YAY! that worked. Heres the combofix report.
"JD" - 2007-07-22 19:37:13 - ComboFix 07-07-22.2 - Service Pack 1 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\hhwyleoe.dll
C:\WINDOWS\system32\vifhwdin.dll
C:\WINDOWS\system32\eoelywhh.ini
C:\WINDOWS\system32\gghjl.bak1
C:\WINDOWS\system32\gghjl.ini
C:\WINDOWS\system32\gghjl.bak1
C:\WINDOWS\system32\gghjl.ini
C:\WINDOWS\system32\ljhgg.dll
C:\WINDOWS\system32\hggedbx.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\exqcxwwl.exe
C:\WINDOWS\system32\fisdgque.exe
C:\WINDOWS\system32\vxhvnejr.exe
C:\WINDOWS\system32\wfqcrwcq.exe
C:\WINDOWS\system32\xwpvfcxl.exe
C:\WINDOWS\system32\yjxypmgc.exe
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((( Files Created from 2007-06-23 to 2007-07-23 )))))))))))))))))))))))))))))))
2007-07-22 13:05 <DIR> d-------- C:\VundoFix Backups
2007-07-21 16:55 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-19 21:26 <DIR> d-------- C:\WINDOWS\E31C348B63A94CBF8D7FD932ABB63244.TMP
2007-07-19 16:22 4,812 --a------ C:\WINDOWS\system32\tmp.reg
2007-07-19 16:20 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-07-19 16:20 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-07-19 16:20 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-07-19 16:08 2,000 --a------ C:\WINDOWS\slog.dll
2007-07-19 07:49 <DIR> d-------- C:\WINDOWS\system32\OS64check
2007-07-19 07:48 94,208 --a------ C:\WINDOWS\msmmsgr.exe
2007-07-19 07:48 61,440 --a------ C:\WINDOWS\msmpls.exe
2007-07-19 07:48 344,064 --a------ C:\WINDOWS\host32.exe
2007-07-19 05:06 <DIR> d-------- C:\DOCUME~1\NETWOR~1\APPLIC~1\NetMon
2007-07-18 23:28 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\NetMon
2007-07-18 23:27 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2007-07-18 23:27 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2007-07-18 23:27 <DIR> d--hs---- C:\WINDOWS\TmV3IFVzZXI
2007-07-18 23:21 465,186 --a------ C:\Temp\bY001.exe
2007-07-18 23:11 <DIR> d-------- C:\WINDOWS\system32\Z11
2007-07-18 23:11 <DIR> d-------- C:\Tempc2
2007-07-18 23:10 <DIR> d-------- C:\Temp\brr
2007-07-18 22:23 <DIR> d-------- C:\I Am Jen
2007-07-15 22:12 <DIR> d-------- C:\Program Files\Enhanced Uninstaller
2007-07-14 22:23 <DIR> dr-hs---- C:\Program Files\PSCS
2007-07-14 10:55 3 --a------ C:\WINDOWS\zclient.dll
2007-07-14 10:55 19 --a------ C:\WINDOWS\MCLDR.dll
2007-07-14 10:55 <DIR> d-------- C:\WINDOWS\system32\OS32check
2007-07-14 10:54 <DIR> d-------- C:\Program Files\Accessories
2007-07-11 03:29 22,016 --a------ C:\WINDOWS\b138.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-23 02:21:38 -------- d-----w C:\Program Files\TrueAssistant
2007-07-22 19:39:55 -------- d-----w C:\Program Files\Sonic Foundry
2007-07-22 05:54:16 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-07-22 05:54:07 -------- d-----w C:\Program Files\iPod
2007-07-22 00:54:12 -------- d-----w C:\Program Files\MusicMatch
2007-07-22 00:51:47 -------- d-----w C:\Program Files\MySpace
2007-07-22 00:15:45 -------- d-----w C:\Program Files\zpocNEW
2007-07-22 00:14:53 -------- d-----w C:\Program Files\BitComet
2007-07-21 21:13:19 -------- d-----w C:\Program Files\Spyware Doctor
2007-07-20 06:12:23 -------- d-----w C:\Program Files\DAP
2007-07-20 04:26:24 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-07-19 06:11:28 -------- d-----w C:\Program Files\Online Services
2007-07-19 04:44:53 -------- d-----w C:\Program Files\Soulseek
2007-07-17 04:14:10 -------- d-----w C:\Program Files\Juno
2007-07-11 20:05:22 -------- d-----w C:\Program Files\Winamp
2007-07-08 00:09:38 -------- d-----w C:\Program Files\ZPoC
2007-06-18 04:46:14 -------- d-----w C:\Program Files\Microsoft Windows OneCare Live
2007-06-18 04:06:27 -------- d-----w C:\Program Files\EPSON
2007-06-16 23:56:09 -------- d-----w C:\Program Files\WebCopier -- Jared's Transformer Web Site Info
2007-06-16 19:53:02 -------- d-----w C:\DOCUME~1\JD\APPLIC~1\Lavasoft
2007-06-16 01:36:01 -------- d-----w C:\Program Files\Replay Converter
2007-06-16 00:15:19 1,889,198 --sha-w C:\WINDOWS\system32\defii.ini2
2007-06-15 15:51:48 1,837,280 --sha-w C:\WINDOWS\system32\defii.bak2
2007-06-14 05:55:15 1,836,776 --sha-w C:\WINDOWS\system32\defii.bak1
2007-06-13 02:56:50 -------- d-----w C:\Program Files\iPod To Computer Transfer
2007-06-11 06:51:35 -------- d-----w C:\DOCUME~1\JD\APPLIC~1\Viewpoint
2007-06-09 14:41:20 -------- d-----w C:\DOCUME~1\JD\APPLIC~1\Sony
2007-06-06 01:16:53 -------- d-----w C:\Program Files\AIM6
2007-06-06 00:40:35 -------- d-----w C:\Program Files\Common Files\wqfr
2007-06-05 22:59:18 102,400 ----a-w C:\WINDOWS\MBDownloader_876916.exe
2007-06-05 00:53:38 -------- d--h--w C:\Program Files\WindowsUpdate
2007-06-04 02:28:50 -------- d-----w C:\Program Files\Vstplugins
2007-06-02 18:30:56 -------- d-----w C:\Program Files\appleJuice
2007-05-30 12:10:42 10,872 ----a-w C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-05-26 06:41:02 -------- d-----w C:\Program Files\Sony Setup
2007-05-26 06:40:28 -------- d-----w C:\Program Files\New Folder (2)
2007-05-26 06:12:59 -------- d-----w C:\DOCUME~1\JD\APPLIC~1\Sony Setup
2007-05-19 22:33:06 233,472 ----a-w C:\WINDOWS\system32\REX Shared Library.dll
2007-05-19 22:33:03 225,280 ----a-w C:\WINDOWS\system32\ReWire.dll
2007-05-15 23:18:25 44 ----a-w C:\WINDOWS\system32\winitn.dll
2007-05-15 23:18:21 90,112 ----a-w C:\WINDOWS\system32\agsaami.dll
2007-05-15 23:18:21 610,304 ----a-w C:\WINDOWS\system32\agsaamg.dll
2007-05-15 23:18:21 372,736 ----a-w C:\WINDOWS\system32\agsaamc.dll
2007-05-15 23:18:21 2,535,424 ----a-w C:\WINDOWS\system32\agsaamj.dll
2007-05-09 18:03:31 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-05-09 18:03:30 25,990,392 ----a-w C:\Program Files\FLV PlayerRCSetup.exe
2006-11-28 01:09:32 21,776 ----a-w C:\DOCUME~1\JD\APPLIC~1\GDIPFONTCACHEV1.DAT
2005-12-24 08:16:52 66,560 ---ha-w C:\DOCUME~1\JD\APPLIC~1\MiconoRGBSurface160.DLL
2005-12-24 08:16:51 265,728 ---ha-w C:\DOCUME~1\JD\APPLIC~1\MiconoRbTIFFLib101b3.dll
2005-12-24 08:16:51 222,208 ---ha-w C:\DOCUME~1\JD\APPLIC~1\MiconoRbRNGLib130b1.dll
2005-12-24 08:16:50 61,440 ---ha-w C:\DOCUME~1\JD\APPLIC~1\MBSQTImporterPlugin4175.dll
2005-12-24 08:16:50 44,032 ---ha-w C:\DOCUME~1\JD\APPLIC~1\MBSMainPlugin4070.dll
2005-12-24 08:16:50 39,936 ---ha-w C:\DOCUME~1\JD\APPLIC~1\MiconoPCX.DLL
2005-12-24 08:16:50 36,352 ---ha-w C:\DOCUME~1\JD\APPLIC~1\MBSFolderitemsPlugin4070.dll
2005-12-24 08:16:50 36,352 ---ha-w C:\DOCUME~1\JD\APPLIC~1\MBSFolderitemsCreatePlugin4070.dll
2005-12-24 08:16:50 191,488 ---ha-w C:\DOCUME~1\JD\APPLIC~1\MiconoRbJPEGLib110b5.dll
2005-12-24 08:16:46 80,384 ---ha-w C:\DOCUME~1\JD\APPLIC~1\MBSPicturePlugin4070.dll
2005-12-24 08:16:45 88,064 ---ha-w C:\DOCUME~1\JD\APPLIC~1\rbap550.dll
2005-12-24 08:16:45 64,512 ---ha-w C:\DOCUME~1\JD\APPLIC~1\MBSZipPlugin4069.dll
2005-12-24 08:16:45 34,304 ---ha-w C:\DOCUME~1\JD\APPLIC~1\MBSEncryptPlugin4073.dll
2005-12-24 08:16:45 29,184 ---ha-w C:\DOCUME~1\JD\APPLIC~1\RBInternetEncodings550.dll
2005-12-24 08:16:45 27,648 ---ha-w C:\DOCUME~1\JD\APPLIC~1\MBSRegistrationPlugin4071.dll
2005-12-12 18:59:35 359,111 ------r C:\Program Files\Common Files\adsmsext.exe
2005-12-12 09:11:15 140,632 ---ha-w C:\DOCUME~1\JD\APPLIC~1\ptads.bin
2004-02-04 00:08:20 1,114 ----a-w C:\Program Files\INSTALL.LOG
1989-12-12 17:10:10 1,136,352 --sh--r C:\WINDOWS\jhdiaufA.exe
2005-11-01 03:41:31 57,685 --sha-w C:\WINDOWS\system32\Aqzh0g6.exe
2007-03-09 07:12:32 27,648 --sha-w C:\WINDOWS\system32\AVSredirect.dll
2005-11-10 14:08:35 38,365 --sha-w C:\WINDOWS\system32\DmfoK.exe
2005-10-28 06:52:36 12,145 --sha-w C:\WINDOWS\system32\Izh6.exe
2005-11-10 14:23:40 3,865 --sha-w C:\WINDOWS\system32\Lun8r9.exe
2005-11-09 13:32:37 14,905 --sha-w C:\WINDOWS\system32\NhgK.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02926036-1591-4920-8EDB-9DEB37A73F8C}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{08A863EA-4452-447C-941C-4FACF5C2FA36}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D3B2489-87EE-46F6-AD7D-723644750431}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{14AF74E3-9CE2-4C84-A95C-420CFE155525}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1695B6F8-43A0-4650-A56C-5E05551C9593}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1B907DF7-7A66-40EE-ABBB-8CF05AB3EF77}]
C:\Program Files\Online Services\hosebujut83122.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2091C322-78B8-47F6-A7E5-BA506D4F161A}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2D356368-B4D5-48E8-82CF-DB8CA51790B5}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E19CBAD-7363-029F-1C16-28C7E807B3BC}]
C:\WINDOWS\System32\vzoyq.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2E681AA2-7C16-44BD-9FDD-0D4CAD521340}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3C1D6236-8A8C-408B-A9F9-7F07B119BE83}]
C:\WINDOWS\System32\qtnagcwa.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{406748CE-8FDE-47C2-A769-2CD03DD2E8C8}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{46483FAC-D468-F59E-1A13-888DBD568FEC}]
C:\WINDOWS\System32\ifbtdv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4C4654CC-9CF8-4BF6-A62F-874CAB7C8059}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4DE9EF9E-04BE-4C9D-9032-07DB9C593BE6}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E7BD74F-2B8D-469E-A3EE-FB7FA682AA7D}]
C:\PROGRA~1\POWERS~1\Toolbar\pwrsdfp\pwrsdp1.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4FE9F0D2-E3AB-4BCC-8DC5-5083BB5C83F1}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5FD1BE21-9E53-48E5-85A3-D4B0393B024A}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{63269E2C-B473-4E38-8FAF-F85D57F3D0B6}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{75F1C3E2-CB1B-4B37-BEFD-07BE6ED387D1}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7707F1CC-11B9-4A44-9988-8E46FF472E9B}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{915E3F62-EEEA-4865-A351-27B7106D17FB}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{92A38B27-4568-4816-958D-26FB59847A58}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9738F504-8C7B-4050-9D22-3A068A9A6DE2}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9C78C3A2-AA12-40EA-8076-C8EAF31179FE}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AC92E576-2327-4B32-B61D-9E1D3C02DAE2}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ADF79F03-0E61-4BAE-A88C-6E229EF7298D}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BC9D3EDB-4AB6-45CD-91C8-7F7B76DE87EA}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C45E565E-4F86-4D68-978D-AE81312BFB0D}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D0A8099D-7FD0-4215-8803-0BC846BFDE47}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D18B2D71-8D39-4354-9DDE-9313DB936F8B}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4B96AF4-42CC-44DB-81D4-B0B1A3592805}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D746A57C-4D47-4B58-94FC-E5CE34A2562F}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D782A6A3-A6E3-47FE-A127-368A42D1989B}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E077BB61-D373-4281-971E-C0E4276C8E8A}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E65D49DA-01DE-458F-8BCF-50F6012A8401}]
C:\WINDOWS\System32\qtnagcwa.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E7B8CC11-9200-4FD9-9088-4BE87B8002F6}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EA028E4E-5641-4C8B-9F6B-0CA6225FBDB0}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EC05920D-B58F-4DE7-BA41-22432427367C}]
C:\Program Files\tka11ani\tka11ani.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25]
"LogonStudio"="C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" [2002-09-03 19:38]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-04-22 09:11]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 10:06 C:\WINDOWS\AGRSMMSG.exe]
"CellVision WLAN Monitor"="C:\Program Files\AirLink101\WLAN Monitor\WLANmon.exe" [2004-07-20 19:01]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58]
"RoxioEngineUtility"="C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 18:44]
"RoxioDragToDisc"="C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-12-01 14:46]
"RoxioAudioCentral"="C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe" [2003-07-15 12:38]
"winicon"="C:\Program Files\VIA\SETICON\winicon.exe" [2004-08-30 15:05]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-30 09:43]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 17:48]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-14 15:22]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-02-18 14:30]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-04-27 14:17]
"Toce"="C:\PROGRA~1\COMMON~1\CROSOF~1.NET\alg.exe" []
"Dkz"="C:\Documents and Settings\JD\Application Data\W?nSxS\??chost.exe" []
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2005-05-26 10:52]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2006-01-24 11:37]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"UPnPMonitor"= {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\System32\upnpui.dll [2002-08-29 00:41 231424]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winuuv32]
winuuv32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=?A?C
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages scecli scecli scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Date Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Date Manager.lnk
backup=C:\WINDOWS\pss\Date Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GStartup.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GStartup.lnk
backup=C:\WINDOWS\pss\GStartup.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LoadGolfCourses]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\LoadGolfCourses
backup=C:\WINDOWS\pss\LoadGolfCoursesCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus QuickStart.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Lotus QuickStart.lnk
backup=C:\WINDOWS\pss\Lotus QuickStart.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lotus SuiteStart 97.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Lotus SuiteStart 97.lnk
backup=C:\WINDOWS\pss\Lotus SuiteStart 97.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MyWebSearch Email Plugin.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MyWebSearch Email Plugin.lnk
backup=C:\WINDOWS\pss\MyWebSearch Email Plugin.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
backup=C:\WINDOWS\pss\Service Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\updater.lnk
backup=C:\WINDOWS\pss\updater.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2wSysTray]
C:\Program Files\2Wire\2PortalMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\5TS2WSK2C62KYK]
C:\WINDOWS\SYSTEM32\JQB4.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\9446e96e5814]
C:\WINDOWS\System32\appmgr37.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\98D0CE0C16B1]
rundll32.exe D0CE0C16B1,D0CE0C16B1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\9a8722df7eb5]
C:\WINDOWS\System32\BDESac10.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\A70F6A1D-0195-42a2-934C-D8AC0F7C08EB]
rundll32.exe E6F1873B.DLL,D9EBC318C
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced Tools Check]
C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
C:\Program Files\AIM\aim.exe -cnetwait.odl
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AltnetPointsManager]
c:\program files\altnet\points manager\points manager.exe -s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\areslite]
"C:\Program Files\Ares Lite Edition\AresLite.exe" -h
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\aseye]
C:\windows\system\aseye.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiPTA]
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\atqvohmx]
C:\WINDOWS\atqvohmx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AutoUpdater]
"C:\Program Files\AutoUpdate\AutoUpdate.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bakra]
C:\WINDOWS\System32\IEHost.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
"C:\Program Files\BearShare\BearShare.exe" /pause
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Belt]
C:\WINDOWS\Belt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BtcMaestro]
C:\Program Files\KMaestro\KMaestro.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccRegVfy]
"C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CellVision WLAN Monitor]
C:\Program Files\AirLink101\WLAN Monitor\WLANmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClockSync]
C:\PROGRA~1\CLOCKS~1\Sync.exe /q
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CMESys]
"C:\Program Files\Common Files\CMEII\CMESys.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dinst]
C:\WINDOWS\dinst.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DM_Server]
C:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe /onreboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
C:\PROGRA~1\DAP\DAP.EXE /STARTUP
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadWare]
"C:\Program Files\DownloadWare\dw.exe" /H
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EbatesMoeMoneyMaker]
"C:\Program Files\EbatesMoeMoneyMaker4\EbatesMoeMoneyMaker.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ehbfbej]
C:\WINDOWS\System32\w?nspool.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eltupt]
C:\WINDOWS\eltupt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eZmmod]
C:\PROGRA~1\ezula\mmod.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Homeland Network]
"C:\Program Files\HomelandNetwork\HomelandNetwork.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hotbar]
C:\Program Files\Hotbar\Bin\4.6.1.0\HbOEAddOn.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPInSightMonitor 01]
"C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
__C:\Program Files\iTunes\iTunesHelper.exe__
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LoadGolfCourses]
C:\Program Files\Mini-Golf\LoadGolfCourses.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWBMOUSE]
C:\MMaestro\BWheel35.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaLoads Installer]
"C:\Program Files\DownloadWare\dw.exe" /H
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Tray]
C:\Documents and Settings\Ron\Desktop\My Shared Folder\Games.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsmqIntCert]
regsvr32 /s mqrt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\navapp]
C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]
rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,ClientStartup -s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nsv]
C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneTouch Monitor]
C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrbitUpdate]
C:\Program Files\Orbit\update.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrbitView]
C:\Program Files\Orbit\view.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\oymrsyen]
C:\WINDOWS\System32\fccbogad.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking]
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRISMSVR.EXE]
"C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RunDLL]
rundll32.exe "C:\WINDOWS\Downloaded Program Files\bridge.dll",Load
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rundll16]
C:\WINDOWS\rundll16.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rundll32_8]
rundll32.exe C:\WINDOWS\System32\inetp60.dll,DllRunServer
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RunWindowsUpdate]
C:\WINDOWS\uptodate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\saap]
c:\program files\180searchassistant\saap.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\satmat]
C:\WINDOWS\satmat.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search-Exe]
"C:\Program Files\se\v11\se.EXE" /H
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
"C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tka11ani]
C:\Program Files\tka11ani\tka11ani.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Toce]
C:\Program Files\ipeo\otet.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tQgmF]
C:\documents and settings\jd\local settings\temp\tQgmF.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TV Media]
C:\Program Files\TV Media\Tvm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vidmon]
C:\WINDOWS\System32\vidmon\vidmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vwmgsdw]
C:\WINDOWS\System32\qsejku.exe r
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeatherOnTray]
C:\Program Files\Hotbar\Bin\4.6.1.0\WeatherOnTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhatPulse]
C:\Program Files\WhatPulse\WhatPulse.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA]
"C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winampnew\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows SA]
C:\Program Files\WindowsSA\omniscient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinTools]
C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wqfr]
C:\PROGRA~1\COMMON~1\wqfr\wqfrm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\x3watch]
C:\Program Files\X3watch\x3watch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
C:\Program Files\Yahoo!\browser\ybrwicon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zyv]
C:\WINDOWS\zyv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{12EE7A5E-0674-42f9-A76B-000000004D00}]
rundll32.exe stlb2.dll,DllRunMain
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"YPCService"=3 (0x3)
"WinVNC4"=2 (0x2)
"WinToolsSvc"=2 (0x2)
"WANMiniportService"=2 (0x2)
"svcWRSSSDK"=3 (0x3)
"SvcProc"=2 (0x2)
"SQLAgent$SOSHOME"=3 (0x3)
"NProtectService"=2 (0x2)
"MSSQL$SOSHOME"=2 (0x2)
"iPodService"=3 (0x3)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"AOL ACS"=2 (0x2)
anio - \??\C:\WINDOWS\System32\ANIO.SYS - ANIO Service
atitunep - System32\DRIVERS\atintuxx.sys - ATI WDM TV Tuner
atixsaudio - System32\DRIVERS\atinxsxx.sys - ATI WDM TV Audio Crossbar
fax - %systemroot%\system32\fxssvc.exe - Fax
mdc8021x - System32\DRIVERS\mdc8021x.sys - AEGIS Protocol (IEEE 802.1x) v2.3.1.9
msmq - C:\WINDOWS\System32\mqsvc.exe - Message Queuing
msmqtriggers - C:\WINDOWS\System32\mqtgsvc.exe - Message Queuing Triggers
mvdcodec - System32\DRIVERS\atinmdxx.sys - ATI WDM Specialized MVD Codec
pcdcodec - System32\DRIVERS\atinpdxx.sys - ATI WDM Specialized PCD Codec
simptcp - %SystemRoot%\System32\tcpsvcs.exe - Simple TCP/IP Services
snmp - %SystemRoot%\System32\snmp.exe - SNMP Service
vdo_69e8-40c7 - \??\C:\WINDOWS\System32\vdo_69e8-40c7.sys - vdo_69e8-40c7
Contents of the 'Scheduled Tasks' folder
2007-07-19 23:25:03 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-07-23 05:26:13 C:\WINDOWS\tasks\Symantec NetDetect.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-23 01:27:42
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{F2897B9F-E454-35FB-C7E9-183F6B082943}]
"haieojiajniifbnj"=hex:6a,61,6b,64,6c,63,62,70,62,65,6f,68,66,68,65,65,6d,61,62,6d,00,..
"iaoamkfhacmcefimop"=hex:6a,61,6a,64,6c,64,6f,6f,70,69,65,6f,69,64,68,62,65,67,69,70,00,..
scanning hidden files ...
**************************************************************************
Completion time: 2007-07-23 1:34:02 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-23 01:32
--- E O F ---