Tried this twice got auto scan stage 1-50 okay, deleting files then the dark blue screen pops up with a warning saying 'A problem has been detected and windows has shut down to prevent damage to your computer BAD_POOL_CALLER
If this is the first time you've seen this error etc, etc.
Tried again in Safe Mode, managed to get the log. You also asked for a HijackThis log, where do I get this??
ComboFix 11-05-07.03 - user 08/05/2011 20:01:07.7.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1022.817 [GMT 1:00]
Running from: c:\documents and settings\user\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\user\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\windows\system32\windrv.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\DFC5A2B2.TMP
C:\Microsoft
c:\program files\qaoiypeq
c:\windows\system32\windrv.sys
.
.
((((((((((((((((((((((((( Files Created from 2011-04-08 to 2011-05-08 )))))))))))))))))))))))))))))))
.
.
2011-05-08 18:55 . 2011-05-08 18:56 -------- d-----w- C:\32788R22FWJFW
2011-05-02 12:32 . 2011-05-02 12:32 -------- d-----w- c:\program files\CCleaner
2011-05-02 12:19 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-02 12:19 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-02 12:12 . 2011-05-02 12:13 -------- d-----w- c:\documents and settings\user\Application Data\GetRightToGo
2011-05-02 09:23 . 2011-05-02 09:23 -------- d-----w- c:\documents and settings\user\Application Data\DriverCure
2011-05-02 09:23 . 2011-05-02 09:23 -------- d-----w- c:\documents and settings\user\Application Data\SpeedMaxPc
2011-05-02 09:22 . 2011-05-02 11:17 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedMaxPc
2011-05-01 15:29 . 2011-05-08 08:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-05-01 15:29 . 2011-05-01 15:33 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-05-01 15:25 . 2011-05-01 16:32 -------- d-----w- c:\program files\Common Files\PC Tools
2011-04-27 19:47 . 2011-04-27 19:47 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Threat Expert
2011-04-25 08:10 . 2011-05-01 16:32 -------- d-----w- c:\program files\PC Tools Security
2011-04-25 08:08 . 2011-05-01 16:27 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2011-04-24 12:14 . 2011-04-24 12:14 -------- d-----w- c:\documents and settings\user\Application Data\Malwarebytes
2011-04-24 10:22 . 2011-04-24 10:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2011-04-24 10:22 . 2011-04-24 10:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-04-24 10:21 . 2011-05-02 12:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-24 10:09 . 2011-04-24 10:09 -------- d-----w- c:\documents and settings\Administrator\Application Data\Apple Computer
2011-04-24 10:09 . 2011-04-24 10:09 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer
2011-04-24 10:08 . 2011-04-24 10:08 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AVG Security Toolbar
2011-04-24 10:07 . 2011-04-24 10:07 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-04-22 18:50 . 2011-04-22 18:50 -------- d-s---w- c:\documents and settings\NetworkService\UserData
2011-04-20 18:13 . 2011-04-20 18:13 -------- d-s---w- c:\documents and settings\LocalService\UserData
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-07 05:33 . 2009-10-01 15:05 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:45 . 2004-08-04 10:00 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2004-08-04 10:00 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-18 16:36 . 2009-10-03 17:23 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 16:36 . 2009-10-03 17:23 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-02-17 13:51 . 2006-03-04 03:33 667136 ----a-w- c:\windows\system32\wininet.dll
2011-02-17 13:51 . 2004-08-04 10:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-02-17 13:51 . 2004-08-04 10:00 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-02-17 13:18 . 2004-08-04 10:00 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2004-08-04 10:00 357888 ----a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:37 . 2004-08-04 10:00 369664 ----a-w- c:\windows\system32\html.iec
2011-02-17 12:32 . 2009-10-03 22:16 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2004-08-04 10:00 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53 . 2004-08-04 10:00 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2004-08-04 10:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2004-08-04 10:00 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2004-08-04 10:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-01-01 08:00 . 2011-04-24 08:48 135168 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-05-02_11.03.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-01 15:13 . 2011-05-02 11:12 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-10-01 15:13 . 2011-05-02 09:48 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-10-01 15:13 . 2011-05-02 09:48 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-10-01 15:13 . 2011-05-02 11:12 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-10-01 15:13 . 2011-05-02 11:12 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-10-01 15:13 . 2011-05-02 09:48 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-05-07 17:40 . 2011-05-08 09:10 191664 c:\windows\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
+ 2011-04-14 14:46 . 2011-04-14 14:46 3854848 c:\windows\Installer\3ca6f.msp
+ 2011-05-02 11:44 . 2011-05-02 11:44 3446272 c:\windows\Installer\3ca6c.msi
+ 2011-05-02 11:42 . 2011-05-02 11:42 1611776 c:\windows\Installer\3ca68.msi
+ 2011-03-13 01:02 . 2011-03-13 01:02 15139328 c:\windows\Installer\3ca6e.msp
+ 2011-01-31 10:45 . 2011-01-31 10:45 11135488 c:\windows\Installer\3ca6d.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-16 149280]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-14 47904]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http:" [X]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
.
S2 COSIDS_TB;COSIDS_TB;c:\progra~1\COSIDS\BIN\TbMux32.exe [04/02/2010 13:02 165376]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [08/04/2010 17:19 233472]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [30/03/2011 19:58 136176]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [08/04/2010 17:19 36608]
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
2011-05-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-30 18:58]
.
2011-05-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-03-30 18:58]
.
2011-05-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-299502267-682003330-1004Core.job
- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-03 18:03]
.
2011-05-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-299502267-682003330-1004UA.job
- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-10-03 18:03]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\5ryolv8x.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.bing.com/search?FORM=IEFM1&q=FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage -
hxxp://uk.yahoo.com/FF - prefs.js: keyword.URL -
hxxp://uk.search.yahoo.com/search?ourma ... e=61465&p=FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-SNM - c:\program files\SpyNoMore\SNM.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-05-08 20:08
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.netWindows 5.1.2600 Disk: Maxtor_7L250S0 rev.BANC1G10 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
.
device: opened successfully
user: MBR read successfully
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8670E57B
user & kernel MBR OK
.
**************************************************************************
.
Completion time: 2011-05-08 20:11:18
ComboFix-quarantined-files.txt 2011-05-08 19:11
.
Pre-Run: 200,133,513,216 bytes free
Post-Run: 200,155,951,104 bytes free
.
- - End Of File - - D74D1DBB1574A3F9F501C98FD5FA7E2C