\Grisoft
2007-12-31 09:50 . 2007-12-31 09:50 <DIR> d-------- C:\Documents and Settings\All Users.WINDOW\Application Data\Grisoft
2007-12-31 09:50 . 2007-05-30 12:10 10,872 --a------ C:\WINDOW\system32\drivers\AvgAsCln.sys
2007-12-31 09:00 . 2007-12-31 09:07 <DIR> d-------- C:\WINDOW\LastGood.Tmp
2007-12-27 15:42 . 2007-12-27 15:42 314,752 --a------ C:\WINDOW\system32\iiiii.dll
2007-12-23 21:34 . 2007-12-23 21:34 314,624 --a------ C:\WINDOW\system32\qopnk.dll
2007-12-21 15:37 . 2007-12-21 15:37 526,848 --a------ C:\RIGHT TO BUY DOC.doc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-20 07:52 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-14 17:21 --------- d-----w C:\Documents and Settings\rik\Application Data\DataLayer
2008-01-12 16:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-12 13:33 --------- d-----w C:\Documents and Settings\rik\Application Data\McAfee.com Personal Firewall
2008-01-12 13:29 --------- d-----w C:\Documents and Settings\All Users.WINDOW\Application Data\McAfee.com Personal Firewall
2008-01-02 21:11 --------- d-----w C:\Program Files\Oberon Media
2007-12-31 14:17 --------- d-----w C:\Program Files\Lavasoft
2007-12-09 00:58 23,728 ----a-w C:\WINDOW\system32\vtuvwuu.dll
2007-11-26 16:52 --------- d-----w C:\Program Files\QuickTime
2007-07-27 18:08 150,672 ----a-w C:\Documents and Settings\Sandra\printclearly.zip
2007-05-28 11:55 576 ----a-w C:\Program Files\userdata.dat
2007-05-28 11:55 176 ----a-w C:\Program Files\log.txt
2007-02-05 20:00 88 --sh--r C:\WINDOW\system32\D36C1C2D64.sys
2007-02-05 20:00 2,516 --sha-w C:\WINDOW\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{13E6025E-AA55-4694-9ADE-4C6F25E69F81}]
2007-12-27 15:42 314752 --a------ C:\WINDOW\System32\iiiii.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{28C703D0-B4A9-4b2f-9123-CE8294761861}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOW\System32\ctfmon.exe" [2002-08-30 04:00 13312]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-02-22 16:18 1302528]
"PowerBar"="" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 18:18 151552]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 12:49 163840]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 22:02 53248]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 18:29 303104]
"MCUpdateExe"="C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe" [2006-01-11 12:05 212992]
"MPFEXE"="C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-11-11 16:00 1005096]
"MPSExe"="c:\PROGRA~1\mcafee.com\mps\mscifapp.exe" [2006-03-30 13:31 296488]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe" [2005-09-26 09:26 110592]
"MSKDetectorExe"="C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe" [2005-08-12 15:16 1121792]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2005-12-13 08:49 217088]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920]
"BigDogPath"="C:\WINDOW\VM_STI.exe" [2004-12-15 18:01 40960]
"NeroFilterCheck"="C:\WINDOW\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-26 16:52 286720]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25 6731312]
"adiras"="adiras.exe" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOW\System32\CTFMON.EXE" [2002-08-30 04:00 13312]
C:\Documents and Settings\Rik.TRUDI.000\Start Menu\Programs\Startup\
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1996-11-20 23:00:00 111376]
C:\Documents and Settings\rik\Start Menu\Programs\Startup\
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1996-11-20 23:00:00 111376]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1996-11-20 23:00:00 51984]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuvuvu]
vtuvuvu.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOW\System32\iiiii.dll
.
Contents of the 'Scheduled Tasks' folder
"2008-01-20 08:33:03 C:\WINDOW\Tasks\RegCure Program Check.job"
- C:\Documents and Settings\rik\Desktop\RegCure\RegCure.exe
"2008-01-03 03:00:00 C:\WINDOW\Tasks\RegCure.job"
- C:\Documents and Settings\rik\Desktop\RegCure\RegCure.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-20 08:35:46
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOW\system32\lsass.exe [5.01.2600.1106]
-> C:\WINDOW\System32\iiiii.dll
PROCESS: C:\WINDOW\Explorer.EXE [6.00.2800.1106]
-> C:\WINDOW\System32\iiiii.dll
.
Completion time: 2008-01-20 8:43:04 - machine was rebooted [rik]
ComboFix-quarantined-files.txt 2008-01-20 08:42:56