I was able to successfully run ComboFix. Here is the log:
ComboFix 09-09-28.01 - Jessica 09/28/2009 21:25.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.382.210 [GMT -4:00]
Running from: c:\documents and settings\Jessica\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\aoqwlrag.exe
C:\cqfuy.exe
C:\ddqud.exe
c:\docume~1\Jessica\LOCALS~1\Temp\lsass.exe
c:\documents and settings\All Users\Application Data\alohuf.vbs
c:\documents and settings\All Users\Desktop\nudetube.com.lnk
c:\documents and settings\All Users\Desktop\pornotube.com.lnk
c:\documents and settings\All Users\Desktop\youporn.com.lnk
c:\documents and settings\All Users\Documents\ewifebury.inf
c:\documents and settings\All Users\Documents\ytemibi.exe
c:\documents and settings\Jessica\Application Data\exyhazux.vbs
c:\documents and settings\Jessica\Application Data\lizkavd.exe
c:\documents and settings\Jessica\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk
c:\documents and settings\Jessica\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk
c:\documents and settings\Jessica\Application Data\seres.exe
c:\documents and settings\Jessica\Application Data\svcst.exe
c:\documents and settings\Jessica\Cookies\guqagokid.scr
c:\documents and settings\Jessica\Local Settings\Application Data\nigama.vbs
c:\documents and settings\Jessica\Local Settings\Application Data\unataxype.vbs
c:\documents and settings\Jessica\Local Settings\Application Data\xofoh.inf
c:\documents and settings\Jessica\Local Settings\Temporary Internet Files\osif.db
c:\documents and settings\Jessica\Start Menu\Programs\AntivirusPro_2010
c:\documents and settings\Jessica\Start Menu\Programs\AntivirusPro_2010\AntivirusPro_2010.lnk
c:\documents and settings\Jessica\Start Menu\Programs\AntivirusPro_2010\Uninstall.lnk
C:\hxlqib.exe
C:\p2hhr.bat
C:\pkusq.exe
c:\program files\AntivirusPro_2010
c:\program files\AntivirusPro_2010\AntivirusPro_2010.cfg
c:\program files\AntivirusPro_2010\AVEngn.dll
c:\program files\AntivirusPro_2010\data\daily.cvd
c:\program files\AntivirusPro_2010\htmlayout.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcm80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcp80.dll
c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcr80.dll
c:\program files\AntivirusPro_2010\pthreadVC2.dll
c:\program files\AntivirusPro_2010\Uninstall.exe
c:\program files\AntivirusPro_2010\wscui.cpl
c:\program files\Common Files\bapulikal.bat
c:\program files\Protection System
c:\program files\Protection System\core.cga
c:\program files\Protection System\coreext.dll
c:\program files\Protection System\firewall.dll
c:\program files\Protection System\help.ico
c:\program files\Protection System\psystem.exe
c:\program files\Protection System\uninstall.exe
c:\program files\Windows Police Pro
c:\program files\Windows Police Pro\msvcm80.dll
c:\program files\Windows Police Pro\msvcp80.dll
c:\program files\Windows Police Pro\msvcr80.dll
c:\program files\Windows Police Pro\tmp\dbsinit.exe
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\emusu._dl
c:\windows\Installer\128efd.msi
c:\windows\jymicyh.vbs
c:\windows\system32\config\systemprofile\protect.dll
c:\windows\system32\dahihiwi.exe
c:\windows\system32\doby.scr
c:\windows\system32\drivers\UACotowylvrgi.sys
c:\windows\system32\hafedeku.dll
c:\windows\system32\hopawiki.exe
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\kofipulo.dll
c:\windows\system32\lipemeye.exe
c:\windows\system32\muzobapu.dll.tmp
c:\windows\system32\nahilifo.dll
c:\windows\system32\nqpibfqp.dll
c:\windows\system32\nzFIu3h78di.dll
c:\windows\system32\regoyivu.dll
c:\windows\system32\UACafulkrjgxi.dll
c:\windows\system32\UAChbahmplvbb.dll
c:\windows\system32\UACidljljlppf.db
c:\windows\system32\uacinit.dll
c:\windows\system32\UACkioettftiv.dll
c:\windows\system32\UAClrxubfwqpl.dll
c:\windows\system32\UACmsqrrbjteh.dat
c:\windows\system32\UACtbafbwkqpp.dll
c:\windows\system32\uactmp.db
c:\windows\system32\vafiyene.exe
c:\windows\system32\vasidifu.exe
c:\windows\system32\verazubo.dll.tmp
c:\windows\system32\wbem\proquota.exe
c:\windows\system32\wowidezo.dll.tmp
c:\windows\system32\zakisohi.exe
c:\windows\Temp\1654329584.exe
c:\windows\tetybano.pif
C:\yhjj.exe
c:\windows\system32\proquota.exe . . . is missing!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
-------\Legacy_UACd.sys
-------\Legacy_usbdriver
-------\Service_usbdriver
((((((((((((((((((((((((( Files Created from 2009-08-28 to 2009-09-29 )))))))))))))))))))))))))))))))
.
2009-09-28 22:36 . 2009-09-28 22:36 -------- d-----w- c:\documents and settings\Jessica\Application Data\McAfee
2009-09-28 18:36 . 2009-09-28 18:36 -------- d-----w- c:\program files\ERUNT
2009-09-28 00:27 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-28 00:27 . 2009-09-28 02:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-28 00:27 . 2009-09-28 00:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-28 00:27 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-28 00:03 . 2009-09-28 00:03 -------- d-----w- c:\program files\Trend Micro
2009-09-23 21:25 . 2009-09-28 20:42 1570 ----a-w- c:\windows\system32\nqpibfqp.dat
2009-09-23 21:19 . 2009-09-27 23:51 -------- d-----w- c:\documents and settings\All Users\Application Data\11818124
2009-09-23 21:19 . 2009-09-23 21:19 -------- d-----w- c:\documents and settings\All Users\Application Data\11818284
2009-09-23 21:19 . 2009-09-23 21:19 155267 ----a-w- c:\windows\system32\vgcdtasa.dll
2009-09-23 20:25 . 2009-09-27 20:42 0 ----a-w- c:\windows\system32\drivers\a0367ed0.sys
2009-09-23 20:23 . 2009-09-23 20:26 22528 --sha-w- c:\windows\system32\calc.dll
2009-09-23 20:22 . 2009-09-23 20:22 143368 ------w- C:\mlhlsvq.exe
2009-09-17 19:18 . 2009-09-17 19:18 -------- d-----w- C:\Webroot
2009-09-13 03:21 . 2005-05-19 18:06 102912 ----a-w- c:\windows\system32\islzma.dll
2009-09-13 03:21 . 2009-09-13 03:21 -------- d-----w- c:\program files\Webroot
2009-09-13 03:21 . 2009-09-13 03:21 -------- d-----w- c:\documents and settings\Jessica\Application Data\Webroot
2009-09-13 03:21 . 2005-07-06 20:16 428032 ----a-w- c:\windows\WRServices.dll
2009-09-04 07:10 . 2009-09-04 07:12 -------- d-----w- C:\18bed3b494b7996a92
2009-09-04 07:09 . 2009-09-04 07:43 -------- d-----w- c:\windows\SxsCaPendDel
2009-09-01 07:04 . 2009-09-01 07:04 -------- d-----w- c:\windows\ServicePackFiles
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-29 01:02 . 2007-08-08 21:21 -------- d-----w- c:\program files\Common Files\McAfee
2009-09-29 01:02 . 2007-08-08 21:15 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-09-29 01:02 . 2007-08-08 21:20 -------- d-----w- c:\program files\McAfee
2009-09-28 21:38 . 2007-08-08 21:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-09-27 20:38 . 2009-06-27 20:38 50176 --sha-w- c:\windows\system32\gazizisa.dll
2009-09-23 21:20 . 2009-09-23 21:20 17314 ----a-w- c:\program files\Common Files\ekogep._sy
2009-09-16 20:03 . 2008-08-06 18:46 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-13 03:26 . 2007-08-08 21:43 -------- d-----w- c:\program files\IrfanView
2009-09-12 02:57 . 2007-10-19 02:18 -------- d-----w- c:\documents and settings\Jessica\Application Data\Move Networks
