I said I think ComboFix must have deleted something it shouldn't have. I didn;t do anything other than what was instructed.
No nothing has changed. How do I go about restoring from the recovery console?
I managed to get the log copied to the shared folder so here it is:
ComboFix 08-09-20.05 - Owner 2008-09-23 9:25:40.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.68 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\Owner\Application Data\WNSXS~1
C:\Documents and Settings\Owner\Application Data\WNSXS~1\W?nSxS\
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt
C:\Documents and Settings\Owner\Cookies\
[email protected][2].txt
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\bestwiner.stt
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\gemy.bin
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\ydysyqufe._dl
C:\Program Files\Altnet
C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\plugins.cab
C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\plugins.cab.cab
C:\Program Files\comet systems
C:\Program Files\comet systems\DM\activeJobs.xml
C:\Program Files\comet systems\DM\completedJobs.xml
C:\Program Files\comet systems\DM\jobIndex.xml
C:\Program Files\comet systems\DM\productInfo.xml
C:\Program Files\comet systems\DM\request.xml
C:\Program Files\comet systems\Platform\Bin\comet.exe
C:\Program Files\comet systems\Platform\Bin\csband.dll
C:\Program Files\comet systems\Platform\Bin\csctx.dll
C:\Program Files\comet systems\Platform\Bin\cseng.dll
C:\Program Files\comet systems\Platform\Bin\cshz.dll
C:\Program Files\comet systems\Platform\Bin\csutil.dll
C:\Program Files\comet systems\Platform\Bin\fileutil.dll
C:\Program Files\comet systems\Platform\Bin\packageinstaller.exe
C:\Program Files\comet systems\Platform\Bin\skinui.dll
C:\Program Files\comet systems\Platform\Bin\unins.exe
C:\Program Files\comet systems\Platform\Data\csres.dat
C:\Program Files\comet systems\Platform\Services\activity.xml
C:\Program Files\comet systems\Platform\Services\AddRemove\aricon_1a.ico
C:\Program Files\comet systems\Platform\Services\AddRemove\aricon_1b.ico
C:\Program Files\comet systems\Platform\Services\AddRemove\arskin_1a.gif
C:\Program Files\comet systems\Platform\Services\AddRemove\arskin_1b.gif
C:\Program Files\comet systems\Platform\Services\AddRemove\arskin_mask.gif
C:\Program Files\comet systems\Platform\Services\cnfmgr.js
C:\Program Files\comet systems\Platform\Services\context.js
C:\Program Files\comet systems\Platform\Services\helpbutton.bmp
C:\Program Files\comet systems\Platform\Services\LogQueue\p0000003E_o01391E80_logging_1113185885750_1.xml
C:\Program Files\comet systems\Platform\Services\LogQueue\p00000064_o013FDD10_logging_1113595115968_1.xml
C:\Program Files\comet systems\Platform\Services\Messaging\Base\1line_left.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\1line_left_mask.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\1line_left_small.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\1line_left_small_mask.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\1line_right.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\1line_right_mask.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\1line_right_small.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\1line_right_small_mask.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\2line_left.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\2line_left_mask.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\2line_left_small.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\2line_left_small_mask.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\2line_right.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\2line_right_mask.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\2line_right_small.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\2line_right_small_mask.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\3line_left.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\3line_left_mask.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\3line_left_small.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\3line_left_small_mask.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\3line_right.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\3line_right_mask.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\3line_right_small.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Base\3line_right_small_mask.gif
C:\Program Files\comet systems\Platform\Services\Messaging\Listeners\travel_0001.js
C:\Program Files\comet systems\Platform\Services\tbmgr.js
C:\Program Files\comet systems\Platform\Services\unins.ico
C:\Program Files\comet systems\Platform\Uninstall\cleaner.xml
C:\Program Files\comet systems\Platform\Uninstall\un_screensaver.xml
C:\Program Files\comet systems\Platform\Uninstall\un_sswpmgr.xml
C:\Program Files\comet systems\Products\Search\autosrch.js
C:\Program Files\comet systems\Products\Search\related.js
C:\Program Files\comet systems\Products\Search\related.xml
C:\Program Files\comet systems\Products\SSWP\launcher_searchbtn.gif
C:\Program Files\comet systems\Products\SSWP\launcher_searchbtn_over.gif
C:\Program Files\comet systems\Products\SSWP\onlinecheck.js
C:\Program Files\comet systems\Products\SSWP\scr_offline.js
C:\Program Files\comet systems\Products\SSWP\sswp.ico
C:\Program Files\comet systems\Products\SSWP\sswp_launch.js
C:\Program Files\comet systems\Products\SSWP\sswp_mask.gif
C:\Program Files\comet systems\Products\SSWP\sswp_offline.gif
C:\Program Files\comet systems\Products\SSWP\sswp_offline.html
C:\Program Files\comet systems\Products\SSWP\sswp_shortcut.exe
C:\Program Files\comet systems\Products\SSWP\sswp_skin.gif
C:\Program Files\comet systems\Products\SSWP\sswp_skinover.gif
C:\Program Files\comet systems\Products\SSWP\sswp_systray.js
C:\Program Files\comet systems\Products\SSWP\sswpmgr.js
C:\Program Files\comet systems\Products\SSWP\sswpmgr.xml
C:\Program Files\comet systems\Products\SSWP\sswpmgr_ar.js
C:\Program Files\comet systems\Products\Toolbar\adzap_tb.js
C:\Program Files\comet systems\Products\Toolbar\adzapper.ani
C:\Program Files\comet systems\Products\Toolbar\beep.wav
C:\Program Files\comet systems\Products\Toolbar\bullet_blue.gif
C:\Program Files\comet systems\Products\Toolbar\bullet_green.gif
C:\Program Files\comet systems\Products\Toolbar\clsdown.gif
C:\Program Files\comet systems\Products\Toolbar\clsmask.gif
C:\Program Files\comet systems\Products\Toolbar\clsover.gif
C:\Program Files\comet systems\Products\Toolbar\clsskin.gif
C:\Program Files\comet systems\Products\Toolbar\def_arr.gif
C:\Program Files\comet systems\Products\Toolbar\doh.wav
C:\Program Files\comet systems\Products\Toolbar\funbutton.bmp
C:\Program Files\comet systems\Products\Toolbar\hzbutton.bmp
C:\Program Files\comet systems\Products\Toolbar\hzbutton_disable.bmp
C:\Program Files\comet systems\Products\Toolbar\hzbutton_on.bmp
C:\Program Files\comet systems\Products\Toolbar\label_instruction.gif
C:\Program Files\comet systems\Products\Toolbar\logo_starter.gif
C:\Program Files\comet systems\Products\Toolbar\logotitle.gif
C:\Program Files\comet systems\Products\Toolbar\meep.wav
C:\Program Files\comet systems\Products\Toolbar\meow.wav
C:\Program Files\comet systems\Products\Toolbar\minmiz_norm.gif
C:\Program Files\comet systems\Products\Toolbar\minmiz_over.gif
C:\Program Files\comet systems\Products\Toolbar\panic_norm.gif
C:\Program Files\comet systems\Products\Toolbar\panic_over.gif
C:\Program Files\comet systems\Products\Toolbar\pcursor.gif
C:\Program Files\comet systems\Products\Toolbar\pix.gif
C:\Program Files\comet systems\Products\Toolbar\pubutton.bmp
C:\Program Files\comet systems\Products\Toolbar\pubutton_alert.bmp
C:\Program Files\comet systems\Products\Toolbar\pubutton_off.bmp
C:\Program Files\comet systems\Products\Toolbar\pwr_offdown.gif
C:\Program Files\comet systems\Products\Toolbar\pwr_offover.gif
C:\Program Files\comet systems\Products\Toolbar\pwr_ondown.gif
C:\Program Files\comet systems\Products\Toolbar\pwr_onover.gif
C:\Program Files\comet systems\Products\Toolbar\refbutton.bmp
C:\Program Files\comet systems\Products\Toolbar\scmask.gif
C:\Program Files\comet systems\Products\Toolbar\screensaver.bmp
C:\Program Files\comet systems\Products\Toolbar\screensaver.js
C:\Program Files\comet systems\Products\Toolbar\scskin.gif
C:\Program Files\comet systems\Products\Toolbar\scskin_over.gif
C:\Program Files\comet systems\Products\Toolbar\smileytown.bmp
C:\Program Files\comet systems\Products\Toolbar\smileytown.xml
C:\Program Files\comet systems\Products\Toolbar\supercursors.bmp
C:\Program Files\comet systems\Products\Toolbar\supercursors.ico
C:\Program Files\comet systems\Products\Toolbar\sys_except.xml
C:\Program Files\comet systems\Products\Toolbar\textbox.gif
C:\Program Files\comet systems\Products\Toolbar\travelbutton.bmp
C:\Program Files\comet systems\Products\Toolbar\webbutton.bmp
C:\Program Files\comet systems\Products\Toolbar\yes.wav
C:\Program Files\comet systems\Products\Toolbar\zap.wav
C:\Program Files\comet systems\Products\Travel\cars.xsl
C:\Program Files\comet systems\Products\Travel\flights.xsl
C:\Program Files\comet systems\Products\Travel\hotels.xsl
C:\Program Files\comet systems\Products\Travel\travel.js
C:\Program Files\comet systems\Products\Travel\travel_context.xml
C:\Program Files\comet systems\Wallpaper\swpstart.exe
C:\Program Files\icroso~1
C:\WINDOWS\system32\3941\4522.dll
C:\WINDOWS\system32\actskn43.ocx
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\smante~1
.
((((((((((((((((((((((((( Files Created from 2008-08-23 to 2008-09-23 )))))))))))))))))))))))))))))))
.
2008-09-23 09:30 . 2008-09-23 09:30 11,564 --a------ C:\WINDOWS\system32\DVCState-{00000002-00000000-00000001-00001102-00000004-00581102}.rfx
2008-09-22 17:10 . 2008-09-22 17:11 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-22 17:10 . 2008-09-22 17:10 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-09-22 17:10 . 2008-09-22 17:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-22 17:10 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-22 17:10 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-22 16:10 . 2008-09-22 16:11 <DIR> d-------- C:\Program Files\QuickTime
2008-09-22 16:10 . 2008-09-22 16:10 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-09-22 16:09 . 2008-09-22 16:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-22 16:08 . 2008-09-22 16:08 <DIR> d-------- C:\Program Files\Apple Software Update
2008-09-22 16:08 . 2008-09-22 16:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-09-22 12:05 . 2008-09-22 12:05 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-09-22 11:57 . 2008-09-22 11:57 578,560 --a--c--- C:\WINDOWS\system32\dllcache\user32.dll
2008-09-22 11:55 . 2008-09-22 11:55 <DIR> d-------- C:\WINDOWS\ERUNT
2008-09-22 11:51 . 2008-09-22 12:29 <DIR> d-------- C:\SDFix
2008-09-19 09:06 . 2008-09-19 09:06 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-17 09:01 . 2008-09-17 09:01 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-09-17 09:01 . 2008-09-17 09:01 <DIR> d-------- C:\WINDOWS\system32\en
2008-09-17 09:01 . 2008-09-17 09:01 <DIR> d-------- C:\WINDOWS\l2schemas
2008-09-16 22:47 . 2008-05-01 09:33 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-16 22:44 . 2008-04-13 19:12 1,306,624 --------- C:\WINDOWS\system32\msxml6.dll
2008-09-16 22:43 . 2008-04-13 19:12 786,432 -----c--- C:\WINDOWS\system32\dllcache\migrate.exe
2008-09-16 22:42 . 2008-04-11 14:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-09-16 22:42 . 2008-04-13 19:11 286,720 -----c--- C:\WINDOWS\system32\dllcache\blackbox.dll
2008-09-16 22:42 . 2008-04-13 19:11 233,472 --------- C:\WINDOWS\system32\azroles.dll
2008-09-16 22:42 . 2008-04-13 19:11 136,192 --------- C:\WINDOWS\system32\aaclient.dll
2008-09-16 22:42 . 2008-04-13 12:23 8,192 -----c--- C:\WINDOWS\system32\dllcache\asferror.dll
2008-09-16 22:42 . 2008-04-13 19:11 7,168 --------- C:\WINDOWS\system32\bitsprx4.dll
2008-09-16 22:42 . 2002-09-03 08:00 999 -----c--- C:\WINDOWS\system32\dllcache\bktrh.gif
2008-09-16 22:14 . 2008-07-18 22:09 25,800 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-09-16 17:24 . 2003-03-18 16:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-09-16 17:24 . 2003-03-18 15:14 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll
2008-09-16 17:24 . 2003-02-20 22:42 348,160 --a------ C:\WINDOWS\system32\MSVCR71.dll
2008-09-16 17:23 . 2008-09-16 17:23 <DIR> d-------- C:\Program Files\Alwil Software
2008-09-16 16:54 . 2008-09-16 16:54 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\AVGTOOLBAR
2008-09-16 16:53 . 2008-09-16 16:53 <DIR> d-------- C:\Program Files\AVG
2008-09-16 16:53 . 2008-09-19 09:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-19 14:12 --------- d-----w C:\Program Files\PhoneTools
2008-09-19 14:12 --------- d-----w C:\Program Files\HP
2008-09-19 14:12 --------- d-----w C:\Program Files\FruityLoops 3.56
2008-09-19 14:12 --------- d-----w C:\Program Files\FinePixViewer
2008-09-19 14:12 --------- d-----w C:\Program Files\Creative
2008-09-19 14:12 --------- d-----w C:\Program Files\Common Files\aolshare
2008-09-19 14:12 --------- d-----w C:\Program Files\Common Files\Adaptec Shared
2008-09-17 16:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-17 16:40 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-17 16:02 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-16 21:58 --------- d-----w C:\Documents and Settings\Owner\Application Data\uTorrent
2008-07-02 08:13 128 ----a-w C:\3g324623.bat
2008-06-15 21:21 17,911 -c--a-w C:\Documents and Settings\All Users\Application Data\gykecevij.sys
2008-06-15 21:21 16,628 -c--a-w C:\Documents and Settings\Owner\Application Data\qopyhah.dll
2008-06-15 21:21 16,523 -c--a-w C:\Program Files\Common Files\ahyrusir.ban
2008-06-15 21:21 16,523 -c--a-w C:\Documents and Settings\All Users\Application Data\byrikody.vbs
2008-06-15 21:21 11,898 -c--a-w C:\Program Files\Common Files\ovigakasof.bat
2004-09-19 17:05 41,416 -c--a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
"NvMediaCenter"="C:\WINDOWS\system32\NVMCTRAY.DLL" [2003-07-28 49152]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-07-28 4841472]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 90112]
"Jet Detection"="C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe" [2001-10-04 28672]
"GWMDMpi"="C:\WINDOWS\GWMDMpi.exe" [2003-05-07 53248]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2002-09-10 368706]
"CapFax"="C:\Program Files\PhoneTools\CapFax.EXE" [2001-11-07 20480]
"nwiz"="nwiz.exe" [2003-07-28 C:\WINDOWS\system32\nwiz.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= vdrcodec.dll
"msacm.ctmp3"= C:\WINDOWS\System32\ctmp3.acm
"VIDC.PIM1"= pclepim1.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL Companion.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AOL Companion.lnk
backup=C:\WINDOWS\pss\AOL Companion.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmakieb]
C:\WINDOWS\system32\S?mantec\j?vaw.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2008-04-13 19:12 1695232 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
--a------ 2004-05-07 16:54 99480 C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2004-01-16 18:23 26112 C:\Program Files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
--a------ 2007-04-09 12:32 19456 C:\WINDOWS\system32\CtHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GWMDMMSG]
--a------ 2003-05-07 06:00 90112 C:\WINDOWS\GWMDMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Hot Key Kbd 9910 Daemon]
--------- 2001-01-03 15:50 66048 C:\WINDOWS\system32\SK9910DM.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\WinMX\\WinMX.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 RioPNP;RioPNP;C:\WINDOWS\system32\drivers\RioPNP.sys [2000-06-06 6736]
S3 DVDACCSS;DVDACCSS;C:\PROGRA~1\DVDACC~1\DVDAX.SYS [2000-07-26 179264]
S3 pc22nd5;Toshiba PCX2200 USB Cable Modem networking driver (NDIS);C:\WINDOWS\system32\DRIVERS\pc22nd5.sys [2001-11-09 17648]
S3 pc22unic;Toshiba PCX2200 USB Cable Modem WDM driver;C:\WINDOWS\system32\DRIVERS\pc22unic.sys [2001-11-09 69744]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-zfwm - C:\PROGRA~1\COMMON~1\zfwm\zfwmm.exe
SSODL-CDBurn- - (no file)
MSConfigStartUp-Antivirus - C:\Program Files\Antivirus2008\Antvrs.exe
MSConfigStartUp-GetModule23 - C:\Program Files\GetModule\GetModule23.exe
MSConfigStartUp-GetPack21 - C:\Program Files\GetPack\GetPack21.exe
MSConfigStartUp-lphc1g7j0ec4n - C:\WINDOWS\system32\lphc1g7j0ec4n.exe
MSConfigStartUp-Microsoft Windows Installer - C:\Documents and Settings\Owner\Application Data\Microsoft\dtsc\13330.exe
MSConfigStartUp-mjc - C:\Program Files\mjc\mjc.exe
MSConfigStartUp-Sakora - C:\Program Files\Sakora\Sakora.exe
MSConfigStartUp-SBUSA - C:\Program Files\SpamBlockerUtility\bin\10.2.215.0\SBUSA.exe
MSConfigStartUp-SMrhc5g7j0ec4n - C:\Program Files\rhc5g7j0ec4n\rhc5g7j0ec4n.exe
MSConfigStartUp-Spam Blocker for Outlook Express - C:\PROGRA~1\SPAMBL~1\bin\102215~1.0\SBInst.exe
MSConfigStartUp-SpamBlockerUtilityOE - C:\Program Files\SpamBlockerUtility\bin\10.2.215.0\OEAddOn.exe
MSConfigStartUp-SpeedRunner - C:\Documents and Settings\Owner\Application Data\SpeedRunner\SpeedRunner.exe
MSConfigStartUp-WeatherDPA - C:\Program Files\SpamBlockerUtility\bin\10.2.215.0\Weather.exe
MSConfigStartUp-webHancer Agent - C:\Program Files\webHancer\Programs\whagent.exe
MSConfigStartUp-zfwm - C:\PROGRA~1\COMMON~1\zfwm\zfwmm.exe
MSConfigStartUp-{4c19b279-d1bc-e7ab-5af0-792276eae63f} - C:\WINDOWS\system32\pnrsveepycvnobaeq.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R0 -: HKLM-Main,Start Page = hxxp://www.google.com
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
O16 -: DirectAnimation Java Classes - file://C:\WINDOWS\Java\classes\dajava.cab
C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
O16 -: {511073AD-BE56-4D43-AE68-93390514385E} - hcp://system/TechTools.CAB
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\TechTools.INF
C:\WINDOWS\System32\scrrun.dll
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\msstkprp.dll
C:\WINDOWS\system32\msvbvm60.dll
C:\WINDOWS\system32\oleaut32.dll
C:\WINDOWS\system32\olepro32.dll
C:\WINDOWS\system32\asycfilt.dll
C:\WINDOWS\system32\stdole2.tlb
C:\WINDOWS\system32\COMCAT.DLL
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\TechTools.ocx
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-23 09:35:39
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\NMSSvc.Exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\snmp.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-09-23 9:40:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-23 14:40:38
Pre-Run: 66,032,472,064 bytes free
Post-Run: 66,368,577,536 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
363 --- E O F --- 2008-09-23 08:06:40