OK I ran combo fix and the windows recovery console. With that I was able to start in safe mode and disable my antivirus and I had to uninstall spybot since it would not open to disable tea timer I got a copy of the combo fix log. The computer said it needed to restart to complete unistall and to change settings for my Mcafee. I restarted and now it keeps restarting. I choose windows recovery and safe mode, safe mode with networking, or normal, and it begins start up, the fails and reboots. Here is my combofix log before all this. I couldn't get a new HJT log since I can't get it to stop rebooting.
ComboFix 09-07-23.04 - Owner 07/24/2009 14:28.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.615 [GMT -4:00]
Running from: F:\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\ALLUSE~1\APPLIC~1\11300464
c:\docume~1\ALLUSE~1\APPLIC~1\11300464\11300464
c:\docume~1\ALLUSE~1\APPLIC~1\11300464\11300464.exe
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\ipwindows
c:\program files\ipwindows\popF2.tmp
c:\recycler\S-1-5-21-968814600-1246504547-813671351-500
c:\windows\Installer\13f4c3.msp
c:\windows\Installer\17aaf09.msp
c:\windows\Installer\1982b8f.msp
c:\windows\Installer\208dd.msp
c:\windows\Installer\20969.msp
c:\windows\Installer\20e88.msp
c:\windows\Installer\21418.msp
c:\windows\Installer\22f2f.msp
c:\windows\Installer\25af2.msp
c:\windows\Installer\263ed.msp
c:\windows\Installer\36d71.msp
c:\windows\Installer\5191e8.msi
c:\windows\Installer\5b7d3f.msp
c:\windows\Installer\a28b7b.msi
c:\windows\Installer\ac260c.msp
c:\windows\kb913800.exe
c:\windows\system32\9.tmp
c:\windows\system32\drivers\smss.exe
c:\windows\system32\drivers\vsfoceuflxylkm.sys
c:\windows\system32\ghaf8jkdfd.dll
c:\windows\system32\uuddc32.dll
c:\windows\system32\vsfoceltnbowpd.dat
c:\windows\system32\vsfocexdnplvho.dll
c:\windows\system32\vsfocexvpovpvc.dll
c:\windows\system32\vsfoceymrdylkr.dat
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_vsfocemowuyniq
-------\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-06-24 to 2009-07-24 )))))))))))))))))))))))))))))))
.
2009-07-24 18:11 . 2009-07-24 18:12 -------- d-----w- C:\32788R22FWJFW
2009-07-24 05:08 . 2008-12-11 12:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-07-24 05:08 . 2009-04-03 15:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-07-24 05:08 . 2008-12-18 16:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-07-24 05:08 . 2009-07-24 18:27 -------- d---a-w- c:\docume~1\ALLUSE~1\APPLIC~1\TEMP
2009-07-24 05:08 . 2009-07-24 05:10 -------- d-----w- c:\program files\Common Files\PC Tools
2009-07-24 05:08 . 2008-12-10 15:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-07-24 05:08 . 2009-07-24 17:07 -------- d-----w- c:\program files\Spyware Doctor
2009-07-24 05:08 . 2009-07-24 05:08 -------- d-----w- c:\documents and settings\Owner\Application Data\PC Tools
2009-07-24 05:08 . 2009-07-24 05:08 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\PC Tools
2009-07-23 10:21 . 2009-07-23 10:21 -------- d-----w- c:\documents and settings\Owner\Application Data\pridl
2009-07-23 10:21 . 2009-07-23 10:21 11264 ----a-w- c:\documents and settings\Owner\Application Data\pridl\pridl.exe
2009-07-23 02:49 . 2009-07-23 03:10 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-07-08 02:56 . 2003-09-05 22:16 757760 ----a-w- c:\documents and settings\Owner\Application Data\Macromedia\Dreamweaver MX 2004\Configuration\Flash Player\NPSWF32.dll
2009-07-08 02:56 . 2003-09-05 22:16 815104 ----a-w- c:\documents and settings\Owner\Application Data\Macromedia\Dreamweaver MX 2004\Configuration\Flash Player\FlashPlayerW.dll
2009-07-08 02:54 . 2009-07-08 02:54 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Macrovision
2009-07-08 02:48 . 2009-07-08 02:48 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Macromedia
2009-07-08 02:33 . 2002-01-05 11:10 57344 ------w- c:\windows\system32\mfc70enu.dll
2009-07-08 02:33 . 2009-07-08 02:33 -------- d-----w- c:\program files\Common Files\Macromedia Shared
2009-07-08 02:33 . 2009-07-08 02:38 -------- d-----w- c:\program files\Common Files\Macromedia
2009-07-08 02:32 . 2009-07-08 02:50 -------- d-----w- c:\program files\Macromedia
2009-07-02 04:11 . 2009-07-02 04:11 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\RapidShare_
2009-06-30 23:50 . 2009-07-08 01:20 -------- d-----w- c:\documents and settings\All Users\AdobeTemp
2009-06-30 22:42 . 2009-06-30 22:42 -------- d-----w- c:\program files\uTorrent
2009-06-30 22:42 . 2009-07-01 01:03 -------- d-----w- c:\documents and settings\Owner\Application Data\uTorrent
2009-06-30 21:53 . 2009-06-30 21:53 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\FLEXnet
2009-06-30 21:34 . 2009-06-30 21:34 -------- d-----w- c:\program files\Adobe Media Player
2009-06-30 21:29 . 2009-06-30 21:29 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-06-27 15:55 . 2009-06-27 15:55 -------- d-----w- c:\documents and settings\Owner\Application Data\Media Player Classic
2009-06-27 15:47 . 2009-07-23 03:24 -------- d-----w- c:\program files\Blubster
2009-06-27 01:04 . 2009-06-27 01:04 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-06-24 20:42 . 2004-08-10 19:00 25600 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-06-24 20:25 . 2009-06-24 20:25 -------- d-----w- c:\program files\Windows Media Connect 2
2009-06-24 20:22 . 2009-06-24 20:23 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-06-24 19:57 . 2001-08-17 17:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-06-24 19:57 . 2001-08-17 17:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-06-24 19:40 . 2009-06-24 19:40 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-06-24 19:29 . 2009-06-24 19:29 -------- d-----w- c:\windows\system32\XPSViewer
2009-06-24 19:29 . 2009-06-24 19:29 -------- d-----w- c:\program files\MSBuild
2009-06-24 19:29 . 2009-06-24 19:29 -------- d-----w- c:\program files\Reference Assemblies
2009-06-24 19:28 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-06-24 19:28 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-06-24 19:28 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-06-24 19:28 . 2009-06-24 19:29 -------- d-----w- C:\cef7ac87ad8b1fbcfba1a9f067fc74
2009-06-24 19:28 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-06-24 19:28 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-06-24 19:28 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-06-24 19:28 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-06-24 19:24 . 2009-06-24 19:24 -------- d-----w- c:\program files\MSXML 6.0
2009-06-24 19:12 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-24 19:12 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-24 19:11 . 2009-03-06 14:44 283648 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-06-24 19:11 . 2009-02-09 10:20 399360 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-06-24 19:11 . 2009-02-09 10:20 473088 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-06-24 19:11 . 2009-02-06 17:14 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-06-24 19:11 . 2009-02-06 16:54 35328 -c----w- c:\windows\system32\dllcache\sc.exe
2009-06-24 19:11 . 2009-02-06 16:39 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-06-24 19:11 . 2005-07-26 04:39 60416 -c----w- c:\windows\system32\dllcache\colbact.dll
2009-06-24 19:11 . 2009-02-09 10:20 616960 -c----w- c:\windows\system32\dllcache\advapi32.dll
2009-06-24 19:11 . 2009-02-09 10:20 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-06-24 19:11 . 2009-02-09 10:20 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-06-24 19:11 . 2008-04-21 10:02 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-06-24 19:09 . 2008-05-01 14:30 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2009-06-24 19:09 . 2008-06-13 13:10 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-06-24 19:09 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\drivers\bthport.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-24 18:27 . 2009-07-24 18:27 0 ----a-w- c:\windows\system32\B.tmp
2009-07-24 18:26 . 2008-01-11 17:42 -------- d-----w- c:\program files\McAfee
2009-07-24 18:21 . 2005-12-12 14:43 52224 ----a-w- c:\windows\system32\Crypserv.exe
2009-07-23 10:21 . 2009-07-23 10:21 84480 ----a-w- c:\windows\system32\9A.tmp
2009-07-23 10:21 . 2009-07-23 10:20 40 ----a-w- c:\windows\system32\8B.tmp
