Ok. Cryptsvc would not stop in the command line, but I was able to stop it with the task manager and then put in the rest of the command lines you said. The log is below.
ComboFix 09-11-29.06 - Trevor White 12/01/2009 20:40.2.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1790.1162 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Trevor White\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\wbem\Performance\WmiApRpl_new.ini
.
((((((((((((((((((((((((( Files Created from 2009-11-02 to 2009-12-02 )))))))))))))))))))))))))))))))
.
2009-12-02 02:50 . 2009-12-02 02:51 ——– d—–w- c:\users\Trevor White\AppData\Local\temp
2009-12-02 02:50 . 2009-12-02 02:50 ——– d—–w- c:\users\yfl\AppData\Local\temp
2009-12-02 02:50 . 2009-12-02 02:50 ——– d—–w- c:\users\Public\AppData\Local\temp
2009-12-02 02:50 . 2009-12-02 02:50 ——– d—–w- c:\users\Mom and Rick\AppData\Local\temp
2009-12-02 02:50 . 2009-12-02 02:50 ——– d—–w- c:\users\Guest\AppData\Local\temp
2009-12-02 02:50 . 2009-12-02 02:50 ——– d—–w- c:\users\Guest.TrevorWhite-PC\AppData\Local\temp
2009-12-02 02:50 . 2009-12-02 02:50 ——– d—–w- c:\users\Default\AppData\Local\temp
2009-12-02 02:38 . 2009-12-02 02:39 12288 d—–w- c:\windows\system32\catroot2
2009-11-17 01:48 . 2009-11-17 01:48 ——– d—–w- c:\users\Trevor White\AppData\Local\Adobe
2009-11-17 01:44 . 2009-11-17 01:44 ——– d—–w- c:\users\Trevor White\AppData\Local\Apple
2009-11-10 03:47 . 2009-11-10 03:47 ——– d—–w- c:\users\Trevor White\AppData\Roaming\Malwarebytes
2009-11-10 03:47 . 2009-04-06 21:32 15504 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-10 03:47 . 2009-04-06 21:32 38496 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-10 03:47 . 2009-11-16 02:08 4096 d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-11-10 03:47 . 2009-11-10 03:47 ——– d—–w- c:\programdata\Malwarebytes
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-17 02:11 . 2009-03-28 20:41 4096 d—–w- c:\program files\Project64 1.6
2009-11-10 03:12 . 2009-10-28 03:02 8192 d—–w- c:\program files\Steam
2009-11-10 03:07 . 2009-03-22 21:40 119296 —-a-w- c:\windows\system32\zlib.dll
2009-10-31 16:33 . 2008-10-28 21:00 4096 d–h–w- c:\program files\InstallShield Installation Information
2009-10-29 20:59 . 2009-10-29 21:00 87328 —-a-w- c:\windows\system32\bcmwlcoi.dll
2009-10-29 20:59 . 2009-10-29 21:00 1122664 —-a-w- c:\windows\system32\WdfCoInstaller01007.dll
2009-10-29 20:59 . 2009-10-29 21:00 3522560 —-a-w- c:\windows\system32\bcmihvsrv.dll
2009-10-29 20:59 . 2009-10-29 21:00 3182592 —-a-w- c:\windows\system32\bcmihvui.dll
2009-10-28 03:02 . 2009-10-28 03:02 ——– d—–w- c:\program files\Common Files\Steam
2009-10-19 12:07 . 2009-03-18 17:11 ——– d—–w- c:\users\Trevor White\AppData\Roaming\CyberLink
2009-10-13 21:06 . 2009-03-07 23:40 ——– d—–w- c:\program files\Common Files\Blizzard Entertainment
2009-10-12 23:18 . 2009-10-12 23:18 ——– d—–w- c:\program files\MySQL
2009-10-12 22:32 . 2009-03-22 07:16 4096 d—–w- c:\users\Trevor White\AppData\Roaming\Any Video Converter
2009-10-12 22:28 . 2006-11-02 12:35 4096 d—–w- c:\program files\Microsoft Games
.
((((((((((((((((((((((((((((( SnapShot@2009-12-01_02.42.27 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-21 01:58 . 2009-11-30 11:26 51280 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-01-21 01:58 . 2009-12-02 02:11 51280 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:02 . 2009-12-02 02:13 72374 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-28 23:32 . 2009-12-02 02:13 10594 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1435818145-1775016462-1809947513-1000_UserData.bin
- 2009-02-28 23:32 . 2009-11-30 11:29 10594 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1435818145-1775016462-1809947513-1000_UserData.bin
- 2009-02-28 23:29 . 2009-11-30 23:02 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-28 23:29 . 2009-12-02 02:22 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-02-28 23:29 . 2009-12-02 02:22 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-02-28 23:29 . 2009-11-30 23:02 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-02-28 23:29 . 2009-12-02 02:22 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-02-28 23:29 . 2009-11-30 23:02 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-02 02:07 . 2009-12-02 02:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-01 02:08 . 2009-12-01 02:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-01 02:08 . 2009-12-01 02:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-12-02 02:07 . 2009-12-02 02:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-12-01 03:14 595446 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-11-30 12:02 595446 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-11-30 12:02 101144 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-12-01 03:14 101144 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-21 2153472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-25 988512]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-13 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-15 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 52256]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-01 198160]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-18 13580832]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-18 92704]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-05-20 6144000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv.exe" - c:\windows\System32\grpconv.exe [2006-11-02 16896]
c:\users\Trevor White\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1435818145-1775016462-1809947513-1000]
"EnableNotificationsRef"=dword:00000003
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20090427.001\IDSvix86.sys [4/29/2009 11:59 AM 272432]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [1/11/2008 9:32 PM 23888]
S3 DX4323;Dynex Wireless N USB Adapter Driver;c:\windows\System32\drivers\DX4323.sys [10/27/2009 9:56 PM 483200]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\System32\drivers\motccgp.sys [8/21/2008 10:49 PM 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\System32\drivers\motccgpfl.sys [8/21/2008 10:49 PM 8320]
S3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2/19/2009 11:31 AM 41008]
S3 WUSB54GSCv2.NTx86;Compact Wireless-G USB Network Adapter with SpeedBooster Service;c:\windows\System32\drivers\WUSB54GSCV2_X86.sys [10/31/2009 10:33 AM 238072]
S4 ETService;Empowering Technology Service;c:\program files\EMACHINES\eMachines Recovery Management\Service\ETService.exe [10/10/2007 1:22 AM 24576]
S4 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/17/2008 2:37 PM 149352]
S4 WOW;WOW;"c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt" –defaults-file="c:\program files\MySQL\MySQL Server 5.0\my.ini" WOW –> c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt [?]
— Other Services/Drivers In Memory —
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&s=1&o=vb32&d=1007&m=el1200-07w
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: playrequiem.com\www
Trusted Zone: pornhub.com\www
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-01 20:51
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
c:\users\TREVOR~1\AppData\Local\Temp\catchme.dll 53248 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\WOW]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" –defaults-file=\"c:\program files\MySQL\MySQL Server 5.0\my.ini\" WOW"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2009-12-01 20:54
ComboFix-quarantined-files.txt 2009-12-02 02:54
ComboFix2.txt 2009-12-01 02:45
Pre-Run: 32,976,470,016 bytes free
Post-Run: 34,366,722,048 bytes free
- - End Of File - - EF051E5106927D48E95FC0080898D086