I was only able to post half of it. Computer shut down before combofix could run its course.
Heres a complete one:
ComboFix 09-10-01.05 - HP_Administrator 10/03/2009 13:19.2.2 - NTFSx86
Running from: c:\documents and settings\HP_Administrator\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HP_Administrator\Application Data\wiaserva.log
c:\windows\9129837.exe
c:\windows\system32\wbem\proquota.exe
.
---- Previous Run -------
.
C:\cuysn.exe
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Application Data\zofity._sy
c:\documents and settings\HP_Administrator\Application Data\alot\Button_0\Button_0.xml
c:\documents and settings\HP_Administrator\Application Data\alot\Button_0\Button_0.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\Button_1\Button_1.xml
c:\documents and settings\HP_Administrator\Application Data\alot\Button_1\Button_1.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\Button_10\Button_10.xml
c:\documents and settings\HP_Administrator\Application Data\alot\Button_10\Button_10.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\Button_11\Button_11.xml
c:\documents and settings\HP_Administrator\Application Data\alot\Button_11\Button_11.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\Button_2\Button_2.xml
c:\documents and settings\HP_Administrator\Application Data\alot\Button_2\Button_2.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\Button_3\Button_3.xml
c:\documents and settings\HP_Administrator\Application Data\alot\Button_3\Button_3.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\Button_4\Button_4.xml
c:\documents and settings\HP_Administrator\Application Data\alot\Button_4\Button_4.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\Button_5\Button_5.xml
c:\documents and settings\HP_Administrator\Application Data\alot\Button_5\Button_5.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\Button_6\Button_6.xml
c:\documents and settings\HP_Administrator\Application Data\alot\Button_6\Button_6.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\Button_7\Button_7.xml
c:\documents and settings\HP_Administrator\Application Data\alot\Button_7\Button_7.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\Button_8\Button_8.xml
c:\documents and settings\HP_Administrator\Application Data\alot\Button_8\Button_8.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\Button_9\Button_9.xml
c:\documents and settings\HP_Administrator\Application Data\alot\Button_9\Button_9.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\configurator\configurator.xml
c:\documents and settings\HP_Administrator\Application Data\alot\configurator\configurator.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\postInstallLayout\postInstallLayout.xml
c:\documents and settings\HP_Administrator\Application Data\alot\postInstallLayout\postInstallLayout.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\products\products.xml
c:\documents and settings\HP_Administrator\Application Data\alot\products\products.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_0\images\alot_icon_35x16.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_1\images\alot_search_24x16.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_2\images\default_267_alot_ref_refsearch.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_3\images\default_268_alot_ref_research.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\alert-icon.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\alert.png
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\clear.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\cloudy.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\default_281_alot_weather_widget.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\foggy.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\mcloud.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\nclear.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\ncloudy.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\nmcloud.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\pcloud.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\rain.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\shower.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\snow.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_4\images\tstorm.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\active_default_346_alot_ref_word.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\alert-icon.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\alert.png
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\clear.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\cloudy.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\default_281_alot_weather_widget.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\default_346_alot_ref_word.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\foggy.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\mcloud.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\nclear.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\nmcloud.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\pcloud.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\rain.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\shower.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_5\images\snow.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_6\images\default_319_alot_ref_calculator.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_7\images\default_270_alot_mrkt_travel_guides.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_7\images\default_270_alot_ref_mrkt_book.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_7\images\default_270_default_243_alot_news_mrkt_nyt.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_8\images\default_446_alot_mrkt_180.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_8\images\default_446_alot_mrkt_gamevance.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Button_8\images\default_446_alot_ref_mrkt_book.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Shared\domains.dat
