Ok, I ran the program after disabling everything. However, when it restarted there was a norton antivirus question asking me if I wanted to allow psexec.cfexe to run. I googled it and denied it. Apparently it's linked to this rogue antivirus program that tried to get me. Here's the log.
ComboFix 08-11-19.08 - HP_Administrator 2008-11-20 13:09:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.401 [GMT -5:00]
Running from: c:\documents and settings\HP_Administrator\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
c:\documents and settings\HP_Administrator\Local Settings\Temporary Internet Files\curuk.reg
c:\documents and settings\HP_Administrator\Local Settings\Temporary Internet Files\enylub.lib
c:\documents and settings\HP_Administrator\Local Settings\Temporary Internet Files\osuk.lib
c:\documents and settings\HP_Administrator\Local Settings\Temporary Internet Files\oxorepe.lib
c:\documents and settings\MCX1\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000010_.tmp.dll
c:\windows\system32\disk.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-10-20 to 2008-11-20 )))))))))))))))))))))))))))))))
.
2008-11-18 21:14 . 2008-11-18 21:14 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-18 21:14 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-18 21:14 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-18 20:47 . 2008-11-18 20:47 578,560 --a------ c:\windows\system32\dllcache\user32.dll
2008-11-18 20:45 . 2008-11-18 20:45 <DIR> d-------- c:\windows\ERUNT
2008-11-18 20:27 . 2008-11-18 21:04 <DIR> d-------- C:\SDFix
2008-11-18 18:23 . 2008-11-18 18:23 <DIR> d-------- c:\program files\Trend Micro
2008-11-18 13:44 . 2008-11-18 13:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Tools
2008-11-18 13:44 . 2008-11-18 13:43 160,792 --a------ c:\windows\system32\drivers\pctfw2.sys
2008-11-18 13:42 . 2008-11-18 13:44 <DIR> d-------- c:\program files\Common Files\PC Tools
2008-11-18 13:28 . 2008-11-19 17:22 <DIR> d-------- c:\program files\Spyware Doctor
2008-11-18 13:28 . 2008-11-18 13:28 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\PC Tools
2008-11-18 13:28 . 2008-11-19 17:22 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-11-18 13:28 . 2008-08-25 12:36 81,288 --a------ c:\windows\system32\drivers\iksyssec.sys
2008-11-18 13:28 . 2008-08-25 12:36 66,952 --a------ c:\windows\system32\drivers\iksysflt.sys
2008-11-18 13:28 . 2008-08-25 12:36 40,840 --a------ c:\windows\system32\drivers\ikfilesec.sys
2008-11-18 13:28 . 2008-06-02 16:19 29,576 --a------ c:\windows\system32\drivers\kcom.sys
2008-11-18 13:20 . 2008-11-18 13:20 19,639 --a------ c:\program files\Common Files\ematuk.exe
2008-11-18 13:20 . 2008-11-18 13:20 17,938 --a------ c:\windows\jypuweso.sys
2008-11-18 13:20 . 2008-11-18 13:20 17,818 --a------ c:\documents and settings\HP_Administrator\Application Data\ijavymy.bin
2008-11-18 13:20 . 2008-11-18 13:20 17,744 --a------ c:\windows\fyqimyna.inf
2008-11-18 13:20 . 2008-11-18 13:20 17,071 --a------ c:\windows\system32\ripa.vbs
2008-11-18 13:20 . 2008-11-18 13:20 11,571 --a------ c:\windows\ukudurorac.sys
2008-11-18 13:20 . 2008-11-18 13:20 10,972 --a------ c:\documents and settings\HP_Administrator\Application Data\vovy.bin
2008-11-18 13:19 . 2008-11-18 13:19 <DIR> d-------- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2008-11-18 13:19 . 2008-11-18 13:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-12 00:48 . 2008-09-04 12:15 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
2008-11-12 00:48 . 2008-10-24 06:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 20:17 . 2008-10-15 11:34 337,408 --------- c:\windows\system32\dllcache\netapi32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 19:05 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-19 19:03 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-19 19:03 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-19 17:48 --------- d-----w c:\program files\Warcraft III
2008-11-18 18:20 13,979 ----a-w c:\program files\Common Files\ewolaf.lib
2008-11-12 08:09 --------- d-----w c:\program files\Common Files\Blizzard Entertainment
2008-11-03 19:05 --------- d-----w c:\documents and settings\HP_Administrator\Application Data\Hamachi
2008-10-24 11:21 455,296 ------w c:\windows\system32\drivers\mrxsmb.sys
2008-10-12 07:08 --------- d-----w c:\documents and settings\HP_Administrator\Application Data\Roxio
2008-10-12 07:04 --------- d-----w c:\documents and settings\HP_Administrator\Application Data\muvee Technologies
2008-10-12 07:03 --------- d-----w c:\documents and settings\All Users\Application Data\muvee Technologies
2008-10-12 06:50 --------- d-----w c:\program files\MP3 Converter
2008-10-12 06:37 256 ----a-w c:\documents and settings\HP_Administrator\pool.bin
2008-10-12 06:35 --------- d-----w c:\documents and settings\LocalService\Application Data\Roxio
2008-10-08 17:11 --------- d-----w c:\program files\iTunes
2008-10-08 17:11 --------- d-----w c:\program files\iPod
2008-10-08 17:11 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-06 03:10 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-01 17:01 32,000 ----a-w c:\windows\system32\drivers\usbaapl.sys
2008-10-01 15:52 --------- d-----w c:\program files\Apple Software Update
2008-10-01 15:46 --------- d-----w c:\program files\QuickTime
2008-10-01 15:46 --------- d-----w c:\program files\Common Files\Apple
2008-10-01 15:38 --------- d-----w c:\program files\Bonjour
2008-09-28 03:58 25,280 ----a-w c:\windows\system32\drivers\hamachi.sys
2008-09-28 03:35 --------- d-----w c:\program files\MySQL
2008-09-25 04:05 --------- d-----w c:\documents and settings\HP_Administrator\Application Data\U3
2008-03-06 04:56 0 -c--a-w c:\documents and settings\HP_Administrator\Application Data\wklnhst.dat
1999-04-23 22:22 12 -csha-w c:\windows\system\WININETICMP32.drv
2008-04-18 18:30 88 -csh--r c:\windows\system32\BDCED8ACD3.sys
2008-04-18 18:30 4,704 -csha-w c:\windows\system32\KGyGaAvL.sys
2008-07-10 12:51 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008071020080711\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-03-01 4670968]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 218032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13529088]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-22 52840]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"D-Link AirPlus XtremeG"="c:\program files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [2004-10-27 987136]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-10-14 45056]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-11 218032]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-02 86016]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"ftutil2"="ftutil2.dll" [2004-06-07 c:\windows\system32\ftutil2.dll]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-13 c:\windows\RTHDCPL.EXE]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 c:\windows\arpwrmsg.exe]
"nwiz"="nwiz.exe" [2008-05-02 c:\windows\system32\nwiz.exe]
c:\documents and settings\MCX1\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-09-06 27136]
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-09-06 27136]
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2007-11-12 1447184]
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624]
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-09-06 36903]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"vidc.wmv3"= c:\progra~1\COMBIN~1\Filters\wmv9vcm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Blizz
"6113:TCP"= 6113:TCP:blizz3
"6114:TCP"= 6114:TCP:blizz4
"6115:TCP"= 6115:TCP:blizz5
"6116:TCP"= 6116:TCP:blizz6
"6117:TCP"= 6117:TCP:blizz7
"6118:TCP"= 6118:TCP:blizz8
"6119:TCP"= 6119:TCP:blizz9
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
"3724:TCP"= 3724:TCP:Blizzard Downloader
R1 pctfw2;pctfw2;\??\c:\windows\system32\drivers\pctfw2.sys [2008-11-18 160792]
R2 RMSvc;Media Center Extender Resource Monitor;c:\windows\ehome\RMSvc.exe [2005-10-20 28160]
R3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\DRIVERS\A5AGU.sys [2004-10-06 283904]
S2 MySQL4;MySQL4;"c:\program files\MySQL\MySQL Server 4.1\bin\mysqld-nt" --defaults-file="c:\program files\MySQL\MySQL Server 4.1\my.ini" MySQL4 []
S3 ATHFMWDL;D-Link predator Bootloader driver;c:\windows\system32\Drivers\ATHFMWDL.sys [2004-10-04 43392]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
S3 QWAVE;QWAVE service;c:\windows\system32\svchost.exe -k QWAVE [2004-08-09 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\Shell\AutoRun\command - J:\LaunchU3.exe -a
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
2008-11-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-11-15 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - HP_Administrator.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2006-10-17 13:44]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
HKLM-Run-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
HKLM-Run-PCDrProfiler - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\b2foru0c.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF -: plugin - c:\documents and settings\HP_Administrator\Application Data\Mozilla\plugins\npoctoshape.dll
FF -: plugin - c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Octoshape Streaming Services\HP_Administrator\octoprogram-L03-NMS0806260_SUA_000\npoctoshape.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-20 13:16:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MySQL4]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 4.1\bin\mysqld-nt\" --defaults-file=\"c:\program files\MySQL\MySQL Server 4.1\my.ini\" MySQL4"
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Symantec Shared\CCSETMGR.EXE
c:\program files\Common Files\Symantec Shared\CCEVTMGR.EXE
c:\program files\Common Files\Symantec Shared\CCPROXY.EXE
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\arservice.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Norton Internet Security\Norton AntiVirus\NAVAPSVC.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\ehome\McrdSvc.exe
c:\program files\Windows Media Connect 2\wmccds.exe
c:\windows\system32\dllhost.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe
c:\program files\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
.
**************************************************************************
.
Completion time: 2008-11-20 13:23:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-20 18:23:11
Pre-Run: 212,136,218,624 bytes free
Post-Run: 212,850,266,112 bytes free
263 --- E O F --- 2008-11-12 08:03:02