This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please check my HJT log

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

It looks like we've disabled all those bad services.

I want to give this another try before asking you to do an online scan because I know you're on dial-up.


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\K092L3IQ.tmp
c:\windows\ZCMBPO.bat
c:\program files\Registry Winner\RegistryWinner.exe

Folder::
c:\program files\QFLOZJC5K
c:\program files\PWHNMWA7DXAX
c:\program files\V1M8H117OBDI
c:\program files\RB3VBY8R
c:\program files\ROLAZVR5
c:\program files\LOVZEC
c:\program files\9E3E5IBOMKOE
c:\program files\T7ADVS1KE1U
c:\program files\X7LW1WZIV
c:\program files\KHU2T7RCOWKX
c:\program files\Registry Winner

Registry:
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 0 (0x0)
"DisableRegistryTools"= 0 (0x0)

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
I can't tell any difference


ComboFix 09-03-15.01 - Kristy 2009-03-20 21:04:08.11 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.187 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kristy\Desktop\CFScript.txt
* Created a new restore point

FILE ::
c:\program files\Registry Winner\RegistryWinner.exe
c:\windows\K092L3IQ.tmp
c:\windows\ZCMBPO.bat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\9E3E5IBOMKOE
c:\program files\KHU2T7RCOWKX
c:\program files\LOVZEC
c:\program files\PWHNMWA7DXAX
c:\program files\QFLOZJC5K
c:\program files\RB3VBY8R
c:\program files\Registry Winner
c:\program files\Registry Winner\Settings.ini
c:\program files\Registry Winner\Utilities\Favorites\Desktop.ini
c:\program files\Registry Winner\Utilities\Favorites\Links\desktop.ini
c:\program files\Registry Winner\Utilities\Favorites\Links\Suggested Sites.url
c:\program files\Registry Winner\Utilities\Favorites\Links\Web Slice Gallery.url
c:\program files\Registry Winner\Utilities\Favorites\Microsoft Websites\IE Add-on site.url
c:\program files\Registry Winner\Utilities\Favorites\Microsoft Websites\IE site on Microsoft.com.url
c:\program files\Registry Winner\Utilities\Favorites\Microsoft Websites\Marketplace.url
c:\program files\Registry Winner\Utilities\Favorites\Microsoft Websites\Microsoft At Home.url
c:\program files\Registry Winner\Utilities\Favorites\Microsoft Websites\Microsoft At Work.url
c:\program files\Registry Winner\Utilities\Favorites\Microsoft Websites\Welcome to IE7.url
c:\program files\ROLAZVR5
c:\program files\T7ADVS1KE1U
c:\program files\V1M8H117OBDI
c:\program files\X7LW1WZIV
c:\windows\K092L3IQ.tmp
c:\windows\ZCMBPO.bat

.
((((((((((((((((((((((((( Files Created from 2009-02-21 to 2009-03-21 )))))))))))))))))))))))))))))))
.

2009-03-20 03:41 . 2009-03-20 03:42 d——– c:\documents and settings\Kristy\Application Data\uTorrent
2009-03-19 16:30 . 2009-03-19 16:30 d——– c:\program files\directx
2009-03-19 16:24 . 2009-03-19 16:24 d——– c:\program files\SpongeBob SquarePants
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Michael
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Kristy\Application Data\Panasonic
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Kristy\Application Data\InstallShield
2009-03-18 22:20 . 2009-03-19 00:08 d——– c:\program files\Outpost Firewall 1.0
2009-03-18 22:20 . 2009-03-18 22:20 d——– c:\program files\Common Files\Agnitum Shared
2009-03-18 18:13 . 2009-03-18 21:17 120 –a—— c:\windows\CIS_Setup_3.8.65951.477_XP_Vista_x32.INI
2009-03-18 16:12 . 2009-03-20 21:01 3,180 –a—— c:\windows\system32\notepad.ini
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a—— c:\windows\system32\notepad.exe.orig
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a–c— c:\windows\system32\dllcache\notepad.exe.orig
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a—— c:\windows\notepad.exe.orig
2009-03-18 01:29 . 2009-03-18 01:29 d——– c:\program files\Avira
2009-03-18 01:29 . 2009-03-18 01:29 d——– c:\documents and settings\All Users\Application Data\Avira
2009-03-18 01:29 . 2009-02-13 11:31 55,640 –a—— c:\windows\system32\drivers\avgntflt.sys
2009-03-16 13:59 . 2008-04-14 05:42 116,224 –a–c— c:\windows\system32\dllcache\xrxwiadr.dll
2009-03-16 13:59 . 2001-08-17 22:37 99,865 –a–c— c:\windows\system32\dllcache\xlog.exe
2009-03-16 13:59 . 2001-08-17 22:37 27,648 –a–c— c:\windows\system32\dllcache\xrxftplt.exe
2009-03-16 13:59 . 2001-08-17 22:36 23,040 –a–c— c:\windows\system32\dllcache\xrxwbtmp.dll
2009-03-16 13:59 . 2008-04-13 22:04 19,455 –a–c— c:\windows\system32\dllcache\wvchntxx.sys
2009-03-16 13:59 . 2008-04-14 00:16 19,200 –a–c— c:\windows\system32\dllcache\wstcodec.sys
2009-03-16 13:59 . 2008-04-14 05:42 18,944 –a–c— c:\windows\system32\dllcache\xrxscnui.dll
2009-03-16 13:59 . 2001-08-17 12:11 16,970 –a–c— c:\windows\system32\dllcache\xem336n5.sys
2009-03-16 13:59 . 2008-04-13 22:04 12,063 –a–c— c:\windows\system32\dllcache\wsiintxx.sys
2009-03-16 13:59 . 2008-04-14 05:42 8,192 –a–c— c:\windows\system32\dllcache\wshirda.dll
2009-03-16 13:59 . 2001-08-17 22:37 4,608 –a–c— c:\windows\system32\dllcache\xrxflnch.exe
2009-03-16 13:57 . 2001-08-17 13:28 794,654 –a–c— c:\windows\system32\dllcache\usr1801.sys
2009-03-16 13:56 . 2001-08-17 22:36 525,568 –a–c— c:\windows\system32\dllcache\tridxp.dll
2009-03-16 13:55 . 2001-08-17 14:01 241,664 –a–c— c:\windows\system32\dllcache\tosdvd02.sys
2009-03-16 13:54 . 2001-08-17 12:18 285,760 –a–c— c:\windows\system32\dllcache\stlnata.sys
2009-03-16 13:53 . 2001-08-17 22:36 114,688 –a–c— c:\windows\system32\dllcache\sonypi.dll
2009-03-16 13:53 . 2001-08-17 22:36 106,584 –a–c— c:\windows\system32\dllcache\spdports.dll
2009-03-16 13:53 . 2001-08-17 22:36 99,328 –a–c— c:\windows\system32\dllcache\srusd.dll
2009-03-16 13:53 . 2001-08-17 13:51 61,824 –a–c— c:\windows\system32\dllcache\speed.sys
2009-03-16 13:53 . 2001-08-17 12:51 37,040 –a–c— c:\windows\system32\dllcache\sonypi.sys
2009-03-16 13:53 . 2001-08-17 22:36 24,660 –a–c— c:\windows\system32\dllcache\spxupchk.dll
2009-03-16 13:53 . 2001-08-17 12:51 20,752 –a–c— c:\windows\system32\dllcache\sonync.sys
2009-03-16 13:53 . 2001-08-17 14:07 19,072 –a–c— c:\windows\system32\dllcache\sparrow.sys
2009-03-16 13:53 . 2001-08-17 13:53 9,600 –a–c— c:\windows\system32\dllcache\sonymc.sys
2009-03-16 13:53 . 2001-08-17 13:56 7,552 –a–c— c:\windows\system32\dllcache\sonypvu1.sys
2009-03-16 13:53 . 2008-04-14 00:10 7,552 –a–c— c:\windows\system32\dllcache\sonyait.sys
2009-03-16 13:53 . 2001-08-17 13:53 7,040 –a–c— c:\windows\system32\dllcache\snyaitmc.sys
2009-03-16 13:51 . 2001-08-17 22:36 386,560 –a–c— c:\windows\system32\dllcache\sgiul50.dll
2009-03-16 13:51 . 2001-08-17 14:56 252,032 –a–c— c:\windows\system32\dllcache\sis300iv.dll
2009-03-16 13:51 . 2001-08-17 22:36 238,592 –a–c— c:\windows\system32\dllcache\sisgrv.dll
2009-03-16 13:51 . 2001-07-21 14:29 161,568 –a–c— c:\windows\system32\dllcache\sgsmusb.sys
2009-03-16 13:51 . 2001-08-17 14:56 150,144 –a–c— c:\windows\system32\dllcache\sis6306v.dll
2009-03-16 13:51 . 2001-08-17 12:50 104,064 –a–c— c:\windows\system32\dllcache\sisgrp.sys
2009-03-16 13:51 . 2001-08-17 12:50 101,760 –a–c— c:\windows\system32\dllcache\sis300ip.sys
2009-03-16 13:51 . 2001-08-17 12:51 98,080 –a–c— c:\windows\system32\dllcache\sgiulnt5.sys
2009-03-16 13:51 . 2001-08-17 12:50 68,608 –a–c— c:\windows\system32\dllcache\sis6306p.sys
2009-03-16 13:51 . 2001-08-17 12:19 36,480 –a–c— c:\windows\system32\dllcache\sfmanm.sys
2009-03-16 13:51 . 2001-07-21 14:29 18,400 –a–c— c:\windows\system32\dllcache\sgsmld.sys
2009-03-16 13:51 . 2001-08-17 13:48 17,664 –a–c— c:\windows\system32\dllcache\sermouse.sys
2009-03-16 13:51 . 2001-08-17 13:53 6,784 –a–c— c:\windows\system32\dllcache\serscan.sys
2009-03-16 13:50 . 2001-08-17 13:52 11,648 –a–c— c:\windows\system32\dllcache\scsiprnt.sys
2009-03-16 13:50 . 2008-04-14 00:15 11,520 –a–c— c:\windows\system32\dllcache\scsiscan.sys
2009-03-16 13:50 . 2001-08-17 13:53 6,912 –a–c— c:\windows\system32\dllcache\seaddsmc.sys
2009-03-16 13:49 . 2001-08-17 22:36 495,616 –a–c— c:\windows\system32\dllcache\sblfx.dll
2009-03-16 13:49 . 2001-08-17 14:56 245,632 –a–c— c:\windows\system32\dllcache\s3savmx.dll
2009-03-16 13:49 . 2001-08-17 14:56 198,400 –a–c— c:\windows\system32\dllcache\s3sav4.dll
2009-03-16 13:49 . 2001-08-17 14:56 179,264 –a–c— c:\windows\system32\dllcache\s3sav3d.dll
2009-03-16 13:49 . 2001-08-17 12:50 77,824 –a–c— c:\windows\system32\dllcache\s3sav4m.sys
2009-03-16 13:49 . 2001-08-17 12:50 75,392 –a–c— c:\windows\system32\dllcache\s3savmxm.sys
2009-03-16 13:49 . 2001-08-17 12:50 61,504 –a–c— c:\windows\system32\dllcache\s3sav3dm.sys
2009-03-16 13:49 . 2008-04-14 00:10 43,904 –a–c— c:\windows\system32\dllcache\sbp2port.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmusbm.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmn50m.sys
2009-03-16 13:49 . 2001-08-17 13:51 17,280 –a–c— c:\windows\system32\dllcache\scr111.sys
2009-03-16 13:49 . 2001-08-17 13:51 16,640 –a–c— c:\windows\system32\dllcache\scmstcs.sys
2009-03-16 13:47 . 2001-08-17 13:28 899,146 –a–c— c:\windows\system32\dllcache\r2mdkxga.sys
2009-03-16 13:46 . 2008-04-14 05:42 363,520 –a–c— c:\windows\system32\dllcache\psisdecd.dll
2009-03-16 13:45 . 2001-08-17 14:05 351,616 –a–c— c:\windows\system32\dllcache\ovcodek2.sys
2009-03-16 13:44 . 2001-08-17 12:50 198,144 –a–c— c:\windows\system32\dllcache\nv3.sys
2009-03-16 13:44 . 2001-08-17 22:36 123,776 –a–c— c:\windows\system32\dllcache\nv3.dll
2009-03-16 13:44 . 2001-08-17 12:49 51,552 –a–c— c:\windows\system32\dllcache\ntgrip.sys
2009-03-16 13:44 . 2001-08-17 13:47 9,344 –a–c— c:\windows\system32\dllcache\ntapm.sys
2009-03-16 13:44 . 2001-08-17 13:53 7,552 –a–c— c:\windows\system32\dllcache\nsmmc.sys
2009-03-16 13:42 . 2001-08-17 12:50 103,296 –a–c— c:\windows\system32\dllcache\mtxvideo.sys
2009-03-16 13:42 . 2008-04-14 00:16 49,024 –a–c— c:\windows\system32\dllcache\mstape.sys
2009-03-16 13:42 . 2008-04-14 00:24 22,016 –a–c— c:\windows\system32\dllcache\msircomm.sys
2009-03-16 13:42 . 2001-08-17 13:50 21,888 –a–c— c:\windows\system32\dllcache\mxcard.sys
2009-03-16 13:42 . 2001-08-17 13:49 19,968 –a–c— c:\windows\system32\dllcache\mxnic.sys
2009-03-16 13:42 . 2001-08-17 22:36 19,968 –a–c— c:\windows\system32\dllcache\mxicfg.dll
2009-03-16 13:42 . 2001-08-17 13:48 12,416 –a–c— c:\windows\system32\dllcache\msriffwv.sys
2009-03-16 13:42 . 2001-08-17 22:36 7,168 –a–c— c:\windows\system32\dllcache\mxport.dll
2009-03-16 13:42 . 2008-04-14 00:09 5,504 –a–c— c:\windows\system32\dllcache\mstee.sys
2009-03-16 13:42 . 2001-08-17 14:00 2,944 –a–c— c:\windows\system32\dllcache\msmpu401.sys
2009-03-16 13:40 . 2001-08-17 13:28 802,683 –a–c— c:\windows\system32\dllcache\ltsm.sys
2009-03-16 13:39 . 2008-04-14 05:41 253,952 –a–c— c:\windows\system32\dllcache\kdsusd.dll
2009-03-16 13:38 . 2008-04-14 05:41 702,845 –a–c— c:\windows\system32\dllcache\i81xdnt5.dll
2009-03-16 13:37 . 2001-08-17 13:28 542,879 –a–c— c:\windows\system32\dllcache\hsf_msft.sys
2009-03-16 13:36 . 2001-08-17 14:56 1,733,120 –a–c— c:\windows\system32\dllcache\g400d.dll
2009-03-16 13:35 . 2001-08-17 12:15 455,680 –a–c— c:\windows\system32\dllcache\fus2base.sys
2009-03-16 13:34 . 2001-08-17 13:28 634,134 –a–c— c:\windows\system32\dllcache\el656ct5.sys
2009-03-16 13:33 . 2001-08-17 12:14 952,007 –a–c— c:\windows\system32\dllcache\diwan.sys
2009-03-16 13:32 . 2001-08-17 22:36 256,512 –a–c— c:\windows\system32\dllcache\devcon32.dll
2009-03-16 13:31 . 2001-08-17 12:13 980,034 –a–c— c:\windows\system32\dllcache\cicap.sys
2009-03-16 13:30 . 2001-08-17 13:28 871,388 –a–c— c:\windows\system32\dllcache\bcmdm.sys
2009-03-16 13:29 . 2001-08-17 14:55 382,592 –a–c— c:\windows\system32\dllcache\atidrab.dll
2009-03-16 13:28 . 2001-08-17 13:28 762,780 –a–c— c:\windows\system32\dllcache\3cwmcru.sys
2009-03-16 13:27 . 2001-08-17 14:56 66,048 –a–c— c:\windows\system32\dllcache\s3legacy.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a—— c:\windows\system32\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a–c— c:\windows\system32\dllcache\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a—— c:\windows\system32\kbdkor.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a–c— c:\windows\system32\dllcache\kbdkor.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a—— c:\windows\system32\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a–c— c:\windows\system32\dllcache\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a—— c:\windows\system32\kbd103.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a–c— c:\windows\system32\dllcache\kbd103.dll
2009-03-15 21:05 . 2009-03-15 21:05 d——– c:\documents and settings\Administrator
2009-03-15 11:48 . 2009-03-16 02:05 d——– c:\documents and settings\Kristy\Application Data\Azureus
2009-03-15 11:48 . 2009-03-15 11:48 d——– c:\documents and settings\All Users\Application Data\Azureus
2009-03-15 03:15 . 2009-03-15 03:15 82 –a—— c:\windows\wininit.ini
2009-03-15 01:52 . 2009-03-15 02:07 d——– c:\program files\Trojan Remover
2009-03-15 01:52 . 2006-05-25 14:52 162,304 –a—— c:\windows\system32\ztvunrar36.dll
2009-03-15 01:52 . 2003-02-02 19:06 153,088 –a—— c:\windows\system32\UNRAR3.dll
2009-03-15 01:52 . 2005-08-26 00:50 77,312 –a—— c:\windows\system32\ztvunace26.dll
2009-03-15 01:52 . 2002-03-06 00:00 75,264 –a—— c:\windows\system32\unacev2.dll
2009-03-15 01:52 . 2006-06-19 12:01 69,632 –a—— c:\windows\system32\ztvcabinet.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-17 08:03 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-09 23:46 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-08 08:59 ——— d—–w c:\program files\Java
2009-03-08 00:07 ——— d—–w c:\program files\CCleaner
2009-03-08 00:07 ——— d—–w c:\program files\7-Zip
2009-03-08 00:04 ——— d—–w c:\program files\Foxit Software
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2008-08-09 13:34 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080920080810\index.dat
.

((((((((((((((((((((((((((((( SnapShot_2009-03-20_ 3.25.28.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-21 01:57:36 16,384 —-atw c:\windows\temp\Perflib_Perfdata_5b8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-03-08 160592]
"PlaxoSysTray"="c:\program files\Plaxo\3.19.0.16\PlaxoSysTray.exe" [2009-02-09 20480]
"uTorrent"="c:\documents and settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe" [2009-03-20 281392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Outpost Firewall"="c:\program files\Outpost Firewall 1.0\outpost.exe" [2002-06-14 78848]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\pmremind.exe [2009-03-09 331776]
LUMIX Simple Viewer.lnk - c:\program files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2008-11-04 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.MSNAUDIO"= msnaudio.acm
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GetGoDM]
–a—— 2009-02-11 03:40 3280568 c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
——— 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlaxoUpdate]
–a—— 2009-02-09 11:08 371271 c:\program files\Plaxo\3.19.0.16\PlaxoHelper_en.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2009-02-04 12:27 23975720 c:\program files\Skype\Phone\Skype.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\eMule Plus\\eMule.exe"=
"c:\\Documents and Settings\\Kristy\\My Documents\\Documents\\uTorrent\\uTorrent.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 VFILT;Outpost Firewall Kernel Driver;c:\progra~1\OUTPOS~1.0\kernel\2000\FILTNT.SYS [2009-03-18 90368]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-18 108289]
R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);c:\progra~1\OUTPOS~1.0\kernel\ADBLOCK.DLL [2009-03-18 15552]
R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);c:\progra~1\OUTPOS~1.0\kernel\CONTENT.DLL [2009-03-18 3904]
R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);c:\progra~1\OUTPOS~1.0\kernel\DNSCACHE.DLL [2009-03-18 6144]
R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\FTPFILT.DLL [2009-03-18 6304]
R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\HTMLFILT.DLL [2009-03-18 7776]
R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\HTTPFILT.DLL [2009-03-18 9152]
R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\IMAPFILT.DLL [2009-03-18 7072]
R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\MAILFILT.DLL [2009-03-18 9920]
R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\NNTPFILT.DLL [2009-03-18 6656]
R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\POP3FILT.DLL [2009-03-18 7136]
R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);c:\progra~1\OUTPOS~1.0\kernel\PROTECT.DLL [2009-03-18 15584]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys –> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S4 08FX8JFV;08FX8JFV;c:\windows\IH6RNKYKZ0.exe -CZ7LF5R –> c:\windows\IH6RNKYKZ0.exe -CZ7LF5R [?]
S4 10YX3FD3;10YX3FD3;c:\windows\TJTQZPSRY5T.exe -J2X0DEKU –> c:\windows\TJTQZPSRY5T.exe -J2X0DEKU [?]
S4 19T3H;19T3H;c:\windows\IHC9IIA.exe -AQLU44CEC3UJ –> c:\windows\IHC9IIA.exe -AQLU44CEC3UJ [?]
S4 1MV0BLHXE;1MV0BLHXE;c:\windows\I3ETXM0MNZS.exe -PR79NGT9 –> c:\windows\I3ETXM0MNZS.exe -PR79NGT9 [?]
S4 1Q0PLJK5F7EO;1Q0PLJK5F7EO;c:\windows\ILUJFR.exe -A73PR9ZTP3Q –> c:\windows\ILUJFR.exe -A73PR9ZTP3Q [?]
S4 2NXBWF;2NXBWF;c:\windows\J3GBGKSA.exe -BQUON –> c:\windows\J3GBGKSA.exe -BQUON [?]
S4 2O1L3;2O1L3;c:\windows\XAVRLDW.exe -M3N189R55ALV –> c:\windows\XAVRLDW.exe -M3N189R55ALV [?]
S4 2Z8EHAJGE1;2Z8EHAJGE1;c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP –> c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP [?]
S4 3GJ665NT766;3GJ665NT766;c:\windows\LKZA4.exe -CTKCPFB64F –> c:\windows\LKZA4.exe -CTKCPFB64F [?]
S4 3Q3BVMFQZTJ;3Q3BVMFQZTJ;c:\windows\K7NAN.exe -BR0QMKHWMT –> c:\windows\K7NAN.exe -BR0QMKHWMT [?]
S4 4B5HRB6B9;4B5HRB6B9;c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ –> c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ [?]
S4 5AX67SALZ;5AX67SALZ;c:\windows\MRG2LUTA629.exe -DDUEXG6H –> c:\windows\MRG2LUTA629.exe -DDUEXG6H [?]
S4 5ZHFDU4;5ZHFDU4;c:\windows\O7TEQDAQJ.exe -E0DS20 –> c:\windows\O7TEQDAQJ.exe -E0DS20 [?]
S4 8IT5Y44;8IT5Y44;c:\windows\PWD8KYGTP.exe -GJQKUE –> c:\windows\PWD8KYGTP.exe -GJQKUE [?]
S4 ADA2EG1;ADA2EG1;c:\windows\YT1X0GD7P.exe -QE361V –> c:\windows\YT1X0GD7P.exe -QE361V [?]
S4 AQ0LBRDMS1M;AQ0LBRDMS1M;c:\windows\Z6JHX.exe -QTXY9RXXUB –> c:\windows\Z6JHX.exe -QTXY9RXXUB [?]
S4 BBCAH;BBCAH;c:\windows\1R34WHI.exe -REG646GTN16P –> c:\windows\1R34WHI.exe -REG646GTN16P [?]
S4 BPYV25IQ;BPYV25IQ;c:\windows\14H3H0Y1RNH.exe -RQVMLG86 –> c:\windows\14H3H0Y1RNH.exe -RQVMLG86 [?]
S4 BQAGVE30;BQAGVE30;c:\windows\ZOA2WXS1BF.exe -RANNAKM –> c:\windows\ZOA2WXS1BF.exe -RANNAKM [?]
S4 CMUODPSJO8DW;CMUODPSJO8DW;c:\windows\23DIZQ.exe -SQR19Y93WQS –> c:\windows\23DIZQ.exe -SQR19Y93WQS [?]
S4 D0V37G51X3;D0V37G51X3;c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ –> c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ [?]
S4 D9XBL1I9PX;D9XBL1I9PX;c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L –> c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L [?]
S4 DULWFJE;DULWFJE;c:\windows\4Q0MXNJ9F.exe -TXI97K –> c:\windows\4Q0MXNJ9F.exe -TXI97K [?]
S4 FEK1UEF;FEK1UEF;c:\windows\3VUMPGTGW.exe -VFHLTB –> c:\windows\3VUMPGTGW.exe -VFHLTB [?]
S4 GAY2F;GAY2F;c:\windows\4OIW0C0.exe -WBVYPWKID628 –> c:\windows\4OIW0C0.exe -WBVYPWKID628 [?]
S4 H0252AAY6QPU;H0252AAY6QPU;c:\windows\5MZHQ6.exe -W3ZBRSF05CN –> c:\windows\5MZHQ6.exe -W3ZBRSF05CN [?]
S4 H0PC5IV3;H0PC5IV3;c:\windows\YYT6FQVUUD.exe -OK6IRIO –> c:\windows\YYT6FQVUUD.exe -OK6IRIO [?]
S4 H76MC;H76MC;c:\windows\5HQIYDY.exe -X83ZZL7VQJLS –> c:\windows\5HQIYDY.exe -X83ZZL7VQJLS [?]
S4 HC5IOVVW3;HC5IOVVW3;c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS –> c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS [?]
S4 IC56FJ2OJE;IC56FJ2OJE;c:\windows\9SP00JBDUZJ0.exe -YF2C670NL –> c:\windows\9SP00JBDUZJ0.exe -YF2C670NL [?]
S4 II9TFZ;II9TFZ;c:\windows\6YY3H4PB.exe -YLFI2 –> c:\windows\6YY3H4PB.exe -YLFI2 [?]
S4 J1GCP0;J1GCP0;c:\windows\9LKVE6PM.exe -YXS5Z –> c:\windows\9LKVE6PM.exe -YXS5Z [?]
S4 J33FQ1F;J33FQ1F;c:\windows\WXNZ1SB24.exe -OK0B75 –> c:\windows\WXNZ1SB24.exe -OK0B75 [?]
S4 L69Y08;L69Y08;c:\windows\9GTTF99O.exe -196QP –> c:\windows\9GTTF99O.exe -196QP [?]
S4 LHFUA;LHFUA;c:\windows\WUAA71E.exe -1I8UJXUVI7F6 –> c:\windows\WUAA71E.exe -1I8UJXUVI7F6 [?]
S4 LTQLZP2FX6;LTQLZP2FX6;c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA –> c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA [?]
S4 MPJ5MST1U93;MPJ5MST1U93;c:\windows\6Z8VQ.exe -2QGBD1K9XL –> c:\windows\6Z8VQ.exe -2QGBD1K9XL [?]
S4 MUAL22T09A;MUAL22T09A;c:\windows\1HH5P.exe -2VYRJYKRXN –> c:\windows\1HH5P.exe -2VYRJYKRXN [?]
S4 NBG7GOASD1KS;NBG7GOASD1KS;c:\windows\T31TZW.exe -JQK3SOQXCMO –> c:\windows\T31TZW.exe -JQK3SOQXCMO [?]
S4 PXNMBMJR;PXNMBMJR;c:\windows\98UBG40EEE.exe -4YKLBSH –> c:\windows\98UBG40EEE.exe -4YKLBSH [?]
S4 R9I2V5;R9I2V5;c:\windows\I8V5ZLII.exe -7FLLY –> c:\windows\I8V5ZLII.exe -7FLLY [?]
S4 RO3SKV;RO3SKV;c:\windows\2NNPM3AS8.exe -7P05Z7 –> c:\windows\2NNPM3AS8.exe -7P05Z7 [?]
S4 ROO5X4F;ROO5X4F;c:\windows\40UYFPMNI.exe -7RLA4D –> c:\windows\40UYFPMNI.exe -7RLA4D [?]
S4 SQFAY;SQFAY;c:\windows\B56DIMNM.exe -8RCNP –> c:\windows\B56DIMNM.exe -8RCNP [?]
S4 TERDNO1D5;TERDNO1D5;c:\windows\CVBOD9AX78UD.exe -HOQE73D8L –> c:\windows\CVBOD9AX78UD.exe -HOQE73D8L [?]
S4 UNGVG2LBWEL;UNGVG2LBWEL;c:\windows\B276A.exe -ODIM38SNRI –> c:\windows\B276A.exe -ODIM38SNRI [?]
S4 VMAJ4WFY;VMAJ4WFY;c:\windows\C009543J07.exe -NLK1XNBF –> c:\windows\C009543J07.exe -NLK1XNBF [?]
S4 W42CWKTK7;W42CWKTK7;c:\windows\EELB1IVL92C.exe -5ZPNRQCZ –> c:\windows\EELB1IVL92C.exe -5ZPNRQCZ [?]
S4 Y2EN4QW5889;Y2EN4QW5889;c:\windows\FC596.exe -5BMEKWTTJ5 –> c:\windows\FC596.exe -5BMEKWTTJ5 [?]
S4 YT92TP;YT92TP;c:\windows\G9Z2U3LI.exe -UE5IC –> c:\windows\G9Z2U3LI.exe -UE5IC [?]
S4 YTMP1NBHT2;YTMP1NBHT2;c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB –> c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB [?]
S4 ZGC2AK;ZGC2AK;c:\windows\HW2VWLUR.exe -H67JL –> c:\windows\HW2VWLUR.exe -H67JL [?]
S4 ZO48L;ZO48L;c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU –> c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU [?]
.
Contents of the 'Scheduled Tasks' folder

2009-03-15 c:\windows\Tasks\Registry Winner Schedule.job
- c:\program files\Registry Winner\RegistryWinner.exe []
.
.
——- Supplementary Scan ——-
.
IE: &Down&load &Link& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatch.htm
IE: &Down&load All &Links& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
IE: &GetGo Toolbar Search - c:\program files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{01A13E40-2F55-4397-B39B-7851BCFB8008} - c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-tyc&p=
FF - component: c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\extensions\[removed]\platform\WINNT_x86-msvc\components\lpxpcom.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-20 21:06:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-20 21:08:46
ComboFix-quarantined-files.txt 2009-03-21 02:08:27
ComboFix2.txt 2009-03-20 08:26:46
ComboFix3.txt 2009-03-18 17:48:36
ComboFix4.txt 2009-03-17 18:38:00
ComboFix5.txt 2009-03-21 02:03:18

Pre-Run: 42,385,149,952 bytes free
Post-Run: 42,371,780,608 bytes free

329 — E O F — 2009-03-09 21:51:30




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:17:47 PM, on 3/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\OUTPOS~1.0\outpost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://test.catalog.update.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: GetGo URL Catcher (dont remove!) - {0315AA2C-10C7-4504-A1C4-F552ABA8A095} - C:\Program Files\GetGo Software\GetGo Download Manager\URLCatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: GetGo Toolbar - {075BBE29-FEC0-404a-A459-FF58713616FA} - C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Outpost Firewall] "C:\Program Files\Outpost Firewall 1.0\outpost.exe" /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Program Files\Plaxo\3.19.0.16\PlaxoSysTray.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe"
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O8 - Extra context menu item: &Down&load &Link& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatch.htm
O8 - Extra context menu item: &Down&load All &Links& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
O8 - Extra context menu item: &GetGo Toolbar Search - res://C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: GetGo - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra 'Tools' menuitem: GetGo Download Manager - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://test.catalog.update.microsoft.com/v…b?1236661267875
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1218290032265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum - C:\PROGRA~1\OUTPOS~1.0\outpost.exe

–
End of file - 7234 bytes
Is Taskmanager working now?

Download Dr.WEB CureIt to your desktop from here:
ftp://ftp.drweb.com/pub/drweb/cureit/cureit.exe
  • Double-click cureit.exe to start the program.
  • Press Start and then OK to start the Express scan
  • The Express scan takes just a few moments to finish, if something is found, click Yes to cure it
  • Once the short scan has finished, Click Options->Change settings
  • Choose the Scan tab and UN-CHECK Heuristic analysis
  • Choose the Actions tab and make these changes:
    • Next to Infected objects select Report
    • Next to Incurable objects select Report
    • Next to Infected containers select Report
  • At the bottom-left, UN-CHECK Prompt on action, then press OK to close the settings box.
  • Note: These settings changes are IMPORTANT, please ensure you have made them before scanning
  • Then select Complete scan and press the green arrow to start the scan
  • When the scan is complete, click File-> Save report list, save the report to your desktop and close Dr Web CureIt
I've downloaded that 2 times and when I open it, it says "The archive is either in unknown format or damaged". And usually there's more than one location for the file but every time it goes back to dr. web.
Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


After that click on Security level then choose Customize then click on the tab that says Heuristic Analyzer then choose Enable Deep rootkit search then choose ok.
Then choose OK again then you are back to the main screen.

  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left un-neutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

This is what it found but there good files though Detected ——– Status Object —— —— detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\dos622.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk1.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk2.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk3.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk4.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\2000\Win98-Me-2K-WDM\SETUP.EXE detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\Lxk1100\drivers\WIN_XP2K\ENGLISH\lxbkun5c.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcchkid.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcrmv.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcrmv9x.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcupd.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\Setup.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\WDM\RTLCPL.EXE detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\WDM\SoundMan.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\dotnetfx.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\ie6setup.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\MPSetup.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\NetFx20SP1_x86.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\directx_jun2008_redist.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\dotnetfx.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\dotnetfx30SP1setup.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\dotNetFx35setup.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\NetFx20SP1_x86.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\7z465.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\CarCompanion-1.3.2.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\ccsetup217.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\cedt370r.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\CleanUp452.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\dfsetup107.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\FHSetup.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Firefox Setup 3.0.7.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\FoxitReader30_enu_Setup.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\gigatribe_setup246.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\GOMPLAYERENSETUP.EXE detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\install_flash_player_10.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\install_flash_player_10_active_x.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\jre-6u12-windows-i586-p.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Shockwave_Installer_Full.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\spybotsd162.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\spybotsd_includes.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\spywareblastersetup41.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\SpywareTerminatorSetup.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\TrackerChecker203inst.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\utorrent.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Everest Ultimate Edition 4.20.1292 beta\Everest Ultimate Edition 4.20.1292 beta\everest.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Everest Ultimate Edition 4.20.1292 beta\Everest Ultimate Edition 4.20.1292 beta\unins000.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\fp2006-final-3.00-setup\fp2006-final-3.00-setup.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\sapi51tts\InstMsiA.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\sapi51tts\InstMsiW.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\sapi51tts\setup.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\AgtX0407.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\lhttseng.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\Merlin.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\MSagent.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\mscsr.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\msdapp.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\msttsl.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\spchapi.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\SpchCpl.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\tv_enua.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\Start Tor Browser.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\App\vidalia.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\FirefoxPortable.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\App\Firefox\firefox.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\App\Firefox\updater.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\App\Firefox\uninstall\helper.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\PidginPortable\PidginPortable.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\PidginPortable\App\Pidgin\pidgin-portable.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\Programs\TorrentSpy-0.2.4.26-win32\TorrentSpy-0.2.4.26-win32\TorrentSpy-0.2.4.26.exe detected: Trojan program Trojan-Downloader.Win32.Agent.bhfr File: C:\Documents and Settings\Kristy\My Documents\Documents\uTorrent\Torrents\New\A NWO 2006 -6cd\Anti NWO 2006 Volume 3 -2cd\Anti NWO 2006 Volume3-disc2\08 Nummer 8.mp3.!ut
It wouldn't be the first time legit files were infected.
Lets get another scan.

Please go to http://virusscan.jotti.org, click on Browse, and upload the following file for analysis:

C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\dos622.exe


Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.


If virscan.org is too busy you can try these.

http://virscan.org/

http://www.virustotal.com/en/indexf.html
File: dos622.exe Status: INFECTED/MALWARE MD5: 5545e940b623cdff43358828f14d3004 Packers detected: - Scanner results Scan taken on 23 Mar 2009 23:32:26 (GMT) A-Squared Found Win32.SuspectCrc!IK AntiVir Found TR/Drop.Agent.QQJ ArcaVir Found nothing Avast Found Win32:Trojan-gen {Other} AVG Antivirus Found Downloader.Small.FHT BitDefender Found Trojan.Generic.1426244 ClamAV Found Bupt.C CPsecure Found Boot.Bupt.C Dr.Web Found Win32.HLLO.Blop.9 F-Prot Antivirus Found nothing F-Secure Anti-Virus Found Trojan-Downloader.Win32.Agent.bhfr Ikarus Found Win32.SuspectCrc Kaspersky Anti-Virus Found Trojan-Downloader.Win32.Agent.bhfr NOD32 Found Win32/TrojanDownloader.Agent.OUO Norman Virus Control Found W32/Agent.LLKU Panda Antivirus Found nothing Quick Heal Found W32.Agent.BH Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found Trojan-Downloader.Win32.Agent.bhfr
So, now, what do I do? *SIGH* I looked it up and that's it… Most of all this stuff that this website has (http://www.threatexpert.com/report.aspx?md5=3bfd41471b55b78dd62c999d6994ff61) is symptoms, like the virus deleted all of my windows sounds, folder names as numbers and letters ect…
But how did it get attached, I don't think it was there before I don't like deleting my own stuff but I guess, since we have to then I will
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\dos622.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk1.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk2.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk3.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk4.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\2000\Win98-Me-2K-WDM\SETUP.EXE
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\Lxk1100\drivers\WIN_XP2K\ENGLISH\lxbkun5c.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcchkid.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcrmv.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcrmv9x.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcupd.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\Setup.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\WDM\RTLCPL.EXE
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\WDM\SoundMan.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\dotnetfx.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\ie6setup.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\MPSetup.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\NetFx20SP1_x86.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\directx_jun2008_redist.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\dotnetfx.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\dotnetfx30SP1setup.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\dotNetFx35setup.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\NetFx20SP1_x86.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\7z465.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\CarCompanion-1.3.2.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\ccsetup217.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\cedt370r.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\CleanUp452.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\dfsetup107.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\FHSetup.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Firefox Setup 3.0.7.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\FoxitReader30_enu_Setup.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\gigatribe_setup246.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\GOMPLAYERENSETUP.EXE
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\install_flash_player_10.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\install_flash_player_10_active_x.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\jre-6u12-windows-i586-p.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Shockwave_Installer_Full.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\spybotsd162.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\spybotsd_includes.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\spywareblastersetup41.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\SpywareTerminatorSetup.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\TrackerChecker203inst.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\utorrent.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Everest Ultimate Edition 4.20.1292 beta\Everest Ultimate Edition 4.20.1292 beta\everest.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Everest Ultimate Edition 4.20.1292 beta\Everest Ultimate Edition 4.20.1292 beta\unins000.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\fp2006-final-3.00-setup\fp2006-final-3.00-setup.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\sapi51tts\InstMsiA.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\sapi51tts\InstMsiW.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\sapi51tts\setup.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\AgtX0407.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\lhttseng.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\Merlin.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\MSagent.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\mscsr.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\msdapp.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\msttsl.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\spchapi.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\SpchCpl.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\speechsystem\tv_enua.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\Start Tor Browser.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\App\vidalia.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\FirefoxPortable.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\App\Firefox\firefox.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\App\Firefox\updater.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\App\Firefox\uninstall\helper.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\PidginPortable\PidginPortable.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\Tor Browser\PidginPortable\App\Pidgin\pidgin-portable.exe
C:\Documents and Settings\Kristy\My Documents\Documents\Programs\TorrentSpy-0.2.4.26-win32\TorrentSpy-0.2.4.26-win32\TorrentSpy-0.2.4.26.exe
C:\Documents and Settings\Kristy\My Documents\Documents\uTorrent\Torrents\New\A NWO 2006 -6cd\Anti NWO 2006 Volume 3 -2cd\Anti NWO 2006 Volume3-disc2\08 Nummer 8.mp3.!ut

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Ok, I did that… didn't want to but lol

What can we do about all those bad services?


ComboFix 09-03-22.01 - Kristy 2009-03-24 0:04:47.13 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.223 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kristy\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\dos622.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk1.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk2.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk3.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk4.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\2000\Win98-Me-2K-WDM\SETUP.EXE
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\Lxk1100\drivers\WIN_XP2K\ENGLISH\lxbkun5c.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcchkid.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcrmv.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcrmv9x.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcupd.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\Setup.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\WDM\RTLCPL.EXE
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\WDM\SoundMan.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\dotnetfx.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\ie6setup.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\MPSetup.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\NetFx20SP1_x86.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\directx_jun2008_redist.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\dotnetfx.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\dotnetfx30SP1setup.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\dotNetFx35setup.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\NetFx20SP1_x86.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\7z465.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\CarCompanion-1.3.2.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\ccsetup217.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\cedt370r.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\CleanUp452.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\dfsetup107.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Everest Ultimate Edition 4.20.1292 beta\Everest Ultimate Edition 4.20.1292 beta\everest.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Everest Ultimate Edition 4.20.1292 beta\Everest Ultimate Edition 4.20.1292 beta\unins000.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\FHSetup.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Firefox Setup 3.0.7.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\FoxitReader30_enu_Setup.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\fp2006-final-3.00-setup\fp2006-final-3.00-setup.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\gigatribe_setup246.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\GOMPLAYERENSETUP.EXE
c:\documents and settings\Kristy\My Documents\Documents\Programs\install_flash_player_10.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\install_flash_player_10_active_x.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\jre-6u12-windows-i586-p.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\sapi51tts\InstMsiA.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\sapi51tts\InstMsiW.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\sapi51tts\setup.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Shockwave_Installer_Full.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\AgtX0407.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\lhttseng.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\Merlin.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\MSagent.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\mscsr.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\msdapp.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\msttsl.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\spchapi.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\SpchCpl.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\tv_enua.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\spybotsd_includes.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\spybotsd162.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\spywareblastersetup41.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\SpywareTerminatorSetup.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\App\vidalia.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\App\Firefox\firefox.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\App\Firefox\uninstall\helper.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\App\Firefox\updater.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\FirefoxPortable.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\PidginPortable\App\Pidgin\pidgin-portable.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\PidginPortable\PidginPortable.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\Start Tor Browser.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\TorrentSpy-0.2.4.26-win32\TorrentSpy-0.2.4.26-win32\TorrentSpy-0.2.4.26.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\TrackerChecker203inst.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\utorrent.exe
c:\documents and settings\Kristy\My Documents\Documents\uTorrent\Torrents\New\A NWO 2006 -6cd\Anti NWO 2006 Volume 3 -2cd\Anti NWO 2006 Volume3-disc2\08 Nummer 8.mp3.!ut
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\dos622.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk1.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk2.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk3.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Michael\Win2kpro\win2kpro\win2kpro\disk4.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\2000\Win98-Me-2K-WDM\SETUP.EXE
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\Lxk1100\drivers\WIN_XP2K\ENGLISH\lxbkun5c.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcchkid.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcrmv.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcrmv9x.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\alcupd.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\Setup.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\WDM\RTLCPL.EXE
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Drivers\XP\snd_realtek_ac97_3_1_.68_w98-wme-w2k-wxp\snd_realtek_ac97_3.68_w98-wme-w2k-wxp\WDM\SoundMan.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\dotnetfx.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\ie6setup.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\MPSetup.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\Windows 2000 Updates\NetFx20SP1_x86.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\directx_jun2008_redist.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\dotnetfx.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\dotnetfx30SP1setup.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\dotNetFx35setup.exe
c:\documents and settings\Kristy\My Documents\Documents\Michael's Stuff\Windows 2000 & XP Updates\XP Updates\NetFx20SP1_x86.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\7z465.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\CarCompanion-1.3.2.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\ccsetup217.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\cedt370r.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\CleanUp452.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\dfsetup107.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Everest Ultimate Edition 4.20.1292 beta\Everest Ultimate Edition 4.20.1292 beta\everest.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Everest Ultimate Edition 4.20.1292 beta\Everest Ultimate Edition 4.20.1292 beta\unins000.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\FHSetup.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Firefox Setup 3.0.7.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\FoxitReader30_enu_Setup.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\fp2006-final-3.00-setup\fp2006-final-3.00-setup.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\gigatribe_setup246.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\GOMPLAYERENSETUP.EXE
c:\documents and settings\Kristy\My Documents\Documents\Programs\install_flash_player_10.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\install_flash_player_10_active_x.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\jre-6u12-windows-i586-p.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\sapi51tts\InstMsiA.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\sapi51tts\InstMsiW.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\sapi51tts\setup.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Shockwave_Installer_Full.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\AgtX0407.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\lhttseng.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\Merlin.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\MSagent.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\mscsr.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\msdapp.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\msttsl.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\spchapi.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\SpchCpl.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\speechsystem\tv_enua.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\spybotsd_includes.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\spybotsd162.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\spywareblastersetup41.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\SpywareTerminatorSetup.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\App\vidalia.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\App\Firefox\firefox.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\App\Firefox\uninstall\helper.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\App\Firefox\updater.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\FirefoxPortable\FirefoxPortable.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\PidginPortable\App\Pidgin\pidgin-portable.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\PidginPortable\PidginPortable.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\Tor Browser\Start Tor Browser.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\TorrentSpy-0.2.4.26-win32\TorrentSpy-0.2.4.26-win32\TorrentSpy-0.2.4.26.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\TrackerChecker203inst.exe
c:\documents and settings\Kristy\My Documents\Documents\Programs\utorrent.exe

.
((((((((((((((((((((((((( Files Created from 2009-02-24 to 2009-03-24 )))))))))))))))))))))))))))))))
.

2009-03-23 13:35 . 2009-03-23 13:37 1,917 –a—— c:\windows\imsins.BAK
2009-03-23 01:55 . 2009-03-23 01:56 12,288 –a—— c:\windows\M0UF5.tmp
2009-03-22 17:12 . 2009-03-22 17:27 808,992 –ahs—- c:\windows\system32\drivers\fidbox.dat
2009-03-22 17:12 . 2009-03-22 17:27 10,556 –ahs—- c:\windows\system32\drivers\fidbox.idx
2009-03-22 00:40 . 2009-03-23 14:29 d——– c:\documents and settings\Kristy\Application Data\FileZilla
2009-03-22 00:39 . 2009-03-22 00:39 d——– c:\program files\FileZilla FTP Client
2009-03-21 22:07 . 2009-03-21 22:07 d——– c:\program files\Common Files\Nova Development
2009-03-21 22:05 . 2009-03-21 22:05 d——– c:\program files\Nova Development
2009-03-21 20:50 . 2009-03-21 20:50 d——– c:\documents and settings\Kristy\Application Data\ComodoGroup
2009-03-20 03:41 . 2009-03-20 03:42 d——– c:\documents and settings\Kristy\Application Data\uTorrent
2009-03-19 16:30 . 2009-03-19 16:30 d——– c:\program files\directx
2009-03-19 16:24 . 2009-03-19 16:24 d——– c:\program files\SpongeBob SquarePants
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Michael
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Kristy\Application Data\Panasonic
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Kristy\Application Data\InstallShield
2009-03-18 22:20 . 2009-03-21 20:51 d——– c:\program files\Outpost Firewall 1.0
2009-03-18 22:20 . 2009-03-18 22:20 d——– c:\program files\Common Files\Agnitum Shared
2009-03-18 18:13 . 2009-03-18 21:17 120 –a—— c:\windows\CIS_Setup_3.8.65951.477_XP_Vista_x32.INI
2009-03-18 16:12 . 2009-03-23 22:32 3,180 –a—— c:\windows\system32\notepad.ini
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a—— c:\windows\system32\notepad.exe.orig
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a–c— c:\windows\system32\dllcache\notepad.exe.orig
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a—— c:\windows\notepad.exe.orig
2009-03-18 01:29 . 2009-03-18 01:29 d——– c:\program files\Avira
2009-03-18 01:29 . 2009-03-18 01:29 d——– c:\documents and settings\All Users\Application Data\Avira
2009-03-18 01:29 . 2009-02-13 11:31 55,640 –a—— c:\windows\system32\drivers\avgntflt.sys
2009-03-16 13:59 . 2008-04-14 05:42 116,224 –a–c— c:\windows\system32\dllcache\xrxwiadr.dll
2009-03-16 13:59 . 2001-08-17 22:37 99,865 –a–c— c:\windows\system32\dllcache\xlog.exe
2009-03-16 13:59 . 2001-08-17 22:37 27,648 –a–c— c:\windows\system32\dllcache\xrxftplt.exe
2009-03-16 13:59 . 2001-08-17 22:36 23,040 –a–c— c:\windows\system32\dllcache\xrxwbtmp.dll
2009-03-16 13:59 . 2008-04-13 22:04 19,455 –a–c— c:\windows\system32\dllcache\wvchntxx.sys
2009-03-16 13:59 . 2008-04-14 00:16 19,200 –a–c— c:\windows\system32\dllcache\wstcodec.sys
2009-03-16 13:59 . 2008-04-14 05:42 18,944 –a–c— c:\windows\system32\dllcache\xrxscnui.dll
2009-03-16 13:59 . 2001-08-17 12:11 16,970 –a–c— c:\windows\system32\dllcache\xem336n5.sys
2009-03-16 13:59 . 2008-04-13 22:04 12,063 –a–c— c:\windows\system32\dllcache\wsiintxx.sys
2009-03-16 13:59 . 2008-04-14 05:42 8,192 –a–c— c:\windows\system32\dllcache\wshirda.dll
2009-03-16 13:59 . 2001-08-17 22:37 4,608 –a–c— c:\windows\system32\dllcache\xrxflnch.exe
2009-03-16 13:57 . 2001-08-17 13:28 794,654 –a–c— c:\windows\system32\dllcache\usr1801.sys
2009-03-16 13:56 . 2001-08-17 22:36 525,568 –a–c— c:\windows\system32\dllcache\tridxp.dll
2009-03-16 13:55 . 2001-08-17 14:01 241,664 –a–c— c:\windows\system32\dllcache\tosdvd02.sys
2009-03-16 13:54 . 2001-08-17 12:18 285,760 –a–c— c:\windows\system32\dllcache\stlnata.sys
2009-03-16 13:53 . 2001-08-17 22:36 114,688 –a–c— c:\windows\system32\dllcache\sonypi.dll
2009-03-16 13:53 . 2001-08-17 22:36 106,584 –a–c— c:\windows\system32\dllcache\spdports.dll
2009-03-16 13:53 . 2001-08-17 22:36 99,328 –a–c— c:\windows\system32\dllcache\srusd.dll
2009-03-16 13:53 . 2001-08-17 13:51 61,824 –a–c— c:\windows\system32\dllcache\speed.sys
2009-03-16 13:53 . 2001-08-17 12:51 37,040 –a–c— c:\windows\system32\dllcache\sonypi.sys
2009-03-16 13:53 . 2001-08-17 22:36 24,660 –a–c— c:\windows\system32\dllcache\spxupchk.dll
2009-03-16 13:53 . 2001-08-17 12:51 20,752 –a–c— c:\windows\system32\dllcache\sonync.sys
2009-03-16 13:53 . 2001-08-17 14:07 19,072 –a–c— c:\windows\system32\dllcache\sparrow.sys
2009-03-16 13:53 . 2001-08-17 13:53 9,600 –a–c— c:\windows\system32\dllcache\sonymc.sys
2009-03-16 13:53 . 2001-08-17 13:56 7,552 –a–c— c:\windows\system32\dllcache\sonypvu1.sys
2009-03-16 13:53 . 2008-04-14 00:10 7,552 –a–c— c:\windows\system32\dllcache\sonyait.sys
2009-03-16 13:53 . 2001-08-17 13:53 7,040 –a–c— c:\windows\system32\dllcache\snyaitmc.sys
2009-03-16 13:51 . 2001-08-17 22:36 386,560 –a–c— c:\windows\system32\dllcache\sgiul50.dll
2009-03-16 13:51 . 2001-08-17 14:56 252,032 –a–c— c:\windows\system32\dllcache\sis300iv.dll
2009-03-16 13:51 . 2001-08-17 22:36 238,592 –a–c— c:\windows\system32\dllcache\sisgrv.dll
2009-03-16 13:51 . 2001-07-21 14:29 161,568 –a–c— c:\windows\system32\dllcache\sgsmusb.sys
2009-03-16 13:51 . 2001-08-17 14:56 150,144 –a–c— c:\windows\system32\dllcache\sis6306v.dll
2009-03-16 13:51 . 2001-08-17 12:50 104,064 –a–c— c:\windows\system32\dllcache\sisgrp.sys
2009-03-16 13:51 . 2001-08-17 12:50 101,760 –a–c— c:\windows\system32\dllcache\sis300ip.sys
2009-03-16 13:51 . 2001-08-17 12:51 98,080 –a–c— c:\windows\system32\dllcache\sgiulnt5.sys
2009-03-16 13:51 . 2001-08-17 12:50 68,608 –a–c— c:\windows\system32\dllcache\sis6306p.sys
2009-03-16 13:51 . 2001-08-17 12:19 36,480 –a–c— c:\windows\system32\dllcache\sfmanm.sys
2009-03-16 13:51 . 2001-07-21 14:29 18,400 –a–c— c:\windows\system32\dllcache\sgsmld.sys
2009-03-16 13:51 . 2001-08-17 13:48 17,664 –a–c— c:\windows\system32\dllcache\sermouse.sys
2009-03-16 13:51 . 2001-08-17 13:53 6,784 –a–c— c:\windows\system32\dllcache\serscan.sys
2009-03-16 13:50 . 2001-08-17 13:52 11,648 –a–c— c:\windows\system32\dllcache\scsiprnt.sys
2009-03-16 13:50 . 2008-04-14 00:15 11,520 –a–c— c:\windows\system32\dllcache\scsiscan.sys
2009-03-16 13:50 . 2001-08-17 13:53 6,912 –a–c— c:\windows\system32\dllcache\seaddsmc.sys
2009-03-16 13:49 . 2001-08-17 22:36 495,616 –a–c— c:\windows\system32\dllcache\sblfx.dll
2009-03-16 13:49 . 2001-08-17 14:56 245,632 –a–c— c:\windows\system32\dllcache\s3savmx.dll
2009-03-16 13:49 . 2001-08-17 14:56 198,400 –a–c— c:\windows\system32\dllcache\s3sav4.dll
2009-03-16 13:49 . 2001-08-17 14:56 179,264 –a–c— c:\windows\system32\dllcache\s3sav3d.dll
2009-03-16 13:49 . 2001-08-17 12:50 77,824 –a–c— c:\windows\system32\dllcache\s3sav4m.sys
2009-03-16 13:49 . 2001-08-17 12:50 75,392 –a–c— c:\windows\system32\dllcache\s3savmxm.sys
2009-03-16 13:49 . 2001-08-17 12:50 61,504 –a–c— c:\windows\system32\dllcache\s3sav3dm.sys
2009-03-16 13:49 . 2008-04-14 00:10 43,904 –a–c— c:\windows\system32\dllcache\sbp2port.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmusbm.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmn50m.sys
2009-03-16 13:49 . 2001-08-17 13:51 17,280 –a–c— c:\windows\system32\dllcache\scr111.sys
2009-03-16 13:49 . 2001-08-17 13:51 16,640 –a–c— c:\windows\system32\dllcache\scmstcs.sys
2009-03-16 13:47 . 2001-08-17 13:28 899,146 –a–c— c:\windows\system32\dllcache\r2mdkxga.sys
2009-03-16 13:46 . 2008-04-14 05:42 363,520 –a–c— c:\windows\system32\dllcache\psisdecd.dll
2009-03-16 13:45 . 2001-08-17 14:05 351,616 –a–c— c:\windows\system32\dllcache\ovcodek2.sys
2009-03-16 13:44 . 2001-08-17 12:50 198,144 –a–c— c:\windows\system32\dllcache\nv3.sys
2009-03-16 13:44 . 2001-08-17 22:36 123,776 –a–c— c:\windows\system32\dllcache\nv3.dll
2009-03-16 13:44 . 2001-08-17 12:49 51,552 –a–c— c:\windows\system32\dllcache\ntgrip.sys
2009-03-16 13:44 . 2001-08-17 13:47 9,344 –a–c— c:\windows\system32\dllcache\ntapm.sys
2009-03-16 13:44 . 2001-08-17 13:53 7,552 –a–c— c:\windows\system32\dllcache\nsmmc.sys
2009-03-16 13:42 . 2001-08-17 12:50 103,296 –a–c— c:\windows\system32\dllcache\mtxvideo.sys
2009-03-16 13:42 . 2008-04-14 00:16 49,024 –a–c— c:\windows\system32\dllcache\mstape.sys
2009-03-16 13:42 . 2008-04-14 00:24 22,016 –a–c— c:\windows\system32\dllcache\msircomm.sys
2009-03-16 13:42 . 2001-08-17 13:50 21,888 –a–c— c:\windows\system32\dllcache\mxcard.sys
2009-03-16 13:42 . 2001-08-17 13:49 19,968 –a–c— c:\windows\system32\dllcache\mxnic.sys
2009-03-16 13:42 . 2001-08-17 22:36 19,968 –a–c— c:\windows\system32\dllcache\mxicfg.dll
2009-03-16 13:42 . 2001-08-17 13:48 12,416 –a–c— c:\windows\system32\dllcache\msriffwv.sys
2009-03-16 13:42 . 2001-08-17 22:36 7,168 –a–c— c:\windows\system32\dllcache\mxport.dll
2009-03-16 13:42 . 2008-04-14 00:09 5,504 –a–c— c:\windows\system32\dllcache\mstee.sys
2009-03-16 13:42 . 2001-08-17 14:00 2,944 –a–c— c:\windows\system32\dllcache\msmpu401.sys
2009-03-16 13:40 . 2001-08-17 13:28 802,683 –a–c— c:\windows\system32\dllcache\ltsm.sys
2009-03-16 13:39 . 2008-04-14 05:41 253,952 –a–c— c:\windows\system32\dllcache\kdsusd.dll
2009-03-16 13:38 . 2008-04-14 05:41 702,845 –a–c— c:\windows\system32\dllcache\i81xdnt5.dll
2009-03-16 13:37 . 2001-08-17 13:28 542,879 –a–c— c:\windows\system32\dllcache\hsf_msft.sys
2009-03-16 13:36 . 2001-08-17 14:56 1,733,120 –a–c— c:\windows\system32\dllcache\g400d.dll
2009-03-16 13:35 . 2001-08-17 12:15 455,680 –a–c— c:\windows\system32\dllcache\fus2base.sys
2009-03-16 13:34 . 2001-08-17 13:28 634,134 –a–c— c:\windows\system32\dllcache\el656ct5.sys
2009-03-16 13:33 . 2001-08-17 12:14 952,007 –a–c— c:\windows\system32\dllcache\diwan.sys
2009-03-16 13:32 . 2001-08-17 22:36 256,512 –a–c— c:\windows\system32\dllcache\devcon32.dll
2009-03-16 13:31 . 2001-08-17 12:13 980,034 –a–c— c:\windows\system32\dllcache\cicap.sys
2009-03-16 13:30 . 2001-08-17 13:28 871,388 –a–c— c:\windows\system32\dllcache\bcmdm.sys
2009-03-16 13:29 . 2001-08-17 14:55 382,592 –a–c— c:\windows\system32\dllcache\atidrab.dll
2009-03-16 13:28 . 2001-08-17 13:28 762,780 –a–c— c:\windows\system32\dllcache\3cwmcru.sys
2009-03-16 13:27 . 2001-08-17 14:56 66,048 –a–c— c:\windows\system32\dllcache\s3legacy.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a—— c:\windows\system32\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a–c— c:\windows\system32\dllcache\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a—— c:\windows\system32\kbdkor.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a–c— c:\windows\system32\dllcache\kbdkor.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a—— c:\windows\system32\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a–c— c:\windows\system32\dllcache\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a—— c:\windows\system32\kbd103.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a–c— c:\windows\system32\dllcache\kbd103.dll
2009-03-15 21:05 . 2009-03-22 23:07 d——– c:\documents and settings\Administrator

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-22 03:04 ——— d—–w c:\program files\Common Files\InstallShield
2009-03-17 08:03 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-09 23:46 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-08 08:59 ——— d—–w c:\program files\Java
2009-03-08 00:07 ——— d—–w c:\program files\CCleaner
2009-03-08 00:07 ——— d—–w c:\program files\7-Zip
2009-03-08 00:04 ——— d—–w c:\program files\Foxit Software
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2008-08-09 13:34 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080920080810\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-03-21_21.05.41.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-22 03:07:58 61,440 —-a-r c:\windows\Installer\{A75AC597-EDCD-4FC7-94C5-2F72B52C95CA}\ARPPRODUCTICON.exe
+ 2009-03-22 03:07:59 61,440 —-a-r c:\windows\Installer\{A75AC597-EDCD-4FC7-94C5-2F72B52C95CA}\NewShortcut1_A75AC597EDCD4FC794C52F72B52C95CA.exe
+ 2009-03-22 03:07:59 61,440 —-a-r c:\windows\Installer\{A75AC597-EDCD-4FC7-94C5-2F72B52C95CA}\NewShortcut2_A75AC597EDCD4FC794C52F72B52C95CA.exe
- 2009-03-16 06:56:48 157,160 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-03-22 14:44:23 200,144 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2002-01-05 09:48:16 974,848 —-a-w c:\windows\system32\mfc70.dll
+ 2002-01-05 09:36:38 964,608 —-a-w c:\windows\system32\mfc70u.dll
+ 2003-03-19 02:20:00 1,060,864 —-a-w c:\windows\system32\mfc71.dll
+ 2003-03-19 02:12:12 1,047,552 —-a-w c:\windows\system32\mfc71u.dll
+ 2002-01-05 08:38:38 54,784 —-a-w c:\windows\system32\msvci70.dll
+ 2002-01-05 08:37:28 344,064 —-a-w c:\windows\system32\msvcr70.dll
- 2009-03-08 08:06:15 71,308 —-a-w c:\windows\system32\perfc009.dat
+ 2009-03-23 18:37:23 71,308 —-a-w c:\windows\system32\perfc009.dat
- 2009-03-08 08:06:15 441,624 —-a-w c:\windows\system32\perfh009.dat
+ 2009-03-23 18:37:23 441,624 —-a-w c:\windows\system32\perfh009.dat
+ 2009-03-24 04:19:36 16,384 —-atw c:\windows\temp\Perflib_Perfdata_5cc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-03-08 160592]
"uTorrent"="c:\documents and settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe" [2009-03-20 281392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Outpost Firewall"="c:\progra~1\OUTPOS~1.0\outpost.exe" [2002-06-14 78848]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\pmremind.exe [2009-03-09 331776]
LUMIX Simple Viewer.lnk - c:\program files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2008-11-04 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.MSNAUDIO"= msnaudio.acm
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0cnat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GetGoDM]
–a—— 2009-02-11 03:40 3280568 c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
—hs—- 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2009-02-04 12:27 23975720 c:\program files\Skype\Phone\Skype.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\eMule Plus\\eMule.exe"=
"c:\\Documents and Settings\\Kristy\\My Documents\\Documents\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 VFILT;Outpost Firewall Kernel Driver;c:\progra~1\OUTPOS~1.0\kernel\2000\FILTNT.SYS [2009-03-18 90368]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-18 108289]
R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);c:\progra~1\OUTPOS~1.0\kernel\ADBLOCK.DLL [2009-03-18 15552]
R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);c:\progra~1\OUTPOS~1.0\kernel\CONTENT.DLL [2009-03-18 3904]
R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);c:\progra~1\OUTPOS~1.0\kernel\DNSCACHE.DLL [2009-03-18 6144]
R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\FTPFILT.DLL [2009-03-18 6304]
R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\HTMLFILT.DLL [2009-03-18 7776]
R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\HTTPFILT.DLL [2009-03-18 9152]
R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\IMAPFILT.DLL [2009-03-18 7072]
R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\MAILFILT.DLL [2009-03-18 9920]
R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\NNTPFILT.DLL [2009-03-18 6656]
R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\POP3FILT.DLL [2009-03-18 7136]
R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);c:\progra~1\OUTPOS~1.0\kernel\PROTECT.DLL [2009-03-18 15584]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys –> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S4 08FX8JFV;08FX8JFV;c:\windows\IH6RNKYKZ0.exe -CZ7LF5R –> c:\windows\IH6RNKYKZ0.exe -CZ7LF5R [?]
S4 10YX3FD3;10YX3FD3;c:\windows\TJTQZPSRY5T.exe -J2X0DEKU –> c:\windows\TJTQZPSRY5T.exe -J2X0DEKU [?]
S4 19T3H;19T3H;c:\windows\IHC9IIA.exe -AQLU44CEC3UJ –> c:\windows\IHC9IIA.exe -AQLU44CEC3UJ [?]
S4 1MV0BLHXE;1MV0BLHXE;c:\windows\I3ETXM0MNZS.exe -PR79NGT9 –> c:\windows\I3ETXM0MNZS.exe -PR79NGT9 [?]
S4 1Q0PLJK5F7EO;1Q0PLJK5F7EO;c:\windows\ILUJFR.exe -A73PR9ZTP3Q –> c:\windows\ILUJFR.exe -A73PR9ZTP3Q [?]
S4 2NXBWF;2NXBWF;c:\windows\J3GBGKSA.exe -BQUON –> c:\windows\J3GBGKSA.exe -BQUON [?]
S4 2O1L3;2O1L3;c:\windows\XAVRLDW.exe -M3N189R55ALV –> c:\windows\XAVRLDW.exe -M3N189R55ALV [?]
S4 2Z8EHAJGE1;2Z8EHAJGE1;c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP –> c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP [?]
S4 3GJ665NT766;3GJ665NT766;c:\windows\LKZA4.exe -CTKCPFB64F –> c:\windows\LKZA4.exe -CTKCPFB64F [?]
S4 3Q3BVMFQZTJ;3Q3BVMFQZTJ;c:\windows\K7NAN.exe -BR0QMKHWMT –> c:\windows\K7NAN.exe -BR0QMKHWMT [?]
S4 4B5HRB6B9;4B5HRB6B9;c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ –> c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ [?]
S4 5AX67SALZ;5AX67SALZ;c:\windows\MRG2LUTA629.exe -DDUEXG6H –> c:\windows\MRG2LUTA629.exe -DDUEXG6H [?]
S4 5ZHFDU4;5ZHFDU4;c:\windows\O7TEQDAQJ.exe -E0DS20 –> c:\windows\O7TEQDAQJ.exe -E0DS20 [?]
S4 8IT5Y44;8IT5Y44;c:\windows\PWD8KYGTP.exe -GJQKUE –> c:\windows\PWD8KYGTP.exe -GJQKUE [?]
S4 ADA2EG1;ADA2EG1;c:\windows\YT1X0GD7P.exe -QE361V –> c:\windows\YT1X0GD7P.exe -QE361V [?]
S4 AQ0LBRDMS1M;AQ0LBRDMS1M;c:\windows\Z6JHX.exe -QTXY9RXXUB –> c:\windows\Z6JHX.exe -QTXY9RXXUB [?]
S4 BBCAH;BBCAH;c:\windows\1R34WHI.exe -REG646GTN16P –> c:\windows\1R34WHI.exe -REG646GTN16P [?]
S4 BPYV25IQ;BPYV25IQ;c:\windows\14H3H0Y1RNH.exe -RQVMLG86 –> c:\windows\14H3H0Y1RNH.exe -RQVMLG86 [?]
S4 BQAGVE30;BQAGVE30;c:\windows\ZOA2WXS1BF.exe -RANNAKM –> c:\windows\ZOA2WXS1BF.exe -RANNAKM [?]
S4 CMUODPSJO8DW;CMUODPSJO8DW;c:\windows\23DIZQ.exe -SQR19Y93WQS –> c:\windows\23DIZQ.exe -SQR19Y93WQS [?]
S4 D0V37G51X3;D0V37G51X3;c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ –> c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ [?]
S4 D9XBL1I9PX;D9XBL1I9PX;c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L –> c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L [?]
S4 DULWFJE;DULWFJE;c:\windows\4Q0MXNJ9F.exe -TXI97K –> c:\windows\4Q0MXNJ9F.exe -TXI97K [?]
S4 FEK1UEF;FEK1UEF;c:\windows\3VUMPGTGW.exe -VFHLTB –> c:\windows\3VUMPGTGW.exe -VFHLTB [?]
S4 GAY2F;GAY2F;c:\windows\4OIW0C0.exe -WBVYPWKID628 –> c:\windows\4OIW0C0.exe -WBVYPWKID628 [?]
S4 H0252AAY6QPU;H0252AAY6QPU;c:\windows\5MZHQ6.exe -W3ZBRSF05CN –> c:\windows\5MZHQ6.exe -W3ZBRSF05CN [?]
S4 H0PC5IV3;H0PC5IV3;c:\windows\YYT6FQVUUD.exe -OK6IRIO –> c:\windows\YYT6FQVUUD.exe -OK6IRIO [?]
S4 H76MC;H76MC;c:\windows\5HQIYDY.exe -X83ZZL7VQJLS –> c:\windows\5HQIYDY.exe -X83ZZL7VQJLS [?]
S4 HC5IOVVW3;HC5IOVVW3;c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS –> c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS [?]
S4 IC56FJ2OJE;IC56FJ2OJE;c:\windows\9SP00JBDUZJ0.exe -YF2C670NL –> c:\windows\9SP00JBDUZJ0.exe -YF2C670NL [?]
S4 II9TFZ;II9TFZ;c:\windows\6YY3H4PB.exe -YLFI2 –> c:\windows\6YY3H4PB.exe -YLFI2 [?]
S4 J1GCP0;J1GCP0;c:\windows\9LKVE6PM.exe -YXS5Z –> c:\windows\9LKVE6PM.exe -YXS5Z [?]
S4 J33FQ1F;J33FQ1F;c:\windows\WXNZ1SB24.exe -OK0B75 –> c:\windows\WXNZ1SB24.exe -OK0B75 [?]
S4 L69Y08;L69Y08;c:\windows\9GTTF99O.exe -196QP –> c:\windows\9GTTF99O.exe -196QP [?]
S4 LHFUA;LHFUA;c:\windows\WUAA71E.exe -1I8UJXUVI7F6 –> c:\windows\WUAA71E.exe -1I8UJXUVI7F6 [?]
S4 LTQLZP2FX6;LTQLZP2FX6;c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA –> c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA [?]
S4 MPJ5MST1U93;MPJ5MST1U93;c:\windows\6Z8VQ.exe -2QGBD1K9XL –> c:\windows\6Z8VQ.exe -2QGBD1K9XL [?]
S4 MUAL22T09A;MUAL22T09A;c:\windows\1HH5P.exe -2VYRJYKRXN –> c:\windows\1HH5P.exe -2VYRJYKRXN [?]
S4 NBG7GOASD1KS;NBG7GOASD1KS;c:\windows\T31TZW.exe -JQK3SOQXCMO –> c:\windows\T31TZW.exe -JQK3SOQXCMO [?]
S4 PXNMBMJR;PXNMBMJR;c:\windows\98UBG40EEE.exe -4YKLBSH –> c:\windows\98UBG40EEE.exe -4YKLBSH [?]
S4 R9I2V5;R9I2V5;c:\windows\I8V5ZLII.exe -7FLLY –> c:\windows\I8V5ZLII.exe -7FLLY [?]
S4 RO3SKV;RO3SKV;c:\windows\2NNPM3AS8.exe -7P05Z7 –> c:\windows\2NNPM3AS8.exe -7P05Z7 [?]
S4 ROO5X4F;ROO5X4F;c:\windows\40UYFPMNI.exe -7RLA4D –> c:\windows\40UYFPMNI.exe -7RLA4D [?]
S4 SQFAY;SQFAY;c:\windows\B56DIMNM.exe -8RCNP –> c:\windows\B56DIMNM.exe -8RCNP [?]
S4 TERDNO1D5;TERDNO1D5;c:\windows\CVBOD9AX78UD.exe -HOQE73D8L –> c:\windows\CVBOD9AX78UD.exe -HOQE73D8L [?]
S4 UNGVG2LBWEL;UNGVG2LBWEL;c:\windows\B276A.exe -ODIM38SNRI –> c:\windows\B276A.exe -ODIM38SNRI [?]
S4 VMAJ4WFY;VMAJ4WFY;c:\windows\C009543J07.exe -NLK1XNBF –> c:\windows\C009543J07.exe -NLK1XNBF [?]
S4 W42CWKTK7;W42CWKTK7;c:\windows\EELB1IVL92C.exe -5ZPNRQCZ –> c:\windows\EELB1IVL92C.exe -5ZPNRQCZ [?]
S4 Y2EN4QW5889;Y2EN4QW5889;c:\windows\FC596.exe -5BMEKWTTJ5 –> c:\windows\FC596.exe -5BMEKWTTJ5 [?]
S4 YT92TP;YT92TP;c:\windows\G9Z2U3LI.exe -UE5IC –> c:\windows\G9Z2U3LI.exe -UE5IC [?]
S4 YTMP1NBHT2;YTMP1NBHT2;c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB –> c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB [?]
S4 ZGC2AK;ZGC2AK;c:\windows\HW2VWLUR.exe -H67JL –> c:\windows\HW2VWLUR.exe -H67JL [?]
S4 ZO48L;ZO48L;c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU –> c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU [?]

— Other Services/Drivers In Memory —

*Deregistered* - PROCEXP113
.
Contents of the 'Scheduled Tasks' folder

2009-03-22 c:\windows\Tasks\Registry Winner Schedule.job
- c:\program files\Registry Winner\RegistryWinner.exe []
.
.
——- Supplementary Scan ——-
.
IE: &Down&load &Link& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatch.htm
IE: &Down&load All &Links& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
IE: &GetGo Toolbar Search - c:\program files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{01A13E40-2F55-4397-B39B-7851BCFB8008} - c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: keyword.URL -
FF - component: c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\extensions\[removed]\platform\WINNT_x86-msvc\components\lpxpcom.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-24 00:06:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-24 0:08:06
ComboFix-quarantined-files.txt 2009-03-24 05:07:52
ComboFix2.txt 2009-03-22 02:07:02
ComboFix3.txt 2009-03-21 02:08:47
ComboFix4.txt 2009-03-20 08:26:46
ComboFix5.txt 2009-03-24 05:03:54

Pre-Run: 19,666,268,160 bytes free
Post-Run: 19,661,266,944 bytes free

462


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:12:16 AM, on 3/24/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\OUTPOS~1.0\outpost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\WINDOWS\system32\wscntfy.exe
C:\ProcessExplorer\procexp.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://test.catalog.update.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: GetGo URL Catcher (dont remove!) - {0315AA2C-10C7-4504-A1C4-F552ABA8A095} - C:\Program Files\GetGo Software\GetGo Download Manager\URLCatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: GetGo Toolbar - {075BBE29-FEC0-404a-A459-FF58713616FA} - C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRA~1\OUTPOS~1.0\outpost.exe /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe"
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O8 - Extra context menu item: &Down&load &Link& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatch.htm
O8 - Extra context menu item: &Down&load All &Links& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
O8 - Extra context menu item: &GetGo Toolbar Search - res://C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: GetGo - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra 'Tools' menuitem: GetGo Download Manager - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://test.catalog.update.microsoft.com/v…b?1236661267875
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1218290032265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ECC1FB7-D0B6-463E-99BE-7563CC59E2CB}: NameServer = 65.240.162.65 65.240.162.66
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum - C:\PROGRA~1\OUTPOS~1.0\outpost.exe

–
End of file - 7466 bytes
They aren't running.
Lets see if we can remove them.

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\IH6RNKYKZ0.exe
c:\windows\TJTQZPSRY5T.exe
c:\windows\IHC9IIA.exe
c:\windows\I3ETXM0MNZS.exe
c:\windows\ILUJFR.exe
c:\windows\J3GBGKSA.exe
c:\windows\XAVRLDW.exe 
c:\windows\LS3A0NEFDUJ3.exe
c:\windows\LKZA4.exe 
c:\windows\K7NAN.exe
c:\windows\LQPCVSRVKNR.exe
c:\windows\MRG2LUTA629.exe 
c:\windows\O7TEQDAQJ.exe
c:\windows\PWD8KYGTP.exe 
c:\windows\YT1X0GD7P.exe 
c:\windows\Z6JHX.exe
c:\windows\1R34WHI.exe
c:\windows\14H3H0Y1RNH.exe 
c:\windows\ZOA2WXS1BF.exe
c:\windows\23DIZQ.exe
c:\windows\3AF9ILF5N53S.exe 
c:\windows\2IG72ZYZBFVN.exe
c:\windows\4Q0MXNJ9F.exe
c:\windows\3VUMPGTGW.exe
c:\windows\4OIW0C0.exe
c:\windows\5MZHQ6.exe
c:\windows\YYT6FQVUUD.exe
c:\windows\5HQIYDY.exe
c:\windows\7SOC9WZ6HAXG.exe
c:\windows\9SP00JBDUZJ0.exe
c:\windows\6YY3H4PB.exe
c:\windows\9LKVE6PM.exe
c:\windows\WXNZ1SB24.exe 
c:\windows\9GTTF99O.exe 
c:\windows\WUAA71E.exe
c:\windows\9NDQ984HDLAE.exe 
c:\windows\6Z8VQ.exe
c:\windows\1HH5P.exe
c:\windows\T31TZW.exe
c:\windows\98UBG40EEE.exe 
c:\windows\I8V5ZLII.exe 
c:\windows\2NNPM3AS8.exe
c:\windows\40UYFPMNI.exe
c:\windows\B56DIMNM.exe 
c:\windows\CVBOD9AX78UD.exe
c:\windows\B276A.exe
c:\windows\C009543J07.exe
c:\windows\EELB1IVL92C.exe
c:\windows\FC596.exe 
c:\windows\G9Z2U3LI.exe
c:\windows\ZCHSCNE8H0QU.exe 
c:\windows\HW2VWLUR.exe
c:\windows\XZPMNYK.exe 
c:\program files\Registry Winner\RegistryWinner.exe

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI