Okee dokee...
I ran Fixwareout again. And it completed this time. Something was hanging it up before and it completed this time, here's the log..
The ComboFix log with the recovery console is below.
Thanks again for your help.
Username "Dave" - 04/19/2008 18:27:33 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_05\\bin\\jusched.exe\""
"SoundMAXPnP"="\"C:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe\""
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"osCheck"="\"C:\\Program Files\\Norton AntiVirus\\osCheck.exe\""
"Samsung PanelMgr"="C:\\WINDOWS\\Samsung\\PanelMgr\\SSMMgr.exe /autorun"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
ComboFix 08-04-18.3 - Dave 2008-04-19 18:18:33.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.625 [GMT -7:00]
Running from: C:\Documents and Settings\Dave\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Dave\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-03-20 to 2008-04-20 )))))))))))))))))))))))))))))))
.
2008-04-13 15:10 . 2008-04-13 15:10 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-13 14:53 . 2008-04-13 14:53 <DIR> d-------- C:\Program Files\Panda Security
2008-04-13 14:37 . 2008-04-19 08:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-04-13 14:36 . 2008-04-13 14:37 <DIR> d-------- C:\Program Files\Google
2008-04-13 13:23 . 2008-04-13 13:23 <DIR> d-------- C:\!KillBox
2008-04-13 13:00 . 2008-04-13 13:00 <DIR> d--h----- C:\WINDOWS\PIF
2008-04-13 01:41 . 2008-04-13 01:43 <DIR> d-------- C:\Dist 2
2008-04-12 23:38 . 2008-04-13 11:51 <DIR> d-------- C:\Distributed
2008-04-12 23:05 . 2008-04-12 23:05 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-12 22:55 . 2007-07-09 06:09 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-04-12 22:40 . 2008-04-11 04:14 <DIR> d-------- C:\SDFix
2008-04-12 22:09 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-04-12 20:58 . 2008-04-12 20:59 <DIR> d-------- C:\Documents and Settings\Dave\.SunDownloadManager
2008-04-12 19:55 . 2008-04-17 20:22 <DIR> d-------- C:\fixwareout
2008-04-12 18:42 . 2008-04-12 18:42 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-12 18:42 . 2008-04-12 18:42 <DIR> d-------- C:\Documents and Settings\Dave\Application Data\Malwarebytes
2008-04-12 18:42 . 2008-04-12 18:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-12 18:33 . 2008-04-12 18:33 283,160 --a------ C:\Pass2.cmd
2008-04-12 18:32 . 2008-04-12 18:32 2,700 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-12 18:31 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-04-12 18:31 . 2008-03-29 00:19 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-04-12 18:31 . 2008-04-08 22:44 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-04-12 18:31 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-04-12 18:31 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-12 18:31 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-12 18:26 . 2008-04-12 18:26 <DIR> d-------- C:\Deckard
2008-04-12 17:31 . 2008-04-12 17:31 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2008-04-12 17:16 . 2008-04-12 17:16 <DIR> d-------- C:\VundoFix Backups
2008-04-12 16:51 . 2004-08-04 00:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-04-12 16:51 . 2004-08-04 01:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-04-05 11:05 . 2001-08-23 05:00 4,224 --a------ C:\WINDOWS\system32\beep.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-13 22:19 --------- d-----w C:\Documents and Settings\Dave\Application Data\Intuit
2008-04-13 09:40 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-13 05:33 --------- d-----w C:\Program Files\Norton AntiVirus
2008-04-13 05:09 --------- d-----w C:\Program Files\Java
2008-03-25 02:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-10 05:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-10 05:16 --------- d-----w C:\Program Files\Samsung
2008-03-09 18:59 --------- d-----w C:\Program Files\MSECache
2008-03-09 17:08 --------- d-----w C:\Documents and Settings\Ingrid\Application Data\Intuit
2008-03-08 19:20 --------- d-----w C:\Program Files\Common Files\AnswerWorks 4.0
2008-03-08 19:18 --------- d-----w C:\Program Files\TurboTax
2008-03-07 05:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-07 05:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-07 05:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 20:07 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2007-04-06 03:22 17,936,384 ----a-w C:\Program Files\Jupiter-8V.dll
.
