i have dont the SAS again and i also did the combofix and after them i have done another hijackthis all three are below. kez.
"maz" - 2007-06-08 3:02:32 Service Pack 2 NTFS
ComboFix 07-06-3B - Running from: "C:\Documents and Settings\maz\Desktop\"
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\awvtr.dll
C:\WINDOWS\system32\cpqbpsdp.dll
C:\WINDOWS\system32\fjeeylam.dll
C:\WINDOWS\system32\fvrpyxth.dll
C:\WINDOWS\system32\mhcetjyt.dll
C:\WINDOWS\system32\uvsjlrib.dll
C:\WINDOWS\system32\vhgewybc.dll
C:\WINDOWS\system32\mljhebb.dll
C:\WINDOWS\system32\tuvuvst.dll
C:\WINDOWS\system32\winuns32.dll
C:\WINDOWS\system32\rtvwa.ini
C:\WINDOWS\system32\pdspbqpc.ini
C:\WINDOWS\system32\htxyprvf.ini
C:\WINDOWS\system32\dfhkj.bak1
C:\WINDOWS\system32\dfhkj.bak2
C:\WINDOWS\system32\dfhkj.ini
C:\WINDOWS\system32\dfhkj.ini2
C:\WINDOWS\system32\dfhkj.tmp
C:\WINDOWS\system32\tyjtechm.ini
C:\WINDOWS\system32\dfhkj.bak1
C:\WINDOWS\system32\dfhkj.bak2
C:\WINDOWS\system32\dfhkj.ini
C:\WINDOWS\system32\dfhkj.ini2
C:\WINDOWS\system32\dfhkj.tmp
C:\WINDOWS\system32\dfhkj.bak1
C:\WINDOWS\system32\dfhkj.bak2
C:\WINDOWS\system32\dfhkj.ini
C:\WINDOWS\system32\dfhkj.ini2
C:\WINDOWS\system32\dfhkj.tmp
C:\WINDOWS\system32\jkhfd.dll
C:\WINDOWS\system32\tuvvsqp.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
-- Purity Folders:
C:\DOCUME~1\maz\APPLIC~1\CROSOF~1.NET
C:\DOCUME~1\maz\APPLIC~1\MCROSO~1
C:\install.log
C:\Program Files\Common Files\svchost.exe
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1162OinAdmin.exe
C:\Program Files\Common Files\Yazzle1162OinUninstaller.exe
C:\Program Files\inetget2
C:\Program Files\outerinfo
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\screensavers.com
C:\Program Files\screensavers.com\SSSInst\bin\iebyterange.xml
C:\Program Files\screensavers.com\SSSInst\bin\iebyterange.xml.backup
C:\Program Files\screensavers.com\SSSInst\bin\SSSUninst.exe
C:\Program Files\screensavers.com\Wallpaper\swpstart.exe
C:\WINDOWS\retadpu1000272.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\system32\bund1
C:\WINDOWS\system32\bund1\temp.txt
C:\WINDOWS\system32\drivers\sfsync02.sys
C:\WINDOWS\system32\wnscpicomsv32.exe
C:\WINDOWS\wr.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NM
-------\LEGACY_SFSYNC02
-------\nm
-------\sfsync02
((((((((((((((((((((((((( Files Created from 2007-05-08 to 2007-06-08 )))))))))))))))))))))))))))))))
2007-06-08 03:09 0 --a------ C:\WINDOWS\system32\sfsync02.dll
2007-06-07 18:00 d-------- C:\Program Files\Norton 360
2007-06-07 17:55 48,776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-06-07 17:55 115,000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-06-07 17:52 d-------- C:\Program Files\Symantec
2007-06-07 16:19 58,420 --a--c--- C:\WINDOWS\system32\ttbocaos.dll
2007-06-07 15:59 55,316 --a--c--- C:\WINDOWS\system32\enywjnte.dll
2007-06-07 15:13 d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-06-07 15:10 d-------- C:\Program Files\Common Files\Symantec Shared
2007-06-07 15:01 93,696 --a------ C:\WINDOWS\system32\drvpuz.dll
2007-06-07 15:01 33,302 --a------ C:\WINDOWS\system32\cbxwxuv.dll
2007-06-07 14:47 262,144 --a------ C:\DOCUME~1\Owner\NTUSER.DAT
2007-06-07 14:47 262,144 --a------ C:\DOCUME~1\KERRYM~1\NTUSER.DAT
2007-06-06 13:58 57,344 --a--c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\jmrotsvu.exe
2007-06-06 13:56 93,696 --a------ C:\WINDOWS\system32\drvkul.dll
2007-06-06 13:56 33,302 --a------ C:\WINDOWS\system32\mljjihi.dll
2007-06-06 03:05 1,376 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-06 03:04 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-06-06 03:04 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-06-06 03:04 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-06-06 01:11 33,302 --a------ C:\WINDOWS\system32\qomlmmk.dll
