Ok recoveryconsole would not install cause virus wouldnt let it connect but the rest ran. Here are the logs:
ComboFix 08-12-21.04 - Eric 2008-12-22 18:53:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1741 [GMT -6:00]
Running from: c:\documents and settings\Eric\Desktop\ramboboFox.exe
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\reged.exe
c:\windows\spoolsystem.exe
c:\windows\sys.com
c:\windows\syscert.exe
c:\windows\sysexplorer.exe
c:\windows\system32\drivers\TDSSmaxt.sys
c:\windows\system32\fpbwpqwx.ini
c:\windows\system32\lgqdamvv.ini
c:\windows\system32\LoqAaccf.ini
c:\windows\system32\LoqAaccf.ini2
c:\windows\system32\TDSScfub.dll
c:\windows\system32\TDSSfpmp.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnrsr.dll
c:\windows\system32\TDSSofxh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSrhym.log
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsbhc.dll
c:\windows\system32\TDSStkdv.log
c:\windows\Tasks\thugnbvc.job
c:\windows\vmreg.dll
c:\windows\wiaserviv.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
((((((((((((((((((((((((( Files Created from 2008-11-23 to 2008-12-23 )))))))))))))))))))))))))))))))
.
2008-12-21 22:37 . 2008-12-21 22:37 <DIR> d-------- c:\program files\Trend Micro
2008-12-19 21:12 . 2008-12-19 21:12 685,056 --a------ c:\windows\is-S9A1A.exe
2008-12-19 21:12 . 2008-12-19 21:12 10,498 --a------ c:\windows\is-S9A1A.msg
2008-12-19 21:12 . 2008-12-19 21:12 369 --a------ c:\windows\is-S9A1A.lst
2008-12-19 20:45 . 2008-12-19 20:45 <DIR> d-------- c:\program files\MSXML 4.0
2008-12-19 20:37 . 2008-12-03 19:53 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-19 20:36 . 2008-12-20 00:00 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-19 20:36 . 2008-12-19 20:36 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-19 20:36 . 2008-12-03 19:53 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-19 20:35 . 2008-12-19 20:41 <DIR> d-------- c:\windows\system32\CatRoot_bak
2008-12-19 20:35 . 2008-06-13 07:10 272,128 --------- c:\windows\system32\drivers\bthport.sys
2008-12-19 20:35 . 2008-06-13 07:10 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-12-17 18:53 . 2008-12-21 22:37 <DIR> d-------- C:\hjp
2008-12-15 21:27 . 2008-12-15 21:27 <DIR> d-------- c:\program files\Microsoft Silverlight
2008-12-15 20:18 . 2008-12-15 20:18 <DIR> d-------- c:\documents and settings\Administrator
2008-12-15 20:10 . 2008-12-15 20:10 49,664 --a------ c:\windows\system32\svchstb.dll
2008-12-15 20:10 . 2008-12-15 20:10 1 --a------ c:\windows\system32\edl.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-20 05:48 --------- d-----w c:\program files\XoftSpySE
2008-12-04 03:31 138,784 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-12-04 03:20 --------- d-----w c:\program files\EVGA Precision
2008-11-15 01:52 22,328 ----a-w c:\documents and settings\Eric\Application Data\PnkBstrK.sys
2008-11-15 01:52 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-12-18 04:01 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-18 04:01 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-18 04:01 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-18 04:01 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-18 04:01 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AsusStartupHelp"="c:\program files\ASUS\AASP\1.00.15\AsRunHelp.exe" [2006-11-14 363008]
"Launch Ai Booster"="c:\program files\ASUS\AI Booster\OverClk.exe" [2006-11-28 3714048]
"Ai Gear Help"="c:\program files\ASUS\AI Gear\GearHelp.exe" [2006-07-27 415744]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"Reclusa"="c:\program files\Razer\Reclusa\razerhid.exe" [2007-03-07 167936]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-02-29 949376]
"RivaTuner"="c:\program files\RivaTuner v2.09\RivaTuner.exe" [2008-04-28 2707456]
"RivaTunerStatisticsServer"="c:\program files\EVGA Precision\Bundle\OSDServer\RTSS.exe" [2008-08-11 64528]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2007-07-23 77824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-02 86016]
"EVGAPrecision"="c:\program files\EVGA Precision\EVGAPrecision.exe" [2008-08-11 236560]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 c:\windows\KHALMNPR.Exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-02-28 692224]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 10:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-05-02 21:46 1630208 c:\windows\system32\nwiz.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"e:\\QuakeWars\\etqwded.exe"=
"e:\\QuakeWars\\etqw.exe"=
"c:\\Program Files\\Qtracker\\qtracker.exe"=
"e:\\Quake III Arena\\quake3.exe"=
"e:\\Quake2\\r1q2.exe"=
"e:\\UT3\\Binaries\\UT3.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"e:\\Quake 4\\Quake4.exe"=
"e:\\Call of Duty 4\\iw3mp.exe"=
"e:\\GRID\\GRID.exe"=
"e:\\Call of Duty WAW\\CoDWaW.exe"=
"e:\\Call of Duty WAW\\CoDWaWmp.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-02-29 15424]
R3 RecFltr;Reclusa Keyboard;c:\windows\system32\Drivers\RecFltr.sys [2008-02-28 41984]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09f8839f-f956-11dc-a855-001d60a2c2d5}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL unlock.exe
\Shell\open\command - F:\unlock.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{930f8b61-e5d0-11dc-949f-806d6172696f}]
\Shell\AutoRun\command - D:\Setup.exe
.
Contents of the 'Scheduled Tasks' folder
2008-12-23 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2007-03-30 12:05]
2008-12-06 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2007-03-30 12:05]
.
- - - - ORPHANS REMOVED - - - -
ShellExecuteHooks-{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} - (no file)
MSConfigStartUp-NVIDIA nTune - c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.msn.com
mStart Page = hxxp://www.msn.com
LSP: c:\windows\system32\imon.dll
FF - ProfilePath - c:\documents and settings\Eric\Application Data\Mozilla\Firefox\Profiles\cyr013pi.default\
FF - prefs.js: browser.startup.homepage - hxxp://cm.my.yahoo.com/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-22 18:55:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(744)
c:\windows\system32\imon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Logitech\KhalShared\KHALMNPR.exe
c:\program files\ESET\nod32krn.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Razer\Reclusa\razertra.exe
.
**************************************************************************
.
Completion time: 2008-12-22 18:59:55 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-23 00:59:52
Pre-Run: 62,588,407,808 bytes free
Post-Run: 66,877,591,552 bytes free
176 --- E O F --- 2008-12-21 22:54:41
HJT txt:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:00:48 PM, on 12/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ASUS\AI Gear\GearHelp.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Razer\Reclusa\razerhid.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\RivaTuner v2.09\RivaTuner.exe
C:\Program Files\EVGA Precision\Bundle\OSDServer\RTSS.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Razer\Reclusa\razertra.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.15\AsRunHelp.exe
O4 - HKLM\..\Run: [Launch Ai Booster] "C:\Program Files\ASUS\AI Booster\OverClk.exe"
O4 - HKLM\..\Run: [Ai Gear Help] "C:\Program Files\ASUS\AI Gear\GearHelp.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Reclusa] C:\Program Files\Razer\Reclusa\razerhid.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [RivaTuner] "C:\Program Files\RivaTuner v2.09\RivaTuner.exe" /T
O4 - HKLM\..\Run: [RivaTunerStatisticsServer] "C:\Program Files\EVGA Precision\Bundle\OSDServer\RTSS.exe" /s
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EVGAPrecision] "C:\Program Files\EVGA Precision\EVGAPrecision.exe" /s
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1204243587264
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 4105 bytes