When I ran combofix it said it detected that the machine does not have the 'windows recovery console' - what is that and should I go back and do it again and install it?
ComboFix 08-12-01.01 - Kristen 2008-12-02 7:49:40.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.249 [GMT -5:00]
Running from: c:\documents and settings\Kristen\Desktop\ComboFix.exe
* Created a new restore point
[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Kristen\nah_log.dat
c:\documents and settings\Kristen\nah_uhgt.exe
c:\windows\system32\ieupdates.exe.tmp
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\winsrc.dll.tmp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2008-11-02 to 2008-12-02 )))))))))))))))))))))))))))))))
.
2008-12-01 16:21 . 2008-12-01 16:21 <DIR> d-------- c:\documents and settings\Kristen\Application Data\Malwarebytes
2008-12-01 16:09 . 2008-12-01 16:09 <DIR> d-------- c:\documents and settings\James\Application Data\BullGuard
2008-12-01 15:59 . 2008-12-01 16:21 <DIR> d-------- c:\program files\Malwar
2008-12-01 15:59 . 2008-12-01 15:59 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-01 15:59 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-01 15:59 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-29 23:15 . 2005-02-16 11:06 218,112 --a------ c:\program files\HijackThis.exe
2008-11-29 13:05 . 2006-10-24 22:28 <DIR> d-------- c:\documents and settings\James\Application Data\Symantec
2008-11-29 13:05 . 2006-10-24 22:25 <DIR> d-------- c:\documents and settings\James\Application Data\Sonic
2008-11-29 13:05 . 2006-10-24 22:24 <DIR> d-------- c:\documents and settings\James\Application Data\IBM
2008-11-29 13:05 . 2008-11-29 13:05 <DIR> d-------- c:\documents and settings\James
2008-11-27 13:34 . 2008-11-28 16:13 <DIR> d-------- c:\documents and settings\Kristen\Application Data\BullGuard
2008-11-26 18:13 . 2008-11-27 13:27 <DIR> d-------- c:\documents and settings\Randy\Application Data\BullGuard
2008-11-26 18:13 . 2008-12-02 07:55 <DIR> d-------- c:\documents and settings\All Users\Application Data\BullGuard
2008-11-26 18:12 . 2008-11-10 08:51 252,568 --a------ c:\windows\system32\drivers\AfwCore.sys
2008-11-26 18:11 . 2008-11-26 18:11 <DIR> d-------- c:\program files\BullGuard Ltd
2008-11-26 18:11 . 2008-03-13 09:27 52,560 --a------ c:\windows\system32\drivers\BdFileSpy.sys
2008-11-26 12:04 . 2008-11-26 12:15 <DIR> d-------- c:\program files\Windows Live Safety Center
2008-11-13 06:20 . 2008-09-04 12:15 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
2008-11-13 06:20 . 2008-10-24 06:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-10 08:51 . 2008-11-10 08:51 30,872 --a------ c:\windows\system32\drivers\afw.sys
2008-11-02 12:45 . 2008-11-02 12:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kodak
2008-11-02 12:37 . 2008-11-02 12:37 <DIR> d--hs---- c:\windows\ftpcache
2008-11-02 12:37 . 2008-11-04 19:22 <DIR> d-------- c:\documents and settings\Randy\Application Data\CVS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-28 19:04 --------- d-----w c:\documents and settings\Randy\Application Data\Intuit
2008-11-28 19:04 --------- d-----w c:\documents and settings\Kristen\Application Data\Intuit
2008-11-28 19:04 --------- d-----w c:\documents and settings\All Users\Application Data\Intuit
2008-11-26 16:34 --------- d-----w c:\program files\Common Files\Intuit
2008-11-20 03:34 296,090 ----a-w c:\documents and settings\Randy\HC43SInstaller.exe
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-04 13:22 --------- d-----w c:\program files\MySpace
2008-10-03 22:19 --------- d-----w c:\documents and settings\Randy\Application Data\MySpace
2008-10-02 04:37 --------- d-----w c:\documents and settings\Kristen\Application Data\MySpace
2008-04-27 05:11 296,089 ----a-w c:\documents and settings\Kristen\HC43SInstaller.exe
2007-07-07 21:50 0 ----a-w c:\documents and settings\Randy\HCUpgrade3.1.exe
2007-02-17 06:20 800,272 ----a-w c:\documents and settings\Randy\ppctl.dll
.
------- Sigcheck -------
2004-08-04 08:00 502272 01c3346c241652f43aed8e2149881bfe c:\windows\$NtServicePackUninstall$\winlogon.exe
2008-04-13 19:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\ServicePackFiles\i386\winlogon.exe
2008-11-26 09:38 507904 3969440ba384d35317dbbdeeaae641ce c:\windows\system32\winlogon.exe
2004-08-04 08:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\$NtServicePackUninstall$\termsrv.dll
2008-04-13 19:12 295424 ff3477c03be7201c294c35f684b3479f c:\windows\ServicePackFiles\i386\termsrv.dll
2008-11-26 09:38 295424 63999d0abd8dabfd76a9c07f6e104868 c:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ibmmessages"="c:\program files\IBM\Messages By IBM\ibmmessages.exe" [2004-08-06 442368]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"BullGuard"="c:\program files\BullGuard Ltd\BullGuard\BullGuard.exe" [2008-11-12 304464]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-08 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-08 512000]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2004-02-04 897024]
"TPHOTKEY"="c:\progra~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe" [2005-04-04 94208]
"ControlCenter"="c:\program files\IBM fingerprint software\ctlcntr.exe" [2005-04-12 286821]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2005-03-23 217088]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-11 344064]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-09-02 127035]
"ibmmessages"="c:\program files\IBM\Messages By IBM\\ibmmessages.exe" [2004-08-06 442368]
"IBMPRC"="c:\ibmtools\UTILS\ibmprc.exe" [2005-04-27 90112]
"QCTRAY"="c:\program files\ThinkPad\ConnectUtilities\QCTRAY.EXE" [2005-03-18 745472]
"QCWLICON"="c:\program files\ThinkPad\ConnectUtilities\QCWLICON.EXE" [2005-03-18 86016]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2005-04-14 139264]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-04-14 208896]
"tgcmd"="c:\program files\Support.com\bin\tgcmd.exe" [2002-04-12 1564737]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb06.exe" [2002-07-11 188416]
"BullGuard"="c:\program files\BullGuard Ltd\BullGuard\bullguard.exe" [2008-11-12 304464]
"TpShocks"="TpShocks.exe" [2005-04-05 c:\windows\system32\TpShocks.exe]
"TP4EX"="tp4ex.exe" [2004-11-12 c:\windows\system32\TP4EX.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-10-24 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2005-04-12 19:39 110179 c:\program files\IBM fingerprint software\psfus.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\QConGina]
2005-03-18 06:07 262144 c:\windows\system32\QConGina.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2004-08-12 23:11 24576 c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli pwdmon
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BgMainSvc]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 Shockprf;Shockprf;c:\windows\system32\drivers\Shockprf.sys [2006-10-24 59776]
R0 TPDiskPM;TPDiskPM;c:\windows\system32\drivers\TPDiskPM.sys [2006-10-24 14208]
R1 ANC;ANC;c:\windows\system32\drivers\ANC.SYS [2006-10-24 11520]
R1 IBMTPCHK;IBMTPCHK;c:\windows\system32\drivers\IBMBLDID.SYS [2006-10-24 2432]
R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [2006-10-24 4608]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\Tppwrif.sys [2006-10-24 4442]
R2 BdFileSpy;BullGuard File Monitor Driver;\??\c:\windows\system32\drivers\BdFileSpy.sys [2008-11-26 52560]
R2 BsFileScan;BullGuard File Scan Service;c:\windows\System32\svchost.exe -k BullGuard [1980-01-01 14336]
R2 BsFire;BullGuard Firewall Service;c:\windows\System32\svchost.exe -k BullGuard [1980-01-01 14336]
R2 ibmfilter;ibmfilter;\??\c:\windows\system32\drivers\ibmfilter.sys [2005-04-27 63616]
R2 SmiHlp;SMI helper driver;\??\c:\program files\IBM fingerprint software\smihlp.sys [2005-04-12 3328]
R3 afw;Agnitum firewall driver;c:\windows\system32\DRIVERS\afw.sys [2008-11-10 30872]
R3 AfwCore;Agnitum Firewall Core Driver;\??\c:\windows\system32\Drivers\AfwCore.sys [2008-11-26 252568]
R3 Reconn;BullGuard Email Monitor;\??\c:\program files\BullGuard Ltd\BullGuard\Reconn.sys [2008-07-29 16984]
R3 TPInput;TPInput;c:\windows\system32\DRIVERS\TPInput.sys [2006-10-24 6016]
R3 TPM11;NSC Integrated Trusted Platform Module 1.1;c:\windows\system32\DRIVERS\nsctpm11.sys [1980-01-01 14336]
S3 BGRaSvc;BGRaSvc;"c:\program files\BullGuard Ltd\BullGuard\support\bgrasvc.exe" [2008-07-29 73728]
S3 QCNDISIF;QCNDISIF;c:\windows\system32\drivers\qcndisif.SYS [2006-10-24 12288]
S3 WAM;Wicked Access by Mark;\??\c:\program files\IBM\IBM Rapid Restore Ultra\WAM.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard REG_MULTI_SZ BgMainSvc BsFileScan BsMailProxy BsFire
.
Contents of the 'Scheduled Tasks' folder
2008-12-02 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2005-04-14 04:01]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Download - c:\program files\Bellsouth\HelpCenter\ssGet.exe 120 http://download.fastaccess.com/download/HC43SInstaller.exe
HKLM-Run-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwar\mbam.exe
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-02 07:54:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1620)
c:\windows\system32\vrlogon.dll
c:\program files\IBM fingerprint software\ExtVapi.dll
c:\program files\Common Files\Virtual Token\psutil.dll
c:\program files\Common Files\Virtual Token\resmgr.dll
c:\program files\Common Files\Virtual Token\Remote.dll
c:\program files\Common Files\Virtual Token\passport.dll
c:\windows\system32\Ati2evxx.dll
c:\program files\IBM fingerprint software\psfus.dll
c:\windows\system32\tphklock.dll
c:\program files\Common Files\Virtual Token\config.dll
c:\program files\Common Files\Virtual Token\LocPass.dll
c:\program files\Common Files\Virtual Token\SBioPass.dll
c:\program files\Common Files\Virtual Token\psdlg.dll
c:\program files\Common Files\Virtual Token\BGTcVer.dll
c:\program files\Common Files\Virtual Token\BTcVer.dll
- - - - - - - > 'lsass.exe'(1676)
c:\windows\system32\pwdmon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Virtual Token\vtserver.exe
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
c:\program files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
c:\windows\system32\QCONSVC.EXE
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Sprint\Sierra Wireless\Sprint PCS Connection Manager\SPCSUtilityService.exe
c:\windows\system32\TPHDEXLG.exe
c:\windows\system32\TpKmpSvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\ati2evxx.exe
c:\program files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
c:\program files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
c:\progra~1\ThinkPad\CONNEC~1\QCTRAY.EXE
c:\windows\system32\rundll32.exe
c:\program files\BellSouth\HelpCenter\SSGet.exe
.
**************************************************************************
.
Completion time: 2008-12-02 7:56:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-02 12:56:50
Pre-Run: 64,726,978,560 bytes free
Post-Run: 64,792,219,648 bytes free
210 --- E O F --- 2008-11-13 22:52:21