hi jintan, did all of the above, sent you a mail with the requested files and did a scan with a fresh comb ofix download. heres the log:
"anto" - 2007-07-07 12:33:04 - ComboFix 07-07-04.4 - Service Pack 2
((((((((((((((((((((((((( Files Created from 2007-06-07 to 2007-07-07 )))))))))))))))))))))))))))))))
2007-07-07 12:32 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-07 11:56 d——– C:\Programme\Windows Resource Kits
2007-07-06 14:20 75,512 –a—— C:\WINDOWS\zllsputility.exe
2007-07-06 14:19 1,087,216 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-07-06 14:19 d——– C:\WINDOWS\system32\ZoneLabs
2007-07-06 08:32 d——– C:\WINDOWS\system32\ActiveScan
2007-07-04 09:16 d——– C:\WINDOWS\ERUNT
2007-06-30 21:43 drahs—- C:\autorun.inf
2007-06-30 13:44 853 –a—— C:\reboot.cmd
2007-06-30 13:44 68,096 –a—— C:\diff.exe
2007-06-30 13:44 103,424 –a—— C:\grep.exe
2007-06-30 13:39 d——– C:\DiagHelp
2007-06-29 21:41 d——– C:\Programme\EVEREST Ultimate Edition
2007-06-29 00:58 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Kaspersky Lab
2007-06-27 09:59 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-06-27 09:36 d——– C:\Programme\regbackup
2007-06-26 08:34 d——– C:\WINDOWS\BDOSCAN8
2007-06-25 23:01 d——– C:\DOKUME~1\anto\ricerche di mercato
2007-06-18 09:26 d——– C:\gmer
2007-06-18 09:10 d——– C:\getservice
2007-06-13 14:52 d——– C:\Programme\ht
2007-06-13 13:46 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-13 09:45 d——– C:\pulire
2007-06-12 10:05 d——– C:\program files
2007-06-12 09:43 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-06-12 09:42 d——– C:\DOKUME~1\anto\.housecall6.6
2007-06-11 16:27 d——– C:\DOKUME~1\anto\ANWEND~1\Comodo
2007-06-11 16:26 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Comodo
2007-06-11 16:20 d——– C:\Programme\Comodo
2007-06-11 16:06 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2007-06-11 16:06 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2007-06-11 16:06 154,112 –a—— C:\WINDOWS\system32\irftp.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-06 12:22:39 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-07-06 06:58:14 ——– d—–w C:\Programme\Spybot
2007-06-25 15:31:48 ——– d—–w C:\Programme\JKDefrag
2007-06-25 11:36:29 48,486 —-a-w C:\WINDOWS\system32\perfc007.dat
2007-06-25 11:36:29 316,888 —-a-w C:\WINDOWS\system32\perfh007.dat
2007-06-11 11:48:27 ——– d—–w C:\Programme\Startup Optimizer
2007-06-11 10:40:11 ——– d—–w C:\Programme\SyncBack
2007-05-29 15:33:50 ——– d—–w C:\Programme\CCleaner
2007-05-29 14:46:36 ——– d—–w C:\Programme\ClamWin
2007-05-29 09:14:44 ——– d—–w C:\DOKUME~1\anto\ANWEND~1\.clamwin
2007-05-16 15:11:44 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:22:27 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:13:24 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 –a—— C:\Programme\Spybot\SDHelper.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-05-15 12:03]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 09:58 C:\WINDOWS\system32\bthprops.cpl]
"ZoneAlarm Client"="C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Programme\Grisoft\AVGAntiSpyware7.5\shellexecutehook.dll" [2007-05-30 14:29]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2kadiras]
2kadiras.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\9xadiras]
9xadiras.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
"C:\Programme\ClamWin\bin\ClamTray.exe" –logon
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
pctspk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZCfgSvc.exe]
C:\WINDOWS\System32\ZCfgSvc.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\System32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rundisabled]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3a5fda0-0df4-11dc-8c7f-00904bb1fd80}]
AutoRun\command- explorer.exe /n,/e,\
Contents of the 'Scheduled Tasks' folder
2007-01-15 18:05:04 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-07 12:35:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-07 12:36:59
C:\ComboFix-quarantined-files.txt … 2007-07-07 12:36
C:\ComboFix2.txt … 2007-07-01 17:52
C:\ComboFix3.txt … 2007-06-30 23:13
— E O F —