Allright, I ran the new CFScript.txt with Combofix and just like the last time I got the message "Combofix needs to submit malware files for further analysis." After the combofix finished, the computer seems to have sped up a lot more. Below you'll find the log from the combofix.
ComboFix 10-09-03.01 - BRIAN WEBB 09/03/2010 23:28:04.4.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.186 [GMT -4:00]
Running from: c:\documents and settings\BRIAN WEBB\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\BRIAN WEBB\Desktop\CFScript.txt
AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FILE ::
"c:\windows\system32\drivers\OLD40D1.tmp"
"c:\windows\system32\drivers\OLD40D4.tmp"
"c:\windows\system32\drivers\OLD40D7.tmp"
"c:\windows\system32\drivers\OLD40DA.tmp"
"c:\windows\system32\drivers\OLD40DD.tmp"
"c:\windows\system32\drivers\OLD40E0.tmp"
"c:\windows\system32\drivers\OLD40E3.tmp"
"c:\windows\system32\drivers\OLD40E6.tmp"
"c:\windows\system32\drivers\OLD40E9.tmp"
"c:\windows\system32\drivers\OLD40EC.tmp"
"c:\windows\system32\drivers\OLD40EF.tmp"
"c:\windows\system32\drivers\OLD40F2.tmp"
"c:\windows\system32\drivers\OLD40F5.tmp"
"c:\windows\system32\drivers\OLD40F8.tmp"
"c:\windows\system32\drivers\OLD40FB.tmp"
"c:\windows\system32\drivers\OLD40FE.tmp"
"c:\windows\system32\drivers\OLD4101.tmp"
"c:\windows\system32\drivers\OLD4104.tmp"
"c:\windows\system32\drivers\OLD4107.tmp"
"c:\windows\system32\drivers\OLD410A.tmp"
"c:\windows\system32\drivers\OLD410D.tmp"
"c:\windows\system32\drivers\OLD4110.tmp"
"c:\windows\system32\drivers\OLD4113.tmp"
"c:\windows\system32\drivers\OLD4116.tmp"
"c:\windows\system32\drivers\OLD4119.tmp"
"c:\windows\system32\drivers\OLD411C.tmp"
"c:\windows\system32\drivers\OLD411F.tmp"
"c:\windows\system32\drivers\OLD4122.tmp"
"c:\windows\system32\drivers\OLD4125.tmp"
"c:\windows\system32\drivers\OLD4128.tmp"
"c:\windows\system32\drivers\OLD412B.tmp"
"c:\windows\system32\drivers\OLD412E.tmp"
"c:\windows\system32\drivers\OLD4131.tmp"
"c:\windows\system32\drivers\OLD4134.tmp"
"c:\windows\system32\drivers\OLD4137.tmp"
"c:\windows\system32\drivers\OLD413A.tmp"
"c:\windows\system32\drivers\OLD413D.tmp"
"c:\windows\system32\drivers\OLD4140.tmp"
"c:\windows\system32\drivers\OLD4143.tmp"
"c:\windows\system32\drivers\OLD4146.tmp"
"c:\windows\system32\drivers\OLD4149.tmp"
"c:\windows\system32\drivers\OLD414C.tmp"
"c:\windows\system32\drivers\OLD414F.tmp"
"c:\windows\system32\drivers\OLD4152.tmp"
"c:\windows\system32\drivers\OLD4155.tmp"
"c:\windows\system32\drivers\OLD4158.tmp"
"c:\windows\system32\drivers\OLD415B.tmp"
"c:\windows\system32\drivers\OLD415E.tmp"
"c:\windows\system32\drivers\OLD4161.tmp"
"c:\windows\system32\drivers\OLD4164.tmp"
"c:\windows\system32\drivers\OLD4167.tmp"
"c:\windows\system32\drivers\OLD416A.tmp"
"c:\windows\system32\drivers\OLD416D.tmp"
"c:\windows\system32\drivers\OLD4170.tmp"
"c:\windows\system32\drivers\OLD4173.tmp"
"c:\windows\system32\drivers\OLD4176.tmp"
"c:\windows\system32\drivers\OLD4179.tmp"
"c:\windows\system32\drivers\OLD417C.tmp"
"c:\windows\system32\drivers\OLD417F.tmp"
"c:\windows\system32\drivers\OLD4182.tmp"
"c:\windows\system32\drivers\OLD4185.tmp"
"c:\windows\system32\drivers\OLD4188.tmp"
"c:\windows\system32\drivers\OLD418B.tmp"
"c:\windows\system32\drivers\OLD418E.tmp"
"c:\windows\system32\drivers\OLD4191.tmp"
"c:\windows\system32\drivers\OLD4194.tmp"
"c:\windows\system32\drivers\OLD4197.tmp"
"c:\windows\system32\drivers\OLD419A.tmp"
"c:\windows\system32\drivers\OLD419D.tmp"
"c:\windows\system32\drivers\OLD41A0.tmp"
"c:\windows\system32\drivers\OLD41A3.tmp"
"c:\windows\system32\drivers\OLD41A6.tmp"
"c:\windows\system32\drivers\OLD41A9.tmp"
"c:\windows\system32\drivers\OLD41AC.tmp"
"c:\windows\system32\drivers\OLD41AF.tmp"
"c:\windows\system32\drivers\OLD41B2.tmp"
"c:\windows\system32\drivers\OLD41B5.tmp"
"c:\windows\system32\drivers\OLD41B8.tmp"
"c:\windows\system32\drivers\OLD41BB.tmp"
"c:\windows\system32\drivers\OLD41BE.tmp"
"c:\windows\system32\drivers\OLD41C1.tmp"
"c:\windows\system32\drivers\OLD41C4.tmp"
"c:\windows\system32\drivers\OLD41C7.tmp"
"c:\windows\system32\drivers\OLD41CA.tmp"
"c:\windows\system32\drivers\OLD41CD.tmp"
"c:\windows\system32\drivers\OLD41D0.tmp"
"c:\windows\system32\drivers\OLD41D3.tmp"
"c:\windows\system32\drivers\OLD41D6.tmp"
"c:\windows\system32\drivers\OLD41D9.tmp"
"c:\windows\system32\drivers\OLD41DC.tmp"
"c:\windows\system32\drivers\OLD41DF.tmp"
"c:\windows\system32\drivers\OLD41E2.tmp"
"c:\windows\system32\drivers\OLD41E5.tmp"
"c:\windows\system32\drivers\OLD41E8.tmp"
"c:\windows\system32\drivers\OLD41EB.tmp"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\OLD40D1.tmp
c:\windows\system32\drivers\OLD40D4.tmp
c:\windows\system32\drivers\OLD40D7.tmp
c:\windows\system32\drivers\OLD40DA.tmp
c:\windows\system32\drivers\OLD40DD.tmp
c:\windows\system32\drivers\OLD40E0.tmp
c:\windows\system32\drivers\OLD40E3.tmp
c:\windows\system32\drivers\OLD40E6.tmp
c:\windows\system32\drivers\OLD40E9.tmp
c:\windows\system32\drivers\OLD40EC.tmp
c:\windows\system32\drivers\OLD40EF.tmp
c:\windows\system32\drivers\OLD40F2.tmp
c:\windows\system32\drivers\OLD40F5.tmp
c:\windows\system32\drivers\OLD40F8.tmp
c:\windows\system32\drivers\OLD40FB.tmp
c:\windows\system32\drivers\OLD40FE.tmp
c:\windows\system32\drivers\OLD4101.tmp
c:\windows\system32\drivers\OLD4104.tmp
c:\windows\system32\drivers\OLD4107.tmp
c:\windows\system32\drivers\OLD410A.tmp
c:\windows\system32\drivers\OLD410D.tmp
c:\windows\system32\drivers\OLD4110.tmp
c:\windows\system32\drivers\OLD4113.tmp
c:\windows\system32\drivers\OLD4116.tmp
c:\windows\system32\drivers\OLD4119.tmp
c:\windows\system32\drivers\OLD411C.tmp
c:\windows\system32\drivers\OLD411F.tmp
c:\windows\system32\drivers\OLD4122.tmp
c:\windows\system32\drivers\OLD4125.tmp
c:\windows\system32\drivers\OLD4128.tmp
c:\windows\system32\drivers\OLD412B.tmp
c:\windows\system32\drivers\OLD412E.tmp
c:\windows\system32\drivers\OLD4131.tmp
c:\windows\system32\drivers\OLD4134.tmp
c:\windows\system32\drivers\OLD4137.tmp
c:\windows\system32\drivers\OLD413A.tmp
c:\windows\system32\drivers\OLD413D.tmp
c:\windows\system32\drivers\OLD4140.tmp
c:\windows\system32\drivers\OLD4143.tmp
c:\windows\system32\drivers\OLD4146.tmp
c:\windows\system32\drivers\OLD4149.tmp
c:\windows\system32\drivers\OLD414C.tmp
c:\windows\system32\drivers\OLD414F.tmp
c:\windows\system32\drivers\OLD4152.tmp
c:\windows\system32\drivers\OLD4155.tmp
c:\windows\system32\drivers\OLD4158.tmp
c:\windows\system32\drivers\OLD415B.tmp
c:\windows\system32\drivers\OLD415E.tmp
c:\windows\system32\drivers\OLD4161.tmp
c:\windows\system32\drivers\OLD4164.tmp
c:\windows\system32\drivers\OLD4167.tmp
c:\windows\system32\drivers\OLD416A.tmp
c:\windows\system32\drivers\OLD416D.tmp
c:\windows\system32\drivers\OLD4170.tmp
c:\windows\system32\drivers\OLD4173.tmp
c:\windows\system32\drivers\OLD4176.tmp
c:\windows\system32\drivers\OLD4179.tmp
c:\windows\system32\drivers\OLD417C.tmp
c:\windows\system32\drivers\OLD417F.tmp
c:\windows\system32\drivers\OLD4182.tmp
c:\windows\system32\drivers\OLD4185.tmp
c:\windows\system32\drivers\OLD4188.tmp
c:\windows\system32\drivers\OLD418B.tmp
c:\windows\system32\drivers\OLD418E.tmp
c:\windows\system32\drivers\OLD4191.tmp
c:\windows\system32\drivers\OLD4194.tmp
c:\windows\system32\drivers\OLD4197.tmp
c:\windows\system32\drivers\OLD419A.tmp
c:\windows\system32\drivers\OLD419D.tmp
c:\windows\system32\drivers\OLD41A0.tmp
c:\windows\system32\drivers\OLD41A3.tmp
c:\windows\system32\drivers\OLD41A6.tmp
c:\windows\system32\drivers\OLD41A9.tmp
c:\windows\system32\drivers\OLD41AC.tmp
c:\windows\system32\drivers\OLD41AF.tmp
c:\windows\system32\drivers\OLD41B2.tmp
c:\windows\system32\drivers\OLD41B5.tmp
c:\windows\system32\drivers\OLD41B8.tmp
c:\windows\system32\drivers\OLD41BB.tmp
c:\windows\system32\drivers\OLD41BE.tmp
c:\windows\system32\drivers\OLD41C1.tmp
c:\windows\system32\drivers\OLD41C4.tmp
c:\windows\system32\drivers\OLD41C7.tmp
c:\windows\system32\drivers\OLD41CA.tmp
c:\windows\system32\drivers\OLD41CD.tmp
c:\windows\system32\drivers\OLD41D0.tmp
c:\windows\system32\drivers\OLD41D3.tmp
c:\windows\system32\drivers\OLD41D6.tmp
c:\windows\system32\drivers\OLD41D9.tmp
c:\windows\system32\drivers\OLD41DC.tmp
c:\windows\system32\drivers\OLD41DF.tmp
c:\windows\system32\drivers\OLD41E2.tmp
c:\windows\system32\drivers\OLD41E5.tmp
c:\windows\system32\drivers\OLD41E8.tmp
c:\windows\system32\drivers\OLD41EB.tmp
.
((((((((((((((((((((((((( Files Created from 2010-08-04 to 2010-09-04 )))))))))))))))))))))))))))))))
.
2010-09-02 21:34 . 2008-04-13 18:40 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-09-02 21:34 . 2008-04-13 18:40 96512 ----a-w- C:\atapi.sys
2010-08-28 15:32 . 2010-08-28 15:32 -------- d-----w- c:\documents and settings\Administrator.BRIAN\Local Settings\Application Data\Symantec
2010-08-13 12:16 . 2010-08-14 03:11 -------- d-----w- c:\windows\system32\MpEngineStore
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-02 00:15 . 2010-01-22 00:45 -------- d-----w- c:\program files\PlaySushi
2010-09-02 00:15 . 2009-08-04 02:49 -------- d-----w- c:\program files\iWin Games
2010-09-01 03:13 . 2006-06-03 20:15 -------- d-----w- c:\documents and settings\BRIAN WEBB\Application Data\Wildfire
2010-09-01 00:46 . 2009-07-16 17:01 -------- d-----w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2010-08-28 15:34 . 2010-04-10 16:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-27 12:22 . 2010-08-27 12:22 96512 ----a-w- c:\windows\system32\drivers\OLD40CE.tmp
2010-08-27 12:22 . 2010-08-27 12:22 96512 ----a-w- c:\windows\system32\drivers\OLD40CB.tmp
2010-08-27 12:22 . 2010-08-27 12:22 96512 ----a-w- c:\windows\system32\drivers\OLD40C8.tmp
2010-08-27 12:22 . 2010-08-27 12:22 96512 ----a-w- c:\windows\system32\drivers\OLD40C5.tmp
2010-08-27 12:22 . 2010-08-27 12:22 96512 ----a-w- c:\windows\system32\drivers\OLD40C2.tmp
2010-08-27 12:22 . 2010-08-27 12:22 96512 ----a-w- c:\windows\system32\drivers\OLD40BF.tmp
2010-08-27 12:22 . 2010-08-27 12:22 96512 ----a-w- c:\windows\system32\drivers\OLD40BC.tmp
2010-08-27 12:21 . 2010-08-27 12:22 96512 ----a-w- c:\windows\system32\drivers\OLD40B9.tmp
2010-08-27 12:21 . 2010-08-27 12:21 96512 ----a-w- c:\windows\system32\drivers\OLD40B6.tmp
2010-08-27 12:21 . 2010-08-27 12:21 96512 ----a-w- c:\windows\system32\drivers\OLD40B3.tmp
2010-08-27 12:21 . 2010-08-27 12:21 96512 ----a-w- c:\windows\system32\drivers\OLD40B0.tmp
2010-08-27 12:21 . 2010-08-27 12:21 96512 ----a-w- c:\windows\system32\drivers\OLD40AD.tmp
2010-08-27 12:21 . 2010-08-27 12:21 96512 ----a-w- c:\windows\system32\drivers\OLD40AA.tmp
2010-08-27 12:21 . 2010-08-27 12:21 96512 ----a-w- c:\windows\system32\drivers\OLD40A7.tmp
2010-08-27 12:21 . 2010-08-27 12:21 96512 ----a-w- c:\windows\system32\drivers\OLD40A4.tmp
2010-08-27 12:21 . 2010-08-27 12:21 96512 ----a-w- c:\windows\system32\drivers\OLD40A1.tmp
2010-08-27 12:21 . 2010-08-27 12:21 96512 ----a-w- c:\windows\system32\drivers\OLD409E.tmp
2010-08-27 12:21 . 2010-08-27 12:21 96512 ----a-w- c:\windows\system32\drivers\OLD409B.tmp
2010-08-27 12:20 . 2010-08-27 12:21 96512 ----a-w- c:\windows\system32\drivers\OLD4098.tmp
2010-08-27 12:20 . 2010-08-27 12:20 96512 ----a-w- c:\windows\system32\drivers\OLD4095.tmp
2010-08-27 12:20 . 2010-08-27 12:20 96512 ----a-w- c:\windows\system32\drivers\OLD4092.tmp
2010-08-27 12:20 . 2010-08-27 12:20 96512 ----a-w- c:\windows\system32\drivers\OLD408F.tmp
2010-08-27 12:20 . 2010-08-27 12:20 96512 ----a-w- c:\windows\system32\drivers\OLD408C.tmp
2010-08-27 12:20 . 2010-08-27 12:20 96512 ----a-w- c:\windows\system32\drivers\OLD4089.tmp
2010-08-27 12:20 . 2010-08-27 12:20 96512 ----a-w- c:\windows\system32\drivers\OLD4086.tmp
2010-08-27 12:20 . 2010-08-27 12:20 96512 ----a-w- c:\windows\system32\drivers\OLD4083.tmp
2010-08-27 12:20 . 2010-08-27 12:20 96512 ----a-w- c:\windows\system32\drivers\OLD4080.tmp
2010-08-27 12:20 . 2010-08-27 12:20 96512 ----a-w- c:\windows\system32\drivers\OLD407D.tmp
2010-08-27 12:20 . 2010-08-27 12:20 96512 ----a-w- c:\windows\system32\drivers\OLD407A.tmp
2010-08-27 12:19 . 2010-08-27 12:20 96512 ----a-w- c:\windows\system32\drivers\OLD4077.tmp
2010-08-27 12:19 . 2010-08-27 12:19 96512 ----a-w- c:\windows\system32\drivers\OLD4074.tmp
2010-08-27 12:19 . 2010-08-27 12:19 96512 ----a-w- c:\windows\system32\drivers\OLD4071.tmp
2010-08-27 12:19 . 2010-08-27 12:19 96512 ----a-w- c:\windows\system32\drivers\OLD406E.tmp
2010-08-27 12:19 . 2010-08-27 12:19 96512 ----a-w- c:\windows\system32\drivers\OLD406B.tmp
2010-08-27 12:19 . 2010-08-27 12:19 96512 ----a-w- c:\windows\system32\drivers\OLD4068.tmp
2010-08-27 12:19 . 2010-08-27 12:19 96512 ----a-w- c:\windows\system32\drivers\OLD4065.tmp
2010-08-27 12:19 . 2010-08-27 12:19 96512 ----a-w- c:\windows\system32\drivers\OLD4062.tmp
2010-08-27 12:19 . 2010-08-27 12:19 96512 ----a-w- c:\windows\system32\drivers\OLD405F.tmp
2010-08-27 12:19 . 2010-08-27 12:19 96512 ----a-w- c:\windows\system32\drivers\OLD405C.tmp
2010-08-27 12:19 . 2010-08-27 12:19 96512 ----a-w- c:\windows\system32\drivers\OLD4059.tmp
2010-08-27 12:18 . 2010-08-27 12:19 96512 ----a-w- c:\windows\system32\drivers\OLD4056.tmp
2010-08-27 12:18 . 2010-08-27 12:18 96512 ----a-w- c:\windows\system32\drivers\OLD4053.tmp
2010-08-27 12:18 . 2010-08-27 12:18 96512 ----a-w- c:\windows\system32\drivers\OLD4050.tmp
2010-08-27 12:18 . 2010-08-27 12:18 96512 ----a-w- c:\windows\system32\drivers\OLD404D.tmp
2010-08-27 12:18 . 2010-08-27 12:18 96512 ----a-w- c:\windows\system32\drivers\OLD404A.tmp
2010-08-27 12:18 . 2010-08-27 12:18 96512 ----a-w- c:\windows\system32\drivers\OLD4047.tmp
2010-08-27 12:18 . 2010-08-27 12:18 96512 ----a-w- c:\windows\system32\drivers\OLD4044.tmp
2010-08-27 12:18 . 2010-08-27 12:18 96512 ----a-w- c:\windows\system32\drivers\OLD4041.tmp
2010-08-27 12:18 . 2010-08-27 12:18 96512 ----a-w- c:\windows\system32\drivers\OLD403E.tmp
2010-08-27 12:18 . 2010-08-27 12:18 96512 ----a-w- c:\windows\system32\drivers\OLD403B.tmp
2010-08-27 12:18 . 2010-08-27 12:18 96512 ----a-w- c:\windows\system32\drivers\OLD4038.tmp
2010-08-27 12:17 . 2010-08-27 12:18 96512 ----a-w- c:\windows\system32\drivers\OLD4035.tmp
2010-08-27 12:17 . 2010-08-27 12:17 96512 ----a-w- c:\windows\system32\drivers\OLD4032.tmp
2010-08-27 12:17 . 2010-08-27 12:17 96512 ----a-w- c:\windows\system32\drivers\OLD402F.tmp
2010-08-27 12:17 . 2010-08-27 12:17 96512 ----a-w- c:\windows\system32\drivers\OLD402C.tmp
2010-08-27 12:17 . 2010-08-27 12:17 96512 ----a-w- c:\windows\system32\drivers\OLD4029.tmp
2010-08-27 12:17 . 2010-08-27 12:17 96512 ----a-w- c:\windows\system32\drivers\OLD4026.tmp
2010-08-27 12:17 . 2010-08-27 12:17 96512 ----a-w- c:\windows\system32\drivers\OLD4023.tmp
2010-08-27 12:17 . 2010-08-27 12:17 96512 ----a-w- c:\windows\system32\drivers\OLD4020.tmp
2010-08-27 12:17 . 2010-08-27 12:17 96512 ----a-w- c:\windows\system32\drivers\OLD401D.tmp
2010-08-27 12:17 . 2010-08-27 12:17 96512 ----a-w- c:\windows\system32\drivers\OLD401A.tmp
2010-08-27 12:17 . 2010-08-27 12:17 96512 ----a-w- c:\windows\system32\drivers\OLD4017.tmp
2010-08-27 12:16 . 2010-08-27 12:17 96512 ----a-w- c:\windows\system32\drivers\OLD4014.tmp
2010-08-27 12:16 . 2010-08-27 12:16 96512 ----a-w- c:\windows\system32\drivers\OLD4011.tmp
2010-08-27 12:16 . 2010-08-27 12:16 96512 ----a-w- c:\windows\system32\drivers\OLD400E.tmp
2010-08-27 12:16 . 2010-08-27 12:16 96512 ----a-w- c:\windows\system32\drivers\OLD400B.tmp
2010-08-27 12:16 . 2010-08-27 12:16 96512 ----a-w- c:\windows\system32\drivers\OLD4008.tmp
2010-08-27 12:16 . 2010-08-27 12:16 96512 ----a-w- c:\windows\system32\drivers\OLD4005.tmp
2010-08-27 12:16 . 2010-08-27 12:16 96512 ----a-w- c:\windows\system32\drivers\OLD4002.tmp
2010-08-27 12:16 . 2010-08-27 12:16 96512 ----a-w- c:\windows\system32\drivers\OLD3FFF.tmp
2010-08-27 12:16 . 2010-08-27 12:16 96512 ----a-w- c:\windows\system32\drivers\OLD3FFC.tmp
2010-08-27 12:16 . 2010-08-27 12:16 96512 ----a-w- c:\windows\system32\drivers\OLD3FF9.tmp
2010-08-27 12:16 . 2010-08-27 12:16 96512 ----a-w- c:\windows\system32\drivers\OLD3FF6.tmp
2010-08-27 12:15 . 2010-08-27 12:16 96512 ----a-w- c:\windows\system32\drivers\OLD3FF3.tmp
2010-08-27 12:15 . 2010-08-27 12:15 96512 ----a-w- c:\windows\system32\drivers\OLD3FF0.tmp
2010-08-27 12:15 . 2010-08-27 12:15 96512 ----a-w- c:\windows\system32\drivers\OLD3FED.tmp
2010-08-27 12:15 . 2010-08-27 12:15 96512 ----a-w- c:\windows\system32\drivers\OLD3FEA.tmp
2010-08-27 12:15 . 2010-08-27 12:15 96512 ----a-w- c:\windows\system32\drivers\OLD3FE7.tmp
2010-08-27 12:15 . 2010-08-27 12:15 96512 ----a-w- c:\windows\system32\drivers\OLD3FE4.tmp
2010-08-27 12:15 . 2010-08-27 12:15 96512 ----a-w- c:\windows\system32\drivers\OLD3FE1.tmp
2010-08-27 12:15 . 2010-08-27 12:15 96512 ----a-w- c:\windows\system32\drivers\OLD3FDE.tmp
2010-08-27 12:15 . 2010-08-27 12:15 96512 ----a-w- c:\windows\system32\drivers\OLD3FDB.tmp
2010-08-27 12:15 . 2010-08-27 12:15 96512 ----a-w- c:\windows\system32\drivers\OLD3FD8.tmp
2010-08-27 12:15 . 2010-08-27 12:15 96512 ----a-w- c:\windows\system32\drivers\OLD3FD5.tmp
2010-08-27 12:14 . 2010-08-27 12:15 96512 ----a-w- c:\windows\system32\drivers\OLD3FD2.tmp
2010-08-27 12:14 . 2010-08-27 12:14 96512 ----a-w- c:\windows\system32\drivers\OLD3FCF.tmp
2010-08-27 12:14 . 2010-08-27 12:14 96512 ----a-w- c:\windows\system32\drivers\OLD3FCC.tmp
2010-08-27 12:14 . 2010-08-27 12:14 96512 ----a-w- c:\windows\system32\drivers\OLD3FC9.tmp
2010-08-27 12:14 . 2010-08-27 12:14 96512 ----a-w- c:\windows\system32\drivers\OLD3FC6.tmp
2010-08-27 12:14 . 2010-08-27 12:14 96512 ----a-w- c:\windows\system32\drivers\OLD3FC3.tmp
2010-08-27 12:14 . 2010-08-27 12:14 96512 ----a-w- c:\windows\system32\drivers\OLD3FC0.tmp
2010-08-27 12:14 . 2010-08-27 12:14 96512 ----a-w- c:\windows\system32\drivers\OLD3FBD.tmp
2010-08-27 12:14 . 2010-08-27 12:14 96512 ----a-w- c:\windows\system32\drivers\OLD3FBA.tmp
2010-08-27 12:14 . 2010-08-27 12:14 96512 ----a-w- c:\windows\system32\drivers\OLD3FB7.tmp
2010-08-27 12:14 . 2010-08-27 12:14 96512 ----a-w- c:\windows\system32\drivers\OLD3FB4.tmp
2008-03-19 16:26 . 2008-03-05 14:58 848 --sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-10-02 198160]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SWHelper"="c:\windows\system32\Macromed\Shockwave 10\PostUpdate.exe" [2010-08-19 53248]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Billminder.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Billminder.lnk
backup=c:\windows\pss\Billminder.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^dlbcserv.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\dlbcserv.lnk
backup=c:\windows\pss\dlbcserv.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Startup.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Quicken Startup.lnk
backup=c:\windows\pss\Quicken Startup.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SideACT!.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SideACT!.lnk
backup=c:\windows\pss\SideACT!.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^BRIAN WEBB^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\BRIAN WEBB\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^BRIAN WEBB^Start Menu^Programs^Startup^OneNote Table Of Contents.onetoc2]
path=c:\documents and settings\BRIAN WEBB\Start Menu\Programs\Startup\OneNote Table Of Contents.onetoc2
backup=c:\windows\pss\OneNote Table Of Contents.onetoc2Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-02-27 21:10 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
2009-10-07 12:23 323392 ----a-w- c:\program files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
2002-04-11 01:03 368706 ----a-w- c:\program files\BroadJump\Client Foundation\CFD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2008-03-18 01:06 1848648 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2008-12-12 01:31 722256 ----a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
2004-07-19 12:51 306688 ----a-w- c:\program files\Dell Support\DSAgnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2004-10-12 21:54 57344 ------w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2005-09-20 14:32 77824 ----a-w- c:\windows\SYSTEM32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2005-09-20 14:35 94208 ----a-w- c:\windows\SYSTEM32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelMeM]
2003-09-04 01:12 221184 -c--a-w- c:\program files\Intel\Modem Event Monitor\IntelMEM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
2004-09-14 13:50 53248 -c--a-w- c:\program files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2004-09-14 13:50 131072 -c--a-w- c:\program files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 --sh--w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2007-06-29 10:24 286720 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Radio365Agent]
2006-12-19 22:55 884736 ----a-w- c:\progra~1\Live365\Radio365\Radio365TrayAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2009-10-02 12:24 222728 ----a-w- c:\program files\Real\realplayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-14 19:42 1404928 -c--a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedTouch USB Diagnostics]
2001-10-03 14:09 4247552 -c--a-w- c:\program files\Alcatel\SpeedTouch USB\dragdiag.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2003-11-19 22:48 32881 -c--a-w- c:\program files\Java\j2re1.4.2_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tgcmd]
2004-07-25 18:45 1277952 -c--a-w- c:\program files\Support.com\BellSouth\hcenter.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-10-02 12:24 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
2004-01-07 06:01 110592 -c--a-w- c:\program files\Common Files\Sonic\Update Manager\sgtray.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\GameTap\\bin\\release\\gametap.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\My Games\\Red Ace Squadron\\ras.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\iWin Games\\iWinGames.exe"=
"c:\\Program Files\\iWin Games\\WebUpdater.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R0 SymEFA;Symantec Extended File Attributes;c:\windows\SYSTEM32\DRIVERS\NAV\1008000.029\SymEFA.sys [4/28/2010 8:42 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\SYSTEM32\DRIVERS\NAV\1008000.029\BHDrvx86.sys [4/28/2010 8:42 PM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\SYSTEM32\DRIVERS\NAV\1008000.029\cchpx86.sys [4/28/2010 8:40 PM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100901.003\IDSXpx86.sys [9/2/2010 8:36 PM 331640]
R2 iWinTrusted;iWinTrusted;c:\program files\iWin Games\iWinTrusted.exe [7/9/2009 4:21 PM 78104]
R2 mrtRate;mrtRate;c:\windows\SYSTEM32\DRIVERS\MrtRate.sys [5/25/2005 9:11 AM 34916]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe [4/28/2010 8:41 PM 117640]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/22/2007 1:00 PM 24652]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/26/2010 4:00 AM 102448]
S2 gupdate1ca06755eda3c02;Google Update Service (gupdate1ca06755eda3c02);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
S2 srserviceShellHWDetection;System Restore Service srserviceShellHWDetection;c:\windows\system32\ACTMOVIEe.exe srv --> c:\windows\system32\ACTMOVIEe.exe srv [?]
S3 EraserUtilDrv11010;EraserUtilDrv11010;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11010.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11010.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-09-04 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-05-19 17:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://att.my.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: aflac.com\my
Trusted Zone: turbotax.com
DPF: {4635A474-9AA7-4467-8FA5-FAF329CB593C} - hxxps://ssl5.dealerups.com/v8/DealerUps.cab
DPF: {77DD44BF-551D-4E3C-82CD-D637D5018D3C} - hxxp://www.surveys.com/promptcast/Installs/SURVEYS.COM%20PROMPTCAST%20SETUP.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-09-03 23:48
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"
.
Completion time: 2010-09-04 00:00:57
ComboFix-quarantined-files.txt 2010-09-04 04:00
ComboFix2.txt 2010-09-04 01:03
ComboFix3.txt 2010-09-03 23:30
ComboFix4.txt 2010-09-02 00:41
Pre-Run: 40,122,560,512 bytes free
Post-Run: 40,104,263,680 bytes free
- - End Of File - - F36F2BE51AFCF1F97EE83A22B40E49C9