2007-06-06 01:09 131,124 --a--c--- C:\WINDOWS\system32\ponvhguw.dll
2007-06-05 22:34 131,124 --a--c--- C:\WINDOWS\system32\brfotitg.dll
2007-06-05 21:40 d----c--- C:\DOCUME~1\maz\Saved Games
2007-06-05 21:40 d----c--- C:\DOCUME~1\maz\APPLIC~1\FloodLightGames
2007-06-05 21:40 d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\FloodLightGames
2007-06-05 19:17 d----c--- C:\!KillBox
2007-06-05 18:43 131,124 --a--c--- C:\WINDOWS\system32\ffcksbso.dll
2007-06-05 02:31 131,124 --a--c--- C:\WINDOWS\system32\iotpyojx.dll
2007-06-05 02:30 2,580 --a--c--- C:\WINDOWS\system32\nmxcgbyp.exe
2007-06-04 17:52 d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-06-04 17:50 d----c--- C:\DOCUME~1\maz\APPLIC~1\SUPERAntiSpyware.com
2007-06-04 17:50 d-------- C:\Program Files\SUPERAntiSpyware
2007-06-04 17:48 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-06-04 12:00 2,580 --a--c--- C:\WINDOWS\system32\rcyyhpuk.exe
2007-06-04 02:34 2,580 --a--c--- C:\WINDOWS\system32\noikdjwu.exe
2007-06-03 20:44 2,580 --a--c--- C:\WINDOWS\system32\qejfjkvk.exe
2007-06-03 20:25 1,048,576 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-06-03 20:25 d---sc--- C:\DOCUME~1\ADMINI~1\UserData
2007-06-03 20:25 d----c--- C:\DOCUME~1\ADMINI~1\WINDOWS
2007-06-03 20:25 d----c--- C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver
2007-06-03 20:25 d----c--- C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
2007-06-03 20:25 d----c--- C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
2007-06-03 20:25 d----c--- C:\DOCUME~1\ADMINI~1\APPLIC~1\AOL
2007-06-03 19:05 2,580 --a--c--- C:\WINDOWS\system32\lsfqfsuu.exe
2007-06-02 23:20 33,302 --a------ C:\WINDOWS\system32\mljkife.dll
2007-06-02 22:48 2,580 --a--c--- C:\WINDOWS\system32\hkiegbyh.exe
2007-06-02 22:27 2,580 --a--c--- C:\WINDOWS\system32\vbxjubwq.exe
2007-06-02 05:46 2,580 --a--c--- C:\WINDOWS\system32\chflwghg.exe
2007-06-02 05:45 d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
2007-06-02 05:33 d-------- C:\WINDOWS\çasks
2007-06-02 05:31 93,696 --a------ C:\WINDOWS\system32\drvfov.dll
2007-06-02 05:31 33,302 --a------ C:\WINDOWS\system32\yaywtqp.dll
2007-06-02 05:08 2,580 --a--c--- C:\WINDOWS\system32\padvxlmk.exe
2007-06-02 04:59 2,580 --a--c--- C:\WINDOWS\system32\itnlosua.exe
2007-06-02 04:44 2,580 --a--c--- C:\WINDOWS\system32\bvdmbutr.exe
2007-06-02 04:20 d----c--- C:\DOCUME~1\maz\APPLIC~1\Virgin Broadband
2007-06-02 04:19 d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Virgin Broadband
2007-06-01 19:43 152 --a--c--- C:\DOCUME~1\maz\APPLIC~1\wklnhst.dat
2007-06-01 15:46 14,868 --a------ C:\WINDOWS\system32\ejoewpqg.exe
2007-06-01 15:46 10,752 --a------ C:\WINDOWS\system32\j0291030.dll
2007-06-01 15:42 d--h----- C:\WINDOWS\PIF
2007-06-01 15:39 d-------- C:\Program Files\Free Download Manager
2007-06-01 01:22 d----c--- C:\DOCUME~1\maz\APPLIC~1\SpywareBot
2007-06-01 01:10 2,097,152 --ah----- C:\DOCUME~1\maz\NTUSER.DAT
2007-06-01 01:10 d--hsc--- C:\DOCUME~1\maz\UserData
2007-06-01 01:10 d----c--- C:\DOCUME~1\maz\WINDOWS
2007-06-01 01:10 d----c--- C:\DOCUME~1\maz\APPLIC~1\You've Got Pictures Screensaver
2007-06-01 01:10 d----c--- C:\DOCUME~1\maz\APPLIC~1\Real
2007-06-01 01:10 d----c--- C:\DOCUME~1\maz\APPLIC~1\CyberLink
2007-06-01 01:10 d----c--- C:\DOCUME~1\maz\APPLIC~1\AOL
2007-06-01 01:01 57,344 --a--c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\tezchiby.exe
2007-05-31 06:06 56,832 --a--c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\novsvida.exe
2007-05-29 21:41 d-------- C:\Program Files\Paparazzi_at
2007-05-29 17:12 d--hs---- C:\WINDOWS\ftpcache
2007-05-26 00:26 d-------- C:\Program Files\Big City Adventure San Francisco
