I did follow ur instruction n this is wat i got from combofix log:
ComboFix 07-12-09.1 - Owner 2007-12-08 22:30:09.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.242 [GMT -8:00]
Running from: C:\DOCUME~1\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\svchost.com
.
((((((((((((((((((((((((( Files Created from 2007-11-09 to 2007-12-09 )))))))))))))))))))))))))))))))
.
2007-12-06 11:47 . 2007-12-07 13:09 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-12-06 11:47 . 2007-12-06 11:47 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2007-12-06 11:47 . 2007-12-06 11:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-06 11:45 . 2007-12-06 11:45 <DIR> d-------- C:\Program Files\CCleaner
2007-12-05 17:39 . 2007-12-06 10:53 807,528 ---hs---- C:\WINDOWS\system32\xdcmtxhf.ini
2007-12-05 03:45 . 2004-01-26 05:10 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-12-05 03:45 . 2005-08-01 15:59 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2007-12-05 03:45 . 2005-08-01 15:51 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo! Messenger
2007-12-05 03:45 . 2005-09-12 22:13 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo!
2007-12-05 03:45 . 2005-12-04 02:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Ventrilo
2007-12-05 03:45 . 2004-01-27 02:21 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2007-12-05 03:45 . 2004-01-26 04:28 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2007-12-05 03:45 . 2006-01-30 16:11 <DIR> dr-h----- C:\Documents and Settings\Administrator\Application Data\SecuROM
2007-12-05 03:45 . 2004-01-26 05:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SampleView
2007-12-05 03:45 . 2005-12-05 15:58 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Motive
2007-12-05 03:45 . 2005-08-16 23:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Kazaa Lite
2007-12-05 03:45 . 2004-01-27 02:26 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\interMute
2007-12-05 03:45 . 2005-08-20 20:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\FotoWire
2007-12-05 03:45 . 2005-10-22 11:54 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Aim
2007-12-05 03:45 . 2005-09-15 09:45 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2007-12-05 03:45 . 2005-10-31 18:05 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\.bt2
2007-12-05 03:45 . 2005-10-09 02:03 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\.BitTornado
2007-12-04 23:46 . 2007-12-05 12:43 2,076,049 ---hs---- C:\WINDOWS\system32\lrfojqbb.ini
2007-12-04 23:21 . 2007-12-04 23:21 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-04 23:21 . 2007-12-04 23:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-04 23:02 . 2007-12-04 23:02 <DIR> d-------- C:\Program Files\Trend Micro
2007-12-04 22:46 . 2007-12-04 23:44 1,471,158 ---hs---- C:\WINDOWS\system32\cjynxpts.ini
2007-12-04 22:42 . 2004-05-27 18:53 237,568 -ra------ C:\WINDOWS\system32\SiSWPars.dll
2007-12-04 22:42 . 2004-05-27 18:53 155,648 -ra------ C:\WINDOWS\system32\SiSWInst.dll
2007-12-04 22:42 . 2004-05-27 19:49 154,112 -ra------ C:\WINDOWS\system32\drivers\sis162u.sys
2007-12-04 22:42 . 2004-05-27 18:53 49,152 -ra------ C:\WINDOWS\system32\SiSWBase.dll
2007-12-04 15:10 . 2007-12-04 22:38 848,777 ---hs---- C:\WINDOWS\system32\mkwhomsv.ini
2007-12-03 15:32 . 2007-12-04 15:05 794,770 ---hs---- C:\WINDOWS\system32\ulbmfrpa.ini
2007-12-02 21:35 . 2007-12-03 15:30 794,325 ---hs---- C:\WINDOWS\system32\exmkqfsi.ini
2007-12-01 23:58 . 2007-12-01 23:59 <DIR> d-------- C:\Program Files\7-Zip
2007-12-01 23:08 . 2007-12-01 23:08 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-12-01 23:08 . 2007-12-01 23:08 268 --ah----- C:\sqmdata03.sqm
2007-12-01 23:08 . 2007-12-01 23:08 244 --ah----- C:\sqmnoopt03.sqm
2007-12-01 21:27 . 2007-12-02 21:30 794,205 ---hs---- C:\WINDOWS\system32\eqvioqie.ini
2007-11-30 14:16 . 2007-11-30 14:16 2,238 --a------ C:\WINDOWS\system32\GClogo_32x32.ico
2007-11-30 11:10 . 2007-12-01 21:22 794,085 ---hs---- C:\WINDOWS\system32\vpgxequf.ini
2007-11-29 21:42 . 2007-11-30 11:02 789,960 ---hs---- C:\WINDOWS\system32\yidiauvd.ini
2007-11-26 16:05 . 2007-11-30 13:43 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Avant Profiles
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-07 22:14 --------- d-----w C:\Program Files\Winamp
2007-12-07 22:14 --------- d-----w C:\Program Files\Common Files\rqzi
2007-12-07 22:14 --------- d-----w C:\Program Files\AIM
2007-12-06 22:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-06 19:46 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-02 07:07 --------- d-----w C:\Program Files\MSN Messenger
2007-11-30 23:12 --------- d-----w C:\Program Files\Starcraft
2007-10-19 08:46 --------- d-----w C:\Program Files\Avant Browser
2007-10-19 03:43 --------- d-----w C:\Program Files\Norton AntiVirus
2007-10-19 01:51 --------- d-----w C:\Documents and Settings\Owner\Application Data\Avant Browser
2007-10-13 23:09 75,840 ----a-w C:\WINDOWS\system32\awooswon.dll
2007-10-13 10:57 75,840 ----a-w C:\WINDOWS\system32\lsbajwxf.dll
2007-09-23 07:25 7,806 ----a-w C:\syssylo.exe
2007-09-19 06:14 4,096 ----a-w C:\WINDOWS\system32\tcpsvcs.dll
2007-09-18 06:14 133,632 --s-a-r C:\WINDOWS\system32\sys32time.dll
2007-09-02 10:50 304,453 ----a-w C:\Documents and Settings\Owner\mcc.exe
2007-09-02 06:01 160,768 ----a-w C:\Documents and Settings\Owner\gotgo.exe
2006-01-02 08:03 300,760 --sh--w C:\WINDOWS\mshostsr.exe
1989-12-12 16:10 404,208 --sh--r C:\WINDOWS\orqeenq.exe
2006-02-23 07:31 19,456 --sh--r C:\WINDOWS\system\svchost.dll
.
((((((((((((((((((((((((((((( snapshot@2007-12-07_14.58.32.14 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-27 11:58:11 140,288 ----a-w C:\WINDOWS\catchme.exe
+ 2007-12-08 11:32:45 141,824 ----a-w C:\WINDOWS\catchme.exe
- 2007-12-07 22:45:48 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-12-09 06:25:57 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-12-07 22:45:48 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-09 06:25:57 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-12-07 22:45:48 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-09 06:25:57 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-07 22:53:12 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
+ 2007-12-09 06:11:53 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95CB3857-A0E7-F21B-EE5B-FD8A45862C97}]
C:\WINDOWS\System32\cnsi.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RecordNow!"="" []
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-28 14:10]
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" []
"Notn"="C:\WINDOWS\System32\SCURIT~1\wuaclt.exe" []
"Omht"="C:\WINDOWS\??stem32\?poolsv.exe" [2003-08-15 18:40]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2004-01-26 02:24]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 16:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-11-18 07:11]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 03:23]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-08-21 03:15]
"KBD"="C:\HP\KBD\KBD.EXE" [2007-12-08 22:01]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 08:01]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-01-26 04:29]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 16:50]
"VTTimer"=" " []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 00:59]
"LTMSG"="LTMSG.exe" [2003-07-14 17:52 C:\WINDOWS\ltmsg.exe]
"PS2"=" " []
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-03 20:35 C:\WINDOWS\ALCXMNTR.EXE]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe" [2003-03-12 04:23]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-03-28 14:10]
"QuickTime Task"="C:\PROGRA~1\QUICKT~1\qttask.exe" [2007-09-24 23:37]
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSub.exe [2004-01-27 02:26:18]
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSub.exe [2004-01-27 02:26:18]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-01-26 05:20:47]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 12:19:24]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-01-19 00:44:15]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-07-30 04:49:48]
SBC Self Support Tool.lnk - C:\Program Files\SBC Self Support Tool\bin\matcli.exe [2006-07-11 13:16:00]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
.
Contents of the 'Scheduled Tasks' folder
"2007-10-19 00:33:48 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-08 22:33:14
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-08 22:34:05
C:\ComboFix2.txt ... 2007-12-08 22:18
C:\ComboFix3.txt ... 2007-12-07 22:31
.
--- E O F ---