Here is the Combofix-quarantined-files.txt file:
2005-08-12 14:46 139 --a--c--- C:\Qoobox\Quarantine\C\Program Files\DNS\urls.dat.vir
2005-10-20 09:06 2 --a--c--- C:\Qoobox\Quarantine\C\Program Files\DNS\version.txt.vir
2005-10-28 21:50 18 --a--c--- C:\Qoobox\Quarantine\C\Program Files\DNS\affid.dat.vir
2005-10-28 21:50 40 --a--c--- C:\Qoobox\Quarantine\C\Program Files\DNS\uid.dat.vir
2005-10-28 21:56 12 --a--c--- C:\Qoobox\Quarantine\C\Program Files\DNS\regexpDate.dat.vir
2005-10-28 21:56 538 --a--c--- C:\Qoobox\Quarantine\C\Program Files\DNS\regexp.dat.vir
2005-11-04 15:22 2217897 --a--c--- C:\Qoobox\Quarantine\C\Documents and Settings\David.BILL\Application Data\Install.dat.vir
2007-10-11 18:12 0 --a------ C:\Qoobox\Quarantine\C\WINDOWS\gf1002.cnf3.vir
2007-10-12 04:01 5 --a------ C:\Qoobox\Quarantine\C\WINDOWS\gf1002.cnf2.vir
2007-12-11 20:57 3 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ctl_w32.sys.vir
2008-01-17 13:11 0 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ksvcl.dll.vir
2008-01-17 13:11 606 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\kcopt.dll.vir
2008-01-18 14:45 39424 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ssqnnnl.dll.vir
2008-01-18 14:46 15360 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\drvremr.dll.vir
2008-01-19 15:18 76352 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\vdhvdpxn.dll.vir
2008-01-19 15:21 163904 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mkhyyvev.dll.vir
2008-01-19 15:21 87104 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\unyhgyda.dll.vir
2008-01-20 05:51 42496 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\17467.exe.vir
2008-01-20 05:52 42496 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\KernelDrv.exe.vir
2008-01-20 05:54 280064 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\scchk32.exe.vir
2008-01-20 21:09 1073712 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\adyghynu.ini.vir
2008-01-21 11:19 76352 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\evjyxfvv.dll.vir
2008-01-21 11:19 88640 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\blbyareh.dll.vir
2008-01-21 14:54 255 --a------ C:\Qoobox\Quarantine\C\WINDOWS\cookies.ini.vir
2008-01-22 12:52 8836 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ttutv.ini.vir
2008-01-22 12:52 8836 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\ttutv.ini2.vir
2008-01-25 14:16 143 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\mcrh.tmp.vir
2008-01-29 16:04 1136777 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\herayblb.ini.vir
2008-01-30 16:13 1034 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_CTL_W32.reg.dat
2008-01-30 16:13 1034 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_SMTPDRV.reg.dat
2008-01-30 16:13 1138 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_NM.reg.dat
2008-01-30 16:13 1148 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_RUNTIME.reg.dat
2008-01-30 16:13 1158 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_RUNTIME2.reg.dat
2008-01-30 16:13 1160 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_NPF.reg.dat
2008-01-30 16:13 1178 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_INR48.reg.dat
2008-01-30 16:13 2474 --a------ C:\Qoobox\Quarantine\Registry_backups\services_Inr48.reg.dat
2008-01-30 16:13 2556 --a------ C:\Qoobox\Quarantine\Registry_backups\services_mp32.reg.dat
2008-01-30 16:13 5080 --a------ C:\Qoobox\Quarantine\Registry_backups\services_nm.reg.dat
2008-01-30 16:13 758 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_GB.reg.dat
2008-01-30 16:13 870 --a------ C:\Qoobox\Quarantine\Registry_backups\services_ctl_w32.reg.dat
2008-01-30 16:13 876 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_LANMANDRV.reg.dat
2008-01-30 16:13 896 --a------ C:\Qoobox\Quarantine\Registry_backups\services_smtpdrv.reg.dat
2008-01-30 16:14 54764 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\dxdss.sys.vir
2008-01-30 16:14 584 --a------ C:\Qoobox\Quarantine\catchme.log
2008-01-30 16:14 64820 --a------ C:\Qoobox\Quarantine\catchme2008-01-30_162125.42.zip
2008-01-30 16:15 10701 --a------ C:\Qoobox\Quarantine\C\cf\errdbg.dat.vir
2008-01-30 16:16 25984 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\Inr48.sys.vir
2008-01-30 16:19 0 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\6_exception.nls.vir
Below is the logfile from running ComboFix with CFScript:
ComboFix 08-01-30.1 - Bill 2008-02-04 11:43:41.3 - NTFSx86
Running from: C:\Documents and Settings\Bill\Desktop\cf.exe
Command switches used :: C:\Documents and Settings\Bill\Desktop\CFScript.txt
FILE
C:\WINDOWS\system32\drvrem.dll
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\8_exception.nls
C:\WINDOWS\system32\drivers\Ejn04.sys
.