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Shared\images\alot_brand.png
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Shared\images\spinner.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Shared\images\widget_bottom.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Shared\images\widget_btnclose0.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Shared\images\widget_btnclose1.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Shared\images\widget_btnmin0.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Shared\images\widget_btnmin1.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Shared\images\widget_caption.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Shared\images\widget_error_bg.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Shared\images\widget_error_close.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\Resources\Shared\images\widget_error_icon.bmp
c:\documents and settings\HP_Administrator\Application Data\alot\TimerManager\TimerManager.xml
c:\documents and settings\HP_Administrator\Application Data\alot\TimerManager\TimerManager.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\toolbar.xml
c:\documents and settings\HP_Administrator\Application Data\alot\ToolbarSearch\ToolbarSearch.xml
c:\documents and settings\HP_Administrator\Application Data\alot\ToolbarSearch\ToolbarSearch.xml.backup
c:\documents and settings\HP_Administrator\Application Data\alot\Updater\Updater.xml
c:\documents and settings\HP_Administrator\Application Data\alot\Updater\Updater.xml.backup
c:\documents and settings\HP_Administrator\Application Data\lizkavd.exe
c:\documents and settings\HP_Administrator\Application Data\seres.exe
c:\documents and settings\HP_Administrator\Application Data\svcst.exe
c:\documents and settings\HP_Administrator\Application Data\wiaserva.log
c:\documents and settings\HP_Administrator\Application Data\ytat.dll
c:\documents and settings\HP_Administrator\Application Data\ytomi.pif
c:\documents and settings\HP_Administrator\Local Settings\Application Data\cisusuc._sy
c:\documents and settings\HP_Administrator\Local Settings\Application Data\ilyxuqo.scr
c:\documents and settings\HP_Administrator\Local Settings\Application Data\sibut._dl
c:\documents and settings\LocalService\Application Data\alot\Button_0\Button_0.xml
c:\documents and settings\LocalService\Application Data\alot\Button_0\Button_0.xml.backup
c:\documents and settings\LocalService\Application Data\alot\Button_1\Button_1.xml
c:\documents and settings\LocalService\Application Data\alot\Button_1\Button_1.xml.backup
c:\documents and settings\LocalService\Application Data\alot\Button_10\Button_10.xml
c:\documents and settings\LocalService\Application Data\alot\Button_10\Button_10.xml.backup
c:\documents and settings\LocalService\Application Data\alot\Button_11\Button_11.xml
c:\documents and settings\LocalService\Application Data\alot\Button_11\Button_11.xml.backup
c:\documents and settings\LocalService\Application Data\alot\Button_2\Button_2.xml
c:\documents and settings\LocalService\Application Data\alot\Button_2\Button_2.xml.backup
c:\documents and settings\LocalService\Application Data\alot\Button_3\Button_3.xml
c:\documents and settings\LocalService\Application Data\alot\Button_3\Button_3.xml.backup
c:\documents and settings\LocalService\Application Data\alot\Button_4\Button_4.xml
c:\documents and settings\LocalService\Application Data\alot\Button_4\Button_4.xml.backup
c:\documents and settings\LocalService\Application Data\alot\Button_5\Button_5.xml
c:\documents and settings\LocalService\Application Data\alot\Button_5\Button_5.xml.backup
c:\documents and settings\LocalService\Application Data\alot\Button_6\Button_6.xml
c:\documents and settings\LocalService\Application Data\alot\Button_6\Button_6.xml.backup
c:\documents and settings\LocalService\Application Data\alot\Button_7\Button_7.xml
c:\documents and settings\LocalService\Application Data\alot\Button_7\Button_7.xml.backup
c:\documents and settings\LocalService\Application Data\alot\Button_8\Button_8.xml
c:\documents and settings\LocalService\Application Data\alot\Button_8\Button_8.xml.backup
c:\documents and settings\LocalService\Application Data\alot\Button_9\Button_9.xml
c:\documents and settings\LocalService\Application Data\alot\Button_9\Button_9.xml.backup
c:\documents and settings\LocalService\Application Data\alot\configurator\configurator.xml
c:\documents and settings\LocalService\Application Data\alot\configurator\configurator.xml.backup
c:\documents and settings\LocalService\Application Data\alot\TimerManager\TimerManager.xml
c:\documents and settings\LocalService\Application Data\alot\TimerManager\TimerManager.xml.backup
C:\nksrq.exe
C:\pphqrer.exe
c:\program files\alot\alotUninst.exe
c:\program files\Common Files\yjasyliha.exe
C:\tlcefbe.exe
c:\windows\9129837.exe
c:\windows\aconeloq.exe
c:\windows\aquwaruyumogavim.dll
c:\windows\Installer\54f091fc.msi
c:\windows\kb913800.exe
c:\windows\mqcd.dbt
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_scui.cpl
c:\windows\system32\ashl.nq
c:\windows\system32\gogowito.dll
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\lowsec\user.ds.lll
c:\windows\system32\wbem\proquota.exe
c:\windows\system32\yidomabi.dll
c:\windows\ugilivi.sys
c:\windows\umuj.bin
c:\windows\upytyha.exe
c:\windows\uvir.ban
D:\Autorun.inf
-- Previous Run --
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\eventlog.dll
c:\windows\system32\proquota.exe . . . is missing!!
--------
c:\windows\system32\proquota.exe . . . is missing!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
((((((((((((((((((((((((( Files Created from 2009-09-03 to 2009-10-03 )))))))))))))))))))))))))))))))
.
2009-10-03 20:05 . 2009-10-03 20:05 -------- d-----w- c:\windows\LastGood
2009-09-27 10:25 . 2009-09-27 10:25 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\{5D6BD32C-E7F1-4910-94A0-444E5E7E818F}
2009-09-27 10:19 . 2009-09-27 10:19 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-09-27 09:59 . 2009-09-27 10:27 -------- d-----w- c:\program files\PALADIN
2009-09-27 09:40 . 2009-09-27 10:24 -------- d-----w- c:\program files\Search & Destroy
2009-09-27 09:03 . 2009-09-27 09:03 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\McAfee
2009-09-25 04:38 . 2009-07-08 20:44 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-25 04:38 . 2009-07-08 20:44 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-25 04:38 . 2009-07-08 20:44 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-25 04:38 . 2009-07-16 19:32 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-09-25 04:37 . 2009-09-25 04:38 -------- d-----w- c:\program files\Common Files\McAfee
2009-09-25 04:37 . 2009-09-25 04:37 -------- d-----w- c:\program files\McAfee.com
2009-09-25 04:35 . 2009-07-08 20:43 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-25 04:05 . 2009-10-03 09:32 -------- d-----w- c:\program files\McAfee
2009-09-25 03:01 . 2009-09-25 03:01 16524 ----a-w- c:\windows\ucejeliv.dat
2009-09-25 03:01 . 2009-09-25 03:01 18660 ----a-w- c:\windows\mosaxatod.dat
2009-09-25 03:01 . 2009-09-25 03:01 10487 ----a-w- c:\windows\system32\tomobico.dat
2009-09-24 22:04 . 2009-10-02 04:36 120 ----a-w- c:\windows\Dxilanerulato.dat
2009-09-24 22:04 . 2009-10-02 04:36 0 ----a-w- c:\windows\Kqoyedesuvaruku.bin
2009-09-24 22:04 . 2009-09-24 22:04 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\{B8542336-4284-4675-9352-84D2DE8DE27F}
2009-09-24 21:58 . 2009-05-14 01:47 61224 ----a-w- c:\documents and settings\HelpAssistant\GoToAssistDownloadHelper.exe
2009-09-24 21:53 . 2009-09-24 21:53 4707 ----a-w- c:\windows\system32\z98a.bin
2009-09-23 01:04 . 2009-09-24 15:08 -------- d-----w- c:\program files\AOL 9.1c
2009-09-20 01:30 . 2009-10-03 19:41 0 ----a-w- c:\windows\win32k.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-30 21:45 . 2006-10-19 01:21 18668 ----a-w- c:\documents and settings\HP_Administrator\Application Data\wklnhst.dat
2009-09-27 10:26 . 2009-04-01 22:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-27 09:38 . 2009-04-01 22:06 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-27 09:05 . 2008-01-03 20:45 -------- d-----w- c:\program files\Security Task Manager
2009-09-25 07:38 . 2009-05-13 18:11 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-09-25 03:35 . 2006-08-01 02:25 -------- d-----w- c:\program files\DISC
2009-09-24 15:18 . 2006-08-01 02:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-09-24 15:07 . 2006-10-03 22:13 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\AOL
2009-09-24 09:59 . 2009-05-14 05:15 -------- d-----w- c:\program files\AOL Toolbar
2009-09-23 01:05 . 2006-10-03 22:05 -------- d-----w- c:\program files\Common Files\AOL
2009-09-23 01:04 . 2006-10-03 22:07 -------- d-----w- c:\program files\Common Files\aolshare
2009-09-23 01:04 . 2006-10-03 22:05 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-09-01 00:58 . 2009-08-14 09:08 -------- d-----w- c:\program files\NCH Swift Sound
2009-09-01 00:58 . 2009-08-14 09:08 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\NCH Swift Sound
2009-08-17 07:57 . 2007-11-19 19:51 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-17 07:49 . 2006-08-01 01:49 -------- d-----w- c:\program files\GemMaster
2009-08-17 07:37 . 2009-08-14 09:08 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-08-17 06:22 . 2009-08-13 21:21 -------- d-----w- c:\program files\THQ
2009-08-17 06:22 . 2006-08-01 02:27 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-14 09:11 . 2009-08-14 09:11 -------- d-----w- c:\program files\NCH Software
2009-08-14 02:10 . 2009-08-14 02:08 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Winamp
2009-08-14 02:09 . 2009-08-14 02:08 -------- d-----w- c:\program files\Winamp
2009-07-08 20:44 . 2009-07-08 20:44 214024 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-04-13 07:04 . 2009-04-13 07:04 2098 --sh--w- c:\windows\system32\liyujupe.dll
2009-04-13 07:04 . 2009-04-13 07:04 2098 --sh--w- c:\windows\system32\pokefige.dll
2009-01-28 21:53 . 2009-01-28 21:53 12288 --sha-w- c:\windows\system32\wetelumo.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"Lexmark X74-X75"="c:\program files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 57344]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-29 583048]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-01 180269]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2005-09-27 169984]
