here is the combo fix text
"Glenn" - 2007-07-13 11:54:25 - ComboFix 07-07-13.8 - Service Pack 2 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\awuuvs.dll
C:\WINDOWS\gedbcy.dll
C:\WINDOWS\hgghfe.dll
C:\WINDOWS\iiffcd.dll
C:\WINDOWS\iihfed.dll
C:\WINDOWS\khebbb.dll
C:\WINDOWS\ljkkkl.dll
C:\WINDOWS\mlkllj.dll
C:\WINDOWS\pmljgg.dll
C:\WINDOWS\pmlljg.dll
C:\WINDOWS\ssqnki.dll
C:\WINDOWS\ursqrq.dll
C:\WINDOWS\yaxxya.dll
C:\WINDOWS\dcffii.ini
C:\WINDOWS\gjllmp.ini
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Glenn\APPLIC~1\tmp1143.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp1145.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp129D.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp12A0.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp13A7.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp171.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp1807.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp183F.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp1FE.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp39.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp3B.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp3CB.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp3CE.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp49.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp55.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp56.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp6FB.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp702.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp71.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp75.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp82C.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp84C.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp96B.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp96E.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmp99.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmpA9.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmpC3.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmpCD1.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmpCD4.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmpD2.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmpE5E.tmp.exe
C:\DOCUME~1\Glenn\APPLIC~1\tmpE62.tmp.exe
C:\WINDOWS\wr.txt
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
-------\DomainService
-------\nm
((((((((((((((((((((((((( Files Created from 2007-06-13 to 2007-07-13 )))))))))))))))))))))))))))))))
2007-07-13 11:53 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-12 10:23 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-07-12 10:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-07-11 14:58 <DIR> d-------- C:\Program Files\Trend Micro
2007-07-11 14:54 <DIR> d-------- C:\Deckard
2007-07-11 14:26 <DIR> d-------- C:\ie-spyad
2007-07-11 14:22 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-07-11 12:41 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-07-11 11:30 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-07-11 11:30 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-07-11 11:30 <DIR> d-------- C:\DOCUME~1\Glenn\APPLIC~1\SUPERAntiSpyware.com
2007-07-11 11:30 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-11 09:41 126,864 --a------ C:\WINDOWS\system32\drivers\dne2000.sys
2007-07-11 09:41 101,904 --a------ C:\WINDOWS\system32\dneinobj.dll
2007-07-11 09:40 <DIR> d-------- C:\Program Files\Common Files\Deterministic Networks
2007-07-11 09:40 <DIR> d-------- C:\Program Files\Cisco Systems
2007-07-07 22:46 <DIR> d-------- C:\Program Files\iPod
2007-07-07 22:43 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-07-07 22:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
2007-06-29 20:57 1,087,216 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-06-29 20:47 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-06-29 20:47 298,104 --a------ C:\WINDOWS\system32\imon.dll
2007-06-29 20:47 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2007-06-28 19:06 <DIR> d-------- C:\DOCUME~1\Glenn\Shared
2007-06-28 19:06 <DIR> d-------- C:\DOCUME~1\Glenn\Incomplete
2007-06-28 19:05 <DIR> d-------- C:\Program Files\LimeWire
2007-06-28 19:05 <DIR> d-------- C:\DOCUME~1\Glenn\APPLIC~1\LimeWire
2007-06-28 08:58 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-06-28 08:52 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-06-28 08:50 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
2007-06-28 08:49 <DIR> dr-h----- C:\MSOCache
2007-06-25 07:47 215,144 -ra------ C:\WINDOWS\patchw32.dll
2007-06-25 07:45 215,144 -ra------ C:\WINDOWS\pw32a.dll
2007-06-24 17:36 10,344 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-06-24 16:31 241,664 --a------ C:\WINDOWS\system32\drivers\c2scsi.sys
2007-06-19 08:26 <DIR> d-------- C:\VundoFix Backups
2007-06-15 20:39 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-06-14 22:21 59,160 --a------ C:\WINDOWS\zllsputility.exe
2007-06-14 22:21 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-06-14 22:21 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs
2007-06-14 22:19 <DIR> d-------- C:\WINDOWS\Internet Logs
2007-06-14 21:33 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Roxio
2007-06-14 21:29 <DIR> d-------- C:\Program Files\InterActual
2007-06-14 21:25 51,800 --a------ C:\WINDOWS\system32\drivers\DRVNDDM.SYS
2007-06-14 21:24 92,920 --a------ C:\WINDOWS\DLA.EXE
2007-06-14 21:24 56,056 --a------ C:\WINDOWS\system32\DLAAPI_W.DLL
2007-06-14 21:24 28,216 --a------ C:\WINDOWS\system32\drivers\DLARTL_M.SYS
2007-06-14 21:24 12,952 --a------ C:\WINDOWS\system32\drivers\DLACDBHM.SYS
