Hello,
I'm sending the combfix in 2 parts.
ComboFix 08-12-01.03 - john 2008-12-03 18:22:04.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1228 [GMT -5:00]
Running from: c:\users\john\Desktop\ComboFix.exe
Command switches used :: c:\users\john\Desktop\CFscript.txt
* Created a new restore point
FILE ::
c:\windows\System32\TDSSfopt.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\System32\TDSSfopt.dll
.
((((((((((((((((((((((((( Files Created from 2008-11-03 to 2008-12-03 )))))))))))))))))))))))))))))))
.
2008-12-01 04:30 . 2008-12-01 04:32
d-------- c:\users\All Users\Lavasoft
2008-12-01 04:30 . 2008-12-01 04:32 d-------- c:\programdata\Lavasoft
2008-12-01 04:30 . 2008-12-01 04:30 d-------- c:\program files\Lavasoft
2008-12-01 04:29 . 2008-12-01 04:29 d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-01 00:36 . 2008-12-01 00:36 d-------- c:\program files\Panda Security
2008-12-01 00:36 . 2008-06-19 17:24 28,544 --a------ c:\windows\System32\drivers\pavboot.sys
2008-11-27 14:33 . 2008-08-27 22:40 712,704 --a------ c:\windows\System32\WindowsCodecs.dll
2008-11-27 14:33 . 2008-08-27 22:40 425,472 --a------ c:\windows\System32\PhotoMetadataHandler.dll
2008-11-27 14:33 . 2008-08-27 22:40 347,136 --a------ c:\windows\System32\WindowsCodecsExt.dll
2008-11-27 14:33 . 2008-10-21 22:57 241,152 --a------ c:\windows\System32\PortableDeviceApi.dll
2008-11-27 14:32 . 2008-10-21 00:25 1,645,568 --a------ c:\windows\System32\connect.dll
2008-11-27 12:39 . 2008-11-27 12:39 d-------- c:\users\All Users\CanonIJPLM
2008-11-27 12:39 . 2008-11-27 12:39 d-------- c:\programdata\CanonIJPLM
2008-11-27 12:33 . 2008-11-27 12:33 d--h----- c:\users\All Users\CanonBJ
2008-11-27 12:33 . 2008-11-27 12:33 d--h----- c:\programdata\CanonBJ
2008-11-27 12:32 . 2008-11-27 12:32 d--h----- c:\windows\System32\CanonIJ Uninstaller Information
2008-11-27 12:30 . 2008-11-27 12:30 d--h----- c:\program files\CanonBJ
2008-11-27 12:30 . 2008-11-27 12:39 d-------- c:\program files\Canon
2008-11-27 04:24 . 2008-10-16 16:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll
2008-11-27 04:24 . 2008-10-16 15:56 1,524,736 --a------ c:\windows\System32\wucltux.dll
2008-11-27 04:24 . 2008-10-16 16:09 51,224 --a------ c:\windows\System32\wuauclt.exe
2008-11-27 04:24 . 2008-10-16 16:09 43,544 --a------ c:\windows\System32\wups2.dll
2008-11-27 04:23 . 2008-10-16 16:12 561,688 --a------ c:\windows\System32\wuapi.dll
2008-11-27 04:23 . 2008-10-16 15:55 83,456 --a------ c:\windows\System32\wudriver.dll
2008-11-27 04:23 . 2008-10-16 16:08 34,328 --a------ c:\windows\System32\wups.dll
2008-11-27 04:22 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll
2008-11-27 04:22 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe
2008-11-26 19:17 . 2008-11-30 19:28 d-------- c:\program files\Windows Live Safety Center
2008-11-23 05:49 . 2008-11-23 05:49 25,887 --a------ c:\windows\System32\ef6b26db-344d-4ad3-ba24-aca0bdaa999a.cab
2008-11-23 05:49 . 2008-11-23 05:49 19,775 --a------ c:\windows\System32\f04d289f-c60a-422b-8396-6c372047042e.cab
2008-11-23 05:17 . 2008-11-23 05:17 dr------- c:\users\john\Searches
2008-11-23 05:07 . 2008-11-25 03:08 d-------- C:\MGADiagToolOutput
2008-11-23 05:05 . 2008-11-23 05:05 d-------- c:\users\All Users\Office Genuine Advantage
2008-11-23 05:05 . 2008-11-23 05:05 d-------- c:\programdata\Office Genuine Advantage
2008-11-23 04:02 . 2008-11-23 04:02 d-------- c:\users\All Users\Windows Genuine Advantage
2008-11-20 01:10 . 2008-11-20 01:10 d-------- c:\users\john\Documents
2008-11-19 04:18 . 2008-11-19 04:18 0 --a------ c:\windows\ynh.dx
2008-11-15 14:49 . 2008-11-23 04:22 d-------- c:\program files\Flipz4Flash
2008-11-12 04:49 . 2008-09-09 22:40 1,334,272 --a------ c:\windows\System32\msxml6.dll
2008-11-12 04:48 . 2008-08-26 20:05 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-11-12 04:47 . 2008-09-05 00:14 1,191,936 --a------ c:\windows\System32\msxml3.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-03 01:34 --------- d-----w c:\program files\ZipCentral
2008-11-30 11:37 --------- d-----w c:\users\john\AppData\Roaming\Hewlett-Packard
2008-11-30 11:37 --------- d-----w c:\users\john\AppData\Roaming\EbkReader
2008-11-30 11:37 --------- d-----w c:\users\john\AppData\Roaming\Earthlink
2008-11-30 11:37 --------- d-----w c:\users\john\AppData\Roaming\Downloaded Installations
2008-11-30 11:37 --------- d-----w c:\users\john\AppData\Roaming\CyberLink
2008-11-29 14:44 --------- d-----w c:\program files\Google
2008-11-27 11:49 --------- d-----w c:\users\john\AppData\Roaming\uTorrent
2008-11-26 08:53 --------- d-----w c:\program files\Windows Mail
2008-11-26 08:53 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-25 23:02 --------- d-----w c:\program files\Directory Buzz
2008-11-23 17:02 --------- d-----w c:\program files\Norton Internet Security
2008-11-23 16:58 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2008-11-23 16:58 123,952 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2008-11-23 16:58 10,671 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-11-23 16:58 --------- d-----w c:\program files\Symantec
2008-11-22 18:38 737,280 ----a-w c:\windows\iun6002.exe
2008-10-11 01:45 --------- d-----w c:\program files\Directory Buzz2
2008-10-05 14:45 --------- d-----w c:\program files\earthlink totalaccess
2008-10-03 19:14 39,984 ----a-w c:\windows\system32\drivers\symids.sys
2008-10-03 19:14 37,936 ----a-w c:\windows\system32\drivers\symndisv.sys
2008-10-03 19:14 27,696 ----a-w c:\windows\system32\drivers\symredrv.sys
2008-10-03 19:14 187,952 ----a-w c:\windows\system32\drivers\symtdi.sys
2008-10-03 19:14 146,096 ----a-w c:\windows\system32\drivers\symfw.sys
2008-10-03 19:14 12,848 ----a-w c:\windows\system32\drivers\symdns.sys
2008-10-03 19:14 10,804 ----a-w c:\windows\system32\drivers\SymRedir.cat
2008-10-03 19:14 1,358 ----a-w c:\windows\system32\drivers\SymRedir.inf
2008-10-02 03:49 827,392 ----a-w c:\windows\System32\wininet.dll
2008-09-30 21:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
2008-09-18 05:09 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 04:56 147,456 ----a-w c:\windows\System32\Faultrep.dll
2008-09-18 04:56 125,952 ----a-w c:\windows\System32\wersvc.dll
2008-09-18 02:16 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-07-03 22:38 174 --sha-w c:\program files\desktop.ini
2008-04-07 22:15 514 ----a-w c:\users\john\AppData\Roaming\wklnhst.dat
.
((((((((((((((((((((((((((((( snapshot@2008-12-02_21.54.12.69 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-03 02:46:16 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-12-03 23:05:49 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-12-03 02:46:16 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-12-03 23:05:49 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-12-03 02:49:44 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-12-03 23:08:34 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-12-03 02:49:44 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-12-03 23:08:40 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2008-12-03 02:10:48 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-12-03 23:21:16 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-12-03 02:10:48 81,920 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-03 23:21:16 81,920 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-03 02:10:48 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-12-03 23:21:16 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-12-03 02:50:09 10,912 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-111490406-3634019498-3922500362-1000_UserData.bin
+ 2008-12-03 23:08:04 10,936 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-111490406-3634019498-3922500362-1000_UserData.bin
- 2008-12-03 02:50:08 60,020 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-12-03 23:08:04 60,020 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-12-03 02:07:29 44,722 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-12-03 23:08:03 44,746 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.