This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google Malware

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there..

My computer seems to be infected with some nasty redirecting malware.

If you can help, I would be extremely grateful :)

I think I have gotten rid of some of it by using a full scan in safe mode with Malwarebyte's Anti-Malware program.

Before I used this, every time I clicked on any link it would redirect me to google-redirect.com.. which would then redirect me to homesearchtulsa.com or incomeppc.com or some other site.

However, that appears to have stopped *for now*. I emphasize "for now", because I have run Anti-Malware program a few times for this problem, and it has a nasty habit of coming right back.

Right now, the only thing that seems to be occuring is that when I go to google , it loads up v1.adwarefeed.com , which is obviously nthing to do with Google. I have no idea of the interntions of this, but it can't be good.

I'd like to make sure my computer is completely clean of all this junk

I have listed my Anti-Malware logs below and also the HijackThis log.

Please help:


Malwarebytes' Anti-Malware 1.37
Database version: 2186
Windows 5.1.2600 Service Pack 2

02/06/2009 22:40:03
mbam-log-2009-06-02 (22-40-03).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 246006
Time elapsed: 52 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 9

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autochk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysldtray (Worm.Koobface) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\autochk.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Paul\protect.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Paul\Start Menu\Programs\Startup\ChkDisk.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\ld08.exe (Worm.Koobface) -> Quarantined and deleted successfully.
c:\documents and settings\Paul\Start Menu\Programs\Startup\ChkDisk.lnk (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\Paul\Local Settings\Temp\nsrbgxod.bak (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\nsrbgxod.bak (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\msb.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lmn_setup.exe (Trojan.Downloader) -> Quarantined and deleted successfully.


—————-

HIJACKTHIS LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:04:20, on 03/06/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common

Files\LightScribe\LSSrvc.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-

Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common

Files\Real\Update_OB\realsched.exe
C:\Program Files\Siber Systems\AI

RoboForm\RoboTaskBarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend

Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Search Bar =

http://uk.red.clientapps.yahoo.com/customize/btyaho

o/defaults/sb/*http://uk.docs.yahoo.com/info/bt_sid

e.html
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet

Explorer\SearchURL,(Default) =

http://uk.red.clientapps.yahoo.com/customize/btyaho

o/defaults/su/*http://uk.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection

Wizard,ShellNext =

http://ie.redirect.hp.com/svs/rdr?

TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf

=laptop
R1 -

HKCU\Software\Microsoft\Windows\CurrentVersion\Inte

rnet Settings,ProxyServer = :
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-

C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-

009027A5CD4F} - c:\program

files\google\googletoolbar4.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908

-00400523e39a} - C:\Program Files\Siber Systems\AI

RoboForm\roboform.dll
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-

DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program

Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2

-892F-0090271D4F88} - C:\Program Files\Yahoo!

\Companion\Installs\cpn\yt.dll
O3 - Toolbar: StatsJunky - {1D417F37-A1EF-4D7B-

AFEB-8FC8B2A404F6} - C:\Program

Files\StatsJunky\StatsJunkyTool.dll
O3 - Toolbar: SpeedBit - {EBFCD017-BCAD-42C3-9ED5-

89DBDFC59171} - C:\Program Files\SpeedBit

Toolbar\Toolbar\SpeedBit.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program

Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program

Files\Common Files\Real\Update_OB\realsched.exe"

-osboot
O4 - HKCU\..\Run: [RoboForm] "C:\Program

Files\Siber Systems\AI

RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32

\ctfmon.exe
O4 - HKCU\..\Run: [Anonymizer] C:\Program

Files\Anonymizer\Anonymizer Software\Anonymizer.exe

-nogui
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE]

C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [brastk]

C:\WINDOWS\system32\brastk.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting]

"C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

(User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [autochk] rundll32.exe

C:\WINDOWS\system32\config\SYSTEM~1

\protect.dll,_IWMPEvents@16 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE]

C:\WINDOWS\system32\CTFMON.EXE (User 'Default

user')
O4 - S-1-5-18 Startup: ChkDisk.lnk = ? (User

'SYSTEM')
O4 - .DEFAULT Startup: ChkDisk.lnk = ? (User

'Default user')
O8 - Extra context menu item: &Download by Orbit -

res://C:\Program

Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit

- res://C:\Program

Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: &Save Flash In This

Page by Flash Saver - C:\PROGRA~1\FLASHS~1\save.htm
O8 - Extra context menu item: Customize Menu -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Do&wnload selected by

