This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please check my HJT log

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

No different… And those services didn't get deleted


ComboFix 09-03-22.01 - Kristy 2009-03-24 22:43:47.15 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.244 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kristy\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\program files\Registry Winner\RegistryWinner.exe
c:\windows\14H3H0Y1RNH.exe
c:\windows\1HH5P.exe
c:\windows\1R34WHI.exe
c:\windows\23DIZQ.exe
c:\windows\2IG72ZYZBFVN.exe
c:\windows\2NNPM3AS8.exe
c:\windows\3AF9ILF5N53S.exe
c:\windows\3VUMPGTGW.exe
c:\windows\40UYFPMNI.exe
c:\windows\4OIW0C0.exe
c:\windows\4Q0MXNJ9F.exe
c:\windows\5HQIYDY.exe
c:\windows\5MZHQ6.exe
c:\windows\6YY3H4PB.exe
c:\windows\6Z8VQ.exe
c:\windows\7SOC9WZ6HAXG.exe
c:\windows\98UBG40EEE.exe
c:\windows\9GTTF99O.exe
c:\windows\9LKVE6PM.exe
c:\windows\9NDQ984HDLAE.exe
c:\windows\9SP00JBDUZJ0.exe
c:\windows\B276A.exe
c:\windows\B56DIMNM.exe
c:\windows\C009543J07.exe
c:\windows\CVBOD9AX78UD.exe
c:\windows\EELB1IVL92C.exe
c:\windows\FC596.exe
c:\windows\G9Z2U3LI.exe
c:\windows\HW2VWLUR.exe
c:\windows\I3ETXM0MNZS.exe
c:\windows\I8V5ZLII.exe
c:\windows\IH6RNKYKZ0.exe
c:\windows\IHC9IIA.exe
c:\windows\ILUJFR.exe
c:\windows\J3GBGKSA.exe
c:\windows\K7NAN.exe
c:\windows\LKZA4.exe
c:\windows\LQPCVSRVKNR.exe
c:\windows\LS3A0NEFDUJ3.exe
c:\windows\MRG2LUTA629.exe
c:\windows\O7TEQDAQJ.exe
c:\windows\PWD8KYGTP.exe
c:\windows\T31TZW.exe
c:\windows\TJTQZPSRY5T.exe
c:\windows\WUAA71E.exe
c:\windows\WXNZ1SB24.exe
c:\windows\XAVRLDW.exe
c:\windows\XZPMNYK.exe
c:\windows\YT1X0GD7P.exe
c:\windows\YYT6FQVUUD.exe
c:\windows\Z6JHX.exe
c:\windows\ZCHSCNE8H0QU.exe
c:\windows\ZOA2WXS1BF.exe
.

((((((((((((((((((((((((( Files Created from 2009-02-25 to 2009-03-25 )))))))))))))))))))))))))))))))
.

