thanks for the reply . When avenger rebooted it said starting windows and then it froze , so to restart all I could do was turn the power off (not the button on the computer but the powerstrip it's plugged into ) . When I restarted I got the following avenger log . The rsit log I did before that avenger run . My problem now is I can only get the computer to work in safe mode . Safe Mode with networking or regular mode don't work . doubleclicking on an icon doesn't do anything and I can't get ctr alt del to bring up the task manager I can't do a start shutdown because the mouse won't work when I click on start , so I just have to power off the power strip . Also , in safe mode now when I click on rsit or other .exe applications I get the can not open you may not be authorized problem . Therefore , I am now using my sons computer to send this reply . I'm thinking of taking it somewhere but I think they'll just reformat my hard drive and I'll lose my stuff ? So , right now I'm really stuck . Thanks in advance for your help.
below is the rsit log that I ran before your reply and the avenger log is below that .
Logfile of random's system information tool 1.06 (written by random/random)
Run by Owner at 2009-08-28 07:41:08
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 113 GB (76%) free of 148 GB
Total RAM: 1022 MB (66% free)
======Scheduled tasks folder======
C:\WINDOWS\tasks\BBE1A86D9FDA5DD5.job
C:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
C:\WINDOWS\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Recguard"=C:\WINDOWS\SMINST\RECGUARD.EXE [2002-09-14 212992]
"BullGuard"=C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe [2009-08-01 304464]
"winupdate.exe"=C:\WINDOWS\system32\winupdate.exe [2009-08-28 43008]
"Twogizuta"=C:\WINDOWS\ajizicifa.dll [2008-04-13 174080]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BullGuard"=C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe [2009-08-01 304464]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-10-18 204288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2007-09-13 1603152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [2007-10-25 652624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Diagnostic Manager]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Monopod]
C:\DOCUME~1\Owner\LOCALS~1\Temp\a.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NordBull]
C:\WINDOWS\msa.exe [2009-08-27 138752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SVCHOST.EXE]
C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
C:\Program Files\Trojan Remover\Trjscan.exe [2009-08-04 1068424]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Resurections]
[]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"notification packages"=scecli
ryms40.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BgMainSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSserv.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BgLiveSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BgMainSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PEVSystemStart]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TDSSserv.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"NoDispScrSavPage"=0
"DisableTaskMgr"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoFolderOptions"=0
"NoDriveAutoRun"=67108863
"NoSetActiveDesktop"=1
"NoActiveDesktopChanges"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoSetActiveDesktop"=
"NoActiveDesktopChanges"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
"C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed"
"C:\Program Files\Common Files\AOL\1155243762\EE\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1155243762\EE\AOLServiceHost.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\System Information\sinf.exe"="C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe"="C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe"="C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe"="C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
""=":*:Enabled:Yahoo! Music Jukebox"
"C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe"="C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Jukebox"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2009-08-28 07:41:08 ----D---- C:\rsit
2009-08-28 07:41:08 ----D---- C:\Program Files\trend micro
2009-08-28 07:28:03 ----A---- C:\WINDOWS\ntbtlog.txt
2009-08-28 06:00:50 ----A---- C:\WINDOWS\system32\winhelper.dll
2009-08-28 06:00:50 ----A---- C:\WINDOWS\system32\AVR09.exe
2009-08-28 06:00:37 ----A---- C:\WINDOWS\system32\winupdate.exe
2009-08-28 06:00:36 ----A---- C:\WINDOWS\system32\tajf83ikdmf.dll
2009-08-28 05:56:43 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-08-28 05:55:00 ----A---- C:\trythisnigger.exe
2009-08-28 05:35:33 ----SD---- C:\go
2009-08-28 05:35:30 ----A---- C:\WINDOWS\system32\CF22166.exe
2009-08-28 04:53:26 ----A---- C:\WINDOWS\system32\CF13852.exe
2009-08-28 04:51:12 ----SD---- C:\ComboFix
2009-08-28 04:51:10 ----A---- C:\WINDOWS\system32\CF13287.exe
2009-08-28 04:13:27 ----A---- C:\WINDOWS\system32\CF6090.exe
2009-08-28 04:11:51 ----A---- C:\WINDOWS\system32\CF5773.exe
2009-08-28 03:57:11 ----A---- C:\WINDOWS\system32\CF2903.exe
2009-08-28 03:55:37 ----A---- C:\WINDOWS\system32\CF2596.exe
2009-08-28 00:55:42 ----A---- C:\WINDOWS\system32\CF105.exe
2009-08-28 00:47:55 ----A---- C:\WINDOWS\system32\CF31355.exe
2009-08-28 00:44:11 ----A---- C:\WINDOWS\zip.exe
2009-08-28 00:44:11 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-08-28 00:44:11 ----A---- C:\WINDOWS\SWSC.exe
2009-08-28 00:44:11 ----A---- C:\WINDOWS\SWREG.exe
2009-08-28 00:44:11 ----A---- C:\WINDOWS\sed.exe
2009-08-28 00:44:11 ----A---- C:\WINDOWS\PEV.exe
2009-08-28 00:44:11 ----A---- C:\WINDOWS\NIRCMD.exe
2009-08-28 00:44:11 ----A---- C:\WINDOWS\grep.exe
2009-08-28 00:43:49 ----D---- C:\WINDOWS\ERDNT
2009-08-28 00:43:45 ----A---- C:\WINDOWS\system32\CF30535.exe
2009-08-28 00:43:29 ----D---- C:\Qoobox
2009-08-28 00:09:32 ----A---- C:\WINDOWS\system32\ztvunrar36.dll
2009-08-28 00:09:32 ----A---- C:\WINDOWS\system32\ztvunace26.dll
2009-08-28 00:09:32 ----A---- C:\WINDOWS\system32\ztvcabinet.dll
2009-08-28 00:09:32 ----A---- C:\WINDOWS\system32\UNRAR3.dll
2009-08-28 00:09:32 ----A---- C:\WINDOWS\system32\unacev2.dll
2009-08-28 00:09:31 ----D---- C:\Program Files\Trojan Remover
2009-08-28 00:09:31 ----D---- C:\Documents and Settings\Owner\Application Data\Simply Super Software
2009-08-28 00:09:31 ----D---- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2009-08-27 21:22:41 ----A---- C:\WINDOWS\msc.exe
2009-08-27 21:21:59 ----A---- C:\WINDOWS\msb.exe
2009-08-27 21:21:50 ----A---- C:\WINDOWS\msa.exe
2009-08-21 00:48:15 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2009-08-21 00:46:46 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2009-08-21 00:45:19 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2009-08-21 00:43:53 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2009-08-21 00:42:27 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2009-08-21 00:41:01 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2009-08-21 00:39:38 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2009-08-21 00:38:07 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2009-08-21 00:37:54 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2009-08-21 00:36:30 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2009-08-21 00:34:54 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2$
2009-08-21 00:29:58 ----HDC---- C:\WINDOWS\$NtUninstallKB973346$
2009-08-21 00:27:55 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2009-08-21 00:26:38 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2009-08-21 00:25:20 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2009-08-21 00:24:03 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
======List of files/folders modified in the last 1 months======
2009-08-28 07:41:08 ----RD---- C:\Program Files
2009-08-28 07:40:25 ----D---- C:\WINDOWS
2009-08-28 07:40:10 ----D---- C:\WINDOWS\system32
2009-08-28 07:32:34 ----D---- C:\Program Files\Mozilla Firefox
2009-08-28 07:31:08 ----D---- C:\WINDOWS\Temp
2009-08-28 07:30:28 ----D---- C:\WINDOWS\Registration
2009-08-28 07:20:30 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-08-28 06:07:42 ----SHD---- C:\System Volume Information
2009-08-28 06:07:42 ----D---- C:\WINDOWS\system32\Restore
2009-08-28 06:00:37 ----SD---- C:\WINDOWS\Tasks
2009-08-28 06:00:11 ----A---- C:\WINDOWS\system.ini
2009-08-28 05:56:44 ----D---- C:\WINDOWS\system32\drivers
2009-08-28 04:33:19 ----SHD---- C:\WINDOWS\Installer
2009-08-28 04:33:09 ----D---- C:\WINDOWS\system32\CatRoot2
2009-08-28 04:33:01 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-08-28 04:05:26 ----SH---- C:\boot.ini
2009-08-28 04:05:26 ----A---- C:\WINDOWS\win.ini
2009-08-27 23:31:30 ----D---- C:\Program Files\SpywareBlaster
2009-08-27 21:32:32 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-27 21:22:28 ----D---- C:\WINDOWS\system32\config
2009-08-27 21:21:28 ----HD---- C:\WINDOWS\PIF
2009-08-27 21:21:28 ----D---- C:\WINDOWS\system32\xircom
2009-08-27 21:21:28 ----D---- C:\WINDOWS\system32\wins
2009-08-27 21:21:28 ----D---- C:\WINDOWS\system32\ShellExt
2009-08-27 21:21:28 ----D---- C:\WIN
Logfile of The Avenger Version 2.0, (c) by Swandog46
https://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\UACd" not found!
Deletion of driver "UACd" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\TDSSserv" not found!
Deletion of driver "TDSSserv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Driver "Kbiwkmuwwiyvnk" deleted successfully.
File "C:\WINDOWS\system32\drivers\kbiwkmepwaomsn.sys" deleted successfully.
Error: could not open file "C:\WINDOWS\ system32\drivers\TDSSmaxt.sys"
Deletion of file "C:\WINDOWS\ system32\drivers\TDSSmaxt.sys" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist
File "C:\WINDOWS\system32\drivers\UACxjjqbhgmec.sys" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.