Here is my ComboFix log:
ComboFix 09-12-23.06 - A Str8 nOOb 12/25/2009 9:40.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.552 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\A Str8 nOOb\Application Data\inst.exe
c:\windows\system32\_000004_.tmp.dll
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
c:\windows\system32\_000013_.tmp.dll
c:\windows\system32\_000016_.tmp.dll
c:\windows\system32\_000017_.tmp.dll
c:\windows\system32\_000018_.tmp.dll
F:\autorun.inf
F:\install.exe
.
((((((((((((((((((((((((( Files Created from 2009-11-25 to 2009-12-25 )))))))))))))))))))))))))))))))
.
2016-04-12 20:24 . 2016-04-12 20:24 ——– d—–w- c:\documents and settings\A Str8 nOOb\Application Data\Canneverbe_Limited
2016-04-12 20:24 . 2016-04-12 20:24 ——– d—–w- c:\documents and settings\All Users\Application Data\Canneverbe Limited
2016-04-12 04:56 . 2016-04-12 04:56 ——– d—–w- c:\documents and settings\A Str8 nOOb\Application Data\Webroot
2016-04-12 04:56 . 2016-04-12 04:56 ——– d—–w- c:\program files\Common Files\Webroot Shared
2016-04-12 04:56 . 2016-04-12 04:56 ——– d—–w- c:\program files\Webroot
2016-04-12 04:56 . 2016-04-12 04:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Webroot
2016-04-12 01:12 . 2016-04-12 00:03 ——– d—–w- c:\documents and settings\Toya Trenise\Application Data\AdobeUM
2016-04-12 01:11 . 2016-04-12 01:11 ——– d—–w- c:\documents and settings\Toya Trenise\Local Settings\Application Data\Adobe
2016-04-12 01:02 . 2016-04-12 01:02 ——– d—–w- c:\program files\Common Files\Adobe
2016-04-12 00:40 . 2016-04-12 00:40 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2016-04-12 00:28 . 2016-04-12 00:28 ——– d—–w- c:\documents and settings\All Users\Application Data\PCSettings
2016-04-12 00:28 . 2016-04-12 00:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2016-04-12 00:19 . 2016-04-12 00:19 ——– d—–w- c:\windows\LMI1AB.tmp
2016-04-12 00:18 . 2016-04-12 00:18 ——– d-sh–w- c:\documents and settings\Toya Trenise\IETldCache
2016-04-12 00:10 . 2007-11-26 19:47 194888 —-a-w- c:\windows\Unwash6.exe
2016-04-12 00:08 . 2016-04-12 00:08 ——– d—–w- c:\program files\Trend Micro
2016-04-12 00:06 . 2009-11-05 06:30 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20091217.002\Scxpx86.dll
2016-04-12 00:06 . 2009-11-05 06:30 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20091217.002\IDSxpx86.dll
2016-04-12 00:06 . 2009-11-05 06:30 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20091217.002\IDSviA64.sys
2016-04-12 00:06 . 2009-11-05 06:30 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20091217.002\IDSvix86.sys
2016-04-12 00:06 . 2009-11-05 06:30 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20091217.002\IDSXpx86.sys
2016-04-12 00:06 . 2009-12-05 04:54 529456 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20091205.001\BHDrvx86.sys
2016-04-12 00:06 . 2009-12-05 04:54 201616 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20091205.001\BHRules.dll
2016-04-12 00:06 . 2009-12-05 04:54 1405840 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20091205.001\BHEngine.dll
2016-04-12 00:06 . 2009-12-05 04:54 668720 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20091205.001\BHDrvx64.sys
2016-04-12 00:06 . 2009-12-05 04:54 610704 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20091205.001\bbRGen.dll
2016-04-12 00:05 . 2016-04-12 00:05 ——– d-sh–w- c:\documents and settings\Toya Trenise\PrivacIE
2016-04-12 00:05 . 2009-11-05 06:30 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\BinHub\Scxpx86.dll
2016-04-12 00:05 . 2009-11-05 06:30 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\BinHub\IDSxpx86.dll
2016-04-12 00:05 . 2009-11-05 06:30 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\BinHub\IDSvix86.sys
2016-04-12 00:05 . 2009-11-05 06:30 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\BinHub\IDSXpx86.sys
2016-04-12 00:05 . 2009-11-05 06:30 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\BinHub\IDSviA64.sys
2016-04-12 00:02 . 2009-10-01 09:19 164216 —-a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\IPSFFPlgn\components\IPSFFPl.dll
2016-04-12 00:02 . 2016-04-12 00:02 ——– d—–w- c:\program files\Common Files\xing shared
2016-04-12 00:02 . 2009-09-29 02:57 7168 —-a-w- c:\windows\system32\drivers\StarOpen.sys
2016-04-12 00:02 . 2016-04-12 00:02 ——– d—–w- c:\program files\CDBurnerXP
2016-04-12 00:02 . 2016-04-12 00:02 152576 —-a-w- c:\documents and settings\A Str8 nOOb\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2016-04-12 00:01 . 2016-04-12 00:01 ——– d—–w- c:\program files\Symantec
2016-04-12 00:01 . 2016-04-12 00:01 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2016-04-12 00:01 . 2016-04-12 00:01 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2016-04-12 00:01 . 2016-04-12 00:01 ——– d—–w- c:\program files\real
2016-04-12 00:01 . 2016-04-12 00:01 79488 —-a-w- c:\documents and settings\A Str8 nOOb\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2016-04-12 00:01 . 2009-10-05 17:34 929648 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\OCS\hsplayer.dll
2016-04-12 00:01 . 2009-11-07 01:16 893808 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\CLT\cltLMSx.dll
2016-04-12 00:00 . 2016-04-12 00:00 ——– d—–w- c:\documents and settings\Toya Trenise\Local Settings\Application Data\Mozilla
2016-04-12 00:00 . 2016-04-12 00:00 ——– d—–w- c:\windows\system32\drivers\NAV
2016-04-12 00:00 . 2016-04-12 00:00 ——– d—–w- c:\program files\Windows Sidebar
2016-04-12 00:00 . 2016-04-12 00:00 ——– d—–w- c:\program files\Norton AntiVirus
2016-04-12 00:00 . 2007-04-12 19:19 129024 —-a-w- c:\windows\system32\AVERM.dll
2016-04-12 00:00 . 2006-09-26 18:57 28672 —-a-w- c:\windows\system32\AVEQT.dll
2016-04-12 00:00 . 2016-04-12 00:00 ——– d—–w- c:\program files\Allok Video to 3GP Converter
2009-12-25 15:35 . 2009-12-25 15:35 ——– d—–w- c:\documents and settings\A Str8 nOOb\Application Data\Media Player Classic
2009-12-25 15:33 . 2009-08-16 15:08 178176 —-a-w- c:\windows\system32\unrar.dll
2009-12-25 15:33 . 2004-01-25 16:18 217088 —-a-w- c:\windows\system32\yv12vfw.dll
2009-12-25 15:33 . 2009-05-29 21:37 205824 —-a-w- c:\windows\system32\xvidvfw.dll
2009-12-25 15:33 . 2009-05-29 21:31 881664 —-a-w- c:\windows\system32\xvidcore.dll
2009-12-25 15:33 . 2009-12-11 18:00 85504 —-a-w- c:\windows\system32\ff_vfw.dll
2009-12-25 15:33 . 2009-12-25 15:34 ——– d—–w- c:\program files\K-Lite Codec Pack
2009-12-25 15:25 . 2004-08-04 11:00 25600 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-12-25 15:21 . 2009-12-25 15:21 ——– d—–w- c:\program files\Windows Media Connect 2
2009-12-25 15:16 . 2009-12-25 15:18 ——– d—–w- c:\windows\system32\drivers\UMDF
2009-12-25 15:16 . 2009-12-25 15:16 ——– d—–w- c:\windows\system32\LogFiles
2009-12-25 15:15 . 2009-12-25 15:15 ——– d—–w- c:\windows\LastGood
2009-12-25 14:47 . 2009-08-01 16:16 6256600 —ha-w- c:\documents and settings\A Str8 nOOb\Application Data\mjusbsp\in00000\setup.exe
2009-12-25 14:46 . 2009-08-01 16:12 728600 —ha-w- c:\documents and settings\A Str8 nOOb\Application Data\mjusbsp\ar00000\install.exe
2009-12-25 08:20 . 2016-04-12 00:05 1323568 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20091223.040\NAVEX15.SYS
2009-12-25 08:20 . 2016-04-12 00:05 84912 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20091223.040\NAVENG.SYS
2009-12-25 08:20 . 2016-04-12 00:05 371248 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20091223.040\EECTRL.SYS
2009-12-25 08:20 . 2016-04-12 00:05 2747440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20091223.040\CCERASER.DLL
2009-12-25 08:20 . 2016-04-12 00:05 259440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20091223.040\ECMSVR32.DLL
2009-12-25 08:20 . 2016-04-12 00:05 177520 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20091223.040\NAVENG32.DLL
2009-12-25 08:20 . 2016-04-12 00:05 1647984 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20091223.040\NAVEX32A.DLL
2009-12-25 08:20 . 2016-04-12 00:05 102448 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\VirusDefs\20091223.040\ERASER.SYS
2009-12-24 14:34 . 2009-12-24 14:34 ——– d—–w- c:\documents and settings\A Str8 nOOb\Application Data\Malwarebytes
2009-12-24 14:34 . 2009-12-03 22:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-24 14:34 . 2009-12-24 14:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-24 14:34 . 2009-12-24 14:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-24 14:34 . 2009-12-03 22:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-20 21:05 . 2009-12-20 21:05 ——– d-sh–w- c:\documents and settings\A Str8 nOOb\IETldCache
2009-12-20 20:59 . 2009-10-29 07:45 12800 ——w- c:\windows\system32\dllcache\xpshims.dll
2009-12-20 20:59 . 2009-10-29 07:45 594432 ——w- c:\windows\system32\dllcache\msfeeds.dll
2009-12-20 20:59 . 2009-10-29 07:45 55296 ——w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-12-20 20:59 . 2009-10-29 07:45 246272 ——w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-20 20:59 . 2009-10-29 07:45 1985536 ——w- c:\windows\system32\dllcache\iertutil.dll
2009-12-20 20:59 . 2009-10-29 07:45 11069952 ——w- c:\windows\system32\dllcache\ieframe.dll
2009-12-20 20:59 . 2009-12-20 21:00 ——– d—–w- c:\windows\ie8updates
2009-12-20 20:59 . 2009-10-02 04:44 92160 ——w- c:\windows\system32\dllcache\iecompat.dll
2009-12-20 20:57 . 2009-12-20 20:59 ——– dc-h–w- c:\windows\ie8
2009-12-20 20:53 . 2009-12-20 20:53 388096 —-a-r- c:\documents and settings\A Str8 nOOb\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2009-12-20 20:53 . 2009-12-20 20:53 ——– d—–w- c:\program files\TrendMicro
2009-12-20 18:00 . 2009-12-20 18:00 ——– d—–w- c:\documents and settings\A Str8 nOOb\Local Settings\Application Data\tjnet
2009-12-20 06:20 . 2003-03-09 20:31 94208 —-a-r- c:\windows\system32\HPZipt12.dll
2009-12-20 06:20 . 2003-03-09 20:31 65795 —-a-r- c:\windows\system32\HPZipm12.exe
2009-12-20 06:20 . 2003-03-09 20:31 61699 —-a-r- c:\windows\system32\HPZinw12.exe
2009-12-20 06:20 . 2003-03-09 20:31 57344 —-a-r- c:\windows\system32\HPZisn12.dll
2009-12-20 06:20 . 2003-03-09 20:31 167936 —-a-r- c:\windows\system32\HPZipr12.dll
2009-12-20 06:20 . 2003-03-09 20:31 16080 —-a-r- c:\windows\system32\drivers\HPZipr12.sys
2009-12-20 06:20 . 2003-03-09 20:31 233528 —-a-r- c:\windows\system32\HPZidr12.dll
2009-12-20 06:20 . 2003-03-09 20:31 51024 —-a-r- c:\windows\system32\drivers\hpzid412.sys
2009-12-20 06:19 . 2003-03-09 20:31 21456 —-a-r- c:\windows\system32\drivers\HPZius12.sys
2009-12-20 06:19 . 2004-08-04 05:01 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2009-12-20 06:19 . 2004-08-04 05:01 25856 —-a-w- c:\windows\system32\dllcache\usbprint.sys
2009-12-20 06:19 . 2004-08-04 04:58 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2009-12-20 06:19 . 2004-08-04 04:58 15104 —-a-w- c:\windows\system32\dllcache\usbscan.sys
2009-12-20 06:17 . 2009-12-20 06:17 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2009-12-20 06:14 . 2009-12-19 18:23 ——– d—–w- c:\program files\Hewlett-Packard
2009-12-20 06:11 . 2009-12-19 18:24 20454 —-a-w- c:\windows\hpoins01.dat
2009-12-20 06:11 . 2003-04-06 03:24 16618 ——w- c:\windows\hpomdl01.dat
2009-12-20 06:08 . 2007-04-09 19:23 28552 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2009-12-20 06:08 . 2007-04-09 19:23 28040 —-a-w- c:\windows\system32\mdimon.dll
