Alright, I downloaded ComboFix, followed the instructions and let it run. I didn't get any prompts whatsoever during the scan, and only noticed that it erased a file from my system32 folder.
Checking the log file for myself, it says that my laptop doesn't have the Microsoft Windows Recovery Console installed, yet according to your guide I didn't receive a prompt for it. ComboFix also didn't re-start my laptop after deleting that one file (maybe it was a minor one). Regardless, here's the log file, hope it is of help. So, how can I go about installing this Recovery Console?:
EDIT: Correction, I ran a second ComboFix scan, received the same prompts listed in your guide, and ComboFix d/led and installed Recovery Console. It didn't delete anything the second time around. Services such as "Automatic Updates" and "BITS (Background Intelligent Transfer Service) are still permanently stopped though.ComboFix 09-04-04.01 - Daniel Ramirez 2009-04-09 5:01:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.533 [GMT -4:00]
Running from: c:\documents and settings\Daniel Ramirez\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\uniq.tll
.
((((((((((((((((((((((((( Files Created from 2009-03-09 to 2009-04-09 )))))))))))))))))))))))))))))))
.
2009-04-03 23:55 . 2009-04-03 23:55 <DIR> d----c--- c:\documents and settings\Daniel Ramirez\Application Data\Ahead
2009-04-03 22:43 . 2009-04-03 23:28 <DIR> d----c--- c:\documents and settings\Daniel Ramirez\Application Data\BitTorrent
2009-04-03 22:09 . 2009-04-03 22:09 <DIR> d----c--- c:\documents and settings\Daniel Ramirez\Application Data\com.doubleperfect.ggpo.0753AD3679DBFCA1E7F470171B7D0DB8B404A7EA.1
2009-04-02 02:16 . 2009-04-02 02:18 <DIR> d----c--- c:\documents and settings\Daniel Ramirez\Application Data\vlc
2009-04-01 02:24 . 2009-04-01 02:24 <DIR> d--hsc--- c:\documents and settings\Daniel Ramirez\IECompatCache
2009-04-01 02:22 . 2009-04-01 02:22 <DIR> d--hsc--- c:\documents and settings\LocalService\IETldCache
2009-04-01 02:22 . 2009-04-01 02:22 <DIR> d--hsc--- c:\documents and settings\Daniel Ramirez\PrivacIE
2009-04-01 02:21 . 2009-04-01 02:21 <DIR> d--hsc--- c:\documents and settings\NetworkService\IETldCache
2009-04-01 02:21 . 2009-04-01 02:21 <DIR> d--hsc--- c:\documents and settings\Daniel Ramirez\IETldCache
2009-04-01 02:14 . 2009-04-01 02:15 <DIR> d--h-c--- c:\windows\ie8
2009-03-31 21:20 . 2009-04-01 01:09 <DIR> d----c--- c:\program files\Windows Live Safety Center
2009-03-29 00:13 . 2009-03-29 05:21 <DIR> d----c--- c:\documents and settings\Daniel Ramirez\Application Data\Winamp
2009-03-28 02:27 . 2009-03-28 02:28 <DIR> d----c--- C:\RootkitNO
2009-03-28 02:05 . 2009-03-28 02:49 <DIR> d----c--- c:\program files\UnHackMe
2009-03-28 02:05 . 2009-03-28 02:05 (2) -rahscot- c:\windows\winstart.bat
2009-03-28 01:29 . 2009-03-28 01:29 <DIR> d----c--- c:\documents and settings\Daniel Ramirez\Application Data\Windows Search
2009-03-27 21:32 . 2009-03-27 21:32 <DIR> d----c--- c:\program files\Prevx
2009-03-27 21:32 . 2009-03-29 21:48 <DIR> d----c--- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-03-27 21:32 . 2009-03-27 21:32 22,024 --a--c--- c:\windows\system32\drivers\pxscan.sys
2009-03-27 21:32 . 2009-03-27 21:32 67 --a--c--- c:\windows\wininit.ini
2009-03-27 05:50 . 2009-03-27 05:50 <DIR> d----c--- c:\documents and settings\Daniel Ramirez\Application Data\SUPERAntiSpyware.com
2009-03-27 04:14 . 2009-03-27 04:14 <DIR> d----c--- c:\documents and settings\Daniel Ramirez\Application Data\Malwarebytes
2009-03-27 04:12 . 2008-01-20 23:52 <DIR> d----c--- c:\documents and settings\Daniel Ramirez\Application Data\Apple Computer
2009-03-27 04:12 . 2009-04-01 02:24 <DIR> d----c--- c:\documents and settings\Daniel Ramirez
2009-03-27 02:10 . 2009-03-27 02:10 <DIR> d----c--- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-03-27 01:57 . 2009-03-27 01:57 <DIR> d----c--- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-03-27 01:46 . 2009-03-27 01:46 182,656 --a--c--- c:\windows\system32\dllcache\ndis.sys
2009-03-25 22:05 . 2009-03-27 05:11 <DIR> d----c--- c:\program files\hkSFV
2009-03-20 00:52 . 2009-03-20 00:52 <DIR> d----c--- c:\documents and settings\All Users\Application Data\RoboForm
2009-03-12 16:28 . 2009-03-12 16:28 <DIR> d----c--- c:\program files\Virtual VCR
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-09 08:58 --------- dc----w c:\program files\Symantec AntiVirus
2009-04-08 06:39 --------- dc----w c:\program files\Malwarebytes' Anti-Malware
2009-04-06 19:32 38,496 -c--a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 19:32 15,504 -c--a-w c:\windows\system32\drivers\mbam.sys
2009-03-27 09:30 --------- dc----w c:\program files\Replay Music 3
2009-03-27 05:46 182,656 -c--a-w c:\windows\system32\drivers\ndis.sys
2009-03-27 05:36 323,584 -c--a-w c:\windows\system32\AUDIOGENIE2.DLL
2009-03-22 17:50 --------- dc----w c:\program files\Common Files\Adobe