2009-08-05 09:11 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:53 . 2004-08-04 12:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-07-29 04:53 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-17 18:55 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-04 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-08 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeper.exe" [2005-07-06 2972672]
c:\documents and settings\Jessica\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
backup=c:\windows\pss\Microsoft Find Fast.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Office Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Office Startup.lnk
backup=c:\windows\pss\Office Startup.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Jessica^Start Menu^Programs^Startup^Webshots.lnk]
path=c:\documents and settings\Jessica\Start Menu\Programs\Startup\Webshots.lnk
backup=c:\windows\pss\Webshots.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"Viewpoint Manager Service"=2 (0x2)
"MpfService"=2 (0x2)
"McSysmon"=3 (0x3)
"McShield"=2 (0x2)
"McProxy"=2 (0x2)
"McODS"=3 (0x3)
"McNASvc"=2 (0x2)
"mcmscsvc"=2 (0x2)
"LVSrvLauncher"=2 (0x2)
"LVPrcSrv"=2 (0x2)
"iPod Service"=3 (0x3)
"idsvc"=3 (0x3)
"hpqwmi"=3 (0x3)
"gusvc"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Java\\jre1.5.0_02\\bin\\javaw.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/20/2009 7:38 AM 24652]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [8/6/2007 9:18 PM 231424]
S1 a0367ed0;a0367ed0;c:\windows\system32\drivers\a0367ed0.sys [9/23/2009 4:25 PM 0]
S2 antippolice_;AntiPol;c:\windows\svchast.exe --> c:\windows\svchast.exe [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder
2009-09-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]
2009-09-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-08-08 00:39]
2009-09-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-08-08 17:32]
2009-09-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-08-08 17:32]
.
.
------- Supplementary Scan -------
.
uStart Page =
https://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&bsv=zpwhtygjntrz&scc=1<mpl=default<mplcache=2&hl=enuInternet Settings,ProxyOverride = *.local
IE: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
Trusted Zone: internet
Trusted Zone: mcafee.com
.
- - - - ORPHANS REMOVED - - - -
BHO-{142bbaa6-82a0-4375-a9c3-e02096bdff2f} - vujigami.dll
HKCU-Run-Protection System - c:\program files\Protection System\psystem.exe
HKCU-Run-Aim6 - (no file)
HKLM-Run-sabukivuw - c:\windows\system32\hutijezu.dll
HKLM-Run-tefehunefu - hafedeku.dll
SharedTaskScheduler-{1236452b-611f-4720-ab75-9e12c7906992} - c:\windows\system32\norefose.dll
SharedTaskScheduler-{931e46ed-0ae0-44cc-be27-173f9d4f4708} - c:\windows\system32\hutijezu.dll
SSODL-mozitudab-{1236452b-611f-4720-ab75-9e12c7906992} - c:\windows\system32\norefose.dll
SSODL-mowigabom-{931e46ed-0ae0-44cc-be27-173f9d4f4708} - c:\windows\system32\hutijezu.dll
AddRemove-protection system - c:\program files\Protection System\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-28 21:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\windows\TEMP\mc22.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(660)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3828)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Webroot\Spy Sweeper\WRSSSDK.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2009-09-29 21:42 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-29 01:41
Pre-Run: 45,570,519,040 bytes free
Post-Run: 46,642,593,792 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
337 --- E O F --- 2009-09-09 07:02