2009-07-23 10:20 . 2009-07-23 10:20 360320 ----a-w- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2009-07-23 10:20 . 2005-04-13 16:56 360320 ----a-w- c:\windows\system32\drivers\TCPIP.SYS
2009-07-23 03:25 . 2005-11-26 20:22 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-07-23 03:17 . 2005-11-26 20:22 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-08 02:46 . 2005-05-19 22:06 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-08 01:35 . 2008-05-22 03:46 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-02 17:44 . 2005-12-29 02:04 88968 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-25 15:24 . 2005-12-11 21:56 -------- d-----w- c:\program files\My Shared Folder
2009-06-24 20:07 . 2009-07-24 01:47 177842 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
2009-06-24 20:06 . 2005-04-13 17:18 86811 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-06-16 14:55 . 2005-04-13 16:56 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2005-04-13 16:55 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-04 16:06 . 2008-11-27 00:17 -------- d-----w- c:\documents and settings\Owner\Application Data\Move Networks
2009-06-03 19:24 . 2005-04-13 16:55 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-13 05:15 . 2005-04-13 16:56 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-07 15:44 . 2005-04-13 16:55 344064 ----a-w- c:\windows\system32\localspl.dll
2005-03-02 18:37 . 2006-10-04 17:56 22819 ----a-w- c:\program files\CDCOPS.DLL
2005-02-24 19:57 . 2006-10-04 17:56 36093 ----a-w- c:\program files\SP.VOC
2005-02-24 19:54 . 2006-10-04 17:56 50002 ----a-w- c:\program files\IT.VOC
2005-02-24 19:49 . 2006-10-04 17:56 33776 ----a-w- c:\program files\FR.VOC
2005-02-24 19:43 . 2006-10-04 17:56 35379 ----a-w- c:\program files\GE.voc
2005-02-24 19:39 . 2006-10-04 17:56 32610 ----a-w- c:\program files\TU.voc
2009-06-27 14:42 . 2008-09-08 17:30 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
------- Sigcheck -------
[7] 2005-05-25 19:07 359936 63FDFEA54EB53DE2D863EE454937CE1E c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[7] 2006-01-13 17:07 360448 5562CC0A47B2AEF06D3417B733F3C195 c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[7] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2005-05-25 19:04 359808 88763A98A4C26C409741B4AA162720C9 c:\windows\$NtUninstallKB913446$\tcpip.sys
[7] 2006-01-13 02:28 359808 583E063FDC888CA30D05C2724B0D7EF4 c:\windows\$NtUninstallKB917953$\tcpip.sys
[7] 2006-04-20 11:51 359808 1DBF125862891817F374F407626967F4 c:\windows\$NtUninstallKB951748$\tcpip.sys
[-] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\tcpip.sys
[-] 2009-07-23 10:20 360320 073941D59AE065910064B728DEE981EE c:\windows\system32\dllcache\TCPIP.SYS
[-] 2009-07-23 10:20 360320 073941D59AE065910064B728DEE981EE c:\windows\system32\drivers\TCPIP.SYS
[-] 2007-06-13 10:23 1053696 0803AFF01DBF0C4CD0F2E5ED3AA94A72 c:\windows\explorer.exe
[-] 2007-06-13 11:26 1033216 E644780B0A82D807610B1F2F739CCF76 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2004-08-10 19:00 1032192 6746CF2FA16D3A5DF8AAF3B1A246D97B c:\windows\$NtUninstallKB938828$\explorer.exe
[-] 2008-04-14 00:12 1033728 5453DC164BD317ED2AE80DC738F962E1 c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\explorer.exe
[-] 2007-06-13 10:23 1053696 A93113210A660F1540BA73E5CF094CB3 c:\windows\system32\dllcache\explorer.exe
[-] 2008-04-14 00:12 15360 C57ABD3A5599C0519A119FEFCC7D1D0A c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\ctfmon.exe
[-] 2004-08-10 19:00 35840 D0F345DAC41FB51A9C64562AE6ABEA55 c:\windows\system32\ctfmon.exe
[-] 2005-06-11 00:17 57856 32B1509B48612035B5656971BCA3EEEA c:\windows\$hf_mig$\KB896423\SP2QFE\spoolsv.exe
[-] 2004-08-10 19:00 57856 059B2144B6D22170BADF7CC9A55D0ABB c:\windows\$NtUninstallKB896423$\spoolsv.exe
[-] 2008-04-14 00:12 57856 BDF823FB267FD0459F15F644A8A5E108 c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\spoolsv.exe
[-] 2005-06-10 23:53 78336 7E11C852534988C790F9946C6BE81253 c:\windows\system32\spoolsv.exe
[-] 2008-04-14 00:12 26112 2C88AF3B982C8E48E6D3B777CDA055E3 c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\userinit.exe
[-] 2004-08-10 19:00 45056 24BEFCE61490784AD7246F33955229C2 c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 35840]
