This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please check my HJT log

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok, I did that and I can't tell that nothings changed, I still can't install some things and my task manager just pops up and closes again…

ComboFix 09-03-15.01 - Kristy 2009-03-16 18:21:23.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.212 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kristy\Desktop\CFScript.txt
* Created a new restore point

FILE ::
c:\documents and settings\All Users\Start Menu\Programs\Administrative Tools\Recycle Bin\kdja.exe
c:\program files\MBWMY6KR.exe
c:\windows\14H3H0Y1RNH.exe
c:\windows\1HH5P.exe
c:\windows\1R34WHI.exe
c:\windows\23DIZQ.exe
c:\windows\2IG72ZYZBFVN.exe
c:\windows\2NNPM3AS8.exe
c:\windows\3AF9ILF5N53S.exe
c:\windows\3VUMPGTGW.exe
c:\windows\40UYFPMNI.exe
c:\windows\4OIW0C0.exe
c:\windows\4Q0MXNJ9F.exe
c:\windows\5HQIYDY.exe
c:\windows\5MZHQ6.exe
c:\windows\6YY3H4PB.exe
c:\windows\6Z8VQ.exe
c:\windows\7SOC9WZ6HAXG.exe
c:\windows\98UBG40EEE.exe
c:\windows\9GTTF99O.exe
c:\windows\9LKVE6PM.exe
c:\windows\9NDQ984HDLAE.exe
c:\windows\9SP00JBDUZJ0.exe
c:\windows\B276A.exe
c:\windows\B56DIMNM.exe
c:\windows\C009543J07.exe
c:\windows\CVBOD9AX78UD.exe
c:\windows\EELB1IVL92C.exe
c:\windows\FC596.exe
c:\windows\G79UN1.exe
c:\windows\G9Z2U3LI.exe
c:\windows\HW2VWLUR.exe
c:\windows\I3ETXM0MNZS.exe
c:\windows\I8V5ZLII.exe
c:\windows\IH6RNKYKZ0.exe
c:\windows\IHC9IIA.exe
c:\windows\ILUJFR.exe
c:\windows\J3GBGKSA.exe
c:\windows\K7NAN.exe
c:\windows\LKZA4.exe
c:\windows\LQPCVSRVKNR.exe
c:\windows\LS3A0NEFDUJ3.exe
c:\windows\MRG2LUTA629.exe
c:\windows\PWD8KYGTP.exe
c:\windows\system32\svcchost.exe
c:\windows\T31TZW.exe
c:\windows\TJTQZPSRY5T.exe
c:\windows\VASC9CIY810.exe
c:\windows\WUAA71E.exe
c:\windows\WXNZ1SB24.exe
c:\windows\XAVRLDW.exe
c:\windows\XZPMNYK.exe
c:\windows\YT1X0GD7P.exe
c:\windows\YYT6FQVUUD.exe
c:\windows\ZCHSCNE8H0QU.exe
c:\windows\ZCMBPO.bat
c:\windows\ZOA2WXS1BF.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\OM9WWU5
c:\program files\OM9WWU5\EQ49WTDX.exe
c:\program files\XNUJA
c:\program files\XNUJA\NTRX0.exe
c:\windows\14H3H0Y1RNH.exe
c:\windows\1HH5P.exe
c:\windows\1R34WHI.exe
c:\windows\2IG72ZYZBFVN.exe
c:\windows\2NNPM3AS8.exe
c:\windows\3AF9ILF5N53S.exe
c:\windows\3VUMPGTGW.exe
c:\windows\40UYFPMNI.exe
c:\windows\4OIW0C0.exe
c:\windows\5HQIYDY.exe
c:\windows\5MZHQ6.exe
c:\windows\6YY3H4PB.exe
c:\windows\6Z8VQ.exe
c:\windows\7SOC9WZ6HAXG.exe
c:\windows\98UBG40EEE.exe
c:\windows\9GTTF99O.exe
c:\windows\9LKVE6PM.exe
c:\windows\9NDQ984HDLAE.exe
c:\windows\B276A.exe
c:\windows\C009543J07.exe
c:\windows\CVBOD9AX78UD.exe
c:\windows\EELB1IVL92C.exe
c:\windows\FC596.exe
c:\windows\G79UN1.exe
c:\windows\HW2VWLUR.exe
c:\windows\I8V5ZLII.exe
c:\windows\IH6RNKYKZ0.exe
c:\windows\IHC9IIA.exe
c:\windows\ILUJFR.exe
c:\windows\LKZA4.exe
c:\windows\LQPCVSRVKNR.exe
c:\windows\LS3A0NEFDUJ3.exe
c:\windows\MRG2LUTA629.exe
c:\windows\system32\svcchost.exe
c:\windows\T31TZW.exe
c:\windows\TJTQZPSRY5T.exe
c:\windows\VASC9CIY810.exe
c:\windows\WUAA71E.exe
c:\windows\WXNZ1SB24.exe
c:\windows\XAVRLDW.exe
c:\windows\XZPMNYK.exe
c:\windows\YT1X0GD7P.exe
c:\windows\YYT6FQVUUD.exe
c:\windows\ZCHSCNE8H0QU.exe
c:\windows\ZCMBPO.bat
c:\windows\ZOA2WXS1BF.exe

.
((((((((((((((((((((((((( Files Created from 2009-02-16 to 2009-03-16 )))))))))))))))))))))))))))))))
.

2009-03-16 18:20 . 2009-03-16 18:20 d——– c:\program files\S335JURT2I
2009-03-16 18:20 . 2009-03-16 18:20 d——– c:\program files\NV8S8KKR4
2009-03-16 18:20 . 2009-03-16 18:20 d——– c:\program files\EHFD7L
2009-03-16 18:20 . 2009-03-14 21:40 69,632 -rahs—- c:\windows\PMKYK.exe
2009-03-16 18:20 . 2009-03-14 01:08 69,632 -rahs—- c:\windows\DZ24L36PZCJ.exe
2009-03-16 18:20 . 2009-03-16 14:38 69,632 –a—— c:\windows\3X45UPLE8B.exe
2009-03-16 13:59 . 2008-04-14 05:42 116,224 –a–c— c:\windows\system32\dllcache\xrxwiadr.dll
2009-03-16 13:59 . 2001-08-17 22:37 99,865 –a–c— c:\windows\system32\dllcache\xlog.exe
2009-03-16 13:59 . 2001-08-17 22:37 27,648 –a–c— c:\windows\system32\dllcache\xrxftplt.exe
2009-03-16 13:59 . 2001-08-17 22:36 23,040 –a–c— c:\windows\system32\dllcache\xrxwbtmp.dll
2009-03-16 13:59 . 2008-04-13 22:04 19,455 –a–c— c:\windows\system32\dllcache\wvchntxx.sys
2009-03-16 13:59 . 2008-04-14 00:16 19,200 –a–c— c:\windows\system32\dllcache\wstcodec.sys
2009-03-16 13:59 . 2008-04-14 05:42 18,944 –a–c— c:\windows\system32\dllcache\xrxscnui.dll
2009-03-16 13:59 . 2001-08-17 12:11 16,970 –a–c— c:\windows\system32\dllcache\xem336n5.sys
2009-03-16 13:59 . 2008-04-13 22:04 12,063 –a–c— c:\windows\system32\dllcache\wsiintxx.sys
2009-03-16 13:59 . 2008-04-14 05:42 8,192 –a–c— c:\windows\system32\dllcache\wshirda.dll
2009-03-16 13:59 . 2001-08-17 22:37 4,608 –a–c— c:\windows\system32\dllcache\xrxflnch.exe
2009-03-16 13:57 . 2001-08-17 13:28 794,654 –a–c— c:\windows\system32\dllcache\usr1801.sys
2009-03-16 13:56 . 2001-08-17 22:36 525,568 –a–c— c:\windows\system32\dllcache\tridxp.dll
2009-03-16 13:55 . 2001-08-17 14:01 241,664 –a–c— c:\windows\system32\dllcache\tosdvd02.sys
2009-03-16 13:54 . 2001-08-17 12:18 285,760 –a–c— c:\windows\system32\dllcache\stlnata.sys
2009-03-16 13:53 . 2001-08-17 22:36 114,688 –a–c— c:\windows\system32\dllcache\sonypi.dll
2009-03-16 13:53 . 2001-08-17 22:36 106,584 –a–c— c:\windows\system32\dllcache\spdports.dll
2009-03-16 13:53 . 2001-08-17 22:36 99,328 –a–c— c:\windows\system32\dllcache\srusd.dll
2009-03-16 13:53 . 2001-08-17 13:51 61,824 –a–c— c:\windows\system32\dllcache\speed.sys
2009-03-16 13:53 . 2001-08-17 12:51 37,040 –a–c— c:\windows\system32\dllcache\sonypi.sys
2009-03-16 13:53 . 2001-08-17 22:36 24,660 –a–c— c:\windows\system32\dllcache\spxupchk.dll
2009-03-16 13:53 . 2001-08-17 12:51 20,752 –a–c— c:\windows\system32\dllcache\sonync.sys
2009-03-16 13:53 . 2001-08-17 14:07 19,072 –a–c— c:\windows\system32\dllcache\sparrow.sys
2009-03-16 13:53 . 2001-08-17 13:53 9,600 –a–c— c:\windows\system32\dllcache\sonymc.sys
2009-03-16 13:53 . 2001-08-17 13:56 7,552 –a–c— c:\windows\system32\dllcache\sonypvu1.sys
2009-03-16 13:53 . 2008-04-14 00:10 7,552 –a–c— c:\windows\system32\dllcache\sonyait.sys
2009-03-16 13:53 . 2001-08-17 13:53 7,040 –a–c— c:\windows\system32\dllcache\snyaitmc.sys
2009-03-16 13:51 . 2001-08-17 22:36 386,560 –a–c— c:\windows\system32\dllcache\sgiul50.dll
2009-03-16 13:51 . 2001-08-17 14:56 252,032 –a–c— c:\windows\system32\dllcache\sis300iv.dll
2009-03-16 13:51 . 2001-08-17 22:36 238,592 –a–c— c:\windows\system32\dllcache\sisgrv.dll
2009-03-16 13:51 . 2001-07-21 14:29 161,568 –a–c— c:\windows\system32\dllcache\sgsmusb.sys
2009-03-16 13:51 . 2001-08-17 14:56 150,144 –a–c— c:\windows\system32\dllcache\sis6306v.dll
2009-03-16 13:51 . 2001-08-17 12:50 104,064 –a–c— c:\windows\system32\dllcache\sisgrp.sys
2009-03-16 13:51 . 2001-08-17 12:50 101,760 –a–c— c:\windows\system32\dllcache\sis300ip.sys
2009-03-16 13:51 . 2001-08-17 12:51 98,080 –a–c— c:\windows\system32\dllcache\sgiulnt5.sys
2009-03-16 13:51 . 2001-08-17 12:50 68,608 –a–c— c:\windows\system32\dllcache\sis6306p.sys
2009-03-16 13:51 . 2001-08-17 12:19 36,480 –a–c— c:\windows\system32\dllcache\sfmanm.sys
2009-03-16 13:51 . 2001-07-21 14:29 18,400 –a–c— c:\windows\system32\dllcache\sgsmld.sys
2009-03-16 13:51 . 2001-08-17 13:48 17,664 –a–c— c:\windows\system32\dllcache\sermouse.sys
2009-03-16 13:51 . 2001-08-17 13:53 6,784 –a–c— c:\windows\system32\dllcache\serscan.sys
2009-03-16 13:50 . 2001-08-17 13:52 11,648 –a–c— c:\windows\system32\dllcache\scsiprnt.sys
2009-03-16 13:50 . 2008-04-14 00:15 11,520 –a–c— c:\windows\system32\dllcache\scsiscan.sys
2009-03-16 13:50 . 2001-08-17 13:53 6,912 –a–c— c:\windows\system32\dllcache\seaddsmc.sys
2009-03-16 13:49 . 2001-08-17 22:36 495,616 –a–c— c:\windows\system32\dllcache\sblfx.dll
2009-03-16 13:49 . 2001-08-17 14:56 245,632 –a–c— c:\windows\system32\dllcache\s3savmx.dll
2009-03-16 13:49 . 2001-08-17 14:56 198,400 –a–c— c:\windows\system32\dllcache\s3sav4.dll
2009-03-16 13:49 . 2001-08-17 14:56 179,264 –a–c— c:\windows\system32\dllcache\s3sav3d.dll
2009-03-16 13:49 . 2001-08-17 12:50 77,824 –a–c— c:\windows\system32\dllcache\s3sav4m.sys
2009-03-16 13:49 . 2001-08-17 12:50 75,392 –a–c— c:\windows\system32\dllcache\s3savmxm.sys
2009-03-16 13:49 . 2001-08-17 12:50 61,504 –a–c— c:\windows\system32\dllcache\s3sav3dm.sys
2009-03-16 13:49 . 2008-04-14 00:10 43,904 –a–c— c:\windows\system32\dllcache\sbp2port.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmusbm.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmn50m.sys
2009-03-16 13:49 . 2001-08-17 13:51 17,280 –a–c— c:\windows\system32\dllcache\scr111.sys
2009-03-16 13:49 . 2001-08-17 13:51 16,640 –a–c— c:\windows\system32\dllcache\scmstcs.sys
2009-03-16 13:47 . 2001-08-17 13:28 899,146 –a–c— c:\windows\system32\dllcache\r2mdkxga.sys
2009-03-16 13:46 . 2008-04-14 05:42 363,520 –a–c— c:\windows\system32\dllcache\psisdecd.dll
2009-03-16 13:45 . 2001-08-17 14:05 351,616 –a–c— c:\windows\system32\dllcache\ovcodek2.sys
2009-03-16 13:44 . 2001-08-17 12:50 198,144 –a–c— c:\windows\system32\dllcache\nv3.sys
2009-03-16 13:44 . 2001-08-17 22:36 123,776 –a–c— c:\windows\system32\dllcache\nv3.dll
2009-03-16 13:44 . 2001-08-17 12:49 51,552 –a–c— c:\windows\system32\dllcache\ntgrip.sys
2009-03-16 13:44 . 2001-08-17 13:47 9,344 –a–c— c:\windows\system32\dllcache\ntapm.sys
2009-03-16 13:44 . 2001-08-17 13:53 7,552 –a–c— c:\windows\system32\dllcache\nsmmc.sys
2009-03-16 13:42 . 2001-08-17 12:50 103,296 –a–c— c:\windows\system32\dllcache\mtxvideo.sys
2009-03-16 13:42 . 2008-04-14 00:16 49,024 –a–c— c:\windows\system32\dllcache\mstape.sys
2009-03-16 13:42 . 2008-04-14 00:24 22,016 –a–c— c:\windows\system32\dllcache\msircomm.sys
2009-03-16 13:42 . 2001-08-17 13:50 21,888 –a–c— c:\windows\system32\dllcache\mxcard.sys
2009-03-16 13:42 . 2001-08-17 13:49 19,968 –a–c— c:\windows\system32\dllcache\mxnic.sys
2009-03-16 13:42 . 2001-08-17 22:36 19,968 –a–c— c:\windows\system32\dllcache\mxicfg.dll
2009-03-16 13:42 . 2001-08-17 13:48 12,416 –a–c— c:\windows\system32\dllcache\msriffwv.sys
2009-03-16 13:42 . 2001-08-17 22:36 7,168 –a–c— c:\windows\system32\dllcache\mxport.dll
2009-03-16 13:42 . 2008-04-14 00:09 5,504 –a–c— c:\windows\system32\dllcache\mstee.sys
2009-03-16 13:42 . 2001-08-17 14:00 2,944 –a–c— c:\windows\system32\dllcache\msmpu401.sys
2009-03-16 13:40 . 2001-08-17 13:28 802,683 –a–c— c:\windows\system32\dllcache\ltsm.sys
2009-03-16 13:39 . 2008-04-14 05:41 253,952 –a–c— c:\windows\system32\dllcache\kdsusd.dll
2009-03-16 13:38 . 2008-04-14 05:41 702,845 –a–c— c:\windows\system32\dllcache\i81xdnt5.dll
2009-03-16 13:37 . 2001-08-17 13:28 542,879 –a–c— c:\windows\system32\dllcache\hsf_msft.sys
2009-03-16 13:36 . 2001-08-17 14:56 1,733,120 –a–c— c:\windows\system32\dllcache\g400d.dll
2009-03-16 13:35 . 2001-08-17 12:15 455,680 –a–c— c:\windows\system32\dllcache\fus2base.sys
2009-03-16 13:34 . 2001-08-17 13:28 634,134 –a–c— c:\windows\system32\dllcache\el656ct5.sys
2009-03-16 13:33 . 2001-08-17 12:14 952,007 –a–c— c:\windows\system32\dllcache\diwan.sys
2009-03-16 13:32 . 2001-08-17 22:36 256,512 –a–c— c:\windows\system32\dllcache\devcon32.dll
2009-03-16 13:31 . 2001-08-17 12:13 980,034 –a–c— c:\windows\system32\dllcache\cicap.sys
2009-03-16 13:30 . 2001-08-17 13:28 871,388 –a–c— c:\windows\system32\dllcache\bcmdm.sys
2009-03-16 13:29 . 2001-08-17 14:55 382,592 –a–c— c:\windows\system32\dllcache\atidrab.dll
2009-03-16 13:28 . 2001-08-17 13:28 762,780 –a–c— c:\windows\system32\dllcache\3cwmcru.sys
2009-03-16 13:27 . 2001-08-17 14:56 66,048 –a–c— c:\windows\system32\dllcache\s3legacy.dll
2009-03-16 12:41 . 2009-03-16 12:41 d——– c:\program files\V44R8C
2009-03-16 12:41 . 2009-03-16 12:41 d——– c:\program files\BCFF1BJHSQ9
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a—— c:\windows\system32\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a–c— c:\windows\system32\dllcache\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a—— c:\windows\system32\kbdkor.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a–c— c:\windows\system32\dllcache\kbdkor.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a—— c:\windows\system32\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a–c— c:\windows\system32\dllcache\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a—— c:\windows\system32\kbd103.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a–c— c:\windows\system32\dllcache\kbd103.dll
2009-03-16 01:56 . 2009-03-16 01:56 d——– c:\program files\RZC6G2C3JDJ
2009-03-16 01:56 . 2009-03-16 01:56 d——– c:\program files\1VH2JLCEEN
2009-03-16 01:47 . 2009-03-16 12:37 1,374 –a—— c:\windows\imsins.BAK
2009-03-15 21:15 . 2009-03-15 21:15 d——– c:\program files\L8Z5MUU6T0SE
2009-03-15 21:15 . 2009-03-15 21:15 d——– c:\program files\HKUTC0T
2009-03-15 21:05 . 2009-03-15 21:05 d——– c:\documents and settings\Administrator
2009-03-15 11:48 . 2009-03-15 11:48 d——– c:\program files\Vuze
2009-03-15 11:48 . 2009-03-16 02:05 d——– c:\documents and settings\Kristy\Application Data\Azureus
2009-03-15 11:48 . 2009-03-15 11:48 d——– c:\documents and settings\All Users\Application Data\Azureus
2009-03-15 03:15 . 2009-03-15 03:15 82 –a—— c:\windows\wininit.ini
2009-03-15 02:42 . 2009-03-15 02:42 d——– c:\program files\8CKTMRAWT2
2009-03-15 02:39 . 2009-03-15 02:39 d——– c:\program files\DLRIVH
2009-03-15 02:07 . 2009-03-15 02:07 d——– c:\program files\LA53CFICB
2009-03-15 02:05 . 2009-03-15 20:55 10,349 –a—— c:\windows\system32\svcchost
2009-03-15 01:57 . 2009-03-15 01:57 d——– c:\program files\BZLD2M
2009-03-15 01:57 . 2009-03-15 01:57 69,632 -r-hs—- c:\windows\S7E0J8KAX383.exe
2009-03-15 01:56 . 2009-03-15 01:56 d——– c:\program files\2U6CHEYWF
2009-03-15 01:52 . 2009-03-15 02:07 d——– c:\program files\Trojan Remover

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 08:51 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-09 23:46 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-09 23:02 9,589,760 —-a-w c:\windows\system32\RTLCPL.EXE
2009-03-09 23:02 204,800 ——w c:\windows\alcrmv.exe
2009-03-09 23:02 143,360 —-a-w c:\windows\SOUNDMAN.EXE
2009-03-08 08:59 ——— d—–w c:\program files\Java
2009-03-08 00:07 ——— d—–w c:\program files\CCleaner
2009-03-08 00:07 ——— d—–w c:\program files\7-Zip
2009-03-08 00:04 ——— d—–w c:\program files\Foxit Software
2009-03-06 19:50 241,664 ——w c:\windows\alcupd.exe
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2008-12-20 23:15 826,368 —-a-w c:\windows\system32\wininet.dll
2008-08-09 13:34 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080920080810\index.dat
.

((((((((((((((((((((((((((((( SnapShot_2009-03-16_16.38.21.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-16 23:20:08 16,384 —-atw c:\windows\temp\Perflib_Perfdata_170.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-03-08 160592]
"PlaxoSysTray"="c:\program files\Plaxo\3.19.0.16\PlaxoSysTray.exe" [2009-02-09 20480]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\pmremind.exe [2009-03-09 331776]
LUMIX Simple Viewer.lnk - c:\program files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2008-11-04 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.MSNAUDIO"= msnaudio.acm
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GetGoDM]
–a—— 2009-02-11 03:40 3280568 c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
–a—— 2009-02-09 11:08 371271 c:\program files\Plaxo\3.19.0.16\PlaxoHelper_en.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2009-02-04 12:27 23975720 c:\program files\Skype\Phone\Skype.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\eMule Plus\\eMule.exe"=
"c:\\Documents and Settings\\Kristy\\My Documents\\Documents\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

