My desktop and start menu has returned. HJT still does not respond, saying that I do not have the appropriate permissions to access it. Here is the Combofix log.
ComboFix 09-09-16.05 - HP_Owner 09/17/2009 12:17.4.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.228 [GMT -7:00]
Running from: c:\documents and settings\HP_Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HP_Owner\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
c:\documents and settings\HP_Owner\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
c:\documents and settings\HP_Owner\Application Data\Microsoft\Installer\{F99C5427-4D78-43E2-B97E-F4C4E622D612}\NewShortcut1_F99C54274D7843E2B97EF4C4E622D612.exe
c:\documents and settings\HP_Owner\Application Data\Microsoft\Installer\{F99C5427-4D78-43E2-B97E-F4C4E622D612}\NewShortcut11_F99C54274D7843E2B97EF4C4E622D612.exe
c:\recycler\S-1-5-21-2787584264-3490589648-1648143588-1003
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\Installer\871a5.msi
c:\windows\msa.exe
c:\windows\system32\abfpfmnh.ini
c:\windows\system32\ackpjytm.ini
c:\windows\system32\aiacixvk.ini
c:\windows\system32\arautfhe.ini
c:\windows\system32\aruergls.ini
c:\windows\system32\aupvtpjc.ini
c:\windows\system32\auujkumc.ini
c:\windows\system32\bfvgfntr.ini
c:\windows\system32\bkedbbmm.ini
c:\windows\system32\bsgbjwyh.ini
c:\windows\system32\bwlenwjl.ini
c:\windows\system32\bwvadxmd.ini
c:\windows\system32\cdanppvu.ini
c:\windows\system32\cgakuqcj.ini
c:\windows\system32\cjifhsob.ini
c:\windows\system32\cpsprfdp.ini
c:\windows\system32\cuyokdpr.ini
c:\windows\system32\danhfnuo.ini
c:\windows\system32\dbhgxmrw.ini
c:\windows\system32\dhfykltw.ini
c:\windows\system32\douuyvxq.ini
c:\windows\system32\drpetyst.ini
c:\windows\system32\dtecjqnn.ini
c:\windows\system32\dumphive.exe
c:\windows\system32\eamqbcgm.ini
c:\windows\system32\eowenwdq.ini
c:\windows\system32\ewgtilpl.ini
c:\windows\system32\ewpiudqo.ini
c:\windows\system32\fcrtphjm.ini
c:\windows\system32\fofalvif.ini
c:\windows\system32\fqyykeel.ini
c:\windows\system32\fsmsfefi.ini
c:\windows\system32\fwbaapou.ini
c:\windows\system32\gbimxbbq.ini
c:\windows\system32\gbtnbelv.ini
c:\windows\system32\glijsgcm.ini
c:\windows\system32\gmrgmmak.ini
c:\windows\system32\gmvleeku.ini
c:\windows\system32\gpmrecyc.ini
c:\windows\system32\guyttmpm.ini
c:\windows\system32\hlsddqyy.ini
c:\windows\system32\husplwkf.ini
c:\windows\system32\hvgueybb.ini
c:\windows\system32\ignnoueg.ini
c:\windows\system32\ikhbvrph.ini
c:\windows\system32\ilhaevcf.ini
c:\windows\system32\isohfpcf.ini
c:\windows\system32\issakdir.ini
c:\windows\system32\ityvenxk.ini
c:\windows\system32\iuqcqhrt.ini
c:\windows\system32\jfjabvth.ini
c:\windows\system32\jnyjfgvr.ini
c:\windows\system32\jqtlaise.ini
c:\windows\system32\jtjrrnjy.ini
c:\windows\system32\jtlplshg.ini
c:\windows\system32\jtximqfs.ini
c:\windows\system32\jyqavohj.ini
c:\windows\system32\kbogjtyn.ini
c:\windows\system32\ksgvchok.ini
c:\windows\system32\ktiystsl.ini
c:\windows\system32\kupuaiuw.ini
c:\windows\system32\labkhpvy.ini
c:\windows\system32\lsjwvxjq.ini
c:\windows\system32\marvemyd.ini
c:\windows\system32\mlrvgdvu.ini
c:\windows\system32\mvyxosbt.ini
c:\windows\system32\mweeeiun.ini
c:\windows\system32\mxibxkgt.ini
c:\windows\system32\nasmjcet.ini
c:\windows\system32\ndfffmed.ini
c:\windows\system32\nfdgblau.ini
c:\windows\system32\ngfyqqym.ini
c:\windows\system32\nykwdpqc.ini
c:\windows\system32\nyowspfv.ini
c:\windows\system32\ojrdksay.ini
c:\windows\system32\ooapnxlx.ini
c:\windows\system32\ophllxlq.ini
c:\windows\system32\oxllfplu.ini
c:\windows\system32\pbywnsfj.ini
c:\windows\system32\phtyxnyw.ini
c:\windows\system32\pjvalekw.ini
c:\windows\system32\Process.exe
c:\windows\system32\ps2.bat
c:\windows\system32\qddorkrg.ini
c:\windows\system32\qfigmxvv.ini
c:\windows\system32\qhomxifg.ini
c:\windows\system32\qhyiwogd.ini
c:\windows\system32\qndrpfln.ini
c:\windows\system32\qpjyfpts.ini
c:\windows\system32\qvbhkxca.ini
c:\windows\system32\qvdfxfvn.ini
c:\windows\system32\rlgvlgcp.ini
c:\windows\system32\rxhqxpfs.ini
c:\windows\system32\shegdjpm.ini
c:\windows\system32\sioyoiqi.ini
c:\windows\system32\slugqmkh.ini
c:\windows\system32\sprgxdrq.ini
c:\windows\system32\SrchSTS.exe
c:\windows\system32\ssrkmegj.ini
c:\windows\system32\teymdrtp.ini
c:\windows\system32\tjptenuh.ini
c:\windows\system32\tmp.reg
c:\windows\system32\txhaftjr.ini
c:\windows\system32\ubcsbiww.ini
c:\windows\system32\ucvmbfus.ini
c:\windows\system32\ujvirgnb.ini
c:\windows\system32\urdshupt.ini
c:\windows\system32\urhbdffe.ini
c:\windows\system32\urppxvku.ini
c:\windows\system32\utmlwsci.ini
c:\windows\system32\uyjkhgva.ini
c:\windows\system32\VCCLSID.exe
c:\windows\system32\vivkvswt.ini
c:\windows\system32\vjultoka.ini
c:\windows\system32\vpskadol.ini
c:\windows\system32\vudaoodq.ini
c:\windows\system32\wbcplxie.ini
c:\windows\system32\widsuxaq.ini
c:\windows\system32\wifoayjo.ini
c:\windows\system32\wmjsgluk.ini
c:\windows\system32\WS2Fix.exe
c:\windows\system32\wuurkmxx.ini
c:\windows\system32\wyfuenaf.ini
c:\windows\system32\xbmwfmiy.ini
c:\windows\system32\xuxyjjrf.ini
c:\windows\system32\xxqlkmkp.ini
c:\windows\system32\yairfegs.ini
c:\windows\system32\yeglmysr.ini
c:\windows\system32\yjjfjndl.ini
c:\windows\system32\yonobgtr.ini
c:\windows\system32\ywiuelpw.ini
c:\windows\system32\ywwoutge.ini
c:\windows\viassary-hp.reg
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\eventlog.dll
-- Previous Run --
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\eventlog.dll
--------
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
((((((((((((((((((((((((( Files Created from 2009-08-17 to 2009-09-17 )))))))))))))))))))))))))))))))
.
2009-09-14 06:55 . 2009-09-14 06:56 -------- d-----w- c:\program files\ERUNT
2009-09-13 23:11 . 2008-04-14 00:12 116224 -c--a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2009-09-13 23:11 . 2001-08-18 05:36 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2009-09-13 23:11 . 2008-04-14 00:12 18944 -c--a-w- c:\windows\system32\dllcache\xrxscnui.dll
2009-09-13 23:11 . 2001-08-18 05:37 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe
2009-09-13 23:11 . 2001-08-18 05:37 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe
2009-09-13 23:11 . 2001-08-18 05:37 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe
2009-09-13 23:11 . 2001-08-17 19:11 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys
2009-09-13 23:11 . 2004-08-04 05:29 19455 -c--a-w- c:\windows\system32\dllcache\wvchntxx.sys
2009-09-13 23:11 . 2004-08-04 05:29 12063 -c--a-w- c:\windows\system32\dllcache\wsiintxx.sys
2009-09-13 23:11 . 2008-04-14 00:12 8192 -c--a-w- c:\windows\system32\dllcache\wshirda.dll
2009-09-13 23:10 . 2008-04-13 18:36 8832 -c--a-w- c:\windows\system32\dllcache\wmiacpi.sys
2009-09-13 23:10 . 2004-08-04 05:31 154624 -c--a-w- c:\windows\system32\dllcache\wlluc48.sys
2009-09-13 23:10 . 2001-08-17 19:12 34890 -c--a-w- c:\windows\system32\dllcache\wlandrv2.sys
2009-09-13 23:10 . 2001-08-17 20:28 771581 -c--a-w- c:\windows\system32\dllcache\winacisa.sys
2009-09-13 23:10 . 2001-08-18 05:36 53760 -c--a-w- c:\windows\system32\dllcache\wiamsmud.dll
2009-09-13 23:08 . 2001-08-17 20:28 687999 -c--a-w- c:\windows\system32\dllcache\usrwdxjs.sys
2009-09-13 23:07 . 2001-08-17 20:58 22912 -c--a-w- c:\windows\system32\dllcache\umaxpcls.sys
2009-09-13 23:06 . 2008-04-14 00:12 82944 -c--a-w- c:\windows\system32\dllcache\tp4mon.exe
2009-09-13 23:05 . 2001-08-17 21:56 172768 -c--a-w- c:\windows\system32\dllcache\t2r4disp.dll
2009-09-13 23:04 . 2001-08-17 20:51 16896 -c--a-w- c:\windows\system32\dllcache\stcusb.sys
2009-09-13 23:03 . 2001-08-17 21:56 147200 -c--a-w- c:\windows\system32\dllcache\smidispb.dll
2009-09-13 23:02 . 2001-08-17 19:50 68608 -c--a-w- c:\windows\system32\dllcache\sis6306p.sys
2009-09-13 23:01 . 2001-08-17 20:51 23936 -c--a-w- c:\windows\system32\dllcache\sccmn50m.sys
2009-09-13 23:00 . 2001-08-17 19:12 19017 -c--a-w- c:\windows\system32\dllcache\rtl8029.sys
2009-09-13 23:00 . 2001-08-17 19:19 30720 -c--a-w- c:\windows\system32\dllcache\rthwcls.sys
2009-09-13 23:00 . 2001-08-18 05:36 9216 -c--a-w- c:\windows\system32\dllcache\rsmgrstr.dll
2009-09-13 23:00 . 2001-08-17 19:19 3840 -c--a-w- c:\windows\system32\dllcache\rpfun.sys
2009-09-13 23:00 . 2008-04-13 18:40 79104 -c--a-w- c:\windows\system32\dllcache\rocket.sys
2009-09-13 23:00 . 2001-08-17 19:12 37563 -c--a-w- c:\windows\system32\dllcache\rlnet5.sys
2009-09-13 23:00 . 2001-08-18 05:36 86097 -c--a-w- c:\windows\system32\dllcache\reslog32.dll
2009-09-13 23:00 . 2001-08-17 20:51 19584 -c--a-w- c:\windows\system32\dllcache\rasirda.sys
2009-09-13 23:00 . 2001-08-17 20:28 714762 -c--a-w- c:\windows\system32\dllcache\r2mdmkxx.sys
2009-09-13 23:00 . 2001-08-17 20:28 899146 -c--a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2009-09-13 23:00 . 2001-08-18 05:36 41472 -c--a-w- c:\windows\system32\dllcache\qvusd.dll
2009-09-13 23:00 . 2001-08-17 20:53 3328 -c--a-w- c:\windows\system32\dllcache\qv2kux.sys
2009-09-13 23:00 . 2001-08-17 20:52 49024 -c--a-w- c:\windows\system32\dllcache\ql1280.sys
2009-09-13 22:58 . 2001-08-17 21:04 173696 -c--a-w- c:\windows\system32\dllcache\philcam2.sys
2009-09-13 22:57 . 2001-08-18 05:36 20480 -c--a-w- c:\windows\system32\dllcache\ovcomc.dll
2009-09-13 22:56 . 2001-08-17 20:47 9344 -c--a-w- c:\windows\system32\dllcache\ntapm.sys
2009-09-13 22:55 . 2001-08-17 19:11 52255 -c--a-w- c:\windows\system32\dllcache\n1000nt5.sys
2009-09-13 22:54 . 2001-08-17 20:52 17280 -c--a-w- c:\windows\system32\dllcache\mraid35x.sys
2009-09-13 22:53 . 2001-08-17 20:28 797500 -c--a-w- c:\windows\system32\dllcache\ltsmt.sys
2009-09-13 22:52 . 2001-08-17 20:49 26624 -c--a-w- c:\windows\system32\dllcache\irstusb.sys