2009-03-24 22:42 . 2009-03-24 22:42 d——– C:\32788R22FWJFW
2009-03-23 13:35 . 2009-03-23 13:37 1,917 –a—— c:\windows\imsins.BAK
2009-03-23 01:55 . 2009-03-23 01:56 12,288 –a—— c:\windows\M0UF5.tmp
2009-03-22 17:12 . 2009-03-22 17:27 808,992 –ahs—- c:\windows\system32\drivers\fidbox.dat
2009-03-22 17:12 . 2009-03-22 17:27 10,556 –ahs—- c:\windows\system32\drivers\fidbox.idx
2009-03-22 00:40 . 2009-03-23 14:29 d——– c:\documents and settings\Kristy\Application Data\FileZilla
2009-03-22 00:39 . 2009-03-22 00:39 d——– c:\program files\FileZilla FTP Client
2009-03-21 22:07 . 2009-03-21 22:07 d——– c:\program files\Common Files\Nova Development
2009-03-21 22:05 . 2009-03-21 22:05 d——– c:\program files\Nova Development
2009-03-21 20:50 . 2009-03-21 20:50 d——– c:\documents and settings\Kristy\Application Data\ComodoGroup
2009-03-20 03:41 . 2009-03-20 03:42 d——– c:\documents and settings\Kristy\Application Data\uTorrent
2009-03-19 16:30 . 2009-03-19 16:30 d——– c:\program files\directx
2009-03-19 16:24 . 2009-03-19 16:24 d——– c:\program files\SpongeBob SquarePants
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Michael
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Kristy\Application Data\Panasonic
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Kristy\Application Data\InstallShield
2009-03-18 22:20 . 2009-03-21 20:51 d——– c:\program files\Outpost Firewall 1.0
2009-03-18 22:20 . 2009-03-18 22:20 d——– c:\program files\Common Files\Agnitum Shared
2009-03-18 18:13 . 2009-03-18 21:17 120 –a—— c:\windows\CIS_Setup_3.8.65951.477_XP_Vista_x32.INI
2009-03-18 16:12 . 2009-03-24 22:45 3,180 –a—— c:\windows\system32\notepad.ini
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a—— c:\windows\system32\notepad.exe.orig
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a–c— c:\windows\system32\dllcache\notepad.exe.orig
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a—— c:\windows\notepad.exe.orig
2009-03-18 01:29 . 2009-03-18 01:29 d——– c:\program files\Avira
2009-03-18 01:29 . 2009-03-18 01:29 d——– c:\documents and settings\All Users\Application Data\Avira
2009-03-18 01:29 . 2009-02-13 11:31 55,640 –a—— c:\windows\system32\drivers\avgntflt.sys
2009-03-16 13:59 . 2008-04-14 05:42 116,224 –a–c— c:\windows\system32\dllcache\xrxwiadr.dll
2009-03-16 13:59 . 2001-08-17 22:37 99,865 –a–c— c:\windows\system32\dllcache\xlog.exe
2009-03-16 13:59 . 2001-08-17 22:37 27,648 –a–c— c:\windows\system32\dllcache\xrxftplt.exe
2009-03-16 13:59 . 2001-08-17 22:36 23,040 –a–c— c:\windows\system32\dllcache\xrxwbtmp.dll
2009-03-16 13:59 . 2008-04-13 22:04 19,455 –a–c— c:\windows\system32\dllcache\wvchntxx.sys
2009-03-16 13:59 . 2008-04-14 00:16 19,200 –a–c— c:\windows\system32\dllcache\wstcodec.sys
2009-03-16 13:59 . 2008-04-14 05:42 18,944 –a–c— c:\windows\system32\dllcache\xrxscnui.dll
2009-03-16 13:59 . 2001-08-17 12:11 16,970 –a–c— c:\windows\system32\dllcache\xem336n5.sys
2009-03-16 13:59 . 2008-04-13 22:04 12,063 –a–c— c:\windows\system32\dllcache\wsiintxx.sys
2009-03-16 13:59 . 2008-04-14 05:42 8,192 –a–c— c:\windows\system32\dllcache\wshirda.dll
2009-03-16 13:59 . 2001-08-17 22:37 4,608 –a–c— c:\windows\system32\dllcache\xrxflnch.exe
2009-03-16 13:57 . 2001-08-17 13:28 794,654 –a–c— c:\windows\system32\dllcache\usr1801.sys
2009-03-16 13:56 . 2001-08-17 22:36 525,568 –a–c— c:\windows\system32\dllcache\tridxp.dll
2009-03-16 13:55 . 2001-08-17 14:01 241,664 –a–c— c:\windows\system32\dllcache\tosdvd02.sys
2009-03-16 13:54 . 2001-08-17 12:18 285,760 –a–c— c:\windows\system32\dllcache\stlnata.sys
2009-03-16 13:53 . 2001-08-17 22:36 114,688 –a–c— c:\windows\system32\dllcache\sonypi.dll
2009-03-16 13:53 . 2001-08-17 22:36 106,584 –a–c— c:\windows\system32\dllcache\spdports.dll
2009-03-16 13:53 . 2001-08-17 22:36 99,328 –a–c— c:\windows\system32\dllcache\srusd.dll
2009-03-16 13:53 . 2001-08-17 13:51 61,824 –a–c— c:\windows\system32\dllcache\speed.sys
2009-03-16 13:53 . 2001-08-17 12:51 37,040 –a–c— c:\windows\system32\dllcache\sonypi.sys
2009-03-16 13:53 . 2001-08-17 22:36 24,660 –a–c— c:\windows\system32\dllcache\spxupchk.dll
2009-03-16 13:53 . 2001-08-17 12:51 20,752 –a–c— c:\windows\system32\dllcache\sonync.sys
2009-03-16 13:53 . 2001-08-17 14:07 19,072 –a–c— c:\windows\system32\dllcache\sparrow.sys
2009-03-16 13:53 . 2001-08-17 13:53 9,600 –a–c— c:\windows\system32\dllcache\sonymc.sys
2009-03-16 13:53 . 2001-08-17 13:56 7,552 –a–c— c:\windows\system32\dllcache\sonypvu1.sys
2009-03-16 13:53 . 2008-04-14 00:10 7,552 –a–c— c:\windows\system32\dllcache\sonyait.sys
2009-03-16 13:53 . 2001-08-17 13:53 7,040 –a–c— c:\windows\system32\dllcache\snyaitmc.sys
2009-03-16 13:51 . 2001-08-17 22:36 386,560 –a–c— c:\windows\system32\dllcache\sgiul50.dll
2009-03-16 13:51 . 2001-08-17 14:56 252,032 –a–c— c:\windows\system32\dllcache\sis300iv.dll
2009-03-16 13:51 . 2001-08-17 22:36 238,592 –a–c— c:\windows\system32\dllcache\sisgrv.dll
2009-03-16 13:51 . 2001-07-21 14:29 161,568 –a–c— c:\windows\system32\dllcache\sgsmusb.sys
2009-03-16 13:51 . 2001-08-17 14:56 150,144 –a–c— c:\windows\system32\dllcache\sis6306v.dll
2009-03-16 13:51 . 2001-08-17 12:50 104,064 –a–c— c:\windows\system32\dllcache\sisgrp.sys
2009-03-16 13:51 . 2001-08-17 12:50 101,760 –a–c— c:\windows\system32\dllcache\sis300ip.sys
2009-03-16 13:51 . 2001-08-17 12:51 98,080 –a–c— c:\windows\system32\dllcache\sgiulnt5.sys
2009-03-16 13:51 . 2001-08-17 12:50 68,608 –a–c— c:\windows\system32\dllcache\sis6306p.sys
2009-03-16 13:51 . 2001-08-17 12:19 36,480 –a–c— c:\windows\system32\dllcache\sfmanm.sys
2009-03-16 13:51 . 2001-07-21 14:29 18,400 –a–c— c:\windows\system32\dllcache\sgsmld.sys
2009-03-16 13:51 . 2001-08-17 13:48 17,664 –a–c— c:\windows\system32\dllcache\sermouse.sys
2009-03-16 13:51 . 2001-08-17 13:53 6,784 –a–c— c:\windows\system32\dllcache\serscan.sys
2009-03-16 13:50 . 2001-08-17 13:52 11,648 –a–c— c:\windows\system32\dllcache\scsiprnt.sys
2009-03-16 13:50 . 2008-04-14 00:15 11,520 –a–c— c:\windows\system32\dllcache\scsiscan.sys
2009-03-16 13:50 . 2001-08-17 13:53 6,912 –a–c— c:\windows\system32\dllcache\seaddsmc.sys
2009-03-16 13:49 . 2001-08-17 22:36 495,616 –a–c— c:\windows\system32\dllcache\sblfx.dll
2009-03-16 13:49 . 2001-08-17 14:56 245,632 –a–c— c:\windows\system32\dllcache\s3savmx.dll
2009-03-16 13:49 . 2001-08-17 14:56 198,400 –a–c— c:\windows\system32\dllcache\s3sav4.dll
2009-03-16 13:49 . 2001-08-17 14:56 179,264 –a–c— c:\windows\system32\dllcache\s3sav3d.dll
2009-03-16 13:49 . 2001-08-17 12:50 77,824 –a–c— c:\windows\system32\dllcache\s3sav4m.sys
2009-03-16 13:49 . 2001-08-17 12:50 75,392 –a–c— c:\windows\system32\dllcache\s3savmxm.sys
2009-03-16 13:49 . 2001-08-17 12:50 61,504 –a–c— c:\windows\system32\dllcache\s3sav3dm.sys
2009-03-16 13:49 . 2008-04-14 00:10 43,904 –a–c— c:\windows\system32\dllcache\sbp2port.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmusbm.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmn50m.sys
