This is the report from the combo fix below. Will do the hijack this again now. and post in a bit.
"Mahmoud" - 2007-05-29 20:20:18 Service Pack 2 [SAFE MODE]
ComboFix 07-05.27.V - Running from: "C:\Documents and Settings\Mahmoud\Desktop\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
"C:\WINDOWS\avp.exe"
"C:\WINDOWS\smanager.7.exe"
"C:\WINDOWS\system32\klikalka.exe"
"C:\WINDOWS\system32\drivers\sfsync02.sys"
((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_SFSYNC02
-------\sfsync02
((((((((((((((((((((((((((((((( Files Created from 2007-04-28 to 2007-05-29 ))))))))))))))))))))))))))))))))))
2007-05-29 20:22 0 --a------ C:\WINDOWS\system32\sfsync02.dll
2007-05-29 20:13 28,160 --a------ C:\WINDOWS\system32\driver.exe
2007-05-28 14:59 <DIR> d-------- C:\WINDOWS\Prefetch
2007-05-28 14:53 95,424 --------- C:\WINDOWS\system32\drivers\slnthal.sys
2007-05-28 14:53 870,784 --------- C:\WINDOWS\system32\ati3d1ag.dll
2007-05-28 14:53 78,464 --------- C:\WINDOWS\system32\drivers\usbvideo.sys
2007-05-28 14:53 73,832 --------- C:\WINDOWS\system32\slcoinst.dll
2007-05-28 14:53 73,796 --------- C:\WINDOWS\system32\slserv.exe
2007-05-28 14:53 73,216 --------- C:\WINDOWS\system32\drivers\atintuxx.sys
2007-05-28 14:53 701,440 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-05-28 14:53 685,056 --------- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2007-05-28 14:53 63,663 --------- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2007-05-28 14:53 63,488 --------- C:\WINDOWS\system32\drivers\atinxsxx.sys
2007-05-28 14:53 6,016 --------- C:\WINDOWS\system32\drivers\smbali.sys
2007-05-28 14:53 59,648 --------- C:\WINDOWS\system32\drivers\rfcomm.sys
2007-05-28 14:53 57,856 --------- C:\WINDOWS\system32\drivers\atinbtxx.sys
2007-05-28 14:53 56,623 --------- C:\WINDOWS\system32\drivers\ati1btxx.sys
2007-05-28 14:53 52,224 --------- C:\WINDOWS\system32\drivers\atinraxx.sys
2007-05-28 14:53 516,768 --------- C:\WINDOWS\system32\ativvaxx.dll
2007-05-28 14:53 46,464 --------- C:\WINDOWS\system32\drivers\gagp30kx.sys
2007-05-28 14:53 452,736 --------- C:\WINDOWS\system32\drivers\mtxparhm.sys
2007-05-28 14:53 44,672 --------- C:\WINDOWS\system32\drivers\uagp35.sys
2007-05-28 14:53 404,990 --------- C:\WINDOWS\system32\drivers\slntamr.sys
2007-05-28 14:53 4,255 --------- C:\WINDOWS\system32\drivers\adv01nt5.dll
2007-05-28 14:53 397,056 --------- C:\WINDOWS\system32\s3gnb.dll
2007-05-28 14:53 38,016 --------- C:\WINDOWS\system32\drivers\bthmodem.sys
2007-05-28 14:53 377,984 --------- C:\WINDOWS\system32\ati2dvaa.dll
2007-05-28 14:53 36,463 --------- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2007-05-28 14:53 35,456 --------- C:\WINDOWS\system32\drivers\bthprint.sys
2007-05-28 14:53 34,735 --------- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2007-05-28 14:53 327,040 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2007-05-28 14:53 32,866 --------- C:\WINDOWS\system32\slrundll.exe
2007-05-28 14:53 32,866 --------- C:\WINDOWS\slrundll.exe
2007-05-28 14:53 32,768 --------- C:\WINDOWS\system32\ativtmxx.dll
2007-05-28 14:53 32,285 --------- C:\WINDOWS\system32\hsfcisp2.dll
2007-05-28 14:53 31,744 --------- C:\WINDOWS\system32\drivers\atinxbxx.sys
2007-05-28 14:53 30,671 --------- C:\WINDOWS\system32\drivers\ati1raxx.sys
2007-05-28 14:53 30,080 --------- C:\WINDOWS\system32\drivers\rndismpx.sys
2007-05-28 14:53 3,967 --------- C:\WINDOWS\system32\drivers\adv02nt5.dll
2007-05-28 14:53 3,901 --------- C:\WINDOWS\system32\drivers\siint5.dll
2007-05-28 14:53 3,775 --------- C:\WINDOWS\system32\drivers\adv11nt5.dll
2007-05-28 14:53 3,711 --------- C:\WINDOWS\system32\drivers\adv09nt5.dll
2007-05-28 14:53 3,647 --------- C:\WINDOWS\system32\drivers\adv07nt5.dll
2007-05-28 14:53 3,615 --------- C:\WINDOWS\system32\drivers\adv05nt5.dll
2007-05-28 14:53 3,135 --------- C:\WINDOWS\system32\drivers\adv08nt5.dll
2007-05-28 14:53 29,455 --------- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2007-05-28 14:53 286,792 --------- C:\WINDOWS\system32\slextspk.dll
2007-05-28 14:53 28,672 --------- C:\WINDOWS\system32\drivers\atinsnxx.sys
2007-05-28 14:53 274,304 --------- C:\WINDOWS\system32\drivers\bthport.sys
2007-05-28 14:53 26,367 --------- C:\WINDOWS\system32\drivers\ati1snxx.sys
2007-05-28 14:53 25,600 --------- C:\WINDOWS\system32\drivers\hidbth.sys
2007-05-28 14:53 25,471 --------- C:\WINDOWS\system32\drivers\watv10nt.sys
2007-05-28 14:53 25,471 --------- C:\WINDOWS\system32\drivers\atv04nt5.dll
2007-05-28 14:53 229,376 --------- C:\WINDOWS\system32\ati2cqag.dll
2007-05-28 14:53 220,032 --------- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2007-05-28 14:53 22,271 --------- C:\WINDOWS\system32\drivers\watv06nt.sys
2007-05-28 14:53 21,343 --------- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2007-05-28 14:53 21,183 --------- C:\WINDOWS\system32\drivers\atv01nt5.dll
2007-05-28 14:53 201,728 --------- C:\WINDOWS\system32\ati2dvag.dll
2007-05-28 14:53 188,508 --------- C:\WINDOWS\system32\slgen.dll
2007-05-28 14:53 180,360 --------- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2007-05-28 14:53 18,944 --------- C:\WINDOWS\system32\drivers\bthusb.sys
2007-05-28 14:53 17,279 --------- C:\WINDOWS\system32\drivers\atv10nt5.dll
2007-05-28 14:53 17,024 --------- C:\WINDOWS\system32\drivers\bthenum.sys
2007-05-28 14:53 166,912 --------- C:\WINDOWS\system32\drivers\s3gnbm.sys
2007-05-28 14:53 15,423 --------- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
2007-05-28 14:53 15,104 --------- C:\WINDOWS\system32\drivers\hidir.sys
2007-05-28 14:53 14,336 --------- C:\WINDOWS\system32\drivers\atinpdxx.sys
2007-05-28 14:53 14,143 --------- C:\WINDOWS\system32\drivers\atv06nt5.dll
2007-05-28 14:53 13,824 --------- C:\WINDOWS\system32\drivers\atinttxx.sys
2007-05-28 14:53 13,824 --------- C:\WINDOWS\system32\drivers\atinmdxx.sys
2007-05-28 14:53 13,776 --------- C:\WINDOWS\system32\drivers\recagent.sys
2007-05-28 14:53 13,568 --------- C:\WINDOWS\system32\drivers\wacompen.sys
2007-05-28 14:53 13,240 --------- C:\WINDOWS\system32\drivers\slwdmsup.sys
2007-05-28 14:53 129,535 --------- C:\WINDOWS\system32\drivers\slnt7554.sys
2007-05-28 14:53 126,686 --------- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2007-05-28 14:53 12,672 --------- C:\WINDOWS\system32\drivers\usb8023x.sys
2007-05-28 14:53 12,672 --------- C:\WINDOWS\system32\drivers\mutohpen.sys
2007-05-28 14:53 12,047 --------- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2007-05-28 14:53 11,935 --------- C:\WINDOWS\system32\drivers\wadv11nt.sys
2007-05-28 14:53 11,871 --------- C:\WINDOWS\system32\drivers\wadv09nt.sys
2007-05-28 14:53 11,807 --------- C:\WINDOWS\system32\drivers\wadv07nt.sys
2007-05-28 14:53 11,615 --------- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2007-05-28 14:53 11,359 --------- C:\WINDOWS\system32\drivers\atv02nt5.dll
2007-05-28 14:53 11,325 --------- C:\WINDOWS\system32\drivers\vchnt5.dll
2007-05-28 14:53 11,295 --------- C:\WINDOWS\system32\drivers\wadv08nt.sys
2007-05-28 14:53 104,960 --------- C:\WINDOWS\system32\drivers\atinrvxx.sys
2007-05-28 14:53 100,992 --------- C:\WINDOWS\system32\drivers\bthpan.sys
2007-05-28 14:53 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2007-05-28 14:53 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2007-05-28 14:53 1,309,184 --------- C:\WINDOWS\system32\drivers\mtlstrm.sys
2007-05-28 14:53 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2007-05-28 14:48 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2007-05-28 14:46 <DIR> d-------- C:\WINDOWS\EHome
2007-05-28 13:32 <DIR> d-------- C:\Program Files\Macrovision
2007-05-28 13:30 <DIR> d-------- C:\DOCUME~1\Mahmoud\APPLIC~1\InstallShield
2007-05-28 09:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-05-27 22:58 <DIR> d-------- C:\DOCUME~1\Mahmoud\APPLIC~1\TrojanHunter
2007-05-27 22:51 <DIR> d-------- C:\Program Files\TrojanHunter 4.6
2007-05-27 22:05 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-05-27 22:05 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\APPLIC~1\Gtek
2007-05-27 22:05 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver
2007-05-27 22:05 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Corel
2007-05-27 22:05 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\AOL
2007-05-27 20:58 <DIR> d-------- C:\Documents and Settings\Mahmoud\.housecall6.6
2007-05-27 20:58 <DIR> d-------- C:\DOCUME~1\Mahmoud\.housecall6.6
2007-05-13 14:02 <DIR> d-------- C:\Program Files\SopCast
2007-05-13 14:02 <DIR> d-------- C:\DOCUME~1\Mahmoud\APPLIC~1\SopCast
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-28 12:31:55 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-05-28 12:09:30 -------- d-----w C:\Program Files\McAfee
2007-05-27 20:33:16 -------- d-----w C:\Program Files\Dl_cats
2007-05-27 20:07:19 -------- d-----w C:\Program Files\Google
2007-05-26 19:02:19 -------- d-----w C:\Program Files\Egyptian Arabic Vocab Clinic 2.0
2007-05-26 16:47:13 -------- d-----w C:\DOCUME~1\Mahmoud\APPLIC~1\SiteAdvisor
2007-05-21 14:59:53 -------- d-----w C:\Program Files\Digital Line Detect
2007-05-21 14:56:24 -------- d-----w C:\Program Files\Bricks Of Egypt 2
2007-05-21 14:56:08 -------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-04-13 21:43:33 -------- d-----w C:\Program Files\Star Defender 2
2007-04-13 20:06:17 -------- d-----w C:\Program Files\SiteAdvisor
2007-04-10 18:10:23 -------- d-----w C:\Program Files\LimeWire
2007-04-09 21:58:18 6,112 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-04-09 21:58:03 104 --sh--r C:\WINDOWS\system32\25971BB0AD.sys
2007-04-05 19:02:26 -------- d-----w C:\DOCUME~1\Mahmoud\APPLIC~1\Alive Games
2007-03-31 18:19:04 -------- d-----w C:\Program Files\McAfee.com
2007-03-31 17:01:04 -------- d-----w C:\Program Files\Common Files\McAfee
2007-03-28 22:20:17 2,368 ----a-w C:\WINDOWS\system32\STEC3.sys
2007-03-26 18:33:52 160,411 ----a-w C:\WINDOWS\English4Today studyGuide 1 Uninstaller.exe
2007-03-25 12:36:17 675,579 ----a-w C:\WINDOWS\PROGRAM.exe
2007-03-25 12:35:25 363,980 ----a-w C:\WINDOWS\1-fe5e180d56ed9c233080898276c260cc.exe
2007-03-19 21:55:55 246,992 ----a-w C:\Program Files\VkeyInst.EXE
2007-03-05 23:01:50 94,208 ----a-w C:\WINDOWS\system32\ScrUnZip.dll
2007-03-05 22:56:55 352,256 ----a-w C:\WINDOWS\system32\IJL15.dll
2007-03-05 22:50:24 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-03-03 17:20:23 18,895,728 ----a-w C:\Program Files\Install_Messenger.exe
2007-03-02 20:12:01 159,740 ----a-w C:\WINDOWS\Google Pack Screensaver Uninstaller.exe
2007-03-02 20:10:48 782,504 ----a-w C:\Program Files\Google Updater.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{089FD14D-132B-48FC-8861-0048AE113215}=C:\Program Files\SiteAdvisor\6066\SiteAdv.dll [2007-03-30 16:41]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
{5CA3D70E-1895-11CF-8E15-001234567890}=C:\WINDOWS\System32\DLA\DLASHX_W.DLL [2005-09-08 05:20]
{7DB2D5A0-7241-4E79-B68D-6309F01C5231}=c:\program files\mcafee\virusscan\scriptcl.dll [2006-12-22 16:02]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 03:12]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-04-08 12:27]
"dlcgmon.exe"="C:\Program Files\Dell AIO 810\dlcgmon.exe" [2005-10-21 02:42]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-03-02 21:13]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-03-02 22:26]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-10-31 02:03]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2006-11-15 22:58]
"Athan"="C:\Program Files\Athan\Athan.exe" [2007-01-11 08:45]
"MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 17:30]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6066\SiteAdv.exe" [2007-02-09 05:37]
"LVCOMSX"="C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-11-15 23:01]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 04:56]
"THGuard"="C:\Program Files\TrojanHunter 4.6\THGuard.exe" [2007-05-11 20:01]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 04:56]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2004-07-19 07:51]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" []
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 04:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
AutoRun\command- D:\autorun\autorun.exe
Contents of the 'Scheduled Tasks' folder
2007-05-25 17:30:01 C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (DFWJJ62J-Rosemary).job
2007-03-31 16:58:57 C:\WINDOWS\tasks\McDefragTask.job
2007-03-31 16:58:55 C:\WINDOWS\tasks\McQcTask.job
********************************************************************
catchme 0.3.681 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-05-29 20:24:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
Completion time: 2007-05-29 20:26:27 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-29 20:26
--- E O F ---