2009-09-13 22:52 . 2001-08-17 20:51 18688 -c--a-w- c:\windows\system32\dllcache\irsir.sys
2009-09-13 22:52 . 2008-04-14 00:11 28160 -c--a-w- c:\windows\system32\dllcache\irmon.dll
2009-09-13 22:52 . 2008-04-14 00:12 151552 -c--a-w- c:\windows\system32\dllcache\irftp.exe
2009-09-13 22:52 . 2001-08-17 20:49 23552 -c--a-w- c:\windows\system32\dllcache\irmk7.sys
2009-09-13 22:52 . 2008-04-13 18:54 88192 -c--a-w- c:\windows\system32\dllcache\irda.sys
2009-09-13 22:52 . 2001-08-17 19:12 45632 -c--a-w- c:\windows\system32\dllcache\ip5515.sys
2009-09-13 22:52 . 2001-08-18 05:36 90200 -c--a-w- c:\windows\system32\dllcache\io8ports.dll
2009-09-13 22:52 . 2001-08-17 20:50 38784 -c--a-w- c:\windows\system32\dllcache\io8.sys
2009-09-13 22:52 . 2001-08-17 20:47 13056 -c--a-w- c:\windows\system32\dllcache\inport.sys
2009-09-13 22:52 . 2001-08-17 20:52 16000 -c--a-w- c:\windows\system32\dllcache\ini910u.sys
2009-09-13 22:50 . 2001-08-17 20:28 50751 -c--a-w- c:\windows\system32\dllcache\hsf_tone.sys
2009-09-13 22:49 . 2001-08-18 05:36 48128 -c--a-w- c:\windows\system32\dllcache\hpgt33tk.dll
2009-09-13 22:48 . 2001-08-17 19:14 441728 -c--a-w- c:\windows\system32\dllcache\fpcmbase.sys
2009-09-13 22:47 . 2001-08-17 19:19 40704 -c--a-w- c:\windows\system32\dllcache\es1371mp.sys
2009-09-13 22:46 . 2001-08-17 19:20 334208 -c--a-w- c:\windows\system32\dllcache\ds1wdm.sys
2009-09-13 22:45 . 2001-08-18 05:36 419357 -c--a-w- c:\windows\system32\dllcache\dgconfig.dll
2009-09-13 22:44 . 2001-08-18 05:36 175104 -c--a-w- c:\windows\system32\dllcache\csamsp.dll
2009-09-13 22:43 . 2001-08-18 05:36 74240 -c--a-w- c:\windows\system32\dllcache\camexo20.dll
2009-09-13 22:42 . 2001-08-18 05:36 102400 -c--a-w- c:\windows\system32\dllcache\binlsvc.dll
2009-09-13 22:41 . 2001-08-17 20:51 5248 -c--a-w- c:\windows\system32\dllcache\aliide.sys
2009-09-13 22:40 . 2001-08-17 21:56 66048 -c--a-w- c:\windows\system32\dllcache\s3legacy.dll
2009-09-13 22:23 . 2009-09-13 22:23 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-08-18 22:50 . 2009-08-18 22:50 -------- d-----w- c:\program files\Apple Software Update
2009-08-18 22:48 . 2009-08-18 22:48 -------- d-----w- c:\program files\iPod
2009-08-18 22:47 . 2009-08-18 22:48 -------- d-----w- c:\program files\iTunes
2009-08-18 22:47 . 2009-08-18 22:48 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-18 22:46 . 2009-08-18 22:46 -------- d-----w- c:\program files\Bonjour
2009-08-18 22:45 . 2009-08-18 22:46 -------- d-----w- c:\program files\QuickTime
2009-08-18 22:43 . 2009-08-18 22:48 -------- d-----w- c:\program files\Common Files\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-16 23:11 . 2008-07-27 19:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-09-06 03:32 . 2008-08-27 15:30 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\HPAppData
2009-09-02 18:39 . 2006-07-02 05:24 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-28 15:14 . 2009-03-23 23:05 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-28 15:14 . 2009-03-23 23:04 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-28 15:14 . 2007-03-01 17:17 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-18 14:35 . 2008-04-06 21:06 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-18 14:14 . 2008-04-06 21:06 -------- d-----w- c:\program files\SpywareBlaster
2009-08-14 04:45 . 2009-08-14 04:45 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\IObit
2009-08-14 04:45 . 2009-08-14 04:45 -------- d-----w- c:\program files\IObit
2009-08-14 03:59 . 2009-08-14 03:59 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\ImgBurn
2009-08-14 03:27 . 2009-08-14 03:26 -------- d-----w- c:\program files\ImgBurn
2009-08-14 03:00 . 2006-08-22 00:25 -------- d-----w- c:\program files\Azureus
2009-08-14 02:59 . 2006-08-22 00:25 -------- d-----w- c:\documents and settings\HP_Owner\Application Data\Azureus
2009-08-11 22:25 . 2004-08-07 19:36 -------- d-----w- c:\program files\Java
2009-07-25 12:23 . 2009-05-03 15:10 411368 ----a-w- c:\windows\system32\deploytk.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-08 49152]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-08 659456]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2005-03-08 53248]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2005-03-04 88209]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]
c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 15:14 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Photags AutoDetect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Photags AutoDetect.lnk
backup=c:\windows\pss\Photags AutoDetect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates from HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates from HP.lnk
backup=c:\windows\pss\Updates from HP.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Owner^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\HP_Owner\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Roxio\\Media Manager 9\\MediaManager9.exe"=
"c:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Documents and Settings\\HP_Owner\\My Documents\\Ryan Homework\\World of Warcraft\\Launcher.exe"=
"c:\\Documents and Settings\\HP_Owner\\My Documents\\Ryan Homework\\World of Warcraft\\WoW-3.1.2.9901-to-3.1.3.9947-enUS-downloader.exe"=
"c:\\Documents and Settings\\HP_Owner\\My Documents\\Ryan Homework\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\HP_Owner\\My Documents\\Ryan Homework\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:0.0.0.0/255.255.255.255:Enabled

HCP Discovery Service
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/23/2009 4:04 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/23/2009 4:05 PM 108552]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [12/28/2007 10:52 PM 79096]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [12/28/2007 10:52 PM 23672]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/23/2009 4:04 PM 297752]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [3/26/2009 8:49 PM 55152]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/7/2008 4:48 PM 24652]
S2 Ca533av;Icatch(IV) Video Camera Device;c:\windows\system32\drivers\Ca533av.sys [3/15/2006 9:02 PM 515803]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 6:08 PM 533360]
S3 QCPro;Logitech QuickCam Pro USB(PID_D001);c:\windows\system32\drivers\p35u.sys [2/12/2005 4:52 PM 116480]
S3 USBCamera;Icatch(IV) Still Camera Device;c:\windows\system32\drivers\Bulk533.sys [3/15/2006 9:02 PM 10986]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-09-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2009-09-17 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-27 16:56]
2009-09-17 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2004-08-08 08:38]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=pavilion&pf=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*
http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*
http://www.yahoo.com
IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
IE: Add To HP Organize... - c:\progra~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
DPF: ActiveGS.cab - hxxp://www.virtualapple.org/activegs.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\3qfmgr2w.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Aim6 - (no file)
AddRemove-HP Photosmart Essential - c:\program files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
AddRemove-NVIDIA GART Driver - c:\windows\system32\nvugart.exe
AddRemove-{FF1F4E8E-A833-4c4b-A14A-45D5B841B5D8} - c:\program files\HP\Digital Imaging\{FF1F4E8E-A833-4c4b-A14A-45D5B841B5D8}\setup\hpzscr01.exe -datfile hposcr29.dat
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-17 12:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1820)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\COMODO\Firewall\cmdagent.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\HP\hpcoretech\comp\hptskmgr.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-09-17 12:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-17 19:36
Pre-Run: 109,881,200,640 bytes free
Post-Run: 109,796,896,768 bytes free
432 --- E O F --- 2009-06-20 23:14