2009-03-16 13:49 . 2001-08-17 13:51 17,280 –a–c— c:\windows\system32\dllcache\scr111.sys
2009-03-16 13:49 . 2001-08-17 13:51 16,640 –a–c— c:\windows\system32\dllcache\scmstcs.sys
2009-03-16 13:47 . 2001-08-17 13:28 899,146 –a–c— c:\windows\system32\dllcache\r2mdkxga.sys
2009-03-16 13:46 . 2008-04-14 05:42 363,520 –a–c— c:\windows\system32\dllcache\psisdecd.dll
2009-03-16 13:45 . 2001-08-17 14:05 351,616 –a–c— c:\windows\system32\dllcache\ovcodek2.sys
2009-03-16 13:44 . 2001-08-17 12:50 198,144 –a–c— c:\windows\system32\dllcache\nv3.sys
2009-03-16 13:44 . 2001-08-17 22:36 123,776 –a–c— c:\windows\system32\dllcache\nv3.dll
2009-03-16 13:44 . 2001-08-17 12:49 51,552 –a–c— c:\windows\system32\dllcache\ntgrip.sys
2009-03-16 13:44 . 2001-08-17 13:47 9,344 –a–c— c:\windows\system32\dllcache\ntapm.sys
2009-03-16 13:44 . 2001-08-17 13:53 7,552 –a–c— c:\windows\system32\dllcache\nsmmc.sys
2009-03-16 13:42 . 2001-08-17 12:50 103,296 –a–c— c:\windows\system32\dllcache\mtxvideo.sys
2009-03-16 13:42 . 2008-04-14 00:16 49,024 –a–c— c:\windows\system32\dllcache\mstape.sys
2009-03-16 13:42 . 2008-04-14 00:24 22,016 –a–c— c:\windows\system32\dllcache\msircomm.sys
2009-03-16 13:42 . 2001-08-17 13:50 21,888 –a–c— c:\windows\system32\dllcache\mxcard.sys
2009-03-16 13:42 . 2001-08-17 13:49 19,968 –a–c— c:\windows\system32\dllcache\mxnic.sys
2009-03-16 13:42 . 2001-08-17 22:36 19,968 –a–c— c:\windows\system32\dllcache\mxicfg.dll
2009-03-16 13:42 . 2001-08-17 13:48 12,416 –a–c— c:\windows\system32\dllcache\msriffwv.sys
2009-03-16 13:42 . 2001-08-17 22:36 7,168 –a–c— c:\windows\system32\dllcache\mxport.dll
2009-03-16 13:42 . 2008-04-14 00:09 5,504 –a–c— c:\windows\system32\dllcache\mstee.sys
2009-03-16 13:42 . 2001-08-17 14:00 2,944 –a–c— c:\windows\system32\dllcache\msmpu401.sys
2009-03-16 13:40 . 2001-08-17 13:28 802,683 –a–c— c:\windows\system32\dllcache\ltsm.sys
2009-03-16 13:39 . 2008-04-14 05:41 253,952 –a–c— c:\windows\system32\dllcache\kdsusd.dll
2009-03-16 13:38 . 2008-04-14 05:41 702,845 –a–c— c:\windows\system32\dllcache\i81xdnt5.dll
2009-03-16 13:37 . 2001-08-17 13:28 542,879 –a–c— c:\windows\system32\dllcache\hsf_msft.sys
2009-03-16 13:36 . 2001-08-17 14:56 1,733,120 –a–c— c:\windows\system32\dllcache\g400d.dll
2009-03-16 13:35 . 2001-08-17 12:15 455,680 –a–c— c:\windows\system32\dllcache\fus2base.sys
2009-03-16 13:34 . 2001-08-17 13:28 634,134 –a–c— c:\windows\system32\dllcache\el656ct5.sys
2009-03-16 13:33 . 2001-08-17 12:14 952,007 –a–c— c:\windows\system32\dllcache\diwan.sys
2009-03-16 13:32 . 2001-08-17 22:36 256,512 –a–c— c:\windows\system32\dllcache\devcon32.dll
2009-03-16 13:31 . 2001-08-17 12:13 980,034 –a–c— c:\windows\system32\dllcache\cicap.sys
2009-03-16 13:30 . 2001-08-17 13:28 871,388 –a–c— c:\windows\system32\dllcache\bcmdm.sys
2009-03-16 13:29 . 2001-08-17 14:55 382,592 –a–c— c:\windows\system32\dllcache\atidrab.dll
2009-03-16 13:28 . 2001-08-17 13:28 762,780 –a–c— c:\windows\system32\dllcache\3cwmcru.sys
2009-03-16 13:27 . 2001-08-17 14:56 66,048 –a–c— c:\windows\system32\dllcache\s3legacy.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a—— c:\windows\system32\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a–c— c:\windows\system32\dllcache\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a—— c:\windows\system32\kbdkor.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a–c— c:\windows\system32\dllcache\kbdkor.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a—— c:\windows\system32\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a–c— c:\windows\system32\dllcache\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a—— c:\windows\system32\kbd103.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a–c— c:\windows\system32\dllcache\kbd103.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-22 03:04 ——— d—–w c:\program files\Common Files\InstallShield
2009-03-17 08:03 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-09 23:46 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-08 08:59 ——— d—–w c:\program files\Java
2009-03-08 00:07 ——— d—–w c:\program files\CCleaner
2009-03-08 00:07 ——— d—–w c:\program files\7-Zip
2009-03-08 00:04 ——— d—–w c:\program files\Foxit Software
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2008-08-09 13:34 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080920080810\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-03-21_21.05.41.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-22 03:07:58 61,440 —-a-r c:\windows\Installer\{A75AC597-EDCD-4FC7-94C5-2F72B52C95CA}\ARPPRODUCTICON.exe
+ 2009-03-22 03:07:59 61,440 —-a-r c:\windows\Installer\{A75AC597-EDCD-4FC7-94C5-2F72B52C95CA}\NewShortcut1_A75AC597EDCD4FC794C52F72B52C95CA.exe
+ 2009-03-22 03:07:59 61,440 —-a-r c:\windows\Installer\{A75AC597-EDCD-4FC7-94C5-2F72B52C95CA}\NewShortcut2_A75AC597EDCD4FC794C52F72B52C95CA.exe
- 2009-03-16 06:56:48 157,160 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-03-22 14:44:23 200,144 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2002-01-05 09:48:16 974,848 —-a-w c:\windows\system32\mfc70.dll
+ 2002-01-05 09:36:38 964,608 —-a-w c:\windows\system32\mfc70u.dll
+ 2003-03-19 02:20:00 1,060,864 —-a-w c:\windows\system32\mfc71.dll
+ 2003-03-19 02:12:12 1,047,552 —-a-w c:\windows\system32\mfc71u.dll
+ 2002-01-05 08:38:38 54,784 —-a-w c:\windows\system32\msvci70.dll
+ 2002-01-05 08:37:28 344,064 —-a-w c:\windows\system32\msvcr70.dll
- 2009-03-08 08:06:15 71,308 —-a-w c:\windows\system32\perfc009.dat
+ 2009-03-23 18:37:23 71,308 —-a-w c:\windows\system32\perfc009.dat
- 2009-03-08 08:06:15 441,624 —-a-w c:\windows\system32\perfh009.dat
+ 2009-03-23 18:37:23 441,624 —-a-w c:\windows\system32\perfh009.dat
+ 2009-03-24 15:09:28 16,384 —-atw c:\windows\temp\Perflib_Perfdata_5c4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-03-08 160592]
"uTorrent"="c:\documents and settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe" [2009-03-20 281392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Outpost Firewall"="c:\progra~1\OUTPOS~1.0\outpost.exe" [2002-06-14 78848]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\pmremind.exe [2009-03-09 331776]
LUMIX Simple Viewer.lnk - c:\program files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2008-11-04 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.MSNAUDIO"= msnaudio.acm
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0cnat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GetGoDM]
–a—— 2009-02-11 03:40 3280568 c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
—hs—- 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2009-02-04 12:27 23975720 c:\program files\Skype\Phone\Skype.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\eMule Plus\\eMule.exe"=
"c:\\Documents and Settings\\Kristy\\My Documents\\Documents\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 VFILT;Outpost Firewall Kernel Driver;c:\progra~1\OUTPOS~1.0\kernel\2000\FILTNT.SYS [2009-03-18 90368]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-18 108289]
R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);c:\progra~1\OUTPOS~1.0\kernel\ADBLOCK.DLL [2009-03-18 15552]
R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);c:\progra~1\OUTPOS~1.0\kernel\CONTENT.DLL [2009-03-18 3904]
R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);c:\progra~1\OUTPOS~1.0\kernel\DNSCACHE.DLL [2009-03-18 6144]
R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\FTPFILT.DLL [2009-03-18 6304]
R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\HTMLFILT.DLL [2009-03-18 7776]
R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\HTTPFILT.DLL [2009-03-18 9152]
R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\IMAPFILT.DLL [2009-03-18 7072]
R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\MAILFILT.DLL [2009-03-18 9920]
R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\NNTPFILT.DLL [2009-03-18 6656]
R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\POP3FILT.DLL [2009-03-18 7136]
R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);c:\progra~1\OUTPOS~1.0\kernel\PROTECT.DLL [2009-03-18 15584]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys –> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S4 08FX8JFV;08FX8JFV;c:\windows\IH6RNKYKZ0.exe -CZ7LF5R –> c:\windows\IH6RNKYKZ0.exe -CZ7LF5R [?]
S4 10YX3FD3;10YX3FD3;c:\windows\TJTQZPSRY5T.exe -J2X0DEKU –> c:\windows\TJTQZPSRY5T.exe -J2X0DEKU [?]
S4 19T3H;19T3H;c:\windows\IHC9IIA.exe -AQLU44CEC3UJ –> c:\windows\IHC9IIA.exe -AQLU44CEC3UJ [?]
S4 1MV0BLHXE;1MV0BLHXE;c:\windows\I3ETXM0MNZS.exe -PR79NGT9 –> c:\windows\I3ETXM0MNZS.exe -PR79NGT9 [?]
S4 1Q0PLJK5F7EO;1Q0PLJK5F7EO;c:\windows\ILUJFR.exe -A73PR9ZTP3Q –> c:\windows\ILUJFR.exe -A73PR9ZTP3Q [?]
S4 2NXBWF;2NXBWF;c:\windows\J3GBGKSA.exe -BQUON –> c:\windows\J3GBGKSA.exe -BQUON [?]
S4 2O1L3;2O1L3;c:\windows\XAVRLDW.exe -M3N189R55ALV –> c:\windows\XAVRLDW.exe -M3N189R55ALV [?]
S4 2Z8EHAJGE1;2Z8EHAJGE1;c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP –> c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP [?]
S4 3GJ665NT766;3GJ665NT766;c:\windows\LKZA4.exe -CTKCPFB64F –> c:\windows\LKZA4.exe -CTKCPFB64F [?]
S4 3Q3BVMFQZTJ;3Q3BVMFQZTJ;c:\windows\K7NAN.exe -BR0QMKHWMT –> c:\windows\K7NAN.exe -BR0QMKHWMT [?]
S4 4B5HRB6B9;4B5HRB6B9;c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ –> c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ [?]
S4 5AX67SALZ;5AX67SALZ;c:\windows\MRG2LUTA629.exe -DDUEXG6H –> c:\windows\MRG2LUTA629.exe -DDUEXG6H [?]
S4 5ZHFDU4;5ZHFDU4;c:\windows\O7TEQDAQJ.exe -E0DS20 –> c:\windows\O7TEQDAQJ.exe -E0DS20 [?]
S4 8IT5Y44;8IT5Y44;c:\windows\PWD8KYGTP.exe -GJQKUE –> c:\windows\PWD8KYGTP.exe -GJQKUE [?]
S4 ADA2EG1;ADA2EG1;c:\windows\YT1X0GD7P.exe -QE361V –> c:\windows\YT1X0GD7P.exe -QE361V [?]
S4 AQ0LBRDMS1M;AQ0LBRDMS1M;c:\windows\Z6JHX.exe -QTXY9RXXUB –> c:\windows\Z6JHX.exe -QTXY9RXXUB [?]
S4 BBCAH;BBCAH;c:\windows\1R34WHI.exe -REG646GTN16P –> c:\windows\1R34WHI.exe -REG646GTN16P [?]
S4 BPYV25IQ;BPYV25IQ;c:\windows\14H3H0Y1RNH.exe -RQVMLG86 –> c:\windows\14H3H0Y1RNH.exe -RQVMLG86 [?]
S4 BQAGVE30;BQAGVE30;c:\windows\ZOA2WXS1BF.exe -RANNAKM –> c:\windows\ZOA2WXS1BF.exe -RANNAKM [?]
S4 CMUODPSJO8DW;CMUODPSJO8DW;c:\windows\23DIZQ.exe -SQR19Y93WQS –> c:\windows\23DIZQ.exe -SQR19Y93WQS [?]
S4 D0V37G51X3;D0V37G51X3;c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ –> c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ [?]
S4 D9XBL1I9PX;D9XBL1I9PX;c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L –> c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L [?]
S4 DULWFJE;DULWFJE;c:\windows\4Q0MXNJ9F.exe -TXI97K –> c:\windows\4Q0MXNJ9F.exe -TXI97K [?]
S4 FEK1UEF;FEK1UEF;c:\windows\3VUMPGTGW.exe -VFHLTB –> c:\windows\3VUMPGTGW.exe -VFHLTB [?]
S4 GAY2F;GAY2F;c:\windows\4OIW0C0.exe -WBVYPWKID628 –> c:\windows\4OIW0C0.exe -WBVYPWKID628 [?]
S4 H0252AAY6QPU;H0252AAY6QPU;c:\windows\5MZHQ6.exe -W3ZBRSF05CN –> c:\windows\5MZHQ6.exe -W3ZBRSF05CN [?]
S4 H0PC5IV3;H0PC5IV3;c:\windows\YYT6FQVUUD.exe -OK6IRIO –> c:\windows\YYT6FQVUUD.exe -OK6IRIO [?]
S4 H76MC;H76MC;c:\windows\5HQIYDY.exe -X83ZZL7VQJLS –> c:\windows\5HQIYDY.exe -X83ZZL7VQJLS [?]
S4 HC5IOVVW3;HC5IOVVW3;c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS –> c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS [?]
S4 IC56FJ2OJE;IC56FJ2OJE;c:\windows\9SP00JBDUZJ0.exe -YF2C670NL –> c:\windows\9SP00JBDUZJ0.exe -YF2C670NL [?]
S4 II9TFZ;II9TFZ;c:\windows\6YY3H4PB.exe -YLFI2 –> c:\windows\6YY3H4PB.exe -YLFI2 [?]
S4 J1GCP0;J1GCP0;c:\windows\9LKVE6PM.exe -YXS5Z –> c:\windows\9LKVE6PM.exe -YXS5Z [?]
S4 J33FQ1F;J33FQ1F;c:\windows\WXNZ1SB24.exe -OK0B75 –> c:\windows\WXNZ1SB24.exe -OK0B75 [?]
S4 L69Y08;L69Y08;c:\windows\9GTTF99O.exe -196QP –> c:\windows\9GTTF99O.exe -196QP [?]
S4 LHFUA;LHFUA;c:\windows\WUAA71E.exe -1I8UJXUVI7F6 –> c:\windows\WUAA71E.exe -1I8UJXUVI7F6 [?]
S4 LTQLZP2FX6;LTQLZP2FX6;c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA –> c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA [?]
S4 MPJ5MST1U93;MPJ5MST1U93;c:\windows\6Z8VQ.exe -2QGBD1K9XL –> c:\windows\6Z8VQ.exe -2QGBD1K9XL [?]
S4 MUAL22T09A;MUAL22T09A;c:\windows\1HH5P.exe -2VYRJYKRXN –> c:\windows\1HH5P.exe -2VYRJYKRXN [?]
S4 NBG7GOASD1KS;NBG7GOASD1KS;c:\windows\T31TZW.exe -JQK3SOQXCMO –> c:\windows\T31TZW.exe -JQK3SOQXCMO [?]
S4 PXNMBMJR;PXNMBMJR;c:\windows\98UBG40EEE.exe -4YKLBSH –> c:\windows\98UBG40EEE.exe -4YKLBSH [?]
S4 R9I2V5;R9I2V5;c:\windows\I8V5ZLII.exe -7FLLY –> c:\windows\I8V5ZLII.exe -7FLLY [?]
S4 RO3SKV;RO3SKV;c:\windows\2NNPM3AS8.exe -7P05Z7 –> c:\windows\2NNPM3AS8.exe -7P05Z7 [?]
S4 ROO5X4F;ROO5X4F;c:\windows\40UYFPMNI.exe -7RLA4D –> c:\windows\40UYFPMNI.exe -7RLA4D [?]
S4 SQFAY;SQFAY;c:\windows\B56DIMNM.exe -8RCNP –> c:\windows\B56DIMNM.exe -8RCNP [?]
S4 TERDNO1D5;TERDNO1D5;c:\windows\CVBOD9AX78UD.exe -HOQE73D8L –> c:\windows\CVBOD9AX78UD.exe -HOQE73D8L [?]
S4 UNGVG2LBWEL;UNGVG2LBWEL;c:\windows\B276A.exe -ODIM38SNRI –> c:\windows\B276A.exe -ODIM38SNRI [?]
S4 VMAJ4WFY;VMAJ4WFY;c:\windows\C009543J07.exe -NLK1XNBF –> c:\windows\C009543J07.exe -NLK1XNBF [?]
S4 W42CWKTK7;W42CWKTK7;c:\windows\EELB1IVL92C.exe -5ZPNRQCZ –> c:\windows\EELB1IVL92C.exe -5ZPNRQCZ [?]
S4 Y2EN4QW5889;Y2EN4QW5889;c:\windows\FC596.exe -5BMEKWTTJ5 –> c:\windows\FC596.exe -5BMEKWTTJ5 [?]
S4 YT92TP;YT92TP;c:\windows\G9Z2U3LI.exe -UE5IC –> c:\windows\G9Z2U3LI.exe -UE5IC [?]
S4 YTMP1NBHT2;YTMP1NBHT2;c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB –> c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB [?]
S4 ZGC2AK;ZGC2AK;c:\windows\HW2VWLUR.exe -H67JL –> c:\windows\HW2VWLUR.exe -H67JL [?]
S4 ZO48L;ZO48L;c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU –> c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU [?]
.
Contents of the 'Scheduled Tasks' folder

2009-03-22 c:\windows\Tasks\Registry Winner Schedule.job
- c:\program files\Registry Winner\RegistryWinner.exe []
.
.
——- Supplementary Scan ——-
.
IE: &Down&load &Link& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatch.htm
IE: &Down&load All &Links& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
IE: &GetGo Toolbar Search - c:\program files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{01A13E40-2F55-4397-B39B-7851BCFB8008} - c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: keyword.URL -
FF - component: c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\extensions\[removed]\platform\WINNT_x86-msvc\components\lpxpcom.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-24 22:45:35
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-24 22:47:15
ComboFix-quarantined-files.txt 2009-03-25 03:47:08
ComboFix2.txt 2009-03-24 05:52:26
ComboFix3.txt 2009-03-24 05:08:07
ComboFix4.txt 2009-03-22 02:07:02
ComboFix5.txt 2009-03-25 03:43:05

Pre-Run: 23,828,291,584 bytes free
Post-Run: 23,816,134,656 bytes free

372


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:48:07 PM, on 3/24/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\OUTPOS~1.0\outpost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://test.catalog.update.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: GetGo URL Catcher (dont remove!) - {0315AA2C-10C7-4504-A1C4-F552ABA8A095} - C:\Program Files\GetGo Software\GetGo Download Manager\URLCatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: GetGo Toolbar - {075BBE29-FEC0-404a-A459-FF58713616FA} - C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRA~1\OUTPOS~1.0\outpost.exe /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe"
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O8 - Extra context menu item: &Down&load &Link& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatch.htm
O8 - Extra context menu item: &Down&load All &Links& Us&ing Ge&tGo - C:\Program Files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
O8 - Extra context menu item: &GetGo Toolbar Search - res://C:\Program Files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: GetGo - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra 'Tools' menuitem: GetGo Download Manager - {01A13E40-2F55-4397-B39B-7851BCFB8008} - C:\Program Files\GetGo Software\GetGo Download Manager\GetGoDM.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://test.catalog.update.microsoft.com/v…b?1236661267875
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1218290032265
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum - C:\PROGRA~1\OUTPOS~1.0\outpost.exe

–
End of file - 7266 bytes
Lets try a couple to see if this would delete them.
If you get an error that the services isn't running, just try the delete on anyway.

Click Start > Run and Copy/Paste these commands hitting enter after each one:

sc stop 08FX8JFV Hit enter.

sc delete 08FX8JFV Hit enter.


sc stop 10YX3FD3 Hit enter.

sc delete 10YX3FD3 Hit enter.

Now run Combofix again and we'll see if they were removed.
ComboFix 09-03-22.01 - Kristy 2009-03-26 17:08:46.16 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Kristy\Application Data\sborka_blackmanos_13_66.exe

.
((((((((((((((((((((((((( Files Created from 2009-02-26 to 2009-03-26 )))))))))))))))))))))))))))))))
.

2009-03-25 17:50 . 2009-03-26 07:14 d——– c:\program files\WinAce
2009-03-23 13:35 . 2009-03-23 13:37 1,917 –a—— c:\windows\imsins.BAK
2009-03-23 01:55 . 2009-03-23 01:56 12,288 –a—— c:\windows\M0UF5.tmp
2009-03-22 17:12 . 2009-03-22 17:27 808,992 –ahs—- c:\windows\system32\drivers\fidbox.dat
2009-03-22 17:12 . 2009-03-22 17:27 10,556 –ahs—- c:\windows\system32\drivers\fidbox.idx
2009-03-22 00:40 . 2009-03-23 14:29 d——– c:\documents and settings\Kristy\Application Data\FileZilla
2009-03-22 00:39 . 2009-03-22 00:39 d——– c:\program files\FileZilla FTP Client
2009-03-21 22:07 . 2009-03-21 22:07 d——– c:\program files\Common Files\Nova Development
2009-03-21 22:05 . 2009-03-21 22:05 d——– c:\program files\Nova Development
2009-03-21 20:50 . 2009-03-21 20:50 d——– c:\documents and settings\Kristy\Application Data\ComodoGroup
2009-03-20 03:41 . 2009-03-20 03:42 d——– c:\documents and settings\Kristy\Application Data\uTorrent
2009-03-19 16:30 . 2009-03-19 16:30 d——– c:\program files\directx
2009-03-19 16:24 . 2009-03-19 16:24 d——– c:\program files\SpongeBob SquarePants
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Michael
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Kristy\Application Data\Panasonic
2009-03-19 13:45 . 2009-03-19 13:45 d——– c:\documents and settings\Kristy\Application Data\InstallShield
2009-03-18 22:20 . 2009-03-21 20:51 d——– c:\program files\Outpost Firewall 1.0
2009-03-18 22:20 . 2009-03-18 22:20 d——– c:\program files\Common Files\Agnitum Shared
2009-03-18 18:13 . 2009-03-18 21:17 120 –a—— c:\windows\CIS_Setup_3.8.65951.477_XP_Vista_x32.INI
2009-03-18 16:12 . 2009-03-26 16:42 3,178 –a—— c:\windows\system32\notepad.ini
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a—— c:\windows\system32\notepad.exe.orig
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a–c— c:\windows\system32\dllcache\notepad.exe.orig
2009-03-18 16:10 . 2008-04-14 05:42 69,120 –a—— c:\windows\notepad.exe.orig
2009-03-18 01:29 . 2009-03-18 01:29 d——– c:\program files\Avira
2009-03-18 01:29 . 2009-03-18 01:29 d——– c:\documents and settings\All Users\Application Data\Avira
2009-03-18 01:29 . 2009-02-13 11:31 55,640 –a—— c:\windows\system32\drivers\avgntflt.sys
2009-03-16 13:59 . 2008-04-14 05:42 116,224 –a–c— c:\windows\system32\dllcache\xrxwiadr.dll
2009-03-16 13:59 . 2001-08-17 22:37 99,865 –a–c— c:\windows\system32\dllcache\xlog.exe
2009-03-16 13:59 . 2001-08-17 22:37 27,648 –a–c— c:\windows\system32\dllcache\xrxftplt.exe
2009-03-16 13:59 . 2001-08-17 22:36 23,040 –a–c— c:\windows\system32\dllcache\xrxwbtmp.dll
2009-03-16 13:59 . 2008-04-13 22:04 19,455 –a–c— c:\windows\system32\dllcache\wvchntxx.sys
2009-03-16 13:59 . 2008-04-14 00:16 19,200 –a–c— c:\windows\system32\dllcache\wstcodec.sys
2009-03-16 13:59 . 2008-04-14 05:42 18,944 –a–c— c:\windows\system32\dllcache\xrxscnui.dll
2009-03-16 13:59 . 2001-08-17 12:11 16,970 –a–c— c:\windows\system32\dllcache\xem336n5.sys
2009-03-16 13:59 . 2008-04-13 22:04 12,063 –a–c— c:\windows\system32\dllcache\wsiintxx.sys
2009-03-16 13:59 . 2008-04-14 05:42 8,192 –a–c— c:\windows\system32\dllcache\wshirda.dll
2009-03-16 13:59 . 2001-08-17 22:37 4,608 –a–c— c:\windows\system32\dllcache\xrxflnch.exe
2009-03-16 13:57 . 2001-08-17 13:28 794,654 –a–c— c:\windows\system32\dllcache\usr1801.sys
2009-03-16 13:56 . 2001-08-17 22:36 525,568 –a–c— c:\windows\system32\dllcache\tridxp.dll
2009-03-16 13:55 . 2001-08-17 14:01 241,664 –a–c— c:\windows\system32\dllcache\tosdvd02.sys
2009-03-16 13:54 . 2001-08-17 12:18 285,760 –a–c— c:\windows\system32\dllcache\stlnata.sys
2009-03-16 13:53 . 2001-08-17 22:36 114,688 –a–c— c:\windows\system32\dllcache\sonypi.dll
2009-03-16 13:53 . 2001-08-17 22:36 106,584 –a–c— c:\windows\system32\dllcache\spdports.dll
2009-03-16 13:53 . 2001-08-17 22:36 99,328 –a–c— c:\windows\system32\dllcache\srusd.dll
2009-03-16 13:53 . 2001-08-17 13:51 61,824 –a–c— c:\windows\system32\dllcache\speed.sys
2009-03-16 13:53 . 2001-08-17 12:51 37,040 –a–c— c:\windows\system32\dllcache\sonypi.sys
2009-03-16 13:53 . 2001-08-17 22:36 24,660 –a–c— c:\windows\system32\dllcache\spxupchk.dll
2009-03-16 13:53 . 2001-08-17 12:51 20,752 –a–c— c:\windows\system32\dllcache\sonync.sys
2009-03-16 13:53 . 2001-08-17 14:07 19,072 –a–c— c:\windows\system32\dllcache\sparrow.sys
2009-03-16 13:53 . 2001-08-17 13:53 9,600 –a–c— c:\windows\system32\dllcache\sonymc.sys
2009-03-16 13:53 . 2001-08-17 13:56 7,552 –a–c— c:\windows\system32\dllcache\sonypvu1.sys
2009-03-16 13:53 . 2008-04-14 00:10 7,552 –a–c— c:\windows\system32\dllcache\sonyait.sys
2009-03-16 13:53 . 2001-08-17 13:53 7,040 –a–c— c:\windows\system32\dllcache\snyaitmc.sys
2009-03-16 13:51 . 2001-08-17 22:36 386,560 –a–c— c:\windows\system32\dllcache\sgiul50.dll
2009-03-16 13:51 . 2001-08-17 14:56 252,032 –a–c— c:\windows\system32\dllcache\sis300iv.dll
2009-03-16 13:51 . 2001-08-17 22:36 238,592 –a–c— c:\windows\system32\dllcache\sisgrv.dll
2009-03-16 13:51 . 2001-07-21 14:29 161,568 –a–c— c:\windows\system32\dllcache\sgsmusb.sys
2009-03-16 13:51 . 2001-08-17 14:56 150,144 –a–c— c:\windows\system32\dllcache\sis6306v.dll
2009-03-16 13:51 . 2001-08-17 12:50 104,064 –a–c— c:\windows\system32\dllcache\sisgrp.sys
2009-03-16 13:51 . 2001-08-17 12:50 101,760 –a–c— c:\windows\system32\dllcache\sis300ip.sys
2009-03-16 13:51 . 2001-08-17 12:51 98,080 –a–c— c:\windows\system32\dllcache\sgiulnt5.sys
2009-03-16 13:51 . 2001-08-17 12:50 68,608 –a–c— c:\windows\system32\dllcache\sis6306p.sys
2009-03-16 13:51 . 2001-08-17 12:19 36,480 –a–c— c:\windows\system32\dllcache\sfmanm.sys
2009-03-16 13:51 . 2001-07-21 14:29 18,400 –a–c— c:\windows\system32\dllcache\sgsmld.sys
2009-03-16 13:51 . 2001-08-17 13:48 17,664 –a–c— c:\windows\system32\dllcache\sermouse.sys
2009-03-16 13:51 . 2001-08-17 13:53 6,784 –a–c— c:\windows\system32\dllcache\serscan.sys
2009-03-16 13:50 . 2001-08-17 13:52 11,648 –a–c— c:\windows\system32\dllcache\scsiprnt.sys
2009-03-16 13:50 . 2008-04-14 00:15 11,520 –a–c— c:\windows\system32\dllcache\scsiscan.sys
2009-03-16 13:50 . 2001-08-17 13:53 6,912 –a–c— c:\windows\system32\dllcache\seaddsmc.sys
2009-03-16 13:49 . 2001-08-17 22:36 495,616 –a–c— c:\windows\system32\dllcache\sblfx.dll
2009-03-16 13:49 . 2001-08-17 14:56 245,632 –a–c— c:\windows\system32\dllcache\s3savmx.dll
2009-03-16 13:49 . 2001-08-17 14:56 198,400 –a–c— c:\windows\system32\dllcache\s3sav4.dll
2009-03-16 13:49 . 2001-08-17 14:56 179,264 –a–c— c:\windows\system32\dllcache\s3sav3d.dll
2009-03-16 13:49 . 2001-08-17 12:50 77,824 –a–c— c:\windows\system32\dllcache\s3sav4m.sys
2009-03-16 13:49 . 2001-08-17 12:50 75,392 –a–c— c:\windows\system32\dllcache\s3savmxm.sys
2009-03-16 13:49 . 2001-08-17 12:50 61,504 –a–c— c:\windows\system32\dllcache\s3sav3dm.sys
2009-03-16 13:49 . 2008-04-14 00:10 43,904 –a–c— c:\windows\system32\dllcache\sbp2port.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmusbm.sys
2009-03-16 13:49 . 2001-08-17 13:51 23,936 –a–c— c:\windows\system32\dllcache\sccmn50m.sys
2009-03-16 13:49 . 2001-08-17 13:51 17,280 –a–c— c:\windows\system32\dllcache\scr111.sys
2009-03-16 13:49 . 2001-08-17 13:51 16,640 –a–c— c:\windows\system32\dllcache\scmstcs.sys
2009-03-16 13:47 . 2001-08-17 13:28 899,146 –a–c— c:\windows\system32\dllcache\r2mdkxga.sys
2009-03-16 13:46 . 2008-04-14 05:42 363,520 –a–c— c:\windows\system32\dllcache\psisdecd.dll
2009-03-16 13:45 . 2001-08-17 14:05 351,616 –a–c— c:\windows\system32\dllcache\ovcodek2.sys
2009-03-16 13:44 . 2001-08-17 12:50 198,144 –a–c— c:\windows\system32\dllcache\nv3.sys
2009-03-16 13:44 . 2001-08-17 22:36 123,776 –a–c— c:\windows\system32\dllcache\nv3.dll
2009-03-16 13:44 . 2001-08-17 12:49 51,552 –a–c— c:\windows\system32\dllcache\ntgrip.sys
2009-03-16 13:44 . 2001-08-17 13:47 9,344 –a–c— c:\windows\system32\dllcache\ntapm.sys
2009-03-16 13:44 . 2001-08-17 13:53 7,552 –a–c— c:\windows\system32\dllcache\nsmmc.sys
2009-03-16 13:42 . 2001-08-17 12:50 103,296 –a–c— c:\windows\system32\dllcache\mtxvideo.sys
2009-03-16 13:42 . 2008-04-14 00:16 49,024 –a–c— c:\windows\system32\dllcache\mstape.sys
2009-03-16 13:42 . 2008-04-14 00:24 22,016 –a–c— c:\windows\system32\dllcache\msircomm.sys
2009-03-16 13:42 . 2001-08-17 13:50 21,888 –a–c— c:\windows\system32\dllcache\mxcard.sys
2009-03-16 13:42 . 2001-08-17 13:49 19,968 –a–c— c:\windows\system32\dllcache\mxnic.sys
2009-03-16 13:42 . 2001-08-17 22:36 19,968 –a–c— c:\windows\system32\dllcache\mxicfg.dll
2009-03-16 13:42 . 2001-08-17 13:48 12,416 –a–c— c:\windows\system32\dllcache\msriffwv.sys
2009-03-16 13:42 . 2001-08-17 22:36 7,168 –a–c— c:\windows\system32\dllcache\mxport.dll
2009-03-16 13:42 . 2008-04-14 00:09 5,504 –a–c— c:\windows\system32\dllcache\mstee.sys
2009-03-16 13:42 . 2001-08-17 14:00 2,944 –a–c— c:\windows\system32\dllcache\msmpu401.sys
2009-03-16 13:40 . 2001-08-17 13:28 802,683 –a–c— c:\windows\system32\dllcache\ltsm.sys
2009-03-16 13:39 . 2008-04-14 05:41 253,952 –a–c— c:\windows\system32\dllcache\kdsusd.dll
2009-03-16 13:38 . 2008-04-14 05:41 702,845 –a–c— c:\windows\system32\dllcache\i81xdnt5.dll
2009-03-16 13:37 . 2001-08-17 13:28 542,879 –a–c— c:\windows\system32\dllcache\hsf_msft.sys
2009-03-16 13:36 . 2001-08-17 14:56 1,733,120 –a–c— c:\windows\system32\dllcache\g400d.dll
2009-03-16 13:35 . 2001-08-17 12:15 455,680 –a–c— c:\windows\system32\dllcache\fus2base.sys
2009-03-16 13:34 . 2001-08-17 13:28 634,134 –a–c— c:\windows\system32\dllcache\el656ct5.sys
2009-03-16 13:33 . 2001-08-17 12:14 952,007 –a–c— c:\windows\system32\dllcache\diwan.sys
2009-03-16 13:32 . 2001-08-17 22:36 256,512 –a–c— c:\windows\system32\dllcache\devcon32.dll
2009-03-16 13:31 . 2001-08-17 12:13 980,034 –a–c— c:\windows\system32\dllcache\cicap.sys
2009-03-16 13:30 . 2001-08-17 13:28 871,388 –a–c— c:\windows\system32\dllcache\bcmdm.sys
2009-03-16 13:29 . 2001-08-17 14:55 382,592 –a–c— c:\windows\system32\dllcache\atidrab.dll
2009-03-16 13:28 . 2001-08-17 13:28 762,780 –a–c— c:\windows\system32\dllcache\3cwmcru.sys
2009-03-16 13:27 . 2001-08-17 14:56 66,048 –a–c— c:\windows\system32\dllcache\s3legacy.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a—— c:\windows\system32\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,704 –a–c— c:\windows\system32\dllcache\kbdjpn.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a—— c:\windows\system32\kbdkor.dll
2009-03-16 02:05 . 2001-08-17 22:36 8,192 –a–c— c:\windows\system32\dllcache\kbdkor.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a—— c:\windows\system32\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2009-03-16 02:05 . 2008-04-14 05:39 6,144 –a–c— c:\windows\system32\dllcache\kbd106.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101c.dll
2009-03-16 02:05 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a—— c:\windows\system32\kbd103.dll
2009-03-16 02:05 . 2001-08-17 14:55 5,632 –a–c— c:\windows\system32\dllcache\kbd103.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-22 03:04 ——— d—–w c:\program files\Common Files\InstallShield
2009-03-17 08:03 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-09 23:46 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-08 08:59 ——— d—–w c:\program files\Java
2009-03-08 00:07 ——— d—–w c:\program files\CCleaner
2009-03-08 00:07 ——— d—–w c:\program files\7-Zip
2009-03-08 00:04 ——— d—–w c:\program files\Foxit Software
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2008-08-09 13:34 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008080920080810\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-03-21_21.05.41.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-22 03:07:58 61,440 —-a-r c:\windows\Installer\{A75AC597-EDCD-4FC7-94C5-2F72B52C95CA}\ARPPRODUCTICON.exe
+ 2009-03-22 03:07:59 61,440 —-a-r c:\windows\Installer\{A75AC597-EDCD-4FC7-94C5-2F72B52C95CA}\NewShortcut1_A75AC597EDCD4FC794C52F72B52C95CA.exe
+ 2009-03-22 03:07:59 61,440 —-a-r c:\windows\Installer\{A75AC597-EDCD-4FC7-94C5-2F72B52C95CA}\NewShortcut2_A75AC597EDCD4FC794C52F72B52C95CA.exe
- 2009-03-16 06:56:48 157,160 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-03-22 14:44:23 200,144 —-a-w c:\windows\system32\FNTCACHE.DAT
+ 2002-01-05 09:48:16 974,848 —-a-w c:\windows\system32\mfc70.dll
+ 2002-01-05 09:36:38 964,608 —-a-w c:\windows\system32\mfc70u.dll
+ 2003-03-19 02:20:00 1,060,864 —-a-w c:\windows\system32\mfc71.dll
+ 2003-03-19 02:12:12 1,047,552 —-a-w c:\windows\system32\mfc71u.dll
+ 2002-01-05 08:38:38 54,784 —-a-w c:\windows\system32\msvci70.dll
+ 2002-01-05 08:37:28 344,064 —-a-w c:\windows\system32\msvcr70.dll
- 2009-03-08 08:06:15 71,308 —-a-w c:\windows\system32\perfc009.dat
+ 2009-03-23 18:37:23 71,308 —-a-w c:\windows\system32\perfc009.dat
- 2009-03-08 08:06:15 441,624 —-a-w c:\windows\system32\perfh009.dat
+ 2009-03-23 18:37:23 441,624 —-a-w c:\windows\system32\perfh009.dat
+ 2009-03-26 12:14:54 16,384 —-atw c:\windows\temp\Perflib_Perfdata_5c0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-03-08 160592]
"uTorrent"="c:\documents and settings\Kristy\My Documents\Documents\uTorrent\uTorrent.exe" [2009-03-20 281392]
"GetGoDM"="c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe" [2009-02-11 3280568]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Outpost Firewall"="c:\progra~1\OUTPOS~1.0\outpost.exe" [2002-06-14 78848]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Event Reminder.lnk - c:\program files\Broderbund\PrintMaster\pmremind.exe [2009-03-09 331776]
LUMIX Simple Viewer.lnk - c:\program files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2008-11-04 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.MSNAUDIO"= msnaudio.acm
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0cnat

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GetGoDM]
–a—— 2009-02-11 03:40 3280568 c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
—hs—- 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2009-02-04 12:27 23975720 c:\program files\Skype\Phone\Skype.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\eMule Plus\\eMule.exe"=
"c:\\Documents and Settings\\Kristy\\My Documents\\Documents\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 VFILT;Outpost Firewall Kernel Driver;c:\progra~1\OUTPOS~1.0\kernel\2000\FILTNT.SYS [2009-03-18 90368]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-18 108289]
R3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);c:\progra~1\OUTPOS~1.0\kernel\ADBLOCK.DLL [2009-03-18 15552]
R3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);c:\progra~1\OUTPOS~1.0\kernel\CONTENT.DLL [2009-03-18 3904]
R3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);c:\progra~1\OUTPOS~1.0\kernel\DNSCACHE.DLL [2009-03-18 6144]
R3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\FTPFILT.DLL [2009-03-18 6304]
R3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\HTMLFILT.DLL [2009-03-18 7776]
R3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\HTTPFILT.DLL [2009-03-18 9152]
R3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\IMAPFILT.DLL [2009-03-18 7072]
R3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\MAILFILT.DLL [2009-03-18 9920]
R3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\NNTPFILT.DLL [2009-03-18 6656]
R3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);c:\progra~1\OUTPOS~1.0\kernel\POP3FILT.DLL [2009-03-18 7136]
R3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);c:\progra~1\OUTPOS~1.0\kernel\PROTECT.DLL [2009-03-18 15584]
S3 ATE_PROCMON;ATE_PROCMON;\??\c:\program files\Anti Trojan Elite\ATEPMon.sys –> c:\program files\Anti Trojan Elite\ATEPMon.sys [?]
S4 19T3H;19T3H;c:\windows\IHC9IIA.exe -AQLU44CEC3UJ –> c:\windows\IHC9IIA.exe -AQLU44CEC3UJ [?]
S4 1MV0BLHXE;1MV0BLHXE;c:\windows\I3ETXM0MNZS.exe -PR79NGT9 –> c:\windows\I3ETXM0MNZS.exe -PR79NGT9 [?]
S4 1Q0PLJK5F7EO;1Q0PLJK5F7EO;c:\windows\ILUJFR.exe -A73PR9ZTP3Q –> c:\windows\ILUJFR.exe -A73PR9ZTP3Q [?]
S4 2NXBWF;2NXBWF;c:\windows\J3GBGKSA.exe -BQUON –> c:\windows\J3GBGKSA.exe -BQUON [?]
S4 2O1L3;2O1L3;c:\windows\XAVRLDW.exe -M3N189R55ALV –> c:\windows\XAVRLDW.exe -M3N189R55ALV [?]
S4 2Z8EHAJGE1;2Z8EHAJGE1;c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP –> c:\windows\LS3A0NEFDUJ3.exe -B25RXP6TP [?]
S4 3GJ665NT766;3GJ665NT766;c:\windows\LKZA4.exe -CTKCPFB64F –> c:\windows\LKZA4.exe -CTKCPFB64F [?]
S4 3Q3BVMFQZTJ;3Q3BVMFQZTJ;c:\windows\K7NAN.exe -BR0QMKHWMT –> c:\windows\K7NAN.exe -BR0QMKHWMT [?]
S4 4B5HRB6B9;4B5HRB6B9;c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ –> c:\windows\LQPCVSRVKNR.exe -DC2W5GPQ [?]
S4 5AX67SALZ;5AX67SALZ;c:\windows\MRG2LUTA629.exe -DDUEXG6H –> c:\windows\MRG2LUTA629.exe -DDUEXG6H [?]
S4 5ZHFDU4;5ZHFDU4;c:\windows\O7TEQDAQJ.exe -E0DS20 –> c:\windows\O7TEQDAQJ.exe -E0DS20 [?]
S4 8IT5Y44;8IT5Y44;c:\windows\PWD8KYGTP.exe -GJQKUE –> c:\windows\PWD8KYGTP.exe -GJQKUE [?]
S4 ADA2EG1;ADA2EG1;c:\windows\YT1X0GD7P.exe -QE361V –> c:\windows\YT1X0GD7P.exe -QE361V [?]
S4 AQ0LBRDMS1M;AQ0LBRDMS1M;c:\windows\Z6JHX.exe -QTXY9RXXUB –> c:\windows\Z6JHX.exe -QTXY9RXXUB [?]
S4 BBCAH;BBCAH;c:\windows\1R34WHI.exe -REG646GTN16P –> c:\windows\1R34WHI.exe -REG646GTN16P [?]
S4 BPYV25IQ;BPYV25IQ;c:\windows\14H3H0Y1RNH.exe -RQVMLG86 –> c:\windows\14H3H0Y1RNH.exe -RQVMLG86 [?]
S4 BQAGVE30;BQAGVE30;c:\windows\ZOA2WXS1BF.exe -RANNAKM –> c:\windows\ZOA2WXS1BF.exe -RANNAKM [?]
S4 CMUODPSJO8DW;CMUODPSJO8DW;c:\windows\23DIZQ.exe -SQR19Y93WQS –> c:\windows\23DIZQ.exe -SQR19Y93WQS [?]
S4 D0V37G51X3;D0V37G51X3;c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ –> c:\windows\3AF9ILF5N53S.exe -U2SMSO6FQ [?]
S4 D9XBL1I9PX;D9XBL1I9PX;c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L –> c:\windows\2IG72ZYZBFVN.exe -TTQCIOT5L [?]
S4 DULWFJE;DULWFJE;c:\windows\4Q0MXNJ9F.exe -TXI97K –> c:\windows\4Q0MXNJ9F.exe -TXI97K [?]
S4 FEK1UEF;FEK1UEF;c:\windows\3VUMPGTGW.exe -VFHLTB –> c:\windows\3VUMPGTGW.exe -VFHLTB [?]
S4 GAY2F;GAY2F;c:\windows\4OIW0C0.exe -WBVYPWKID628 –> c:\windows\4OIW0C0.exe -WBVYPWKID628 [?]
S4 H0252AAY6QPU;H0252AAY6QPU;c:\windows\5MZHQ6.exe -W3ZBRSF05CN –> c:\windows\5MZHQ6.exe -W3ZBRSF05CN [?]
S4 H0PC5IV3;H0PC5IV3;c:\windows\YYT6FQVUUD.exe -OK6IRIO –> c:\windows\YYT6FQVUUD.exe -OK6IRIO [?]
S4 H76MC;H76MC;c:\windows\5HQIYDY.exe -X83ZZL7VQJLS –> c:\windows\5HQIYDY.exe -X83ZZL7VQJLS [?]
S4 HC5IOVVW3;HC5IOVVW3;c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS –> c:\windows\7SOC9WZ6HAXG.exe -XD1VEC1TS [?]
S4 IC56FJ2OJE;IC56FJ2OJE;c:\windows\9SP00JBDUZJ0.exe -YF2C670NL –> c:\windows\9SP00JBDUZJ0.exe -YF2C670NL [?]
S4 II9TFZ;II9TFZ;c:\windows\6YY3H4PB.exe -YLFI2 –> c:\windows\6YY3H4PB.exe -YLFI2 [?]
S4 J1GCP0;J1GCP0;c:\windows\9LKVE6PM.exe -YXS5Z –> c:\windows\9LKVE6PM.exe -YXS5Z [?]
S4 J33FQ1F;J33FQ1F;c:\windows\WXNZ1SB24.exe -OK0B75 –> c:\windows\WXNZ1SB24.exe -OK0B75 [?]
S4 L69Y08;L69Y08;c:\windows\9GTTF99O.exe -196QP –> c:\windows\9GTTF99O.exe -196QP [?]
S4 LHFUA;LHFUA;c:\windows\WUAA71E.exe -1I8UJXUVI7F6 –> c:\windows\WUAA71E.exe -1I8UJXUVI7F6 [?]
S4 LTQLZP2FX6;LTQLZP2FX6;c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA –> c:\windows\9NDQ984HDLAE.exe -1AQL0TYDA [?]
S4 MPJ5MST1U93;MPJ5MST1U93;c:\windows\6Z8VQ.exe -2QGBD1K9XL –> c:\windows\6Z8VQ.exe -2QGBD1K9XL [?]
S4 MUAL22T09A;MUAL22T09A;c:\windows\1HH5P.exe -2VYRJYKRXN –> c:\windows\1HH5P.exe -2VYRJYKRXN [?]
S4 NBG7GOASD1KS;NBG7GOASD1KS;c:\windows\T31TZW.exe -JQK3SOQXCMO –> c:\windows\T31TZW.exe -JQK3SOQXCMO [?]
S4 PXNMBMJR;PXNMBMJR;c:\windows\98UBG40EEE.exe -4YKLBSH –> c:\windows\98UBG40EEE.exe -4YKLBSH [?]
S4 R9I2V5;R9I2V5;c:\windows\I8V5ZLII.exe -7FLLY –> c:\windows\I8V5ZLII.exe -7FLLY [?]
S4 RO3SKV;RO3SKV;c:\windows\2NNPM3AS8.exe -7P05Z7 –> c:\windows\2NNPM3AS8.exe -7P05Z7 [?]
S4 ROO5X4F;ROO5X4F;c:\windows\40UYFPMNI.exe -7RLA4D –> c:\windows\40UYFPMNI.exe -7RLA4D [?]
S4 SQFAY;SQFAY;c:\windows\B56DIMNM.exe -8RCNP –> c:\windows\B56DIMNM.exe -8RCNP [?]
S4 TERDNO1D5;TERDNO1D5;c:\windows\CVBOD9AX78UD.exe -HOQE73D8L –> c:\windows\CVBOD9AX78UD.exe -HOQE73D8L [?]
S4 UNGVG2LBWEL;UNGVG2LBWEL;c:\windows\B276A.exe -ODIM38SNRI –> c:\windows\B276A.exe -ODIM38SNRI [?]
S4 VMAJ4WFY;VMAJ4WFY;c:\windows\C009543J07.exe -NLK1XNBF –> c:\windows\C009543J07.exe -NLK1XNBF [?]
S4 W42CWKTK7;W42CWKTK7;c:\windows\EELB1IVL92C.exe -5ZPNRQCZ –> c:\windows\EELB1IVL92C.exe -5ZPNRQCZ [?]
S4 Y2EN4QW5889;Y2EN4QW5889;c:\windows\FC596.exe -5BMEKWTTJ5 –> c:\windows\FC596.exe -5BMEKWTTJ5 [?]
S4 YT92TP;YT92TP;c:\windows\G9Z2U3LI.exe -UE5IC –> c:\windows\G9Z2U3LI.exe -UE5IC [?]
S4 YTMP1NBHT2;YTMP1NBHT2;c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB –> c:\windows\ZCHSCNE8H0QU.exe -PZQZ4WCCB [?]
S4 ZGC2AK;ZGC2AK;c:\windows\HW2VWLUR.exe -H67JL –> c:\windows\HW2VWLUR.exe -H67JL [?]
S4 ZO48L;ZO48L;c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU –> c:\windows\XZPMNYK.exe -M0LZ9ATO5ZWU [?]

— Other Services/Drivers In Memory —

*Deregistered* - PROCEXP113
.
Contents of the 'Scheduled Tasks' folder

2009-03-22 c:\windows\Tasks\Registry Winner Schedule.job
- c:\program files\Registry Winner\RegistryWinner.exe []
.
.
——- Supplementary Scan ——-
.
IE: &Down&load &Link& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatch.htm
IE: &Down&load All &Links& Us&ing Ge&tGo - c:\program files\GetGo Software\GetGo Download Manager\GGCatchAll.htm
IE: &GetGo Toolbar Search - c:\program files\GetGo Software\GetGo Download Manager\GGToolBand.dll/MENUSEARCH.HTM
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: {{01A13E40-2F55-4397-B39B-7851BCFB8008} - c:\program files\GetGo Software\GetGo Download Manager\GetGoDM.exe
TCP: {9ECC1FB7-D0B6-463E-99BE-7563CC59E2CB} = 65.240.162.65 65.240.162.66
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
FF - ProfilePath - c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: keyword.URL -
FF - component: c:\documents and settings\Kristy\Application Data\Mozilla\Firefox\Profiles\at8t2c53.default\extensions\[removed]\platform\WINNT_x86-msvc\components\lpxpcom.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-26 17:10:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-26 17:12:22
ComboFix-quarantined-files.txt 2009-03-26 22:12:10
ComboFix2.txt 2009-03-25 03:47:17
ComboFix3.txt 2009-03-24 05:52:26
ComboFix4.txt 2009-03-24 05:08:07
ComboFix5.txt 2009-03-26 22:07:24

Pre-Run: 23,533,662,208 bytes free
Post-Run: 23,513,595,904 bytes free

320
Looks like that removed them

Where did that come from?
Have you been downloading again?
c:\documents and settings\Kristy\Application Data\sborka_blackmanos_13_66.exe

Ok, yes but I thought I could… sorry about that.

You need to be careful of downloading programs or you're never going to have a clean / safe computer. If you download something, before installing it, right click on the file and scan it with your anti-virus / anti-spyware program.



Sorry I don't have time to help you remove all of them.

If you want to delete those services you can do it the same way we just did it.
Look at the each line. The service is the first one listed after the S4 like these:

Click Start > Run and Copy/Paste these commands hitting enter after each one:

sc stop ATE_PROCMON Hit enter.

sc delete ATE_PROCMON Hit enter.


sc stop 08FX8JFV Hit enter.

sc delete 08FX8JFV Hit enter.


So your for the next two:

S4 10YX3FD3;10YX3FD3;c:\windows\TJTQZPSRY5T.exe -J2X0DEKU –> c:\windows\TJTQZPSRY5T.exe -J2X0DEKU [?]
S4 19T3H;19T3H;c:\windows\IHC9IIA.exe -AQLU44CEC3UJ –> c:\windows\IHC9IIA.exe -AQLU44CEC3UJ [?]

You would use this:

sc stop 10YX3FD3 Hit enter.

sc delete 10YX3FD3 Hit enter.


sc stop 19T3H Hit enter.

sc delete 19T3H Hit enter.


After your finished be sure to do this:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]
Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    To be on the safe side, I would also change all my passwords.


    Here's my usual all clean post

    Log looks good :D


    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI