Ok
well i booted my comp in safe mode and started it and it worked
so heres my results
ComboFix 07-06-13.3 - C:\hijack\ComboFix.exe
"Administrator" - 2007-06-14 18:27:58 - Service Pack 2 NTFS [SAFE MODE]
Unable to gain System Privileges
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\pmkjh.dll
C:\WINDOWS\system32\pmnll.dll
C:\WINDOWS\system32\ssqpo.dll
C:\WINDOWS\system32\ssqrs.dll
C:\WINDOWS\system32\vturq.dll
C:\WINDOWS\system32\abldvkjo.dll
C:\WINDOWS\system32\ajhrchyx.dll
C:\WINDOWS\system32\axgipvju.dll
C:\WINDOWS\system32\bjxqitdp.dll
C:\WINDOWS\system32\ccpmkfmr.dll
C:\WINDOWS\system32\eunryeaw.dll
C:\WINDOWS\system32\ggwqowrr.dll
C:\WINDOWS\system32\gjwaxvlt.dll
C:\WINDOWS\system32\hnxwlrhu.dll
C:\WINDOWS\system32\ijffubis.dll
C:\WINDOWS\system32\jnxclwwu.dll
C:\WINDOWS\system32\kqadnoxt.dll
C:\WINDOWS\system32\lcumqegg.dll
C:\WINDOWS\system32\mpjkqrfu.dll
C:\WINDOWS\system32\nghnbncy.dll
C:\WINDOWS\system32\ofyanrpj.dll
C:\WINDOWS\system32\pmytltnk.dll
C:\WINDOWS\system32\pohmxmro.dll
C:\WINDOWS\system32\rgmgnegq.dll
C:\WINDOWS\system32\shhsdhuq.dll
C:\WINDOWS\system32\tphdoxrl.dll
C:\WINDOWS\system32\vrbbsipu.dll
C:\WINDOWS\system32\wabeapgn.dll
C:\WINDOWS\system32\wkenviti.dll
C:\WINDOWS\system32\wwknepmb.dll
C:\WINDOWS\system32\xfmgxibv.dll
C:\WINDOWS\system32\xnljfglq.dll
C:\WINDOWS\system32\ylfpexqv.dll
C:\WINDOWS\system32\ssqolli.dll
C:\WINDOWS\system32\vtutrpp.dll
C:\WINDOWS\system32\vtuusqp.dll
C:\WINDOWS\system32\urwcsgbx.exe
C:\WINDOWS\system32\winhoq32.dll
C:\WINDOWS\system32\rmfkmpcc.ini
C:\WINDOWS\system32\yycdd.bak1
C:\WINDOWS\system32\yycdd.bak2
C:\WINDOWS\system32\yycdd.ini
C:\WINDOWS\system32\yycdd.ini2
C:\WINDOWS\system32\yycdd.tmp
C:\WINDOWS\system32\waeyrnue.ini
C:\WINDOWS\system32\tlvxawjg.ini
C:\WINDOWS\system32\sibuffji.ini
C:\WINDOWS\system32\uwwlcxnj.ini
C:\WINDOWS\system32\qgengmgr.ini
C:\WINDOWS\system32\quhdshhs.ini
C:\WINDOWS\system32\lrxodhpt.ini
C:\WINDOWS\system32\itivnekw.ini
C:\WINDOWS\system32\vbixgmfx.ini
C:\WINDOWS\system32\qlgfjlnx.ini
C:\WINDOWS\system32\yycdd.bak1
C:\WINDOWS\system32\yycdd.bak2
C:\WINDOWS\system32\yycdd.ini
C:\WINDOWS\system32\yycdd.ini2
C:\WINDOWS\system32\yycdd.tmp
C:\WINDOWS\system32\yycdd.bak1
C:\WINDOWS\system32\yycdd.bak2
C:\WINDOWS\system32\yycdd.ini
C:\WINDOWS\system32\yycdd.ini2
C:\WINDOWS\system32\yycdd.tmp
C:\WINDOWS\system32\ddcyy.dll
C:\WINDOWS\system32\nnnmjkl.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
C:\WINDOWS\system32\ddcyy.dll
C:\WINDOWS\system32\nnnmjkl.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ADMINI~1\APPLIC~1.\macromedia\Flash Player\#SharedObjects\2T7XWW2J\
www.broadcaster.com
C:\DOCUME~1\ADMINI~1\APPLIC~1.\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#
www.broadcaster.com
C:\Program Files\Common Files\{3C530~1
C:\Program Files\Common Files\{3C530~1\Bar888.dll
C:\Program Files\Common Files\{3C530~1\toolbardll.lzma
C:\Program Files\Common Files\{3C530~1\UnInstall.exe
C:\Program Files\Common Files\{4C530~1
C:\Program Files\outlook
C:\Program Files\winupdates
C:\WINDOWS\Registration\CRMLog\ntp2.ini
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\cmd.com
C:\WINDOWS\system32\ping.com
C:\WINDOWS\system32\tasklist.com
C:\WINDOWS\system32\tracert.com
((((((((((((((((((((((((( Files Created from 2007-05-15 to 2007-06-15 )))))))))))))))))))))))))))))))
2007-06-14 13:28 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-13 15:48 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-06-13 15:46 <DIR> d-------- C:\DOCUME~1\ADMINI~1\.housecall6.6
2007-06-13 13:21 <DIR> d-------- C:\hijack
2007-06-13 09:45 62,516 --a------ C:\WINDOWS\system32\jqtgeirv.dll
2007-06-13 01:07 57,344 --a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\gtcfaxaz.exe
2007-06-06 21:59 55,316 --a------ C:\WINDOWS\system32\naybjuut.dll
2007-06-04 21:53 2,580 --a------ C:\WINDOWS\system32\jswiwsut.exe
2007-06-04 10:54 2,580 --a------ C:\WINDOWS\system32\eyyfpauk.exe
2007-06-03 10:54 2,580 --a------ C:\WINDOWS\system32\jjttahks.exe
2007-06-03 10:27 2,580 --a------ C:\WINDOWS\system32\kxaduuea.exe
2007-06-02 10:27 2,580 --a------ C:\WINDOWS\system32\mgdgpxhp.exe
2007-06-01 11:43 2,580 --a------ C:\WINDOWS\system32\dwnptxdm.exe
2007-06-01 11:29 2,580 --a------ C:\WINDOWS\system32\ppmtgwjk.exe
2007-05-21 15:17 <DIR> d-------- C:\Program Files\QuickTime
2007-05-19 17:40 35,840 --a------ C:\WINDOWS\system32\drivers\AFS2K.SYS
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-14 01:01:08 -------- d-----w C:\Program Files\America Online 9.0a
2007-06-13 20:49:16 288 ----a-w C:\WINDOWS\system32\DVCStateBkp-{00000002-00000000-00000009-00001102-00000004-00541102}.dat
2007-06-13 20:49:16 288 ----a-w C:\WINDOWS\system32\DVCState-{00000002-00000000-00000009-00001102-00000004-00541102}.dat
2007-06-12 21:59:23 -------- d-----w C:\Program Files\iTunes
2007-06-05 03:02:41 -------- d-----w C:\Program Files\Messenger
2007-06-04 17:11:39 -------- d-----w C:\Program Files\PokerStars
2007-05-20 00:42:53 -------- d-----w C:\Program Files\Hewlett-Packard
2007-05-16 20:42:09 -------- d-----w C:\Program Files\AOL Pictures
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-14 01:42:40 262,708 ------w C:\WINDOWS\system32\ddcyy.dll
2007-05-13 00:14:58 1,494,932 --sh--w C:\WINDOWS\system32\ycbeg.bak2
2007-05-12 05:34:13 -------- d-----w C:\Program Files\Common Files\AOL
2007-05-12 00:14:45 1,495,347 --sh--w C:\WINDOWS\system32\ycbeg.bak1
2007-05-11 23:19:05 -------- d-----w C:\Program Files\hp deskjet 930c series
2007-05-03 22:03:44 1,252,495 --sh--w C:\WINDOWS\system32\bdeeg.bak2
2007-05-03 00:08:15 -------- d-----w C:\Program Files\Kylix Ringtone Maker
2007-04-30 12:25:45 64,000 ----a-w C:\WINDOWS\system32\ztkmged.dll
2007-04-30 12:25:44 86,528 ----a-w C:\WINDOWS\system32\khuyapm.dll
2007-04-28 14:04:04 86,528 ----a-w C:\WINDOWS\system32\zfdeihg.dll
2007-04-28 14:04:04 64,000 ----a-w C:\WINDOWS\system32\vopnzag.dll
2007-04-27 18:00:49 1,245,537 --sh--w C:\WINDOWS\system32\bdeeg.bak1
2007-04-27 16:00:46 244,983 ----a-w C:\WINDOWS\system32\pmnnm.dll
2007-04-27 15:00:29 246,443 ----a-w C:\WINDOWS\system32\mlljj.dll
2007-04-27 13:00:24 218,703 ----a-w C:\WINDOWS\system32\mlljk.dll
2007-04-27 12:00:22 228,923 ----a-w C:\WINDOWS\system32\ssqpp.dll
2007-04-27 11:00:25 266,883 ----a-w C:\WINDOWS\system32\mljgf.dll
2007-04-27 11:00:25 247,903 ----a-w C:\WINDOWS\system32\pmkji.dll
2007-04-27 09:54:21 86,528 ----a-w C:\WINDOWS\system32\lxzvaqb.dll
2007-04-27 09:54:21 63,488 ----a-w C:\WINDOWS\system32\ekgzipi.dll
2007-04-27 01:40:03 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\MSN6
2007-04-26 18:17:58 1,402,038 --sh--w C:\WINDOWS\system32\dfhkj.bak1
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-24 16:19:29 86,528 ----a-w C:\WINDOWS\system32\ycyfwlf.dll
2007-04-24 16:19:29 63,488 ----a-w C:\WINDOWS\system32\wgbyiwn.dll
2007-04-24 01:44:23 1,406,444 --sh--w C:\WINDOWS\system32\svvwa.bak1
2007-04-24 00:28:11 -------- d-----w C:\Program Files\LimeWire
2007-04-23 11:52:05 63,488 ----a-w C:\WINDOWS\system32\qjwgdrd.dll
2007-04-23 11:52:04 86,016 ----a-w C:\WINDOWS\system32\xpksmhn.dll
2007-04-22 14:09:00 4,083 ----a-w C:\WINDOWS\system32\ddccb.dll
2007-04-22 10:03:23 86,528 ----a-w C:\WINDOWS\system32\xnpgxm.dll
2007-04-22 10:03:23 63,488 ----a-w C:\WINDOWS\system32\lhmzmq.dll
2007-04-21 08:04:37 225,280 ----a-w C:\WINDOWS\system32\ccc3.dll
2007-04-21 08:04:14 86,528 ----a-w C:\WINDOWS\system32\hvjtihd.dll
2007-04-21 08:04:14 63,488 ----a-w C:\WINDOWS\system32\ziccdrj.dll
2007-04-20 17:53:01 -------- d-----w C:\Program Files\MySpace
2007-04-20 12:08:35 269,803 ----a-w C:\WINDOWS\system32\pmnnn.dll
2007-04-19 00:20:18 1,400,178 --sh--w C:\WINDOWS\system32\wycdd.bak1
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-18 00:20:04 1,394,750 --sh--w C:\WINDOWS\system32\wycdd.bak2
2007-04-17 05:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 05:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 05:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 05:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 05:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 05:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 05:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 05:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 05:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-17 05:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
2007-04-16 16:19:28 86,016 ----a-w C:\WINDOWS\system32\tdblxbe.dll
2007-04-16 16:19:28 63,488 ----a-w C:\WINDOWS\system32\ggvsmlg.dll
2007-04-13 17:31:03 103,984 ----a-w C:\WINDOWS\system32\AOLDial.dll
2007-04-12 19:45:27 86,528 ----a-w C:\WINDOWS\system32\zohvrse.dll
2007-04-12 19:45:27 64,000 ----a-w C:\WINDOWS\system32\neizojg.dll
2007-04-10 02:37:57 26,694 ------w C:\WINDOWS\system32\nnnmjkl.dll
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-16 23:13:44 350 ----a-w C:\WINDOWS\system32\vfw_32.reg
2006-06-16 00:11:32 0 -csha-w C:\WINDOWS\SMINST\HPCD.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{05AA754E-35FA-FDCF-F0C6-02CBD2EF7953}=C:\WINDOWS\system32\ekgzipi.dll [2007-04-27 02:54]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-03-02 20:02]
{075CA83D-FDEC-D1F0-8CC4-06B3BD7DF97C}=C:\WINDOWS\system32\ggvsmlg.dll [2007-04-16 09:19]
{0902BEBD-A638-D767-9C24-03D7FE29622D}=C:\WINDOWS\system32\tdblxbe.dll [2007-04-16 09:19]
{0A99A153-E4A0-4124-9DBE-AFADC0C902B6}=c:\windows\registration\crmlog\olelog.dll [2007-04-27 11:00]
{0AE5365B-97FC-471C-9980-7DEFF8141A43}=C:\WINDOWS\system32\ddcyy.dll [2007-05-13 18:42]
{14A714F9-F11A-9622-85CD-06DF6A39C544}=C:\WINDOWS\system32\lhmzmq.dll [2007-04-22 03:03]
{248D8ED0-2897-63D2-D555-0A35EE90CFA6}=C:\WINDOWS\system32\ziccdrj.dll [2007-04-21 01:04]
{2E12C9DF-39EE-353F-CF7A-0B0DD5174E44}=C:\WINDOWS\system32\wgbyiwn.dll [2007-04-24 09:19]
{2E887CAB-8390-4BBF-B4B9-E5796266346D}=C:\WINDOWS\system32\gebcy.dll []
{35D3810F-5636-A7C1-51F1-07E019A89F67}=C:\WINDOWS\system32\zohvrse.dll [2007-04-12 12:45]
{3E508C18-4B6C-AA38-7C37-015C60582AF2}=C:\WINDOWS\system32\ztkmged.dll [2007-04-30 05:25]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
{59B956DE-8B06-A767-A9F8-09C7EE3966EC}=C:\WINDOWS\system32\hvjtihd.dll [2007-04-21 01:04]
{5ADF3862-9E2E-4ad3-86F7-4510E6550CD0}=C:\WINDOWS\system32\jqtgeirv.dll [2007-06-13 09:45]
{5EAAAD19-AFC2-45B3-B15C-44BD9A0BB424}=C:\WINDOWS\system32\jkhfd.dll []
{6CDBBA58-25ED-D768-1E27-0B45FA88BF39}=C:\WINDOWS\system32\xnpgxm.dll [2007-04-22 03:03]
{71D93778-31D9-F7A2-321C-04BD4EEE6E4A}=C:\WINDOWS\system32\qjwgdrd.dll [2007-04-23 04:52]
{73E0DDC2-A93A-4D64-97B5-646627F61DD2}=C:\WINDOWS\system32\ccc3.dll [2007-04-21 01:04]
{745B4715-CFAE-9023-C49A-08061C46B4A5}=C:\WINDOWS\system32\vopnzag.dll [2007-04-28 07:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll [2006-12-15 04:23]
{76253FF7-A828-08C3-4792-0B03AEDE12F8}=C:\WINDOWS\system32\neizojg.dll [2007-04-12 12:45]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 20:33]
{A416D604-EAA3-4618-958C-2ECA22414616}=C:\WINDOWS\system32\nnnmjkl.dll [2007-04-09 19:37]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=C:\Program Files\Windows Live Toolbar\msntb.dll [2006-09-27 17:45]
{E57AE6A3-C900-4C48-AAF1-7BA94730E98F}=C:\WINDOWS\system32\geedb.dll []
{ECC0A5E9-68BD-4223-BCD4-6061BF347ED8}=C:\WINDOWS\system32\awvvs.dll []
{F1D0758E-4218-42A7-B369-2FBEFAE618BA}=C:\WINDOWS\system32\ddcyw.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KYE_Showicon"="C:\Program Files\USB Storage RW\shwicon.exe" [2002-10-25 16:33]
"Share-to-Web Namespace Daemon"="c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 18:42]
"CamMonitor"="c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [2002-06-18 00:11]
"KBD"="C:\HP\KBD\KBD.EXE" [2001-07-06 21:56]
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [2002-06-18 09:01]
"AutoTBar"="C:\hp\bin\autotbar.exe" []
"nwiz"="nwiz.exe" [2003-07-28 14:19 C:\WINDOWS\system32\nwiz.exe]
"CTHelper"="CTHELPER.EXE" [2003-01-09 01:39 C:\WINDOWS\system32\cthelper.exe]
"Jet Detection"="C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe" []
"LTMSG"="LTMSG.exe" []
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 05:50]
"HostManager"="C:\Program Files\Common Files\AOL\1150422044\ee\AOLSoftware.exe" [2006-09-25 17:52]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-06-15 18:42]
"Pure Networks Port Magic"="C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" []
"My Web Search Bar"="C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL" []
"sscRun"="C:\Program Files\Common Files\AOL\1150422044\ee\SSCRun.exe" []
