My only hard disk has 2 partitions C:/ and PQSERVICE which is the recovery partition and is also hidden, so what can i do if the recovery partition is infected? Since every time i reinstall windows from that partition it will also copy the virus over and over again? Heres the log file, and again thanks for your time! ComboFix ComboFix 10-05-17.01 - Perez 05/18/2010 21:33:43.1.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.584 [GMT -6:00] Running from: c:\documents and settings\Perez\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((( Files Created from 2010-04-19 to 2010-05-19 ))))))))))))))))))))))))))))))) . 2010-05-18 23:24 . 2010-05-18 23:24 -------- d-sh--w- c:\documents and settings\Perez\IECompatCache 2010-05-18 17:28 . 2010-05-18 17:28 -------- d-----w- c:\windows\system32\XPSViewer 2010-05-18 17:28 . 2010-05-18 17:28 -------- d-----w- c:\program files\MSBuild 2010-05-18 17:27 . 2010-05-18 17:27 -------- d-----w- c:\program files\Reference Assemblies 2010-05-18 17:27 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll 2010-05-18 17:27 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2010-05-18 17:27 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll 2010-05-18 17:27 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2010-05-18 17:27 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe 2010-05-18 17:27 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll 2010-05-18 17:27 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll 2010-05-18 17:27 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll 2010-05-18 17:27 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll 2010-05-18 17:27 . 2010-05-18 17:27 -------- d-----w- C:\18c83ea38e4aed1e31 2010-05-18 07:42 . 2010-05-18 07:42 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache 2010-05-18 07:41 . 2010-05-18 07:41 -------- d-sh--w- c:\documents and settings\Perez\PrivacIE 2010-05-18 07:39 . 2010-05-18 07:39 -------- d-sh--w- c:\documents and settings\Perez\IETldCache 2010-05-18 07:26 . 2010-05-18 07:26 -------- d-----w- c:\program files\MSXML 4.0 2010-05-18 07:22 . 2010-02-25 06:24 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll 2010-05-18 07:22 . 2010-02-25 06:24 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll 2010-05-18 07:22 . 2010-02-25 06:24 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll 2010-05-18 07:22 . 2010-02-25 06:24 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll 2010-05-18 07:22 . 2010-02-25 06:24 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll 2010-05-18 07:22 . 2010-02-25 17:54 11070976 -c----w- c:\windows\system32\dllcache\ieframe.dll 2010-05-18 07:22 . 2010-05-18 07:22 -------- d-----w- c:\windows\ie8updates 2010-05-18 07:22 . 2010-02-16 04:50 64000 -c----w- c:\windows\system32\dllcache\iecompat.dll 2010-05-18 07:20 . 2010-05-18 07:22 -------- dc-h--w- c:\windows\ie8 2010-05-18 06:12 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys 2010-05-18 06:12 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys 2010-05-18 06:09 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys 2010-05-18 05:47 . 2010-02-16 14:08 2146304 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe 2010-05-18 05:47 . 2010-02-17 15:10 2189952 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe 2010-05-18 05:47 . 2010-02-16 13:25 2024448 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe 2010-05-18 05:30 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll 2010-05-18 05:06 . 2009-08-07 01:23 274288 ----a-w- c:\windows\system32\mucltui.dll 2010-05-18 05:06 . 2009-08-07 01:23 215920 ----a-w- c:\windows\system32\muweb.dll 2010-05-18 04:42 . 2010-05-18 04:42 12464 ----a-w- c:\windows\system32\avgrsstx.dll 2010-05-18 04:42 . 2010-05-18 04:42 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2010-05-18 04:42 . 2010-05-18 04:42 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2010-05-18 04:42 . 2010-05-19 03:23 -------- d-----w- c:\windows\system32\drivers\Avg 2010-05-18 04:41 . 2010-05-18 04:41 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys 2010-05-18 04:37 . 2010-05-18 04:37 -------- d-----w- c:\program files\AVG 2010-05-18 04:37 . 2010-05-18 04:37 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9 2010-05-18 02:35 . 2010-05-18 02:35 -------- d-----w- c:\documents and settings\Perez\Application Data\Malwarebytes 2010-05-18 02:35 . 2010-04-29 21:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-05-18 02:35 . 2010-05-18 02:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-05-18 02:35 . 2010-05-18 02:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-05-18 02:35 . 2010-04-29 21:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-05-17 23:38 . 2010-05-17 23:38 60592 ----a-w- c:\documents and settings\Perez\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-05-17 23:33 . 2010-05-17 23:33 -------- d-----w- c:\documents and settings\Perez\Local Settings\Application Data\Google 2010-05-17 23:30 . 2007-04-13 17:51 321024 ----a-w- c:\windows\system32\ERUpdateHidden.EXE 2010-05-17 23:30 . 2006-03-30 19:06 258048 ----a-w- c:\windows\system32\CheckD2DSystem.exe 2010-05-17 23:30 . 2006-03-23 18:02 258048 ----a-w- c:\windows\system32\Uninstall_eRecovery.exe 2010-05-17 23:30 . 2005-12-09 15:12 16384 ----a-w- c:\windows\system32\ClearEvent.exe 2010-05-17 23:30 . 2004-11-03 15:06 159744 ----a-w- c:\windows\system32\CloseProcessWindow.dll 2010-05-17 23:29 . 2010-05-17 23:29 125 ----a-w- c:\windows\xUninstall.bat 2010-05-17 23:29 . 2010-05-17 23:29 -------- d-----w- c:\windows\JMCR_DIR 2010-05-17 23:29 . 2008-07-08 01:16 96856 ----a-w- c:\windows\system32\drivers\jmcr.sys 2010-05-17 23:29 . 2008-05-14 10:53 110080 ----a-w- c:\windows\system32\JmCrIcon.dll 2010-05-17 23:27 . 2010-05-17 23:27 -------- d-----w- c:\program files\Common Files\CrystalEye 2010-05-17 23:26 . 2008-06-13 23:43 4342912 ----a-w- c:\windows\system32\acer.exe 2010-05-17 23:26 . 2007-04-19 19:41 83554304 ----a-w- c:\windows\system32\acer.scr 2010-05-17 23:26 . 2010-05-17 23:26 -------- d-----w- c:\program files\Acer Incorporated 2010-05-17 23:26 . 2010-05-17 23:27 -------- d-----w- c:\windows\ACER 2010-05-17 23:25 . 2010-05-17 23:25 110576 ----a-w- c:\documents and settings\All Users\Application Data\Partner\partner.exe 2010-05-17 23:25 . 2010-05-17 23:25 157168 ----a-w- c:\documents and settings\All Users\Application Data\Partner\partner.dll 2010-05-17 23:25 . 2010-05-17 23:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Partner 2010-05-17 23:25 . 2010-05-18 03:48 -------- d-----w- c:\program files\Google 2010-05-17 23:25 . 2010-05-17 23:25 -------- d-----w- c:\program files\Launch Manager 2010-05-17 23:18 . 2008-04-14 06:16 10880 ----a-w- c:\windows\system32\drivers\NdisIP.sys 2010-05-17 23:18 . 2008-04-15 03:00 15232 ----a-w- c:\windows\system32\drivers\StreamIP.sys 2010-05-17 23:18 . 2008-04-15 03:00 11136 ----a-w- c:\windows\system32\drivers\SLIP.sys 2010-05-17 23:18 . 2008-04-14 06:09 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys 2010-05-17 23:18 . 2008-04-14 06:16 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS 2010-05-17 23:18 . 2010-05-17 23:01 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\InstallShield 2010-05-17 23:18 . 2008-04-14 06:16 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys 2010-05-17 23:17 . 2008-04-14 06:16 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys 2010-05-17 23:16 . 2008-08-15 18:10 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SiteAdvisor 2010-05-17 23:13 . 2010-05-17 23:13 -------- d-----w- c:\windows\WebCam 2010-05-17 23:13 . 2008-04-14 11:42 53760 ----a-w- c:\windows\vfwwdm32.dll 2010-05-17 23:06 . 2010-05-17 23:06 -------- d---a-w- c:\windows\AcerStore . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-05-18 07:35 . 2008-08-15 18:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2010-05-18 07:28 . 2008-08-15 18:18 -------- d-----w- c:\program files\Microsoft Works 2010-05-17 23:29 . 2008-08-15 18:12 -------- d--h--w- c:\program files\InstallShield Installation Information 2010-05-17 23:06 . 2004-09-21 21:28 3 ----a-w- c:\windows\HotFix.bat 2010-05-17 23:06 . 2004-06-26 00:13 139 ----a-w- c:\windows\HotFix2.bat 2010-05-17 23:03 . 2008-08-15 17:59 -------- d-----w- c:\program files\Realtek 2010-05-17 23:03 . 2008-08-15 18:15 -------- d-----w- c:\program files\Microsoft.NET 2010-05-17 23:03 . 2008-08-15 18:18 -------- d-----w- c:\program files\Microsoft Office Suite Activation Assistant 2010-05-17 23:02 . 2008-08-15 17:37 -------- d-----w- c:\program files\microsoft frontpage 2010-05-17 23:02 . 2008-08-15 18:12 -------- d-----w- c:\program files\InterVideo 2010-05-17 23:02 . 2008-08-15 17:41 -------- d-----w- c:\program files\Intel 2010-05-17 23:02 . 2008-08-15 18:12 -------- d-----w- c:\program files\Common Files\InterVideo 2010-05-17 23:02 . 2008-08-15 18:03 -------- d-----w- c:\program files\Common Files\Adobe AIR 2010-05-17 23:02 . 2008-08-15 17:58 -------- d-----w- c:\program files\Common Files\InstallShield 2010-05-17 23:02 . 2008-08-15 18:03 -------- d-----w- c:\program files\Common Files\Adobe 2010-05-17 23:02 . 2008-08-15 18:00 -------- d-----w- c:\program files\Atheros 2010-05-17 23:01 . 2010-05-17 23:19 -------- d-----w- c:\documents and settings\Perez\Application Data\InstallShield 2010-05-17 23:01 . 2008-08-15 18:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Atheros 2010-03-11 12:38 . 2010-03-11 12:38 78336 ------w- c:\windows\system32\ieencode.dll 2010-02-25 06:24 . 2007-08-14 01:54 916480 ----a-w- c:\windows\system32\wininet.dll 2010-02-24 13:11 . 2008-04-15 03:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}] 2010-05-17 23:25 157168 ----a-w- c:\documents and settings\All Users\Application Data\Partner\partner.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LaunchApp"="Alaunch" [X] "M3000Mnt"="M3000Rmv.dll " [X] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752] "RTHDCPL"="RTHDCPL.EXE" [2008-05-16 16862720] "AzMixerSel"="c:\program files\Realtek\Audio\InstallShield\AzMixerSel.exe" [2006-07-17 53248] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1044480] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-15 208952] "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-15 59392] "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168] "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168] "LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-05-14 821768] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-05-17 24064] "eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-05-22 425984] c:\documents and settings\All Users\Start Menu\Programs\Startup\ InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-6-4 114688] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2010-05-18 04:42 12464 ----a-w- c:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\AVG\\AVG9\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"= R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/17/2010 10:42 PM 216200] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/17/2010 10:41 PM 242896] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [5/17/2010 10:40 PM 916760] R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [5/17/2010 10:39 PM 308064] R3 M3000Srv;Acer Crystal Eye webcam Driver;c:\windows\system32\drivers\M3000KNT.sys [5/5/2008 10:01 AM 254976] S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [5/17/2010 5:25 PM 24064] S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [5/17/2010 5:29 PM 96856] S3 Partner Service;Partner Service;c:\documents and settings\All Users\Application Data\Partner\partner.exe [5/17/2010 5:25 PM 110576] . Contents of the 'Scheduled Tasks' folder . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 . ************************************************************************** scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(3740) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\AVG\AVG9\avgchsvx.exe c:\program files\AVG\AVG9\avgrsx.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe c:\program files\AVG\AVG9\avgnsx.exe c:\program files\AVG\AVG9\avgcsrvx.exe c:\system volume information\_restore{d5fffa500b1b}\smss.exe c:\windows\system32\wscntfy.exe c:\windows\RTHDCPL.EXE c:\windows\system32\igfxsrvc.exe c:\windows\system32\igfxext.exe c:\docume~1\Perez\LOCALS~1\Temp\RtkBtMnt.exe . ************************************************************************** . Completion time: 2010-05-18 21:42:13 - machine was rebooted ComboFix-quarantined-files.txt 2010-05-19 03:42 Pre-Run: 144,117,424,128 bytes free Post-Run: 144,212,455,424 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect - - End Of File - - 2641F1C78A7B30DFF13B2C6A0B49F795