Here is the second part of the Combofix log:
2008-01-16 18:24 . 2008-01-16 18:24 3,140,096 --a------ C:\WINDOWS\Cyb2k .exe
2008-01-16 18:24 . 2008-01-16 18:24 3,140,096 --a------ C:\WINDOWS\Cyb2k .exe
2008-01-16 18:24 . 2008-01-16 18:24 337,920 --a------ C:\WINDOWS\SYSTEM32\jkkjk.exe
2008-01-16 18:24 . 2008-01-16 18:24 334,336 --------- C:\WINDOWS\SYSTEM32\jkkjk.dll
2008-01-16 18:24 . 2008-01-16 18:27 391 --ahs---- C:\WINDOWS\SYSTEM32\kjkkj.ini
2008-01-16 17:59 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-15 21:52 . 2008-01-15 21:52 <DIR> d-------- C:\VundoFix Backups
2008-01-15 21:50 . 2008-01-15 21:50 28 --a------ C:\WINDOWS\liccyval.dat
2008-01-15 20:40 . 2008-01-15 20:40 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-15 20:40 . 2008-01-15 20:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-15 20:39 . 2008-01-15 20:39 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-15 19:29 . 2008-01-15 20:34 <DIR> d-------- C:\Program Files\a-squared Free
2008-01-14 23:51 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mouhid.sys
2008-01-14 23:02 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\hidusb.sys
2008-01-14 22:37 . 2004-12-07 00:46 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\You've Got Pictures Screensaver
2008-01-14 22:37 . 2004-12-07 00:48 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2008-01-14 22:37 . 2004-12-07 00:43 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-01-14 22:37 . 2004-12-07 00:47 <DIR> d--h----- C:\Documents and Settings\Administrator\Application Data\Gtek
2008-01-14 21:26 . 2008-01-14 23:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-13 18:04 . 2008-01-13 18:04 15,360 --a------ C:\WINDOWS\SYSTEM32\ctfmon .exe
2008-01-13 17:56 . 2008-01-14 20:45 <DIR> d-------- C:\WINDOWS\SYSTEM32\edcA01
2008-01-13 17:56 . 2008-01-13 17:56 <DIR> d-------- C:\Temp\Ryuan1
2008-01-13 17:56 . 2008-01-13 17:56 <DIR> d-------- C:\Temp
2008-01-04 00:56 . 2008-01-10 18:53 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-04 00:56 . 2008-01-04 00:56 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-03 18:13 . 2008-01-03 18:13 287 --a------ C:\WINDOWS\game.ini
2007-12-27 16:46 . 2007-12-27 16:46 10,240 --a------ C:\Sasso Corvo.wps
2007-12-27 16:20 . 2007-12-27 16:20 210,164 --a------ C:\airfrance.pdf
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-15 19:58 --------- d-----w C:\Program Files\Dell Support
2008-01-14 23:56 --------- d-----w C:\Program Files\Google
2008-01-13 18:33 --------- d-----w C:\Documents and Settings\Benet P\Application Data\U3
2008-01-13 18:04 3,480,064 ----a-w C:\WINDOWS\Cyb2k.exe
2008-01-03 18:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-27 16:25 --------- d-----w C:\Documents and Settings\Benet P\Application Data\AdobeUM
2007-12-19 13:23 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-12-19 13:19 107,832 ----a-w C:\WINDOWS\SYSTEM32\PnkBstrB.exe
2007-12-15 23:39 66,872 ----a-w C:\WINDOWS\SYSTEM32\PnkBstrA.exe
2007-12-15 22:50 --------- d-----w C:\Program Files\EA GAMES
2007-12-02 11:09 --------- d-----w C:\Program Files\PowerPacket
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\SYSTEM32\lsasrv.dll
2007-11-07 09:26 721,920 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\lsasrv.dll
2007-10-30 23:42 3,590,656 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-10-30 17:20 360,064 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\SYSTEM32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\quartz.dll
2007-10-27 17:40 222,720 ----a-w C:\WINDOWS\SYSTEM32\wmasf.dll
2007-10-27 17:40 222,720 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2006-10-06 22:22 1 -c--a-w C:\Documents and Settings\Benet P\SI.bin
2006-05-11 16:39 35,160 ----a-w C:\Documents and Settings\Benet P\Application Data\GDIPFONTCACHEV1.DAT
2003-06-20 03:05 49,776 ----a-w C:\WINDOWS\INF\usbhub20.sys
2003-06-20 03:05 24,752 ----a-w C:\WINDOWS\INF\hidclass.sys
2003-06-20 03:05 20,688 ----a-w C:\WINDOWS\INF\usbd.sys
2003-06-20 03:05 19,728 ----a-w C:\WINDOWS\INF\usbehci.sys
2003-06-20 03:05 138,288 ----a-w C:\WINDOWS\INF\usbport.sys
.
Code:
<pre>
----a-w 3,140,096 2008-01-16 18:24:53 C:\WINDOWS\Cyb2k .exe
----a-w 3,140,096 2008-01-16 18:24:45 C:\WINDOWS\Cyb2k .exe
----a-w 15,360 2008-01-13 18:04:49 C:\WINDOWS\SYSTEM32\ctfmon .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7AA3DD5B-A2C9-4A06-9493-D4F7BC8D7DD2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4576C73-52BD-4401-B966-5A128C4433D4}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FFC38657-0FD2-4C9B-935D-4FB1D569CE88}]
2008-01-16 18:24 334336 --------- C:\WINDOWS\system32\jkkjk.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [ ]
"Dot1XCfg"="C:\Program Files\Dot1XCfg\Dot1XCfg.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-16 18:24 1802240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [ ]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [ ]
"DiTask.exe"="C:\Program Files\Eicon\Diva\DiTask.exe" [ ]
"Divamon.exe"="C:\Program Files\Eicon\Diva\Divamon.exe" [ ]
"Eicon TechnologyLAN_DAEMON"="C:\Program Files\Eicon\Diva\watch.exe" [ ]
"CGServer"="C:\Program Files\Eicon\Diva\cgserver.exe" [ ]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [ ]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [ ]
"AOL Spyware Protection"="C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [ ]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [ ]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 101136 C:\WINDOWS\KHALMNPR.Exe]
"C2K"="C:\WINDOWS\Cyb2k .exe" [2008-01-16 18:24 3140096]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AOL 9.0 Tray Icon.lnk - C:\Program Files\AOL 9.0\aoltray.exe [2004-12-07 00:45:27]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-03-06 17:22:54]
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1997-08-26]
NETGEAR WG111T Smart Wizard.lnk - C:\Program Files\NETGEAR\WG111T Configuration Utility\wlan111t.exe [2006-01-16 16:55:15]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1997-08-26]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\jkkjk.exe
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\jkkjk
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
R0 DiMaint;Eicon Maintenance Driver;C:\WINDOWS\system32\DRIVERS\DISDN\dimaint.sys [2002-12-04 13:49]
R0 NaiFsRec;NaiFsRec;C:\WINDOWS\system32\drivers\NaiFsRec.sys [2001-04-30 04:51]
R2 AvSynMgr;AVSync Manager;"C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe" [2001-04-30 04:51]
R2 DiCapi;Eicon CAPI 2.0 Driver;C:\WINDOWS\system32\DRIVERS\DISDN\capi202k.sys [2001-06-12 13:27]
R2 DiPort;Eicon Port Driver;C:\WINDOWS\system32\DRIVERS\DISDN\diport40.sys [2002-10-16 14:32]
R3 DiWan;Eicon Driver for all Diva Client cards;C:\WINDOWS\system32\DRIVERS\DISDN\Diwan.sys [2002-10-03 15:35]
S3 AR5523;NETGEAR WG111T USB2.0 Wireless Card Service;C:\WINDOWS\system32\DRIVERS\wg11tnd5.sys [2004-10-15 10:41]
S3 ATHFMWDL;NETGEAR WG111T bootloader driver;C:\WINDOWS\system32\Drivers\ATHFMWDL.sys [2004-10-14 18:24]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\DNINDIS5.SYS [2003-07-24 12:10]
S3 oflpydin;oflpydin;C:\DOCUME~1\BENETP~1\LOCALS~1\Temp\oflpydin.sys []
S3 PLCMPR5;PLCMPR5 NDIS Protocol Driver;C:\WINDOWS\system32\PLCMPR5.SYS []
S3 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\PLCNDIS5.SYS [2004-04-26 10:11]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e52c8c7-4b80-11d9-8a2b-806d6172696f}]
\Shell\AutoRun\command - D:\AutoRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-16 18:26:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-16 18:29:50 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-16 18:29:40
.
2008-01-09 21:53:15 --- E O F ---