Hi tetonbob, thank you for the fast responce. I've done everything - installed Recovery Console and ran ComboFix. Here's the log. There's also a message that a .dll file could not be loaded on system startup, I'll write down the name and show it to you with my next reply - I don't know, it could be important.
ComboFix 08-12-01.03 - Krasi 2008-12-03 10:58:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1251.1.1033.18.1530 [GMT 2:00]
Running from: c:\documents and settings\Krasi\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\cIPpAJlm.ini
c:\windows\system32\cIPpAJlm.ini2
c:\windows\system32\evtinblr.ini
c:\windows\system32\ijgtbvih.ini
c:\windows\system32\lffpfjds.ini
c:\windows\system32\mlJApPIc.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_OREANS32
-------\Service_oreans32
((((((((((((((((((((((((( Files Created from 2008-11-03 to 2008-12-03 )))))))))))))))))))))))))))))))
.
2008-12-03 11:03 . 2008-12-03 11:03 <DIR> d-------- c:\windows\system32\xircom
2008-12-03 11:03 . 2008-12-03 11:03 <DIR> d-------- c:\program files\microsoft frontpage
2008-12-02 10:25 . 2008-12-02 10:26 250 --a------ c:\windows\gmer.ini
2008-12-02 08:39 . 2008-08-13 23:44 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Intel
2008-12-02 08:39 . 2008-08-13 23:09 <DIR> d-------- c:\documents and settings\Administrator\7zS2092.tmp
2008-12-02 08:39 . 2008-08-13 23:09 <DIR> d-------- c:\documents and settings\Administrator\_ir_sf7_temp_0
2008-12-02 08:39 . 2008-12-02 08:39 <DIR> d-------- c:\documents and settings\Administrator
2008-11-22 17:25 . 2008-11-22 19:31 <DIR> d-------- c:\documents and settings\Krasi\Application Data\TeamViewer
2008-11-22 16:35 . 2008-12-02 02:22 <DIR> d-------- c:\program files\ESET
2008-11-22 16:35 . 2008-11-22 16:35 502,368 --a------ c:\windows\system32\drivers\amon.sys
2008-11-22 16:35 . 2008-11-22 16:35 270,336 --a------ c:\windows\system32\imon.dll
2008-11-21 20:58 . 2008-11-21 20:58 <DIR> d-------- c:\documents and settings\Krasi\Application Data\Thinking Minds Budiling Bytes
2008-11-21 19:02 . 2008-11-21 19:02 <DIR> d-------- c:\documents and settings\Krasi\Application Data\Real Desktop
2008-11-21 19:01 . 2008-11-21 19:01 <DIR> d-------- c:\documents and settings\Krasi\Application Data\AD ON Multimedia
2008-11-19 18:45 . 2008-11-19 18:45 30,206 --a------ c:\windows\system32\msiexec.rar
2008-11-18 18:59 . 2008-11-18 18:59 33,824 --a------ c:\windows\system32\drivers\oreans32.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-03 09:04 22,528 ----a-w c:\windows\system32\drivers\nhcDriver.sys
2008-12-03 09:04 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-12-03 09:01 426,016 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-12-03 09:01 3,584 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-12-03 09:01 21,308 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-12-03 09:01 2,455,072 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-12-02 08:13 --------- d-----w c:\documents and settings\Krasi\Application Data\Skype
2008-11-30 14:04 --------- d-----w c:\documents and settings\Krasi\Application Data\skypePM
2008-11-21 19:33 --------- d-----w c:\documents and settings\Krasi\Application Data\uTorrent
2008-11-19 16:52 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-19 14:46 --------- d-----w c:\documents and settings\Krasi\Application Data\PC Suite
2008-11-02 15:29 --------- d-----w c:\documents and settings\Krasi\Application Data\WeatherWatcher
2008-11-01 17:19 --------- d-----w c:\program files\Launch Manager
2008-10-25 21:44 --------- d-----w c:\program files\Skype
2008-10-15 16:22 --------- d-----w c:\documents and settings\Krasi\Application Data\Samsung
2008-10-15 16:20 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-15 16:17 --------- d-----w c:\program files\Samsung
2008-10-15 16:06 --------- d-----w c:\program files\Common Files\Adobe
2008-10-04 06:50 --------- d-----w c:\documents and settings\Krasi\Application Data\Ubisoft
2008-10-04 06:50 --------- d-----w c:\documents and settings\All Users\Application Data\Ubisoft
2008-08-13 21:13 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008081420080815\index.dat
.
