Thanks again for your help. Here is the requested info. Please advise on next steps.
Here is the log file. I also uploaded combofix.txt file, not sure if they are one in the same.
ComboFix 09-12-18.03 - Tim 12/20/2009 12:44:26.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.959.480 [GMT -5:00]
Running from: c:\documents and settings\Tim.YOUR-0CDC4F5844\Desktop\KittyFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Tim.YOUR-0CDC4F5844\Start Menu\Programs\StartUp\scandisk.dll
c:\documents and settings\Tim.YOUR-0CDC4F5844\Start Menu\Programs\StartUp\scandisk.lnk
c:\program files\Shared\liB.dll
c:\program files\Shared\lib.sig
c:\recycler\S-1-5-21-2634240986-3808314100-2425551066-1005
c:\recycler\S-1-5-21-2634240986-3808314100-2425551066-1006
c:\windows\Fonts\RandFont.dll
c:\windows\kb913800.exe
c:\windows\system32\critical_warning.html
c:\windows\system32\hugeloko.dll
c:\windows\system32\huhukuge.dll
c:\windows\system32\lovojefu.dll
c:\windows\system32\notepad.dll
c:\windows\system32\pujadoli.dll
c:\windows\system32\pworr.dll
c:\windows\ujipahogevopeba.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-11-20 to 2009-12-20 )))))))))))))))))))))))))))))))
.
2009-12-20 17:52 . 2009-12-20 17:55 -------- d-----w- C:\698def7004e822201cf5
2009-12-19 19:41 . 2009-12-19 19:39 293376 ----a-w- C:\oikyjdxg.exe
2009-12-19 19:28 . 2009-12-19 19:08 524288 ----a-w- C:\dds.scr
2009-12-19 19:02 . 2009-12-19 19:02 -------- d-----w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Application Data\Malwarebytes
2009-12-19 19:00 . 2009-12-19 19:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-19 18:57 . 2009-12-19 18:57 -------- d-----w- c:\program files\ERUNT
2009-12-19 02:30 . 2008-11-06 07:03 -------- d-----w- C:\SDFix
2009-12-19 02:21 . 2009-12-19 02:21 -------- d-sh--w- c:\windows\system32\config\systemprofile\Temporary Internet Files
2009-12-19 02:21 . 2009-12-19 02:21 -------- d-sh--w- c:\windows\system32\config\systemprofile\History
2009-12-14 18:00 . 2009-12-14 18:00 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-12-13 02:14 . 2009-12-13 02:50 -------- d-----w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Local Settings\Application Data\xgsdnr
2009-12-12 00:11 . 2009-12-20 17:22 0 ----a-w- c:\windows\Pveduqodi.bin
2009-12-12 00:11 . 2009-12-13 01:50 120 ----a-w- c:\windows\Mjoyuku.dat
2009-12-10 23:59 . 2009-12-10 23:59 -------- d-sh--w- c:\documents and settings\Tim.YOUR-0CDC4F5844\IECompatCache
2009-12-06 18:24 . 2009-12-06 18:24 -------- d-sh--w- c:\documents and settings\Tim.YOUR-0CDC4F5844\PrivacIE
2009-12-06 14:39 . 2009-12-06 14:39 -------- d-sh--w- c:\documents and settings\Tim.YOUR-0CDC4F5844\IETldCache
2009-12-06 14:21 . 2009-10-02 04:44 92160 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-12-06 14:21 . 2009-10-29 07:45 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-12-06 14:21 . 2009-10-29 07:45 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll
2009-12-06 14:21 . 2009-10-29 07:45 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-12-06 14:21 . 2009-10-29 07:45 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-06 14:21 . 2009-10-29 07:45 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll
2009-12-06 14:21 . 2009-10-29 07:45 11069952 ------w- c:\windows\system32\dllcache\ieframe.dll
2009-12-06 02:35 . 2008-02-26 11:59 294912 ------w- c:\windows\system32\dllcache\msctf.dll
2009-12-05 15:41 . 2009-12-05 15:41 -------- d-----w- c:\program files\MSXML 6.0
2009-12-05 15:39 . 2009-12-20 17:48 -------- d-----w- c:\program files\Shared
2009-12-03 21:07 . 2009-12-03 21:22 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-12-03 20:58 . 2009-12-03 20:58 -------- d-----w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Local Settings\Application Data\Identities
2009-12-03 20:43 . 2009-12-10 23:46 6172 ----a-w- c:\windows\system32\d3d9caps.dat
2009-12-03 16:17 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-12-03 16:17 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2009-12-03 16:16 . 2009-03-06 14:44 283648 ------w- c:\windows\system32\dllcache\pdh.dll
2009-12-03 16:16 . 2009-02-06 16:54 35328 ------w- c:\windows\system32\dllcache\sc.exe
2009-12-03 16:16 . 2005-07-26 04:39 60416 ------w- c:\windows\system32\dllcache\colbact.dll
2009-12-03 16:16 . 2009-02-09 10:20 399360 ------w- c:\windows\system32\dllcache\rpcss.dll
2009-12-03 16:16 . 2009-02-09 10:20 473088 ------w- c:\windows\system32\dllcache\fastprox.dll
2009-12-03 16:16 . 2009-02-06 17:14 110592 ------w- c:\windows\system32\dllcache\services.exe
2009-12-03 16:16 . 2009-02-06 16:39 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2009-12-03 16:16 . 2009-02-09 10:20 616960 ------w- c:\windows\system32\dllcache\advapi32.dll
2009-12-03 16:16 . 2009-02-09 10:20 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-12-03 16:16 . 2009-02-09 10:20 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
2009-12-03 16:16 . 2009-06-21 22:04 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2009-12-03 16:13 . 2008-05-08 12:28 202752 ------w- c:\windows\system32\dllcache\rmcast.sys
2009-12-03 16:13 . 2008-10-24 11:10 453632 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2009-12-03 16:13 . 2008-12-11 11:57 333184 ------w- c:\windows\system32\dllcache\srv.sys
2009-12-03 16:13 . 2008-05-01 14:30 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2009-12-03 16:13 . 2008-04-11 18:50 683520 ------w- c:\windows\system32\dllcache\inetcomm.dll
2009-12-03 16:12 . 2009-07-31 04:57 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll
2009-12-03 16:12 . 2008-06-24 16:23 74240 ------w- c:\windows\system32\dllcache\mscms.dll
2009-12-03 16:11 . 2009-07-10 13:42 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-12-03 16:11 . 2008-10-15 16:57 332800 ------w- c:\windows\system32\dllcache\netapi32.dll
2009-12-03 16:08 . 2009-05-07 15:44 344064 ------w- c:\windows\system32\dllcache\localspl.dll
2009-12-03 16:08 . 2008-06-12 14:16 91648 ------w- c:\windows\system32\dllcache\mtxoci.dll
2009-12-03 16:08 . 2008-06-12 14:16 161792 ------w- c:\windows\system32\dllcache\msdtcuiu.dll
2009-12-03 16:08 . 2008-06-12 14:16 956928 ------w- c:\windows\system32\dllcache\msdtctm.dll
2009-12-03 16:08 . 2008-06-12 14:16 66560 ------w- c:\windows\system32\dllcache\mtxclu.dll
2009-12-03 16:08 . 2008-06-12 14:16 58880 ------w- c:\windows\system32\dllcache\msdtclog.dll
2009-12-03 16:08 . 2008-06-12 14:16 428032 ------w- c:\windows\system32\dllcache\msdtcprx.dll
2009-12-03 16:04 . 2008-04-21 10:02 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2009-12-03 16:03 . 2009-06-10 14:21 84992 ------w- c:\windows\system32\dllcache\avifil32.dll
2009-12-03 16:03 . 2009-08-04 12:51 2185984 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-12-03 16:03 . 2009-08-04 12:02 2020864 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-12-03 16:03 . 2009-08-04 12:49 2142720 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-12-03 16:03 . 2009-08-04 12:02 2062976 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-12-03 16:00 . 2008-07-03 13:16 8454656 ------w- c:\windows\system32\dllcache\shell32.dll
2009-12-03 15:59 . 2009-06-05 07:42 655872 ------w- c:\windows\system32\dllcache\mstscax.dll
2009-11-25 19:16 . 2009-11-25 19:16 -------- d-----w- c:\documents and settings\All Users\Application Data\WD_SmartWareCommon
2009-11-25 19:14 . 2009-11-25 19:14 -------- d-----w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Local Settings\Application Data\Western_Digital
2009-11-25 19:13 . 2009-11-25 19:13 -------- d-----w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Application Data\Western Digital
2009-11-25 19:13 . 2009-11-25 19:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Western Digital
2009-11-25 19:13 . 2009-11-25 19:13 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\ServiceTest
2009-11-25 19:13 . 2009-02-13 17:02 11520 ----a-w- c:\windows\system32\drivers\wdcsam.sys
2009-11-25 19:12 . 2009-11-25 19:12 -------- d-----w- c:\program files\Western Digital
2009-11-25 19:10 . 2009-11-25 19:10 -------- d-----w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Local Settings\Application Data\Western Digital
2009-11-25 18:56 . 2009-12-10 03:35 -------- d-----w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Application Data\ZoomBrowser EX
2009-11-25 18:53 . 2009-11-25 19:07 -------- d-----w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Application Data\CameraWindowDC
2009-11-25 18:53 . 2009-11-25 18:53 -------- d-----w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Application Data\CANON INC
2009-11-23 23:24 . 2009-11-23 23:24 -------- d-----w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Application Data\Leadertech
2009-11-23 23:24 . 2001-08-18 03:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2009-11-23 23:24 . 2004-08-04 03:58 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-11-23 23:24 . 2004-08-04 03:58 15104 ----a-w- c:\windows\system32\dllcache\usbscan.sys
2009-11-23 23:24 . 2004-08-04 05:56 159232 ----a-w- c:\windows\system32\ptpusd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-20 16:05 . 2009-11-12 02:56 -------- d-----w- c:\program files\McAfee
2009-11-15 16:29 . 2009-11-15 16:29 -------- d-----w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Application Data\AdobeUM
2009-11-12 03:18 . 2009-11-12 03:18 -------- d-----w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Application Data\U3
2009-11-12 02:59 . 2007-01-23 03:47 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-11-12 02:56 . 2009-11-12 02:56 -------- d-----w- c:\program files\McAfee.com
2009-11-11 12:45 . 2009-11-11 12:45 -------- d-----w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Application Data\McAfee
2009-11-11 02:41 . 2006-11-18 01:40 65664 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-11 02:40 . 2006-11-18 02:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-11-11 02:40 . 2006-11-18 02:00 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-11-11 02:37 . 2006-11-18 02:39 -------- d-----w- c:\program files\Quicken
2009-11-11 02:30 . 2006-11-18 02:28 -------- d-----w- c:\documents and settings\All Users\Application Data\WildTangent
2009-11-11 02:26 . 2006-11-18 02:52 -------- d-----w- c:\program files\HP Rhapsody
2009-11-11 02:25 . 2006-11-18 02:16 -------- d-----w- c:\program files\GemMaster
2009-11-10 17:07 . 2009-11-10 17:07 -------- d-----w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Application Data\GTek
2009-11-10 11:05 . 2009-11-10 11:02 142 ----a-w- c:\documents and settings\Tim.YOUR-0CDC4F5844\Local Settings\Application Data\fusioncache.dat
2009-11-10 11:03 . 2006-11-18 02:12 1681 --sha-r- c:\windows\system32\drivers\103C_HP_NTBK_HP Pavilion dv2000 (RG404UA#ABA)_YN_0Pavi_Q2CE6461VZF_E433352003_46_I30B5_SWistron_V62.46_BF.13_T061018_WXP2_L409_M959_J120_7AMD_8Turion 64 X2_91.61_#061117_N14E44311_(RG404UA#ABA)_XMOBILE_CN10_Z_2F.13.MRK
2009-11-10 09:31 . 2006-11-18 02:38 -------- d-----w- c:\program files\Windows Media Connect 2
2009-11-10 09:30 . 2006-11-18 02:39 -------- d-----w- c:\program files\Quickensetup
2009-11-10 09:30 . 2006-11-18 02:19 -------- d-----w- c:\program files\RGB
2009-11-10 09:28 . 2006-11-18 02:22 -------- d-----w- c:\program files\NetWaiting
2009-11-10 09:28 . 2006-11-18 02:36 -------- d-----w- c:\program files\music_now
2009-11-10 09:27 . 2006-11-18 02:38 -------- d-----w- c:\program files\Microsoft Office Trial Wizard
2009-11-10 09:26 . 2006-11-18 01:54 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-11-10 09:19 . 2006-11-18 02:37 -------- d-----w- c:\program files\DivX
2009-11-10 09:19 . 2006-11-18 02:13 -------- d-----w- c:\program files\Encarta Online
2009-11-10 09:19 . 2006-11-18 01:59 -------- d-----w- c:\program files\CONEXANT
2009-11-10 09:18 . 2006-11-18 01:32 -------- d-----w- c:\program files\Common Files\SureThing Shared
2009-11-10 09:18 . 2006-11-18 01:32 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-11-10 09:17 . 2006-11-18 02:54 -------- d-----w- c:\program files\Common Files\LightScribe
2009-11-10 09:10 . 2006-11-18 01:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Sonic
2009-11-10 09:10 . 2009-11-10 11:00 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Symantec
2009-11-10 09:10 . 2006-11-18 02:08 -------- d-----w- c:\documents and settings\Administrator\Application Data\Symantec
2009-10-29 07:45 . 2006-03-16 04:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-24 22:06 . 2009-10-24 12:42 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-10-21 06:00 . 2006-03-16 04:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 06:00 . 2006-03-16 04:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 14:58 . 2006-03-16 04:00 263552 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:53 . 2006-03-16 04:00 266752 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:54 . 2006-03-16 04:00 69632 ----a-w- c:\windows\system32\raschap.dll
2009-10-12 13:54 . 2006-03-16 04:00 112128 ----a-w- c:\windows\system32\rastls.dll
2009-03-21 14:18 . 2006-03-16 04:00 29696 --sha-w- c:\windows\system32\config\systemprofile\ntload.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 458752]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-24 7569408]
"MsmqIntCert"="mqrt.dll" [2009-06-25 177152]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 61952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-06-17 794713]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-07-12 102400]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-12 81920]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 163840]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2006-01-27 40960]
"RecGuard"="c:\windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
"Reminder"="c:\windows\CREATOR\Remind_XP.exe" [2006-02-09 643072]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"McAfee Backup"="c:\program files\McAfee\MBK\McAfeeDataBackup.exe" [2009-07-09 5134864]
"Dzevipataxuhiju"="c:\windows\uvaxuluqiz.dll" [2006-03-16 163840]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-12 249856]
c:\documents and settings\Tim\Start Menu\Programs\Startup\
LaunchU3.exe.lnk - c:\documents and settings\Tim\Application Data\Microsoft\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe [2007-9-14 1078]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
HP Pavilion Webcam Tray Icon.lnk - c:\program files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe [2007-1-14 102400]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-9-24 73728]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2006-9-19 960032]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2009-8-17 2043904]
WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2009-8-17 8919040]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli LO2pnt.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\McAfee\\VirusScan\\mcods.exe"=
"c:\\Program Files\\McAfee\\VirusScan\\mcvsmap.exe"=
"c:\\Program Files\\McAfee\\MSC\\mcinfo.exe"=
"c:\\WINDOWS\\ehome\\ehSched.exe"=
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [11/25/2009 2:13 PM 11520]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://m.www.yahoo.com/
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: mcafee.com
TCP: {D7F32DF7-1E24-46FC-A5F8-B294C7742EBF} = 193.104.110.38,4.2.2.1,68.87.64.150 68.87.75.198
TCP: {E8BB457B-AD5D-4B10-9C41-7B1C1F339B98} = 193.104.110.38,4.2.2.1
.
- - - - ORPHANS REMOVED - - - -
BHO-{45029581-4904-4af7-b019-f5ad2e8bd699} - zekizuma.dll
HKCU-Run-jckcuyyj - c:\documents and settings\Tim.YOUR-0CDC4F5844\Local Settings\Application Data\xgsdnr\iyjpsysguard.exe
HKLM-Run-notepad - c:\windows\system32\notepad.dll
HKLM-Run-jvkphb - c:\windows\system32\msmkkrqf.dll
HKLM-Run-guzemejon - c:\windows\system32\wijutopa.dll
HKLM-Run-luyahibefu - hugeloko.dll
SharedTaskScheduler-{1d5aeefa-3078-4987-925c-faca5280da9c} - c:\windows\system32\wijutopa.dll
SSODL-jarolejaw-{1d5aeefa-3078-4987-925c-faca5280da9c} - c:\windows\system32\wijutopa.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-20 13:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe?????? ???@???????????????@? ????W????????@???????@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,6d,2c,f9,66,b8,cc,54,45,a6,ce,a5,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,6d,2c,f9,66,b8,cc,54,45,a6,ce,a5,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(984)
c:\windows\LO2pnt.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2100)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\LO2pnt.dll
c:\windows\uvaxuluqiz.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\msdtc.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\mqsvc.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\dllhost.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\system32\wscntfy.exe
c:\windows\eHome\ehmsas.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
.
**************************************************************************
.
Completion time: 2009-12-20 13:33:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-20 18:33
Pre-Run: 69,734,539,264 bytes free
Post-Run: 70,189,723,648 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect /usepmtimer
- - End Of File - - A2BED45ED91ABCEE865E7B4B4D980B1A