---- Previous Run -------
.
C:\WINDOWS\system32\drvrem.dll
C:\WINDOWS\system32\drivers\Yei50.sys
C:\WINDOWS\system32\drvrem.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_NPF
-------\LEGACY_SMTPDRV
-------\LEGACY_YEI50
-------\smtpdrv
-------\Yei50
-------\LEGACY_EJN04
-------\LEGACY_NPF
-------\Ejn04
((((((((((((((((((((((((( Files Created from 2008-01-04 to 2008-02-04 )))))))))))))))))))))))))))))))
.
2008-02-04 11:53 . 2008-02-04 11:53 0 --a------ C:\WINDOWS\system32\3_exception.nls
2008-02-01 17:30 . 2002-07-17 09:20 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2008-02-01 17:30 . 2002-07-17 08:53 16,877 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2008-02-01 17:30 . 2002-07-17 16:22 5,600 --a------ C:\WINDOWS\system\WINASPI.DLL
2008-02-01 17:30 . 2002-07-17 16:22 4,672 --a------ C:\WINDOWS\system\WOWPOST.EXE
2008-02-01 17:16 . 2008-02-01 17:16 <DIR> d-------- C:\adaptec
2008-01-31 20:58 . 2008-01-31 20:58 1,590,379 --a------ C:\cf.exe
2008-01-31 18:25 . 2008-01-31 18:25 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-01-28 21:03 . 2008-01-29 15:59 <DIR> d-------- C:\ComboFix
2008-01-26 10:56 . 2008-01-26 10:56 206 --a------ C:\WINDOWS\wininit.ini
2008-01-25 16:42 . 2008-01-25 16:42 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-25 16:00 . 2008-01-25 16:00 <DIR> d-------- C:\Documents and Settings\Bill\Application Data\HouseCall 6.6
2008-01-25 15:42 . 2008-01-25 15:42 <DIR> d-------- C:\Documents and Settings\Bill\.housecall6.6
2008-01-24 14:00 . 2008-01-25 14:51 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-24 13:57 . 2008-01-25 15:24 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-01-24 13:10 . 2008-02-01 17:57 <DIR> d-------- C:\Documents and Settings\Bill\Application Data\Lavasoft
2008-01-21 16:03 . 2008-02-04 11:51 2,444 --a------ C:\WINDOWS\system32\Config.MPF
2008-01-18 16:36 . 2008-01-20 05:51 15,360 --a------ C:\WINDOWS\system32\ctfmon.exe
2008-01-18 14:46 . 2008-01-18 14:59 2 --a------ C:\-1943412827
2008-01-17 16:36 . 2008-01-17 16:36 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2008-01-16 13:58 . 2008-02-04 10:47 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-16 13:58 . 2008-01-16 13:58 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-09 12:44 . 2007-11-07 04:26 721,920 --a------ C:\WINDOWS\system32\lsasrv.dll
2008-01-09 12:44 . 2007-10-30 12:20 360,064 --a------ C:\WINDOWS\system32\drivers\tcpip.sys
2008-01-07 20:16 . 2008-01-07 20:16 630,784 --a------ C:\WINDOWS\system32\divxdec.ax
2008-01-04 16:59 . 2008-01-20 05:51 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2008-01-04 16:59 . 2008-01-04 16:59 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
2008-01-04 16:58 . 2008-01-04 16:58 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-01-04 16:58 . 2008-01-04 16:58 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2008-01-04 16:58 . 2008-01-04 16:58 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2008-01-04 16:56 . 2008-01-04 16:56 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-01-04 16:56 . 2008-01-04 16:56 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-02 20:16 --------- d-----w C:\Program Files\BitTorrent
2008-02-01 22:57 --------- d-----w C:\Program Files\Lavasoft
2008-01-31 16:28 --------- d-----w C:\Program Files\XoftSpySE
2008-01-24 00:07 --------- d-----w C:\Program Files\McAfee.com
2008-01-22 05:11 --------- d-----w C:\Program Files\Replay AV 8
2008-01-22 05:10 --------- d-----w C:\Program Files\eMule
