ComboFix 09-06-20.02 - Mom 06/20/2009 15:07.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2610 [GMT -6:00]
Running from: c:\documents and settings\Mom\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Mom\Desktop\CFScript.txt.txt
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
FILE ::
"c:\windows\jsr468ijdfghfjsw3rw3i6tjag81.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\jsr468ijdfghfjsw3rw3i6tjag81.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_JSR468IJDFGHFJSW3RW3I6TJAG80
-------\Service_jsr468ijdfghfjsw3rw3i6tjag80
((((((((((((((((((((((((( Files Created from 2009-05-20 to 2009-06-20 )))))))))))))))))))))))))))))))
.
2009-06-20 17:18 . 2009-06-20 17:18 404225 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\TMP_UPDATE\update.exe
2009-06-20 17:18 . 2009-06-20 17:18 345345 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\TMP_UPDATE\update.dll
2009-06-20 17:18 . 2009-04-09 16:20 79105 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\TMP_UPDATE\updaterc.dll
2009-06-20 17:18 . 2009-02-27 17:59 8961 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\TMP_UPDATE\updguirc.dll
2009-06-20 17:18 . 2009-02-24 19:16 117505 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\TMP_UPDATE\updgui.dll
2009-06-20 17:18 . 2009-02-13 22:01 79105 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\TMP_UPDATE\updext.dll
2009-06-20 17:18 . 2008-12-05 17:32 126721 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\TMP_UPDATE\scewxmlw.dll
2009-06-20 02:13 . 2009-03-30 16:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-20 02:13 . 2009-03-24 22:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-20 02:13 . 2009-02-13 18:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-06-20 02:13 . 2009-02-13 18:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-06-20 02:13 . 2009-06-20 02:13 -------- d-----w- c:\program files\Avira
2009-06-20 02:13 . 2009-06-20 02:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-06-20 01:04 . 2009-06-17 17:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-20 01:04 . 2009-06-20 01:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malwar
2009-06-20 01:02 . 2009-06-20 01:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-20 01:02 . 2009-06-17 17:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-20 00:28 . 2009-06-20 01:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-20 00:25 . 2009-06-20 00:25 -------- d-----w- c:\documents and settings\Mom\Application Data\MSN6
2009-06-20 00:25 . 2009-06-20 00:25 -------- d-----w- c:\documents and settings\All Users\Application Data\MSN6
2009-06-19 22:57 . 2009-06-19 22:57 -------- d-----w- c:\documents and settings\Mom\Application Data\BitZipper
2009-06-19 22:16 . 2006-05-24 00:04 110592 ----a-w- c:\documents and settings\Mom\Application Data\U3\temp\cleanup.exe
2009-06-19 22:00 . 2009-06-19 22:16 -------- d-----w- c:\documents and settings\Mom\Application Data\U3
2009-06-19 21:18 . 2009-06-19 21:18 -------- d-----w- c:\documents and settings\Mom\Local Settings\Application Data\AIM Toolbar
2009-06-19 20:13 . 2009-06-19 20:13 -------- d-----w- c:\documents and settings\Antonio\Local Settings\Application Data\AIM Toolbar
2009-06-18 19:39 . 2009-06-18 19:39 -------- d-----w- c:\program files\Common Files\Software Update Utility
2009-06-18 19:39 . 2009-06-18 19:39 -------- d-----w- c:\program files\AIM Toolbar
2009-06-18 19:39 . 2009-06-18 19:39 -------- d-----w- c:\documents and settings\All Users\Application Data\AIM Toolbar
2009-06-18 19:39 . 2009-06-18 19:39 -------- d-----w- c:\documents and settings\All Users\Application Data\acccore
2009-06-16 14:33 . 2009-06-16 14:33 -------- d-----w- c:\windows\system32\Adobe
2009-06-16 14:30 . 2009-06-16 14:30 -------- d-----w- c:\documents and settings\Antonio\Application Data\BitZipper
2009-06-16 14:30 . 2009-06-16 14:30 -------- d-----w- c:\program files\BitZipper
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-20 21:09 . 2004-09-12 21:19 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000004-00000000-00000001-00001102-00000004-10031102}.dat
2009-06-20 21:09 . 2004-09-12 21:19 288 ----a-w- c:\windows\system32\DVCState-{00000004-00000000-00000001-00001102-00000004-10031102}.dat
2009-06-19 21:58 . 2007-04-19 08:02 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-19 20:29 . 2007-02-04 04:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-19 17:39 . 2004-10-30 19:38 -------- d-----w- c:\program files\Warcraft III
2009-06-18 19:39 . 2006-12-16 23:17 -------- d-----w- c:\program files\AIM6
2009-06-18 19:39 . 2004-10-12 02:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-05-17 00:25 . 2008-03-07 05:50 -------- d-----w- c:\program files\Steam
2009-05-17 00:12 . 2009-05-17 00:10 -------- d-----w- c:\documents and settings\Antonio\Application Data\dota_allstars
2009-05-17 00:10 . 2009-05-17 00:10 -------- d-----w- c:\documents and settings\Antonio\Application Data\dota-allstars.71E01812711E1682B196CE418CDA466F24682743.1
2009-05-17 00:07 . 2009-05-17 00:07 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-05-17 00:07 . 2009-05-17 00:10 38208 ----a-w- c:\documents and settings\Antonio\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe2009-05-13 12:03 . 2009-05-13 12:03 -------- d-----w- c:\program files\Microsoft
2009-05-13 12:02 . 2004-09-12 21:12 -------- d-----w- c:\program files\Java
2009-05-13 12:00 . 2009-05-13 12:00 152576 ----a-w- c:\documents and settings\Antonio\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-12 01:52 . 2008-03-29 02:30 -------- d-----w- c:\documents and settings\Antonio\Application Data\LimeWire
2009-05-10 17:59 . 2009-05-10 17:59 -------- d-----w- c:\program files\uTorrent
2009-05-07 15:32 . 2004-03-19 22:38 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-07 03:15 . 2009-05-07 03:06 -------- d-----w- c:\program files\Coupons
2009-05-06 18:11 . 2009-05-06 18:11 69120 ----a-w- c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\aimtbres.dll
2009-04-30 02:27 . 2008-05-07 12:59 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-04-29 04:56 . 2005-06-18 05:49 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2005-12-10 01:21 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-22 23:48 . 2004-10-30 20:11 69025 ----a-w- c:\windows\War3Unin.dat
2009-04-19 11:54 . 2004-03-20 17:57 88611 ----a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-04-17 12:26 . 2003-09-25 14:35 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-03-06 02:16 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-09 06:45 . 2009-04-19 13:26 2602736 -c--a-w- c:\documents and settings\All Users\Application Data\{1E77E486-38CF-4688-B1E4-B86D08856D09}\Impulse_setup.exe
2009-04-07 16:48 . 2009-04-19 13:25 9728 -c--a-w- c:\documents and settings\All Users\Application Data\{1E77E486-38CF-4688-B1E4-B86D08856D09}\OFFLINE\86D01CB6\597810BF\DeElevator64.dll
2009-04-07 16:48 . 2009-04-19 13:25 323584 -c--a-w- c:\documents and settings\All Users\Application Data\{1E77E486-38CF-4688-B1E4-B86D08856D09}\OFFLINE\86D01CB6\757C30BC\ImpulseNow.exe
2009-04-06 22:19 . 2009-04-19 13:25 587120 -c--a-w- c:\documents and settings\All Users\Application Data\{1E77E486-38CF-4688-B1E4-B86D08856D09}\OFFLINE\86D01CB6\12FD35EB\SDC.dll
2009-04-06 22:19 . 2009-04-19 13:25 9072 -c--a-w- c:\documents and settings\All Users\Application Data\{1E77E486-38CF-4688-B1E4-B86D08856D09}\OFFLINE\86D01CB6\7A63466D\Sd.Irc.resources.dll
2009-03-27 14:20 . 2009-04-19 13:25 616696 -c--a-w- c:\documents and settings\All Users\Application Data\{1E77E486-38CF-4688-B1E4-B86D08856D09}\OFFLINE\86D01CB6\597810BF\7z.dll
2007-04-13 20:58 . 2004-12-06 02:33 848 --sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
.
(((((((((((((((((((((((((((((
SnapShot@2009-06-20_20.22.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-20 21:10 . 2009-06-20 21:10 16384 c:\windows\temp\Perflib_Perfdata_250.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{474597C5-AB09-49d6-A4D5-2E8D7341384E}]
2008-02-07 10:54 398768 ----a-w- c:\program files\iMesh Applications\iMesh MediaBar\iMeshIEHelper.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"mmtask"="c:\program files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe" [2004-04-19 53248]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-04 111936]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"nwiz"="nwiz.exe" - c:\windows\SYSTEM32\nwiz.exe [2008-09-17 1657376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Symantec NetDriver Warning"="c:\progra~1\SYMNET~1\SNDWarn.exe" [2004-10-29 218232]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\SYSTEM32\narrator.exe [2008-04-14 53760]
c:\documents and settings\Antonio\Start Menu\Programs\Startup\
ImpulseNow.lnk - c:\program files\Stardock\Impulse\Now\ImpulseNow.exe [2009-4-7 356352]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup