ComboFix 09-07-19.01 - Torrie 07/19/2009 15:00.3.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.638 [GMT -4:00]
Running from: c:\documents and settings\Torrie\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Torrie\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FILE ::
"c:\windows\3456665.bat"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\3456665.bat
C:\4b5b4d4025c336b9d9cb2cea . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_PXNUWSVV
-------\Service_pxnuwsvv
((((((((((((((((((((((((( Files Created from 2009-06-19 to 2009-07-19 )))))))))))))))))))))))))))))))
.
2009-07-18 04:50 . 2009-07-18 04:50 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-18 04:50 . 2005-08-25 23:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2009-07-18 04:50 . 2009-07-18 04:50 -------- d-----w- c:\program files\SpywareBlaster
2009-07-18 04:18 . 2009-07-03 14:49 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-07-18 04:10 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-18 01:30 . 2009-07-18 02:03 -------- d-----w- c:\documents and settings\Torrie\DoctorWeb
2009-07-17 23:10 . 2009-07-17 23:10 -------- d-s---w- c:\documents and settings\Torrie\UserData
2009-07-12 19:17 . 2009-07-12 19:17 6500 ----a-w- C:\backup.reg
2009-07-12 19:17 . 2009-07-12 19:17 574 ----a-w- C:\cleanup.bat
2009-07-12 19:17 . 2009-07-12 19:17 135168 ----a-w- C:\zip.exe
2009-07-12 18:28 . 2009-07-12 18:28 -------- d--h--w- c:\windows\PIF
2009-07-12 17:53 . 2009-07-12 17:53 152576 ----a-w- c:\documents and settings\Torrie\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-07-12 17:49 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2009-07-12 17:48 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-07-12 17:31 . 2008-04-14 00:12 1306624 -c----w- c:\windows\system32\dllcache\msxml6.dll
2009-07-12 17:31 . 2008-04-13 17:27 79872 -c----w- c:\windows\system32\dllcache\msxml6r.dll
2009-07-12 12:56 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-07-12 12:56 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2009-07-12 12:56 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-07-12 12:56 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-07-12 12:36 . 2009-07-12 12:36 6944624 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aaw2008_upd.exe
2009-07-12 05:24 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-07-12 05:24 . 2009-03-24 20:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-07-12 05:24 . 2009-02-13 16:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-07-12 05:24 . 2009-02-13 16:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-07-12 05:24 . 2009-07-12 05:24 -------- d-----w- c:\program files\Avira
2009-07-12 05:24 . 2009-07-12 05:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-07-12 03:21 . 2009-07-12 03:21 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-07-11 22:14 . 2009-07-11 22:14 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-07-11 20:33 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-11 20:33 . 2009-07-12 01:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-11 20:33 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-11 20:08 . 2009-07-11 20:08 -------- d-----w- c:\documents and settings\Torrie\Application Data\Malwarebytes
2009-07-11 17:13 . 2009-07-11 17:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-11 17:13 . 2009-07-11 17:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-07-11 16:26 . 2004-08-04 10:00 41600 -c--a-w- c:\windows\system32\dllcache\weitekp9.dll
2009-07-11 16:26 . 2004-08-04 10:00 31232 -c--a-w- c:\windows\system32\dllcache\weitekp9.sys
2009-07-11 16:24 . 2001-08-18 02:36 38912 -c--a-w- c:\windows\system32\dllcache\EXCH_ntfsdrv.dll
2009-07-11 16:23 . 2004-08-04 10:00 10129408 -c--a-w- c:\windows\system32\dllcache\hwxkor.dll
2009-07-11 16:22 . 2001-08-18 02:36 45056 -c--a-w- c:\windows\system32\dllcache\EXCH_aqadmin.dll
2009-07-11 16:22 . 2001-08-18 02:36 5632 -c--a-w- c:\windows\system32\dllcache\EXCH_adsiisex.dll
2009-07-11 16:18 . 2004-08-04 10:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2009-07-11 16:06 . 2004-08-04 10:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2009-07-11 16:06 . 2004-08-04 10:00 13312 ----a-w- c:\windows\system32\irclass.dll
2009-07-11 16:06 . 2004-08-04 10:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-07-11 16:06 . 2004-08-04 10:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2009-07-11 16:05 . 2009-07-11 16:05 -------- d-s---w- c:\windows\system32\config\systemprofile\History
2009-07-11 14:52 . 2009-07-19 16:55 -------- d-----w- C:\4b5b4d4025c336b9d9cb2cea
2009-07-11 11:54 . 2009-07-11 11:54 -------- d-----w- c:\windows\msapps
2009-07-11 11:54 . 2009-07-11 11:54 -------- d-----w- c:\windows\dell
2009-06-30 05:04 . 2009-06-30 05:04 -------- d-----w- c:\program files\7-Zip
2009-06-29 17:21 . 2009-06-30 17:10 -------- d-----w- c:\program files\MuseScore 0.9
2009-06-28 20:07 . 2009-06-28 20:07 -------- d-----w- c:\documents and settings\Torrie\Local Settings\Application Data\MusE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-18 21:43 . 2007-06-26 02:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-18 21:14 . 2007-05-04 09:32 44985 ----a-w- c:\windows\system32\nvModes.dat
2009-07-18 05:37 . 2008-04-27 03:48 -------- d-----w- c:\program files\Conference
2009-07-18 04:48 . 2007-06-26 02:14 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-18 04:09 . 2007-06-26 02:26 -------- d-----w- c:\program files\Lavasoft
2009-07-12 19:15 . 2007-05-04 09:58 -------- d-----w- c:\program files\Google
2009-07-12 19:12 . 2007-05-04 09:44 -------- d-----w- c:\program files\Java
2009-07-12 12:42 . 2007-06-26 02:25 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-07-12 12:36 . 2007-06-26 02:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-07-12 01:58 . 2007-06-26 02:33 -------- d-----w- c:\program files\hijack this
2009-07-11 16:17 . 2004-08-10 18:02 23444 ----a-w- c:\windows\system32\emptyregdb.dat
2009-06-28 20:04 . 2009-03-23 02:48 -------- d-----w- c:\program files\Bonjour
2009-06-16 14:36 . 2004-08-04 10:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 10:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:09 . 2004-08-04 10:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-08 21:57 . 2009-05-08 19:17 140839968 ----a-w- c:\documents and settings\All Users\Application Data\Rosetta Stone\Updates\Download\Update.exe
2009-05-07 15:32 . 2004-08-04 10:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:46 . 2006-03-04 03:33 666624 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2004-08-04 10:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-07-15 20:30 . 2009-07-18 04:57 137208 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2008-09-16 20:04 . 2007-11-01 03:44 5642 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-07-18_22.29.27 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-10 17:51 . 2009-07-19 17:02 64490 c:\windows\system32\perfc009.dat
- 2004-08-10 17:51 . 2009-07-18 22:30 64490 c:\windows\system32\perfc009.dat
+ 2004-08-10 17:51 . 2009-07-19 17:02 405024 c:\windows\system32\perfh009.dat
- 2004-08-10 17:51 . 2009-07-18 22:30 405024 c:\windows\system32\perfh009.dat
.
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.638 [GMT -4:00]
Running from: c:\documents and settings\Torrie\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Torrie\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FILE ::
"c:\windows\3456665.bat"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\3456665.bat
C:\4b5b4d4025c336b9d9cb2cea . . . . failed to delete
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_PXNUWSVV
-------\Service_pxnuwsvv
((((((((((((((((((((((((( Files Created from 2009-06-19 to 2009-07-19 )))))))))))))))))))))))))))))))
.
2009-07-18 04:50 . 2009-07-18 04:50 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-18 04:50 . 2005-08-25 23:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2009-07-18 04:50 . 2009-07-18 04:50 -------- d-----w- c:\program files\SpywareBlaster
2009-07-18 04:18 . 2009-07-03 14:49 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-07-18 04:10 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-18 01:30 . 2009-07-18 02:03 -------- d-----w- c:\documents and settings\Torrie\DoctorWeb
2009-07-17 23:10 . 2009-07-17 23:10 -------- d-s---w- c:\documents and settings\Torrie\UserData
2009-07-12 19:17 . 2009-07-12 19:17 6500 ----a-w- C:\backup.reg
2009-07-12 19:17 . 2009-07-12 19:17 574 ----a-w- C:\cleanup.bat
2009-07-12 19:17 . 2009-07-12 19:17 135168 ----a-w- C:\zip.exe
2009-07-12 18:28 . 2009-07-12 18:28 -------- d--h--w- c:\windows\PIF
2009-07-12 17:53 . 2009-07-12 17:53 152576 ----a-w- c:\documents and settings\Torrie\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-07-12 17:49 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2009-07-12 17:48 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-07-12 17:31 . 2008-04-14 00:12 1306624 -c----w- c:\windows\system32\dllcache\msxml6.dll
2009-07-12 17:31 . 2008-04-13 17:27 79872 -c----w- c:\windows\system32\dllcache\msxml6r.dll
2009-07-12 12:56 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-07-12 12:56 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2009-07-12 12:56 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-07-12 12:56 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-07-12 12:36 . 2009-07-12 12:36 6944624 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aaw2008_upd.exe
2009-07-12 05:24 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-07-12 05:24 . 2009-03-24 20:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-07-12 05:24 . 2009-02-13 16:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-07-12 05:24 . 2009-02-13 16:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-07-12 05:24 . 2009-07-12 05:24 -------- d-----w- c:\program files\Avira
2009-07-12 05:24 . 2009-07-12 05:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-07-12 03:21 . 2009-07-12 03:21 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-07-11 22:14 . 2009-07-11 22:14 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-07-11 20:33 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-11 20:33 . 2009-07-12 01:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-11 20:33 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-11 20:08 . 2009-07-11 20:08 -------- d-----w- c:\documents and settings\Torrie\Application Data\Malwarebytes
2009-07-11 17:13 . 2009-07-11 17:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-11 17:13 . 2009-07-11 17:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-07-11 16:26 . 2004-08-04 10:00 41600 -c--a-w- c:\windows\system32\dllcache\weitekp9.dll
2009-07-11 16:26 . 2004-08-04 10:00 31232 -c--a-w- c:\windows\system32\dllcache\weitekp9.sys
2009-07-11 16:24 . 2001-08-18 02:36 38912 -c--a-w- c:\windows\system32\dllcache\EXCH_ntfsdrv.dll
2009-07-11 16:23 . 2004-08-04 10:00 10129408 -c--a-w- c:\windows\system32\dllcache\hwxkor.dll
2009-07-11 16:22 . 2001-08-18 02:36 45056 -c--a-w- c:\windows\system32\dllcache\EXCH_aqadmin.dll
2009-07-11 16:22 . 2001-08-18 02:36 5632 -c--a-w- c:\windows\system32\dllcache\EXCH_adsiisex.dll
2009-07-11 16:18 . 2004-08-04 10:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2009-07-11 16:06 . 2004-08-04 10:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2009-07-11 16:06 . 2004-08-04 10:00 13312 ----a-w- c:\windows\system32\irclass.dll
2009-07-11 16:06 . 2004-08-04 10:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-07-11 16:06 . 2004-08-04 10:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2009-07-11 16:05 . 2009-07-11 16:05 -------- d-s---w- c:\windows\system32\config\systemprofile\History
2009-07-11 14:52 . 2009-07-19 16:55 -------- d-----w- C:\4b5b4d4025c336b9d9cb2cea
2009-07-11 11:54 . 2009-07-11 11:54 -------- d-----w- c:\windows\msapps
2009-07-11 11:54 . 2009-07-11 11:54 -------- d-----w- c:\windows\dell
2009-06-30 05:04 . 2009-06-30 05:04 -------- d-----w- c:\program files\7-Zip
2009-06-29 17:21 . 2009-06-30 17:10 -------- d-----w- c:\program files\MuseScore 0.9
2009-06-28 20:07 . 2009-06-28 20:07 -------- d-----w- c:\documents and settings\Torrie\Local Settings\Application Data\MusE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-18 21:43 . 2007-06-26 02:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-18 21:14 . 2007-05-04 09:32 44985 ----a-w- c:\windows\system32\nvModes.dat
2009-07-18 05:37 . 2008-04-27 03:48 -------- d-----w- c:\program files\Conference
2009-07-18 04:48 . 2007-06-26 02:14 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-18 04:09 . 2007-06-26 02:26 -------- d-----w- c:\program files\Lavasoft
2009-07-12 19:15 . 2007-05-04 09:58 -------- d-----w- c:\program files\Google
2009-07-12 19:12 . 2007-05-04 09:44 -------- d-----w- c:\program files\Java
2009-07-12 12:42 . 2007-06-26 02:25 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-07-12 12:36 . 2007-06-26 02:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-07-12 01:58 . 2007-06-26 02:33 -------- d-----w- c:\program files\hijack this
2009-07-11 16:17 . 2004-08-10 18:02 23444 ----a-w- c:\windows\system32\emptyregdb.dat
2009-06-28 20:04 . 2009-03-23 02:48 -------- d-----w- c:\program files\Bonjour
2009-06-16 14:36 . 2004-08-04 10:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 10:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:09 . 2004-08-04 10:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-08 21:57 . 2009-05-08 19:17 140839968 ----a-w- c:\documents and settings\All Users\Application Data\Rosetta Stone\Updates\Download\Update.exe
2009-05-07 15:32 . 2004-08-04 10:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:46 . 2006-03-04 03:33 666624 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2004-08-04 10:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-07-15 20:30 . 2009-07-18 04:57 137208 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2008-09-16 20:04 . 2007-11-01 03:44 5642 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-07-18_22.29.27 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-10 17:51 . 2009-07-19 17:02 64490 c:\windows\system32\perfc009.dat
- 2004-08-10 17:51 . 2009-07-18 22:30 64490 c:\windows\system32\perfc009.dat
+ 2004-08-10 17:51 . 2009-07-19 17:02 405024 c:\windows\system32\perfh009.dat
- 2004-08-10 17:51 . 2009-07-18 22:30 405024 c:\windows\system32\perfh009.dat
.