2008-01-21 21:00 --------- d-----w C:\Program Files\McAfee
2008-01-20 10:42 99,840 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\HelpHost.exe
2008-01-20 10:42 768,512 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\helpctr.exe
2008-01-20 10:42 743,936 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\helpsvc.exe
2008-01-20 10:42 35,328 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\notiflag.exe
2008-01-20 10:42 18,944 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\hscupd.exe
2008-01-20 10:24 94,208 ----a-r C:\WINDOWS\SM1bg.exe
2008-01-20 10:24 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-01-20 10:24 69,120 ----a-w C:\WINDOWS\notepad.exe
2008-01-20 10:24 32,768 ----a-w C:\WINDOWS\slrundll.exe
2008-01-20 10:24 306,688 ----a-w C:\WINDOWS\IsUninst.exe
2008-01-20 10:24 283,648 ----a-w C:\WINDOWS\winhlp32.exe
2008-01-20 10:24 266,240 -c--a-r C:\WINDOWS\SM1nint.exe
2008-01-20 10:24 25,600 -c--a-w C:\WINDOWS\twunk_32.exe
2008-01-20 10:24 18,944 -c--a-w C:\WINDOWS\ALI.EXE
2008-01-20 10:24 15,360 -c--a-w C:\WINDOWS\TASKMAN.EXE
2008-01-20 10:24 146,432 ----a-w C:\WINDOWS\regedit.exe
2008-01-20 10:24 14,848 -c--a-w C:\WINDOWS\MAGIC.EXE
2008-01-20 10:24 10,752 ----a-w C:\WINDOWS\hh.exe
2008-01-20 03:15 --------- d-----w C:\Program Files\QuickTime
2008-01-19 23:53 1,033,216 ----a-w C:\WINDOWS\explorer.exe
2008-01-18 12:54 --------- d-----w C:\Documents and Settings\Bill\Application Data\BitTorrent
2008-01-17 20:37 9,216 ----a-w C:\flashsaver6.dat
2008-01-11 21:19 --------- d-----w C:\Program Files\WM Recorder 10.2
2008-01-10 15:44 --------- d-----w C:\Program Files\DivX
2008-01-10 08:06 21,760 ----a-w C:\WINDOWS\Puy50.sys
2008-01-06 19:27 --------- d-----w C:\Program Files\MegaSpoof
2008-01-04 21:58 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-01-04 02:14 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee
2008-01-04 02:12 --------- d-----w C:\Documents and Settings\Bill\Application Data\McAfee
2008-01-03 18:51 --------- d-----w C:\Program Files\Common Files\McAfee
2008-01-01 21:11 21,760 ----a-w C:\WINDOWS\Puy50(2).sys
2008-01-01 15:39 21,760 ----a-w C:\WINDOWS\Puy50(3).sys
2008-01-01 15:18 21,760 ----a-w C:\WINDOWS\Puy50(4).sys
2007-12-20 17:22 21,760 ----a-w C:\WINDOWS\system32\drivers\Puy50.sys
2007-12-19 00:57 --------- d-----w C:\Program Files\TorrentSeek
2007-12-19 00:47 --------- d-----w C:\Program Files\Digital Locker Assistant
2007-12-14 15:20 --------- d-----w C:\Program Files\Microsoft Broadband Networking
2007-12-04 20:44 23,600 ----a-w C:\WINDOWS\system32\drivers\TVICHW32.SYS
2007-09-24 15:26 27,704 ----a-w C:\Documents and Settings\Bill\Application Data\GDIPFONTCACHEV1.DAT
2005-03-05 02:58 70,472 -c--a-w C:\Documents and Settings\WEL\Application Data\GDIPFONTCACHEV1.DAT
2003-08-27 22:19 36,963 -c--a-r C:\Program Files\Common Files\SM1updtr.dll
2007-03-09 08:12 27,648 --sha-w C:\WINDOWS\system32\AVSredirect.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Inr48.sys]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-05-11 03:06 40048 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
-ra------ 2007-03-01 10:37 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
--a------ 2008-01-19 21:28 5308416 C:\Program Files\eMule\emule.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
--a------ 2008-01-19 21:36 241664 C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2008-01-19 21:36 49152 c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