"TranscodingService"="c:\program files\TiVo\Desktop\TranscodingService.exe" [2009-01-27 540672]
"TivoServer"="c:\program files\TiVo\Desktop\TiVoServer.exe" [2009-01-27 2164736]
"TivoNotify"="c:\program files\TiVo\Desktop\TiVoNotify.exe" [2009-01-27 449024]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2280960]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2005-11-15 1220608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-07-06 200749]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 53248]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 434176]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 176128]
"msnappau"="c:\program files\MSN Apps\Updater\01.03.0000.1005\en-us\msnappau.exe" [2004-08-13 106496]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2005-12-21 299008]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb06.exe" [2002-07-11 208896]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 69632]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3760128]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 84992]
"eBayToolbar"="c:\program files\eBay\eBay Toolbar2\eBayTBDaemon.exe" [2009-01-18 632048]
"Blubster"="c:\program files\Blubster\Blubster.exe" [2008-11-10 1368064]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-18 360448]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 65536]
"AOL Spyware Protection"="c:\progra~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-03-19 78960]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-12-01 98304]
"ShowWnd"="ShowWnd.exe" - c:\windows\ShowWnd.exe [2003-09-19 57344]
"CHotkey"="zHotkey.exe" - c:\windows\zHotkey.exe [2004-05-18 565760]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\Palm\HOTSYNC.EXE [2002-8-9 319488]
c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 50176]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-9-16 258048]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 86068]
NETGEAR WPN311 Wireless Assistant.lnk - c:\program files\NETGEAR\WPN311\wlancfg5.exe [2005-2-21 4538368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UserInit"="c:\windows\explorer.exe,"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Blubster\\Blubster.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [7/24/2009 1:08 AM 130936]
R1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [9/2/2006 2:37 PM 3026]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [7/24/2009 1:08 AM 348752]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [1/29/2007 4:14 PM 113896]
S2 0144421248459507mcinstcleanup;McAfee Application Installer Cleanup (0144421248459507);c:\windows\TEMP\014442~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\windows\TEMP\014442~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S3 KCFdcDevice0;KCFdcDevice0;\??\c:\futura\kcfdc.sys --> c:\futura\kcfdc.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - 0144421248459507MCINSTCLEANUP
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DriverUpdaterPro - c:\program files\XPC Tools\Driver Updater Pro\DriverUpdaterPro.exe
HKLM-Run-IS CfgWiz - c:\program files\Norton Internet Security\cfgwiz.exe
HKLM-Run-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
HKLM-Run-11300464 - c:\documents and settings\All Users\Application Data\11300464\11300464.exe
HKLM-Run-DXDllRegExe - dxdllreg.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.adelphia.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
FF - ProfilePath - c:\docume~1\Owner\APPLIC~1\Mozilla\Firefox\Profiles\qdqhzd2c.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://moneycentral.msn.com/home.asp
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\qdqhzd2c.default\extensions\keyscrambler@qfx.software.corporation\components\KeyScramblerIE.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-24 14:34
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(764)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\WININET.DLL
.
Completion time: 2009-07-24 14:36
ComboFix-quarantined-files.txt 2009-07-24 18:36
Pre-Run: 69,079,355,392 bytes free
Post-Run: 69,117,624,320 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
323 --- E O F --- 2009-07-23 10:17