this is the log. i followed the directions to disable the anit-virus but when it had to reboot the second time to finish then it came back on and i couldn't cut it off again because combofix was still running. if i need to redo it or do it different please let me know. thank you for your help once again.
ComboFix 10-01-16.04 - Compaq_Owner 01/17/2010 21:44:05.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.140 [GMT -6:00]
Running from: c:\documents and settings\Compaq_Owner\My Documents\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\s
c:\windows\system32\11478.exe
c:\windows\system32\15724.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\26500.exe
c:\windows\system32\6334.exe
c:\windows\system32\ps2.bat
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :p
.
((((((((((((((((((((((((( Files Created from 2009-12-18 to 2010-01-18 )))))))))))))))))))))))))))))))
.
2010-01-17 20:17 . 2010-01-17 20:17 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
2010-01-17 20:17 . 2010-01-07 22:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-17 20:17 . 2010-01-17 20:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-17 20:17 . 2010-01-07 22:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-17 20:17 . 2010-01-17 20:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-17 01:56 . 2010-01-17 01:56 388096 ----a-r- c:\documents and settings\Compaq_Owner\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-17 01:56 . 2010-01-17 01:56 -------- d-----w- c:\program files\TrendMicro
2010-01-16 20:26 . 2010-01-16 20:26 -------- d-----w- c:\program files\CCleaner
2010-01-16 20:18 . 2010-01-16 20:18 28360 ----a-w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-16 17:44 . 2010-01-16 17:44 -------- d-----w- c:\documents and settings\Janice\Local Settings\Application Data\Identities
2010-01-16 15:40 . 2010-01-16 15:40 -------- d-----w- c:\documents and settings\Janice\Application Data\AdobeUM
2010-01-16 15:40 . 2010-01-16 15:40 -------- d-----w- c:\documents and settings\Janice\Local Settings\Application Data\Adobe
2010-01-13 16:32 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 20:07 . 2010-01-12 20:07 -------- d-----w- c:\windows\system32\scripting
2010-01-12 20:07 . 2010-01-12 20:07 -------- d-----w- c:\windows\l2schemas
2010-01-12 20:07 . 2010-01-12 20:07 -------- d-----w- c:\windows\system32\en
2010-01-12 20:07 . 2010-01-12 20:07 -------- d-----w- c:\windows\system32\bits
2010-01-12 19:46 . 2010-01-12 19:46 -------- d-----w- c:\windows\EHome
2010-01-12 14:53 . 2010-01-12 14:53 -------- d-----w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Adobe
2010-01-12 14:53 . 2010-01-12 14:53 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\AdobeUM
2010-01-12 14:53 . 2010-01-12 14:53 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-10 01:26 . 2010-01-10 01:26 -------- d-----w- c:\documents and settings\Janice\Local Settings\Application Data\Yahoo
2010-01-10 01:22 . 2010-01-10 01:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-01-10 01:22 . 2009-06-20 08:04 607472 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2010-01-10 01:22 . 2010-01-10 01:22 -------- d-----w- c:\program files\Yahoo!
2010-01-10 00:51 . 2010-01-12 19:11 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2010-01-10 00:48 . 2010-01-10 00:48 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-10 00:45 . 2010-01-10 00:45 -------- d-----w- c:\documents and settings\All Users\Application Data\SiteAdvisor
2010-01-10 00:41 . 2009-11-04 22:54 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2010-01-10 00:41 . 2009-11-04 22:54 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2010-01-10 00:41 . 2009-11-04 22:54 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2010-01-10 00:41 . 2009-07-16 18:32 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2010-01-10 00:40 . 2010-01-10 00:41 -------- d-----w- c:\program files\Common Files\McAfee
2010-01-10 00:40 . 2010-01-10 00:40 -------- d-----w- c:\program files\McAfee.com
2010-01-10 00:40 . 2010-01-12 20:47 -------- d-----w- c:\program files\McAfee
2010-01-10 00:27 . 2009-11-04 22:53 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2010-01-10 00:22 . 2010-01-10 03:43 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2010-01-10 00:03 . 2010-01-10 20:10 -------- d-----w- c:\windows\SxsCaPendDel
2010-01-09 23:59 . 2010-01-09 23:59 -------- d-----w- c:\program files\ATT-RC
2010-01-09 23:16 . 2010-01-09 23:43 -------- d-----w- c:\documents and settings\Janice\Application Data\Motive
2010-01-09 23:16 . 2010-01-09 23:16 -------- d-----w- c:\program files\ATT-HSI
2010-01-09 23:16 . 2010-01-09 23:16 -------- d-----w- c:\program files\Common Files\Motive
2010-01-09 22:53 . 2010-01-10 00:03 -------- d-----w- c:\program files\SBC Yahoo!
2010-01-07 23:49 . 2004-08-04 04:29 73216 ------w- c:\windows\system32\drivers\atintuxx.sys
2010-01-07 22:26 . 2010-01-12 20:01 -------- d-----w- c:\windows\ServicePackFiles
2010-01-07 22:24 . 2010-01-07 22:24 -------- d-----w- c:\windows\ie8updates
2010-01-07 17:08 . 2010-01-07 17:08 -------- d-----w- c:\documents and settings\Janice\Local Settings\Application Data\Google
2010-01-07 13:47 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-01-07 13:47 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-01-07 13:47 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2010-01-07 13:47 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-01-07 13:47 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-01-07 13:46 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-01-07 13:46 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2010-01-07 13:44 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-01-07 13:44 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-01-07 13:44 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-01-07 05:07 . 2010-01-14 02:16 -------- d--h--w- c:\windows\$hf_mig$
2010-01-07 04:38 . 2010-01-07 04:38 -------- d-----w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\Google
2010-01-07 04:16 . 2010-01-07 04:16 -------- d-----w- c:\program files\Google
2010-01-07 04:14 . 2010-01-07 04:14 1956072 ----a-w- c:\documents and settings\Compaq_Owner\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdateax\fpupdateax.exe2010-01-06 23:53 . 2010-01-06 23:53 1956072 ----a-w- c:\documents and settings\Janice\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdateax\fpupdateax.exe2010-01-06 23:41 . 2010-01-06 23:41 -------- d-sh--w- c:\documents and settings\Janice\IECompatCache
2010-01-06 23:40 . 2010-01-06 23:40 -------- d-sh--w- c:\documents and settings\Janice\PrivacIE
2010-01-06 23:40 . 2010-01-18 03:54 182 ----a-w- c:\windows\system\hpsysdrv.DAT
2010-01-06 23:34 . 2004-08-04 12:00 82432 -c--a-w- c:\windows\system32\dllcache\ufat.dll
2010-01-06 23:33 . 2008-04-14 00:11 927504 ----a-w- c:\windows\system32\mfc40u.dll
2010-01-06 23:32 . 2008-04-14 00:11 32768 ----a-w- c:\windows\system32\dispex.dll
2010-01-06 23:24 . 2010-01-17 20:17 -------- d-----r- C:\Program Files
2010-01-06 23:22 . 2010-01-06 23:32 -------- d-----r- c:\documents and settings\All Users\Documents
2010-01-06 23:20 . 2010-01-18 03:44 -------- dcsh--r- c:\windows\system32\dllcache
2010-01-06 23:08 . 2010-01-06 23:08 -------- d-----w- c:\windows\Sun
2010-01-06 23:08 . 2010-01-06 23:08 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-06 23:07 . 2010-01-06 23:07 152576 ----a-w- c:\documents and settings\Compaq_Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-06 23:07 . 2010-01-06 23:07 79488 ----a-w- c:\documents and settings\Compaq_Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-06 22:57 . 2010-01-06 22:57 -------- d-sh--w- c:\documents and settings\Compaq_Owner\PrivacIE
2010-01-06 22:54 . 2010-01-06 22:54 -------- d-sh--w- c:\documents and settings\Compaq_Owner\IETldCache
2010-01-06 22:52 . 2009-01-08 00:21 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2010-01-06 22:52 . 2010-01-06 22:52 -------- dc-h--w- c:\windows\ie8
2010-01-06 22:48 . 2010-01-06 22:48 -------- d-sh--w- c:\documents and settings\Compaq_Owner\UserData
2010-01-06 22:48 . 2008-04-14 00:12 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-01-06 22:44 . 2004-08-09 09:03 128 ----a-w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\fusioncache.dat
2010-01-06 22:44 . 2004-08-10 23:45 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Symantec
2010-01-06 22:44 . 2004-08-09 09:03 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\ApplicationHistory
2010-01-06 22:44 . 2004-08-09 08:57 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SampleView
2010-01-06 22:44 . 2004-08-09 08:55 -------- d-----w- c:\windows\system32\config\systemprofile\WINDOWS
2010-01-06 22:44 . 2004-08-09 06:12 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
2010-01-06 22:43 . 2002-11-21 16:57 204800 ----a-w- c:\windows\system32\IVIresizeW7.dll
2010-01-06 22:43 . 2002-11-21 16:57 200704 ----a-w- c:\windows\system32\IVIresizeA6.dll
2010-01-06 22:43 . 2002-11-21 16:57 192512 ----a-w- c:\windows\system32\IVIresizeP6.dll
2010-01-06 22:43 . 2002-11-21 16:57 192512 ----a-w- c:\windows\system32\IVIresizeM6.dll
2010-01-06 22:43 . 2002-11-21 16:57 188416 ----a-w- c:\windows\system32\IVIresizePX.dll
2010-01-06 22:43 . 2002-11-21 16:57 20480 ----a-w- c:\windows\system32\IVIresize.dll
2010-01-06 22:43 . 2010-01-06 22:43 -------- d-----w- c:\program files\InterVideo
2010-01-06 22:42 . 2004-08-09 08:55 -------- d-----w- c:\documents and settings\Default User\WINDOWS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-12 20:17 . 2004-08-09 05:44 81971 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-01-12 20:16 . 2010-01-12 20:16 98304 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\PluginCtrl.dll
