this is combofix. i dont know if u need the quaratined txt but if u do let me know:
ComboFix 07-09-30.5 - Julio 2007-09-30 3:37:20.4 - NTFSx86
Running from: C:\Documents and Settings\Julio.HOME-TE6W3IOMYE\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\check_LSA7.txt
C:\WINDOWS\system32\iifccax.dll
C:\WINDOWS\system32\khfcy.dll
C:\WINDOWS\system32\ntio256.sys
C:\WINDOWS\system32\protector.exe
C:\WINDOWS\system32\xpdx.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_NTIO256
-------\LEGACY_XPDX
-------\ntio256
((((((((((((((((((((((((( Files Created from 2007-08-28 to 2007-09-30 )))))))))))))))))))))))))))))))
.
2007-09-30 02:29 72,220 --a------ C:\uvbbeuu.exe
2007-09-30 02:29 25,088 --a------ C:\pgwgygwn.exe
2007-09-30 02:29 20,480 --a------ C:\rkburvxa.exe
2007-09-30 02:16 62,464 --a------ C:\WINDOWS\NirCmd.exe
2007-09-29 03:34 158,432 --a------ C:\WINDOWS\system32\bf81d339.sys
2007-09-28 17:09 122,944 --a------ C:\WINDOWS\system32\ltjwnsyb.exe
2007-09-28 17:06 158,432 --a------ C:\WINDOWS\system32\61b0b765.sys
2007-09-28 01:19 158,432 --a------ C:\WINDOWS\system32\2dd3a4cd.sys
2007-09-27 16:33 90,176 --------- C:\WINDOWS\system32\rogdakwa.exe
2007-09-27 10:38 155,712 --a------ C:\WINDOWS\system32\vjlprhtb.exe
2007-09-27 06:28 90,176 --a------ C:\WINDOWS\system32\yhwehvkj.exe
2007-09-27 00:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-09-27 00:45 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-09-27 00:34 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-27 00:16 90,176 --a------ C:\WINDOWS\system32\parrwnjh.exe
2007-09-27 00:08 122,944 --a------ C:\WINDOWS\system32\twtrletl.exe
2007-09-26 18:33 352,320 --a------ C:\WINDOWS\system32\jyimhgkr.exe
2007-09-26 17:25 122,944 --a------ C:\WINDOWS\system32\jmxnmetq.exe
2007-09-25 23:07 122,944 --a------ C:\WINDOWS\system32\rgsvvntc.exe
2007-09-25 21:59 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-25 21:38 188,480 --a------ C:\WINDOWS\system32\lyjwrbke.exe
2007-09-25 21:32 62,464 --a------ C:\WINDOWS\system32\dumphive.exe
2007-09-25 21:32 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-09-25 21:31 90,176 --a------ C:\WINDOWS\system32\rrajehyq.exe
2007-09-25 21:20 <DIR> d-------- C:\Documents and Settings\Julio.HOME-TE6W3IOMYE\.housecall6.6
2007-09-25 21:03 122,432 --a------ C:\WINDOWS\system32\vaillfgg.exe
2007-09-25 20:57 90,176 --a------ C:\WINDOWS\system32\mbwstwqo.exe
2007-09-25 17:54 90,176 --a------ C:\WINDOWS\system32\mvpkmfyg.exe
2007-09-25 16:22 122,432 --a------ C:\WINDOWS\system32\vxdkspuj.exe
2007-09-24 20:28 90,176 --a------ C:\WINDOWS\system32\feigpdeu.exe
2007-09-24 18:35 155,712 --a------ C:\WINDOWS\system32\bjftrkvk.exe
2007-09-23 22:13 90,176 --a------ C:\WINDOWS\system32\oicxersb.exe
2007-09-23 22:11 <DIR> d-------- C:\!KillBox
2007-09-23 22:04 155,712 --a------ C:\WINDOWS\system32\ejwlrlkg.exe
2007-09-23 21:19 90,176 --a------ C:\WINDOWS\system32\fthgfvei.exe
2007-09-23 21:17 90,176 --a------ C:\WINDOWS\system32\xmfcxfoa.exe
2007-09-23 08:58 90,176 --a------ C:\WINDOWS\system32\puntprag.exe
2007-09-21 01:22 221,248 --a------ C:\WINDOWS\system32\vamltqep.exe
2007-09-21 00:51 286,784 --a------ C:\WINDOWS\system32\kiwyrygm.exe
2007-09-17 17:01 122,944 --a------ C:\WINDOWS\system32\uiwfacru.exe
2007-09-17 16:17 90,176 --a------ C:\WINDOWS\system32\fpcytlkc.exe
2007-09-14 16:05 122,944 --a------ C:\WINDOWS\system32\ekgrmtda.exe
2007-09-13 22:01 90,176 --a------ C:\WINDOWS\system32\rbcmtbil.exe
2007-09-07 01:38 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2007-09-07 01:38 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2007-08-16 13:44 96,256 --a--c--- C:\WINDOWS\system32\dllcache\ac97intc.sys
2007-08-16 13:44 96,256 --a------ C:\WINDOWS\system32\drivers\ac97intc.sys
2007-08-16 13:35 509,353 --a--c--- C:\WINDOWS\system32\dllcache\ltmdmnt.sys
2007-08-16 13:35 509,353 --a------ C:\WINDOWS\system32\drivers\ltmdmnt.sys
2007-08-16 13:34 585,344 --a--c--- C:\WINDOWS\system32\dllcache\i81xdnt5.dll
2007-08-16 13:34 585,344 --a------ C:\WINDOWS\system32\i81xdnt5.dll
2007-08-16 13:34 138,240 --a--c--- C:\WINDOWS\system32\dllcache\i81xnt5.sys
2007-08-16 13:34 138,240 --a------ C:\WINDOWS\system32\drivers\i81xnt5.sys
2007-08-16 03:30 31,170 --a------ C:\WINDOWS\system32\drivers\Partizan.sys
2007-08-16 03:21 46,080 --a------ C:\WINDOWS\system32\tt.exe
2007-08-16 03:20 45,568 --a------ C:\WINDOWS\system32\cr.exe
2007-08-16 03:16 22,528 --a------ C:\WINDOWS\system32\Partizan.exe
2007-08-16 03:09 (2) -rahs-ot- C:\WINDOWS\winstart.bat
2007-08-16 02:57 45,568 --a------ C:\WINDOWS\system32\kb.exe
2007-08-16 02:57 111,616 --a------ C:\WINDOWS\system32\xd.exe
2007-08-16 02:32 78,848 --a------ C:\WINDOWS\system32\xg.exe
2007-08-16 02:32 46,080 --a------ C:\WINDOWS\system32\qs.exe
2007-08-16 02:09 78,336 --a------ C:\WINDOWS\system32\uq.exe
2007-08-16 00:40 1,700,116 ---hs---- C:\WINDOWS\system32\ceggh.ini2
2007-08-15 23:35 90,176 --a------ C:\WINDOWS\system32\coulwlgv.exe
2007-08-15 17:44 188,480 --a------ C:\WINDOWS\system32\qdgqjvtx.exe
2007-08-15 03:11 122,944 --a------ C:\WINDOWS\system32\xomeaixu.exe
2007-08-15 01:41 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-08-15 01:19 89,664 --a------ C:\WINDOWS\system32\ughummbm.exe
2007-08-15 00:58 155,712 --a------ C:\WINDOWS\system32\jhwvplso.exe
2007-08-15 00:41 122,944 --a------ C:\WINDOWS\system32\sjshqbrk.exe
2007-08-15 00:32 90,176 --a------ C:\WINDOWS\system32\igdwbtln.exe
2007-08-13 11:00 90,176 --a------ C:\WINDOWS\system32\hyansied.exe
2007-08-13 10:48 122,944 --a------ C:\WINDOWS\system32\yvatnhsy.exe
2007-08-13 10:45 90,176 --a------ C:\WINDOWS\system32\xlbvvlcn.exe
2007-08-11 11:50 90,176 --a------ C:\WINDOWS\system32\iptjxqsp.exe
2007-08-11 11:50 1,687,655 ---hs---- C:\WINDOWS\system32\ceggh.bak2
2007-08-10 01:19 1,728,635 ---hs---- C:\WINDOWS\system32\ceggh.bak1
2007-08-04 04:18 0 --a------ C:\WINDOWS\system32\scricon.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-29 01:30 --------- d-------- C:\Program Files\SUPERAntiSpyware
2007-09-28 00:42 7168 --a------ C:\WINDOWS\system32\protect.dll
2007-09-28 00:41 9216 --a------ C:\WINDOWS\system32\yatool.dll
2007-09-28 00:41 8192 --a------ C:\WINDOWS\system32\iphelp.dll
2007-09-28 00:41 5120 --a------ C:\WINDOWS\system32\rsh.dll
2007-09-28 00:41 4096 --a------ C:\WINDOWS\system32\mscert.dll
2007-09-27 20:38 --------- d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-09-26 23:30 77312 --a------ C:\WINDOWS\ua2.dll
2007-09-25 21:33 --------- d-------- C:\Program Files\FlashGet
2007-09-20 18:10 --------- d-------- C:\Program Files\AIM
2007-09-20 18:03 --------- d-------- C:\Documents and Settings\Julio.HOME-TE6W3IOMYE\Application Data\Aim
2007-09-20 17:08 --------- d-------- C:\Program Files\BitLord
2007-09-14 00:31 4608 --a------ C:\WINDOWS\system32\netd.dll
2007-09-14 00:30 9216 --a------ C:\WINDOWS\system32\rcpdu.dll
2007-09-14 00:30 8192 --a------ C:\WINDOWS\system32\dcphnet.dll
2007-09-14 00:30 7680 --a------ C:\WINDOWS\system32\gdid32.dll
2007-09-14 00:30 7680 --a------ C:\WINDOWS\system32\cbrowse.dll
2007-09-14 00:30 5120 --a------ C:\WINDOWS\system32\ftpsystem.dll
2007-09-14 00:30 4608 --a------ C:\WINDOWS\system32\psx.dll
2007-09-14 00:30 4608 --a------ C:\WINDOWS\system32\credigui.dll
2007-09-14 00:30 3072 --a------ C:\WINDOWS\system32\pxcrt.dll
2007-08-31 00:37 --------- d-------- C:\Documents and Settings\Julio.HOME-TE6W3IOMYE\Application Data\AdobeUM
2007-08-16 01:42 --------- d-------- C:\Program Files\Comodo
2007-08-15 01:11 --------- d--h----- C:\Program Files\QuickTime
2007-08-15 00:44 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-05 10:31 --------- d-------- C:\Program Files\mIRC
2007-07-07 21:10 44676 --a------ C:\WINDOWS\system32\ut.exe
2007-07-07 20:00 46004 --a------ C:\WINDOWS\system32\sq.exe
2007-02-16 17:19 0 --a------ C:\Program Files\Common Files\Internat.sys
2000-06-16 05:26 271 ---hs---- C:\Program Files\desktop.ini
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54C7D1DD-4296-451e-B756-1E94F665B4FF}]
2007-09-28 00:41 9216 --a------ C:\WINDOWS\System32\yatool.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{64B94229-7967-860A-A0C2-034C02BA876B}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"@"="" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"@"="" []
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispBackgroundPage"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2007-06-18 22:32 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winqeo32]
winqeo32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Julio.HOME-TE6W3IOMYE^Start Menu^Programs^Startup^TA_Start.lnk]
path=C:\Documents and Settings\Julio.HOME-TE6W3IOMYE\Start Menu\Programs\Startup\TA_Start.lnk
backup=C:\WINDOWS\pss\TA_Start.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2F7U3ml]
athwave.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\650f0e7c.exe]
C:\WINDOWS\System32\650f0e7c.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adprot]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdRoarUpdate]
C:\WINDOWS\ARUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\aiyhbfq]
C:\WINDOWS\System32\pnmlt\aiyhbfq.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoLoader2soo1aYlUYXM]
"C:\WINDOWS\System32\athwave.exe" /PC="CP.CDT3" /ShowLegalNote="nonbranded" /UninstallName="CtxPls"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoUpdater]
"C:\Program Files\AutoUpdate\AutoUpdate.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avp]
C:\WINDOWS\TEMP\win22.tmp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\COMODO Firewall Pro]
"C:\Program Files\Comodo\Firewall\CPF.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DllRunning]
rundll32.exe "C:\WINDOWS\qonmjg.dll",setvm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DM_Server]
C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe /onreboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DNS]
C:\Program Files\Common Files\mc-58-12-0000140.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dodcbsnm]
regsvr32 /u "C:\Documents and Settings\All Users\Application Data\dodcbsnm.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\E-Gold]
C:\WINDOWS\TEMP\VRR2.tmp
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExploreUpdSched]
C:\WINDOWS\System32\mwinkmdt.exe CHD003
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\frwx]
C:\WINDOWS\System32\tycp\frwx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1125542246\ee\AOLHostManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPwxVsG]
C:\WINDOWS\xpqdc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Optimizer]
"C:\Program Files\Internet Optimizer\optimize.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Joo8RgJnP]
vcdd3x40.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jwyehnl.dll]
C:\WINDOWS\System32\rundll32.exe "C:\Documents and Settings\NetworkService\Local Settings\Application Data\jwyehnl.dll",zjpegeg
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\links]
links.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lsciy]
C:\WINDOWS\System32\qkxcykeh\lsciy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lwbidyfm]
rundll32.exe "C:\Program Files\lwbidyfm\borgfuvw.dll",Init
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
c:\PROGRA~1\mcafee.com\agent\McAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McRegWiz]
C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Windows Update]
"C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ms-update]
scvhost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSN Messenger]
msnmrgrs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsUpdate]
C:\Program Files\MsUpdate\MsUpdate.exe /auto
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NoteBurner]
C:\Program Files\NoteBurner\VTBurnerGUI.exe /silence
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pjpru]
C:\WINDOWS\System32\pvaotsnh\pjpru.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrinTray]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProfileWatcher]
C:\Program Files\ProfileWatcher\profilewatcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
C:\WINDOWS\retadpu21.exe 61A847B5BBF72810338B2B27128065E9C084320161C4661227A755E9C2933154389A
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchIndexer]
rundll32.exe "C:\WINDOWS\System32\piaasgyy.dll",sitypnow
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\services32]
C:\Program Files\Common Files\Windows\mc-58-12-0000137.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ShowBehind]
C:\WINDOWS\sbnet\ShowBehind.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smgr]
mgrs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spoolsvv]
C:\WINDOWS\System32\spoolsvv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System]
C:\WINDOWS\System32\kernels8.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updater]
C:\Program Files\Common files\updater\wupdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
"c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
"c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebRun]
"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows update loader]
C:\Windows\xpupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{3E-EA-AD-D9-ZN}]
C:\WINDOWS\system32\dwdsrngt.exe CHD003
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MCVSRte"=2 (0x2)
"mcupdmgr.exe"=3 (0x3)
"McShield"=3 (0x3)
"McTskshd.exe"=2 (0x2)
"McDetect.exe"=2 (0x2)
"iPodService"=3 (0x3)
"wuauserv"=2 (0x2)
"uysmhernxqkgee"=2 (0x2)
"TlntSvr"=3 (0x3)
"snmuxxvitojnt"=2 (0x2)
"RSVP"=3 (0x3)
"PREVXAgent"=2 (0x2)
"Microsoft update Service"=2 (0x2)
"DomainService"=2 (0x2)
"CmdAgent"=2 (0x2)
S3 Partizan;Partizan;C:\WINDOWS\System32\drivers\Partizan.sys
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-30 03:46:02
Windows 5.1.2600 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-09-30 3:48:36 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-09-30 03:48
.
--- E O F ---