I unchecked everything on autoruns then hit the close “x” button in the right corner. Then I ran autoruns again and nothing was checked this time. I named combofix paul.exe on the flash drive, copied it to the desktop, copied the windows link to the desktop, then dropped the link onto combofix (paul.exe) and it automatically ran. I agreed to the Combofix user agreement and it ran (I did all of this in safe mode)
I still can’t get into system recovery. It is just a black screen with a blinking curser in the upper left corner. I hit 1, enter, other keys and nothing happens. Just sits there.
Below is my latest log
ComboFix 11-08-27.01 - User 08/26/2011 17:39:33.8.1 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.790 [GMT -4:00]
Running from: d:\documents and settings\Desktop\paul.exe
Command switches used :: d:\documents and settings\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
AV: AntiVir Desktop *Disabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Trend Micro OfficeScan Enterprise Client Firewall *Enabled* {9EFC479D-082C-471E-BB2E-DB50CFB21926}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
d:\documents and settings\Desktop\autoruns.exe
d:\documents and settings\Desktop\paul.exe
d:\documents and settings\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-07-26 to 2011-08-26 )))))))))))))))))))))))))))))))
.
.
2011-08-26 17:23 . 2008-04-13 18:40 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-08-26 14:45 . 2011-08-26 14:45 -------- d-sh--w- d:\documents and settings\LocalService.NT AUTHORITY.000
2011-08-26 14:45 . 2011-08-26 14:45 -------- d-sh--w- d:\documents and settings\NetworkService.NT AUTHORITY.000
2011-08-26 14:43 . 2011-08-26 14:43 -------- d-----w- c:\windows\system32\wbem\Repository
2011-08-26 14:42 . 2011-08-26 14:42 -------- d-----w- d:\documents and settings\All Users\Application Data\Avira
2011-08-26 14:42 . 2011-08-26 14:42 -------- d-----w- c:\windows\system32\save$$updater
2011-08-26 14:42 . 2011-08-26 14:42 -------- d-----w- c:\windows\system32\(null)
2011-08-26 14:42 . 2011-08-26 14:42 -------- d-----w- c:\program files\Avira
2011-08-25 02:45 . 2011-07-06 23:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-25 02:45 . 2011-07-06 23:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-24 00:45 . 2011-08-24 00:45 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-08-24 00:45 . 2011-08-24 00:45 142296 ----a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-08-24 00:45 . 2011-08-24 00:45 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
2011-08-24 00:45 . 2011-08-24 00:45 89048 ----a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-08-24 00:45 . 2011-08-24 00:45 465880 ----a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-08-24 00:45 . 2011-08-24 00:45 15832 ----a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-08-24 00:45 . 2011-08-24 00:45 1850328 ----a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-08-24 00:45 . 2011-08-24 00:45 781272 ----a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-08-15 01:05 . 2011-08-15 01:05 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-11 01:31 . 2006-10-18 18:05 232448 ----a-w- c:\windows\system32\mp3fhg.acm
2011-08-11 01:31 . 2011-07-16 14:17 151552 ----a-w- c:\windows\system32\ac3acm.acm
2011-08-11 01:31 . 2011-06-24 14:44 243200 ----a-w- c:\windows\system32\xvidvfw.dll
2011-08-11 01:31 . 2011-06-24 14:28 650752 ----a-w- c:\windows\system32\xvidcore.dll
2011-08-11 01:31 . 2010-11-03 18:08 237568 ----a-w- c:\windows\system32\yv12vfw.dll
2011-08-11 01:31 . 2011-08-08 08:00 74752 ----a-w- c:\windows\system32\ff_vfw.dll
2011-08-11 00:54 . 2011-08-11 00:54 -------- d-----w- d:\documents and settings\User\Application Data\Media Player Classic
2011-08-11 00:50 . 2005-05-26 19:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2011-08-11 00:48 . 2011-08-11 00:48 -------- d-----w- c:\windows\Logs
2011-08-11 00:47 . 2011-08-11 00:47 -------- d-----w- c:\program files\Media Player Classic - Home Cinema
2011-08-10 18:49 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-10 18:49 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2011-08-09 03:20 . 2011-03-02 10:43 175616 ----a-w- c:\windows\system32\unrar.dll
2011-08-02 00:42 . 2011-08-02 00:42 -------- d-----w- d:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Apple
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-21 04:00 . 2005-04-27 13:16 5427 ----a-w- c:\windows\system32\EGATHDRV.SYS
2011-07-15 13:29 . 2005-06-28 01:12 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2005-06-28 01:12 10496 ------w- c:\windows\system32\drivers\ndistapi.sys
2011-06-24 14:10 . 2005-06-27 22:24 139656 ------w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36 . 2005-06-28 01:12 916480 ----a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36 . 2005-06-28 01:12 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36 . 2005-06-28 01:11 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2005-06-28 01:11 385024 ----a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2005-06-28 01:12 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-06-02 14:02 . 2005-06-28 01:12 1858944 ------w- c:\windows\system32\win32k.sys
2011-08-24 00:45 . 2011-08-24 00:45 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-26_17.39.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-25 14:53 . 2011-08-26 20:27 214452 c:\windows\system32\inetsrv\MetaBase.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-02-14 512000]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2006-02-14 110592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\katrack.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0090404]
IME File REG_SZ MSTCICJA.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0080404]
IME File REG_SZ MSTCIPHA.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200412]
Ime File REG_SZ IMEKR70.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0100804]
IME File REG_SZ WINWB86.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0110804]
IME File REG_SZ WINWB98.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e00e0804]
IME File REG_SZ IMSC40A.IME
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200411]
Ime File REG_SZ IMJP9.IME
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Visual Studio\\COMMON\\Tools\\VS-Ent98\\Vanalyzr\\VARPC.EXE"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\java.exe"=
"c:\\Program Files\\IBM\\Updater\\jre\\bin\\javaw.exe"=
"c:\\Program Files\\IBM\\Updater\\ucsmb.exe"=
"c:\\WINDOWS\\keyacc32.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AirPort\\APAgent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\inetsrv\\inetinfo.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5353:UDP"= 5353:UDP:Bonjour
.
R3 TPM11;NSC Integrated Trusted Platform Module 1.1;c:\windows\system32\drivers\nsctpm11.sys [8/2/2005 6:00 PM 14336]
R4 TPDiskPM;TPDiskPM;c:\windows\system32\drivers\TPDiskPM.sys [6/27/2005 6:49 PM 14848]
R4 TPInput;TPInput;c:\windows\system32\drivers\TPInput.sys [6/27/2005 6:49 PM 6784]
S4 AntiVirSchedulerService;Avira AntiVir Scheduler;"c:\program files\Avira\AntiVir Desktop\sched.exe" --> c:\program files\Avira\AntiVir Desktop\sched.exe [?]
S4 smi2;smi2;c:\program files\SMI2\smi2.sys [8/2/2005 5:47 PM 3968]
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title = Sacred Heart University
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.10.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - d:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\2x311ay5.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
Notify-AutorunsDisabled - notifyf2.dll tphklock.dll WgaLogon.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-08-26 17:51
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\.redbook]
"ImagePath"="\*"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(264)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\tphklock.dll
.
Completion time: 2011-08-26 17:56:31
ComboFix-quarantined-files.txt 2011-08-26 21:56
ComboFix2.txt 2011-08-26 19:15
ComboFix3.txt 2011-08-26 18:00
ComboFix4.txt 2011-08-26 17:45
.
Pre-Run: 18,785,759,232 bytes free
Post-Run: 18,750,025,728 bytes free
.
- - End Of File - - 04B955BF107527587E84F5D3DDD360F4