kahdah,
Thanks for the quick response.
I ran comb fix and post the log here.
Couple updates, still can't run an anti-virus or hijack this - not a valid win32 application.
Downloaded and ran Super anti spyware and it crashes the machine as it scans the registry.
Can't boot in to safe mode. Get the screens and all and when I select safe mode, it just reboots, but not in to safe mode.
Anyway, here is the combo fix log:
ComboFix 08-02-20.2 - Big 2008-02-19 22:06:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2113 [GMT -5:00]
Running from: C:\Documents and Settings\Big\Desktop\Combo-Fix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\mdelk.exe
C:\WINDOWS\system32\wintems.exe
C:\WINDOWS\system32\drivers\down
C:\WINDOWS\system32\drivers\down\101975343.exe
C:\WINDOWS\system32\drivers\down\101978828.exe
C:\WINDOWS\system32\drivers\down\101980046.exe
C:\WINDOWS\system32\drivers\down\101982000.exe
C:\WINDOWS\system32\drivers\down\101999062.exe
C:\WINDOWS\system32\drivers\down\101999265.exe
C:\WINDOWS\system32\drivers\down\102002093.exe
C:\WINDOWS\system32\drivers\down\102003312.exe
C:\WINDOWS\system32\drivers\down\102004625.exe
C:\WINDOWS\system32\drivers\down\102006531.exe
C:\WINDOWS\system32\drivers\down\102010453.exe
C:\WINDOWS\system32\drivers\down\102015593.exe
C:\WINDOWS\system32\drivers\down\102016218.exe
C:\WINDOWS\system32\drivers\down\102016687.exe
C:\WINDOWS\system32\drivers\down\102017265.exe
C:\WINDOWS\system32\drivers\down\102019265.exe
C:\WINDOWS\system32\drivers\down\102020546.exe
C:\WINDOWS\system32\drivers\down\102046828.exe
C:\WINDOWS\system32\drivers\down\102048500.exe
C:\WINDOWS\system32\drivers\down\110859.exe
C:\WINDOWS\system32\drivers\down\111093.exe
C:\WINDOWS\system32\drivers\down\111750.exe
C:\WINDOWS\system32\drivers\down\113453.exe
C:\WINDOWS\system32\drivers\down\113765.exe
C:\WINDOWS\system32\drivers\down\115343.exe
C:\WINDOWS\system32\drivers\down\116459484.exe
C:\WINDOWS\system32\drivers\down\116462546.exe
C:\WINDOWS\system32\drivers\down\116464156.exe
C:\WINDOWS\system32\drivers\down\116465921.exe
C:\WINDOWS\system32\drivers\down\116500890.exe
C:\WINDOWS\system32\drivers\down\116500906.exe
C:\WINDOWS\system32\drivers\down\116505078.exe
C:\WINDOWS\system32\drivers\down\116506015.exe
C:\WINDOWS\system32\drivers\down\116507640.exe
C:\WINDOWS\system32\drivers\down\116510390.exe
C:\WINDOWS\system32\drivers\down\116515781.exe
C:\WINDOWS\system32\drivers\down\116517578.exe
C:\WINDOWS\system32\drivers\down\116518109.exe
C:\WINDOWS\system32\drivers\down\116518359.exe
C:\WINDOWS\system32\drivers\down\116518625.exe
C:\WINDOWS\system32\drivers\down\116520890.exe
C:\WINDOWS\system32\drivers\down\116521796.exe
C:\WINDOWS\system32\drivers\down\116531.exe
C:\WINDOWS\system32\drivers\down\116548140.exe
C:\WINDOWS\system32\drivers\down\116549906.exe
C:\WINDOWS\system32\drivers\down\116593.exe
C:\WINDOWS\system32\drivers\down\117734.exe
C:\WINDOWS\system32\drivers\down\118156.exe
C:\WINDOWS\system32\drivers\down\118750.exe
C:\WINDOWS\system32\drivers\down\119625.exe
