You betcha. I think it's a wonderful tool as it is the only thing I've found that fixed my computer!
Here's the ComboFix Log:
"Administrator" - 2007-05-15 6:41:52 Service Pack 2
ComboFix 07-05.13.V - Running from: "C:\Documents and Settings\Administrator\Desktop\"
(((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\dnjgvudr.dll
C:\WINDOWS\system32\exbpgpmg.dll
C:\WINDOWS\system32\htofxagl.dll
C:\WINDOWS\system32\lqgwjxjh.dll
C:\WINDOWS\system32\mkulsyod.dll
C:\WINDOWS\system32\opnklih.dll
C:\WINDOWS\system32\rbcoepxa.dll
C:\WINDOWS\system32\sxlelins.dll
C:\WINDOWS\system32\gmpgpbxe.ini
C:\WINDOWS\system32\hjxjwgql.ini
C:\WINDOWS\system32\axpeocbr.ini
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ADMINI~1\Desktop.\internet explorer.lnk
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-15 ))))))))))))))))))))))))))))))))))
2007-05-14 14:00 970,673 --ahs---- C:\WINDOWS\system32\rtstv.bak1
2007-05-14 13:12 958,324 --ahs---- C:\WINDOWS\system32\nqstv.ini2
2007-05-13 20:31 955,767 --ahs---- C:\WINDOWS\system32\nqstv.bak1
2007-05-13 19:53 <DIR> d-------- C:\Program Files\HJT
2007-05-13 17:35 <DIR> d-------- C:\Program Files\RegCure
2007-05-13 16:20 956,911 --ahs---- C:\WINDOWS\system32\jjkkj.ini2
2007-05-13 16:08 956,664 --ahs---- C:\WINDOWS\system32\jjkkj.bak1
2007-05-13 16:03 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\SUPERAntiSpyware.com
2007-05-13 15:45 <DIR> d-------- C:\Program Files\CCleaner
2007-05-13 11:30 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-05-13 11:30 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-05-13 11:30 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-05-07 07:16 90,112 --a------ C:\WINDOWS\system32\lfjbg13n.dll
2007-05-07 07:16 73,728 --a------ C:\WINDOWS\system32\lffax13n.dll
2007-05-07 07:16 453,120 --a------ C:\WINDOWS\system32\ltkrn13n.dll
2007-05-07 07:16 445,440 --a------ C:\WINDOWS\system32\ltimg13n.dll
2007-05-07 07:16 388,608 --a------ C:\WINDOWS\system32\lfcmp13n.dll
2007-05-07 07:16 265,216 --a------ C:\WINDOWS\system32\ltdis13n.dll
2007-05-07 07:16 246,272 --a------ C:\WINDOWS\system32\lfj2k13n.dll
2007-05-07 07:16 206,848 --a------ C:\WINDOWS\system32\ltefx13n.dll
2007-05-07 07:16 154,112 --a------ C:\WINDOWS\system32\ltfil13n.dll
2007-05-07 07:16 142,848 --a------ C:\WINDOWS\system32\lftif13n.dll
2007-05-07 07:16 1,693,696 --a------ C:\WINDOWS\system32\ltclr13n.dll
2007-05-06 15:37 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-05-05 22:01 2,882 --a------ C:\WINDOWS\system32\tmp.reg
2007-05-05 15:52 878,252 --ahs---- C:\WINDOWS\system32\pqstv.ini2
2007-05-05 15:45 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-05-05 15:45 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-05-05 15:44 876,768 --ahs---- C:\WINDOWS\system32\pqstv.bak1
2007-05-05 15:31 <DIR> d-------- C:\VundoFix Backups
2007-05-05 13:00 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-05-05 12:39 <DIR> d-------- C:\WINDOWS\CSC
2007-05-05 07:50 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-05-04 18:02 82,258 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-05-04 18:02 82,258 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-05-04 18:01 12,149,792 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-05-04 18:01 112,160 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-05-04 18:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-05-04 18:00 <DIR> d-------- C:\KAV
2007-05-04 16:47 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-05-04 16:46 <DIR> d-------- C:\DOCUME~1\ADMINI~1\.housecall6.6
2007-04-29 16:28 348,160 --a------ C:\WINDOWS\system32\eSellerateEngine.dll
2007-04-29 16:28 <DIR> d-------- C:\Program Files\Acoustica CD Label Maker
2007-04-29 16:28 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Acoustica
2007-04-29 16:28 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Acoustica
2007-04-20 20:38 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\ACD Systems
2007-04-20 20:37 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\ACD Systems
2007-04-20 20:36 <DIR> d-------- C:\Program Files\ACD Systems
2007-04-17 20:44 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-04-17 06:45 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Riverdeep Interactive Learning Limited
2007-04-17 06:33 970,752 --a------ C:\WINDOWS\system32\cdintf210.dll
2007-04-17 06:33 35,840 --a------ C:\WINDOWS\system32\drivers\AFS2K.SYS
2007-04-17 06:33 <DIR> d-------- C:\Program Files\Web Publish
2007-04-17 06:28 <DIR> d-------- C:\Program Files\Common Files\Broderbund
2007-04-17 06:28 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Broderbund Software
2007-04-15 21:24 <DIR> d-------- C:\WINDOWS\Downloaded Installations
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-05 15:18:38 -------- d-----w C:\Program Files\Lavasoft
2007-04-30 00:37:03 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\Roxio
2007-04-29 23:38:47 -------- d-----w C:\Program Files\Common Files\Roxio Shared
2007-04-17 12:26:51 -------- d-----w C:\Program Files\Common Files\InstallShield
2007-04-05 03:34:20 -------- d-----w C:\Program Files\Webshots
2007-03-31 21:49:58 -------- d-----w C:\Program Files\TAXWIZ 2006
2007-03-31 17:41:26 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-03-23 12:07:56 1,683,280 ----a-w C:\WINDOWS\system32\XpsSvcs.dll
2007-03-23 12:07:54 583,504 ----a-w C:\WINDOWS\system32\XPSSHHDR.dll
2007-03-23 02:25:02 124,928 ----a-w C:\WINDOWS\system32\prntvpt.dll
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-15 18:23:16 497,496 ----a-w C:\WINDOWS\system32\XceedZip.dll
2007-03-15 18:19:58 526,184 ----a-w C:\WINDOWS\system32\XceedCry.dll
2007-03-12 13:12:11 55,600 ----a-w C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
2007-03-11 19:30:20 -------- d-----w C:\Program Files\Quicken
2007-03-10 01:52:52 200,768 ----a-w C:\WINDOWS\system32\klogon.dll
2007-03-10 01:26:32 -------- d-----w C:\Program Files\MSN Messenger
2007-03-10 00:24:49 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-03-10 00:15:34 -------- d-----w C:\Program Files\MSBuild
2007-03-10 00:12:22 -------- d-----w C:\Program Files\Reference Assemblies
2007-03-09 01:46:46 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\Lavasoft
2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys
2007-03-07 23:34:41 -------- d-----w C:\Program Files\WinMX
2007-03-07 03:42:34 -------- d-----w C:\DOCUME~1\ADMINI~1\APPLIC~1\Google
2007-03-07 03:42:31 -------- d-----w C:\Program Files\Google
2007-02-05 20:17:02 185,344 ----a-w C:\WINDOWS\system32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll [2003-04-07 01:07]
{69AE0223-2CBE-4B6F-B905-C77C7734E0CB}=C:\WINDOWS\system32\pmnlmkh.dll []
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-07-07 12:29]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar1.dll [2007-03-06 21:42]
{AE7CD045-E861-484f-8273-0445EE161910}=C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [2003-04-07 01:21]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}=C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.3558\swg.dll [2007-03-30 11:25]
{B97000EE-E5FB-492D-93ED-D81B7DE74F32}=C:\WINDOWS\system32\vtstr.dll []
{EA2676C3-712F-4377-8A0C-6853017D2505}=C:\WINDOWS\system32\vtsqn.dll []
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"
"SoundMAX"="\"C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe\" /tray"
"PrinTray"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\printray.exe"
"Modem Booster"="C:\\Program Files\\inKline Global\\Modem Booster\\ModemBtr.exe"
"PC Pitstop Optimize Scheduler"="C:\\Program Files\\PCPitstop\\Optimize\\PCPOptimize.exe -boot"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_05\\bin\\jusched.exe"
"AVP"="\"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe\""
"RegistryMechanic"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 13:56]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 23:43]
"nwiz"="nwiz.exe" [2006-08-11 23:43 C:\WINDOWS\system32\nwiz.exe])
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-11 23:43]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 05:07]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-04-10 11:19]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2001-10-12 01:42]
"Modem Booster"="C:\Program Files\inKline Global\Modem Booster\ModemBtr.exe" [2005-10-10 18:58]
"PC Pitstop Optimize Scheduler"="C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe" [2007-01-04 15:51]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe" [2005-08-26 18:14]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2007-03-09 19:50]
"RegistryMechanic"="" [])
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:54]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-05-01 09:29]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-15 06:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"SUPERAntiSpyware"="C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{69AE0223-2CBE-4B6F-B905-C77C7734E0CB}"="C:\WINDOWS\system32\pmnlmkh.dll" []
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnlmkh
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtsqn
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtstr
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\
Security Packages kerberosmsv1_0schannelwdigest\
Notification Packages scecli\
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^administrator^start menu^programs^startup^webshots.lnk
C:\PROGRA~1\Webshots\Launcher.exe /t
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^acrobat assistant.lnk
C:\PROGRA~1\Adobe\ACROBA~1.0\Distillr\acrotray.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^adobe gamma loader.lnk
C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^corel registration.lnk
C:\PROGRA~1\Corel\WORDPE~1\Register\Remind32.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^corelcentral 9.lnk
C:\PROGRA~1\Corel\WORDPE~1\programs\ccwin9.exe /NoSplash
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^corelcentral alarms.lnk
C:\PROGRA~1\Corel\WORDPE~1\programs\alarm.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^desktop application director 9.lnk
C:\PROGRA~1\Corel\WORDPE~1\programs\dad9.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^google updater.lnk
C:\PROGRA~1\Google\GOOGLE~2\GOOGLE~1.EXE -systray -startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^microsoft office.lnk
C:\PROGRA~1\MICROS~2\Office10\OSA.EXE -b -l
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^winzip quick pick.lnk
C:\PROGRA~1\WinZip\WZQKPICK.EXE
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\incredimail
C:\Program Files\IncrediMail\bin\IncMail.exe /c
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lexmark x73 button manager
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lexmark x73 button monitor
C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msmsgs
"C:\Program Files\Messenger\msmsgs.exe" /background
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\roxioaudiocentral
"C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\roxiodragtodisc
"C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\roxioengineutility
"C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\userfaultcheck
%systemroot%\system32\dumprep 0 -u
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winflyer32.dll
"rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter HTTPFilter\
LocalService AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService DnsCache\
DcomLaunch DcomLaunchTermService\
rpcss RpcSs\
imgsvc StiSvc\
termsvcs TermService\
WudfServiceGroup WUDFSvc\
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost
~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
backup-20070514-125455-738
O20 - Winlogon Notify: vtsqn - C:\WINDOWS\system32\vtsqn.dll
backup-20070514-125455-287
O20 - Winlogon Notify: pmnlmkh - C:\WINDOWS\SYSTEM32\pmnlmkh.dll
backup-20070514-125455-475
O2 - BHO: (no name) - {E2EE5C44-C66D-499d-BEAE-A2A79189A63A} - C:\WINDOWS\system32\htofxagl.dll
backup-20070514-125455-464
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
backup-20070514-125455-650
O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "C:\WINDOWS\system32\pimuimdj.dll",realset
backup-20070514-125455-255
O2 - BHO: (no name) - {EA2676C3-712F-4377-8A0C-6853017D2505} - C:\WINDOWS\system32\vtsqn.dll
backup-20070514-125455-932
O2 - BHO: (no name) - {69AE0223-2CBE-4B6F-B905-C77C7734E0CB} - C:\WINDOWS\system32\pmnlmkh.dll
backup-20070513-171447-457
O20 - Winlogon Notify: pmnlmkh - C:\WINDOWS\SYSTEM32\pmnlmkh.dll
backup-20070513-171447-821
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
backup-20070513-171446-369
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
backup-20070513-171446-713
O2 - BHO: (no name) - {69AE0223-2CBE-4B6F-B905-C77C7734E0CB} - C:\WINDOWS\system32\pmnlmkh.dll
backup-20070513-171446-194
O2 - BHO: (no name) - {A95D91DD-C5D1-44AD-BE8B-4C379198C7D7} - C:\WINDOWS\system32\jkkjj.dll (file missing)
backup-20070513-171446-974
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
backup-20070513-120812-457
O20 - Winlogon Notify: pmnlmkh - C:\WINDOWS\SYSTEM32\pmnlmkh.dll
backup-20070513-120812-572
O2 - BHO: (no name) - {F54BF22D-ED85-492A-8554-E88B9A9A9BBE} - C:\WINDOWS\system32\geebc.dll (file missing)
backup-20070513-120812-568
O2 - BHO: (no name) - {E2EE5C44-C66D-499d-BEAE-A2A79189A63A} - C:\WINDOWS\system32\mkulsyod.dll
backup-20070513-120812-799
O2 - BHO: (no name) - {69AE0223-2CBE-4B6F-B905-C77C7734E0CB} - C:\WINDOWS\system32\pmnlmkh.dll
backup-20070513-120812-957
O2 - BHO: (no name) - {272FD83A-CF4E-4D41-8341-41720ED290E2} - C:\WINDOWS\system32\ddcca.dll (file missing)
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\RegCure Program Check.job
C:\WINDOWS\tasks\RegCure.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-05-15 06:43:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 2007-05-15 6:43:56
C:\ComboFix-quarantined-files.txt ... 2007-05-15 06:43
QUOTE(LS CalamityJane @ May 15 2007, 02:25 PM)

That's good to hear, only I didn't write tool but I'll be sure to pass that along to the ComboFix author (username: sUBs). He calls it is "really lousy tool" but we think it's terrific.
There is still more to do and there may be additional files needed to delete so I really need to see the ComboFix log it made too, please. It should be located on your hard-drive and is named
ComboFix.txtPlease copy that back here because I need to review to add to the other things I see that still need to be fixed (even if we DID get all the active infection, I want to make sure we got all we can see and Combofix.txt will show me a wider list of things than is on the Hijackthis log)