2009-03-14 03:01 --------- dc----w c:\program files\Winamp
2009-03-14 00:26 --------- dc----w c:\program files\Common Files\Adobe AIR
2009-03-12 20:26 --------- dc----w c:\program files\DScaler
2009-03-11 23:28 --------- dc----w c:\program files\QuickTime
2009-03-10 02:24 --------- dc----w c:\program files\Google
2009-03-08 08:34 914,944 -c--a-w c:\windows\system32\wininet.dll
2009-03-08 08:34 43,008 -c--a-w c:\windows\system32\licmgr10.dll
2009-03-08 08:33 420,352 -c--a-w c:\windows\system32\vbscript.dll
2009-03-08 08:33 18,944 -c--a-w c:\windows\system32\corpol.dll
2009-03-08 08:32 72,704 -c--a-w c:\windows\system32\admparse.dll
2009-03-08 08:32 71,680 -c--a-w c:\windows\system32\iesetup.dll
2009-03-08 08:31 48,128 -c--a-w c:\windows\system32\mshtmler.dll
2009-03-08 08:31 45,568 -c--a-w c:\windows\system32\mshta.exe
2009-03-08 08:31 34,816 -c--a-w c:\windows\system32\imgutil.dll
2009-03-08 08:22 156,160 -c--a-w c:\windows\system32\msls31.dll
2009-02-27 02:17 --------- dc----w c:\program files\Microsoft Silverlight
2009-02-14 08:35 --------- dc----w c:\program files\MSECache
2009-02-09 11:13 1,846,784 -c--a-w c:\windows\system32\win32k.sys
2009-01-16 19:45 73,728 -c--a-w c:\windows\system32\RtNicProp32.dll
2008-10-01 21:58 67,696 -c--a-w c:\program files\mozilla firefox\components\jar50.dll
2008-10-01 21:58 54,376 -c--a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-10-01 21:58 34,952 -c--a-w c:\program files\mozilla firefox\components\myspell.dll
2008-10-01 21:58 46,720 -c--a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-10-01 21:58 172,144 -c--a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-10-06 23:48 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008100620081007\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-11-21 52840]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2006-10-16 1197648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
"washindex"="c:\program files\Cookie Washer\washidx.exe" [2001-07-24 72704]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.g723"= g723.acm
"vidc.I263"= I263_32.drv
"VIDC.I420"= i263_32.drv
"msacm.avis"= ff_acm.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ActivClient Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ActivClient Agent.lnk
backup=c:\windows\pss\ActivClient Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111T Smart Wizard.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111T Smart Wizard.lnk
backup=c:\windows\pss\NETGEAR WG111T Smart Wizard.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickTV.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickTV.lnk
backup=c:\windows\pss\QuickTV.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WLAN Configuration Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WLAN Configuration Utility.lnk
backup=c:\windows\pss\WLAN Configuration Utility.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^User^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\User\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\63204]
--a--c--- 2008-09-06 08:46 8461992 c:\windows\63204.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a--c--- 2009-02-27 17:10 35696 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a--c--- 2008-08-06 11:21 50472 c:\program files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a--c--- 2004-12-08 00:10 344064 c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a--c--- 2008-11-29 21:31 342336 c:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccWasher]
--a--c--- 2001-08-16 12:34 2982400 c:\program files\Cookie Washer\aolwasher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a--c--- 2008-04-13 20:12 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a--c--- 2008-08-08 08:11 490952 c:\program files\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a--c--- 2008-11-20 14:20 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
-----c--- 2008-04-13 20:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2006-01-12 15:40 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2009-01-05 16:18 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2008-06-10 04:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--a--c--- 2008-09-03 14:07 1576176 c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a--c--- 2004-12-29 03:55 688218 c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
--a--c--- 2004-12-29 03:55 98394 c:\program files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
--a--c--- 2007-03-14 22:49 125632 c:\progra~1\SYMANT~1\VPTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a--c--- 2005-05-03 18:43 69632 c:\windows\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
--a--c--- 2005-09-21 15:32 2807808 c:\windows\ALCWZRD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey]
--a--c--- 2001-12-26 04:12 472576 c:\windows\mHotkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
-----c--- 2004-08-12 20:45 61952 c:\windows\system32\Hdaudpropshortcut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PtiuPbmd]
--a--c--- 2004-10-07 05:07 24576 c:\windows\system32\ptipbm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a--c--- 2005-09-21 10:24 86016 c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)
"SLService"=2 (0x2)
"SavRoam"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"Viewpoint Manager Service"=2 (0x2)
"gupdate1c9a12749c48388"=2 (0x2)
"CSIScanner"=2 (0x2)
"btwdins"=2 (0x2)
"msfwsvc"=2 (0x2)
"OcHealthMon"=2 (0x2)
"OneCareMP"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\MusicBrainz Picard\\picard.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\Camisa Negra\\My Video Games Folder\\Emulators\\Arcade\\Dedicated Arcade Emulators\\GGPOFBA (MC68000 - Z80 Arcade Emulator)\\ggpo.exe"=
"c:\\Documents and Settings\\Camisa Negra\\My Video Games Folder\\Emulators\\Arcade\\Dedicated Arcade Emulators\\GGPOFBA (MC68000 - Z80 Arcade Emulator)\\ggpofba.exe"=
"c:\\Netgear\\Netgear Super-G Wireless Router (WGT624)\\bin\\IA\\Core\\MDM_Util.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"7000:TCP"= 7000:TCP:ggpo
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2009-03-27 22024]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-09-03 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-09-03 55024]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-06 101936]
R3 PhTVTune;Cap7134 TVTuner;c:\windows\system32\drivers\PhTVTune.sys [2005-06-20 42176]
S3 bcmntio;bcmntio;\??\c:\progra~1\CheckIt\UTILIT~1\bcmntio.sys --> c:\progra~1\CheckIt\UTILIT~1\bcmntio.sys [?]
S3 CB54G3;Wireless CB54G3/MP54G3 Wireless LAN Card Driver;c:\windows\system32\drivers\i2220ntx.sys [2005-06-20 148480]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [2008-11-09 17149]
S3 mapmem;mapmem;\??\c:\progra~1\CheckIt\UTILIT~1\mapmem.sys --> c:\progra~1\CheckIt\UTILIT~1\mapmem.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2008-05-21 34576]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-09-03 7408]
S3 SCR131C;SCRx31 Serial Smart Card Reader;c:\windows\system32\DRIVERS\SCR131C.sys --> c:\windows\system32\DRIVERS\SCR131C.sys [?]
S3 SCR33X USB Smart Card Reader;SCR33X USB Smart Card Reader;c:\windows\system32\DRIVERS\SCR33X2K.sys --> c:\windows\system32\DRIVERS\SCR33X2K.sys [?]
S3 Slazldrv;SmartLink AMR_PCI Driver;c:\windows\system32\drivers\slazldrv.sys [2004-12-29 223112]
S4 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [2009-03-27 4414520]
S4 gupdate1c9a12749c48388;Google Update Service (gupdate1c9a12749c48388);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-09 133104]
S4 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2007-03-14 116416]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-03-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-02-22 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\system32\cleanmgr.exe [2008-04-13 20:12]
2009-04-09 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-09 22:24]
2009-02-27 c:\windows\Tasks\Symantec AntiVirus.job
- c:\progra~1\SYMANT~1\VPC32.exe [2007-03-14 22:49]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-accrdsub - c:\program files\ActivIdentity\ActivClient\accrdsub.exe
MSConfigStartUp-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
MSConfigStartUp-IDMan - c:\program files\Internet Download Manager\IDMan.exe
MSConfigStartUp-Mlasebewahaz - c:\windows\Nreqagubinago.dll
MSConfigStartUp-Norton Ghost 10 - c:\program files\Norton Ghost\Agent\GhostTray.exe
MSConfigStartUp-OneCareUI - c:\program files\Microsoft Windows OneCare Live\winssnotify.exe
MSConfigStartUp-reader_s - c:\windows\System32\reader_s.exe
MSConfigStartUp-RoboForm - c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
MSConfigStartUp-UnHackMe Monitor - c:\program files\UnHackMe\hackmon.exe
MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe
MSConfigStartUp-Framework Windows - frmwrk32.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Daniel Ramirez\Application Data\Mozilla\Firefox\Profiles\ccyoekty.default\
FF - component: c:\program files\Google\Google Gears\Firefox\components\gears_ff2.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
.
------- File Associations -------
.
inifile=%SystemRoot%\System32\NOTEPAD.EXE %1"
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-04-09 05:04:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{027d284a-a6e2-474b-b278-82140cc2daa1}]
@Denied: (Full) (Everyone)
"Model"=dword:0000000c
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):22,f2,60,ad,43,1c,d5,1f,fe,2b,f7,6e,c7,95,66,21,ac,af,a0,52,75,
9c,1f,b4,f1,28,74,6f,92,8e,50,19,6d,6c,9c,2b,c6,bd,56,51,00,00,00,00,00,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(836)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-04-09 5:06:14
ComboFix-quarantined-files.txt 2009-04-09 09:06:11
Pre-Run: 69,246,943,232 bytes free
Post-Run: 69,289,033,728 bytes free
306 --- E O F --- 2009-03-13 00:34:10
Edited by Dave Finlay, 09 April 2009 - 05:11 AM.