Hi
Open notepad and copy/paste the text in the quotebox below into it:
File::
c:\windows\system32\atxhqi.dll
Driver::
vfvbzbgea
NetSvc::
vfvbzbgea
RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):96,38,50,50,14,32,a6,68,d1,8d,99,7a,0c,35,7d,33,28,e1,51,8e,4e,
98,da,66,d8,63,d3,0d,68,a6,1e,9c,f7,65,7f,19,15,30,70,77,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):0d,48,83,b3,8b,c0,16,fc,60,7b,f7,78,9d,a6,52,21,d9,60,64,a5,29,
0f,c5,5a,13,4a,9d,c9,ae,e8,ad,8f,0d,7f,17,0a,7c,fd,3d,34,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{84083ee5-06a5-4e33-8792-98c42bb540a5}]
@Denied: (Full) (Everyone)
"Model"=dword:0000011a
"Therad"=dword:00000011
"MData"=hex(0):85,8b,fd,20,ce,cb,a4,e4,66,14,4f,d9,ef,fd,e4,b9,1c,82,b7,6c,7c,
68,29,18,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{caf1a451-4081-46f7-bf79-cd9985113c19}]
@Denied: (Full) (Everyone)
"Model"=dword:000000f1
"Therad"=dword:00000020
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,ab,9e,50,1b,eb,77,d1,ab,ce,4a,c2,09,3e,66,22,82,83,e0,8b,c5,07,bb,\
Save this as CFScript to desktop
http://img213.imageshack.us/img213/1218/cfscript1.gif
Close all browser windows and refering to the picture above, drag CFScript into Combofix.exe
Then post the resultant log