C:\WINDOWS\system32\drivers\down\119656.exe
C:\WINDOWS\system32\drivers\down\121093.exe
C:\WINDOWS\system32\drivers\down\122828.exe
C:\WINDOWS\system32\drivers\down\123093.exe
C:\WINDOWS\system32\drivers\down\124640.exe
C:\WINDOWS\system32\drivers\down\124921.exe
C:\WINDOWS\system32\drivers\down\125156.exe
C:\WINDOWS\system32\drivers\down\125656.exe
C:\WINDOWS\system32\drivers\down\126906.exe
C:\WINDOWS\system32\drivers\down\127500.exe
C:\WINDOWS\system32\drivers\down\127718.exe
C:\WINDOWS\system32\drivers\down\127796.exe
C:\WINDOWS\system32\drivers\down\128546.exe
C:\WINDOWS\system32\drivers\down\129703.exe
C:\WINDOWS\system32\drivers\down\130960062.exe
C:\WINDOWS\system32\drivers\down\130961406.exe
C:\WINDOWS\system32\drivers\down\130962953.exe
C:\WINDOWS\system32\drivers\down\130964750.exe
C:\WINDOWS\system32\drivers\down\130997859.exe
C:\WINDOWS\system32\drivers\down\131000453.exe
C:\WINDOWS\system32\drivers\down\131001390.exe
C:\WINDOWS\system32\drivers\down\131003625.exe
C:\WINDOWS\system32\drivers\down\131007531.exe
C:\WINDOWS\system32\drivers\down\131011812.exe
C:\WINDOWS\system32\drivers\down\131013328.exe
C:\WINDOWS\system32\drivers\down\131013671.exe
C:\WINDOWS\system32\drivers\down\131013937.exe
C:\WINDOWS\system32\drivers\down\131017468.exe
C:\WINDOWS\system32\drivers\down\131018890.exe
C:\WINDOWS\system32\drivers\down\131019812.exe
C:\WINDOWS\system32\drivers\down\131076953.exe
C:\WINDOWS\system32\drivers\down\131984.exe
C:\WINDOWS\system32\drivers\down\133812.exe
C:\WINDOWS\system32\drivers\down\135390.exe
C:\WINDOWS\system32\drivers\down\135656.exe
C:\WINDOWS\system32\drivers\down\135906.exe
C:\WINDOWS\system32\drivers\down\138875.exe
C:\WINDOWS\system32\drivers\down\140484.exe
C:\WINDOWS\system32\drivers\down\140984.exe
C:\WINDOWS\system32\drivers\down\142343.exe
C:\WINDOWS\system32\drivers\down\142484.exe
C:\WINDOWS\system32\drivers\down\143203.exe
C:\WINDOWS\system32\drivers\down\143921.exe
C:\WINDOWS\system32\drivers\down\144031.exe
C:\WINDOWS\system32\drivers\down\144750.exe
C:\WINDOWS\system32\drivers\down\145491906.exe
C:\WINDOWS\system32\drivers\down\145496031.exe
C:\WINDOWS\system32\drivers\down\145498296.exe
C:\WINDOWS\system32\drivers\down\145505187.exe
C:\WINDOWS\system32\drivers\down\145531453.exe
C:\WINDOWS\system32\drivers\down\145532187.exe
C:\WINDOWS\system32\drivers\down\145545421.exe
C:\WINDOWS\system32\drivers\down\145549640.exe
C:\WINDOWS\system32\drivers\down\145553343.exe
C:\WINDOWS\system32\drivers\down\145556828.exe
C:\WINDOWS\system32\drivers\down\145565156.exe
C:\WINDOWS\system32\drivers\down\145572281.exe
C:\WINDOWS\system32\drivers\down\145573265.exe
C:\WINDOWS\system32\drivers\down\145586671.exe
C:\WINDOWS\system32\drivers\down\145591703.exe
C:\WINDOWS\system32\drivers\down\145594484.exe
C:\WINDOWS\system32\drivers\down\145597031.exe
C:\WINDOWS\system32\drivers\down\145625031.exe
C:\WINDOWS\system32\drivers\down\145641593.exe
C:\WINDOWS\system32\drivers\down\145687.exe
C:\WINDOWS\system32\drivers\down\14579125.exe
C:\WINDOWS\system32\drivers\down\14607421.exe
C:\WINDOWS\system32\drivers\down\14631734.exe
C:\WINDOWS\system32\drivers\down\14632328.exe
C:\WINDOWS\system32\drivers\down\146390.exe
C:\WINDOWS\system32\drivers\down\14640843.exe
C:\WINDOWS\system32\drivers\down\14644671.exe
C:\WINDOWS\system32\drivers\down\14648328.exe
C:\WINDOWS\system32\drivers\down\14652203.exe
C:\WINDOWS\system32\drivers\down\14660531.exe
C:\WINDOWS\system32\drivers\down\14665375.exe
C:\WINDOWS\system32\drivers\down\14666546.exe
C:\WINDOWS\system32\drivers\down\14668265.exe
C:\WINDOWS\system32\drivers\down\14672984.exe
C:\WINDOWS\system32\drivers\down\14677671.exe
C:\WINDOWS\system32\drivers\down\14680515.exe
C:\WINDOWS\system32\drivers\down\147078.exe
C:\WINDOWS\system32\drivers\down\14710406.exe
C:\WINDOWS\system32\drivers\down\14715203.exe
C:\WINDOWS\system32\drivers\down\147500.exe
C:\WINDOWS\system32\drivers\down\148250.exe
C:\WINDOWS\system32\drivers\down\148781.exe
C:\WINDOWS\system32\drivers\down\149843.exe
C:\WINDOWS\system32\drivers\down\150078.exe
C:\WINDOWS\system32\drivers\down\151828.exe
C:\WINDOWS\system32\drivers\down\152031.exe
C:\WINDOWS\system32\drivers\down\152593.exe
C:\WINDOWS\system32\drivers\down\153328.exe
C:\WINDOWS\system32\drivers\down\153687.exe
C:\WINDOWS\system32\drivers\down\154078.exe
C:\WINDOWS\system32\drivers\down\156578.exe
C:\WINDOWS\system32\drivers\down\157281.exe
C:\WINDOWS\system32\drivers\down\158218.exe
C:\WINDOWS\system32\drivers\down\158406.exe
C:\WINDOWS\system32\drivers\down\160065562.exe
C:\WINDOWS\system32\drivers\down\160070921.exe
C:\WINDOWS\system32\drivers\down\160072765.exe
C:\WINDOWS\system32\drivers\down\160073671.exe
C:\WINDOWS\system32\drivers\down\160125875.exe
C:\WINDOWS\system32\drivers\down\160125906.exe
C:\WINDOWS\system32\drivers\down\160134687.exe
C:\WINDOWS\system32\drivers\down\160138062.exe
C:\WINDOWS\system32\drivers\down\160144453.exe
C:\WINDOWS\system32\drivers\down\160147828.exe
C:\WINDOWS\system32\drivers\down\160156421.exe
C:\WINDOWS\system32\drivers\down\160160343.exe
C:\WINDOWS\system32\drivers\down\160161500.exe
C:\WINDOWS\system32\drivers\down\160165390.exe
C:\WINDOWS\system32\drivers\down\160166875.exe
C:\WINDOWS\system32\drivers\down\160172156.exe
C:\WINDOWS\system32\drivers\down\160174437.exe
C:\WINDOWS\system32\drivers\down\160205468.exe
C:\WINDOWS\system32\drivers\down\160230859.exe
C:\WINDOWS\system32\drivers\down\173875.exe
C:\WINDOWS\system32\drivers\down\174649328.exe
C:\WINDOWS\system32\drivers\down\174653953.exe
C:\WINDOWS\system32\drivers\down\174655750.exe
C:\WINDOWS\system32\drivers\down\174656656.exe
C:\WINDOWS\system32\drivers\down\174657687.exe
C:\WINDOWS\system32\drivers\down\174668750.exe
C:\WINDOWS\system32\drivers\down\174669015.exe
C:\WINDOWS\system32\drivers\down\174673296.exe
C:\WINDOWS\system32\drivers\down\174674625.exe
C:\WINDOWS\system32\drivers\down\174676171.exe
C:\WINDOWS\system32\drivers\down\174677828.exe
C:\WINDOWS\system32\drivers\down\174681828.exe
C:\WINDOWS\system32\drivers\down\174684015.exe
C:\WINDOWS\system32\drivers\down\174684750.exe
C:\WINDOWS\system32\drivers\down\174685406.exe