--a------ 2008-01-20 06:00 176128 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb12.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-07-10 09:18 270648 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-01-19 22:04 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-19 22:15 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
--a------ 2008-01-19 22:27 1695744 C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SM1BG]
-ra------ 2008-01-20 05:24 94208 C:\WINDOWS\SM1BG.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"rpcapd"=3 (0x3)
"Pml Driver HPZ12"=3 (0x3)
"MpfService"=2 (0x2)
"McSysmon"=2 (0x2)
"McShield"=2 (0x2)
"McRedirector"=2 (0x2)
"mcpromgr"=2 (0x2)
"McODS"=2 (0x2)
"McNASvc"=2 (0x2)
"mcmscsvc"=2 (0x2)
"mcmispupdmgr"=2 (0x2)
"McAfee HackerWatch Service"=2 (0x2)
"iPod Service"=3 (0x3)
"hpdj01"=2 (0x2)
"gusvc"=2 (0x2)
"Emproxy"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
.
Contents of the 'Scheduled Tasks' folder
"2008-01-16 21:56:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-15 06:02:43 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-01-03 18:46:41 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-01-22 14:12:37 C:\WINDOWS\Tasks\RegCure Program Check.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-01-17 17:04:55 C:\WINDOWS\Tasks\RegCure.job"
- C:\Program Files\RegCure\RegCure.exe
"2008-01-22 14:12:35 C:\WINDOWS\Tasks\XoftSpySE 2.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
"2008-01-22 14:08:38 C:\WINDOWS\Tasks\XoftSpySE.job"
- C:\Program Files\XoftSpySE\XoftSpy.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-04 11:56:23
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
.
**************************************************************************
.
Completion time: 2008-02-04 12:03:44 - machine was rebooted [Bill]
ComboFix-quarantined-files.txt 2008-02-04 17:03:39
ComboFix2.txt 2008-01-30 21:28:47
.
2008-01-11 08:02:20 --- E O F ---
Here's a new Hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:14:04 PM, on 2/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?linkid=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: NXIECatcher Class - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files\Xi\NetXfer\NXIEHelper.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: TorrentSeek toolbar - {6bcb43af-a20f-4996-8860-48f511a222db} - C:\Program Files\TorrentSeek\tbTorr.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra 'Tools' menuitem: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} (QOLCheck Control) -
https://www.select2perform.com/cabs/QOLCheck.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} -
http://h20264.www2.hp.com/ediags/dd/instal...nosticsxp2k.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupd...b?1199982601343
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) -
https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) -
http://secure2.comned.com/signuptemplates/...login-devel.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -
https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/...211/mcfscan.cab
O23 - Service: AppMgmt - Apple, Inc. - (no file)
O23 - Service: ASP.NET State Service (aspnet_state) - Apple, Inc. - (no file)
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McNASvc - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
--
End of file - 6562 bytes
I do not have another computer to use for downloads, but if it's critical to getting this resolved, I'll try to borrow one.