Orbit - res://C:\Program

Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by

Orbit - res://C:\Program

Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft

Excel - res://C:\PROGRA~1\MICROS~4\Office10

\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF

-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Flash Saver - {09EA1F80-F40A-

11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1

\save.htm
O9 - Extra 'Tools' menuitem: Flash Saver -

{09EA1F80-F40A-11D1-B792-444553540001} -

C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra button: Fill Forms - {320AF880-6646-

11D3-ABEE-C5DBF3571F46} - file://C:\Program

Files\Siber Systems\AI

RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms -

{320AF880-6646-11D3-ABEE-C5DBF3571F46} -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE

-C5DBF3571F49} - file://C:\Program Files\Siber

Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms -

{320AF880-6646-11D3-ABEE-C5DBF3571F49} -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComSavePass.html
O9 - Extra button: Send to Mindjet MindManager -

{531B9DC0-D8EE-4c76-A6EE-6C1E50569655} - C:\Program

Files\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-

9908-00400523e39a} - file://C:\Program Files\Siber

Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar -

{724d43aa-0d85-11d4-9908-00400523e39a} -

file://C:\Program Files\Siber Systems\AI

RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2

-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra button: RapidReader - {C062F84F-428F-

42f7-B6A4-73AE08326339} - C:\PROGRA~1\SOFTOL~1

\RAPIDR~2\RAPIDR~1.DLL (HKCU)
O14 - IERESET.INF:

START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?

TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf

=laptop
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-

9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1

\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: karna.dat ,

,C:\WINDOWS\system32\puvugova.dll

c:\windows\system32\giwaporu.dll
O23 - Service: Lavasoft Ad-Aware Service

(aawservice) - Lavasoft - C:\Program

Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Anonymizer Management Service

(AnonMgmtSvc) - Anonymizer - C:\Program

Files\Anonymizer\Anonymizer

Software\Common\AnonMgmtSvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies

Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: dopewars server (dopewars-server) -

Unknown owner - C:\Program Files\dopewars-1.5.12

\dopewars.exe
O23 - Service: GoogleDesktopManager - Google -

C:\Program Files\Google\Google Desktop

Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) -

Google - C:\Program Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett

-Packard Development Company, L.P. - C:\Program

Files\HPQ\Shared\hpqwmi.exe
O23 - Service: hpqwmiex - Hewlett-Packard

Development Company, L.P. - C:\Program

Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager

(IDriverT) - Macrovision Corporation - C:\Program

Files\Common Files\InstallShield\Driver\1050\Intel

32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc.

- C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Unknown owner -

C:\Program Files\Kontiki\KService.exe
O23 - Service: LightScribeService Direct Disc

Labeling Service (LightScribeService) - Hewlett-

Packard Company - C:\Program Files\Common

Files\LightScribe\LSSrvc.exe
O23 - Service: MozyHome Backup Service (mozybackup)

- Unknown owner - C:\Program

Files\MozyHome\mozybackup.exe
O23 - Service: TrueVector Internet Monitor (vsmon)

- Check Point Software Technologies LTD -

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 9374 bytes


———–


Thank you for helping :-)
Hi,

Please open notepad, click Format and make sure Word Wrap is unchecked.

Please download GooredFix and save it to your Desktop.
  • Double-click GooredFix.exe on your Desktop to run it.
  • Select "2. Fix Goored" by typing 2 and pressing Enter.
  • Make sure all instances of Firefox are closed at this point.
  • Type y at the prompt and press Enter again.
  • A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called GooredLog.txt).
Note: If you receive a message saying that GooredFix needs your system to be restarted, please close all applications and reboot your system. Please also allow any registry changes that may be prompted by any of your security programs.


Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Hi again! First off, I just want to say a sincere thank you for helping me out with this. I really do appreciate your help! :-) Ok.. well, before I post the logs you asked for I should prbably give you an update about new things popping up on my screen. I dont know if they are related the original infection or not. Anyway… my desktop has now changed to a black screen with red writing.. saying "WARNING! YOUR'RE IN DANGER! YOUR COMPUTER IS INFECTED WITH SPYWARE!". It then goes on to explain how everything I do is stored on my hard drive, and it could be found by my boss, my children, my wife etc etc. All of it with awful spelling and grammar. This is obviously scare tactics to get me to buy adware software. Also.. another new thing is that I have some unwanted system scan come up when i start the computer. I didnt catch the name, as I closed it so fast. I think it was "System Scan". I also get fake windows messages telling me I'm infected on the bottom right bit of the screen, by the clock, saying I need to get anti-spyware software. Like I say, I dont know if this is related but I thought I should mention it. Here are the logs you required: GooredFix v1.92 by jpshortstuff Log created at 20:40 on 05/06/2009 running Option #2 (Paul) Firefox version 3.0.10 (en-GB) =====Goored Deletions===== C:\Program Files\Mozilla Firefox\extensions\{FB5C065F-E0ED-4A10-87C3-1BC56A1B59E8} ->Backing up folder… Done. ->Emptying folder… Done. ->Deleting folder… Done. C:\Program Files\Mozilla Firefox\extensions\{C4D578D7-000D-4A6B-A725-D3775FFE69E1} ->Backing up folder… Done. ->Emptying folder… Done. ->Deleting folder… Done. =====Dumping Registry Values===== [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions] "Plugins"="C:\Program Files\Mozilla Firefox\plugins" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions] "Components"="C:\Program Files\Mozilla Firefox\components" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{22119944-ED35-4ab1-910B-E619EA06A115}"="C:\Program Files\Siber Systems\AI RoboForm\Firefox" ——- DDS DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 20:42:11.90 on 05/06/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.382.142 [GMT 1:00] FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\MozyHome\mozybackup.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\GetRight\GetRight.exe C:\WINDOWS\system32\notepad.exe C:\Documents and Settings\Paul\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iehome&locale;=EN_US&c;=Q106&bd;=presario&pf;=laptop uSearchAssistant = hxxp://www.google.com uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/ mSearchAssistant = hxxp://www.google.com uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: &Google;: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar4.dll TB: &RoboForm;: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll TB: ZoneAlarm Spy Blocker: {f0d4b239-da4b-4daf-81e4-dfee4931a4aa} - c:\program files\zonealarmsb\bar\1.bin\SPYBLOCK.DLL TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: StatsJunky: {1d417f37-a1ef-4d7b-afeb-8fc8b2a404f6} - c:\program files\statsjunky\StatsJunkyTool.dll TB: SpeedBit: {ebfcd017-bcad-42c3-9ed5-89dbdfc59171} - c:\program files\speedbit toolbar\toolbar\SpeedBit.dll TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File EB: ClipMate ClipBar 7: {f60c63ce-52af-4915-aac9-f100fcde270f} - c:\progra~1\clipma~1\CLIPMA~1.DLL uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Anonymizer] c:\program files\anonymizer\anonymizer software\Anonymizer.exe -nogui mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [11047184] c:\documents and settings\all users\application data\11047184\11047184.exe mRun: [91057176] c:\documents and settings\all users\application data\91057176\91057176.exe dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE dRun: [brastk] c:\windows\system32\brastk.exe dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t dRun: [autochk] rundll32.exe c:\windows\system32\config\system~1\protect.dll,_IWMPEvents@16 dPolicies-explorer: NoSetActiveDesktop = 1 (0x1) dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) dPolicies-system: DisableTaskMgr = 1 (0x1) IE: &Download; by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201 IE: &Grab; video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204 IE: &Save; Flash In This Page