2009-12-20 06:06 . 2009-12-20 06:06 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-12-20 06:05 . 2009-12-20 06:06 ——– d—–w- c:\windows\SHELLNEW
2009-12-20 06:05 . 2009-12-20 06:05 ——– d—–w- c:\program files\Microsoft.NET
2009-12-20 06:03 . 2009-12-20 06:03 ——– d—–r- C:\MSOCache
2009-12-20 05:16 . 2009-12-20 05:16 92832 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-20 05:13 . 2009-12-20 05:13 ——– d—–w- c:\windows\system32\XPSViewer
2009-12-20 05:13 . 2009-12-20 05:13 ——– d—–w- c:\program files\MSBuild
2009-12-20 05:13 . 2009-12-20 05:13 ——– d—–w- c:\program files\Reference Assemblies
2009-12-20 05:13 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2009-12-20 05:12 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-12-20 05:12 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-12-20 05:12 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-12-20 05:12 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-12-20 05:12 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2009-12-20 05:12 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-04-12 00:28 . 2009-12-18 18:39 ——– d—–w- c:\program files\NortonInstaller
2016-04-12 00:04 . 2006-01-26 02:08 ——– d—–w- c:\program files\Common Files\Symantec Shared
2016-04-12 00:03 . 2006-01-26 02:02 ——– d—–w- c:\program files\Common Files\Real
2016-04-12 00:01 . 2016-04-12 00:01 805 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2016-04-12 00:01 . 2016-04-12 00:01 7443 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2016-04-12 00:01 . 2006-01-26 02:02 348160 —-a-w- c:\windows\system32\msvcr71.dll
2009-12-25 15:04 . 2009-12-18 18:43 ——– d—–w- c:\documents and settings\A Str8 nOOb\Application Data\Vso
2009-12-20 04:51 . 2006-01-26 02:03 ——– d—–w- c:\program files\Common Files\Corel
2009-12-19 15:06 . 2009-12-18 18:46 ——– d—–w- c:\program files\Jewel Quest Solitaire
2009-12-18 18:43 . 2009-12-18 18:43 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-12-18 18:43 . 2009-12-18 18:43 47360 —-a-w- c:\documents and settings\A Str8 nOOb\Application Data\pcouffin.sys
2009-12-18 18:43 . 2009-12-18 18:43 47360 —-a-w- c:\documents and settings\A Str8 nOOb\Application Data\pcouffin.sys
2009-12-18 18:43 . 2009-12-18 18:43 ——– d—–w- c:\program files\VSO
2009-12-18 18:29 . 2006-01-26 02:01 ——– d—–w- c:\program files\Sonic
2009-12-18 18:29 . 2006-01-26 02:01 ——– d—–w- c:\program files\Common Files\Sonic Shared
2009-12-18 18:20 . 2006-01-26 01:59 ——– d—–w- c:\program files\MUSICMATCH
2009-12-18 18:15 . 2006-01-26 02:01 ——– d—–w- c:\program files\Common Files\AOL
2009-12-18 18:15 . 2006-01-26 02:02 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2009-10-29 07:45 . 2004-08-10 18:51 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 05:48 . 2009-10-29 05:48 662016 —-a-w- c:\windows\system32\SET984.tmp
2009-10-29 05:48 . 2009-10-29 05:48 624640 —-a-w- c:\windows\system32\SET985.tmp
2009-10-29 05:48 . 2009-10-29 05:48 449024 —-a-w- c:\windows\system32\SET98C.tmp
2009-10-29 05:48 . 2009-10-29 05:48 1506304 —-a-w- c:\windows\system32\SET988.tmp
2009-10-29 05:48 . 2009-10-29 05:48 357888 —-a-w- c:\windows\system32\SET992.tmp
2009-10-29 05:48 . 2009-10-29 05:48 3063296 —-a-w- c:\windows\system32\SET98D.tmp
2009-10-29 05:48 . 2009-10-29 05:48 205312 —-a-w- c:\windows\system32\SET991.tmp
2009-10-29 05:48 . 2009-10-29 05:48 1023488 —-a-w- c:\windows\system32\SET995.tmp
2009-10-27 10:45 . 2009-10-27 10:45 352768 —-a-w- c:\windows\system32\SET997.tmp
2009-10-13 10:53 . 2009-10-13 10:53 266752 —-a-w- c:\windows\system32\SET932.tmp
2009-10-13 10:53 . 2004-08-10 18:51 266752 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:54 . 2009-10-12 13:54 69632 —-a-w- c:\windows\system32\SETAA2.tmp
2009-10-12 13:54 . 2009-10-12 13:54 112128 —-a-w- c:\windows\system32\SETAA1.tmp
2009-10-12 13:54 . 2004-08-10 18:51 69632 —-a-w- c:\windows\system32\raschap.dll
2009-10-12 13:54 . 2004-08-10 18:51 112128 —-a-w- c:\windows\system32\rastls.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2005-05-15 332800]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"cdloader"="c:\documents and settings\A Str8 nOOb\Application Data\mjusbsp\cdloader2.exe" [2009-08-01 50520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-15 1404928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-06 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-06 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-06 114688]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 32881]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-26 98304]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 6\MediaDetect.exe" [2005-08-31 106496]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2016-04-12 198160]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
hp psc 2000 Series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2003-4-6 323646]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-6 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NAV\1101000.013\SymDS.sys [4/11/2016 6:01 PM 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1101000.013\SymEFA.sys [4/11/2016 6:01 PM 171056]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\BASHDefs\20091205.001\BHDrvx86.sys [4/11/2016 6:06 PM 529456]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1101000.013\cchpx86.sys [4/11/2016 6:01 PM 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NAV\1101000.013\Ironx86.sys [4/11/2016 6:01 PM 114736]
R2 NAV;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\17.1.0.19\ccSvcHst.exe [4/11/2016 6:01 PM 126392]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [4/11/2016 6:10 PM 598856]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [12/20/2009 11:12 AM 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\Definitions\IPSDefs\20091217.002\IDSXpx86.sys [4/11/2016 6:06 PM 329592]
— Other Services/Drivers In Memory —
*NewlyCreated* - SDDMI2
*NewlyCreated* - UPNPHOST
*Deregistered* - SDDMI2
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.comcast.net/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\A Str8 nOOb\Application Data\Mozilla\Firefox\Profiles\iqb89usu.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.1.0.19\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
.
- - - - ORPHANS REMOVED - - - -
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-25 09:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAV]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\17.1.0.19\ccSvcHst.exe\" /s \"NAV\" /m \"c:\program files\Norton AntiVirus\Engine\17.1.0.19\diMaster.dll\" /prefetch:1"
.
Completion time: 2009-12-25 09:49:39
ComboFix-quarantined-files.txt 2009-12-25 15:49
Pre-Run: 62,097,895,424 bytes free
Post-Run: 62,065,340,416 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 46192FB6233226DDDAE01D5F0919697C
And here is my latest HyjackThis Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:53:10 AM, on 12/25/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\Engine\17.1.0.19\ccSvcHst.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Norton AntiVirus\Engine\17.1.0.19\ccSvcHst.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\17.1.0.19\IPSBHO.DLL
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\A Str8 nOOb\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Norton AntiVirus (NAV) - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\17.1.0.19\ccSvcHst.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
–
End of file - 5470 bytes
I have restarted my pc several times and the clock doesn't jump to 2016 and it is running quicker too like it is new…I have no probs in those regards…