2007-05-25 22:59 d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\JollyBear
2007-05-25 14:53 d-------- C:\Program Files\LittleShopOfTreasures_at
2007-05-25 03:42 d----c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\n7-89-o9-3r-4t-r9
2007-05-25 03:41 d-------- C:\Program Files\GameHouse
2007-05-25 02:23 d-------- C:\Program Files\ReflexiveArcade
2007-05-20 05:13 345,600 -ra------ C:\WINDOWS\system\QTIM32.DLL
2007-05-19 03:26 d-------- C:\Program Files\Hasbro Interactive
2007-05-08 20:16 d-------- C:\Program Files\Common Files\ODBC
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-02 04:18:54 -------- d-----w C:\Program Files\Windows Live Toolbar
2007-06-01 22:21:38 -------- d-----w C:\Program Files\eGames
2007-06-01 14:00:36 -------- d-----w C:\Program Files\NoAdware5.0
2007-05-27 17:26:22 -------- d-----w C:\Program Files\DivX
2007-05-26 03:55:00 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-05-24 18:43:48 -------- d-----w C:\Program Files\Shockwave.com
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 14:31:33 -------- d-----w C:\Program Files\Gamenext
2007-04-16 21:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-16 21:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 21:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 21:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 21:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 21:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 21:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 21:45:20 43,352 -c--a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 21:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-16 21:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
2007-04-12 22:11:32 -------- d-----w C:\Program Files\KService
2007-04-12 22:08:05 -------- d-----w C:\Program Files\Common Files\InstallShield
2007-04-10 15:04:57 -------- d-----w C:\Program Files\BitTorrent
2007-03-20 19:07:01 201 ----a-w C:\WINDOWS\system32\q.bat
2007-03-20 19:05:49 147,456 ----a-w C:\WINDOWS\system32\vbzip10.dll
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys
2005-07-14 19:31:20 27,648 --sha-w C:\WINDOWS\system32\AVSredirect.dll
2006-01-31 02:00:51 8 -csh--r C:\WINDOWS\system32\D18081DBF5.sys
2006-01-31 02:00:51 4,184 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{1E8A6170-7264-4D0F-BEAE-D42A53123C75}=C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll [2007-02-19 04:22]
{3455677F-0091-4865-AA3F-62C1A92E7E76}=\ [2007-06-08 03:15]
{37CB412C-1623-4B64-BFCD-F39B1F642830}=\ [2007-06-08 03:15]
{3E619DB4-6BA7-4239-8B60-183F3C62E5B1}=\ [2007-06-08 03:15]
{3F32DFA7-5CEC-4152-8824-00EBC65A1598}=\ [2007-06-08 03:15]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 02:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll [2005-11-10 14:22]
{7D2DA9B8-60D0-43DE-B1E2-211A7697FDA9}=\ [2007-06-08 03:15]
{8E477D3A-CF3C-45BA-96C7-48AC839CBCD6}=\ [2007-06-08 03:15]
{8E4CB8CE-8037-40E9-96EA-38ADB7D41EE8}=\ [2007-06-08 03:15]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-07-07 13:29]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=C:\Program Files\Windows Live Toolbar\msntb.dll [2007-02-12 15:56]
{CC59E0F9-7E43-44FA-9FAA-8377850BF205}=C:\Program Files\Free Download Manager\iefdmcks.dll [2006-08-20 19:55]
{E12BFF69-38A7-406e-A8EF-2738107A7831}=C:\WINDOWS\system32\ttbocaos.dll [2007-06-07 16:19]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"jmrotsvu.exe"="C:\Documents and Settings\All Users\Application Data\jmrotsvu.exe" [2007-06-06 13:58]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 06:59]
"TP CfgWiz"="C:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\SymCuw.exe" [2007-02-08 23:30]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-05-23 10:12]