C:\WINDOWS\system32\drivers\down\174687296.exe
C:\WINDOWS\system32\drivers\down\174689187.exe
C:\WINDOWS\system32\drivers\down\174690593.exe
C:\WINDOWS\system32\drivers\down\174716953.exe
C:\WINDOWS\system32\drivers\down\174718875.exe
C:\WINDOWS\system32\drivers\down\176000.exe
C:\WINDOWS\system32\drivers\down\184546.exe
C:\WINDOWS\system32\drivers\down\186656.exe
C:\WINDOWS\system32\drivers\down\190796.exe
C:\WINDOWS\system32\drivers\down\29136109.exe
C:\WINDOWS\system32\drivers\down\29138390.exe
C:\WINDOWS\system32\drivers\down\29142093.exe
C:\WINDOWS\system32\drivers\down\29159515.exe
C:\WINDOWS\system32\drivers\down\29159546.exe
C:\WINDOWS\system32\drivers\down\29164578.exe
C:\WINDOWS\system32\drivers\down\29166062.exe
C:\WINDOWS\system32\drivers\down\29168781.exe
C:\WINDOWS\system32\drivers\down\29170718.exe
C:\WINDOWS\system32\drivers\down\29176343.exe
C:\WINDOWS\system32\drivers\down\29178687.exe
C:\WINDOWS\system32\drivers\down\29179015.exe
C:\WINDOWS\system32\drivers\down\29179921.exe
C:\WINDOWS\system32\drivers\down\29180765.exe
C:\WINDOWS\system32\drivers\down\29183000.exe
C:\WINDOWS\system32\drivers\down\29184250.exe
C:\WINDOWS\system32\drivers\down\29212203.exe
C:\WINDOWS\system32\drivers\down\29219531.exe
C:\WINDOWS\system32\drivers\down\334968.exe
C:\WINDOWS\system32\drivers\down\337156.exe
C:\WINDOWS\system32\drivers\down\338140.exe
C:\WINDOWS\system32\drivers\down\339515.exe
C:\WINDOWS\system32\drivers\down\372359.exe
C:\WINDOWS\system32\drivers\down\372640.exe
C:\WINDOWS\system32\drivers\down\375609.exe
C:\WINDOWS\system32\drivers\down\377781.exe
C:\WINDOWS\system32\drivers\down\379437.exe
C:\WINDOWS\system32\drivers\down\381484.exe
C:\WINDOWS\system32\drivers\down\387031.exe
C:\WINDOWS\system32\drivers\down\389093.exe
C:\WINDOWS\system32\drivers\down\389593.exe
C:\WINDOWS\system32\drivers\down\390296.exe
C:\WINDOWS\system32\drivers\down\390828.exe
C:\WINDOWS\system32\drivers\down\392765.exe
C:\WINDOWS\system32\drivers\down\421312.exe
C:\WINDOWS\system32\drivers\down\43635859.exe
C:\WINDOWS\system32\drivers\down\43641546.exe
C:\WINDOWS\system32\drivers\down\43644093.exe
C:\WINDOWS\system32\drivers\down\43652781.exe
C:\WINDOWS\system32\drivers\down\43731109.exe
C:\WINDOWS\system32\drivers\down\43731625.exe
C:\WINDOWS\system32\drivers\down\43742296.exe
C:\WINDOWS\system32\drivers\down\43745468.exe
C:\WINDOWS\system32\drivers\down\43749500.exe
C:\WINDOWS\system32\drivers\down\43754078.exe
C:\WINDOWS\system32\drivers\down\43762468.exe
C:\WINDOWS\system32\drivers\down\43767937.exe
C:\WINDOWS\system32\drivers\down\43768984.exe
C:\WINDOWS\system32\drivers\down\43770125.exe
C:\WINDOWS\system32\drivers\down\43771906.exe
C:\WINDOWS\system32\drivers\down\43778046.exe
C:\WINDOWS\system32\drivers\down\43780015.exe
C:\WINDOWS\system32\drivers\down\43810109.exe
C:\WINDOWS\system32\drivers\down\43814515.exe
C:\WINDOWS\system32\drivers\down\447843.exe
C:\WINDOWS\system32\drivers\down\454421.exe
C:\WINDOWS\system32\drivers\down\58245890.exe
C:\WINDOWS\system32\drivers\down\58254609.exe
C:\WINDOWS\system32\drivers\down\58269015.exe
C:\WINDOWS\system32\drivers\down\58288390.exe
C:\WINDOWS\system32\drivers\down\58289171.exe
C:\WINDOWS\system32\drivers\down\58297640.exe
C:\WINDOWS\system32\drivers\down\58301265.exe
C:\WINDOWS\system32\drivers\down\58307406.exe
C:\WINDOWS\system32\drivers\down\58310937.exe
C:\WINDOWS\system32\drivers\down\58321671.exe
C:\WINDOWS\system32\drivers\down\58348500.exe
C:\WINDOWS\system32\drivers\down\58349531.exe
C:\WINDOWS\system32\drivers\down\58351187.exe
C:\WINDOWS\system32\drivers\down\58358359.exe
C:\WINDOWS\system32\drivers\down\58363000.exe
C:\WINDOWS\system32\drivers\down\58419515.exe
C:\WINDOWS\system32\drivers\down\67359.exe
C:\WINDOWS\system32\drivers\down\72854062.exe
C:\WINDOWS\system32\drivers\down\72859765.exe
C:\WINDOWS\system32\drivers\down\72885859.exe
C:\WINDOWS\system32\drivers\down\72886265.exe
C:\WINDOWS\system32\drivers\down\72896500.exe
C:\WINDOWS\system32\drivers\down\72900562.exe
C:\WINDOWS\system32\drivers\down\72904640.exe
C:\WINDOWS\system32\drivers\down\72908484.exe
C:\WINDOWS\system32\drivers\down\72919984.exe
C:\WINDOWS\system32\drivers\down\72924906.exe
C:\WINDOWS\system32\drivers\down\72927750.exe
C:\WINDOWS\system32\drivers\down\72930187.exe
C:\WINDOWS\system32\drivers\down\72931593.exe
C:\WINDOWS\system32\drivers\down\72937921.exe
C:\WINDOWS\system32\drivers\down\72950109.exe
C:\WINDOWS\system32\drivers\down\72989578.exe
C:\WINDOWS\system32\drivers\down\73023640.exe
C:\WINDOWS\system32\drivers\down\76968.exe
C:\WINDOWS\system32\drivers\down\77421.exe
C:\WINDOWS\system32\drivers\down\86859.exe
C:\WINDOWS\system32\drivers\down\87447125.exe
C:\WINDOWS\system32\drivers\down\87450687.exe
C:\WINDOWS\system32\drivers\down\87454796.exe
C:\WINDOWS\system32\drivers\down\87475625.exe
C:\WINDOWS\system32\drivers\down\87476078.exe
C:\WINDOWS\system32\drivers\down\87484515.exe
C:\WINDOWS\system32\drivers\down\87487875.exe
C:\WINDOWS\system32\drivers\down\87491312.exe
C:\WINDOWS\system32\drivers\down\87495890.exe
C:\WINDOWS\system32\drivers\down\87505437.exe
C:\WINDOWS\system32\drivers\down\87510062.exe
C:\WINDOWS\system32\drivers\down\87510703.exe
C:\WINDOWS\system32\drivers\down\87511906.exe
C:\WINDOWS\system32\drivers\down\87513421.exe
C:\WINDOWS\system32\drivers\down\87517625.exe
C:\WINDOWS\system32\drivers\down\87519750.exe
C:\WINDOWS\system32\drivers\down\87549812.exe
C:\WINDOWS\system32\drivers\down\87554218.exe
C:\WINDOWS\system32\drivers\down\88625.exe
C:\WINDOWS\system32\drivers\down\91218.exe
C:\WINDOWS\system32\drivers\down\91281.exe
C:\WINDOWS\system32\drivers\down\96531.exe
C:\WINDOWS\system32\drivers\down\97406.exe
C:\WINDOWS\system32\drivers\down\97968.exe
C:\WINDOWS\system32\drivers\down\99625.exe
C:\WINDOWS\system32\drivers\down\99656.exe
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mdelk.exe
C:\WINDOWS\system32\wintems.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_SROSA
-------\srosa
((((((((((((((((((((((((( Files Created from 2008-01-20 to 2008-02-20 )))))))))))))))))))))))))))))))
.
2008-02-19 21:26 . 2008-02-19 21:47 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-19 21:26 . 2008-02-19 21:26 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-19 21:26 . 2008-02-19 21:26 <DIR> d-------- C:\Documents and Settings\Big\Application Data\SUPERAntiSpyware.com
2008-02-19 21:26 . 2008-02-19 21:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-19 21:25 . 2008-02-19 21:26 <DIR> d-------- C:\Temp\SuperAntiSpyware
2008-02-19 21:23 . 2008-02-19 21:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-19 21:21 . 2008-02-19 21:22 <DIR> d-------- C:\Temp\AVGAntiSpyware7.5
2008-02-19 20:06 . 2008-02-19 20:06 <DIR> d-------- C:\Temp\Bagle
2008-02-19 07:49 . 2008-02-19 07:49 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-02-19 07:49 . 2008-02-19 07:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-17 19:49 . 2008-02-17 19:49 <DIR> d-------- C:\Program Files\Avira
2008-02-17 19:49 . 2008-02-17 19:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-02-17 19:44 . 2008-02-17 19:45 <DIR> d-------- C:\Temp\AviraAntiVir-Free
2008-02-17 16:00 . 2008-02-19 19:48 <DIR> d-------- C:\Temp\Office2CAD
2008-02-17 15:41 . 2008-02-17 15:42 <DIR> d-------- C:\Temp\VistaDriveIcon
2008-02-10 00:15 . 2008-02-10 00:15 <DIR> d-------- C:\Program Files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-18 02:37 --------- d-----w C:\Documents and Settings\Big\Application Data\Simple Sudoku
2008-02-18 00:37 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-18 00:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-17 23:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-17 22:34 --------- d-----w C:\Documents and Settings\Big\Application Data\Symantec
2008-02-17 21:58 --------- d-----w C:\Program Files\Simple Sudoku
2008-02-17 21:24 --------- d-----w C:\Program Files\MYIE2
2008-02-17 20:51 --------- d-----w C:\Program Files\eMule
2008-01-18 22:21 --------- d-----w C:\Documents and Settings\Marc\Application Data\Simple Sudoku
2007-12-31 23:31 --------- d-----w C:\Documents and Settings\Marc\Application Data\Autodesk
2007-12-29 04:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Autodesk
2007-12-29 03:56 --------- d-----w C:\Documents and Settings\Big\Application Data\Autodesk
2007-12-29 03:49 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2007-12-29 03:46 --------- d-----w C:\Program Files\AutoCAD MEP 2008
2007-12-23 17:53 --------- d-----w C:\Program Files\AutoCAD 2008
2007-12-23 02:11 --------- d-----w C:\Program Files\Autodesk
2007-12-23 01:10 --------- d-----w C:\Program Files\Autodesk Building Systems 2005
2007-12-23 01:05 --------- d-----w C:\Program Files\AutoCAD 2007
2007-12-23 00:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-23 00:36 --------- d-----w C:\Program Files\ASUS
2007-12-23 00:35 --------- d-----w C:\Program Files\Common Files\Acronis
2007-12-23 00:27 --------- d-----w C:\Program Files\Lavasoft
2007-12-23 00:27 --------- d-----w C:\Documents and Settings\Big\Application Data\Lavasoft
1989-12-12 14:10 840,000 --sha-r C:\WINDOWS\bak\jsgrgvfA.exe
2006-10-13 18:07 911,346 --sha-w C:\WINDOWS\system32\fgjlm.bak2
2007-05-29 01:47 1,543,908 --sha-w C:\WINDOWS\system32\rqtwa.bak1
2007-05-29 03:12 1,544,486 --sha-w C:\WINDOWS\system32\rqtwa.bak2
2007-05-29 03:12 1,544,092 --sha-w C:\WINDOWS\system32\rqtwa.ini2