2007-06-14 21:24 <DIR> d-------- C:\WINDOWS\system32\DLA
2007-06-14 21:22 <DIR> d-------- C:\Program Files\Common Files\SureThing Shared
2007-06-14 21:19 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Sonic
2007-06-14 21:17 <DIR> d-------- C:\Program Files\SightSpeed
2007-06-14 21:08 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Roxio
2007-06-14 21:07 <DIR> d-------- C:\Program Files\Common Files\SightSpeed
2007-06-14 21:06 <DIR> d-------- C:\Program Files\DivX
2007-06-13 11:03 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-06-13 10:53 <DIR> d-------- C:\WINDOWS\system32\%Report%
2007-06-13 10:53 <DIR> d-------- C:\WINDOWS\system32\%Quarantine%
2007-06-13 10:53 <DIR> d-------- C:\WINDOWS\system32\%Data%
2007-06-13 10:53 <DIR> d-------- C:\WINDOWS\system32\%Backup%
2007-06-13 10:47 <DIR> d-------- C:\KAV
2007-06-13 09:54 <DIR> d-------- C:\Program Files\Nero
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-13 16:28:18 5,478 ----a-w C:\WINDOWS\mozver.dat
2007-07-11 18:39:35 -------- d-----w C:\Program Files\QuickTime
2007-07-11 18:31:26 -------- d-----w C:\Program Files\iTunes
2007-07-11 18:28:33 -------- d-----w C:\Program Files\Google
2007-07-11 18:25:44 -------- d-----w C:\Program Files\Common Files\LightScribe
2007-07-11 15:00:13 -------- d-----w C:\DOCUME~1\Glenn\APPLIC~1\Apple Computer
2007-06-30 02:12:15 4,212 -c-h--w C:\WINDOWS\system32\zllictbl.dat
2007-06-29 02:23:15 -------- d-----w C:\Program Files\Winamp
2007-06-28 14:01:53 -------- d-----w C:\Program Files\Microsoft Works
2007-06-27 09:27:41 -------- d-----w C:\DOCUME~1\Glenn\APPLIC~1\Symantec
2007-06-15 02:32:58 -------- d-----w C:\DOCUME~1\Glenn\APPLIC~1\Roxio
2007-06-15 02:24:01 -------- d-----w C:\Program Files\Roxio
2007-06-15 02:22:43 -------- d-----w C:\Program Files\Common Files\Sonic Shared
2007-06-15 02:18:14 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-15 02:12:42 -------- d-----w C:\Program Files\Common Files\Roxio Shared
2007-06-15 02:01:10 -------- d-----w C:\Program Files\Sonic
2007-06-13 14:58:42 -------- d-----w C:\DOCUME~1\Glenn\APPLIC~1\Ahead
2007-06-13 14:54:37 -------- d-----w C:\Program Files\Common Files\Ahead
2007-06-13 14:49:10 -------- d-----w C:\Program Files\Ahead
2007-06-10 17:30:03 512 ----a-w C:\ScanSectorLog.dat
2007-06-09 02:38:38 -------- d-----w C:\Program Files\Shareaza
2007-06-09 02:38:18 -------- d-----w C:\DOCUME~1\Glenn\APPLIC~1\Shareaza
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 03:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 03:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 03:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 03:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 03:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 03:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 03:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 03:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 03:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-17 03:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
2007-04-13 08:21:14 271,360 ----a-w C:\WINDOWS\system32\mscoree.dll
2007-04-05 12:19:00 268 -c--a-w C:\DOCUME~1\Glenn\APPLIC~1\wklnhst.dat
2003-08-27 19:19:18 36,963 -c--a-r C:\Program Files\Common Files\SM1updtr.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-12-18 05:16 59032 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 --a------ C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
2007-01-20 00:55 2403392 -ra------ c:\program files\google\googletoolbar3.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
2007-06-27 15:56 325048 --a------ C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 13:40]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 13:38]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 14:24]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-02-17 15:01]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 15:54]
"hpWirelessAssistant"="%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe" []
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 00:11]
"Home Theater SchSvr"="C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe" [2005-06-14 02:57]
"WINREMOTE"="C:\Program Files\InterVideo\Common\Bin\WinRemote.exe" [2005-06-14 02:07]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-08-10 12:10]
"RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-07-31 09:00]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-06-29 20:46]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 09:14]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-27 15:56]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-03 15:18]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll --a------ 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\vtstust.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
"C:\Program Files\D-Tools\daemon.exe" -lang 1033
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\retadpu2000373.exe 61A847B5BBF72810329B385575FA01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\setup]
rundll32.exe "C:\WINDOWS\wvtqpq.dll",realset
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"C:\Program Files\Windows Defender\MSASCui.exe" -hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winehq.org]
rundll32.exe "C:\WINDOWS\iiffcd.dll",realset
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ERSvc"=2 (0x2)
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-13 12:01:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????3?3?8?3??`???? ???B?????????????hLC? ??????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-13 12:06:00 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-13 12:05
--- E O F ---
Thank you for giving your time and effort to this. Glenn