"Jqmeoi"="C:\Documents and Settings\maz\Application Data\??crosoft.NET\?ttrib.exe" []
"Atuc"="C:\DOCUME~1\maz\APPLIC~1\MCROSO~1\wucrtupd.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^dllhost.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
backup=C:\WINDOWS\pss\dllhost.exeCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^kerry mahoney^Start Menu^Programs^Startup^Screen Saver Control.lnk]
path=C:\Documents and Settings\kerry mahoney\Start Menu\Programs\Startup\Screen Saver Control.lnk
backup=C:\WINDOWS\pss\Screen Saver Control.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\1]
"C:\WINDOWS\system32\1.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\37]
"C:\WINDOWS\system32\37.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AntivirusRegistration]
C:\Program Files\CA\Etrust Antivirus\Register.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
"C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
"C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DICP]
"C:\Documents and Settings\kerry mahoney\DICP.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Free Download Manager]
C:\Program Files\Free Download Manager\fdm.exe -autorun
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\j0291030]
rundll32 C:\WINDOWS\system32\j0291030.dll sook
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
C:\WINDOWS\kdx\KHost.exe -all
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
C:\Program Files\ltmoh\Ltmoh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MOD]
C:\Program Files\Microangelo\muamgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
"C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]
rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\novsvida.exe]
C:\Documents and Settings\All Users\Application Data\novsvida.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneCareUI]
"C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OSD]
C:\Program Files\OSD\OSD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\p2p networking]
p2pnetworking.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Realtime Monitor]
C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RelevantKnowledge]
C:\windows\system32\rlvknlg.exe -boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\Home Cinema\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\setup]
rundll32.exe "C:\WINDOWS\system32\mhcetjyt.dll",realset
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
"C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpywareBot]
C:\Program Files\SpywareBot\SpywareBot.exe -boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tezchiby.exe]
C:\Documents and Settings\All Users\Application Data\tezchiby.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTrayp]
VTtrayp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"C:\Program Files\Windows Defender\MSASCui.exe" -hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Workflow]
G:\Workflow.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=2 (0x2)
"KService"=2 (0x2)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
*Newly Created Service* - COMHOST
*Newly Created Service* - ERASERUTILREBOOTDRV
Contents of the 'Scheduled Tasks' folder
2007-06-08 02:30:02 C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
2007-06-08 02:28:27 C:\WINDOWS\tasks\HPpromoLoginTask.job
2007-05-30 15:16:44 C:\WINDOWS\tasks\MP Scheduled Quick Scan.job
2007-06-08 02:28:26 C:\WINDOWS\tasks\RegCure Program Check.job
2007-06-08 02:00:01 C:\WINDOWS\tasks\SpywareBot Scheduled Scan.job
**************************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-08 03:28:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-08 3:32:48 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-08 03:32
--- E O F ---