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 0 2003-10-28 21:31:13 C:\Program Files\321Studios\Platinum\bak\makedir
----a-w 118,784 2005-10-26 03:48:30 C:\Program Files\Common Files\Acronis\Schedule2\bak\schedhlp.exe
----a-w 59,040 2008-02-19 15:49:58 C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe
----a-w 784,896 2005-02-18 02:44:28 C:\Program Files\dvd43\bak\dvd43_tray.exe
----a-w 155,896 2006-09-19 23:47:50 C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\bak\GoogleToolbarNotifier.exe
----a-w 98,304 2004-01-24 02:58:58 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 1,142,784 2004-04-12 22:51:40 C:\Program Files\SecCopy\bak\SecCopy.exe
----a-w 290,816 2005-11-11 21:47:10 C:\Program Files\Sunbelt Software\CounterSpy\Consumer\bak\sunserver.exe
--sha-r 840,000 1989-12-12 14:10:10 C:\WINDOWS\bak\jsgrgvfA.exe
----a-w 13,312 2003-03-31 12:00:00 C:\WINDOWS\system32\bak\ctfmon.exe
----a-w 15,360 2004-08-04 05:56:50 C:\WINDOWS\system32\ctfmon.exe
----a-w 491,520 2005-11-24 16:12:34 C:\WINDOWS\system32\spool\drivers\w32x86\3\bak\fppdis2a.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2005-10-22 06:03 675620]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39 1310720]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"@"="C:\Program Files\Internet Explorer\iexplore.exe" [2007-12-06 06:01 625664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2006-10-22 11:22 1622016 C:\WINDOWS\system32\nwiz.exe]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-01-22 16:22 81920]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 07:00 33648]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"DrvIcon"="C:\Program Files\Vista Drive Icon\DrvIcon.exe" [ ]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 11:22 7700480]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-19 22:09 249896]
C:\Documents and Settings\Big\Start Menu\Programs\Startup\
Dialog Tracker.lnk - C:\Program Files\Novatix\ExplorerPlus\Nxdlghlp.exe [2003-09-08 16:26:04 65536]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoBandCustomize"= 0 (0x0)
"NoMovingBands"= 0 (0x0)
"NoCloseDragDropBands"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
backup=C:\WINDOWS\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a------ 2006-11-07 10:29 50736 C:\Program Files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
--a------ 2006-08-11 13:56 17920 C:\WINDOWS\CTHELPER.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
--a------ 2006-08-11 13:56 18944 C:\WINDOWS\system32\CTXFIHLP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u
R0 si3112r;Silicon Image SiI 3112 SATARaid Controller;C:\WINDOWS\system32\drivers\si3112r.sys [2006-01-12 12:56]
R0 SiWinAcc;SiWinAcc;C:\WINDOWS\system32\drivers\SiWinAcc.sys [2004-11-01 12:21]
R3 ProtoWall;ProtoWall Network Service;C:\WINDOWS\system32\DRIVERS\ProtoWall.sys [2004-08-12 10:29]
S2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe []
S2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe []
S3 K5arddlog;K5arddlog;C:\WINDOWS\System32\rdshost.exe [2004-08-04 00:56]
S3 VICESYS;VICESYS;C:\Temp\Vice\VICESYS.sys [2004-04-19 15:27]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-19 22:14:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-02-19 22:23:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-20 03:23:51
ComboFix2.txt 2007-06-15 02:05:44
.
2008-02-13 01:08:13 --- E O F ---