ComboFix 09-07-31.04 - sarah g 08/06/2009 11:41.5.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2037.1533 [GMT -4:00]
Running from: c:\documents and settings\sarah g.SARAH.000\Desktop\Combo-fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\sarah g.SARAH.000\Application Data\02000000ec975e43649C.manifest
c:\documents and settings\sarah g.SARAH.000\Application Data\02000000ec975e43649O.manifest
c:\documents and settings\sarah g.SARAH.000\Application Data\02000000ec975e43649P.manifest
c:\documents and settings\sarah g.SARAH.000\Application Data\02000000ec975e43649S.manifest
c:\documents and settings\sarah g.SARAH.000\My Documents\winlogon.exe
c:\windows\GnuHashes.ini
c:\windows\system32\__c0015940.dat
c:\windows\system32\__c00F6660.dat
c:\windows\system32\GroupPolicy000.dat
c:\windows\system32\SystemX86
c:\windows\system32\SystemX86\245.crack.zip
c:\windows\system32\SystemX86\245.crack.zip.kwd
c:\windows\system32\SystemX86\246.keygen.zip
c:\windows\system32\SystemX86\246.keygen.zip.kwd
c:\windows\system32\SystemX86\247.serial.zip
c:\windows\system32\SystemX86\247.serial.zip.kwd
c:\windows\system32\SystemX86\248.setup.zip
c:\windows\system32\SystemX86\248.setup.zip.kwd
c:\windows\system32\SystemX86\249.music.au
c:\windows\system32\SystemX86\249.music.au.kwd
c:\windows\system32\SystemX86\250.music2.au
c:\windows\system32\SystemX86\250.music2.au.kwd
c:\windows\system32\SystemX86\251.music3.au
c:\windows\system32\SystemX86\251.music3.au.kwd
c:\windows\system32\SystemX86\252.music.snd
c:\windows\system32\SystemX86\252.music.snd.kwd
C:\xcrashdump.dat
.
((((((((((((((((((((((((( Files Created from 2009-07-06 to 2009-08-06 )))))))))))))))))))))))))))))))
.
2009-08-06 15:47 . 2009-08-06 15:47 557 --sha-w- c:\windows\system32\GroupPolicy000.dat
2009-08-06 15:47 . 2009-08-06 15:47 -------- d-sh--w- c:\windows\system32\SystemX86
2009-08-06 00:12 . 2009-08-06 00:25 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-08-05 23:45 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-05 23:45 . 2009-08-05 23:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-05 23:45 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-05 22:18 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2009-08-05 22:18 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-08-05 22:18 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-08-05 22:11 . 2009-08-05 22:11 -------- d-----w- c:\windows\system32\scripting
2009-08-05 22:11 . 2009-08-05 22:11 -------- d-----w- c:\windows\system32\en
2009-08-05 22:11 . 2009-08-05 22:11 -------- d-----w- c:\windows\l2schemas
2009-08-05 22:11 . 2009-08-05 22:11 -------- d-----w- c:\windows\system32\bits
2009-08-05 22:10 . 2009-08-05 22:10 -------- d-----w- c:\windows\ServicePackFiles
2009-08-05 22:06 . 2009-08-05 22:06 -------- d-----w- c:\windows\EHome
2009-08-04 21:52 . 2009-08-04 21:53 -------- d-----w- c:\windows\system32\NtmsData
2009-08-04 21:38 . 2009-08-04 21:38 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2009-07-30 14:15 . 2009-07-30 14:15 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2009-07-30 14:14 . 2009-07-30 14:14 -------- d-----w- c:\program files\Pando Networks
2009-07-30 14:14 . 2009-07-30 14:14 -------- d-----w- C:\users
2009-07-30 14:14 . 2009-07-30 14:14 -------- d-----w- c:\program files\AIM Toolbar
2009-07-30 14:14 . 2009-07-30 14:14 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\AIM Toolbar
2009-07-30 14:14 . 2009-07-30 14:14 -------- d-----w- c:\program files\Opera
2009-07-30 01:21 . 2009-07-30 01:21 -------- d--h--r- c:\documents and settings\sarah g.SARAH.000\Application Data\SecuROM
2009-07-30 01:00 . 2009-07-30 01:00 10134 ----a-r- c:\documents and settings\sarah g.SARAH.000\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-07-30 01:00 . 2009-07-30 00:28 447752 ----a-w- c:\windows\system32\vp6vfw.dll
2009-07-30 01:00 . 2009-07-30 01:00 -------- d-----w- c:\program files\Microsoft WSE
2009-07-30 00:57 . 2006-09-28 20:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2009-07-30 00:57 . 2009-07-30 00:57 -------- d-----w- c:\windows\Logs
2009-07-29 23:48 . 2009-07-29 23:48 -------- d-----w- c:\program files\ESET
2009-07-29 23:21 . 2009-07-29 23:26 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\SITEguard
2009-07-29 23:20 . 2009-07-30 01:09 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\STOPzilla!
2009-07-29 22:29 . 2009-08-01 01:49 -------- d-----w- c:\documents and settings\sarah g.SARAH.000\Application Data\SUPERAntiSpyware.com
2009-07-29 21:09 . 2009-07-29 21:09 -------- d-----w- C:\ProgramData
2009-07-29 21:09 . 2009-07-29 21:09 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Electronic Arts
2009-07-29 21:08 . 2009-07-30 00:46 -------- d-----w- c:\program files\Electronic Arts
2009-07-29 19:53 . 2009-07-29 19:53 120320 ----a-w- c:\windows\system32\icardie32.dll
2009-07-28 14:35 . 2009-07-28 14:35 4096 ----a-w- c:\windows\d3dx.dat
2009-07-28 14:35 . 2009-07-30 14:08 -------- d-----w- c:\program files\Kudos Demo
2009-07-13 19:30 . 2009-08-04 21:26 -------- d-----w- c:\program files\Transparent Windows
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-06 15:47 . 2009-08-06 15:47 518144 --sha-w- c:\windows\system32\3.tmp
2009-08-06 14:03 . 2009-08-06 12:06 117 ----a-w- c:\documents and settings\sarah g.SARAH.000\udpcrawl.tmp
2009-08-06 12:06 . 2009-08-06 12:06 518144 --sha-w- c:\windows\system32\1E.tmp
2009-08-06 10:57 . 2009-08-06 10:57 0 ----a-w- c:\windows\system32\4.tmp
2009-08-06 00:42 . 2008-09-27 16:10 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-08-05 22:13 . 2008-05-16 18:00 77423 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-08-01 01:55 . 2008-05-15 15:02 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-01 01:49 . 2008-05-15 16:22 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-07-30 14:16 . 2008-05-17 22:56 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Viewpoint
2009-07-30 14:14 . 2009-06-27 14:39 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-07-30 14:14 . 2009-06-09 13:38 -------- d-----w- c:\program files\Safari
2009-07-30 14:14 . 2008-05-17 22:55 -------- d-----w- c:\program files\AIM6
2009-07-30 14:14 . 2009-06-09 13:38 -------- d-----w- c:\program files\Bonjour
2009-07-30 14:10 . 2009-06-27 13:41 -------- d-----w- c:\program files\RegGenie
2009-07-30 01:07 . 2009-07-29 23:24 1328 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-07-30 00:46 . 2008-05-10 03:04 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-30 00:11 . 2008-05-15 15:58 -------- d-----w- c:\program files\LabelCommand
2009-07-29 22:49 . 2008-05-22 13:55 12720 ----a-w- c:\documents and settings\sarah g.SARAH.000\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-04 20:45 . 2008-07-29 22:42 -------- d-----w- c:\program files\SIM Edit Tool
2009-06-29 16:12 . 2006-03-04 03:33 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 10:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-04 10:00 17408 ------w- c:\windows\system32\corpol.dll
2009-06-27 14:44 . 2009-06-27 14:44 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-27 14:43 . 2009-06-27 14:43 152576 ----a-w- c:\documents and settings\sarah g.SARAH.000\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-27 14:39 . 2009-06-27 14:40 38208 ----a-w- c:\documents and settings\sarah g.SARAH.000\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe2009-06-21 21:14 . 2008-05-10 03:02 -------- d-----w- c:\program files\Java
2009-06-19 14:05 . 2009-06-19 14:05 -------- d-----w- c:\documents and settings\john\Application Data\Apple Computer
2009-06-16 14:36 . 2004-08-04 10:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 10:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-14 20:50 . 2008-11-17 15:55 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\AOL Downloads
2009-06-09 13:38 . 2009-06-09 13:38 12736 ---ha-w- c:\windows\system32\mlfcache.dat
2009-06-09 13:38 . 2008-08-07 22:28 -------- d-----w- c:\documents and settings\sarah g.SARAH.000\Application Data\Apple Computer
2009-06-05 21:43 . 2009-06-05 21:43 69632 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\Safari 4.30.17.0\SetupAdmin.exe
2009-06-03 19:09 . 2004-08-04 10:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-08-04 21:41 . 2009-06-27 13:29 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.