sorry for the delay, appreciate ur time and assistance with help... had some RL matters to attend to... here is my combofix & hijack logs
ComboFix 07-10-29.1 - Ryda 2007-11-03 16:12:30.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1532 [GMT -5:00]
Running from: C:\Documents and Settings\Ryda\My Documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ryda\Desktop\CFScript.txt
* Created a new restore point
FILE::
C:\Program Files\paytime.exe
C:\WINDOWS\plite731.exe
C:\WINDOWS\plite731_uninstaller_.bat
C:\WINDOWS\system32\ntdp.exe
C:\WINDOWS\system32\vtuttut.dll
C:\WINDOWS\system32\warez.exe
C:\WINDOWS\system32\windrv.sys
C:\WINDOWS\system32\wisk.exe
C:\WINDOWS\system32\wpvworbo.dll
C:\winstall.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.lnk
C:\Documents and Settings\Ryda\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Ryda\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Ryda\Favorites\Online Security Guide.lnk
C:\Program Files\Ringz Studio
C:\Program Files\Ringz Studio\Storm Codec\AviC.exe
C:\Program Files\Ringz Studio\Storm Codec\Codecs\aac_ps.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\atidvdv.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\CFLAC.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\CoreAVC.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\DmoDec.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\DVDNavExt.exe
C:\Program Files\Ringz Studio\Storm Codec\Codecs\dxr.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\empgdmx.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\FCZip.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\ff_kerneldeint.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\ff_liba52.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\ff_libdts.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\ff_realaac.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\ff_samplerate.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\ff_tremor.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\h264dec.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\languages\ffdshow.1033.en
C:\Program Files\Ringz Studio\Storm Codec\Codecs\languages\ffdshow.2052.sc
C:\Program Files\Ringz Studio\Storm Codec\Codecs\libavcodec.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\libmplayer.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\MACDec.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\MASource.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\mkunicode.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\mkx.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\mkzlib.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\mlcom.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\mp4.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\nvviddec.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\ogm.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\RLMPCDec.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\RMSplt.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\splitter.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\tomsmocomp_ff.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\TRLDRP6.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\TTASplt.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\TTL2Dec.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\VgmAudio.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\vgmbgr.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\VgmSplt.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\vgmv2k2.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\Vid1Dec.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\VSFilter.dll
C:\Program Files\Ringz Studio\Storm Codec\Codecs\xebdec.ax
C:\Program Files\Ringz Studio\Storm Codec\Codecs\xebnav.ax
C:\Program Files\Ringz Studio\Storm Codec\ebaylink.ico
C:\Program Files\Ringz Studio\Storm Codec\GSpot.exe
C:\Program Files\Ringz Studio\Storm Codec\GSpot25.dat
C:\Program Files\Ringz Studio\Storm Codec\keys.dat
C:\Program Files\Ringz Studio\Storm Codec\mplayerc.exe
C:\Program Files\Ringz Studio\Storm Codec\Plugins\nppl3260.dll
C:\Program Files\Ringz Studio\Storm Codec\Plugins\nppl3260.xpt
C:\Program Files\Ringz Studio\Storm Codec\Plugins\npqtplugin.dll
C:\Program Files\Ringz Studio\Storm Codec\Plugins\nprpjplug.dll
C:\Program Files\Ringz Studio\Storm Codec\Plugins\nsIQTScriptablePlugin.xpt
C:\Program Files\Ringz Studio\Storm Codec\Plugins\nsJSRealPlayerPlugin.xpt
C:\Program Files\Ringz Studio\Storm Codec\Plugins\QuickTimePlugin.class
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\CFCharacterSetBitmaps.bitmap
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\CoreVideo.qtx
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\CoreVideo.Resources\CoreVideo.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\CoreVideo.Resources\en.lproj\CoreVideoLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\CoreVideo.Resources\zh_CN.lproj\CoreVideoLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QTCheck.ocx
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QTPlugi0.ocx
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTime.cpl
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTime.qts
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTime.Resources\en.lproj\QuickTimeLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTime.Resources\QuickTime.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTime.Resources\zh_CN.lproj\QuickTimeLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTime3GPP.qtx
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTime3GPP.Resources\en.lproj\QuickTime3GPPLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTime3GPP.Resources\QuickTime3GPP.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTime3GPP.Resources\zh_CN.lproj\QuickTime3GPPLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeAudioSupport.qtx
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeAudioSupport.Resources\en.lproj\QuickTimeAudioSupportLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeAudioSupport.Resources\QuickTimeAudioSupport.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeAudioSupport.Resources\zh_CN.lproj\QuickTimeAudioSupportLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeEssentials.qtx
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeEssentials.Resources\en.lproj\QuickTimeEssentialsLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeEssentials.Resources\QuickTimeEssentials.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeEssentials.Resources\zh_CN.lproj\QuickTimeEssentialsLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeH264.qtx
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeH264.Resources\en.lproj\QuickTimeH264Localized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeH264.Resources\QuickTimeH264.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeH264.Resources\zh_CN.lproj\QuickTimeH264Localized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeInternetExtras.qtx
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeInternetExtras.Resources\en.lproj\QuickTimeInternetExtrasLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeInternetExtras.Resources\QuickTimeInternetExtras.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeInternetExtras.Resources\zh_CN.lproj\QuickTimeInternetExtrasLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeMPEG4.qtx
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeMPEG4.Resources\en.lproj\QuickTimeMPEG4Localized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeMPEG4.Resources\QuickTimeMPEG4.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeMPEG4.Resources\zh_CN.lproj\QuickTimeMPEG4Localized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeStreaming.qtx
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeStreaming.Resources\en.lproj\QuickTimeStreamingLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeStreaming.Resources\QuickTimeStreaming.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeStreaming.Resources\zh_CN.lproj\QuickTimeStreamingLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeStreamingExtras.qtx
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeStreamingExtras.Resources\en.lproj\QuickTimeStreamingExtrasLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeStreamingExtras.Resources\QuickTimeStreamingExtras.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeStreamingExtras.Resources\zh_CN.lproj\QuickTimeStreamingExtrasLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeVR.qtx
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeVR.Resources\en.lproj\QuickTimeVRLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeVR.Resources\QuickTimeVR.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeVR.Resources\zh_CN.lproj\QuickTimeVRLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeWebHelper.qtx
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeWebHelper.Resources\en.lproj\QuickTimeWebHelperLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeWebHelper.Resources\QuickTimeWebHelper.qtr
C:\Program Files\Ringz Studio\Storm Codec\QTSystem\QuickTimeWebHelper.Resources\zh_CN.lproj\QuickTimeWebHelperLocalized.qtr
C:\Program Files\Ringz Studio\Storm Codec\stormicl.dll
C:\Program Files\Ringz Studio\Storm Codec\stormicl.txt
C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe
C:\Program Files\Ringz Studio\Storm Codec\uninst6.04.08.exe
c:\Recycler
c:\Recycler\S-1-5-18\desktop.ini
c:\Recycler\S-1-5-18\INFO2
c:\Recycler\S-1-5-21-735536637-386832627-3918677628-1006\desktop.ini
c:\Recycler\S-1-5-21-735536637-386832627-3918677628-1006\INFO2
c:\Recycler\S-1-5-21-735536637-386832627-3918677628-501\desktop.ini
c:\Recycler\S-1-5-21-735536637-386832627-3918677628-501\INFO2
C:\WINDOWS\cookies.ini
C:\WINDOWS\plite731.exe
C:\WINDOWS\plite731_uninstaller_.bat
C:\WINDOWS\system32\blyhanhs.ini
C:\WINDOWS\system32\blyhanhs.ini2
C:\WINDOWS\system32\hjjlm.bak1
C:\WINDOWS\system32\hjjlm.ini
C:\WINDOWS\system32\hjjlm.ini2
C:\WINDOWS\system32\hjjlm.tmp
C:\WINDOWS\system32\iratuxpm.ini
C:\WINDOWS\system32\mljjh.dll
C:\WINDOWS\system32\mpkvsahj.ini
C:\WINDOWS\system32\mpkvsahj.ini2
C:\WINDOWS\system32\mpxutari.dll
C:\WINDOWS\system32\ounyjmph.exe
C:\WINDOWS\system32\qbmyreme.exe
C:\WINDOWS\system32\rickadnx.exe
C:\WINDOWS\system32\rxdvdctn.exe
C:\WINDOWS\system32\trkuqvei.dllbox
C:\WINDOWS\system32\windrv.sys
C:\WINDOWS\system32\wlbosshc.dll
C:\WINDOWS\system32\wpvworbo.dll
C:\WINDOWS\system32\yrwbilfo.ini
C:\WINDOWS\system32\yrwbilfo.ini2
C:\WINDOWS\system32\yrwbilfo.tmp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_EVENSYSTEMS
-------\DomainService
-------\EvenSystems
((((((((((((((((((((((((( Files Created from 2007-10-03 to 2007-11-03 )))))))))))))))))))))))))))))))
.
2007-11-03 16:11 81,472 --a------ C:\WINDOWS\system32\rnpqyfjb.dll
2007-11-03 16:08 87,616 --a------ C:\WINDOWS\system32\shnahylb.dll
2007-11-03 12:37 87,616 --a------ C:\WINDOWS\system32\gxakyqqh.dll
2007-11-03 12:28 87,616 --a------ C:\WINDOWS\system32\jhasvkpm.dll
2007-11-03 00:30 87,616 --a------ C:\WINDOWS\system32\oflibwry.dll
2007-11-03 00:24 87,616 --a------ C:\WINDOWS\system32\clktdbir.dll
2007-11-03 00:19 <DIR> d-------- C:\Documents and Settings\Ryda\Application Data\DAEMON Tools Pro
2007-11-03 00:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2007-11-03 00:17 340,032 --a------ C:\WINDOWS\system32\slwgsoxj.dll
2007-11-02 23:55 87,616 --------- C:\WINDOWS\system32\rlxqysnh.dll
2007-11-02 23:44 <DIR> d-------- C:\Program Files\DAEMON Tools Pro
2007-11-02 23:43 340,032 --a------ C:\WINDOWS\system32\knmuvssc.dll
2007-11-02 04:30 589 --a------ C:\WINDOWS\system32\uimsgoup.dll
2007-10-31 21:10 340,032 --a------ C:\WINDOWS\system32\nksyutmp.dll
2007-10-31 17:37 340,032 --a------ C:\WINDOWS\system32\wvbphgus.dll
2007-10-29 15:54 589 --a------ C:\WINDOWS\system32\xtfuajif.dll
2007-10-29 11:47 842 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-29 11:46 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-10-29 11:46 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-10-29 11:46 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-10-29 11:46 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-10-29 11:46 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-10-29 11:01 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-28 18:23 294,668 --a------ C:\WINDOWS\frexup2.exe
2007-10-27 12:10 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-10-27 11:44 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2007-10-19 20:43 <DIR> d-------- C:\Program Files\SpeedFan
2007-10-19 17:20 <DIR> d-------- C:\Program Files\sunplus
2007-10-19 17:14 <DIR> d-------- C:\Program Files\Multimedia Transcoding Tool
2007-10-19 17:13 <DIR> d-------- C:\Program Files\QuickTime Alternative
2007-10-16 01:20 <DIR> d-------- C:\Program Files\support.com
2007-10-16 01:20 <DIR> d-------- C:\Program Files\Common Files\SupportSoft
2007-10-07 13:26 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-10-07 12:09 <DIR> d-------- C:\Documents and Settings\Ryda\My Games
2007-10-07 12:09 <DIR> d-------- C:\Documents and Settings\All Users\Microsoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-03 21:22 83,593,248 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-11-03 21:21 1,407,520 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2007-11-03 21:19 134,048 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2007-11-03 21:19 1,120,580 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-03 20:58 --------- d-----w C:\Documents and Settings\Ryda\Application Data\uTorrent
2007-11-03 04:34 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-11-03 04:32 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-11-03 04:31 --------- d-----w C:\Program Files\TrojanHunter 4.7
2007-10-28 23:56 --------- d-----w C:\Program Files\Spyware Doctor
2007-10-27 11:18 --------- d-----w C:\Program Files\SUPERAntiSpyware
2007-10-21 21:49 --------- d-----w C:\Program Files\PhoTags Express
2007-10-19 22:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-19 22:13 --------- d-----w C:\Program Files\Media Player Classic
2007-10-19 22:13 --------- d-----w C:\Documents and Settings\Ryda\Application Data\Apple Computer
2007-10-19 22:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-10-19 22:11 --------- d-----w C:\Program Files\Common Files\Real
2007-10-15 23:44 --------- d-----w C:\Program Files\WoW
2007-10-01 05:08 --------- d-----w C:\Program Files\screensavers
2007-10-01 04:43 --------- d-----w C:\Program Files\3Planesoft Screensaver Manager
2007-10-01 04:03 --------- d-----w C:\Program Files\Astro Gemini Software
2007-10-01 03:43 --------- d-----w C:\Documents and Settings\Ryda\Application Data\TERMINAL Studio
2007-09-30 22:57 --------- d-----w C:\Program Files\Viewpoint
2007-09-30 22:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-09-30 21:02 --------- d-----w C:\Program Files\Electronic Arts
2007-09-30 20:53 --------- d-----w C:\Program Files\EA SPORTS
2007-09-26 00:54 --------- d-----w C:\Program Files\MSN Messenger
2007-09-21 19:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2003-08-16 18:56:00 579,584 --sha-r C:\WINDOWS\system32\cd.exe
.