------- Sigcheck -------
2008-04-23 16:32 361344 68f06fe0021b01e670af37b8c5964fdf c:\windows\system32\drivers\tcpip.sys
2008-04-23 07:58 2306560 8c4050bd9fd87e23cded28ffa889b0ba c:\windows\system32\ntoskrnl.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-03-22 1271808]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-06-22 133576]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-02 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LClock"="c:\program files\LClock\LClock.exe" [2004-09-19 65536]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-06-12 174872]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-06 8433664]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-06 81920]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2006-07-17 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-05-09 860160]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2007-06-29 707080]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-03-06 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-03-06 970752]
"NotebookHardwareControl"="c:\program files\Notebook Hardware Control\nhc.exe" [2007-05-04 2629632]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2008-04-25 201992]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"nwiz"="nwiz.exe" [2007-06-06 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-28 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"nltide_3"="advpack.dll" [2008-04-23 c:\windows\system32\advpack.dll]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-04-01 568176]
FlexType 2K.lnk - c:\windows\Datecs\Flex2K.exe [2008-08-14 151552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
--a------ 2008-11-22 16:35 917504 c:\program files\ESET\nod32kui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync]
--a------ 2008-06-17 15:00 1249280 c:\program files\Nokia\Nokia PC Suite 7\PcSync2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-04-23 16:45 22058792 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-11-02 20:22 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R3 A310;AVerMedia A310 DVB-T;c:\windows\system32\DRIVERS\AVerA310USB.sys [2008-08-13 26368]
R3 BDASwCap;AVerMedia A310 BDA DVBT Capture Device;c:\windows\system32\drivers\AVerA310Cap.sys [2008-08-13 42240]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);c:\windows\system32\DRIVERS\ss_bus.sys [2008-10-15 58320]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;c:\windows\system32\DRIVERS\ss_mdfl.sys [2008-10-15 8304]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;c:\windows\system32\DRIVERS\ss_mdm.sys [2008-10-15 94000]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,Register
.
- - - - ORPHANS REMOVED - - - -
BHO-{101561B2-4657-468B-A398-8D9DC740D8E8} - (no file)
BHO-{A4DF5B08-406D-40CA-967B-57EC0503E38E} - c:\windows\system32\mlJApPIc.dll
BHO-{B3983B5E-1B68-44D8-8D36-D9AD07F4778D} - (no file)
HKLM-Run-UnlockerAssistant - c:\program files\Unlocker\UnlockerAssistant.exe
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
HKLM-Run-10ff25e8 - c:\windows\system32\rlbnitve.dll
ShellExecuteHooks-{B3983B5E-1B68-44D8-8D36-D9AD07F4778D} - (no file)
Notify-tuvVMDwU - (no file)
MSConfigStartUp-Real Desktop - d:\games\game\Real Desktop\Real Desktop.exe
MSConfigStartUp-Yodm3D - d:\games\game\Real Desktop\Yod'm 3D\Yodm3D.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Krasi\Application Data\Mozilla\Firefox\Profiles\lvsvkv3w.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.bg/ig?hl=bg
FF -: plugin - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-03 11:03:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1124)
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(1180)
c:\windows\system32\imon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\ESET\nod32krn.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\rundll32.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\windows\system32\wscntfy.exe
c:\docume~1\Krasi\LOCALS~1\temp\RtkBtMnt.exe
.
**************************************************************************
.
Completion time: 2008-12-03 11

45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-03 09

39
Pre-Run: 110,814,855,168 bytes free
Post-Run: 111,036,563,456 bytes free
187