"OASClnt"="C:\Program Files\mcafee.com\antivirus\oasclnt.exe" [2005-08-18 16:57]
"EmailScan"="C:\Program Files\mcafee.com\antivirus\mcvsescn.exe" [2005-10-19 12:13]
"MPFExe"="C:\Program Files\mcafee.com\personal firewall\MPfTray.exe" [2006-03-07 16:05]
"AOLSPScheduler"="C:\Program Files\Common Files\AOL\1150422044\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe" [2006-11-20 13:42]
"Error Nuker"="C:\Program Files\Error Nuker\bin\ErrorNuker.exe" []
"PaperPort PTD"="C:\Program Files\Scansoft\PaperPort\pptd40nt.exe" []
"IndexSearch"="C:\Program Files\Scansoft\PaperPort\IndexSearch.exe" []
"SetDefPrt"="C:\Program Files\Brother\BRMFLPRO\BrDefPrt.exe" []
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05]
"UserFaultCheck"="%systemroot%\system32\dumprep 0 -u" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" []
"hozihatk.exe"="C:\Documents and Settings\All Users\Application Data\hozihatk.exe" []
"gtcfaxaz.exe"="C:\Documents and Settings\All Users\Application Data\gtcfaxaz.exe" [2007-06-13 01:07]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" []
"MyWebSearch Email Plugin"="C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe" []
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" []
"AOL Fast Start"="C:\Program Files\America Online 9.0a\AOL.exe" [2005-07-11 22:17]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"SetDefaultMidi"=MIDIDEF.EXE
"PlayCenter2"="C:\Program Files\Creative\SBAudigy\PlayCenter2\MDEntry.EXE" "C:\Program Files\Creative\SBAudigy\PlayCenter2"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
@=
"AllowLegacyWebView"=1 (0x1)
"AllowUnhashedWebView"=1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{A416D604-EAA3-4618-958C-2ECA22414616}"="C:\WINDOWS\system32\nnnmjkl.dll" [2007-04-09 19:37]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awvvs]
C:\WINDOWS\system32\awvvs.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcyw]
C:\WINDOWS\system32\ddcyw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcyy]
C:\WINDOWS\system32\ddcyy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebcy]
C:\WINDOWS\system32\gebcy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geedb]
C:\WINDOWS\system32\geedb.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhfd]
C:\WINDOWS\system32\jkhfd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnmjkl]
nnnmjkl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\olelog]
c:\windows\registration\crmlog\olelog.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\opnkkhf]
opnkkhf.dll
*Newly Created Service* - ATWPKT2
Contents of the 'Scheduled Tasks' folder
2007-06-04 20:30:06 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-06-15 02:00:36 C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-14 18:59:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\yycdd.ini
scan completed successfully
hidden files: 1
**************************************************************************
Completion time: 2007-06-14 19:11:43 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-14 19:11
--- E O F ---
by the way thanks for the help i thought my comp was gonna crash