(((((((((((((((((((((((((((((
[email protected]_12.11.36.73 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-12-12 05:15:08 34,308 ----a-w C:\WINDOWS\system32\BASSMOD.dll
+ 2007-11-03 05:18:58 9,728 ----a-w C:\WINDOWS\system32\BASSMOD.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9dc02a5d-c7db-44cf-8576-b1f70900adee}]
2007-11-03 16:11 81472 --a------ C:\WINDOWS\system32\rnpqyfjb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-22 23:25 C:\WINDOWS\KHALMNPR.Exe]
"1420bae1"="C:\WINDOWS\system32\shnahylb.dll" [2007-11-03 16:08]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-08-13 19:04]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 08:08]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-07-14 15:38:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2007-04-08 18:03 77824]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000D7}"= C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSEHB.DLL [2006-11-07 11:58 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SABWinLogon]
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL 2007-02-27 11:24 159744 C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2007-04-29 03:01 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\trkuqvei]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= ,"C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\mljjh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=C:\WINDOWS\pss\Digital Line Detect.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-Blaxx Manager]
C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]
c:\dell\bldbubg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"C:\Program Files\D-Tools\daemon.exe" -lang 1033 -lock
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
"C:\Program Files\Dell Support\DSAgnt.exe" /startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
"C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1134124099\ee\AOLSoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
C:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaGateway]
C:\Program Files\MediaGateway\MediaGateway.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Secure Folder Hider Pro]
C:\Program Files\RS Secure Folder Hider Pro Full\sfhpf.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
C:\Program Files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSC_UserPrompt]
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\DOCUME~1\Ryda\LOCALS~1\Temp\SSUPDATE.EXE Software\SUPERAntiSpyware.com\SUPERAntiSpyware
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTray]
C:\Program Files\paytime.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AIM"=C:\Program Files\AIM\aim.exe -cnetwait.odl
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"EA Core"=C:\Program Files\Electronic Arts\EA Downloader\Core.exe -silent
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SAClient"="C:\Program Files\Mediacom\BBClient\Programs\RegCon.exe" /admincheck
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
R1 SABKUTIL;SABKUTIL;\??\C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABKUTIL.sys
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe -k netsvcs
S1 SABDIFSV;SABDIFSV;\??\C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABDIFSV.SYS
S3 BLKWGD;Belkin Wireless G Desktop Card Service;C:\WINDOWS\system32\DRIVERS\BLKWGD.sys
S3 CA500AI;Chameleon XP Digital Camera;C:\WINDOWS\system32\Drivers\LG_BULK.sys
S3 CA500AV;Chameleon XP Video Camera;C:\WINDOWS\system32\DRIVERS\CA500AV.SYS
S3 DCamUSBVeo532;Veo Web Camera;C:\WINDOWS\system32\Drivers\ubVeo532.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
AutoRun\command - F:\Autorun\UbiAutorun.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-11-02 22:17:29 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-03 16:21:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-03 16:23:44 - machine was rebooted
C:\ComboFix2.txt ... 2007-10-31 18:13
C:\ComboFix3.txt ... 2007-10-29 12:13
.
--- E O F ---