by Flash Saver - c:\progra~1\flashs~1\save.htm IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html IE: Do&wnload; selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203 IE: Down&load; all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202 IE: E&xport; to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000 IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {09EA1F80-F40A-11D1-B792-444553540001} - c:\progra~1\flashs~1\save.htm IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll IE: {531B9DC0-D8EE-4c76-A6EE-6C1E50569655} - {AC41D38F-B56D-40AD-94E0-B493D130C959} - c:\program files\mindjet\mindmanager 6\Mm6InternetExplorer.dll DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: AtiExtEvent - Ati2evxx.dll AppInit_DLLs: karna.dat , ,c:\windows\system32\puvugova.dll c:\windows\system32\giwaporu.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, LSA: Notification Packages = scecli c:\windows\system32\puvugova.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\paul\applic~1\mozilla\firefox\profiles\auzstdwt.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;= FF - prefs.js: browser.search.selectedEngine - Google FF - component: c:\documents and settings\paul\application data\mozilla\firefox\profiles\auzstdwt.default\extensions\{22119944-ed35-4ab1-910b-e619ea06a115}\components\rfproxy_27.dll FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll FF - plugin: c:\documents and settings\paul\application data\mozilla\firefox\profiles\auzstdwt.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp07074039.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava11.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava12.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava13.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava14.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJava32.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPOJI610.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPEyeCheck.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPGetRt.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPZoneSB.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll ============= SERVICES / DRIVERS =============== R1 mozyFilter;mozyFilter;c:\windows\system32\drivers\mozy.sys [2008-12-11 53752] R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2006-9-1 353680] R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664] R3 gttap1;GoTrusted TAP Adapter;c:\windows\system32\drivers\gttap1.sys [2007-8-31 20480] R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2004-12-15 200192] S0 aprb;aprb;c:\windows\system32\drivers\gfpbd.sys –> c:\windows\system32\drivers\gfpbd.sys [?] S0 snIxrb;snIxrb;c:\windows\system32\drivers\cuospx.sys –> c:\windows\system32\drivers\cuospx.sys [?] S0 xshts;xshts;c:\windows\system32\drivers\jffpc.sys –> c:\windows\system32\drivers\jffpc.sys [?] S2 AnonMgmtSvc;Anonymizer Management Service;c:\program files\anonymizer\anonymizer software\common\AnonMgmtSvc.exe [2008-11-17 37560] S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?] S3 dopewars-server;dopewars server;c:\program files\dopewars-1.5.12\dopewars.exe -n –> c:\program files\dopewars-1.5.12\dopewars.exe -N [?] S3 NPF;Netgroup Packet Filter;c:\windows\system32\drivers\npf.sys [2005-8-2 32512] =============== Created Last 30 ================ 2009-06-05 05:15 54,156 a—h— c:\windows\QTFont.qfn 2009-06-05 05:15 1,409 a——- c:\windows\QTFont.for 2009-06-04 14:40 –d—– c:\docume~1\alluse~1\applic~1\91057176 2009-06-04 14:40 –d—– c:\docume~1\alluse~1\applic~1\11047184 2009-06-04 14:39 537,918 a——- c:\windows\system32\pv_install.exe 2009-06-02 23:11 –d—– c:\program files\Trend Micro 2009-06-01 18:28 –d—– C:\Market Samurai 2009-05-30 20:37 111,271 a——- c:\windows\system32\install.48025.exe 2009-05-29 01:52 –d—– c:\docume~1\paul\applic~1\Anonymizer 2009-05-29 01:50 –d—– c:\program files\Anonymizer 2009-05-29 01:50 –d—– c:\docume~1\alluse~1\applic~1\Anonymizer 2009-05-29 01:49 –d-h— c:\docume~1\alluse~1\applic~1\{773E7240-B347-4DFF-A6EF-6E829EDD59DF} 2009-05-26 21:58 192 a——- C:\487656.bat 2009-05-26 21:42 105 a——- C:\tj.vbs 2009-05-22 21:47 1 a——- c:\windows\system32\uniq.tll 2009-05-18 06:02 –d—– c:\program files\PromoSoft 2009-05-18 05:26 –d—– c:\docume~1\paul\applic~1\PADGen 2009-05-18 05:26 –d—– c:\program files\PADGen 2009-05-14 13:24 118 a——- c:\windows\system32\MRT.INI 2009-05-14 