Performed Combofix... it deleted several files per the script..
Tried to install Avast again and it gave the same error message halfway through the installation..
**************************************************************
ComboFix 10-04-20.02 - Owner 04/21/2010 7:24.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.503.297 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\Misc Virus Files\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
FILE ::
"c:\windows\system32\aswBoot.exe"
"c:\windows\system32\avastSS.scr"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Alwil Software
c:\documents and settings\All Users\Application Data\Alwil Software\Avast5\avast5.ini
c:\documents and settings\All Users\Application Data\Alwil Software\Avast5\HtmlData\Blocked.htm
c:\documents and settings\All Users\Application Data\Alwil Software\Avast5\HtmlData\image001.png
c:\documents and settings\All Users\Application Data\Alwil Software\Avast5\sounds\1033\scan_completed.wav
c:\documents and settings\All Users\Application Data\Alwil Software\Avast5\sounds\1033\threat_detected.wav
c:\documents and settings\All Users\Application Data\Alwil Software\Avast5\sounds\1033\virus_db_updated.wav
c:\documents and settings\All Users\Application Data\Alwil Software\Avast5\sounds\1033\welcome.wav
c:\documents and settings\All Users\Application Data\Alwil Software\Avast5\sounds\scan_completed.wav
c:\documents and settings\All Users\Application Data\Alwil Software\Avast5\sounds\threat_detected.wav
c:\documents and settings\All Users\Application Data\Alwil Software\Avast5\sounds\virus_db_updated.wav
c:\program files\Alwil Software
c:\program files\Alwil Software\Avast5\1033\aswClnTg.htm
c:\program files\Alwil Software\Avast5\1033\aswClnTg.txt
c:\program files\Alwil Software\Avast5\1033\aswInfTg.htm
c:\program files\Alwil Software\Avast5\1033\aswInfTg.txt
c:\program files\Alwil Software\Avast5\1033\Avast5_1033.chm
c:\program files\Alwil Software\Avast5\1033\Base.dll
c:\program files\Alwil Software\Avast5\1033\Boot.dll
c:\program files\Alwil Software\Avast5\1033\uiLangRes.dll
c:\program files\Alwil Software\Avast5\Aavm4h.dll
c:\program files\Alwil Software\Avast5\AavmRpch.dll
c:\program files\Alwil Software\Avast5\AhResBhv.dll
c:\program files\Alwil Software\Avast5\AhResMai.dll
c:\program files\Alwil Software\Avast5\ahResMes.dll
c:\program files\Alwil Software\Avast5\AhResNS.dll
c:\program files\Alwil Software\Avast5\ahResP2P.dll
c:\program files\Alwil Software\Avast5\AhResStd.dll
c:\program files\Alwil Software\Avast5\AhResWS.dll
c:\program files\Alwil Software\Avast5\ashBase.dll
c:\program files\Alwil Software\Avast5\ashMaiSv.dll
c:\program files\Alwil Software\Avast5\ashOutXt.dll
c:\program files\Alwil Software\Avast5\ashQuick.exe
c:\program files\Alwil Software\Avast5\ashServ.dll
c:\program files\Alwil Software\Avast5\ashShell.dll
c:\program files\Alwil Software\Avast5\ashTask.dll
c:\program files\Alwil Software\Avast5\ashTaskEx.dll
c:\program files\Alwil Software\Avast5\ashUpd.exe
c:\program files\Alwil Software\Avast5\ashWebSv.dll
c:\program files\Alwil Software\Avast5\ashWsFtr.dll
c:\program files\Alwil Software\Avast5\aswAux.dll
c:\program files\Alwil Software\Avast5\aswCmnBS.dll
c:\program files\Alwil Software\Avast5\aswCmnIS.dll
c:\program files\Alwil Software\Avast5\aswCmnOS.dll
c:\program files\Alwil Software\Avast5\aswData.dll
c:\program files\Alwil Software\Avast5\aswDld.dll
c:\program files\Alwil Software\Avast5\aswEngLdr.dll
c:\program files\Alwil Software\Avast5\aswIdle.dll
c:\program files\Alwil Software\Avast5\aswLog.dll
c:\program files\Alwil Software\Avast5\aswMonDS.sys
c:\program files\Alwil Software\Avast5\aswMonVD.dll
c:\program files\Alwil Software\Avast5\aswProperty.dll
c:\program files\Alwil Software\Avast5\aswRegSvr.exe
c:\program files\Alwil Software\Avast5\aswRegSvr64.exe
c:\program files\Alwil Software\Avast5\aswRunDll.exe
c:\program files\Alwil Software\Avast5\aswSqLt.dll
c:\program files\Alwil Software\Avast5\aswUtil.dll
c:\program files\Alwil Software\Avast5\avastSS.dll
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Alwil Software\Avast5\AvastUI.exe
c:\program files\Alwil Software\Avast5\AvSSHook.dll
c:\program files\Alwil Software\Avast5\CommonRes.dll
c:\program files\Alwil Software\Avast5\defs\10041401\algo.dll
c:\program files\Alwil Software\Avast5\defs\10041401\ArPot.dll
c:\program files\Alwil Software\Avast5\defs\10041401\aswAR.dll
c:\program files\Alwil Software\Avast5\defs\10041401\aswBoot.dll
c:\program files\Alwil Software\Avast5\defs\10041401\aswCleanerDLL.dll
c:\program files\Alwil Software\Avast5\defs\10041401\aswCmnBS.dll
c:\program files\Alwil Software\Avast5\defs\10041401\aswCmnIS.dll
c:\program files\Alwil Software\Avast5\defs\10041401\aswCmnOS.dll
c:\program files\Alwil Software\Avast5\defs\10041401\aswEngin.dll
c:\program files\Alwil Software\Avast5\defs\10041401\aswRawFS.dll
c:\program files\Alwil Software\Avast5\defs\10041401\aswScan.dll
c:\program files\Alwil Software\Avast5\defs\10041401\db_el.dat
c:\program files\Alwil Software\Avast5\defs\10041401\db_js.dat
c:\program files\Alwil Software\Avast5\defs\10041401\db_js.map
c:\program files\Alwil Software\Avast5\defs\10041401\db_mx4.dat
c:\program files\Alwil Software\Avast5\defs\10041401\db_mx4.map
c:\program files\Alwil Software\Avast5\defs\10041401\db_mx95.dat
c:\program files\Alwil Software\Avast5\defs\10041401\db_mx95.map
c:\program files\Alwil Software\Avast5\defs\10041401\db_o7.dat
c:\program files\Alwil Software\Avast5\defs\10041401\db_o7.map
c:\program files\Alwil Software\Avast5\defs\10041401\db_ob.dat
c:\program files\Alwil Software\Avast5\defs\10041401\db_pe2.dat
c:\program files\Alwil Software\Avast5\defs\10041401\db_swf.dat
c:\program files\Alwil Software\Avast5\defs\10041401\db_swf.map
c:\program files\Alwil Software\Avast5\defs\10041401\db_tx.dat
c:\program files\Alwil Software\Avast5\defs\10041401\db_u.dat
c:\program files\Alwil Software\Avast5\defs\10041401\db_w6.dat
c:\program files\Alwil Software\Avast5\defs\10041401\db_w6.map
c:\program files\Alwil Software\Avast5\defs\10041401\db_wh.dat
c:\program files\Alwil Software\Avast5\defs\10041401\db_xtn.map
c:\program files\Alwil Software\Avast5\defs\10041401\def.ini
c:\program files\Alwil Software\Avast5\defs\10041401\dllcc.dat
c:\program files\Alwil Software\Avast5\defs\10041401\exts.dll
c:\program files\Alwil Software\Avast5\defs\10041401\fwAux.dll
c:\program files\Alwil Software\Avast5\defs\10041401\l_idx.map
c:\program files\Alwil Software\Avast5\defs\10041401\l_nmp.map
c:\program files\Alwil Software\Avast5\defs\10041401\list_d.txt
c:\program files\Alwil Software\Avast5\defs\10041401\list_i.txt
c:\program files\Alwil Software\Avast5\defs\10041401\lshe3.map
c:\program files\Alwil Software\Avast5\defs\10041401\s_idx.map
c:\program files\Alwil Software\Avast5\defs\10041401\s_nmp.map
c:\program files\Alwil Software\Avast5\defs\10041401\Sf.bin
c:\program files\Alwil Software\Avast5\defs\10041401\sl_idx.map
c:\program files\Alwil Software\Avast5\defs\10041401\sl_nmp.map
c:\program files\Alwil Software\Avast5\defs\10041401\whitelist.db
c:\program files\Alwil Software\Avast5\flash\amline.swf
c:\program files\Alwil Software\Avast5\flash\ammap\ammap.swf
c:\program files\Alwil Software\Avast5\flash\ammap\ammap_key.txt
c:\program files\Alwil Software\Avast5\flash\ammap\ammap_settings_summary.xml
c:\program files\Alwil Software\Avast5\flash\ammap\ammap_settings_tracert.xml
c:\program files\Alwil Software\Avast5\flash\ammap\empty_map.xml
c:\program files\Alwil Software\Avast5\flash\ammap\icons\arrow.swf
c:\program files\Alwil Software\Avast5\flash\ammap\icons\bubble.swf
c:\program files\Alwil Software\Avast5\flash\ammap\icons\cross.swf
c:\program files\Alwil Software\Avast5\flash\ammap\icons\flag.swf
c:\program files\Alwil Software\Avast5\flash\ammap\icons\pin.swf
c:\program files\Alwil Software\Avast5\flash\ammap\icons\zoom_out.swf
c:\program files\Alwil Software\Avast5\flash\ammap\maps\world.swf
c:\program files\Alwil Software\Avast5\sched.exe
c:\program files\Alwil Software\Avast5\Setup\ais_core-19f.vpx
c:\program files\Alwil Software\Avast5\Setup\ais_dll_eng-17d.vpx
c:\program files\Alwil Software\Avast5\Setup\ais_res-113.vpx
c:\program files\Alwil Software\Avast5\Setup\avast.setup
c:\program files\Alwil Software\Avast5\Setup\INF\Aavmker4.sys
c:\program files\Alwil Software\Avast5\Setup\INF\aswFsBlk.sys
c:\program files\Alwil Software\Avast5\Setup\INF\aswMon.sys
c:\program files\Alwil Software\Avast5\Setup\INF\aswMon2.sys
c:\program files\Alwil Software\Avast5\Setup\INF\aswMonFlt.sys
c:\program files\Alwil Software\Avast5\Setup\INF\AswRdr.sys
c:\program files\Alwil Software\Avast5\Setup\INF\aswSP.sys
c:\program files\Alwil Software\Avast5\Setup\INF\AswTdi.sys
c:\program files\Alwil Software\Avast5\Setup\jrog-9b.vpx
c:\program files\Alwil Software\Avast5\Setup\part-jrog-9b.vpx
c:\program files\Alwil Software\Avast5\Setup\part-prg_ais-1fb.vpx
c:\program files\Alwil Software\Avast5\Setup\part-setup_ais-1fb.vpx
c:\program files\Alwil Software\Avast5\Setup\part-vps_win32-10041401.vpx
c:\program files\Alwil Software\Avast5\Setup\prod-ais.vpx
c:\program files\Alwil Software\Avast5\Setup\servers.def
c:\program files\Alwil Software\Avast5\Setup\setif_ais-1fb.vpx
c:\program files\Alwil Software\Avast5\Setup\setiface.dll
c:\program files\Alwil Software\Avast5\Setup\setiface.ovr
c:\program files\Alwil Software\Avast5\Setup\setup.ini
c:\program files\Alwil Software\Avast5\Setup\setup.ovr
c:\program files\Alwil Software\Avast5\Setup\setup_ais-1fb.vpx
c:\program files\Alwil Software\Avast5\Setup\vps_32-186.vpx
c:\program files\Alwil Software\Avast5\Setup\vps_win32-19b.vpx
c:\program files\Alwil Software\Avast5\Setup\winsys-3.vpx
c:\program files\Alwil Software\Avast5\VisthAux.exe
c:\windows\system32\aswBoot.exe
c:\windows\system32\avastSS.scr
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SASDIFSV
-------\Legacy_SASKUTIL
-------\Service_SASDIFSV
-------\Service_SASENUM
-------\Service_SASKUTIL
((((((((((((((((((((((((( Files Created from 2010-03-21 to 2010-04-21 )))))))))))))))))))))))))))))))
.
2010-04-20 03:20 . 2010-04-20 03:20 -------- d-----w- c:\program files\Trend Micro
2010-04-20 02:29 . 2010-03-30 05:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-20 02:29 . 2010-03-30 05:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-17 13:37 . 2010-04-17 13:37 -------- d-----w- c:\program files\Secunia
2010-04-16 21:44 . 2010-04-16 21:44 -------- d-----w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2010-04-16 21:44 . 2010-04-16 21:44 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-04-16 21:40 . 2010-04-16 21:40 503808 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-43017301-n\msvcp71.dll
2010-04-16 21:40 . 2010-04-16 21:40 499712 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-43017301-n\jmc.dll
2010-04-16 21:40 . 2010-04-16 21:40 348160 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-43017301-n\msvcr71.dll
2010-04-16 21:40 . 2010-04-16 21:40 -------- d-----w- c:\program files\Common Files\Java
2010-04-16 21:40 . 2010-04-16 21:40 61440 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7997b7cc-n\decora-sse.dll
2010-04-16 21:40 . 2010-04-16 21:40 12800 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7997b7cc-n\decora-d3d.dll
2010-04-16 21:40 . 2010-04-16 21:39 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-16 21:39 . 2010-04-16 21:39 -------- d-----w- c:\program files\Java
2010-04-16 12:20 . 2010-04-16 12:20 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-04-16 12:20 . 2010-04-16 12:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-04-16 12:20 . 2010-04-20 02:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-15 22:49 . 2010-04-15 22:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Fashion Solitaire 1.2
2010-04-15 02:21 . 2010-04-15 02:22 -------- d-----w- c:\program files\QuickTime
2010-04-15 02:21 . 2010-04-15 02:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-04-10 13:30 . 2010-04-10 13:56 -------- d-----w- c:\program files\AV7
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-20 12:12 . 2010-01-17 07:09 -------- d-----w- c:\documents and settings\Owner\Application Data\MSN6
2010-04-17 19:02 . 2010-01-20 01:50 1744 ----a-w- c:\windows\system32\d3d9caps.dat
2010-04-16 12:16 . 2010-01-21 01:33 -------- d-----w- c:\program files\CCleaner
2010-04-15 23:26 . 2010-01-13 02:59 -------- d-----w- c:\program files\Spyware Doctor
2010-04-15 23:25 . 2010-01-13 02:59 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-15 23:25 . 2010-01-13 02:59 -------- d-----w- c:\program files\Common Files\PC Tools
2010-04-15 22:50 . 2010-01-06 05:15 1632 ----a-w- c:\windows\system32\d3d8caps.dat
2010-04-10 13:55 . 2010-01-06 22:44 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-10 06:15 . 2010-01-06 23:23 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-08 02:44 . 2010-01-17 18:15 -------- d-----w- c:\program files\World's Best Board Games 2009
2010-02-25 06:24 . 2010-01-06 23:23 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2001-08-23 12:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-23 02:59 . 2010-01-07 00:00 25272 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-17 14:10 . 2001-08-23 12:00 2189952 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2001-08-17 13:48 2066816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2010-01-06 23:24 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2001-08-23 12:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-01-22 13:16 . 2010-01-22 13:06 163126 ----a-w- c:\windows\hphins25.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-01-13 39408]
"ccleaner"="c:\program files\CCleaner\ccleaner.exe" [2010-01-26 1724728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-02 65536]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
Secunia PSI.lnk - c:\program files\Secunia\PSI\psi.exe [2009-8-21 900816]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2010-1-7 184320]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [1/12/2010 10:00 PM 207792]
R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [6/17/2009 7:20 AM 12648]
R3 TNET1130;802.11 WLAN;c:\windows\system32\drivers\TNET1130.sys [1/6/2010 5:58 PM 386688]
R3 trid3d;trid3d;c:\windows\system32\drivers\trid3dm.sys [1/5/2010 5:52 PM 222336]
S2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe --> c:\program files\Spyware Doctor\pctsAuxs.exe [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - Hmnt
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2010-04-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
2010-04-20 c:\windows\Tasks\Auslogics Boost Speed Disk Defrag Console Defragmentation.job
- c:\program files\Auslogics\Auslogics Disk Defrag\cdefrag.exe [2010-02-02 21:52]
2010-04-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-01-13 02:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = <local>
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
https://www.gmer.net
Rootkit scan 2010-04-21 07:32
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(4024)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\MsPMSPSv.exe
.
**************************************************************************
.
Completion time: 2010-04-21 07:36:13 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-21 12:36
ComboFix2.txt 2010-04-20 12:28
ComboFix3.txt 2010-04-18 20:01
Pre-Run: 20,828,270,592 bytes free
Post-Run: 20,664,307,712 bytes free
- - End Of File - - C6EEA1065577DD9F8A197B49FD84C988