S2 10YX3FD3;10YX3FD3;c:\windows\TJTQZPSRY5T.exe -J2X0DEKU –> c:\windows\TJTQZPSRY5T.exe -J2X0DEKU [?]
S2 19T3H;19T3H;c:\windows\IHC9IIA.exe -AQLU44CEC3UJ –> c:\windows\IHC9IIA.exe -AQLU44CEC3UJ [?]
S2 1Q0PLJK5F7EO;1Q0PLJK5F7EO;c:\windows\ILUJFR.exe -A73PR9ZTP3Q –> c:\windows\ILUJFR.exe -A73PR9ZTP3Q [?]
S2 2Z8EHAJGE1;2Z8EHAJGE1;c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP –> c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP [?]
S2 5AX67SALZ;5AX67SALZ;c:\windows\MRG2LUTA629.exe -DDUEXG6H –> c:\windows\MRG2LUTA629.exe -DDUEXG6H [?]
S2 BBCAH;BBCAH;c:\windows\1R34WHI.exe -REG646GTN16P –> c:\windows\1R34WHI.exe -REG646GTN16P [?]
S2 D0V37G51X3;D0V37G51X3;c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ –> c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ [?]
S2 FGCN9QYV;FGCN9QYV;c:\windows\3X45UPLE8B.exe -UJAI5JF –> c:\windows\3X45UPLE8B.exe -UJAI5JF [?]
S2 GAY2F;GAY2F;c:\windows\4OIW0C0.exe -WBVYPWKID628 –> c:\windows\4OIW0C0.exe -WBVYPWKID628 [?]
S2 H0PC5IV3;H0PC5IV3;c:\windows\YYT6FQVUUD.exe -OK6IRIO –> c:\windows\YYT6FQVUUD.exe -OK6IRIO [?]
S2 H76MC;H76MC;c:\windows\5HQIYDY.exe -X83ZZL7VQJLS –> c:\windows\5HQIYDY.exe -X83ZZL7VQJLS [?]
S2 L69Y08;L69Y08;c:\windows\9GTTF99O.exe -196QP –> c:\windows\9GTTF99O.exe -196QP [?]
S2 MPJ5MST1U93;MPJ5MST1U93;c:\windows\6Z8VQ.exe -2QGBD1K9XL –> c:\windows\6Z8VQ.exe -2QGBD1K9XL [?]
S2 NU5S59GVTK5;NU5S59GVTK5;c:\windows\PMKYK.exe -3X45UPLE8B –> c:\windows\PMKYK.exe -3X45UPLE8B [?]
S2 PXNMBMJR;PXNMBMJR;c:\windows\98UBG40EEE.exe -4YKLBSH –> c:\windows\98UBG40EEE.exe -4YKLBSH [?]
S2 R9I2V5;R9I2V5;c:\windows\I8V5ZLII.exe -7FLLY –> c:\windows\I8V5ZLII.exe -7FLLY [?]
S2 TERDNO1D5;TERDNO1D5;c:\windows\CVBOD9AX78UD.exe -HOQE73D8L –> c:\windows\CVBOD9AX78UD.exe -HOQE73D8L [?]
S2 UJB973P1O;UJB973P1O;c:\windows\DZ24L36PZCJ.exe -KHVJVK5M –> c:\windows\DZ24L36PZCJ.exe -KHVJVK5M [?]
S2 UNGVG2LBWEL;UNGVG2LBWEL;c:\windows\B276A.exe -ODIM38SNRI –> c:\windows\B276A.exe -ODIM38SNRI [?]
S2 Y2EN4QW5889;Y2EN4QW5889;c:\windows\FC596.exe -5BMEKWTTJ5 –> c:\windows\FC596.exe -5BMEKWTTJ5 [?]
S2 YTMP1NBHT2;YTMP1NBHT2;c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB –> c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB [?]
S2 ZGC2AK;ZGC2AK;c:\windows\HW2VWLUR.exe -H67JL –> c:\windows\HW2VWLUR.exe -H67JL [?]
S2 ZO48L;ZO48L;c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU –> c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU [?]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys –> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S4 08FX8JFV;08FX8JFV;c:\windows\IH6RNKYKZ0.exe -CZ7LF5R –> c:\windows\IH6RNKYKZ0.exe -CZ7LF5R [?]
S4 1MV0BLHXE;1MV0BLHXE;c:\windows\I3ETXM0MNZS.exe -PR79NGT9 –> c:\windows\I3ETXM0MNZS.exe -PR79NGT9 [?]
S4 2NXBWF;2NXBWF;c:\windows\J3GBGKSA.exe -BQUON –> c:\windows\J3GBGKSA.exe -BQUON [?]
S4 2O1L3;2O1L3;c:\windows\XAVRLDW.exe -M3N189R55ALV –> c:\windows\XAVRLDW.exe -M3N189R55ALV [?]
S4 3GJ665NT766;3GJ665NT766;c:\windows\LKZA4.exe -CTKCPFB64F –> c:\windows\LKZA4.exe -CTKCPFB64F [?]
S4 3Q3BVMFQZTJ;3Q3BVMFQZTJ;c:\windows\K7NAN.exe -BR0QMKHWMT –> c:\windows\K7NAN.exe -BR0QMKHWMT [?]
S4 4B5HRB6B9;4B5HRB6B9;c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ –> c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ [?]
S4 5ZHFDU4;5ZHFDU4;c:\windows\O7TEQDAQJ.exe -E0DS20 –> c:\windows\O7TEQDAQJ.exe -E0DS20 [?]
S4 8IT5Y44;8IT5Y44;c:\windows\PWD8KYGTP.exe -GJQKUE –> c:\windows\PWD8KYGTP.exe -GJQKUE [?]
S4 ADA2EG1;ADA2EG1;c:\windows\YT1X0GD7P.exe -QE361V –> c:\windows\YT1X0GD7P.exe -QE361V [?]
S4 BPYV25IQ;BPYV25IQ;c:\windows\14H3H0Y1RNH.exe -RQVMLG86 –> c:\windows\14H3H0Y1RNH.exe -RQVMLG86 [?]
S4 BQAGVE30;BQAGVE30;c:\windows\ZOA2WXS1BF.exe -RANNAKM –> c:\windows\ZOA2WXS1BF.exe -RANNAKM [?]
S4 CMUODPSJO8DW;CMUODPSJO8DW;c:\windows\23DIZQ.exe -SQR19Y93WQS –> c:\windows\23DIZQ.exe -SQR19Y93WQS [?]
S4 D9XBL1I9PX;D9XBL1I9PX;c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L –> c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L [?]
S4 DULWFJE;DULWFJE;c:\windows\4Q0MXNJ9F.exe -TXI97K –> c:\windows\4Q0MXNJ9F.exe -TXI97K [?]
S4 FEK1UEF;FEK1UEF;c:\windows\3VUMPGTGW.exe -VFHLTB –> c:\windows\3VUMPGTGW.exe -VFHLTB [?]
S4 H0252AAY6QPU;H0252AAY6QPU;c:\windows\5MZHQ6.exe -W3ZBRSF05CN –> c:\windows\5MZHQ6.exe -W3ZBRSF05CN [?]
S4 HC5IOVVW3;HC5IOVVW3;c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS –> c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS [?]
S4 IC56FJ2OJE;IC56FJ2OJE;c:\windows\9SP00JBDUZJ0.exe -YF2C670NL –> c:\windows\9SP00JBDUZJ0.exe -YF2C670NL [?]
S4 II9TFZ;II9TFZ;c:\windows\6YY3H4PB.exe -YLFI2 –> c:\windows\6YY3H4PB.exe -YLFI2 [?]
S4 J1GCP0;J1GCP0;c:\windows\9LKVE6PM.exe -YXS5Z –> c:\windows\9LKVE6PM.exe -YXS5Z [?]
S4 J33FQ1F;J33FQ1F;c:\windows\WXNZ1SB24.exe -OK0B75 –> c:\windows\WXNZ1SB24.exe -OK0B75 [?]
S4 LHFUA;LHFUA;c:\windows\WUAA71E.exe -1I8UJXUVI7F6 –> c:\windows\WUAA71E.exe -1I8UJXUVI7F6 [?]
S4 LTQLZP2FX6;LTQLZP2FX6;c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA –> c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA [?]
S4 MUAL22T09A;MUAL22T09A;c:\windows\1HH5P.exe -2VYRJYKRXN –> c:\windows\1HH5P.exe -2VYRJYKRXN [?]
S4 NBG7GOASD1KS;NBG7GOASD1KS;c:\windows\T31TZW.exe -JQK3SOQXCMO –> c:\windows\T31TZW.exe -JQK3SOQXCMO [?]
S4 RO3SKV;RO3SKV;c:\windows\2NNPM3AS8.exe -7P05Z7 –> c:\windows\2NNPM3AS8.exe -7P05Z7 [?]
S4 ROO5X4F;ROO5X4F;c:\windows\40UYFPMNI.exe -7RLA4D –> c:\windows\40UYFPMNI.exe -7RLA4D [?]
S4 SQFAY;SQFAY;c:\windows\B56DIMNM.exe -8RCNP –> c:\windows\B56DIMNM.exe -8RCNP [?]
S4 VMAJ4WFY;VMAJ4WFY;c:\windows\C009543J07.exe -NLK1XNBF –> c:\windows\C009543J07.exe -NLK1XNBF [?]
S4 W42CWKTK7;W42CWKTK7;c:\windows\EELB1IVL92C.exe -5ZPNRQCZ –> c:\windows\EELB1IVL92C.exe -5ZPNRQCZ [?]
S4 YT92TP;YT92TP;c:\windows\G9Z2U3LI.exe -UE5IC –> c:\windows\G9Z2U3LI.exe -UE5IC [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - 1Q0PLJK5F7EO
*NewlyCreated* - R9I2V5
.
Contents of the 'Scheduled Tasks' folder

2009-03-15 c:\windows\Tasks\Registry Winner Schedule.job
- c:\program files\Registry Winner\RegistryWinner.exe []
.
.
——- Supplementary Scan ——-
.
IE: &Down&load &Link& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatch.htm
IE: &Down&load All &Links& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
IE: &GetGo Toolbar Search - c:\program files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{01A13E40-2F55-4397-B39B-7851BCFB8008} - c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - component: c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\extensions\[removed]\platform\WINNT_x86-msvc\components\lpxpcom.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-16 18:24:00
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-16 18:25:45
ComboFix-quarantined-files.txt 2009-03-16 23:25:19
ComboFix2.txt 2009-03-16 21:39:42
ComboFix3.txt 2009-03-16 02:12:51
ComboFix4.txt 2009-03-15 03:21:29

Pre-Run: 43,650,969,600 bytes free
Post-Run: 43,636,027,392 bytes free

402 — E O F — 2009-03-09 21:51:30


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:35:59 PM, on 3/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\IOPXQWM8M.exe
C:\ProcessExplorer\procexp.exe
C:\WINDOWS\IOPXQWM8M.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\IOPXQWM8M.exe
C:\WINDOWS\IOPXQWM8M.exe
C:\WINDOWS\IOPXQWM8M.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://test.catalog.update.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: GetGo URL Catcher (dont remove!) - {0315AA2C-10C7-4504-A1C4-F552ABA8A095} - C:\Program Files\GetGo Software\GetGo Download Manager\URLCatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: GetGo Toolbar - {075BBE29-FEC0-404a-A459-FF58713616FA} - C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O8 - Extra context menu item: &Down&load &Link& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatch.htm
O8 - Extra context menu item: &Down&load All &Links& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
O8 - Extra context menu item: &GetGo Toolbar Search - res://C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: GetGo - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra 'Tools' menuitem: GetGo Download Manager - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://test.catalog.update.microsoft.com/v…b?1236661267875
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1218290032265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ECC1FB7-D0B6-463E-99BE-7563CC59E2CB}: NameServer = 65.240.162.65 65.240.162.66
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: 10YX3FD3 - Unknown owner - C:\WINDOWS\TJTQZPSRY5T.exe (file missing)
O23 - Service: 19T3H - Unknown owner - C:\WINDOWS\IHC9IIA.exe (file missing)
O23 - Service: 1Q0PLJK5F7EO - Unknown owner - C:\WINDOWS\ILUJFR.exe (file missing)
O23 - Service: 2XGVZM - ???? - C:\WINDOWS\J7PE4TJD.exe
O23 - Service: 2Z8EHAJGE1 - Unknown owner - C:\WINDOWS\LS3A0NEFDUJ3.exe (file missing)
O23 - Service: 5AX67SALZ - Unknown owner - C:\WINDOWS\MRG2LUTA629.exe (file missing)
O23 - Service: BBCAH - Unknown owner - C:\WINDOWS\1R34WHI.exe (file missing)
O23 - Service: D0V37G51X3 - Unknown owner - C:\WINDOWS\3AF9ILF5N53S.exe (file missing)
O23 - Service: FGCN9QYV - ???????? - C:\WINDOWS\3X45UPLE8B.exe
O23 - Service: GAY2F - Unknown owner - C:\WINDOWS\4OIW0C0.exe (file missing)
O23 - Service: H0PC5IV3 - Unknown owner - C:\WINDOWS\YYT6FQVUUD.exe (file missing)
O23 - Service: H76MC - Unknown owner - C:\WINDOWS\5HQIYDY.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: L69Y08 - Unknown owner - C:\WINDOWS\9GTTF99O.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MPJ5MST1U93 - Unknown owner - C:\WINDOWS\6Z8VQ.exe (file missing)
O23 - Service: NU5S59GVTK5 - ???? - C:\WINDOWS\PMKYK.exe
O23 - Service: PXNMBMJR - Unknown owner - C:\WINDOWS\98UBG40EEE.exe (file missing)
O23 - Service: R9I2V5 - Unknown owner - C:\WINDOWS\I8V5ZLII.exe (file missing)
O23 - Service: TERDNO1D5 - Unknown owner - C:\WINDOWS\CVBOD9AX78UD.exe (file missing)
O23 - Service: UJB973P1O - ??????????? - C:\WINDOWS\DZ24L36PZCJ.exe
O23 - Service: UNGVG2LBWEL - Unknown owner - C:\WINDOWS\B276A.exe (file missing)
O23 - Service: Y2EN4QW5889 - Unknown owner - C:\WINDOWS\FC596.exe (file missing)
O23 - Service: YTMP1NBHT2 - Unknown owner - C:\WINDOWS\ZCHSCNE8H0QU.exe (file missing)
O23 - Service: ZGC2AK - Unknown owner - C:\WINDOWS\HW2VWLUR.exe (file missing)
O23 - Service: ZO48L - Unknown owner - C:\WINDOWS\XZPMNYK.exe (file missing)

–
End of file - 9173 bytes
We'll keep killing them

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\PMKYK.exe
c:\windows\DZ24L36PZCJ.exe
c:\windows\3X45UPLE8B.exe
c:\windows\system32\svcchost
c:\windows\S7E0J8KAX383.exe

Folder::
c:\program files\S335JURT2I
c:\program files\NV8S8KKR4
c:\program files\EHFD7L
c:\program files\8CKTMRAWT2
c:\program files\DLRIVH
c:\program files\LA53CFICB
c:\program files\BZLD2M
c:\program files\2U6CHEYWF

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
No different :-( It's like they just keep coming back *SIGH*

ComboFix 09-03-15.01 - Kristy 2009-03-16 20:15:09.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.167 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2009-02-17 to 2009-03-17 )))))))))))))))))))))))))))))))
.

2009-03-16 20:06 . 2009-03-16 20:06 d——– c:\program files\QDN7B44A7
2009-03-16 20:06 . 2009-03-16 18:34 69,632 –a—— c:\windows\BM4EE5V9PE.exe
2009-03-16 18:34 . 2009-03-16 18:34 d——– c:\program files\YB8PB7N
2009-03-16 18:34 . 2009-03-16 18:34 69,632 -r-hs—- c:\windows\J7PE4TJD.exe
2009-03-16 18:34 . 2009-03-16 18:34 69,632 -r-hs—- c:\windows\IOPXQWM8M.exe
2009-03-16 13:59 . 2008-04-14 05:42 116,224 –a–c— c:\windows\system32\dllcache\xrxwiadr.dll
2009-03-16 13:59 . 2001-08-17 22:37 99,865 –a–c— c:\windows\system32\dllcache\xlog.exe
2009-03-16 13:59 . 2001-08-17 22:37 27,648 –a–c— c:\windows\system32\dllcache\xrxftplt.exe
2009-03-16 13:59 . 2001-08-17 22:36 23,040 –a–c— c:\windows\system32\dllcache\xrxwbtmp.dll
2009-03-16 13:59 . 2008-04-13 22:04 19,455 –a–c— c:\windows\system32\dllcache\wvchntxx.sys
2009-03-16 13:59 . 2008-04-14 00:16 19,200 –a–c— c:\windows\system32\dllcache\wstcodec.sys
2009-03-16 13:59 . 2008-04-14 05:42 18,944 –a–c— c:\windows\system32\dllcache\xrxscnui.dll
2009-03-16 13:59 . 2001-08-17 12:11 16,970 –a–c— c:\windows\system32\dllcache\xem336n5.sys
2009-03-16 13:59 . 2008-04-13 22:04 12,063 –a–c— c:\windows\system32\dllcache\wsiintxx.sys
2009-03-16 13:59 . 2008-04-14 05:42 8,192 –a–c— c:\windows\system32\dllcache\wshirda.dll
2009-03-16 13:59 . 2001-08-17 22:37 4,608 –a–c— c:\windows\system32\dllcache\xrxflnch.exe
2009-03-16 13:57 . 2001-08-17 13:28 794,654 –a–c— c:\windows\system32\dllcache\usr1801.sys
2009-03-16 13:56 . 2001-08-17 22:36 525,568 –a–c— c:\windows\system32\dllcache\tridxp.dll
2009-03-16 13:55 . 2001-08-17 14:01 241,664 –a–c— c:\windows\system32\dllcache\tosdvd02.sys
2009-03-16 13:54 . 2001-08-17 12:18 285,760 –a–c— c:\windows\system32\dllcache\stlnata.sys
2009-03-16 13:53 . 2001-08-17 22:36 114,688 –a–c— c:\windows\system32\dllcache\sonypi.dll
2009-03-16 13:53 . 2001-08-17 22:36 106,584 –a–c— c:\windows\system32\dllcache\spdports.dll
2009-03-16 13:53 . 2001-08-17 22:36 99,328 –a–c— c:\windows\system32\dllcache\srusd.dll
2009-03-16 13:53 . 2001-08-17 13:51 61,824 –a–c— c:\windows\system32\dllcache\speed.sys
2009-03-16 13:53 . 2001-08-17 12:51 37,040 –a–c— c:\windows\system32\dllcache\sonypi.sys
2009-03-16 13:53 . 2001-08-17 22:36 24,660 –a–c— c:\windows\system32\dllcache\spxupchk.dll
2009-03-16 13:53 . 2001-08-17 12:51 20,752 –a–c— c:\windows\system32\dllcache\sonync.sys
2009-03-16 13:53 . 2001-08-17 14:07 19,072 –a–c— c:\windows\system32\dllcache\sparrow.sys
2009-03-16 13:53 . 2001-08-17 13:53 9,600 –a–c— c:\windows\system32\dllcache\sonymc.sys
2009-03-16 13:53 . 2001-08-17 13:56 7,552 –a–c— c:\windows\system32\dllcache\sonypvu1.sys
2009-03-16 13:53 . 2008-04-14 00:10 7,552 –a–c— c:\windows\system32\dllcache\sonyait.sys
2009-03-16 13:53 . 2001-08-17 13:53 7,040 –a–c— c:\windows\system32\dllcache\snyaitmc.sys
2009-03-16 13:51 . 2001-08-17 22:36 386,560 –a–c— c:\windows\system32\dllcache\sgiul50.dll
2009-03-16 13:51 . 2001-08-17 14:56 252,032 –a–c— c:\windows\system32\dllcache\sis300iv.dll
2009-03-16 13:51 . 2001-08-17 22:36 238,592 –a–c— c:\windows\system32\dllcache\sisgrv.dll
2009-03-16 13:51 . 2001-07-21 14:29 161,568 –a–c— c:\windows\system32\dllcache\sgsmusb.sys
2009-03-16 13:51 . 2001-08-17 14:56 150,144 –a–c— c:\windows\system32\dllcache\sis6306v.dll
2009-03-16 13:51 . 2001-08-17 12:50 104,064 –a–c— c:\windows\system32\dllcache\sisgrp.sys
2009-03-16 13:51 . 2001-08-17 12:50 101,760 –a–c— c:\windows\system32\dllcache\sis300ip.sys
2009-03-16 13:51 . 2001-08-17 12:51 98,080 –a–c— c:\windows\system32\dllcache\sgiulnt5.sys
2009-03-16 13:51 . 2001-08-17 12:50 68,608 –a–c— c:\windows\system32\dllcache\sis6306p.sys
2009-03-16 13:51 . 2001-08-17 12:19 36,480 –a–c— c:\windows\system32\dllcache\sfmanm.sys
2009-03-16 13:51 . 2001-07-21 14:29 18,400 –a–c— c:\windows\system32\dllcache\sgsmld.sys
2009-03-16 13:51 . 2001-08-17 13:48 17,664 –a–c— c:\windows\system32\dllcache\sermouse.sys
2009-03-16 13:51 . 2001-08-17 13:53 6,784 –a–c— c:\windows\system32\dllcache\serscan.sys
2009-03-16 13:50 . 2001-08-17 13:52 11,648 –a–c— c:\windows\system32\dllcache\scsiprnt.sys
2009-03-16 13:50 . 2008-04-14 00:15 11,520 –a–c— c:\windows\system32\dllcache\scsiscan.sys
2009-03-16 13:50 . 2001-08-17 13:53 6,912 –a–c— c:\windows\system32\dllcache\seaddsmc.sys
2009-03-16 13:49 . 2001-08-17 22:36 495,616 –a–c— c:\windows\system32\dllcache\sblfx.dll
2009-03-16 13:49 . 2001-08-17 14:56 245,632 –a–c— c:\windows\system32\dllcache\s3savmx.dll
2009-03-16 13:49 . 2001-08-17 14:56 198,400 –a–c— c:\windows\system32\dllcache\s3sav4.dll
2009-03-16 13:49 . 2001-08-17 14:56 179,264 –a–c— c:\windows\system32\dllcache\s3sav3d.dll
2009-03-16 13:49 . 2001-08-17 12:50 77,824 –a–c— c:\windows\system32\dllcache\s3sav4m.sys
2009-03-16 13:49 . 2001-08-17 12:50 75,392 –a–c— c:\windows\system32\dllcache\s3savmxm.sys
2009-03-16 13:49 . 2001-08-17 12:50 61,504 –a–c— c:\windows\system32\dllcache\s3sav3dm.sys
2009-03-16 13:49 . 2008-04-14 00:10 43,904 –a–c— c:\windows\system32\dllcache\sbp2port.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmusbm.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmn50m.sys
2009-03-16 13:49 . 2001-08-17 13:51 17,280 –a–c— c:\windows\system32\dllcache\scr111.sys
2009-03-16 13:49 . 2001-08-17 13:51 16,640 –a–c— c:\windows\system32\dllcache\scmstcs.sys
2009-03-16 13:47 . 2001-08-17 13:28 899,146 –a–c— c:\windows\system32\dllcache\r2mdkxga.sys
2009-03-16 13:46 . 2008-04-14 05:42 363,520 –a–c— c:\windows\system32\dllcache\psisdecd.dll
2009-03-16 13:45 . 2001-08-17 14:05 351,616 –a–c— c:\windows\system32\dllcache\ovcodek2.sys
2009-03-16 13:44 . 2001-08-17 12:50 198,144 –a–c— c:\windows\system32\dllcache\nv3.sys
2009-03-16 13:44 . 2001-08-17 22:36 123,776 –a–c— c:\windows\system32\dllcache\nv3.dll
2009-03-16 13:44 . 2001-08-17 12:49 51,552 –a–c— c:\windows\system32\dllcache\ntgrip.sys
2009-03-16 13:44 . 2001-08-17 13:47 9,344 –a–c— c:\windows\system32\dllcache\ntapm.sys
2009-03-16 13:44 . 2001-08-17 13:53 7,552 –a–c— c:\windows\system32\dllcache\nsmmc.sys
2009-03-16 13:42 . 2001-08-17 12:50 103,296 –a–c— c:\windows\system32\dllcache\mtxvideo.sys
2009-03-16 13:42 . 2008-04-14 00:16 49,024 –a–c— c:\windows\system32\dllcache\mstape.sys
2009-03-16 13:42 . 2008-04-14 00:24 22,016 –a–c— c:\windows\system32\dllcache\msircomm.sys
2009-03-16 13:42 . 2001-08-17 13:50 21,888 –a–c— c:\windows\system32\dllcache\mxcard.sys
2009-03-16 13:42 . 2001-08-17 13:49 19,968 –a–c— c:\windows\system32\dllcache\mxnic.sys
2009-03-16 13:42 . 2001-08-17 22:36 19,968 –a–c— c:\windows\system32\dllcache\mxicfg.dll
2009-03-16 13:42 . 2001-08-17 13:48 12,416 –a–c— c:\windows\system32\dllcache\msriffwv.sys
2009-03-16 13:42 . 2001-08-17 22:36 7,168 –a–c— c:\windows\system32\dllcache\mxport.dll
2009-03-16 13:42 . 2008-04-14 00:09 5,504 –a–c— c:\windows\system32\dllcache\mstee.sys
2009-03-16 13:42 . 2001-08-17 14:00 2,944 –a–c— c:\windows\system32\dllcache\msmpu401.sys
2009-03-16 13:40 . 2001-08-17 13:28 802,683 –a–c— c:\windows\system32\dllcache\ltsm.sys
2009-03-16 13:39 . 2008-04-14 05:41 253,952 –a–c— c:\windows\system32\dllcache\kdsusd.dll
2009-03-16 13:38 . 2008-04-14 05:41 702,845 –a–c— c:\windows\system32\dllcache\i81xdnt5.dll
2009-03-16 13:37 . 2001-08-17 13:28 542,879 –a–c— c:\windows\system32\dllcache\hsf_msft.sys
2009-03-16 13:36 . 2001-08-17 14:56 1,733,120 –a–c— c:\windows\system32\dllcache\g400d.dll
2009-03-16 13:35 . 2001-08-17 12:15 455,680 –a–c— c:\windows\system32\dllcache\fus2base.sys
2009-03-16 13:34 . 2001-08-17 13:28 634,134 –a–c— c:\windows\system32\dllcache\el656ct5.sys
2009-03-16 13:33 . 2001-08-17 12:14 952,007 –a–c— c:\windows\system32\dllcache\diwan.sys
2009-03-16 13:32 . 2001-08-17 22:36 256,512 –a–c— c:\windows\system32\dllcache\devcon32.dll
2009-03-16 13:31 . 2001-08-17 12:13 980,034 –a–c— c:\windows\system32\dllcache\cicap.sys
2009-03-16 13:30 . 2001-08-17 13:28 871,388 –a–c— c:\windows\system32\dllcache\bcmdm.sys
2009-03-16 13:29 . 2001-08-17 14:55 382,592 –a–c— c:\windows\system32\dllcache\atidrab.dll
2009-03-16 13:28 . 2001-08-17 13:28 762,780 –a–c— c:\windows\system32\dllcache\3cwmcru.sys
2009-03-16 13:27 . 2001-08-17 14:56 66,048 –a–c— c:\windows\system32\dllcache\s3legacy.dll
2009-03-16 12:41 . 2009-03-16 12:41 d——– c:\program files\V44R8C
2009-03-16 12:41 . 2009-03-16 12:41 d——– c:\program files\BCFF1BJHSQ9
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a—— c:\windows\system32\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a–c— c:\windows\system32\dllcache\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a—— c:\windows\system32\kbdkor.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a–c— c:\windows\system32\dllcache\kbdkor.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a—— c:\windows\system32\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a–c— c:\windows\system32\dllcache\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a—— c:\windows\system32\kbd103.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a–c— c:\windows\system32\dllcache\kbd103.dll
2009-03-16 01:56 . 2009-03-16 01:56 d——– c:\program files\RZC6G2C3JDJ
2009-03-16 01:56 . 2009-03-16 01:56 d——– c:\program files\1VH2JLCEEN
2009-03-16 01:47 . 2009-03-16 12:37 1,374 –a—— c:\windows\imsins.BAK
2009-03-15 21:15 . 2009-03-15 21:15 d——– c:\program files\L8Z5MUU6T0SE
2009-03-15 21:15 . 2009-03-15 21:15 d——– c:\program files\HKUTC0T
2009-03-15 21:05 . 2009-03-15 21:05 d——– c:\documents and settings\Administrator
2009-03-15 11:48 . 2009-03-15 11:48 d——– c:\program files\Vuze
2009-03-15 11:48 . 2009-03-16 02:05 d——– c:\documents and settings\Kristy\Application Data\Azureus
2009-03-15 11:48 . 2009-03-15 11:48 d——– c:\documents and settings\All Users\Application Data\Azureus
2009-03-15 03:15 . 2009-03-15 03:15 82 –a—— c:\windows\wininit.ini
2009-03-15 01:52 . 2009-03-15 02:07 d——– c:\program files\Trojan Remover
2009-03-15 01:52 . 2006-05-25 14:52 162,304 –a—— c:\windows\system32\ztvunrar36.dll
2009-03-15 01:52 . 2003-02-02 19:06 153,088 –a—— c:\windows\system32\UNRAR3.dll
2009-03-15 01:52 . 2005-08-26 00:50 77,312 –a—— c:\windows\system32\ztvunace26.dll
2009-03-15 01:52 . 2002-03-06 00:00 75,264 –a—— c:\windows\system32\unacev2.dll
2009-03-15 01:52 . 2006-06-19 12:01 69,632 –a—— c:\windows\system32\ztvcabinet.dll
2009-03-15 01:48 . 2009-03-15 02:08 d——– c:\program files\Registry Winner
2009-03-15 01:48 . 2009-03-15 01:48 d——– c:\documents and settings\Kristy\Application Data\RegistryDefense
2009-03-14 22:28 . 2009-03-14 22:28 69,632 –a—— c:\windows\F50UA5J6F5SG.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 08:51 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-09 23:46 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-09 23:02 9,589,760 —-a-w c:\windows\system32\RTLCPL.EXE
2009-03-09 23:02 204,800 ——w c:\windows\alcrmv.exe
2009-03-09 23:02 143,360 —-a-w c:\windows\SOUNDMAN.EXE
2009-03-08 08:59 ——— d—–w c:\program files\Java
2009-03-08 00:07 ——— d—–w c:\program files\CCleaner
2009-03-08 00:07 ——— d—–w c:\program files\7-Zip
2009-03-08 00:04 ——— d—–w c:\program files\Foxit Software
2009-03-06 19:50 241,664 ——w c:\windows\alcupd.exe
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2008-12-20 23:15 826,368 —-a-w c:\windows\system32\wininet.dll
2008-08-09 13:34 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080920080810\index.dat
.

((((((((((((((((((((((((((((( SnapShot_2009-03-16_16.38.21.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-17 01:06:29 16,384 —-atw c:\windows\temp\Perflib_Perfdata_5b8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-03-08 160592]
"PlaxoSysTray"="c:\program files\Plaxo\3.19.0.16\PlaxoSysTray.exe" [2009-02-09 20480]
"uTorrent"="c:\documents and settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe" [2009-03-07 281392]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\pmremind.exe [2009-03-09 331776]
LUMIX Simple Viewer.lnk - c:\program files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2008-11-04 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.MSNAUDIO"= msnaudio.acm
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GetGoDM]
–a—— 2009-02-11 03:40 3280568 c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
–a—— 2009-02-09 11:08 371271 c:\program files\Plaxo\3.19.0.16\PlaxoHelper_en.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2009-02-04 12:27 23975720 c:\program files\Skype\Phone\Skype.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\eMule Plus\\eMule.exe"=
"c:\\Documents and Settings\\Kristy\\My Documents\\Documents\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

S2 10YX3FD3;10YX3FD3;c:\windows\TJTQZPSRY5T.exe -J2X0DEKU –> c:\windows\TJTQZPSRY5T.exe -J2X0DEKU [?]
S2 19T3H;19T3H;c:\windows\IHC9IIA.exe -AQLU44CEC3UJ –> c:\windows\IHC9IIA.exe -AQLU44CEC3UJ [?]
S2 1Q0PLJK5F7EO;1Q0PLJK5F7EO;c:\windows\ILUJFR.exe -A73PR9ZTP3Q –> c:\windows\ILUJFR.exe -A73PR9ZTP3Q [?]
S2 2XGVZM;2XGVZM;c:\windows\J7PE4TJD.exe -B0D8Q –> c:\windows\J7PE4TJD.exe -B0D8Q [?]
S2 2Z8EHAJGE1;2Z8EHAJGE1;c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP –> c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP [?]
S2 5AX67SALZ;5AX67SALZ;c:\windows\MRG2LUTA629.exe -DDUEXG6H –> c:\windows\MRG2LUTA629.exe -DDUEXG6H [?]
S2 BBCAH;BBCAH;c:\windows\1R34WHI.exe -REG646GTN16P –> c:\windows\1R34WHI.exe -REG646GTN16P [?]
S2 D0V37G51X3;D0V37G51X3;c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ –> c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ [?]
S2 FGCN9QYV;FGCN9QYV;c:\windows\3X45UPLE8B.exe -UJAI5JF –> c:\windows\3X45UPLE8B.exe -UJAI5JF [?]
S2 GAY2F;GAY2F;c:\windows\4OIW0C0.exe -WBVYPWKID628 –> c:\windows\4OIW0C0.exe -WBVYPWKID628 [?]
S2 H0PC5IV3;H0PC5IV3;c:\windows\YYT6FQVUUD.exe -OK6IRIO –> c:\windows\YYT6FQVUUD.exe -OK6IRIO [?]
S2 H76MC;H76MC;c:\windows\5HQIYDY.exe -X83ZZL7VQJLS –> c:\windows\5HQIYDY.exe -X83ZZL7VQJLS [?]
S2 L69Y08;L69Y08;c:\windows\9GTTF99O.exe -196QP –> c:\windows\9GTTF99O.exe -196QP [?]
S2 MPJ5MST1U93;MPJ5MST1U93;c:\windows\6Z8VQ.exe -2QGBD1K9XL –> c:\windows\6Z8VQ.exe -2QGBD1K9XL [?]
S2 NU5S59GVTK5;NU5S59GVTK5;c:\windows\PMKYK.exe -3X45UPLE8B –> c:\windows\PMKYK.exe -3X45UPLE8B [?]
S2 PXNMBMJR;PXNMBMJR;c:\windows\98UBG40EEE.exe -4YKLBSH –> c:\windows\98UBG40EEE.exe -4YKLBSH [?]
S2 R9I2V5;R9I2V5;c:\windows\I8V5ZLII.exe -7FLLY –> c:\windows\I8V5ZLII.exe -7FLLY [?]
S2 TERDNO1D5;TERDNO1D5;c:\windows\CVBOD9AX78UD.exe -HOQE73D8L –> c:\windows\CVBOD9AX78UD.exe -HOQE73D8L [?]
S2 U20Z2HUA;U20Z2HUA;c:\windows\BM4EE5V9PE.exe -3ZHOS879 –> c:\windows\BM4EE5V9PE.exe -3ZHOS879 [?]
S2 UJB973P1O;UJB973P1O;c:\windows\DZ24L36PZCJ.exe -KHVJVK5M –> c:\windows\DZ24L36PZCJ.exe -KHVJVK5M [?]
S2 UNGVG2LBWEL;UNGVG2LBWEL;c:\windows\B276A.exe -ODIM38SNRI –> c:\windows\B276A.exe -ODIM38SNRI [?]
S2 Y2EN4QW5889;Y2EN4QW5889;c:\windows\FC596.exe -5BMEKWTTJ5 –> c:\windows\FC596.exe -5BMEKWTTJ5 [?]
S2 YTMP1NBHT2;YTMP1NBHT2;c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB –> c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB [?]
S2 ZGC2AK;ZGC2AK;c:\windows\HW2VWLUR.exe -H67JL –> c:\windows\HW2VWLUR.exe -H67JL [?]
S2 ZO48L;ZO48L;c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU –> c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU [?]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys –> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S4 08FX8JFV;08FX8JFV;c:\windows\IH6RNKYKZ0.exe -CZ7LF5R –> c:\windows\IH6RNKYKZ0.exe -CZ7LF5R [?]
S4 1MV0BLHXE;1MV0BLHXE;c:\windows\I3ETXM0MNZS.exe -PR79NGT9 –> c:\windows\I3ETXM0MNZS.exe -PR79NGT9 [?]
S4 2NXBWF;2NXBWF;c:\windows\J3GBGKSA.exe -BQUON –> c:\windows\J3GBGKSA.exe -BQUON [?]
S4 2O1L3;2O1L3;c:\windows\XAVRLDW.exe -M3N189R55ALV –> c:\windows\XAVRLDW.exe -M3N189R55ALV [?]
S4 3GJ665NT766;3GJ665NT766;c:\windows\LKZA4.exe -CTKCPFB64F –> c:\windows\LKZA4.exe -CTKCPFB64F [?]
S4 3Q3BVMFQZTJ;3Q3BVMFQZTJ;c:\windows\K7NAN.exe -BR0QMKHWMT –> c:\windows\K7NAN.exe -BR0QMKHWMT [?]
S4 4B5HRB6B9;4B5HRB6B9;c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ –> c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ [?]
S4 5ZHFDU4;5ZHFDU4;c:\windows\O7TEQDAQJ.exe -E0DS20 –> c:\windows\O7TEQDAQJ.exe -E0DS20 [?]
S4 8IT5Y44;8IT5Y44;c:\windows\PWD8KYGTP.exe -GJQKUE –> c:\windows\PWD8KYGTP.exe -GJQKUE [?]
S4 ADA2EG1;ADA2EG1;c:\windows\YT1X0GD7P.exe -QE361V –> c:\windows\YT1X0GD7P.exe -QE361V [?]
S4 BPYV25IQ;BPYV25IQ;c:\windows\14H3H0Y1RNH.exe -RQVMLG86 –> c:\windows\14H3H0Y1RNH.exe -RQVMLG86 [?]
S4 BQAGVE30;BQAGVE30;c:\windows\ZOA2WXS1BF.exe -RANNAKM –> c:\windows\ZOA2WXS1BF.exe -RANNAKM [?]
S4 CMUODPSJO8DW;CMUODPSJO8DW;c:\windows\23DIZQ.exe -SQR19Y93WQS –> c:\windows\23DIZQ.exe -SQR19Y93WQS [?]
S4 D9XBL1I9PX;D9XBL1I9PX;c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L –> c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L [?]
S4 DULWFJE;DULWFJE;c:\windows\4Q0MXNJ9F.exe -TXI97K –> c:\windows\4Q0MXNJ9F.exe -TXI97K [?]
S4 FEK1UEF;FEK1UEF;c:\windows\3VUMPGTGW.exe -VFHLTB –> c:\windows\3VUMPGTGW.exe -VFHLTB [?]
S4 H0252AAY6QPU;H0252AAY6QPU;c:\windows\5MZHQ6.exe -W3ZBRSF05CN –> c:\windows\5MZHQ6.exe -W3ZBRSF05CN [?]
S4 HC5IOVVW3;HC5IOVVW3;c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS –> c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS [?]
S4 IC56FJ2OJE;IC56FJ2OJE;c:\windows\9SP00JBDUZJ0.exe -YF2C670NL –> c:\windows\9SP00JBDUZJ0.exe -YF2C670NL [?]
S4 II9TFZ;II9TFZ;c:\windows\6YY3H4PB.exe -YLFI2 –> c:\windows\6YY3H4PB.exe -YLFI2 [?]
S4 J1GCP0;J1GCP0;c:\windows\9LKVE6PM.exe -YXS5Z –> c:\windows\9LKVE6PM.exe -YXS5Z [?]
S4 J33FQ1F;J33FQ1F;c:\windows\WXNZ1SB24.exe -OK0B75 –> c:\windows\WXNZ1SB24.exe -OK0B75 [?]
S4 LHFUA;LHFUA;c:\windows\WUAA71E.exe -1I8UJXUVI7F6 –> c:\windows\WUAA71E.exe -1I8UJXUVI7F6 [?]
S4 LTQLZP2FX6;LTQLZP2FX6;c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA –> c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA [?]
S4 MUAL22T09A;MUAL22T09A;c:\windows\1HH5P.exe -2VYRJYKRXN –> c:\windows\1HH5P.exe -2VYRJYKRXN [?]
S4 NBG7GOASD1KS;NBG7GOASD1KS;c:\windows\T31TZW.exe -JQK3SOQXCMO –> c:\windows\T31TZW.exe -JQK3SOQXCMO [?]
S4 RO3SKV;RO3SKV;c:\windows\2NNPM3AS8.exe -7P05Z7 –> c:\windows\2NNPM3AS8.exe -7P05Z7 [?]
S4 ROO5X4F;ROO5X4F;c:\windows\40UYFPMNI.exe -7RLA4D –> c:\windows\40UYFPMNI.exe -7RLA4D [?]
S4 SQFAY;SQFAY;c:\windows\B56DIMNM.exe -8RCNP –> c:\windows\B56DIMNM.exe -8RCNP [?]
S4 VMAJ4WFY;VMAJ4WFY;c:\windows\C009543J07.exe -NLK1XNBF –> c:\windows\C009543J07.exe -NLK1XNBF [?]
S4 W42CWKTK7;W42CWKTK7;c:\windows\EELB1IVL92C.exe -5ZPNRQCZ –> c:\windows\EELB1IVL92C.exe -5ZPNRQCZ [?]
S4 YT92TP;YT92TP;c:\windows\G9Z2U3LI.exe -UE5IC –> c:\windows\G9Z2U3LI.exe -UE5IC [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - 2XGVZM
*NewlyCreated* - FGCN9QYV
*NewlyCreated* - NU5S59GVTK5
*NewlyCreated* - UJB973P1O
*Deregistered* - PROCEXP113
.
Contents of the 'Scheduled Tasks' folder

2009-03-15 c:\windows\Tasks\Registry Winner Schedule.job
- c:\program files\Registry Winner\RegistryWinner.exe []
.
.
——- Supplementary Scan ——-
.
IE: &Down&load &Link& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatch.htm
IE: &Down&load All &Links& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
IE: &GetGo Toolbar Search - c:\program files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{01A13E40-2F55-4397-B39B-7851BCFB8008} - c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe
TCP: {9ECC1FB7-D0B6-463E-99BE-7563CC59E2CB} = 65.240.162.65 65.240.162.66
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - component: c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\extensions\[removed]\platform\WINNT_x86-msvc\components\lpxpcom.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-16 20:17:32
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-16 20:19:39
ComboFix-quarantined-files.txt 2009-03-17 01:19:20
ComboFix2.txt 2009-03-17 01:03:46
ComboFix3.txt 2009-03-16 23:25:47
ComboFix4.txt 2009-03-16 21:39:42
ComboFix5.txt 2009-03-17 01:13:57

Pre-Run: 43,330,379,776 bytes free
Post-Run: 43,316,527,104 bytes free

297 — E O F — 2009-03-09 21:51:30


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:20:29 PM, on 3/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\J7PE4TJD.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\WINDOWS\system32\wscntfy.exe
C:\ProcessExplorer\procexp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\J7PE4TJD.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\J7PE4TJD.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\J7PE4TJD.exe
C:\WINDOWS\J7PE4TJD.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://test.catalog.update.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: GetGo URL Catcher (dont remove!) - {0315AA2C-10C7-4504-A1C4-F552ABA8A095} - C:\Program Files\GetGo Software\GetGo Download Manager\URLCatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: GetGo Toolbar - {075BBE29-FEC0-404a-A459-FF58713616FA} - C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe"
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O8 - Extra context menu item: &Down&load &Link& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatch.htm
O8 - Extra context menu item: &Down&load All &Links& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
O8 - Extra context menu item: &GetGo Toolbar Search - res://C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: GetGo - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra 'Tools' menuitem: GetGo Download Manager - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://test.catalog.update.microsoft.com/v…b?1236661267875
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1218290032265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ECC1FB7-D0B6-463E-99BE-7563CC59E2CB}: NameServer = 65.240.162.65 65.240.162.66
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: 10YX3FD3 - Unknown owner - C:\WINDOWS\TJTQZPSRY5T.exe (file missing)
O23 - Service: 19T3H - Unknown owner - C:\WINDOWS\IHC9IIA.exe (file missing)
O23 - Service: 1Q0PLJK5F7EO - Unknown owner - C:\WINDOWS\ILUJFR.exe (file missing)
O23 - Service: 2XGVZM - ???? - C:\WINDOWS\J7PE4TJD.exe
O23 - Service: 2Z8EHAJGE1 - Unknown owner - C:\WINDOWS\LS3A0NEFDUJ3.exe (file missing)
O23 - Service: 5AX67SALZ - Unknown owner - C:\WINDOWS\MRG2LUTA629.exe (file missing)
O23 - Service: BBCAH - Unknown owner - C:\WINDOWS\1R34WHI.exe (file missing)
O23 - Service: D0V37G51X3 - Unknown owner - C:\WINDOWS\3AF9ILF5N53S.exe (file missing)
O23 - Service: FGCN9QYV - Unknown owner - C:\WINDOWS\3X45UPLE8B.exe (file missing)
O23 - Service: GAY2F - Unknown owner - C:\WINDOWS\4OIW0C0.exe (file missing)
O23 - Service: H0PC5IV3 - Unknown owner - C:\WINDOWS\YYT6FQVUUD.exe (file missing)
O23 - Service: H76MC - Unknown owner - C:\WINDOWS\5HQIYDY.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: L69Y08 - Unknown owner - C:\WINDOWS\9GTTF99O.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MPJ5MST1U93 - Unknown owner - C:\WINDOWS\6Z8VQ.exe (file missing)
O23 - Service: NU5S59GVTK5 - Unknown owner - C:\WINDOWS\PMKYK.exe (file missing)
O23 - Service: PXNMBMJR - Unknown owner - C:\WINDOWS\98UBG40EEE.exe (file missing)
O23 - Service: R9I2V5 - Unknown owner - C:\WINDOWS\I8V5ZLII.exe (file missing)
O23 - Service: TERDNO1D5 - Unknown owner - C:\WINDOWS\CVBOD9AX78UD.exe (file missing)
O23 - Service: U20Z2HUA - ???? - C:\WINDOWS\BM4EE5V9PE.exe
O23 - Service: UJB973P1O - Unknown owner - C:\WINDOWS\DZ24L36PZCJ.exe (file missing)
O23 - Service: UNGVG2LBWEL - Unknown owner - C:\WINDOWS\B276A.exe (file missing)
O23 - Service: Y2EN4QW5889 - Unknown owner - C:\WINDOWS\FC596.exe (file missing)
O23 - Service: YTMP1NBHT2 - Unknown owner - C:\WINDOWS\ZCHSCNE8H0QU.exe (file missing)
O23 - Service: ZGC2AK - Unknown owner - C:\WINDOWS\HW2VWLUR.exe (file missing)
O23 - Service: ZO48L - Unknown owner - C:\WINDOWS\XZPMNYK.exe (file missing)

–
End of file - 9432 bytes
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\BM4EE5V9PE.exe
c:\windows\J7PE4TJD.exe
c:\windows\IOPXQWM8M.exe
c:\windows\F50UA5J6F5SG.exe

Folder::
c:\program files\QDN7B44A7
c:\program files\YB8PB7N
c:\program files\V44R8C
c:\program files\BCFF1BJHSQ9
c:\program files\RZC6G2C3JDJ
c:\program files\1VH2JLCEEN
c:\program files\L8Z5MUU6T0SE
c:\program files\HKUTC0T


Driver::
2XGVZM
FGCN9QYV
NU5S59GVTK5
UJB973P1O
PROCEXP113

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 0 (0x0)

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Well, I thought the task manager stayed open, till I tried to open it and flashed open and the closed, some programs I still can't install like the anti-virus or some security programs and the "Help & Support" in the start menu, don't come up. And it's back again, the ??????? in my process manager *SIGH* I close them but every once in awhile they pop right back up. They are like 2 files but in a group of like 3 or 4. They keep closing and re-opening.

It sometimes keeps going to IE and it opens up (several times) a site called baidu.com. That's where the language (Chinese simplified) comes in.

I would forgot my head if it wasn't attached but every time I go to install a program, it creates a .tmp file… Is it supposed to do that? Sorry, about that, though I think that's all that I'm forgetting…

This is a tough little bugger…

ComboFix 09-03-15.01 - Kristy 2009-03-16 23:28:34.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.155 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kristy\Desktop\CFScript.txt
* Created a new restore point

FILE ::
c:\windows\BM4EE5V9PE.exe
c:\windows\F50UA5J6F5SG.exe
c:\windows\IOPXQWM8M.exe
c:\windows\J7PE4TJD.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\1VH2JLCEEN
c:\program files\1VH2JLCEEN\RZC6G2C3JDJ.exe
c:\program files\BCFF1BJHSQ9
c:\program files\BCFF1BJHSQ9\6IAG3VXIBMY.exe
c:\program files\HKUTC0T
c:\program files\HKUTC0T\OO5ZWDM.exe
c:\program files\L8Z5MUU6T0SE
c:\program files\L8Z5MUU6T0SE\7MGGMK5YH0V6.exe
c:\program files\QDN7B44A7
c:\program files\QDN7B44A7\GHHCZ0Q9SR.exe
c:\program files\RZC6G2C3JDJ
c:\program files\RZC6G2C3JDJ\F2LPCO7JVOK.exe
c:\program files\V44R8C
c:\program files\V44R8C\4Z0BAT.exe
c:\program files\YB8PB7N
c:\program files\YB8PB7N\OF43Z3S.exe
c:\windows\BM4EE5V9PE.exe
c:\windows\F50UA5J6F5SG.exe
c:\windows\IOPXQWM8M.exe
c:\windows\J7PE4TJD.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_2XGVZM
——-\Legacy_FGCN9QYV
——-\Legacy_NU5S59GVTK5
——-\Legacy_PROCEXP113
——-\Legacy_UJB973P1O
——-\Service_2XGVZM
——-\Service_FGCN9QYV
——-\Service_NU5S59GVTK5
——-\Service_UJB973P1O


((((((((((((((((((((((((( Files Created from 2009-02-17 to 2009-03-17 )))))))))))))))))))))))))))))))
.

2009-03-16 13:59 . 2008-04-14 05:42 116,224 –a–c— c:\windows\system32\dllcache\xrxwiadr.dll
2009-03-16 13:59 . 2001-08-17 22:37 99,865 –a–c— c:\windows\system32\dllcache\xlog.exe
2009-03-16 13:59 . 2001-08-17 22:37 27,648 –a–c— c:\windows\system32\dllcache\xrxftplt.exe
2009-03-16 13:59 . 2001-08-17 22:36 23,040 –a–c— c:\windows\system32\dllcache\xrxwbtmp.dll
2009-03-16 13:59 . 2008-04-13 22:04 19,455 –a–c— c:\windows\system32\dllcache\wvchntxx.sys
2009-03-16 13:59 . 2008-04-14 00:16 19,200 –a–c— c:\windows\system32\dllcache\wstcodec.sys
2009-03-16 13:59 . 2008-04-14 05:42 18,944 –a–c— c:\windows\system32\dllcache\xrxscnui.dll
2009-03-16 13:59 . 2001-08-17 12:11 16,970 –a–c— c:\windows\system32\dllcache\xem336n5.sys
2009-03-16 13:59 . 2008-04-13 22:04 12,063 –a–c— c:\windows\system32\dllcache\wsiintxx.sys
2009-03-16 13:59 . 2008-04-14 05:42 8,192 –a–c— c:\windows\system32\dllcache\wshirda.dll
2009-03-16 13:59 . 2001-08-17 22:37 4,608 –a–c— c:\windows\system32\dllcache\xrxflnch.exe
2009-03-16 13:57 . 2001-08-17 13:28 794,654 –a–c— c:\windows\system32\dllcache\usr1801.sys
2009-03-16 13:56 . 2001-08-17 22:36 525,568 –a–c— c:\windows\system32\dllcache\tridxp.dll
2009-03-16 13:55 . 2001-08-17 14:01 241,664 –a–c— c:\windows\system32\dllcache\tosdvd02.sys
2009-03-16 13:54 . 2001-08-17 12:18 285,760 –a–c— c:\windows\system32\dllcache\stlnata.sys
2009-03-16 13:53 . 2001-08-17 22:36 114,688 –a–c— c:\windows\system32\dllcache\sonypi.dll
2009-03-16 13:53 . 2001-08-17 22:36 106,584 –a–c— c:\windows\system32\dllcache\spdports.dll
2009-03-16 13:53 . 2001-08-17 22:36 99,328 –a–c— c:\windows\system32\dllcache\srusd.dll
2009-03-16 13:53 . 2001-08-17 13:51 61,824 –a–c— c:\windows\system32\dllcache\speed.sys
2009-03-16 13:53 . 2001-08-17 12:51 37,040 –a–c— c:\windows\system32\dllcache\sonypi.sys
2009-03-16 13:53 . 2001-08-17 22:36 24,660 –a–c— c:\windows\system32\dllcache\spxupchk.dll
2009-03-16 13:53 . 2001-08-17 12:51 20,752 –a–c— c:\windows\system32\dllcache\sonync.sys
2009-03-16 13:53 . 2001-08-17 14:07 19,072 –a–c— c:\windows\system32\dllcache\sparrow.sys
2009-03-16 13:53 . 2001-08-17 13:53 9,600 –a–c— c:\windows\system32\dllcache\sonymc.sys
2009-03-16 13:53 . 2001-08-17 13:56 7,552 –a–c— c:\windows\system32\dllcache\sonypvu1.sys
2009-03-16 13:53 . 2008-04-14 00:10 7,552 –a–c— c:\windows\system32\dllcache\sonyait.sys
2009-03-16 13:53 . 2001-08-17 13:53 7,040 –a–c— c:\windows\system32\dllcache\snyaitmc.sys
2009-03-16 13:51 . 2001-08-17 22:36 386,560 –a–c— c:\windows\system32\dllcache\sgiul50.dll
2009-03-16 13:51 . 2001-08-17 14:56 252,032 –a–c— c:\windows\system32\dllcache\sis300iv.dll
2009-03-16 13:51 . 2001-08-17 22:36 238,592 –a–c— c:\windows\system32\dllcache\sisgrv.dll
2009-03-16 13:51 . 2001-07-21 14:29 161,568 –a–c— c:\windows\system32\dllcache\sgsmusb.sys
2009-03-16 13:51 . 2001-08-17 14:56 150,144 –a–c— c:\windows\system32\dllcache\sis6306v.dll
2009-03-16 13:51 . 2001-08-17 12:50 104,064 –a–c— c:\windows\system32\dllcache\sisgrp.sys
2009-03-16 13:51 . 2001-08-17 12:50 101,760 –a–c— c:\windows\system32\dllcache\sis300ip.sys
2009-03-16 13:51 . 2001-08-17 12:51 98,080 –a–c— c:\windows\system32\dllcache\sgiulnt5.sys
2009-03-16 13:51 . 2001-08-17 12:50 68,608 –a–c— c:\windows\system32\dllcache\sis6306p.sys
2009-03-16 13:51 . 2001-08-17 12:19 36,480 –a–c— c:\windows\system32\dllcache\sfmanm.sys
2009-03-16 13:51 . 2001-07-21 14:29 18,400 –a–c— c:\windows\system32\dllcache\sgsmld.sys
2009-03-16 13:51 . 2001-08-17 13:48 17,664 –a–c— c:\windows\system32\dllcache\sermouse.sys
2009-03-16 13:51 . 2001-08-17 13:53 6,784 –a–c— c:\windows\system32\dllcache\serscan.sys
2009-03-16 13:50 . 2001-08-17 13:52 11,648 –a–c— c:\windows\system32\dllcache\scsiprnt.sys
2009-03-16 13:50 . 2008-04-14 00:15 11,520 –a–c— c:\windows\system32\dllcache\scsiscan.sys
2009-03-16 13:50 . 2001-08-17 13:53 6,912 –a–c— c:\windows\system32\dllcache\seaddsmc.sys
2009-03-16 13:49 . 2001-08-17 22:36 495,616 –a–c— c:\windows\system32\dllcache\sblfx.dll
2009-03-16 13:49 . 2001-08-17 14:56 245,632 –a–c— c:\windows\system32\dllcache\s3savmx.dll
2009-03-16 13:49 . 2001-08-17 14:56 198,400 –a–c— c:\windows\system32\dllcache\s3sav4.dll
2009-03-16 13:49 . 2001-08-17 14:56 179,264 –a–c— c:\windows\system32\dllcache\s3sav3d.dll
2009-03-16 13:49 . 2001-08-17 12:50 77,824 –a–c— c:\windows\system32\dllcache\s3sav4m.sys
2009-03-16 13:49 . 2001-08-17 12:50 75,392 –a–c— c:\windows\system32\dllcache\s3savmxm.sys
2009-03-16 13:49 . 2001-08-17 12:50 61,504 –a–c— c:\windows\system32\dllcache\s3sav3dm.sys
2009-03-16 13:49 . 2008-04-14 00:10 43,904 –a–c— c:\windows\system32\dllcache\sbp2port.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmusbm.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmn50m.sys
2009-03-16 13:49 . 2001-08-17 13:51 17,280 –a–c— c:\windows\system32\dllcache\scr111.sys
2009-03-16 13:49 . 2001-08-17 13:51 16,640 –a–c— c:\windows\system32\dllcache\scmstcs.sys
2009-03-16 13:47 . 2001-08-17 13:28 899,146 –a–c— c:\windows\system32\dllcache\r2mdkxga.sys
2009-03-16 13:46 . 2008-04-14 05:42 363,520 –a–c— c:\windows\system32\dllcache\psisdecd.dll
2009-03-16 13:45 . 2001-08-17 14:05 351,616 –a–c— c:\windows\system32\dllcache\ovcodek2.sys
2009-03-16 13:44 . 2001-08-17 12:50 198,144 –a–c— c:\windows\system32\dllcache\nv3.sys
2009-03-16 13:44 . 2001-08-17 22:36 123,776 –a–c— c:\windows\system32\dllcache\nv3.dll
2009-03-16 13:44 . 2001-08-17 12:49 51,552 –a–c— c:\windows\system32\dllcache\ntgrip.sys
2009-03-16 13:44 . 2001-08-17 13:47 9,344 –a–c— c:\windows\system32\dllcache\ntapm.sys
2009-03-16 13:44 . 2001-08-17 13:53 7,552 –a–c— c:\windows\system32\dllcache\nsmmc.sys
2009-03-16 13:42 . 2001-08-17 12:50 103,296 –a–c— c:\windows\system32\dllcache\mtxvideo.sys
2009-03-16 13:42 . 2008-04-14 00:16 49,024 –a–c— c:\windows\system32\dllcache\mstape.sys
2009-03-16 13:42 . 2008-04-14 00:24 22,016 –a–c— c:\windows\system32\dllcache\msircomm.sys
2009-03-16 13:42 . 2001-08-17 13:50 21,888 –a–c— c:\windows\system32\dllcache\mxcard.sys
2009-03-16 13:42 . 2001-08-17 13:49 19,968 –a–c— c:\windows\system32\dllcache\mxnic.sys
2009-03-16 13:42 . 2001-08-17 22:36 19,968 –a–c— c:\windows\system32\dllcache\mxicfg.dll
2009-03-16 13:42 . 2001-08-17 13:48 12,416 –a–c— c:\windows\system32\dllcache\msriffwv.sys
2009-03-16 13:42 . 2001-08-17 22:36 7,168 –a–c— c:\windows\system32\dllcache\mxport.dll
2009-03-16 13:42 . 2008-04-14 00:09 5,504 –a–c— c:\windows\system32\dllcache\mstee.sys
2009-03-16 13:42 . 2001-08-17 14:00 2,944 –a–c— c:\windows\system32\dllcache\msmpu401.sys
2009-03-16 13:40 . 2001-08-17 13:28 802,683 –a–c— c:\windows\system32\dllcache\ltsm.sys
2009-03-16 13:39 . 2008-04-14 05:41 253,952 –a–c— c:\windows\system32\dllcache\kdsusd.dll
2009-03-16 13:38 . 2008-04-14 05:41 702,845 –a–c— c:\windows\system32\dllcache\i81xdnt5.dll
2009-03-16 13:37 . 2001-08-17 13:28 542,879 –a–c— c:\windows\system32\dllcache\hsf_msft.sys
2009-03-16 13:36 . 2001-08-17 14:56 1,733,120 –a–c— c:\windows\system32\dllcache\g400d.dll
2009-03-16 13:35 . 2001-08-17 12:15 455,680 –a–c— c:\windows\system32\dllcache\fus2base.sys
2009-03-16 13:34 . 2001-08-17 13:28 634,134 –a–c— c:\windows\system32\dllcache\el656ct5.sys
2009-03-16 13:33 . 2001-08-17 12:14 952,007 –a–c— c:\windows\system32\dllcache\diwan.sys
2009-03-16 13:32 . 2001-08-17 22:36 256,512 –a–c— c:\windows\system32\dllcache\devcon32.dll
2009-03-16 13:31 . 2001-08-17 12:13 980,034 –a–c— c:\windows\system32\dllcache\cicap.sys
2009-03-16 13:30 . 2001-08-17 13:28 871,388 –a–c— c:\windows\system32\dllcache\bcmdm.sys
2009-03-16 13:29 . 2001-08-17 14:55 382,592 –a–c— c:\windows\system32\dllcache\atidrab.dll
2009-03-16 13:28 . 2001-08-17 13:28 762,780 –a–c— c:\windows\system32\dllcache\3cwmcru.sys
2009-03-16 13:27 . 2001-08-17 14:56 66,048 –a–c— c:\windows\system32\dllcache\s3legacy.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a—— c:\windows\system32\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a–c— c:\windows\system32\dllcache\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a—— c:\windows\system32\kbdkor.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a–c— c:\windows\system32\dllcache\kbdkor.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a—— c:\windows\system32\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a–c— c:\windows\system32\dllcache\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a—— c:\windows\system32\kbd103.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a–c— c:\windows\system32\dllcache\kbd103.dll
2009-03-16 01:47 . 2009-03-16 12:37 1,374 –a—— c:\windows\imsins.BAK
2009-03-15 21:05 . 2009-03-15 21:05 d——– c:\documents and settings\Administrator
2009-03-15 11:48 . 2009-03-15 11:48 d——– c:\program files\Vuze
2009-03-15 11:48 . 2009-03-16 02:05 d——– c:\documents and settings\Kristy\Application Data\Azureus
2009-03-15 11:48 . 2009-03-15 11:48 d——– c:\documents and settings\All Users\Application Data\Azureus
2009-03-15 03:15 . 2009-03-15 03:15 82 –a—— c:\windows\wininit.ini
2009-03-15 01:52 . 2009-03-15 02:07 d——– c:\program files\Trojan Remover
2009-03-15 01:52 . 2006-05-25 14:52 162,304 –a—— c:\windows\system32\ztvunrar36.dll
2009-03-15 01:52 . 2003-02-02 19:06 153,088 –a—— c:\windows\system32\UNRAR3.dll
2009-03-15 01:52 . 2005-08-26 00:50 77,312 –a—— c:\windows\system32\ztvunace26.dll
2009-03-15 01:52 . 2002-03-06 00:00 75,264 –a—— c:\windows\system32\unacev2.dll
2009-03-15 01:52 . 2006-06-19 12:01 69,632 –a—— c:\windows\system32\ztvcabinet.dll
2009-03-15 01:48 . 2009-03-15 02:08 d——– c:\program files\Registry Winner
2009-03-15 01:48 . 2009-03-15 01:48 d——– c:\documents and settings\Kristy\Application Data\RegistryDefense
2009-03-14 22:28 . 2009-03-14 22:28 69,632 –a—— c:\windows\DHJPOEG7.exe
2009-03-14 22:27 . 2009-03-14 22:27 69,632 –a—— c:\windows\JVTR854F.exe
2009-03-14 21:42 . 2009-03-14 21:42 d——– c:\program files\Belarc
2009-03-14 21:42 . 2008-02-27 13:49 3,840 –a—— c:\windows\system32\drivers\BANTExt.sys
2009-03-14 21:40 . 2009-03-14 21:40 69,632 -r-hs—- c:\windows\H7YBMEH1N.exe
2009-03-14 21:39 . 2009-03-14 21:39 69,632 -r-hs—- c:\windows\CNM41P.exe
2009-03-14 21:13 . 2009-03-14 21:13 69,632 –a—— c:\windows\WFAXPHNL.exe
2009-03-14 21:13 . 2009-03-14 21:13 69,632 -r-hs—- c:\windows\JDDAHCI7WSG.exe
2009-03-14 21:13 . 2009-03-14 21:13 69,632 –a—— c:\windows\BCNONNB8.exe
2009-03-14 21:08 . 2009-03-14 21:08 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-14 21:08 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-14 21:08 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 08:51 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-09 23:46 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-09 23:02 204,800 ——w c:\windows\alcrmv.exe
2009-03-09 23:02 143,360 —-a-w c:\windows\SOUNDMAN.EXE
2009-03-08 08:59 ——— d—–w c:\program files\Java
2009-03-08 00:07 ——— d—–w c:\program files\CCleaner
2009-03-08 00:07 ——— d—–w c:\program files\7-Zip
2009-03-08 00:04 ——— d—–w c:\program files\Foxit Software
2009-03-06 19:50 241,664 ——w c:\windows\alcupd.exe
2008-08-09 13:34 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080920080810\index.dat
.

((((((((((((((((((((((((((((( SnapShot_2009-03-16_16.38.21.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
+ 2009-03-17 04:32:32 16,384 —-atw c:\windows\temp\Perflib_Perfdata_588.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-03-08 160592]
"PlaxoSysTray"="c:\program files\Plaxo\3.19.0.16\PlaxoSysTray.exe" [2009-02-09 20480]
"uTorrent"="c:\documents and settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe" [2009-03-07 281392]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\pmremind.exe [2009-03-09 331776]
LUMIX Simple Viewer.lnk - c:\program files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2008-11-04 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.MSNAUDIO"= msnaudio.acm
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GetGoDM]
–a—— 2009-02-11 03:40 3280568 c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
–a—— 2009-02-09 11:08 371271 c:\program files\Plaxo\3.19.0.16\PlaxoHelper_en.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2009-02-04 12:27 23975720 c:\program files\Skype\Phone\Skype.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\eMule Plus\\eMule.exe"=
"c:\\Documents and Settings\\Kristy\\My Documents\\Documents\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

S2 10YX3FD3;10YX3FD3;c:\windows\TJTQZPSRY5T.exe -J2X0DEKU –> c:\windows\TJTQZPSRY5T.exe -J2X0DEKU [?]
S2 19T3H;19T3H;c:\windows\IHC9IIA.exe -AQLU44CEC3UJ –> c:\windows\IHC9IIA.exe -AQLU44CEC3UJ [?]
S2 1Q0PLJK5F7EO;1Q0PLJK5F7EO;c:\windows\ILUJFR.exe -A73PR9ZTP3Q –> c:\windows\ILUJFR.exe -A73PR9ZTP3Q [?]
S2 2Z8EHAJGE1;2Z8EHAJGE1;c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP –> c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP [?]
S2 5AX67SALZ;5AX67SALZ;c:\windows\MRG2LUTA629.exe -DDUEXG6H –> c:\windows\MRG2LUTA629.exe -DDUEXG6H [?]
S2 BBCAH;BBCAH;c:\windows\1R34WHI.exe -REG646GTN16P –> c:\windows\1R34WHI.exe -REG646GTN16P [?]
S2 D0V37G51X3;D0V37G51X3;c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ –> c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ [?]
S2 GAY2F;GAY2F;c:\windows\4OIW0C0.exe -WBVYPWKID628 –> c:\windows\4OIW0C0.exe -WBVYPWKID628 [?]
S2 H0PC5IV3;H0PC5IV3;c:\windows\YYT6FQVUUD.exe -OK6IRIO –> c:\windows\YYT6FQVUUD.exe -OK6IRIO [?]
S2 H76MC;H76MC;c:\windows\5HQIYDY.exe -X83ZZL7VQJLS –> c:\windows\5HQIYDY.exe -X83ZZL7VQJLS [?]
S2 L69Y08;L69Y08;c:\windows\9GTTF99O.exe -196QP –> c:\windows\9GTTF99O.exe -196QP [?]
S2 MPJ5MST1U93;MPJ5MST1U93;c:\windows\6Z8VQ.exe -2QGBD1K9XL –> c:\windows\6Z8VQ.exe -2QGBD1K9XL [?]
S2 PXNMBMJR;PXNMBMJR;c:\windows\98UBG40EEE.exe -4YKLBSH –> c:\windows\98UBG40EEE.exe -4YKLBSH [?]
S2 R9I2V5;R9I2V5;c:\windows\I8V5ZLII.exe -7FLLY –> c:\windows\I8V5ZLII.exe -7FLLY [?]
S2 TERDNO1D5;TERDNO1D5;c:\windows\CVBOD9AX78UD.exe -HOQE73D8L –> c:\windows\CVBOD9AX78UD.exe -HOQE73D8L [?]
S2 U20Z2HUA;U20Z2HUA;c:\windows\BM4EE5V9PE.exe -3ZHOS879 –> c:\windows\BM4EE5V9PE.exe -3ZHOS879 [?]
S2 UNGVG2LBWEL;UNGVG2LBWEL;c:\windows\B276A.exe -ODIM38SNRI –> c:\windows\B276A.exe -ODIM38SNRI [?]
S2 Y2EN4QW5889;Y2EN4QW5889;c:\windows\FC596.exe -5BMEKWTTJ5 –> c:\windows\FC596.exe -5BMEKWTTJ5 [?]
S2 YTMP1NBHT2;YTMP1NBHT2;c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB –> c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB [?]
S2 ZGC2AK;ZGC2AK;c:\windows\HW2VWLUR.exe -H67JL –> c:\windows\HW2VWLUR.exe -H67JL [?]
S2 ZO48L;ZO48L;c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU –> c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU [?]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys –> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S4 08FX8JFV;08FX8JFV;c:\windows\IH6RNKYKZ0.exe -CZ7LF5R –> c:\windows\IH6RNKYKZ0.exe -CZ7LF5R [?]
S4 1MV0BLHXE;1MV0BLHXE;c:\windows\I3ETXM0MNZS.exe -PR79NGT9 –> c:\windows\I3ETXM0MNZS.exe -PR79NGT9 [?]
S4 2NXBWF;2NXBWF;c:\windows\J3GBGKSA.exe -BQUON –> c:\windows\J3GBGKSA.exe -BQUON [?]
S4 2O1L3;2O1L3;c:\windows\XAVRLDW.exe -M3N189R55ALV –> c:\windows\XAVRLDW.exe -M3N189R55ALV [?]
S4 3GJ665NT766;3GJ665NT766;c:\windows\LKZA4.exe -CTKCPFB64F –> c:\windows\LKZA4.exe -CTKCPFB64F [?]
S4 3Q3BVMFQZTJ;3Q3BVMFQZTJ;c:\windows\K7NAN.exe -BR0QMKHWMT –> c:\windows\K7NAN.exe -BR0QMKHWMT [?]
S4 4B5HRB6B9;4B5HRB6B9;c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ –> c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ [?]
S4 5ZHFDU4;5ZHFDU4;c:\windows\O7TEQDAQJ.exe -E0DS20 –> c:\windows\O7TEQDAQJ.exe -E0DS20 [?]
S4 8IT5Y44;8IT5Y44;c:\windows\PWD8KYGTP.exe -GJQKUE –> c:\windows\PWD8KYGTP.exe -GJQKUE [?]
S4 ADA2EG1;ADA2EG1;c:\windows\YT1X0GD7P.exe -QE361V –> c:\windows\YT1X0GD7P.exe -QE361V [?]
S4 BPYV25IQ;BPYV25IQ;c:\windows\14H3H0Y1RNH.exe -RQVMLG86 –> c:\windows\14H3H0Y1RNH.exe -RQVMLG86 [?]
S4 BQAGVE30;BQAGVE30;c:\windows\ZOA2WXS1BF.exe -RANNAKM –> c:\windows\ZOA2WXS1BF.exe -RANNAKM [?]
S4 CMUODPSJO8DW;CMUODPSJO8DW;c:\windows\23DIZQ.exe -SQR19Y93WQS –> c:\windows\23DIZQ.exe -SQR19Y93WQS [?]
S4 D9XBL1I9PX;D9XBL1I9PX;c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L –> c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L [?]
S4 DULWFJE;DULWFJE;c:\windows\4Q0MXNJ9F.exe -TXI97K –> c:\windows\4Q0MXNJ9F.exe -TXI97K [?]
S4 FEK1UEF;FEK1UEF;c:\windows\3VUMPGTGW.exe -VFHLTB –> c:\windows\3VUMPGTGW.exe -VFHLTB [?]
S4 H0252AAY6QPU;H0252AAY6QPU;c:\windows\5MZHQ6.exe -W3ZBRSF05CN –> c:\windows\5MZHQ6.exe -W3ZBRSF05CN [?]
S4 HC5IOVVW3;HC5IOVVW3;c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS –> c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS [?]
S4 IC56FJ2OJE;IC56FJ2OJE;c:\windows\9SP00JBDUZJ0.exe -YF2C670NL –> c:\windows\9SP00JBDUZJ0.exe -YF2C670NL [?]
S4 II9TFZ;II9TFZ;c:\windows\6YY3H4PB.exe -YLFI2 –> c:\windows\6YY3H4PB.exe -YLFI2 [?]
S4 J1GCP0;J1GCP0;c:\windows\9LKVE6PM.exe -YXS5Z –> c:\windows\9LKVE6PM.exe -YXS5Z [?]
S4 J33FQ1F;J33FQ1F;c:\windows\WXNZ1SB24.exe -OK0B75 –> c:\windows\WXNZ1SB24.exe -OK0B75 [?]
S4 LHFUA;LHFUA;c:\windows\WUAA71E.exe -1I8UJXUVI7F6 –> c:\windows\WUAA71E.exe -1I8UJXUVI7F6 [?]
S4 LTQLZP2FX6;LTQLZP2FX6;c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA –> c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA [?]
S4 MUAL22T09A;MUAL22T09A;c:\windows\1HH5P.exe -2VYRJYKRXN –> c:\windows\1HH5P.exe -2VYRJYKRXN [?]
S4 NBG7GOASD1KS;NBG7GOASD1KS;c:\windows\T31TZW.exe -JQK3SOQXCMO –> c:\windows\T31TZW.exe -JQK3SOQXCMO [?]
S4 RO3SKV;RO3SKV;c:\windows\2NNPM3AS8.exe -7P05Z7 –> c:\windows\2NNPM3AS8.exe -7P05Z7 [?]
S4 ROO5X4F;ROO5X4F;c:\windows\40UYFPMNI.exe -7RLA4D –> c:\windows\40UYFPMNI.exe -7RLA4D [?]
S4 SQFAY;SQFAY;c:\windows\B56DIMNM.exe -8RCNP –> c:\windows\B56DIMNM.exe -8RCNP [?]
S4 VMAJ4WFY;VMAJ4WFY;c:\windows\C009543J07.exe -NLK1XNBF –> c:\windows\C009543J07.exe -NLK1XNBF [?]
S4 W42CWKTK7;W42CWKTK7;c:\windows\EELB1IVL92C.exe -5ZPNRQCZ –> c:\windows\EELB1IVL92C.exe -5ZPNRQCZ [?]
S4 YT92TP;YT92TP;c:\windows\G9Z2U3LI.exe -UE5IC –> c:\windows\G9Z2U3LI.exe -UE5IC [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - U20Z2HUA
.
Contents of the 'Scheduled Tasks' folder

2009-03-15 c:\windows\Tasks\Registry Winner Schedule.job
- c:\program files\Registry Winner\RegistryWinner.exe []
.
.
——- Supplementary Scan ——-
.
IE: &Down&load &Link& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatch.htm
IE: &Down&load All &Links& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
IE: &GetGo Toolbar Search - c:\program files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{01A13E40-2F55-4397-B39B-7851BCFB8008} - c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe
TCP: {9ECC1FB7-D0B6-463E-99BE-7563CC59E2CB} = 65.240.162.65 65.240.162.66
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - component: c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\extensions\[removed]\platform\WINNT_x86-msvc\components\lpxpcom.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-16 23:32:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-16 23:36:15 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-17 04:36:08
ComboFix2.txt 2009-03-17 01:19:41
ComboFix3.txt 2009-03-17 01:03:46
ComboFix4.txt 2009-03-16 23:25:47
ComboFix5.txt 2009-03-17 04:27:43

Pre-Run: 43,302,707,200 bytes free
Post-Run: 43,234,496,512 bytes free

337 — E O F — 2009-03-09 21:51:30


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:48:25 PM, on 3/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Documents and Settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://test.catalog.update.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: GetGo URL Catcher (dont remove!) - {0315AA2C-10C7-4504-A1C4-F552ABA8A095} - C:\Program Files\GetGo Software\GetGo Download Manager\URLCatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: GetGo Toolbar - {075BBE29-FEC0-404a-A459-FF58713616FA} - C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe"
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O8 - Extra context menu item: &Down&load &Link& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatch.htm
O8 - Extra context menu item: &Down&load All &Links& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
O8 - Extra context menu item: &GetGo Toolbar Search - res://C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: GetGo - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra 'Tools' menuitem: GetGo Download Manager - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://test.catalog.update.microsoft.com/v…b?1236661267875
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1218290032265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ECC1FB7-D0B6-463E-99BE-7563CC59E2CB}: NameServer = 65.240.162.65 65.240.162.66
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: 10YX3FD3 - Unknown owner - C:\WINDOWS\TJTQZPSRY5T.exe (file missing)
O23 - Service: 19T3H - Unknown owner - C:\WINDOWS\IHC9IIA.exe (file missing)
O23 - Service: 1Q0PLJK5F7EO - Unknown owner - C:\WINDOWS\ILUJFR.exe (file missing)
O23 - Service: 2Z8EHAJGE1 - Unknown owner - C:\WINDOWS\LS3A0NEFDUJ3.exe (file missing)
O23 - Service: 5AX67SALZ - Unknown owner - C:\WINDOWS\MRG2LUTA629.exe (file missing)
O23 - Service: BBCAH - Unknown owner - C:\WINDOWS\1R34WHI.exe (file missing)
O23 - Service: D0V37G51X3 - Unknown owner - C:\WINDOWS\3AF9ILF5N53S.exe (file missing)
O23 - Service: GAY2F - Unknown owner - C:\WINDOWS\4OIW0C0.exe (file missing)
O23 - Service: H0PC5IV3 - Unknown owner - C:\WINDOWS\YYT6FQVUUD.exe (file missing)
O23 - Service: H76MC - Unknown owner - C:\WINDOWS\5HQIYDY.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: L69Y08 - Unknown owner - C:\WINDOWS\9GTTF99O.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MPJ5MST1U93 - Unknown owner - C:\WINDOWS\6Z8VQ.exe (file missing)
O23 - Service: PXNMBMJR - Unknown owner - C:\WINDOWS\98UBG40EEE.exe (file missing)
O23 - Service: R9I2V5 - Unknown owner - C:\WINDOWS\I8V5ZLII.exe (file missing)
O23 - Service: TERDNO1D5 - Unknown owner - C:\WINDOWS\CVBOD9AX78UD.exe (file missing)
O23 - Service: U20Z2HUA - Unknown owner - C:\WINDOWS\BM4EE5V9PE.exe (file missing)
O23 - Service: UNGVG2LBWEL - Unknown owner - C:\WINDOWS\B276A.exe (file missing)
O23 - Service: Y2EN4QW5889 - Unknown owner - C:\WINDOWS\FC596.exe (file missing)
O23 - Service: YTMP1NBHT2 - Unknown owner - C:\WINDOWS\ZCHSCNE8H0QU.exe (file missing)
O23 - Service: ZGC2AK - Unknown owner - C:\WINDOWS\HW2VWLUR.exe (file missing)
O23 - Service: ZO48L - Unknown owner - C:\WINDOWS\XZPMNYK.exe (file missing)

–
End of file - 9025 bytes
Do you see all the files listed under this key?
Your Firewall is allowing them to come in.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

We are making headway so stay with me.



Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\DHJPOEG7.exe
c:\windows\JVTR854F.exe
c:\windows\H7YBMEH1N.exe
c:\windows\CNM41P.exe
c:\windows\WFAXPHNL.exe
c:\windows\JDDAHCI7WSG.exe
c:\windows\BCNONNB8.exe

Driver::
U20Z2HUA

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 0

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Yes, I do… I thought most firewalls keep bad files and such out… Well, when we get done, I'm going to get a good firewall and anti-virus.

I guess the same, still not letting me install some programsand the task manager wont stay open, just like before.




ComboFix 09-03-15.01 - Kristy 2009-03-17 13:30:49.8 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.225 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kristy\Desktop\CFScript.txt
* Created a new restore point

FILE ::
c:\windows\BCNONNB8.exe
c:\windows\CNM41P.exe
c:\windows\DHJPOEG7.exe
c:\windows\H7YBMEH1N.exe
c:\windows\JDDAHCI7WSG.exe
c:\windows\JVTR854F.exe
c:\windows\WFAXPHNL.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\BCNONNB8.exe
c:\windows\CNM41P.exe
c:\windows\DHJPOEG7.exe
c:\windows\H7YBMEH1N.exe
c:\windows\JDDAHCI7WSG.exe
c:\windows\JVTR854F.exe
c:\windows\WFAXPHNL.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_U20Z2HUA
——-\Service_U20Z2HUA


((((((((((((((((((((((((( Files Created from 2009-02-17 to 2009-03-17 )))))))))))))))))))))))))))))))
.

2009-03-17 13:34 . 2009-03-17 13:34 d——– c:\program files\QFLOZJC5K
2009-03-17 13:34 . 2009-03-17 13:34 d——– c:\program files\PWHNMWA7DXAX
2009-03-17 13:34 . 2009-03-17 01:30 69,632 -rahs—- c:\windows\BBKMCEAD00.exe
2009-03-17 13:34 . 2009-03-17 01:29 69,632 -rahs—- c:\windows\AS9HQ.exe
2009-03-17 06:12 . 2009-03-17 06:12 d——– c:\program files\V1M8H117OBDI
2009-03-17 06:12 . 2009-03-17 06:12 d——– c:\program files\RB3VBY8R
2009-03-17 06:12 . 2009-03-17 01:30 69,632 -rahs—- c:\windows\GXL8K.exe
2009-03-17 06:12 . 2009-03-17 01:29 69,632 -rahs—- c:\windows\C2XJ95L5V.exe
2009-03-17 05:50 . 2009-03-17 05:50 d——– c:\program files\ROLAZVR5
2009-03-17 05:50 . 2009-03-17 01:29 69,632 -rahs—- c:\windows\C6NLC8L2U.exe
2009-03-17 05:40 . 2009-03-17 05:40 d——– c:\program files\LOVZEC
2009-03-17 05:40 . 2009-03-17 01:30 69,632 –a—— c:\windows\KV2MT64.exe
2009-03-17 02:59 . 2009-03-17 02:59 d——– c:\program files\9E3E5IBOMKOE
2009-03-17 02:59 . 2009-03-17 01:30 69,632 -r-hs—- c:\windows\UA2G0.exe
2009-03-17 02:47 . 2009-03-17 02:47 69,632 –a—— c:\windows\WR9J7KXV.exe
2009-03-17 02:40 . 2009-03-17 02:40 d——– c:\program files\T7ADVS1KE1U
2009-03-17 02:40 . 2009-03-17 02:40 69,632 –a—— c:\windows\QYC6NN.exe
2009-03-17 02:40 . 2009-03-17 02:40 69,632 –a—— c:\windows\E3CY1BGCVPNX.exe
2009-03-17 02:40 . 2009-03-17 02:40 69,632 -r-hs—- c:\windows\BWGGFZXS3.exe
2009-03-17 01:36 . 2009-03-17 01:36 69,632 –a—— c:\windows\VIDRM9RY3.exe
2009-03-17 01:35 . 2009-03-17 01:35 69,632 –a—— c:\windows\PBJ829DCGA.exe
2009-03-17 01:30 . 2009-03-17 01:30 d——– c:\program files\X7LW1WZIV
2009-03-17 01:30 . 2009-03-17 01:30 69,632 -r-hs—- c:\windows\I3LU459GPK.exe
2009-03-17 01:30 . 2009-03-17 01:30 69,632 -r-hs—- c:\windows\GVPXN2T.exe
2009-03-17 01:29 . 2009-03-17 01:29 d——– c:\program files\KHU2T7RCOWKX
2009-03-17 01:29 . 2009-03-17 01:29 69,632 -r-hs—- c:\windows\Z6JHX.exe
2009-03-17 01:29 . 2009-03-17 01:29 69,632 -r-hs—- c:\windows\Z4IVWCVBSD3.exe
2009-03-17 01:29 . 2009-03-17 01:29 0 –a—— c:\windows\ZCMBPO.bat
2009-03-16 13:59 . 2008-04-14 05:42 116,224 –a–c— c:\windows\system32\dllcache\xrxwiadr.dll
2009-03-16 13:59 . 2001-08-17 22:37 99,865 –a–c— c:\windows\system32\dllcache\xlog.exe
2009-03-16 13:59 . 2001-08-17 22:37 27,648 –a–c— c:\windows\system32\dllcache\xrxftplt.exe
2009-03-16 13:59 . 2001-08-17 22:36 23,040 –a–c— c:\windows\system32\dllcache\xrxwbtmp.dll
2009-03-16 13:59 . 2008-04-13 22:04 19,455 –a–c— c:\windows\system32\dllcache\wvchntxx.sys
2009-03-16 13:59 . 2008-04-14 00:16 19,200 –a–c— c:\windows\system32\dllcache\wstcodec.sys
2009-03-16 13:59 . 2008-04-14 05:42 18,944 –a–c— c:\windows\system32\dllcache\xrxscnui.dll
2009-03-16 13:59 . 2001-08-17 12:11 16,970 –a–c— c:\windows\system32\dllcache\xem336n5.sys
2009-03-16 13:59 . 2008-04-13 22:04 12,063 –a–c— c:\windows\system32\dllcache\wsiintxx.sys
2009-03-16 13:59 . 2008-04-14 05:42 8,192 –a–c— c:\windows\system32\dllcache\wshirda.dll
2009-03-16 13:59 . 2001-08-17 22:37 4,608 –a–c— c:\windows\system32\dllcache\xrxflnch.exe
2009-03-16 13:57 . 2001-08-17 13:28 794,654 –a–c— c:\windows\system32\dllcache\usr1801.sys
2009-03-16 13:56 . 2001-08-17 22:36 525,568 –a–c— c:\windows\system32\dllcache\tridxp.dll
2009-03-16 13:55 . 2001-08-17 14:01 241,664 –a–c— c:\windows\system32\dllcache\tosdvd02.sys
2009-03-16 13:54 . 2001-08-17 12:18 285,760 –a–c— c:\windows\system32\dllcache\stlnata.sys
2009-03-16 13:53 . 2001-08-17 22:36 114,688 –a–c— c:\windows\system32\dllcache\sonypi.dll
2009-03-16 13:53 . 2001-08-17 22:36 106,584 –a–c— c:\windows\system32\dllcache\spdports.dll
2009-03-16 13:53 . 2001-08-17 22:36 99,328 –a–c— c:\windows\system32\dllcache\srusd.dll
2009-03-16 13:53 . 2001-08-17 13:51 61,824 –a–c— c:\windows\system32\dllcache\speed.sys
2009-03-16 13:53 . 2001-08-17 12:51 37,040 –a–c— c:\windows\system32\dllcache\sonypi.sys
2009-03-16 13:53 . 2001-08-17 22:36 24,660 –a–c— c:\windows\system32\dllcache\spxupchk.dll
2009-03-16 13:53 . 2001-08-17 12:51 20,752 –a–c— c:\windows\system32\dllcache\sonync.sys
2009-03-16 13:53 . 2001-08-17 14:07 19,072 –a–c— c:\windows\system32\dllcache\sparrow.sys
2009-03-16 13:53 . 2001-08-17 13:53 9,600 –a–c— c:\windows\system32\dllcache\sonymc.sys
2009-03-16 13:53 . 2001-08-17 13:56 7,552 –a–c— c:\windows\system32\dllcache\sonypvu1.sys
2009-03-16 13:53 . 2008-04-14 00:10 7,552 –a–c— c:\windows\system32\dllcache\sonyait.sys
2009-03-16 13:53 . 2001-08-17 13:53 7,040 –a–c— c:\windows\system32\dllcache\snyaitmc.sys
2009-03-16 13:51 . 2001-08-17 22:36 386,560 –a–c— c:\windows\system32\dllcache\sgiul50.dll
2009-03-16 13:51 . 2001-08-17 14:56 252,032 –a–c— c:\windows\system32\dllcache\sis300iv.dll
2009-03-16 13:51 . 2001-08-17 22:36 238,592 –a–c— c:\windows\system32\dllcache\sisgrv.dll
2009-03-16 13:51 . 2001-07-21 14:29 161,568 –a–c— c:\windows\system32\dllcache\sgsmusb.sys
2009-03-16 13:51 . 2001-08-17 14:56 150,144 –a–c— c:\windows\system32\dllcache\sis6306v.dll
2009-03-16 13:51 . 2001-08-17 12:50 104,064 –a–c— c:\windows\system32\dllcache\sisgrp.sys
2009-03-16 13:51 . 2001-08-17 12:50 101,760 –a–c— c:\windows\system32\dllcache\sis300ip.sys
2009-03-16 13:51 . 2001-08-17 12:51 98,080 –a–c— c:\windows\system32\dllcache\sgiulnt5.sys
2009-03-16 13:51 . 2001-08-17 12:50 68,608 –a–c— c:\windows\system32\dllcache\sis6306p.sys
2009-03-16 13:51 . 2001-08-17 12:19 36,480 –a–c— c:\windows\system32\dllcache\sfmanm.sys
2009-03-16 13:51 . 2001-07-21 14:29 18,400 –a–c— c:\windows\system32\dllcache\sgsmld.sys
2009-03-16 13:51 . 2001-08-17 13:48 17,664 –a–c— c:\windows\system32\dllcache\sermouse.sys
2009-03-16 13:51 . 2001-08-17 13:53 6,784 –a–c— c:\windows\system32\dllcache\serscan.sys
2009-03-16 13:50 . 2001-08-17 13:52 11,648 –a–c— c:\windows\system32\dllcache\scsiprnt.sys
2009-03-16 13:50 . 2008-04-14 00:15 11,520 –a–c— c:\windows\system32\dllcache\scsiscan.sys
2009-03-16 13:50 . 2001-08-17 13:53 6,912 –a–c— c:\windows\system32\dllcache\seaddsmc.sys
2009-03-16 13:49 . 2001-08-17 22:36 495,616 –a–c— c:\windows\system32\dllcache\sblfx.dll
2009-03-16 13:49 . 2001-08-17 14:56 245,632 –a–c— c:\windows\system32\dllcache\s3savmx.dll
2009-03-16 13:49 . 2001-08-17 14:56 198,400 –a–c— c:\windows\system32\dllcache\s3sav4.dll
2009-03-16 13:49 . 2001-08-17 14:56 179,264 –a–c— c:\windows\system32\dllcache\s3sav3d.dll
2009-03-16 13:49 . 2001-08-17 12:50 77,824 –a–c— c:\windows\system32\dllcache\s3sav4m.sys
2009-03-16 13:49 . 2001-08-17 12:50 75,392 –a–c— c:\windows\system32\dllcache\s3savmxm.sys
2009-03-16 13:49 . 2001-08-17 12:50 61,504 –a–c— c:\windows\system32\dllcache\s3sav3dm.sys
2009-03-16 13:49 . 2008-04-14 00:10 43,904 –a–c— c:\windows\system32\dllcache\sbp2port.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmusbm.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmn50m.sys
2009-03-16 13:49 . 2001-08-17 13:51 17,280 –a–c— c:\windows\system32\dllcache\scr111.sys
2009-03-16 13:49 . 2001-08-17 13:51 16,640 –a–c— c:\windows\system32\dllcache\scmstcs.sys
2009-03-16 13:47 . 2001-08-17 13:28 899,146 –a–c— c:\windows\system32\dllcache\r2mdkxga.sys
2009-03-16 13:46 . 2008-04-14 05:42 363,520 –a–c— c:\windows\system32\dllcache\psisdecd.dll
2009-03-16 13:45 . 2001-08-17 14:05 351,616 –a–c— c:\windows\system32\dllcache\ovcodek2.sys
2009-03-16 13:44 . 2001-08-17 12:50 198,144 –a–c— c:\windows\system32\dllcache\nv3.sys
2009-03-16 13:44 . 2001-08-17 22:36 123,776 –a–c— c:\windows\system32\dllcache\nv3.dll
2009-03-16 13:44 . 2001-08-17 12:49 51,552 –a–c— c:\windows\system32\dllcache\ntgrip.sys
2009-03-16 13:44 . 2001-08-17 13:47 9,344 –a–c— c:\windows\system32\dllcache\ntapm.sys
2009-03-16 13:44 . 2001-08-17 13:53 7,552 –a–c— c:\windows\system32\dllcache\nsmmc.sys
2009-03-16 13:42 . 2001-08-17 12:50 103,296 –a–c— c:\windows\system32\dllcache\mtxvideo.sys
2009-03-16 13:42 . 2008-04-14 00:16 49,024 –a–c— c:\windows\system32\dllcache\mstape.sys
2009-03-16 13:42 . 2008-04-14 00:24 22,016 –a–c— c:\windows\system32\dllcache\msircomm.sys
2009-03-16 13:42 . 2001-08-17 13:50 21,888 –a–c— c:\windows\system32\dllcache\mxcard.sys
2009-03-16 13:42 . 2001-08-17 13:49 19,968 –a–c— c:\windows\system32\dllcache\mxnic.sys
2009-03-16 13:42 . 2001-08-17 22:36 19,968 –a–c— c:\windows\system32\dllcache\mxicfg.dll
2009-03-16 13:42 . 2001-08-17 13:48 12,416 –a–c— c:\windows\system32\dllcache\msriffwv.sys
2009-03-16 13:42 . 2001-08-17 22:36 7,168 –a–c— c:\windows\system32\dllcache\mxport.dll
2009-03-16 13:42 . 2008-04-14 00:09 5,504 –a–c— c:\windows\system32\dllcache\mstee.sys
2009-03-16 13:42 . 2001-08-17 14:00 2,944 –a–c— c:\windows\system32\dllcache\msmpu401.sys
2009-03-16 13:40 . 2001-08-17 13:28 802,683 –a–c— c:\windows\system32\dllcache\ltsm.sys
2009-03-16 13:39 . 2008-04-14 05:41 253,952 –a–c— c:\windows\system32\dllcache\kdsusd.dll
2009-03-16 13:38 . 2008-04-14 05:41 702,845 –a–c— c:\windows\system32\dllcache\i81xdnt5.dll
2009-03-16 13:37 . 2001-08-17 13:28 542,879 –a–c— c:\windows\system32\dllcache\hsf_msft.sys
2009-03-16 13:36 . 2001-08-17 14:56 1,733,120 –a–c— c:\windows\system32\dllcache\g400d.dll
2009-03-16 13:35 . 2001-08-17 12:15 455,680 –a–c— c:\windows\system32\dllcache\fus2base.sys
2009-03-16 13:34 . 2001-08-17 13:28 634,134 –a–c— c:\windows\system32\dllcache\el656ct5.sys
2009-03-16 13:33 . 2001-08-17 12:14 952,007 –a–c— c:\windows\system32\dllcache\diwan.sys
2009-03-16 13:32 . 2001-08-17 22:36 256,512 –a–c— c:\windows\system32\dllcache\devcon32.dll
2009-03-16 13:31 . 2001-08-17 12:13 980,034 –a–c— c:\windows\system32\dllcache\cicap.sys
2009-03-16 13:30 . 2001-08-17 13:28 871,388 –a–c— c:\windows\system32\dllcache\bcmdm.sys
2009-03-16 13:29 . 2001-08-17 14:55 382,592 –a–c— c:\windows\system32\dllcache\atidrab.dll
2009-03-16 13:28 . 2001-08-17 13:28 762,780 –a–c— c:\windows\system32\dllcache\3cwmcru.sys
2009-03-16 13:27 . 2001-08-17 14:56 66,048 –a–c— c:\windows\system32\dllcache\s3legacy.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a—— c:\windows\system32\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a–c— c:\windows\system32\dllcache\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a—— c:\windows\system32\kbdkor.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a–c— c:\windows\system32\dllcache\kbdkor.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a—— c:\windows\system32\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a–c— c:\windows\system32\dllcache\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-17 08:03 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-09 23:46 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-09 23:02 204,800 ——w c:\windows\alcrmv.exe
2009-03-09 23:02 143,360 —-a-w c:\windows\SOUNDMAN.EXE
2009-03-08 08:59 ——— d—–w c:\program files\Java
2009-03-08 00:07 ——— d—–w c:\program files\CCleaner
2009-03-08 00:07 ——— d—–w c:\program files\7-Zip
2009-03-08 00:04 ——— d—–w c:\program files\Foxit Software
2009-03-06 19:50 241,664 ——w c:\windows\alcupd.exe
2008-08-09 13:34 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080920080810\index.dat
.

((((((((((((((((((((((((((((( SnapShot_2009-03-16_16.38.21.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
+ 2004-08-04 12:00:00 28,672 —-a-w c:\windows\system32\NSREG.DLL
+ 2009-03-17 18:34:37 16,384 —-atw c:\windows\temp\Perflib_Perfdata_684.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-03-08 160592]
"PlaxoSysTray"="c:\program files\Plaxo\3.19.0.16\PlaxoSysTray.exe" [2009-02-09 20480]
"uTorrent"="c:\documents and settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe" [2009-03-07 281392]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.MSNAUDIO"= msnaudio.acm
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GetGoDM]
–a—— 2009-02-11 03:40 3280568 c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
–a—— 2009-02-09 11:08 371271 c:\program files\Plaxo\3.19.0.16\PlaxoHelper_en.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2009-02-04 12:27 23975720 c:\program files\Skype\Phone\Skype.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\eMule Plus\\eMule.exe"=
"c:\\Documents and Settings\\Kristy\\My Documents\\Documents\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=

S2 10YX3FD3;10YX3FD3;c:\windows\TJTQZPSRY5T.exe -J2X0DEKU –> c:\windows\TJTQZPSRY5T.exe -J2X0DEKU [?]
S2 19T3H;19T3H;c:\windows\IHC9IIA.exe -AQLU44CEC3UJ –> c:\windows\IHC9IIA.exe -AQLU44CEC3UJ [?]
S2 1NZ0I2YD;1NZ0I2YD;c:\windows\I3LU459GPK.exe -AOYI44K –> c:\windows\I3LU459GPK.exe -AOYI44K [?]
S2 1Q0PLJK5F7EO;1Q0PLJK5F7EO;c:\windows\ILUJFR.exe -A73PR9ZTP3Q –> c:\windows\ILUJFR.exe -A73PR9ZTP3Q [?]
S2 2Z8EHAJGE1;2Z8EHAJGE1;c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP –> c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP [?]
S2 3CA2HIC2OK2;3CA2HIC2OK2;c:\windows\UA2G0.exe -L4NSUN8RR1 –> c:\windows\UA2G0.exe -L4NSUN8RR1 [?]
S2 5AX67SALZ;5AX67SALZ;c:\windows\MRG2LUTA629.exe -DDUEXG6H –> c:\windows\MRG2LUTA629.exe -DDUEXG6H [?]
S2 AQ0LBRDMS1M;AQ0LBRDMS1M;c:\windows\Z6JHX.exe -QTXY9RXXUB –> c:\windows\Z6JHX.exe -QTXY9RXXUB [?]
S2 BBCAH;BBCAH;c:\windows\1R34WHI.exe -REG646GTN16P –> c:\windows\1R34WHI.exe -REG646GTN16P [?]
S2 D0V37G51X3;D0V37G51X3;c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ –> c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ [?]
S2 GAY2F;GAY2F;c:\windows\4OIW0C0.exe -WBVYPWKID628 –> c:\windows\4OIW0C0.exe -WBVYPWKID628 [?]
S2 H0PC5IV3;H0PC5IV3;c:\windows\YYT6FQVUUD.exe -OK6IRIO –> c:\windows\YYT6FQVUUD.exe -OK6IRIO [?]
S2 H76MC;H76MC;c:\windows\5HQIYDY.exe -X83ZZL7VQJLS –> c:\windows\5HQIYDY.exe -X83ZZL7VQJLS [?]
S2 L69Y08;L69Y08;c:\windows\9GTTF99O.exe -196QP –> c:\windows\9GTTF99O.exe -196QP [?]
S2 MPJ5MST1U93;MPJ5MST1U93;c:\windows\6Z8VQ.exe -2QGBD1K9XL –> c:\windows\6Z8VQ.exe -2QGBD1K9XL [?]
S2 PJZGM;PJZGM;c:\windows\KV2MT64.exe -5G9G09U3TBT6 –> c:\windows\KV2MT64.exe -5G9G09U3TBT6 [?]
S2 PXNMBMJR;PXNMBMJR;c:\windows\98UBG40EEE.exe -4YKLBSH –> c:\windows\98UBG40EEE.exe -4YKLBSH [?]
S2 R9I2V5;R9I2V5;c:\windows\I8V5ZLII.exe -7FLLY –> c:\windows\I8V5ZLII.exe -7FLLY [?]
S2 SP4QY7;SP4QY7;c:\windows\C6NLC8L2U.exe -8T03OO –> c:\windows\C6NLC8L2U.exe -8T03OO [?]
S2 TERDNO1D5;TERDNO1D5;c:\windows\CVBOD9AX78UD.exe -HOQE73D8L –> c:\windows\CVBOD9AX78UD.exe -HOQE73D8L [?]
S2 UNGVG2LBWEL;UNGVG2LBWEL;c:\windows\B276A.exe -ODIM38SNRI –> c:\windows\B276A.exe -ODIM38SNRI [?]
S2 VZJ7CJX;VZJ7CJX;c:\windows\C2XJ95L5V.exe -1GF964 –> c:\windows\C2XJ95L5V.exe -1GF964 [?]
S2 XG2590FVJ4M;XG2590FVJ4M;c:\windows\GXL8K.exe -JZKWQ65J81 –> c:\windows\GXL8K.exe -JZKWQ65J81 [?]
S2 XMQJC00R9B;XMQJC00R9B;c:\windows\E3CY1BGCVPNX.exe -PNW9H7AI6U –> c:\windows\E3CY1BGCVPNX.exe -PNW9H7AI6U [?]
S2 Y2EN4QW5889;Y2EN4QW5889;c:\windows\FC596.exe -5BMEKWTTJ5 –> c:\windows\FC596.exe -5BMEKWTTJ5 [?]
S2 YTMP1NBHT2;YTMP1NBHT2;c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB –> c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB [?]
S2 ZGC2AK;ZGC2AK;c:\windows\HW2VWLUR.exe -H67JL –> c:\windows\HW2VWLUR.exe -H67JL [?]
S2 ZO48L;ZO48L;c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU –> c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU [?]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys –> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S4 08FX8JFV;08FX8JFV;c:\windows\IH6RNKYKZ0.exe -CZ7LF5R –> c:\windows\IH6RNKYKZ0.exe -CZ7LF5R [?]
S4 1MV0BLHXE;1MV0BLHXE;c:\windows\I3ETXM0MNZS.exe -PR79NGT9 –> c:\windows\I3ETXM0MNZS.exe -PR79NGT9 [?]
S4 2NXBWF;2NXBWF;c:\windows\J3GBGKSA.exe -BQUON –> c:\windows\J3GBGKSA.exe -BQUON [?]
S4 2O1L3;2O1L3;c:\windows\XAVRLDW.exe -M3N189R55ALV –> c:\windows\XAVRLDW.exe -M3N189R55ALV [?]
S4 3GJ665NT766;3GJ665NT766;c:\windows\LKZA4.exe -CTKCPFB64F –> c:\windows\LKZA4.exe -CTKCPFB64F [?]
S4 3Q3BVMFQZTJ;3Q3BVMFQZTJ;c:\windows\K7NAN.exe -BR0QMKHWMT –> c:\windows\K7NAN.exe -BR0QMKHWMT [?]
S4 4B5HRB6B9;4B5HRB6B9;c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ –> c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ [?]
S4 5ZHFDU4;5ZHFDU4;c:\windows\O7TEQDAQJ.exe -E0DS20 –> c:\windows\O7TEQDAQJ.exe -E0DS20 [?]
S4 8IT5Y44;8IT5Y44;c:\windows\PWD8KYGTP.exe -GJQKUE –> c:\windows\PWD8KYGTP.exe -GJQKUE [?]
S4 ADA2EG1;ADA2EG1;c:\windows\YT1X0GD7P.exe -QE361V –> c:\windows\YT1X0GD7P.exe -QE361V [?]
S4 BPYV25IQ;BPYV25IQ;c:\windows\14H3H0Y1RNH.exe -RQVMLG86 –> c:\windows\14H3H0Y1RNH.exe -RQVMLG86 [?]
S4 BQAGVE30;BQAGVE30;c:\windows\ZOA2WXS1BF.exe -RANNAKM –> c:\windows\ZOA2WXS1BF.exe -RANNAKM [?]
S4 CMUODPSJO8DW;CMUODPSJO8DW;c:\windows\23DIZQ.exe -SQR19Y93WQS –> c:\windows\23DIZQ.exe -SQR19Y93WQS [?]
S4 D9XBL1I9PX;D9XBL1I9PX;c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L –> c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L [?]
S4 DULWFJE;DULWFJE;c:\windows\4Q0MXNJ9F.exe -TXI97K –> c:\windows\4Q0MXNJ9F.exe -TXI97K [?]
S4 FEK1UEF;FEK1UEF;c:\windows\3VUMPGTGW.exe -VFHLTB –> c:\windows\3VUMPGTGW.exe -VFHLTB [?]
S4 H0252AAY6QPU;H0252AAY6QPU;c:\windows\5MZHQ6.exe -W3ZBRSF05CN –> c:\windows\5MZHQ6.exe -W3ZBRSF05CN [?]
S4 HC5IOVVW3;HC5IOVVW3;c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS –> c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS [?]
S4 IC56FJ2OJE;IC56FJ2OJE;c:\windows\9SP00JBDUZJ0.exe -YF2C670NL –> c:\windows\9SP00JBDUZJ0.exe -YF2C670NL [?]
S4 II9TFZ;II9TFZ;c:\windows\6YY3H4PB.exe -YLFI2 –> c:\windows\6YY3H4PB.exe -YLFI2 [?]
S4 J1GCP0;J1GCP0;c:\windows\9LKVE6PM.exe -YXS5Z –> c:\windows\9LKVE6PM.exe -YXS5Z [?]
S4 J33FQ1F;J33FQ1F;c:\windows\WXNZ1SB24.exe -OK0B75 –> c:\windows\WXNZ1SB24.exe -OK0B75 [?]
S4 LHFUA;LHFUA;c:\windows\WUAA71E.exe -1I8UJXUVI7F6 –> c:\windows\WUAA71E.exe -1I8UJXUVI7F6 [?]
S4 LTQLZP2FX6;LTQLZP2FX6;c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA –> c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA [?]
S4 MUAL22T09A;MUAL22T09A;c:\windows\1HH5P.exe -2VYRJYKRXN –> c:\windows\1HH5P.exe -2VYRJYKRXN [?]
S4 NBG7GOASD1KS;NBG7GOASD1KS;c:\windows\T31TZW.exe -JQK3SOQXCMO –> c:\windows\T31TZW.exe -JQK3SOQXCMO [?]
S4 RO3SKV;RO3SKV;c:\windows\2NNPM3AS8.exe -7P05Z7 –> c:\windows\2NNPM3AS8.exe -7P05Z7 [?]
S4 ROO5X4F;ROO5X4F;c:\windows\40UYFPMNI.exe -7RLA4D –> c:\windows\40UYFPMNI.exe -7RLA4D [?]
S4 SQFAY;SQFAY;c:\windows\B56DIMNM.exe -8RCNP –> c:\windows\B56DIMNM.exe -8RCNP [?]
S4 VMAJ4WFY;VMAJ4WFY;c:\windows\C009543J07.exe -NLK1XNBF –> c:\windows\C009543J07.exe -NLK1XNBF [?]
S4 W42CWKTK7;W42CWKTK7;c:\windows\EELB1IVL92C.exe -5ZPNRQCZ –> c:\windows\EELB1IVL92C.exe -5ZPNRQCZ [?]
S4 YT92TP;YT92TP;c:\windows\G9Z2U3LI.exe -UE5IC –> c:\windows\G9Z2U3LI.exe -UE5IC [?]

— Other Services/Drivers In Memory —

*NewlyCreated* - VZJ7CJX
*NewlyCreated* - XG2590FVJ4M
.
Contents of the 'Scheduled Tasks' folder

2009-03-15 c:\windows\Tasks\Registry Winner Schedule.job
- c:\program files\Registry Winner\RegistryWinner.exe []
.
.
——- Supplementary Scan ——-
.
IE: &Down&load &Link& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatch.htm
IE: &Down&load All &Links& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
IE: &GetGo Toolbar Search - c:\program files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{01A13E40-2F55-4397-B39B-7851BCFB8008} - c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - component: c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\extensions\[removed]\platform\WINNT_x86-msvc\components\lpxpcom.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-17 13:34:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\I3LU459GPK.exe
c:\windows\Z6JHX.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\program files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
.
**************************************************************************
.
Completion time: 2009-03-17 13:37:58 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-17 18:37:49
ComboFix2.txt 2009-03-17 04:36:17
ComboFix3.txt 2009-03-17 01:19:41
ComboFix4.txt 2009-03-17 01:03:46
ComboFix5.txt 2009-03-17 18:29:49

Pre-Run: 42,958,065,664 bytes free
Post-Run: 42,981,359,616 bytes free

326 — E O F — 2009-03-09 21:51:30


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:42:37 PM, on 3/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\I3LU459GPK.exe
C:\WINDOWS\Z6JHX.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\ProcessExplorer\procexp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\I3LU459GPK.exe
C:\WINDOWS\Z6JHX.exe
C:\WINDOWS\Z6JHX.exe
C:\WINDOWS\I3LU459GPK.exe
C:\WINDOWS\Z6JHX.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\I3LU459GPK.exe
C:\WINDOWS\Z6JHX.exe
C:\WINDOWS\I3LU459GPK.exe
C:\WINDOWS\Z6JHX.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://test.catalog.update.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: GetGo URL Catcher (dont remove!) - {0315AA2C-10C7-4504-A1C4-F552ABA8A095} - C:\Program Files\GetGo Software\GetGo Download Manager\URLCatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: GetGo Toolbar - {075BBE29-FEC0-404a-A459-FF58713616FA} - C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe"
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O8 - Extra context menu item: &Down&load &Link& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatch.htm
O8 - Extra context menu item: &Down&load All &Links& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
O8 - Extra context menu item: &GetGo Toolbar Search - res://C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: GetGo - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra 'Tools' menuitem: GetGo Download Manager - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://test.catalog.update.microsoft.com/v…b?1236661267875
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1218290032265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ECC1FB7-D0B6-463E-99BE-7563CC59E2CB}: NameServer = 65.240.162.65 65.240.162.66
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: 10YX3FD3 - Unknown owner - C:\WINDOWS\TJTQZPSRY5T.exe (file missing)
O23 - Service: 19T3H - Unknown owner - C:\WINDOWS\IHC9IIA.exe (file missing)
O23 - Service: 1NZ0I2YD - ???? - C:\WINDOWS\I3LU459GPK.exe
O23 - Service: 1Q0PLJK5F7EO - Unknown owner - C:\WINDOWS\ILUJFR.exe (file missing)
O23 - Service: 2Z8EHAJGE1 - Unknown owner - C:\WINDOWS\LS3A0NEFDUJ3.exe (file missing)
O23 - Service: 3CA2HIC2OK2 - ???? - C:\WINDOWS\UA2G0.exe
O23 - Service: 5AX67SALZ - Unknown owner - C:\WINDOWS\MRG2LUTA629.exe (file missing)
O23 - Service: AQ0LBRDMS1M - ???????? - C:\WINDOWS\Z6JHX.exe
O23 - Service: BBCAH - Unknown owner - C:\WINDOWS\1R34WHI.exe (file missing)
O23 - Service: D0V37G51X3 - Unknown owner - C:\WINDOWS\3AF9ILF5N53S.exe (file missing)
O23 - Service: GAY2F - Unknown owner - C:\WINDOWS\4OIW0C0.exe (file missing)
O23 - Service: H0PC5IV3 - Unknown owner - C:\WINDOWS\YYT6FQVUUD.exe (file missing)
O23 - Service: H76MC - Unknown owner - C:\WINDOWS\5HQIYDY.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: L69Y08 - Unknown owner - C:\WINDOWS\9GTTF99O.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MPJ5MST1U93 - Unknown owner - C:\WINDOWS\6Z8VQ.exe (file missing)
O23 - Service: PJZGM - ???? - C:\WINDOWS\KV2MT64.exe
O23 - Service: PXNMBMJR - Unknown owner - C:\WINDOWS\98UBG40EEE.exe (file missing)
O23 - Service: R9I2V5 - Unknown owner - C:\WINDOWS\I8V5ZLII.exe (file missing)
O23 - Service: RBINSVC3HSR - ???????? - C:\WINDOWS\AS9HQ.exe
O23 - Service: SP4QY7 - ???????? - C:\WINDOWS\C6NLC8L2U.exe
O23 - Service: TERDNO1D5 - Unknown owner - C:\WINDOWS\CVBOD9AX78UD.exe (file missing)
O23 - Service: U11TXCYF - ???? - C:\WINDOWS\BBKMCEAD00.exe
O23 - Service: UNGVG2LBWEL - Unknown owner - C:\WINDOWS\B276A.exe (file missing)
O23 - Service: VZJ7CJX - ???????? - C:\WINDOWS\C2XJ95L5V.exe
O23 - Service: XG2590FVJ4M - ???? - C:\WINDOWS\GXL8K.exe
O23 - Service: XMQJC00R9B - ???????? - C:\WINDOWS\E3CY1BGCVPNX.exe
O23 - Service: Y2EN4QW5889 - Unknown owner - C:\WINDOWS\FC596.exe (file missing)
O23 - Service: YTMP1NBHT2 - Unknown owner - C:\WINDOWS\ZCHSCNE8H0QU.exe (file missing)
O23 - Service: ZGC2AK - Unknown owner - C:\WINDOWS\HW2VWLUR.exe (file missing)
O23 - Service: ZO48L - Unknown owner - C:\WINDOWS\XZPMNYK.exe (file missing)

–
End of file - 9798 bytes
I don't see a anti-virus program running. Get a free one.

avast! 4
http://www.avast.com/eng/download-avast-home.html

Or

Avira AntiVir Personal - FREE Antivirus
http://www.free-av.com/en/download/1/downl…_antivirus.html


Just install it and update it for the moment, don't run a scan yet.


Before doing the next fix I need you do unplug your internet connection


Next:
1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
SpyBot


Next:

If you receive any errors just move on with the rest.

Click Start > Run and Copy/Paste these commands hitting enter after each one:

sc stop 1NZ0I2YD Hit enter.

sc delete 1NZ0I2YD Hit enter.


sc stop 3CA2HIC2OK2 Hit enter.

sc delete 3CA2HIC2OK2 Hit enter.


sc stop PJZGM Hit enter.

sc delete PJZGM Hit enter.


sc stop RBINSVC3HSR Hit enter.

sc delete RBINSVC3HSR Hit enter.


sc stop SP4QY7 Hit enter.

sc delete SP4QY7 Hit enter.


sc stop U11TXCYF Hit enter.

sc delete U11TXCYF Hit enter.


sc stop XG2590FVJ4M Hit enter.

sc delete XG2590FVJ4M Hit enter.


sc stop VZJ7CJX Hit enter.

sc delete VZJ7CJX Hit enter.


sc stop XMQJC00R9B Hit enter.

sc delete XMQJC00R9B Hit enter.


Next:

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

O23 - Service: 10YX3FD3 - Unknown owner - C:\WINDOWS\TJTQZPSRY5T.exe (file missing)
O23 - Service: 19T3H - Unknown owner - C:\WINDOWS\IHC9IIA.exe (file missing)
O23 - Service: 1NZ0I2YD - ???? - C:\WINDOWS\I3LU459GPK.exe
O23 - Service: 1Q0PLJK5F7EO - Unknown owner - C:\WINDOWS\ILUJFR.exe (file missing)
O23 - Service: 2Z8EHAJGE1 - Unknown owner - C:\WINDOWS\LS3A0NEFDUJ3.exe (file missing)
O23 - Service: 3CA2HIC2OK2 - ???? - C:\WINDOWS\UA2G0.exe
O23 - Service: 5AX67SALZ - Unknown owner - C:\WINDOWS\MRG2LUTA629.exe (file missing)
O23 - Service: AQ0LBRDMS1M - ???????? - C:\WINDOWS\Z6JHX.exe
O23 - Service: BBCAH - Unknown owner - C:\WINDOWS\1R34WHI.exe (file missing)
O23 - Service: D0V37G51X3 - Unknown owner - C:\WINDOWS\3AF9ILF5N53S.exe (file missing)
O23 - Service: GAY2F - Unknown owner - C:\WINDOWS\4OIW0C0.exe (file missing)
O23 - Service: H0PC5IV3 - Unknown owner - C:\WINDOWS\YYT6FQVUUD.exe (file missing)
O23 - Service: H76MC - Unknown owner - C:\WINDOWS\5HQIYDY.exe (file missing)
O23 - Service: L69Y08 - Unknown owner - C:\WINDOWS\9GTTF99O.exe (file missing)
O23 - Service: MPJ5MST1U93 - Unknown owner - C:\WINDOWS\6Z8VQ.exe (file missing)
O23 - Service: PJZGM - ???? - C:\WINDOWS\KV2MT64.exe
O23 - Service: PXNMBMJR - Unknown owner - C:\WINDOWS\98UBG40EEE.exe (file missing)
O23 - Service: R9I2V5 - Unknown owner - C:\WINDOWS\I8V5ZLII.exe (file missing)
O23 - Service: RBINSVC3HSR - ???????? - C:\WINDOWS\AS9HQ.exe
O23 - Service: SP4QY7 - ???????? - C:\WINDOWS\C6NLC8L2U.exe
O23 - Service: TERDNO1D5 - Unknown owner - C:\WINDOWS\CVBOD9AX78UD.exe (file missing)
O23 - Service: U11TXCYF - ???? - C:\WINDOWS\BBKMCEAD00.exe
O23 - Service: UNGVG2LBWEL - Unknown owner - C:\WINDOWS\B276A.exe (file missing)
O23 - Service: VZJ7CJX - ???????? - C:\WINDOWS\C2XJ95L5V.exe
O23 - Service: XG2590FVJ4M - ???? - C:\WINDOWS\GXL8K.exe
O23 - Service: XMQJC00R9B - ???????? - C:\WINDOWS\E3CY1BGCVPNX.exe
O23 - Service: Y2EN4QW5889 - Unknown owner - C:\WINDOWS\FC596.exe (file missing)
O23 - Service: YTMP1NBHT2 - Unknown owner - C:\WINDOWS\ZCHSCNE8H0QU.exe (file missing)
O23 - Service: ZGC2AK - Unknown owner - C:\WINDOWS\HW2VWLUR.exe (file missing)
O23 - Service: ZO48L - Unknown owner - C:\WINDOWS\XZPMNYK.exe (file missing)

Close ALL windows and browsers except HijackThis and click "Fix checked"



Delete these Files if listed:
C:\WINDOWS\I3LU459GPK.exe
C:\WINDOWS\Z6JHX.exe
C:\WINDOWS\I3LU459GPK.exe
C:\WINDOWS\Z6JHX.exe
C:\WINDOWS\Z6JHX.exe
C:\WINDOWS\I3LU459GPK.exe
C:\WINDOWS\Z6JHX.exe
C:\WINDOWS\I3LU459GPK.exe
C:\WINDOWS\Z6JHX.exe
C:\WINDOWS\I3LU459GPK.exe
C:\WINDOWS\Z6JHX.exe


Next:

Run a full scan with the anti-virus scan, plug your internet connection back in and let us know what it finds along with a new HijackThis log.
I'll try but like I said the last anti-virus (Avira AntiVir) and the one before that one (AVG) I tried to install, wouldn't do anything… along with 2 or 3 other programs. (security programs). Sometimes they showed up in my process manager but that's all.

Have you ever seen something like this before?


EDIT:
Ok, now I got that Avira installed and I did everything you said, and now I'm on the scanning part… It's pretty late here about 2 am, so I think I'm going to let this run and then check on it after I get up. Oh, by the way… I think were getting it. And I found something out… I was just wondering, I turned the windows firewall off and guess what, the trojans stopped but if I turn the firewall on every now and then, they would enter… But I have the firewall on right now…. I hope that's ok.

And the computer is acting a lot better, the task manager stays open but the help and support does nothing and some programs too.

EDIT
Avira AntiVir Personal
Report file date: Wednesday, March 18, 2009 10:30

Scanning for 1305356 virus strains and unwanted programs.

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : FAMILYROOM

Version information:
BUILD.DAT : 9.0.0.386 17962 Bytes 3/11/2009 15:55:00
AVSCAN.EXE : 9.0.3.3 464641 Bytes 2/24/2009 17:13:26
AVSCAN.DLL : 9.0.3.0 40705 Bytes 2/27/2009 15:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 2/20/2009 16:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 2/27/2009 15:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 17:30:36
ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 2/11/2009 01:33:26
ANTIVIR2.VDF : 7.1.2.152 749568 Bytes 3/11/2009 06:48:53
ANTIVIR3.VDF : 7.1.2.183 189952 Bytes 3/17/2009 06:49:28
Engineversion : 8.2.0.116
AEVDF.DLL : 8.1.1.0 106868 Bytes 1/27/2009 22:36:42
AESCRIPT.DLL : 8.1.1.63 364923 Bytes 3/18/2009 06:53:14
AESCN.DLL : 8.1.1.8 127346 Bytes 3/18/2009 06:52:46
AERDL.DLL : 8.1.1.3 438645 Bytes 10/29/2008 23:24:41
AEPACK.DLL : 8.1.3.10 397686 Bytes 3/4/2009 18:06:10
AEOFFICE.DLL : 8.1.0.36 196987 Bytes 2/27/2009 01:01:56
AEHEUR.DLL : 8.1.0.104 1634679 Bytes 3/18/2009 06:52:13
AEHELP.DLL : 8.1.2.2 119158 Bytes 2/27/2009 01:01:56
AEGEN.DLL : 8.1.1.29 336245 Bytes 3/18/2009 06:49:59
AEEMU.DLL : 8.1.0.9 393588 Bytes 10/9/2008 19:32:40
AECORE.DLL : 8.1.6.6 176501 Bytes 2/17/2009 19:22:44
AEBB.DLL : 8.1.0.3 53618 Bytes 10/9/2008 19:32:40
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 13:47:59
AVPREF.DLL : 9.0.0.1 43777 Bytes 12/5/2008 15:32:15
AVREP.DLL : 8.0.0.3 155905 Bytes 1/20/2009 19:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 12/5/2008 15:32:09
AVARKT.DLL : 9.0.0.1 292609 Bytes 2/9/2009 12:52:24
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 1/30/2009 15:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 1/28/2009 20:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 13:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 12/5/2008 15:32:10
RCIMAGE.DLL : 9.0.0.21 2438401 Bytes 2/9/2009 16:45:45
RCTEXT.DLL : 9.0.35.0 87297 Bytes 3/11/2009 20:55:12

Configuration settings for the scan:
Jobname………………………..: Complete system scan
Configuration file………………: c:\program files\avira\antivir desktop\sysscan.avp
Logging………………………..: low
Primary action………………….: interactive
Secondary action………………..: ignore
Scan master boot sector………….: on
Scan boot sector………………..: on
Boot sectors……………………: C:, D:,
Process scan……………………: on
Scan registry…………………..: on
Search for rootkits……………..: on
Integrity checking of system files..: on
Scan all files………………….: All files
Scan archives…………………..: on
Recursion depth…………………: 20
Smart extensions………………..: on
Macro heuristic…………………: on
File heuristic………………….: medium
Skipped files…………………..: C:\Documents and Settings\Kristy\My Documents, C:\Downloads, D:\Documents, D:\My Doc,

Start of the scan: Wednesday, March 18, 2009 10:30

Initiating scan of system files:
Signed -> 'C:\WINDOWS\system32\svchost.exe'
Signed -> 'C:\WINDOWS\system32\winlogon.exe'
Signed -> 'C:\WINDOWS\explorer.exe'
Signed -> 'C:\WINDOWS\system32\smss.exe'
Signed -> 'C:\WINDOWS\system32\wininet.DLL'
Signed -> 'C:\WINDOWS\system32\wsock32.DLL'
Signed -> 'C:\WINDOWS\system32\ws2_32.DLL'
Signed -> 'C:\WINDOWS\system32\services.exe'
Signed -> 'C:\WINDOWS\system32\lsass.exe'
Signed -> 'C:\WINDOWS\system32\csrss.exe'
Signed -> 'C:\WINDOWS\system32\drivers\kbdclass.sys'
Signed -> 'C:\WINDOWS\system32\spoolsv.exe'
Signed -> 'C:\WINDOWS\system32\alg.exe'
Signed -> 'C:\WINDOWS\system32\wuauclt.exe'
Signed -> 'C:\WINDOWS\system32\advapi32.DLL'
Signed -> 'C:\WINDOWS\system32\user32.DLL'
Signed -> 'C:\WINDOWS\system32\gdi32.DLL'
Signed -> 'C:\WINDOWS\system32\kernel32.DLL'
Signed -> 'C:\WINDOWS\system32\ntdll.DLL'
Signed -> 'C:\WINDOWS\system32\ntoskrnl.exe'
Signed -> 'C:\WINDOWS\system32\ctfmon.exe'
The system files were scanned ('21' files)

Starting search for hidden objects.
'54720' objects were checked, '0' hidden objects were found.

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'GetGoDM.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'procexp.exe' - '1' Module(s) have been scanned
Scan process 'PhLeAutoRun.exe' - '1' Module(s) have been scanned
Scan process 'robotaskbaricon.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'jqs.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'LEXPPS.EXE' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'LEXBCES.EXE' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
27 processes with 27 modules were scanned

Starting master boot sector scan:

Start scanning boot sectors:

Starting to scan executable files (registry).
The registry was scanned ( '56' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
The directory 'C:\Documents and Settings\Kristy\My Documents\' was excluded from scanning!
The directory 'C:\Downloads\' was excluded from scanning!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033124.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033125.exe
[DETECTION] Is the TR/Drop.Agent.QQJ Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033126.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033127.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033128.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033129.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033130.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033131.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033132.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033133.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033134.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033135.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033136.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033137.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033138.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033139.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033140.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033141.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033142.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033143.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033144.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033145.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033146.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033147.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033148.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033149.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033150.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033151.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033152.EXE
[DETECTION] Is the TR/Drop.Agent.QQJ Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033153.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033154.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033155.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033156.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033157.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033158.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033159.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033160.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033161.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033162.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033163.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033164.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033165.EXE
[DETECTION] Is the TR/Drop.Agent.QQJ Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033166.EXE
[DETECTION] Is the TR/Drop.Agent.QQJ Trojan
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033167.EXE
[DETECTION] Is the TR/Drop.Agent.QQJ Trojan
C:\WINDOWS\system32\drivers\sptd.sys
[WARNING] The file could not be opened!
Begin scan in 'D:\'
The directory 'D:\My Doc\' was excluded from scanning!
D:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033168.exe
[DETECTION] Is the TR/Drop.Agent.QQJ Trojan
The directory 'D:\Documents\' was excluded from scanning!

Beginning disinfection:
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033124.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033125.exe
[DETECTION] Is the TR/Drop.Agent.QQJ Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033126.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033127.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033128.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033129.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033130.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033131.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033132.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033133.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033134.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033135.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033136.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033137.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033138.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033139.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033140.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033141.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033142.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033143.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033144.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033145.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033146.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033147.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033148.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033149.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033150.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033151.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033152.EXE
[DETECTION] Is the TR/Drop.Agent.QQJ Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033153.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033154.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033155.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033156.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033157.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033158.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033159.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033160.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033161.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033162.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033163.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033164.exe
[DETECTION] Is the TR/Downloader.Gen Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033165.EXE
[DETECTION] Is the TR/Drop.Agent.QQJ Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033166.EXE
[DETECTION] Is the TR/Drop.Agent.QQJ Trojan
[WARNING] The file was ignored!
C:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033167.EXE
[DETECTION] Is the TR/Drop.Agent.QQJ Trojan
[WARNING] The file was ignored!
D:\System Volume Information\_restore{29C98118-E657-47BA-85ED-FFB276B0F258}\RP214\A0033168.exe
[DETECTION] Is the TR/Drop.Agent.QQJ Trojan
[WARNING] The file was ignored!


End of the scan: Wednesday, March 18, 2009 11:37
Used time: 1:06:38 Hour(s)

The scan has been done completely.

3193 Scanned directories
178056 Files were scanned
45 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
0 Files were moved to quarantine
0 Files were renamed
2 Files cannot be scanned
178009 Files not concerned
2733 Archives were scanned
47 Warnings
1 Notes
54720 Objects were scanned with rootkit scan
0 Hidden objects were found


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:50:55 AM, on 3/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\ProcessExplorer\procexp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
C:\Program Files\Avira\AntiVir Desktop\avscan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://test.catalog.update.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: GetGo URL Catcher (dont remove!) - {0315AA2C-10C7-4504-A1C4-F552ABA8A095} - C:\Program Files\GetGo Software\GetGo Download Manager\URLCatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: GetGo Toolbar - {075BBE29-FEC0-404a-A459-FF58713616FA} - C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe"
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O8 - Extra context menu item: &Down&load &Link& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatch.htm
O8 - Extra context menu item: &Down&load All &Links& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
O8 - Extra context menu item: &GetGo Toolbar Search - res://C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: GetGo - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra 'Tools' menuitem: GetGo Download Manager - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://test.catalog.update.microsoft.com/v…b?1236661267875
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1218290032265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ECC1FB7-D0B6-463E-99BE-7563CC59E2CB}: NameServer = 65.240.162.65 65.240.162.66
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

–
End of file - 7341 bytes
Those are in system restore. Lets clean that out first.

Note: This will remove all previous Restore Points

Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.


Now run a new Combofix scan
ComboFix 09-03-15.01 - Kristy 2009-03-18 12:44:14.9 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2009-02-18 to 2009-03-18 )))))))))))))))))))))))))))))))
.

2009-03-18 01:29 . 2009-03-18 01:29 d——– c:\program files\Avira
2009-03-18 01:29 . 2009-03-18 01:29 d——– c:\documents and settings\All Users\Application Data\Avira
2009-03-18 01:29 . 2009-02-13 11:31 55,640 –a—— c:\windows\system32\drivers\avgntflt.sys
2009-03-17 13:34 . 2009-03-18 05:23 d——– c:\program files\QFLOZJC5K
2009-03-17 13:34 . 2009-03-18 05:23 d——– c:\program files\PWHNMWA7DXAX
2009-03-17 06:12 . 2009-03-18 05:23 d——– c:\program files\V1M8H117OBDI
2009-03-17 06:12 . 2009-03-18 05:23 d——– c:\program files\RB3VBY8R
2009-03-17 05:50 . 2009-03-18 05:23 d——– c:\program files\ROLAZVR5
2009-03-17 05:40 . 2009-03-18 05:23 d——– c:\program files\LOVZEC
2009-03-17 02:59 . 2009-03-18 05:23 d——– c:\program files\9E3E5IBOMKOE
2009-03-17 02:40 . 2009-03-18 05:23 d——– c:\program files\T7ADVS1KE1U
2009-03-17 01:30 . 2009-03-18 05:23 d——– c:\program files\X7LW1WZIV
2009-03-17 01:29 . 2009-03-18 05:23 d——– c:\program files\KHU2T7RCOWKX
2009-03-17 01:29 . 2009-03-17 01:29 0 –a—— c:\windows\ZCMBPO.bat
2009-03-16 13:59 . 2008-04-14 05:42 116,224 –a–c— c:\windows\system32\dllcache\xrxwiadr.dll
2009-03-16 13:59 . 2001-08-17 22:37 99,865 –a–c— c:\windows\system32\dllcache\xlog.exe
2009-03-16 13:59 . 2001-08-17 22:37 27,648 –a–c— c:\windows\system32\dllcache\xrxftplt.exe
2009-03-16 13:59 . 2001-08-17 22:36 23,040 –a–c— c:\windows\system32\dllcache\xrxwbtmp.dll
2009-03-16 13:59 . 2008-04-13 22:04 19,455 –a–c— c:\windows\system32\dllcache\wvchntxx.sys
2009-03-16 13:59 . 2008-04-14 00:16 19,200 –a–c— c:\windows\system32\dllcache\wstcodec.sys
2009-03-16 13:59 . 2008-04-14 05:42 18,944 –a–c— c:\windows\system32\dllcache\xrxscnui.dll
2009-03-16 13:59 . 2001-08-17 12:11 16,970 –a–c— c:\windows\system32\dllcache\xem336n5.sys
2009-03-16 13:59 . 2008-04-13 22:04 12,063 –a–c— c:\windows\system32\dllcache\wsiintxx.sys
2009-03-16 13:59 . 2008-04-14 05:42 8,192 –a–c— c:\windows\system32\dllcache\wshirda.dll
2009-03-16 13:59 . 2001-08-17 22:37 4,608 –a–c— c:\windows\system32\dllcache\xrxflnch.exe
2009-03-16 13:57 . 2001-08-17 13:28 794,654 –a–c— c:\windows\system32\dllcache\usr1801.sys
2009-03-16 13:56 . 2001-08-17 22:36 525,568 –a–c— c:\windows\system32\dllcache\tridxp.dll
2009-03-16 13:55 . 2001-08-17 14:01 241,664 –a–c— c:\windows\system32\dllcache\tosdvd02.sys
2009-03-16 13:54 . 2001-08-17 12:18 285,760 –a–c— c:\windows\system32\dllcache\stlnata.sys
2009-03-16 13:53 . 2001-08-17 22:36 114,688 –a–c— c:\windows\system32\dllcache\sonypi.dll
2009-03-16 13:53 . 2001-08-17 22:36 106,584 –a–c— c:\windows\system32\dllcache\spdports.dll
2009-03-16 13:53 . 2001-08-17 22:36 99,328 –a–c— c:\windows\system32\dllcache\srusd.dll
2009-03-16 13:53 . 2001-08-17 13:51 61,824 –a–c— c:\windows\system32\dllcache\speed.sys
2009-03-16 13:53 . 2001-08-17 12:51 37,040 –a–c— c:\windows\system32\dllcache\sonypi.sys
2009-03-16 13:53 . 2001-08-17 22:36 24,660 –a–c— c:\windows\system32\dllcache\spxupchk.dll
2009-03-16 13:53 . 2001-08-17 12:51 20,752 –a–c— c:\windows\system32\dllcache\sonync.sys
2009-03-16 13:53 . 2001-08-17 14:07 19,072 –a–c— c:\windows\system32\dllcache\sparrow.sys
2009-03-16 13:53 . 2001-08-17 13:53 9,600 –a–c— c:\windows\system32\dllcache\sonymc.sys
2009-03-16 13:53 . 2001-08-17 13:56 7,552 –a–c— c:\windows\system32\dllcache\sonypvu1.sys
2009-03-16 13:53 . 2008-04-14 00:10 7,552 –a–c— c:\windows\system32\dllcache\sonyait.sys
2009-03-16 13:53 . 2001-08-17 13:53 7,040 –a–c— c:\windows\system32\dllcache\snyaitmc.sys
2009-03-16 13:51 . 2001-08-17 22:36 386,560 –a–c— c:\windows\system32\dllcache\sgiul50.dll
2009-03-16 13:51 . 2001-08-17 14:56 252,032 –a–c— c:\windows\system32\dllcache\sis300iv.dll
2009-03-16 13:51 . 2001-08-17 22:36 238,592 –a–c— c:\windows\system32\dllcache\sisgrv.dll
2009-03-16 13:51 . 2001-07-21 14:29 161,568 –a–c— c:\windows\system32\dllcache\sgsmusb.sys
2009-03-16 13:51 . 2001-08-17 14:56 150,144 –a–c— c:\windows\system32\dllcache\sis6306v.dll
2009-03-16 13:51 . 2001-08-17 12:50 104,064 –a–c— c:\windows\system32\dllcache\sisgrp.sys
2009-03-16 13:51 . 2001-08-17 12:50 101,760 –a–c— c:\windows\system32\dllcache\sis300ip.sys
2009-03-16 13:51 . 2001-08-17 12:51 98,080 –a–c— c:\windows\system32\dllcache\sgiulnt5.sys
2009-03-16 13:51 . 2001-08-17 12:50 68,608 –a–c— c:\windows\system32\dllcache\sis6306p.sys
2009-03-16 13:51 . 2001-08-17 12:19 36,480 –a–c— c:\windows\system32\dllcache\sfmanm.sys
2009-03-16 13:51 . 2001-07-21 14:29 18,400 –a–c— c:\windows\system32\dllcache\sgsmld.sys
2009-03-16 13:51 . 2001-08-17 13:48 17,664 –a–c— c:\windows\system32\dllcache\sermouse.sys
2009-03-16 13:51 . 2001-08-17 13:53 6,784 –a–c— c:\windows\system32\dllcache\serscan.sys
2009-03-16 13:50 . 2001-08-17 13:52 11,648 –a–c— c:\windows\system32\dllcache\scsiprnt.sys
2009-03-16 13:50 . 2008-04-14 00:15 11,520 –a–c— c:\windows\system32\dllcache\scsiscan.sys
2009-03-16 13:50 . 2001-08-17 13:53 6,912 –a–c— c:\windows\system32\dllcache\seaddsmc.sys
2009-03-16 13:49 . 2001-08-17 22:36 495,616 –a–c— c:\windows\system32\dllcache\sblfx.dll
2009-03-16 13:49 . 2001-08-17 14:56 245,632 –a–c— c:\windows\system32\dllcache\s3savmx.dll
2009-03-16 13:49 . 2001-08-17 14:56 198,400 –a–c— c:\windows\system32\dllcache\s3sav4.dll
2009-03-16 13:49 . 2001-08-17 14:56 179,264 –a–c— c:\windows\system32\dllcache\s3sav3d.dll
2009-03-16 13:49 . 2001-08-17 12:50 77,824 –a–c— c:\windows\system32\dllcache\s3sav4m.sys
2009-03-16 13:49 . 2001-08-17 12:50 75,392 –a–c— c:\windows\system32\dllcache\s3savmxm.sys
2009-03-16 13:49 . 2001-08-17 12:50 61,504 –a–c— c:\windows\system32\dllcache\s3sav3dm.sys
2009-03-16 13:49 . 2008-04-14 00:10 43,904 –a–c— c:\windows\system32\dllcache\sbp2port.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmusbm.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmn50m.sys
2009-03-16 13:49 . 2001-08-17 13:51 17,280 –a–c— c:\windows\system32\dllcache\scr111.sys
2009-03-16 13:49 . 2001-08-17 13:51 16,640 –a–c— c:\windows\system32\dllcache\scmstcs.sys
2009-03-16 13:47 . 2001-08-17 13:28 899,146 –a–c— c:\windows\system32\dllcache\r2mdkxga.sys
2009-03-16 13:46 . 2008-04-14 05:42 363,520 –a–c— c:\windows\system32\dllcache\psisdecd.dll
2009-03-16 13:45 . 2001-08-17 14:05 351,616 –a–c— c:\windows\system32\dllcache\ovcodek2.sys
2009-03-16 13:44 . 2001-08-17 12:50 198,144 –a–c— c:\windows\system32\dllcache\nv3.sys
2009-03-16 13:44 . 2001-08-17 22:36 123,776 –a–c— c:\windows\system32\dllcache\nv3.dll
2009-03-16 13:44 . 2001-08-17 12:49 51,552 –a–c— c:\windows\system32\dllcache\ntgrip.sys
2009-03-16 13:44 . 2001-08-17 13:47 9,344 –a–c— c:\windows\system32\dllcache\ntapm.sys
2009-03-16 13:44 . 2001-08-17 13:53 7,552 –a–c— c:\windows\system32\dllcache\nsmmc.sys
2009-03-16 13:42 . 2001-08-17 12:50 103,296 –a–c— c:\windows\system32\dllcache\mtxvideo.sys
2009-03-16 13:42 . 2008-04-14 00:16 49,024 –a–c— c:\windows\system32\dllcache\mstape.sys
2009-03-16 13:42 . 2008-04-14 00:24 22,016 –a–c— c:\windows\system32\dllcache\msircomm.sys
2009-03-16 13:42 . 2001-08-17 13:50 21,888 –a–c— c:\windows\system32\dllcache\mxcard.sys
2009-03-16 13:42 . 2001-08-17 13:49 19,968 –a–c— c:\windows\system32\dllcache\mxnic.sys
2009-03-16 13:42 . 2001-08-17 22:36 19,968 –a–c— c:\windows\system32\dllcache\mxicfg.dll
2009-03-16 13:42 . 2001-08-17 13:48 12,416 –a–c— c:\windows\system32\dllcache\msriffwv.sys
2009-03-16 13:42 . 2001-08-17 22:36 7,168 –a–c— c:\windows\system32\dllcache\mxport.dll
2009-03-16 13:42 . 2008-04-14 00:09 5,504 –a–c— c:\windows\system32\dllcache\mstee.sys
2009-03-16 13:42 . 2001-08-17 14:00 2,944 –a–c— c:\windows\system32\dllcache\msmpu401.sys
2009-03-16 13:40 . 2001-08-17 13:28 802,683 –a–c— c:\windows\system32\dllcache\ltsm.sys
2009-03-16 13:39 . 2008-04-14 05:41 253,952 –a–c— c:\windows\system32\dllcache\kdsusd.dll
2009-03-16 13:38 . 2008-04-14 05:41 702,845 –a–c— c:\windows\system32\dllcache\i81xdnt5.dll
2009-03-16 13:37 . 2001-08-17 13:28 542,879 –a–c— c:\windows\system32\dllcache\hsf_msft.sys
2009-03-16 13:36 . 2001-08-17 14:56 1,733,120 –a–c— c:\windows\system32\dllcache\g400d.dll
2009-03-16 13:35 . 2001-08-17 12:15 455,680 –a–c— c:\windows\system32\dllcache\fus2base.sys
2009-03-16 13:34 . 2001-08-17 13:28 634,134 –a–c— c:\windows\system32\dllcache\el656ct5.sys
2009-03-16 13:33 . 2001-08-17 12:14 952,007 –a–c— c:\windows\system32\dllcache\diwan.sys
2009-03-16 13:32 . 2001-08-17 22:36 256,512 –a–c— c:\windows\system32\dllcache\devcon32.dll
2009-03-16 13:31 . 2001-08-17 12:13 980,034 –a–c— c:\windows\system32\dllcache\cicap.sys
2009-03-16 13:30 . 2001-08-17 13:28 871,388 –a–c— c:\windows\system32\dllcache\bcmdm.sys
2009-03-16 13:29 . 2001-08-17 14:55 382,592 –a–c— c:\windows\system32\dllcache\atidrab.dll
2009-03-16 13:28 . 2001-08-17 13:28 762,780 –a–c— c:\windows\system32\dllcache\3cwmcru.sys
2009-03-16 13:27 . 2001-08-17 14:56 66,048 –a–c— c:\windows\system32\dllcache\s3legacy.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a—— c:\windows\system32\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a–c— c:\windows\system32\dllcache\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a—— c:\windows\system32\kbdkor.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a–c— c:\windows\system32\dllcache\kbdkor.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a—— c:\windows\system32\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a–c— c:\windows\system32\dllcache\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a—— c:\windows\system32\kbd103.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a–c— c:\windows\system32\dllcache\kbd103.dll
2009-03-16 01:47 . 2009-03-16 12:37 1,374 –a—— c:\windows\imsins.BAK
2009-03-15 21:05 . 2009-03-15 21:05 d——– c:\documents and settings\Administrator
2009-03-15 11:48 . 2009-03-16 02:05 d——– c:\documents and settings\Kristy\Application Data\Azureus
2009-03-15 11:48 . 2009-03-15 11:48 d——– c:\documents and settings\All Users\Application Data\Azureus
2009-03-15 03:15 . 2009-03-15 03:15 82 –a—— c:\windows\wininit.ini
2009-03-15 01:52 . 2009-03-15 02:07 d——– c:\program files\Trojan Remover
2009-03-15 01:52 . 2006-05-25 14:52 162,304 –a—— c:\windows\system32\ztvunrar36.dll
2009-03-15 01:52 . 2003-02-02 19:06 153,088 –a—— c:\windows\system32\UNRAR3.dll
2009-03-15 01:52 . 2005-08-26 00:50 77,312 –a—— c:\windows\system32\ztvunace26.dll
2009-03-15 01:52 . 2002-03-06 00:00 75,264 –a—— c:\windows\system32\unacev2.dll
2009-03-15 01:52 . 2006-06-19 12:01 69,632 –a—— c:\windows\system32\ztvcabinet.dll
2009-03-15 01:48 . 2009-03-15 02:08 d——– c:\program files\Registry Winner

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-17 08:03 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-09 23:46 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-08 08:59 ——— d—–w c:\program files\Java
2009-03-08 00:07 ——— d—–w c:\program files\CCleaner
2009-03-08 00:07 ——— d—–w c:\program files\7-Zip
2009-03-08 00:04 ——— d—–w c:\program files\Foxit Software
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2008-12-20 23:15 826,368 —-a-w c:\windows\system32\wininet.dll
2008-08-09 13:34 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080920080810\index.dat
.

((((((((((((((((((((((((((((( SnapShot_2009-03-16_16.38.21.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
+ 2009-02-13 16:17:49 45,416 —-a-w c:\windows\system32\drivers\avgntdd.sys
+ 2009-02-13 16:29:11 22,360 —-a-w c:\windows\system32\drivers\avgntmgr.sys
+ 2009-02-13 19:22:54 95,576 —-a-w c:\windows\system32\drivers\avipbb.sys
+ 2009-02-13 16:50:02 28,376 —-a-w c:\windows\system32\drivers\ssmdrv.sys
+ 2004-08-04 12:00:00 28,672 —-a-w c:\windows\system32\NSREG.DLL
+ 2009-03-18 06:42:45 16,384 —-atw c:\windows\temp\Perflib_Perfdata_534.dat
+ 2008-07-29 13:05:06 161,784 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2008-07-29 08:54:08 225,280 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 13:05:08 572,928 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 13:05:08 655,872 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 13:05:08 3,768,312 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2008-07-29 13:05:10 3,783,672 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 11:07:42 59,904 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2008-07-29 11:07:42 59,904 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 13:05:06 38,912 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 13:05:06 39,936 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 13:05:08 66,560 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 13:05:08 56,832 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 13:05:06 65,024 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 13:05:08 65,024 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 13:05:06 66,048 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 13:05:08 64,512 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 13:05:08 46,592 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 13:05:08 46,080 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 13:05:08 62,976 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2007-11-07 07:19:20 54,272 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-03-08 160592]
"PlaxoSysTray"="c:\program files\Plaxo\3.19.0.16\PlaxoSysTray.exe" [2009-02-09 20480]
"uTorrent"="c:\documents and settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe" [2009-03-07 281392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.MSNAUDIO"= msnaudio.acm
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GetGoDM]
–a—— 2009-02-11 03:40 3280568 c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
–a—— 2009-02-09 11:08 371271 c:\program files\Plaxo\3.19.0.16\PlaxoHelper_en.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2009-02-04 12:27 23975720 c:\program files\Skype\Phone\Skype.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\eMule Plus\\eMule.exe"=
"c:\\Documents and Settings\\Kristy\\My Documents\\Documents\\uTorrent\\uTorrent.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R3 ATE_PROCMON;ATE_PROCMON; [x]
R4 08FX8JFV;08FX8JFV; [x]
R4 10YX3FD3;10YX3FD3; [x]
R4 19T3H;19T3H; [x]
R4 1MV0BLHXE;1MV0BLHXE; [x]
R4 1Q0PLJK5F7EO;1Q0PLJK5F7EO; [x]
R4 2NXBWF;2NXBWF; [x]
R4 2O1L3;2O1L3; [x]
R4 2Z8EHAJGE1;2Z8EHAJGE1; [x]
R4 3GJ665NT766;3GJ665NT766; [x]
R4 3Q3BVMFQZTJ;3Q3BVMFQZTJ; [x]
R4 4B5HRB6B9;4B5HRB6B9; [x]
R4 5AX67SALZ;5AX67SALZ; [x]
R4 5ZHFDU4;5ZHFDU4; [x]
R4 8IT5Y44;8IT5Y44; [x]
R4 ADA2EG1;ADA2EG1; [x]
R4 AQ0LBRDMS1M;AQ0LBRDMS1M; [x]
R4 BBCAH;BBCAH; [x]
R4 BPYV25IQ;BPYV25IQ; [x]
R4 BQAGVE30;BQAGVE30; [x]
R4 CMUODPSJO8DW;CMUODPSJO8DW; [x]
R4 D0V37G51X3;D0V37G51X3; [x]
R4 D9XBL1I9PX;D9XBL1I9PX; [x]
R4 DULWFJE;DULWFJE; [x]
R4 FEK1UEF;FEK1UEF; [x]
R4 GAY2F;GAY2F; [x]
R4 H0252AAY6QPU;H0252AAY6QPU; [x]
R4 H0PC5IV3;H0PC5IV3; [x]
R4 H76MC;H76MC; [x]
R4 HC5IOVVW3;HC5IOVVW3; [x]
R4 IC56FJ2OJE;IC56FJ2OJE; [x]
R4 II9TFZ;II9TFZ; [x]
R4 J1GCP0;J1GCP0; [x]
R4 J33FQ1F;J33FQ1F; [x]
R4 L69Y08;L69Y08; [x]
R4 LHFUA;LHFUA; [x]
R4 LTQLZP2FX6;LTQLZP2FX6; [x]
R4 MPJ5MST1U93;MPJ5MST1U93; [x]
R4 MUAL22T09A;MUAL22T09A; [x]
R4 NBG7GOASD1KS;NBG7GOASD1KS; [x]
R4 PXNMBMJR;PXNMBMJR; [x]
R4 R9I2V5;R9I2V5; [x]
R4 RO3SKV;RO3SKV; [x]
R4 ROO5X4F;ROO5X4F; [x]
R4 SQFAY;SQFAY; [x]
R4 TERDNO1D5;TERDNO1D5; [x]
R4 UNGVG2LBWEL;UNGVG2LBWEL; [x]
R4 VMAJ4WFY;VMAJ4WFY; [x]
R4 W42CWKTK7;W42CWKTK7; [x]
R4 Y2EN4QW5889;Y2EN4QW5889; [x]
R4 YT92TP;YT92TP; [x]
R4 YTMP1NBHT2;YTMP1NBHT2; [x]
R4 ZGC2AK;ZGC2AK; [x]
R4 ZO48L;ZO48L; [x]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-05 108289]


— Other Services/Drivers In Memory —

*NewlyCreated* - SSMDRV
*Deregistered* - 6to4
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - AntiVirSchedulerService
*Deregistered* - AntiVirService
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - avgio
*Deregistered* - avgntflt
*Deregistered* - avipbb
*Deregistered* - BANTExt
*Deregistered* - Beep
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - Cdfs
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - Dnscache
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - Fastfat
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTTP
*Deregistered* - ImapiService
*Deregistered* - Ip6Fw
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - JavaQuickStarterService
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LexBceS
*Deregistered* - LmHosts
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - pcouffin
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - PROCEXP113
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sptd
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - ssmdrv
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - Tcpip6
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - tunmp
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder

2009-03-15 c:\windows\Tasks\Registry Winner Schedule.job
- c:\program files\Registry Winner\RegistryWinner.exe []
.
.
——- Supplementary Scan ——-
.
IE: &Down&load &Link& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatch.htm
IE: &Down&load All &Links& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
IE: &GetGo Toolbar Search - c:\program files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{01A13E40-2F55-4397-B39B-7851BCFB8008} - c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - component: c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\extensions\[removed]\platform\WINNT_x86-msvc\components\lpxpcom.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-18 12:46:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(504)
c:\windows\system32\COMRes.dll
.
Completion time: 2009-03-18 12:48:34
ComboFix-quarantined-files.txt 2009-03-18 17:48:25
ComboFix2.txt 2009-03-17 18:38:00
ComboFix3.txt 2009-03-17 04:36:17
ComboFix4.txt 2009-03-17 01:19:41
ComboFix5.txt 2009-03-18 17:43:50

Pre-Run: 41,678,618,624 bytes free
Post-Run: 41,669,001,216 bytes free

419 — E O F — 2009-03-09 21:51:30
Turn off Windows Firewall and get one of these free ones.

Below is a list of two free firewalls (in no order of preference).It is important to note that you should only have one firewall installed at a time, but you can download to your Desktop and install each in turn to see which one you prefer.

I'll look at your scan when I get home from work.
Hello LDTate, My computer is a lot better but every now and then the computer doesn't wont to respond, not the actual windows but like the start menu and the task bar, and every time I put in a CD/DVD it don't wont to auto-start.
Combofix deletes the autorun feature.
Many infections are coming from infected Thumb Drives / shared external devices.
When you plug in an infected device, it will autorun / install the infection.


Now lets see what a new Combofix scan looks like please.

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Note: Combofix will run without the Recovery Console installed.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please don't attach the scans / logs, use "copy/paste".

Also please describe how your computer behaves at the moment.
I guess it's still the same… I noticed this about 2 or 3 scans ago when I was playing (not messing with anything) just I guess looking, in my services, there's a ton of baddies in there. Things that don't have a description, just a whole bunch of letters, like about almost 55 services but there disabled though.


ComboFix 09-03-15.01 - Kristy 2009-03-20 3:22:09.10 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2009-02-20 to 2009-03-20 )))))))))))))))))))))))))))))))
.

2009-03-19 16:30 . 2009-03-19 16:30 d——– c:\program files\directx
2009-03-19 16:24 . 2009-03-19 16:24 d——– c:\program files\SpongeBob SquarePants
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Michael
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Kristy\Application Data\Panasonic
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Kristy\Application Data\InstallShield
2009-03-18 22:20 . 2009-03-19 00:08 d——– c:\program files\Outpost Firewall 1.0
2009-03-18 22:20 . 2009-03-18 22:20 d——– c:\program files\Common Files\Agnitum Shared
2009-03-18 18:13 . 2009-03-18 21:17 120 –a—— c:\windows\CIS_Setup_3.8.65951.477_XP_Vista_x32.INI
2009-03-18 16:12 . 2009-03-20 01:00 3,180 –a—— c:\windows\system32\notepad.ini
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a—— c:\windows\system32\notepad.exe.orig
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a–c— c:\windows\system32\dllcache\notepad.exe.orig
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a—— c:\windows\notepad.exe.orig
2009-03-18 15:37 . 2009-03-18 15:37 0 –a—— c:\windows\K092L3IQ.tmp
2009-03-18 01:29 . 2009-03-18 01:29 d——– c:\program files\Avira
2009-03-18 01:29 . 2009-03-18 01:29 d——– c:\documents and settings\All Users\Application Data\Avira
2009-03-18 01:29 . 2009-02-13 11:31 55,640 –a—— c:\windows\system32\drivers\avgntflt.sys
2009-03-17 13:34 . 2009-03-18 05:23 d——– c:\program files\QFLOZJC5K
2009-03-17 13:34 . 2009-03-18 05:23 d——– c:\program files\PWHNMWA7DXAX
2009-03-17 06:12 . 2009-03-18 05:23 d——– c:\program files\V1M8H117OBDI
2009-03-17 06:12 . 2009-03-18 05:23 d——– c:\program files\RB3VBY8R
2009-03-17 05:50 . 2009-03-18 05:23 d——– c:\program files\ROLAZVR5
2009-03-17 05:40 . 2009-03-18 05:23 d——– c:\program files\LOVZEC
2009-03-17 02:59 . 2009-03-18 05:23 d——– c:\program files\9E3E5IBOMKOE
2009-03-17 02:40 . 2009-03-18 05:23 d——– c:\program files\T7ADVS1KE1U
2009-03-17 01:30 . 2009-03-18 05:23 d——– c:\program files\X7LW1WZIV
2009-03-17 01:29 . 2009-03-18 05:23 d——– c:\program files\KHU2T7RCOWKX
2009-03-17 01:29 . 2009-03-17 01:29 0 –a—— c:\windows\ZCMBPO.bat
2009-03-16 13:59 . 2008-04-14 05:42 116,224 –a–c— c:\windows\system32\dllcache\xrxwiadr.dll
2009-03-16 13:59 . 2001-08-17 22:37 99,865 –a–c— c:\windows\system32\dllcache\xlog.exe
2009-03-16 13:59 . 2001-08-17 22:37 27,648 –a–c— c:\windows\system32\dllcache\xrxftplt.exe
2009-03-16 13:59 . 2001-08-17 22:36 23,040 –a–c— c:\windows\system32\dllcache\xrxwbtmp.dll
2009-03-16 13:59 . 2008-04-13 22:04 19,455 –a–c— c:\windows\system32\dllcache\wvchntxx.sys
2009-03-16 13:59 . 2008-04-14 00:16 19,200 –a–c— c:\windows\system32\dllcache\wstcodec.sys
2009-03-16 13:59 . 2008-04-14 05:42 18,944 –a–c— c:\windows\system32\dllcache\xrxscnui.dll
2009-03-16 13:59 . 2001-08-17 12:11 16,970 –a–c— c:\windows\system32\dllcache\xem336n5.sys
2009-03-16 13:59 . 2008-04-13 22:04 12,063 –a–c— c:\windows\system32\dllcache\wsiintxx.sys
2009-03-16 13:59 . 2008-04-14 05:42 8,192 –a–c— c:\windows\system32\dllcache\wshirda.dll
2009-03-16 13:59 . 2001-08-17 22:37 4,608 –a–c— c:\windows\system32\dllcache\xrxflnch.exe
2009-03-16 13:57 . 2001-08-17 13:28 794,654 –a–c— c:\windows\system32\dllcache\usr1801.sys
2009-03-16 13:56 . 2001-08-17 22:36 525,568 –a–c— c:\windows\system32\dllcache\tridxp.dll
2009-03-16 13:55 . 2001-08-17 14:01 241,664 –a–c— c:\windows\system32\dllcache\tosdvd02.sys
2009-03-16 13:54 . 2001-08-17 12:18 285,760 –a–c— c:\windows\system32\dllcache\stlnata.sys
2009-03-16 13:53 . 2001-08-17 22:36 114,688 –a–c— c:\windows\system32\dllcache\sonypi.dll
2009-03-16 13:53 . 2001-08-17 22:36 106,584 –a–c— c:\windows\system32\dllcache\spdports.dll
2009-03-16 13:53 . 2001-08-17 22:36 99,328 –a–c— c:\windows\system32\dllcache\srusd.dll
2009-03-16 13:53 . 2001-08-17 13:51 61,824 –a–c— c:\windows\system32\dllcache\speed.sys
2009-03-16 13:53 . 2001-08-17 12:51 37,040 –a–c— c:\windows\system32\dllcache\sonypi.sys
2009-03-16 13:53 . 2001-08-17 22:36 24,660 –a–c— c:\windows\system32\dllcache\spxupchk.dll
2009-03-16 13:53 . 2001-08-17 12:51 20,752 –a–c— c:\windows\system32\dllcache\sonync.sys
2009-03-16 13:53 . 2001-08-17 14:07 19,072 –a–c— c:\windows\system32\dllcache\sparrow.sys
2009-03-16 13:53 . 2001-08-17 13:53 9,600 –a–c— c:\windows\system32\dllcache\sonymc.sys
2009-03-16 13:53 . 2001-08-17 13:56 7,552 –a–c— c:\windows\system32\dllcache\sonypvu1.sys
2009-03-16 13:53 . 2008-04-14 00:10 7,552 –a–c— c:\windows\system32\dllcache\sonyait.sys
2009-03-16 13:53 . 2001-08-17 13:53 7,040 –a–c— c:\windows\system32\dllcache\snyaitmc.sys
2009-03-16 13:51 . 2001-08-17 22:36 386,560 –a–c— c:\windows\system32\dllcache\sgiul50.dll
2009-03-16 13:51 . 2001-08-17 14:56 252,032 –a–c— c:\windows\system32\dllcache\sis300iv.dll
2009-03-16 13:51 . 2001-08-17 22:36 238,592 –a–c— c:\windows\system32\dllcache\sisgrv.dll
2009-03-16 13:51 . 2001-07-21 14:29 161,568 –a–c— c:\windows\system32\dllcache\sgsmusb.sys
2009-03-16 13:51 . 2001-08-17 14:56 150,144 –a–c— c:\windows\system32\dllcache\sis6306v.dll
2009-03-16 13:51 . 2001-08-17 12:50 104,064 –a–c— c:\windows\system32\dllcache\sisgrp.sys
2009-03-16 13:51 . 2001-08-17 12:50 101,760 –a–c— c:\windows\system32\dllcache\sis300ip.sys
2009-03-16 13:51 . 2001-08-17 12:51 98,080 –a–c— c:\windows\system32\dllcache\sgiulnt5.sys
2009-03-16 13:51 . 2001-08-17 12:50 68,608 –a–c— c:\windows\system32\dllcache\sis6306p.sys
2009-03-16 13:51 . 2001-08-17 12:19 36,480 –a–c— c:\windows\system32\dllcache\sfmanm.sys
2009-03-16 13:51 . 2001-07-21 14:29 18,400 –a–c— c:\windows\system32\dllcache\sgsmld.sys
2009-03-16 13:51 . 2001-08-17 13:48 17,664 –a–c— c:\windows\system32\dllcache\sermouse.sys
2009-03-16 13:51 . 2001-08-17 13:53 6,784 –a–c— c:\windows\system32\dllcache\serscan.sys
2009-03-16 13:50 . 2001-08-17 13:52 11,648 –a–c— c:\windows\system32\dllcache\scsiprnt.sys
2009-03-16 13:50 . 2008-04-14 00:15 11,520 –a–c— c:\windows\system32\dllcache\scsiscan.sys
2009-03-16 13:50 . 2001-08-17 13:53 6,912 –a–c— c:\windows\system32\dllcache\seaddsmc.sys
2009-03-16 13:49 . 2001-08-17 22:36 495,616 –a–c— c:\windows\system32\dllcache\sblfx.dll
2009-03-16 13:49 . 2001-08-17 14:56 245,632 –a–c— c:\windows\system32\dllcache\s3savmx.dll
2009-03-16 13:49 . 2001-08-17 14:56 198,400 –a–c— c:\windows\system32\dllcache\s3sav4.dll
2009-03-16 13:49 . 2001-08-17 14:56 179,264 –a–c— c:\windows\system32\dllcache\s3sav3d.dll
2009-03-16 13:49 . 2001-08-17 12:50 77,824 –a–c— c:\windows\system32\dllcache\s3sav4m.sys
2009-03-16 13:49 . 2001-08-17 12:50 75,392 –a–c— c:\windows\system32\dllcache\s3savmxm.sys
2009-03-16 13:49 . 2001-08-17 12:50 61,504 –a–c— c:\windows\system32\dllcache\s3sav3dm.sys
2009-03-16 13:49 . 2008-04-14 00:10 43,904 –a–c— c:\windows\system32\dllcache\sbp2port.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmusbm.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmn50m.sys
2009-03-16 13:49 . 2001-08-17 13:51 17,280 –a–c— c:\windows\system32\dllcache\scr111.sys
2009-03-16 13:49 . 2001-08-17 13:51 16,640 –a–c— c:\windows\system32\dllcache\scmstcs.sys
2009-03-16 13:47 . 2001-08-17 13:28 899,146 –a–c— c:\windows\system32\dllcache\r2mdkxga.sys
2009-03-16 13:46 . 2008-04-14 05:42 363,520 –a–c— c:\windows\system32\dllcache\psisdecd.dll
2009-03-16 13:45 . 2001-08-17 14:05 351,616 –a–c— c:\windows\system32\dllcache\ovcodek2.sys
2009-03-16 13:44 . 2001-08-17 12:50 198,144 –a–c— c:\windows\system32\dllcache\nv3.sys
2009-03-16 13:44 . 2001-08-17 22:36 123,776 –a–c— c:\windows\system32\dllcache\nv3.dll
2009-03-16 13:44 . 2001-08-17 12:49 51,552 –a–c— c:\windows\system32\dllcache\ntgrip.sys
2009-03-16 13:44 . 2001-08-17 13:47 9,344 –a–c— c:\windows\system32\dllcache\ntapm.sys
2009-03-16 13:44 . 2001-08-17 13:53 7,552 –a–c— c:\windows\system32\dllcache\nsmmc.sys
2009-03-16 13:42 . 2001-08-17 12:50 103,296 –a–c— c:\windows\system32\dllcache\mtxvideo.sys
2009-03-16 13:42 . 2008-04-14 00:16 49,024 –a–c— c:\windows\system32\dllcache\mstape.sys
2009-03-16 13:42 . 2008-04-14 00:24 22,016 –a–c— c:\windows\system32\dllcache\msircomm.sys
2009-03-16 13:42 . 2001-08-17 13:50 21,888 –a–c— c:\windows\system32\dllcache\mxcard.sys
2009-03-16 13:42 . 2001-08-17 13:49 19,968 –a–c— c:\windows\system32\dllcache\mxnic.sys
2009-03-16 13:42 . 2001-08-17 22:36 19,968 –a–c— c:\windows\system32\dllcache\mxicfg.dll
2009-03-16 13:42 . 2001-08-17 13:48 12,416 –a–c— c:\windows\system32\dllcache\msriffwv.sys
2009-03-16 13:42 . 2001-08-17 22:36 7,168 –a–c— c:\windows\system32\dllcache\mxport.dll
2009-03-16 13:42 . 2008-04-14 00:09 5,504 –a–c— c:\windows\system32\dllcache\mstee.sys
2009-03-16 13:42 . 2001-08-17 14:00 2,944 –a–c— c:\windows\system32\dllcache\msmpu401.sys
2009-03-16 13:40 . 2001-08-17 13:28 802,683 –a–c— c:\windows\system32\dllcache\ltsm.sys
2009-03-16 13:39 . 2008-04-14 05:41 253,952 –a–c— c:\windows\system32\dllcache\kdsusd.dll
2009-03-16 13:38 . 2008-04-14 05:41 702,845 –a–c— c:\windows\system32\dllcache\i81xdnt5.dll
2009-03-16 13:37 . 2001-08-17 13:28 542,879 –a–c— c:\windows\system32\dllcache\hsf_msft.sys
2009-03-16 13:36 . 2001-08-17 14:56 1,733,120 –a–c— c:\windows\system32\dllcache\g400d.dll
2009-03-16 13:35 . 2001-08-17 12:15 455,680 –a–c— c:\windows\system32\dllcache\fus2base.sys
2009-03-16 13:34 . 2001-08-17 13:28 634,134 –a–c— c:\windows\system32\dllcache\el656ct5.sys
2009-03-16 13:33 . 2001-08-17 12:14 952,007 –a–c— c:\windows\system32\dllcache\diwan.sys
2009-03-16 13:32 . 2001-08-17 22:36 256,512 –a–c— c:\windows\system32\dllcache\devcon32.dll
2009-03-16 13:31 . 2001-08-17 12:13 980,034 –a–c— c:\windows\system32\dllcache\cicap.sys
2009-03-16 13:30 . 2001-08-17 13:28 871,388 –a–c— c:\windows\system32\dllcache\bcmdm.sys
2009-03-16 13:29 . 2001-08-17 14:55 382,592 –a–c— c:\windows\system32\dllcache\atidrab.dll
2009-03-16 13:28 . 2001-08-17 13:28 762,780 –a–c— c:\windows\system32\dllcache\3cwmcru.sys
2009-03-16 13:27 . 2001-08-17 14:56 66,048 –a–c— c:\windows\system32\dllcache\s3legacy.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a—— c:\windows\system32\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a–c— c:\windows\system32\dllcache\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a—— c:\windows\system32\kbdkor.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a–c— c:\windows\system32\dllcache\kbdkor.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a—— c:\windows\system32\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a–c— c:\windows\system32\dllcache\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a—— c:\windows\system32\kbd103.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-17 08:03 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-09 23:46 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-08 08:59 ——— d—–w c:\program files\Java
2009-03-08 00:07 ——— d—–w c:\program files\CCleaner
2009-03-08 00:07 ——— d—–w c:\program files\7-Zip
2009-03-08 00:04 ——— d—–w c:\program files\Foxit Software
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2008-12-20 23:15 826,368 —-a-w c:\windows\system32\wininet.dll
2008-08-09 13:34 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080920080810\index.dat
.

((((((((((((((((((((((((((((( SnapShot_2009-03-16_16.38.21.06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 01:02:28 163,328 —-a-w c:\windows\ERDNT\subs\ERDNT.EXE
- 2008-04-14 10:42:30 69,120 —-a-w c:\windows\notepad.exe
+ 2008-10-31 05:00:00 266,752 —-a-w c:\windows\notepad.exe
- 2008-04-14 10:42:30 69,120 ——w c:\windows\ServicePackFiles\i386\notepad.exe
+ 2008-10-31 05:00:00 266,752 —-a-w c:\windows\ServicePackFiles\i386\notepad.exe
- 2008-04-14 10:42:30 69,120 -c–a-w c:\windows\system32\dllcache\notepad.exe
+ 2008-10-31 05:00:00 266,752 -c–a-w c:\windows\system32\dllcache\notepad.exe
+ 2009-02-13 16:17:49 45,416 —-a-w c:\windows\system32\drivers\avgntdd.sys
+ 2009-02-13 16:29:11 22,360 —-a-w c:\windows\system32\drivers\avgntmgr.sys
+ 2009-02-13 19:22:54 95,576 —-a-w c:\windows\system32\drivers\avipbb.sys
+ 2009-02-13 16:50:02 28,376 —-a-w c:\windows\system32\drivers\ssmdrv.sys
- 2008-04-14 10:42:30 69,120 —-a-w c:\windows\system32\notepad.exe
+ 2008-10-31 05:00:00 266,752 —-a-w c:\windows\system32\notepad.exe
+ 2004-08-04 12:00:00 28,672 —-a-w c:\windows\system32\NSREG.DLL
+ 2009-03-20 08:20:27 16,384 —-atw c:\windows\temp\Perflib_Perfdata_5c8.dat
+ 2008-07-29 13:05:06 161,784 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2008-07-29 08:54:08 225,280 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 13:05:08 572,928 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 13:05:08 655,872 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 13:05:08 3,768,312 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2008-07-29 13:05:10 3,783,672 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 11:07:42 59,904 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2008-07-29 11:07:42 59,904 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 13:05:06 38,912 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 13:05:06 39,936 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 13:05:08 66,560 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 13:05:08 56,832 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 13:05:06 65,024 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 13:05:08 65,024 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 13:05:06 66,048 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 13:05:08 64,512 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 13:05:08 46,592 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 13:05:08 46,080 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 13:05:08 62,976 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2007-11-07 07:19:20 54,272 —-a-w c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-03-08 160592]
"PlaxoSysTray"="c:\program files\Plaxo\3.19.0.16\PlaxoSysTray.exe" [2009-02-09 20480]
"uTorrent"="c:\documents and settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe" [2009-03-07 281392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Outpost Firewall"="c:\program files\Outpost Firewall 1.0\outpost.exe" [2002-06-14 78848]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.MSNAUDIO"= msnaudio.acm
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GetGoDM]
–a—— 2009-02-11 03:40 3280568 c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
–a—— 2009-02-09 11:08 371271 c:\program files\Plaxo\3.19.0.16\PlaxoHelper_en.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2009-02-04 12:27 23975720 c:\program files\Skype\Phone\Skype.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\eMule Plus\\eMule.exe"=
"c:\\Documents and Settings\\Kristy\\My Documents\\Documents\\uTorrent\\uTorrent.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R3 ATE_PROCMON;ATE_PROCMON; [x]
R4 08FX8JFV;08FX8JFV; [x]
R4 10YX3FD3;10YX3FD3; [x]
R4 19T3H;19T3H; [x]
R4 1MV0BLHXE;1MV0BLHXE; [x]
R4 1Q0PLJK5F7EO;1Q0PLJK5F7EO; [x]
R4 2NXBWF;2NXBWF; [x]
R4 2O1L3;2O1L3; [x]
R4 2Z8EHAJGE1;2Z8EHAJGE1; [x]
R4 3GJ665NT766;3GJ665NT766; [x]
R4 3Q3BVMFQZTJ;3Q3BVMFQZTJ; [x]
R4 4B5HRB6B9;4B5HRB6B9; [x]
R4 5AX67SALZ;5AX67SALZ; [x]
R4 5ZHFDU4;5ZHFDU4; [x]
R4 8IT5Y44;8IT5Y44; [x]
R4 ADA2EG1;ADA2EG1; [x]
R4 AQ0LBRDMS1M;AQ0LBRDMS1M; [x]
R4 BBCAH;BBCAH; [x]
R4 BPYV25IQ;BPYV25IQ; [x]
R4 BQAGVE30;BQAGVE30; [x]
R4 CMUODPSJO8DW;CMUODPSJO8DW; [x]
R4 D0V37G51X3;D0V37G51X3; [x]
R4 D9XBL1I9PX;D9XBL1I9PX; [x]
R4 DULWFJE;DULWFJE; [x]
R4 FEK1UEF;FEK1UEF; [x]
R4 GAY2F;GAY2F; [x]
R4 H0252AAY6QPU;H0252AAY6QPU; [x]
R4 H0PC5IV3;H0PC5IV3; [x]
R4 H76MC;H76MC; [x]
R4 HC5IOVVW3;HC5IOVVW3; [x]
R4 IC56FJ2OJE;IC56FJ2OJE; [x]
R4 II9TFZ;II9TFZ; [x]
R4 J1GCP0;J1GCP0; [x]
R4 J33FQ1F;J33FQ1F; [x]
R4 L69Y08;L69Y08; [x]
R4 LHFUA;LHFUA; [x]
R4 LTQLZP2FX6;LTQLZP2FX6; [x]
R4 MPJ5MST1U93;MPJ5MST1U93; [x]
R4 MUAL22T09A;MUAL22T09A; [x]
R4 NBG7GOASD1KS;NBG7GOASD1KS; [x]
R4 PXNMBMJR;PXNMBMJR; [x]
R4 R9I2V5;R9I2V5; [x]
R4 RO3SKV;RO3SKV; [x]
R4 ROO5X4F;ROO5X4F; [x]
R4 SQFAY;SQFAY; [x]
R4 TERDNO1D5;TERDNO1D5; [x]
R4 UNGVG2LBWEL;UNGVG2LBWEL; [x]
R4 VMAJ4WFY;VMAJ4WFY; [x]
R4 W42CWKTK7;W42CWKTK7; [x]
R4 Y2EN4QW5889;Y2EN4QW5889; [x]
R4 YT92TP;YT92TP; [x]
R4 YTMP1NBHT2;YTMP1NBHT2; [x]
R4 ZGC2AK;ZGC2AK; [x]
R4 ZO48L;ZO48L; [x]
S1 VFILT;Outpost Firewall Kernel Driver;c:\progra~1\OUTPOS~1.0\kernel\2000\FILTNT.SYS [2002-06-14 90368]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-05 108289]
S3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);c:\progra~1\OUTPOS~1.0\kernel\ADBLOCK.DLL [2002-06-14 15552]
S3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);c:\progra~1\OUTPOS~1.0\kernel\CONTENT.DLL [2002-06-14 3904]
S3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);c:\progra~1\OUTPOS~1.0\kernel\DNSCACHE.DLL [2002-06-14 6144]
S3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\FTPFILT.DLL [2002-06-14 6304]
S3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\HTMLFILT.DLL [2002-06-14 7776]
S3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\HTTPFILT.DLL [2002-06-14 9152]
S3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\IMAPFILT.DLL [2002-06-14 7072]
S3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\MAILFILT.DLL [2002-06-14 9920]
S3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\NNTPFILT.DLL [2002-06-14 6656]
S3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\POP3FILT.DLL [2002-06-14 7136]
S3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);c:\progra~1\OUTPOS~1.0\kernel\PROTECT.DLL [2002-06-14 15584]


— Other Services/Drivers In Memory —

*Deregistered* - 6to4
*Deregistered* - ADBLOCK.DLL
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - AntiVirSchedulerService
*Deregistered* - AntiVirService
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - avgio
*Deregistered* - avgntflt
*Deregistered* - avipbb
*Deregistered* - BANTExt
*Deregistered* - Beep
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - Cdfs
*Deregistered* - CONTENT.DLL
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - Dnscache
*Deregistered* - DNSCACHE.DLL
*Deregistered* - EventSystem
*Deregistered* - Fastfat
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - FTPFILT.DLL
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - HTMLFILT.DLL
*Deregistered* - HTTP
*Deregistered* - HTTPFILT.DLL
*Deregistered* - IMAPFILT.DLL
*Deregistered* - ImapiService
*Deregistered* - Ip6Fw
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - JavaQuickStarterService
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LexBceS
*Deregistered* - LmHosts
*Deregistered* - MAILFILT.DLL
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - NNTPFILT.DLL
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - OutpostFirewall
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - pcouffin
*Deregistered* - PolicyAgent
*Deregistered* - POP3FILT.DLL
*Deregistered* - PptpMiniport
*Deregistered* - PROTECT.DLL
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sptd
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - ssmdrv
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - Tcpip6
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - tunmp
*Deregistered* - Update
*Deregistered* - VFILT
*Deregistered* - VgaSave
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
.
Contents of the 'Scheduled Tasks' folder

2009-03-15 c:\windows\Tasks\Registry Winner Schedule.job
- c:\program files\Registry Winner\RegistryWinner.exe []
.
.
——- Supplementary Scan ——-
.
IE: &Down&load &Link& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatch.htm
IE: &Down&load All &Links& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
IE: &GetGo Toolbar Search - c:\program files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{01A13E40-2F55-4397-B39B-7851BCFB8008} - c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - component: c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\extensions\[removed]\platform\WINNT_x86-msvc\components\lpxpcom.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-20 03:24:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-20 3:26:44
ComboFix-quarantined-files.txt 2009-03-20 08:26:33
ComboFix2.txt 2009-03-18 17:48:36
ComboFix3.txt 2009-03-17 18:38:00
ComboFix4.txt 2009-03-17 04:36:17
ComboFix5.txt 2009-03-20 08:19:03

Pre-Run: 42,655,887,360 bytes free
Post-Run: 42,645,204,992 bytes free

446 — E O F — 2009-03-09 21:51:30



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:29:46 AM, on 3/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\OUTPOS~1.0\outpost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\Program Files\Common Files\Agnitum Shared\Aupdate\aupdrun.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://test.catalog.update.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: GetGo URL Catcher (dont remove!) - {0315AA2C-10C7-4504-A1C4-F552ABA8A095} - C:\Program Files\GetGo Software\GetGo Download Manager\URLCatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: GetGo Toolbar - {075BBE29-FEC0-404a-A459-FF58713616FA} - C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Outpost Firewall] "C:\Program Files\Outpost Firewall 1.0\outpost.exe" /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe"
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O8 - Extra context menu item: &Down&load &Link& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatch.htm
O8 - Extra context menu item: &Down&load All &Links& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
O8 - Extra context menu item: &GetGo Toolbar Search - res://C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: GetGo - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra 'Tools' menuitem: GetGo Download Manager - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://test.catalog.update.microsoft.com/v…b?1236661267875
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1218290032265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum - C:\PROGRA~1\OUTPOS~1.0\outpost.exe

–
End of file - 7332 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI