Hi …My home page is infected pls help. I am attachng the hijack this log

file of HijackThis v1.99.1
Scan saved at 5:16:34 PM, on 12/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SYSTEM32\wscript.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\CameraFixer.exe
C:\WINDOWS\tsnpstd3.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Outlook Express\Msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\OEMUser\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sujin.com.np/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Sujin.com.np
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\userinit.exe,C:\WINDOWS\SYSTEM32\wscript.exe C:\WINDOWS\SYSTEM32\VirusRemoval.vbs
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [CameraFixer] C:\WINDOWS\CameraFixer.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{4E23F82E-96EA-4113-B15B-3F20B2722CA4}: NameServer = 208.110.16.14,208.110.16.13
O17 - HKLM\System\CS1\Services\Tcpip\..\{4E23F82E-96EA-4113-B15B-3F20B2722CA4}: NameServer = 208.110.16.14,208.110.16.13
O17 - HKLM\System\CS2\Services\Tcpip\..\{4E23F82E-96EA-4113-B15B-3F20B2722CA4}: NameServer = 208.110.16.14,208.110.16.13
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe

hi i ran the sdfix & the combofix ….i am including the logs here along with the latest HIjack this log Pls let me know what needs to be done next

SDFix: Version 1.112

Run by [removed] on Thu 12/13/2007 at 07:48 AM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

No Trojan Files Found




Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\MTD2002\\mtdserver.exe"="C:\\Program Files\\MTD2002\\mtdserver.exe:*:Enabled:mtdServer"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
—————


Files with Hidden Attributes:

Wed 28 Nov 2007 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\0d4a7c846fe5e74c3056c3e240c1ffeb\BIT1.tmp"
Thu 13 Dec 2007 2,166,832 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\6c0455d67216e75859cc27e7120ab0d1\BIT5.tmp"

Finished!
ComboFix 07-12-12.3 - OEMUser 2007-12-13 7:56:26.5 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.201 [GMT 5.75:45]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-11-13 to 2007-12-13 )))))))))))))))))))))))))))))))
.

2007-12-12 09:55 . 2007-12-12 09:55 d——– C:\Program Files\SUPERAntiSpyware
2007-12-12 09:55 . 2007-12-12 09:55 d——– C:\Documents and Settings\OEMUser\Application Data\SUPERAntiSpyware.com
2007-12-12 09:55 . 2007-12-12 09:55 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-12 09:54 . 2007-12-12 09:54 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-12-09 12:29 . 2007-12-09 12:29 d——– C:\WINDOWS\Cache
2007-12-01 17:48 . 2007-12-01 17:48 17,920 –a—— C:\Documents and Settings\OEMUser\Application Data\GDIPFONTCACHEV1.DAT
2007-11-19 08:21 . 2007-11-19 08:21 d——– C:\Program Files\Ahead
2007-11-19 08:21 . 2002-11-03 18:59 1,007,616 ——— C:\WINDOWS\Unnero.exe
2007-11-19 08:21 . 2002-09-11 18:00 532,480 –a—— C:\WINDOWS\SYSTEM32\imagx5.dll
2007-11-19 08:21 . 2002-09-11 18:00 507,904 –a—— C:\WINDOWS\SYSTEM32\imagr5.dll
2007-11-19 08:21 . 2002-09-11 18:00 275,312 –a—— C:\WINDOWS\SYSTEM32\ImagXpr5.dll
2007-11-19 08:21 . 2002-09-11 18:01 155,648 –a—— C:\WINDOWS\SYSTEM32\NeroCheck.exe
2007-11-19 08:21 . 2002-09-11 18:00 106,496 –a—— C:\WINDOWS\SYSTEM32\TwnLib20.dll
2007-11-19 08:21 . 2002-11-06 12:02 64,506 ——— C:\WINDOWS\Unnero.cfg
2007-11-19 08:21 . 2002-09-11 18:01 49,152 ——— C:\WINDOWS\SYSTEM32\MultiSZ.dll
2007-11-19 08:21 . 2002-09-11 18:00 35,328 –a—— C:\WINDOWS\SYSTEM32\picn20.dll
2007-11-16 20:06 . 2007-11-16 20:06 268 –ah—– C:\sqmdata19.sqm
2007-11-16 20:06 . 2007-11-16 20:06 244 –ah—– C:\sqmnoopt19.sqm
2007-11-16 18:04 . 2007-11-16 18:04 268 –ah—– C:\sqmdata18.sqm
2007-11-16 18:04 . 2007-11-16 18:04 244 –ah—– C:\sqmnoopt18.sqm
2007-11-16 16:36 . 2007-11-16 16:36 268 –ah—– C:\sqmdata17.sqm
2007-11-16 16:36 . 2007-11-16 16:36 244 –ah—– C:\sqmnoopt17.sqm
2007-11-16 11:09 . 2007-11-16 11:09 268 –ah—– C:\sqmdata16.sqm
2007-11-16 11:09 . 2007-11-16 11:09 244 –ah—– C:\sqmnoopt16.sqm
2007-11-15 18:29 . 2007-11-15 18:29 268 –ah—– C:\sqmdata15.sqm
2007-11-15 18:29 . 2007-11-15 18:29 244 –ah—– C:\sqmnoopt15.sqm
2007-11-14 10:08 . 2007-11-14 10:08 268 –ah—– C:\sqmdata14.sqm
2007-11-14 10:08 . 2007-11-14 10:08 244 –ah—– C:\sqmnoopt14.sqm
2007-11-13 19:02 . 2007-11-13 19:02 268 –ah—– C:\sqmdata13.sqm
2007-11-13 19:02 . 2007-11-13 19:02 244 –ah—– C:\sqmnoopt13.sqm
2007-11-13 11:52 . 2007-11-13 11:52 268 –ah—– C:\sqmdata12.sqm
2007-11-13 11:52 . 2007-11-13 11:52 244 –ah—– C:\sqmnoopt12.sqm
2007-11-13 07:24 . 2007-11-13 07:24 268 –ah—– C:\sqmdata11.sqm
2007-11-13 07:24 . 2007-11-13 07:24 244 –ah—– C:\sqmnoopt11.sqm

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-14 07:26 450,560 —-a-w C:\WINDOWS\SYSTEM32\dllcache\jscript.dll
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-12 11:50 ——— d—–w C:\Program Files\Common Files\snpstd3
2007-11-12 11:36 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-12 11:36 ——— d—–w C:\Program Files\Vimicro
2007-11-03 08:29 ——— d—–w C:\Program Files\InCode Solutions
2007-11-03 08:27 155,995 —-a-w C:\WINDOWS\JAVA\Packages\PRVL35ZD.ZIP
2007-11-01 12:10 ——— d—–w C:\Documents and Settings\OEMUser\Application Data\Yahoo!
2007-11-01 12:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-11-01 10:12 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-10-30 10:16 3,058,688 —-a-w C:\WINDOWS\SYSTEM32\dllcache\mshtml.dll
2007-10-30 05:25 11,310 –sha-r C:\WINDOWS\SYSTEM32\VirusRemoval.vbs
2007-10-30 04:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-30 02:24 ——— d—–w C:\Program Files\mtd2002
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\SYSTEM32\quartz.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\SYSTEM32\dllcache\quartz.dll
2007-10-27 18:00 ——— d—–w C:\Program Files\Common Files\Adobe
2007-10-27 18:00 ——— d—–w C:\Documents and Settings\OEMUser\Application Data\InterTrust
2007-10-27 17:14 ——— d—–w C:\Program Files\MSN Messenger
2007-10-27 13:54 99,965 —-a-w C:\WINDOWS\UninstallFirefox.exe
2007-10-27 11:16 ——— d—–w C:\Program Files\Super Fast Shutdown
2007-10-27 11:15 ——— d—–w C:\Program Files\Microsoft ActiveSync
2007-10-27 10:53 ——— d—–w C:\Documents and Settings\OEMUser\Application Data\Yahoo! Messenger
2007-10-27 10:28 ——— d—–w C:\Program Files\Symantec
2007-10-27 10:28 ——— d—–w C:\Program Files\NavNT
2007-10-27 10:28 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-10-27 10:28 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2007-10-27 10:27 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-10-27 10:21 ——— d—–w C:\Program Files\Yahoo!
2007-10-27 09:48 ——— d—–w C:\Program Files\microsoft frontpage
2007-10-27 09:11 30 —-a-w C:\Config_SREBACK_20071103142059.sys
2007-10-27 09:11 ——— d—–w C:\Program Files\DirectX
2007-10-27 09:10 93,271 —-a-w C:\WINDOWS\JAVA\Packages\DRTV17JB.ZIP
2007-10-27 09:10 558,142 —-a-w C:\WINDOWS\JAVA\Packages\RPZR7NZF.ZIP
2007-10-27 09:10 266 –sh–w C:\Program Files\desktop.ini
2007-10-27 09:10 11,079 —h–w C:\Program Files\folder.htt
2007-10-27 08:16 ——— d—–w C:\Program Files\PLUS!
2007-10-27 08:16 ——— d—–w C:\Program Files\CHAT
2007-10-27 08:16 ——— d—–r C:\Program Files\Accessories
2007-10-26 03:36 8,454,656 —-a-w C:\WINDOWS\SYSTEM32\dllcache\shell32.dll
2007-10-11 06:13 96,256 —-a-w C:\WINDOWS\SYSTEM32\dllcache\inseng.dll
2007-10-11 06:13 659,456 —-a-w C:\WINDOWS\SYSTEM32\dllcache\wininet.dll
2007-10-11 06:13 615,424 —-a-w C:\WINDOWS\SYSTEM32\dllcache\urlmon.dll
2007-10-11 06:13 55,808 —-a-w C:\WINDOWS\SYSTEM32\dllcache\extmgr.dll
2007-10-11 06:13 532,480 —-a-w C:\WINDOWS\SYSTEM32\dllcache\mstime.dll
2007-10-11 06:13 474,112 —-a-w C:\WINDOWS\SYSTEM32\dllcache\shlwapi.dll
2007-10-11 06:13 449,024 —-a-w C:\WINDOWS\SYSTEM32\dllcache\mshtmled.dll
2007-10-11 06:13 39,424 —-a-w C:\WINDOWS\SYSTEM32\dllcache\pngfilt.dll
2007-10-11 06:13 357,888 —-a-w C:\WINDOWS\SYSTEM32\dllcache\dxtmsft.dll
2007-10-11 06:13 251,392 —-a-w C:\WINDOWS\SYSTEM32\dllcache\iepeers.dll
2007-10-11 06:13 205,312 —-a-w C:\WINDOWS\SYSTEM32\dllcache\dxtrans.dll
2007-10-11 06:13 16,384 —-a-w C:\WINDOWS\SYSTEM32\dllcache\jsproxy.dll
2007-10-11 06:13 151,040 —-a-w C:\WINDOWS\SYSTEM32\dllcache\cdfview.dll
2007-10-11 06:13 146,432 —-a-w C:\WINDOWS\SYSTEM32\dllcache\msrating.dll
2007-10-11 06:13 1,494,528 —-a-w C:\WINDOWS\SYSTEM32\dllcache\shdocvw.dll
2007-10-11 06:13 1,054,208 —-a-w C:\WINDOWS\SYSTEM32\dllcache\danim.dll
2007-10-11 06:13 1,023,488 —-a-w C:\WINDOWS\SYSTEM32\dllcache\browseui.dll
2007-10-10 11:16 18,432 —-a-w C:\WINDOWS\SYSTEM32\dllcache\iedw.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SlowFile Icon Overlay]
@={7D688A77-C613-11D0-999B-00C04FD655E1}

[HKEY_CLASSES_ROOT\CLSID\{7D688A77-C613-11D0-999B-00C04FD655E1}]
2007-10-26 09:21 8454656 –a—— C:\WINDOWS\SYSTEM32\SHELL32.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:54]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CameraFixer"="C:\WINDOWS\CameraFixer.exe" [2006-06-01 11:26]
"tsnpstd3"="C:\WINDOWS\tsnpstd3.exe" [2006-06-19 13:21]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"SchedulingAgent"=mstinit.exe /firstlogon


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{079a16ae-965c-11dc-b097-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{079a16af-965c-11dc-b097-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0bfe218d-a91b-11dc-b0eb-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26a18f7f-89bd-11dc-b06b-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3544abea-a6cf-11dc-b0e0-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{465f235e-875a-11dc-b068-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{465f235f-875a-11dc-b068-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f91215a-9fc0-11dc-b0c0-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5f91215b-9fc0-11dc-b0c0-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{73f757e4-8b3f-11dc-b070-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{750bf5a6-a49c-11dc-b0dc-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a69ff89a-8522-11dc-b063-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bdc59d68-84e1-11dc-b056-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da8a8806-84fe-11dc-b062-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dbe90894-926e-11dc-b080-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1e4d7e8-918b-11dc-b07d-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e1e4d7e9-918b-11dc-b07d-00012e19426d}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs

.
Contents of the 'Scheduled Tasks' folder
"2007-12-05 08:15:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-13 07:57:24
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-13 7:57:50
C:\ComboFix3.txt … 2007-10-30 09:19
C:\ComboFix2.txt … 2007-11-03 15:05
.
2007-12-12 12:57:31 — E O F —
Logfile of HijackThis v1.99.1
Scan saved at 4:52:49 PM, on 12/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\CameraFixer.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\OEMUser\LOCALS~1\Temp\Rar$EX00.172\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4E23F82E-96EA-4113-B15B-3F20B2722CA4}: NameServer = 208.110.16.14,208.110.16.13
O17 - HKLM\System\CS1\Services\Tcpip\..\{4E23F82E-96EA-4113-B15B-3F20B2722CA4}: NameServer = 208.110.16.14,208.110.16.13
O17 - HKLM\System\CS2\Services\Tcpip\..\{4E23F82E-96EA-4113-B15B-3F20B2722CA4}: NameServer = 208.110.16.14,208.110.16.13
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe