here is logfile:
"User" - 07-03-31 19:11:12 Service Pack 2
ComboFix 07-03-27.4.2 - Running from: "C:\Documents and Settings\User\desktop"
Command switches used :: /v urqroli wvwts
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\urqroli.dll
C:\WINDOWS\system32\wvwts.dll
C:\WINDOWS\system32\stwvw.bak2
C:\WINDOWS\system32\stwvw.ini
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((( Files Created from 2007-02-28 to 2007-03-31 ))))))))))))))))))))))))))))))))))
2007-03-31 19:00 26,694 --a------ C:\WINDOWS\system32\iifffff.dll
2007-03-31 18:38 48,708 --a------ C:\WINDOWS\system32\anoogjgn.dll
2007-03-31 18:30 26,694 --a------ C:\WINDOWS\system32\yayaxwu.dll
2007-03-31 18:20 280,676 ---hs---- C:\WINDOWS\system32\jkkhe.dll
2007-03-31 10:58 71,691 --a------ C:\DOCUME~1\User\x.exe
2007-03-30 18:16 2,874 --a------ C:\WINDOWS\system32\tmp.reg
2007-03-30 18:15 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
2007-03-30 18:15 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-03-30 18:15 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-03-30 18:15 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2007-03-30 18:15 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-03-30 18:15 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2007-03-30 16:54 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-03-30 16:51 <DIR> d-------- C:\WINDOWS\pss
2007-03-28 20:10 71,620 --a--c--- C:\jjj.exe
2007-03-28 20:10 30,781 -----c--- C:\is67295.exe
2007-03-28 20:09 132,116 --a------ C:\WINDOWS\system32\kxbqjamh.dll
2007-03-26 22:44 247,853 --a------ C:\WINDOWS\system32\yabcb.dll
2007-03-26 21:08 132,116 --a------ C:\WINDOWS\system32\xufiwwxw.dll
2007-03-26 20:48 71,691 --a------ C:\DOCUME~1\User\jjj.exe
2007-03-26 20:25 132,116 --a------ C:\WINDOWS\system32\tqjdjhsj.dll
2007-03-26 20:04 <DIR> d-------- C:\VundoFix Backups
2007-03-22 17:19 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-03-03 16:39 <DIR> d-------- C:\WINDOWS\system32\Dell
2007-03-03 16:39 <DIR> d-------- C:\Program Files\Dell
2007-03-03 16:32 <DIR> d-------- C:\Program Files\Motherboard Monitor 5
2007-03-03 14:15 <DIR> d-------- C:\DOCUME~1\User\APPLIC~1\Screenshot Sender
2007-03-03 14:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Gridhopetwocoal
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-03-26 20:47 -------- d-------- C:\Program Files\google
2007-03-26 18:51 -------- d-------- C:\Program Files\windows live toolbar
2007-03-26 18:49 -------- d-------- C:\Program Files\yahoo!
2007-03-26 18:48 -------- d-------- C:\Program Files\msn messenger
2007-03-22 19:21 -------- d-------- C:\Program Files\norton internet security
2007-03-03 16:33 -------- d-------- C:\Program Files\java
2007-02-06 17:40 -------- d-------- C:\Program Files\windows media connect 2
2007-01-24 18:47 48776 --a------ C:\WINDOWS\system32\s32evnt1.dll
2007-01-19 13:53 51056 --a------ C:\WINDOWS\system32\sirenacm.dll
2007-01-08 20:01 17408 --a------ C:\WINDOWS\system32\corpol.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"igfxtray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"igfxhkcmd"="C:\\WINDOWS\\System32\\hkcmd.exe"
"igfxpers"="C:\\WINDOWS\\System32\\igfxpers.exe"
"Dell Photo AIO Printer 922"="\"C:\\Program Files\\Dell Photo AIO Printer 922\\dlbtbmgr.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"osCheck"="\"C:\\Program Files\\Norton Internet Security\\osCheck.exe\""
"Symantec PIF AlertEng"="\"C:\\Program Files\\Common Files\\Symantec Shared\\PIF\\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\\PIFSvc.exe\" /a /m \"C:\\Program Files\\Common Files\\Symantec Shared\\PIF\\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\\AlertEng.dll\""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{7D064D71-DD76-4596-90C0-921766AD560A}"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljgede
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - User.job
********************************************************************
catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-03-31 19:18:40
C:\ComboFix2.txt ... 07-03-31 18:54