((((((((((((((((((((((((((((( snapshot_2008-04-13_11.19.08.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-20 00:56:06 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-03-26 01:13:04 124,208 ----a-w C:\WINDOWS\Downloaded Program Files\as2stubie.dll
+ 2007-07-18 20:49:56 12,592 ----a-w C:\WINDOWS\Downloaded Program Files\libcomm.dll
+ 2007-03-26 01:10:53 2,722 ----a-w C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\SkuStore.bin
+ 2004-08-04 09:07:22 1,788 ------w C:\WINDOWS\ServicePackFiles\i386\dcache.bin
+ 2004-08-04 07:07:58 2,944 ------w C:\WINDOWS\ServicePackFiles\i386\drmkaud.sys
+ 2001-08-23 12:00:00 2,000 ----a-w C:\WINDOWS\system\KEYBOARD.DRV
+ 2001-08-23 12:00:00 2,032 ----a-w C:\WINDOWS\system\MOUSE.DRV
+ 2001-08-23 12:00:00 1,744 ----a-w C:\WINDOWS\system\SOUND.DRV
+ 2001-08-23 12:00:00 2,176 ----a-w C:\WINDOWS\system\VGA.DRV
- 2008-04-13 17:39:51 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-20 00:56:07 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-04-13 17:39:51 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-20 00:56:07 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-04-13 17:39:51 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-20 00:56:07 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2004-08-04 09:07:22 1,788 ----a-w C:\WINDOWS\system32\dcache.bin
+ 2004-08-04 07:07:58 2,944 -c--a-w C:\WINDOWS\system32\dllcache\drmkaud.sys
+ 2001-08-23 12:00:00 2,000 -c--a-w C:\WINDOWS\system32\dllcache\keyboard.drv
+ 2001-08-23 12:00:00 2,560 -c--a-w C:\WINDOWS\system32\dllcache\lz32.dll
+ 2001-08-23 12:00:00 2,032 -c--a-w C:\WINDOWS\system32\dllcache\mouse.drv
+ 2001-08-23 12:00:00 2,944 -c--a-w C:\WINDOWS\system32\dllcache\null.sys
+ 2001-08-23 12:00:00 1,744 -c--a-w C:\WINDOWS\system32\dllcache\sound.drv
+ 2001-08-23 12:00:00 2,176 -c--a-w C:\WINDOWS\system32\dllcache\vga.drv
+ 2001-08-23 12:00:00 2,864 -c--a-w C:\WINDOWS\system32\dllcache\winsock.dll
+ 2001-08-23 12:00:00 2,112 -c--a-w C:\WINDOWS\system32\dllcache\winspool.exe
+ 2001-08-23 12:00:00 2,736 -c--a-w C:\WINDOWS\system32\dllcache\wowdeb.exe
+ 2004-08-04 07:07:58 2,944 ----a-w C:\WINDOWS\system32\drivers\drmkaud.sys
+ 2001-08-23 12:00:00 2,944 ----a-w C:\WINDOWS\system32\drivers\null.sys
+ 2001-08-23 12:00:00 2,000 ----a-w C:\WINDOWS\system32\keyboard.drv
+ 2001-08-23 12:00:00 2,560 ----a-w C:\WINDOWS\system32\lz32.dll
+ 2001-08-23 12:00:00 2,032 ----a-w C:\WINDOWS\system32\mouse.drv
+ 2001-08-23 12:00:00 2,656 ----a-w C:\WINDOWS\system32\netware.drv
+ 2001-08-23 12:00:00 1,744 ----a-w C:\WINDOWS\system32\sound.drv
+ 2001-08-23 12:00:00 2,176 ----a-w C:\WINDOWS\system32\vga.drv
+ 2001-08-23 12:00:00 2,864 ----a-w C:\WINDOWS\system32\winsock.dll
+ 2001-08-23 12:00:00 2,112 ----a-w C:\WINDOWS\system32\winspool.exe
+ 2001-08-23 12:00:00 2,736 ----a-w C:\WINDOWS\system32\wowdeb.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-13 14:37 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 11:07 843776]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 18:41 45056]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 22:59 115816]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-01-14 00:11 771704]
"Samsung PanelMgr"="C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe" [2007-10-22 21:11 524288]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 02:19:50 217193]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-03-25 19:31:56 113664]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-13 14:37:01 124400]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
R0 atiide;atiide;C:\WINDOWS\system32\DRIVERS\atiide.sys [2006-09-13 20:01]
R2 FAH@C:+Distributed+fah6-win32-x86.exe;FAH@C:+Distributed+fah6-win32-x86.exe;C:\Distributed\fah6-win32-x86.exe [2008-03-11 15:39]
R2 RVIEG01;VSC Engine;C:\Program Files\Cakewalk\Shared Dxi\Roland\RVIEg01.sys [2001-04-13 20:16]
S2 SSPORT;SSPORT;C:\WINDOWS\system32\Drivers\SSPORT.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{655fc20b-dfe3-11db-a707-001aa00a7745}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-04-08 04:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Dave.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-19 18:19:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\drivers\clbdriver.sys 7168 bytes executable
C:\WINDOWS\system32\clb.dll 10752 bytes executable
C:\WINDOWS\system32\clbcatex.dll 110080 bytes executable
C:\WINDOWS\system32\clbcatq.dll 501248 bytes executable
C:\WINDOWS\system32\clbcfg.dat 1680 bytes
C:\WINDOWS\system32\clbdll.dll 40960 bytes executable
scan completed successfully
hidden files: 6
**************************************************************************
"ServiceDll"="C:\WINDOWS\System32\es.dll"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\FAH@C:+Distributed+fah6-win32-x86.exe]
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\clbdriver]
"imagepath"="\??\globalroot\systemroot\system32\drivers\clbdriver.sys"
.
Completion time: 2008-04-19 18:20:25
ComboFix-quarantined-files.txt 2008-04-20 01:20:22
ComboFix2.txt 2008-04-18 03:28:45
ComboFix3.txt 2008-04-13 19:45:26
ComboFix4.txt 2008-04-13 18:19:21
ComboFix5.txt 2008-04-13 05:00:54
Pre-Run: 7,789,338,624 bytes free
Post-Run: 7,760,424,960 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
179 --- E O F --- 2008-04-13 06:24:00