"ftutil2"="ftutil2.dll" - c:\windows\system32\ftutil2.dll [2004-06-07 106496]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-06-14 16239616]
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
mhbupd32.exe [2004-8-9 29184]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ Shtret.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DVD@ccess.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DVD@ccess.lnk
backup=c:\windows\pss\DVD@ccess.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates From HP.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk
backup=c:\windows\pss\Updates From HP.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^HP_Administrator^Start Menu^Programs^Startup^mhbupd32.exe]
path=c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\mhbupd32.exe
backup=c:\windows\pss\mhbupd32.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ISPwdSvc"=3 (0x3)
"GameConsoleService"=3 (0x3)
"AOL TopSpeedMonitor"=2 (0x2)
"AOL ACS"=2 (0x2)
"sprtsvc_ddoctorv2"=2 (0x2)
"MpfService"=2 (0x2)
"McSysmon"=3 (0x3)
"McShield"=2 (0x2)
"McProxy"=2 (0x2)
"McODS"=3 (0x3)
"McNASvc"=2 (0x2)
"mcmscsvc"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1159913245\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Common Files\\AOL\\1159913245\\EE\\aolsoftware.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\AOL 9.1a\\waol.exe"=
"c:\\Program Files\\Symantec\\LiveUpdate\\AluSchedulerSvc.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=
"c:\\Program Files\\Java\\jre1.6.0_03\\bin\\jusched.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\AOL 9.1b\\waol.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AOL 9.1c\\waol.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:Remote Desktop
R2 0229931254061299mcinstcleanup;McAfee Application Installer Cleanup (0229931254061299);c:\windows\TEMP\022993~1.EXE [x]
R3 {0D1C65DF-BFC7-4DB1-8A96CF4309C0C846};{0D1C65DF-BFC7-4DB1-8A96CF4309C0C846};c:\windows\System32\svchost.exe [2004-08-10 14336]
S2 DVDAccss;DVDAccss;c:\windows\system32\drivers\DVDAccss.sys [2003-11-22 29156]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
{0D1C65DF-BFC7-4DB1-8A96CF4309C0C846}
.
Contents of the 'Scheduled Tasks' folder
2009-09-25 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-09-25 04:26]
2009-10-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-09-25 04:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
mWindow Title = Windows Internet Explorer provided by Comcast
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
http://www.yahoo.com
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: mhcc.edu
Trusted Zone: trymedia.com
FF - ProfilePath - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\yafy98wb.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffTB50CLie7&query=
FF - prefs.js: browser.search.selectedEngine - AOL Search
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com
FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffTB50CLab&query=
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJPI150_12.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: XULRunner: {B8542336-4284-4675-9352-84D2DE8DE27F} - c:\documents and settings\HP_Administrator\Local Settings\Application Data\{B8542336-4284-4675-9352-84D2DE8DE27F}
FF - HiddenExtension: XULRunner: {5D6BD32C-E7F1-4910-94A0-444E5E7E818F} - c:\documents and settings\Administrator\Local Settings\Application Data\{5D6BD32C-E7F1-4910-94A0-444E5E7E818F}\
---- FIREFOX POLICIES ----
FF - user.js: browser.sessionstore.resume_from_crash - false
.
- - - - ORPHANS REMOVED - - - -
BHO-{85cb03a9-763f-4358-8343-662441ea4870} - (no file)
HKCU-Run-SpybotSD TeaTimer - c:\program files\PALADIN\TeaTimer.exe
Notify-dbbin - dbbin.dll
AddRemove-alotToolbar - c:\program files\alot\alotUninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-03 13:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{0D1C65DF-BFC7-4DB1-8A96CF4309C0C846}]
"ServiceDll"="c:\docume~1\HP_ADM~1\LOCALS~1\Temp\11.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@DACL=(02 0010)
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(824)
c:\windows\Shtret.dll
.
Completion time: 2009-10-03 13:25
ComboFix-quarantined-files.txt 2009-10-03 20:25
Pre-Run: 203,930,058,752 bytes free
Post-Run: 203,935,186,944 bytes free
434 --- E O F --- 2009-10-03 19:57