2010-01-12 20:16 . 2010-01-12 20:16 159744 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\PCHButton.exe
2010-01-12 20:16 . 2010-01-12 20:16 28672 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\InetWrap.dll
2010-01-12 20:16 . 2010-01-12 20:16 434176 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\jsharpde\motivede.dll
2010-01-12 20:16 . 2010-01-12 20:16 139264 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\ContentUpdater.exe
2010-01-12 20:16 . 2010-01-12 20:16 69632 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\msxmlwrapper.dll
2010-01-12 20:16 . 2010-01-12 20:16 5632 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\jsharpde\GUI.dll
2010-01-12 20:16 . 2010-01-12 20:16 69632 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\jsharpde\msxmlwrapper.dll
2010-01-12 20:16 . 2010-01-12 20:16 155877 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\jsharpde\js.zip
2010-01-12 20:16 . 2010-01-12 20:16 344064 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\jsharpde\api.dll
2010-01-12 20:16 . 2010-01-12 20:16 3072 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\jsharpde\pchealthde.exe
2010-01-12 20:14 . 2010-01-12 20:14 315392 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\pchmsxml.dll
2010-01-12 20:14 . 2010-01-12 20:14 4096 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\winverifytrustwrapper.dll
2010-01-12 20:14 . 2010-01-12 20:14 212992 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\jsharpde\jsharpinterp.dll
2010-01-12 20:14 . 2010-01-12 20:14 26572 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\jsharpde\INV16.dll
2010-01-12 20:14 . 2010-01-12 20:14 307200 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Presario\XPHWWRF4Duet\plugin\bin\pchnotify.exe
2010-01-09 23:15 . 2004-08-09 09:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Motive
2010-01-06 23:08 . 2004-08-09 06:12 -------- d-----w- c:\program files\Java
2010-01-06 22:49 . 2004-08-09 09:08 -------- d-----w- c:\program files\Easy Internet signup
2010-01-06 22:47 . 2010-01-06 22:47 4200 --sha-r- c:\windows\system32\drivers\HP_PJ530AA-ABa SR1214NX NA441_YC_Pres_QCNY438_E44NAheRAS2_4_IKelut_SASUSTek Computer INC._V2.02_B3.11_T040902_WXH2_L409_M448_J80_7AMD_8Athlon XP 2900+_92_111063044_N11063065_P_Z11C1048C_K_A11063059_U11063038_G11067205.MRK
2010-01-06 22:47 . 2004-08-09 06:47 -------- d-----w- c:\program files\Microsoft Works
2010-01-06 22:43 . 2004-08-09 08:51 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-21 15:51 . 2004-08-09 04:28 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-04 22:54 . 2009-11-04 22:54 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-10-29 07:45 . 2004-08-09 04:28 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-09 04:28 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-09 04:28 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-01-07 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-06 149280]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2004-04-22 286720]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472]
"VTTimer"="VTTimer.exe" [2004-10-22 53248]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-30 88363]
"PS2"="c:\windows\system32\ps2.exe" [2003-09-13 98304]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 57344]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - c:\program files\Compaq Connections\6750491\Program\Compaq Connections.exe [2004-8-9 16423]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\ATT-HSI\\McciBrowser.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [1/9/2010 6:44 PM 93320]
.
Contents of the 'Scheduled Tasks' folder
2010-01-06 c:\windows\Tasks\Easy Internet Sign-up.job
- c:\program files\Easy Internet signup\HPSdpApp.exe [2004-06-22 04:19]
2010-01-10 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-01-10 18:22]
2010-01-10 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2010-01-10 18:22]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/uDefault_Search_URL =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktopmSearch Bar =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktopIE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-17 21:54
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(308)
c:\windows\system32\WININET.dll
c:\docume~1\COMPAQ~1\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\McAfee\MPF\MPFSrv.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\system32\VTTimer.exe
c:\windows\AGRSMMSG.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\ALCXMNTR.EXE
c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe
.
**************************************************************************
.
Completion time: 2010-01-17 21:59:25 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-18 03:59
Pre-Run: 72,650,883,072 bytes free
Post-Run: 73,176,215,552 bytes free
- - End Of File - - E516385BFB8B64B93EE5E920F9B11C2E