Thank You, Thank You! I ran as requested, and now all of my icons are back along with start button and taskbar. Already a major improvement! Log file is below.
ComboFix 09-06-11.06 - Mike Wilkinson 06/12/2009 9:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.990.616 [GMT -4:00]
Running from: c:\documents and settings\Mike Wilkinson\Desktop\ComboFix.exe
AV: AVG Anti-Virus Network Edition *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\d7592b6f.sys
C:\-1265238579
c:\windows\Install.txt
c:\windows\system32\drivers\UACdgiocylfwuiamof.sys
c:\windows\system32\mssfc.dll
c:\windows\system32\sfcfiles.dat
c:\windows\system32\UACcsxectwvfentfym.dll
c:\windows\system32\UAChxlrxuurilldbvx.log
c:\windows\system32\uacinit.dll
c:\windows\system32\UACiowjfijcnwlxngy.dll
c:\windows\system32\UACjlmtkjbyqwjawbx.dll
c:\windows\system32\UACmoycrsgwboymdfj.log
c:\windows\system32\UACnkpmokbmvixynee.log
c:\windows\system32\UACprqxfmqpqmowksp.dll
c:\windows\system32\UACtebxdnwoctsvpbu.dat
c:\windows\system32\UACwcpexmfuyavbdve.dll
C:\xcrashdump.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_6to4
-------\Legacy_dhcpsrv
-------\Legacy_I386SI
-------\Legacy_isadisk
-------\Legacy_msncache
-------\Legacy_sopidkc
-------\Service_6to4
-------\Service_d7592b6f
-------\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-05-12 to 2009-06-12 )))))))))))))))))))))))))))))))
.
2009-06-11 13:02 . 2009-06-11 13:03 3371383 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-11 13:00 . 2009-05-13 12:40 3401496 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-06-11 13:00 . 2009-05-13 12:40 2301208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avguiadv.dll
2009-06-11 13:00 . 2009-05-13 12:40 3288856 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-06-11 13:00 . 2009-05-13 12:40 1262880 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwd.dll
2009-06-11 12:59 . 2009-05-18 14:19 1439488 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-06-11 12:59 . 2009-05-13 12:40 1085208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-06-11 12:53 . 2004-08-04 10:00 20736 -c--a-w- c:\windows\system32\dllcache\ramdisk.sys
2009-06-11 12:52 . 2004-08-04 10:00 10129408 -c--a-w- c:\windows\system32\dllcache\hwxkor.dll
2009-06-11 12:51 . 2004-08-04 10:00 29696 -c--a-w- c:\windows\system32\dllcache\admexs.dll
2009-06-10 20:18 . 2009-06-10 20:18 -------- d-----w- c:\documents and settings\Default User\Application Data\Malwarebytes
2009-06-10 20:13 . 2004-08-04 10:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-06-10 20:13 . 2004-08-04 10:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2009-06-10 20:13 . 2004-08-04 10:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2009-06-10 20:13 . 2004-08-04 10:00 13312 ----a-w- c:\windows\system32\irclass.dll
2009-06-10 20:11 . 2009-06-10 20:11 -------- d-s---w- c:\windows\system32\config\systemprofile\History
2009-06-10 15:57 . 2009-06-10 15:57 -------- d-----w- c:\windows\dell
2009-06-08 19:31 . 2009-06-10 13:17 0 ----a-w- c:\windows\system32\drivers\7cb889c2.sys
2009-06-08 16:21 . 2009-06-08 16:21 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\AOL
2009-06-08 16:18 . 2009-06-08 16:18 36320 ----a-w- c:\windows\system32\drivers\bfmf602.sys
2009-06-07 06:43 . 2009-06-09 13:54 -------- d-----w- c:\windows\dhcp
2009-06-05 14:54 . 2009-06-05 14:54 -------- d-----w- c:\documents and settings\Mike Wilkinson\Application Data\AVG8
2009-05-30 17:13 . 2009-06-10 18:49 -------- d-----w- c:\program files\DivX
2009-05-18 14:23 . 2009-05-18 14:23 -------- d-----w- c:\documents and settings\Mike Wilkinson\Application Data\Malwarebytes
2009-05-18 14:23 . 2009-05-26 17:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-18 14:23 . 2009-05-26 17:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-18 14:23 . 2009-06-11 13:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-05-18 14:23 . 2009-05-18 14:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-12 13:09 . 2008-03-21 17:16 -------- d-----w- c:\program files\LogMeIn
2009-06-11 13:00 . 2008-04-29 18:15 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-11 12:47 . 2004-08-11 22:12 23428 ----a-w- c:\windows\system32\emptyregdb.dat
2009-06-09 13:57 . 2008-04-29 18:15 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-02 18:14 . 2007-02-28 20:56 -------- d-----w- c:\program files\Room Viewer
2009-05-13 12:40 . 2009-05-13 12:41 2051864 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-04-26 13:05 . 2008-04-29 18:15 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-04-26 13:05 . 2008-04-29 18:15 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-04-26 13:04 . 2008-04-29 18:15 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-04-26 13:04 . 2008-04-29 18:15 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2007-02-23 19:27 . 2007-02-23 19:10 5855216 ----a-w- c:\program files\clj2550pcl6win2kxp2003-en.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 63048]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-11 1948440]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 158208]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-26 13:05 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-17 00:35 87352 ----a-w- c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\c:^documents and settings^mike wilkinson^start menu^programs^startup^zqosys32.exe]
path=c:\documents and settings\Mike Wilkinson\Start Menu\Programs\Startup\zqosys32.exe
backup=c:\windows\pss\zqosys32.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"gusvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [2/20/2007 9:50 PM 3456]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [4/29/2008 2:15 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/29/2008 2:15 PM 327688]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/29/2008 2:15 PM 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/8/2009 11:06 AM 298776]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [8/3/2007 3:09 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [3/21/2008 1:17 PM 47640]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [7/5/2008 9:11 PM 24652]
S1 7cb889c2;7cb889c2;c:\windows\system32\drivers\7cb889c2.sys [6/8/2009 3:31 PM 0]
S2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [4/14/2006 11:07 AM 28933976]
S2 rdhae;rdhae;c:\windows\system32\drivers\nrptq.sys --> c:\windows\system32\drivers\nrptq.sys [?]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-12 09:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(660)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\Crypserv.exe
c:\program files\LogMeIn\x86\ramaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\wscntfy.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
.
**************************************************************************
.
Completion time: 2009-06-12 10:02 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-12 14:02
Pre-Run: 61,414,850,560 bytes free
Post-Run: 61,941,202,944 bytes free
Current=4 Default=4 Failed=0 LastKnownGood=1 Sets=1,2,3,4
169 --- E O F --- 2009-05-28 14:21