02:23 664 a——- c:\windows\system32\d3d9caps.dat 2009-05-13 08:38 244 a—h— C:\sqmnoopt04.sqm 2009-05-13 08:38 232 a—h— C:\sqmdata04.sqm 2009-05-13 08:38 244 a—h— C:\sqmnoopt03.sqm 2009-05-13 08:38 232 a—h— C:\sqmdata03.sqm 2009-05-13 08:38 244 a—h— C:\sqmnoopt02.sqm 2009-05-13 08:38 232 a—h— C:\sqmdata02.sqm 2009-05-13 06:35 244 a—h— C:\sqmnoopt01.sqm 2009-05-13 06:35 232 a—h— C:\sqmdata01.sqm 2009-05-13 06:29 244 a—h— C:\sqmnoopt00.sqm 2009-05-13 06:29 232 a—h— C:\sqmdata00.sqm 2009-05-13 05:23 1,310,720 a——- c:\windows\system32\ChilkatUpload.dll 2009-05-13 05:23 180,224 a——- c:\windows\system32\ijl11.dll 2009-05-08 20:07 455 a——- C:\xcrashdump.dat ==================== Find3M ==================== 2009-06-05 20:41 4,212 a—h— c:\windows\system32\zllictbl.dat 2009-06-05 04:56 512 a——- C:\drmHeader.bin 2009-05-26 13:20 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-05-26 13:19 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-05-14 02:17 94,208 a——- c:\windows\DUMPb0f0.tmp 2009-05-06 13:49 52,224 a–sh— c:\windows\system32\jaduveha.exe 2009-05-05 15:11 50,688 a——- c:\windows\system32\wbhelp2.dll 2009-05-04 09:04 685,056 a——- c:\windows\isRS-000.tmp 2009-04-28 00:35 60,048 a—h— c:\windows\system32\mlfcache.dat 2009-03-21 15:18 986,112 ——– c:\windows\system32\dllcache\kernel32.dll 2009-03-08 14:09 391,536 a——- c:\windows\system32\dllcache\iedkcs32.dll 2009-03-08 14:09 638,816 ——– c:\windows\system32\dllcache\iexplore.exe 2009-03-08 04:41 5,937,152 a——- c:\windows\system32\dllcache\mshtml.dll 2009-03-08 04:34 914,944 a——- c:\windows\system32\wininet.dll 2009-03-08 04:34 914,944 a——- c:\windows\system32\dllcache\wininet.dll 2009-03-08 04:34 1,206,784 a——- c:\windows\system32\dllcache\urlmon.dll 2009-03-08 04:34 236,544 ——– c:\windows\system32\dllcache\webcheck.dll 2009-03-08 04:34 43,008 a——- c:\windows\system32\licmgr10.dll 2009-03-08 04:34 43,008 a——- c:\windows\system32\dllcache\licmgr10.dll 2009-03-08 04:34 105,984 ——– c:\windows\system32\dllcache\url.dll 2009-03-08 04:34 193,536 a——- c:\windows\system32\dllcache\msrating.dll 2009-03-08 04:34 109,568 ——– c:\windows\system32\dllcache\occache.dll 2009-03-08 04:33 759,296 a——- c:\windows\system32\dllcache\VGX.dll 2009-03-08 04:33 18,944 a——- c:\windows\system32\dllcache\corpol.dll 2009-03-08 04:33 18,944 a——- c:\windows\system32\corpol.dll 2009-03-08 04:33 25,600 a——- c:\windows\system32\dllcache\jsproxy.dll 2009-03-08 04:33 726,528 a——- c:\windows\system32\dllcache\jscript.dll 2009-03-08 04:33 229,376 a——- c:\windows\system32\dllcache\ieaksie.dll 2009-03-08 04:33 420,352 a——- c:\windows\system32\vbscript.dll 2009-03-08 04:33 420,352 a——- c:\windows\system32\dllcache\vbscript.dll 2009-03-08 04:33 125,952 a——- c:\windows\system32\dllcache\ieakeng.dll 2009-03-08 04:32 72,704 a——- c:\windows\system32\dllcache\admparse.dll 2009-03-08 04:32 72,704 a——- c:\windows\system32\admparse.dll 2009-03-08 04:32 173,056 a——- c:\windows\system32\dllcache\ie4uinit.exe 2009-03-08 04:32 163,840 a——- c:\windows\system32\dllcache\ieakui.dll 2009-03-08 04:32 71,680 a——- c:\windows\system32\iesetup.dll 2009-03-08 04:32 71,680 a——- c:\windows\system32\dllcache\iesetup.dll 2009-03-08 04:32 55,808 a——- c:\windows\system32\dllcache\iernonce.dll 2009-03-08 04:32 128,512 ——– c:\windows\system32\dllcache\advpack.dll 2009-03-08 04:32 94,720 a——- c:\windows\system32\dllcache\inseng.dll 2009-03-08 04:32 611,840 a——- c:\windows\system32\dllcache\mstime.dll 2009-03-08 04:31 183,808 a——- c:\windows\system32\dllcache\iepeers.dll 2009-03-08 04:31 348,160 a——- c:\windows\system32\dllcache\dxtmsft.dll 2009-03-08 04:31 216,064 a——- c:\windows\system32\dllcache\dxtrans.dll 2009-03-08 04:31 34,816 a——- c:\windows\system32\imgutil.dll 2009-03-08 04:31 34,816 ——– c:\windows\system32\dllcache\imgutil.dll 2009-03-08 04:31 46,592 a——- c:\windows\system32\dllcache\pngfilt.dll 2009-03-08 04:31 66,560 a——- c:\windows\system32\dllcache\mshtmled.dll 2009-03-08 04:31 48,128 a——- c:\windows\system32\mshtmler.dll 2009-03-08 04:31 48,128 ——– c:\windows\system32\dllcache\mshtmler.dll 2009-03-08 04:31 45,568 a——- c:\windows\system32\mshta.exe 2009-03-08 04:31 45,568 a——- c:\windows\system32\dllcache\mshta.exe 2009-03-08 04:24 68,608 a——- c:\windows\system32\dllcache\hmmapi.dll 2009-03-08 04:22 156,160 a——- c:\windows\system32\msls31.dll 2009-03-08 04:22 156,160 ——– c:\windows\system32\dllcache\msls31.dll 2008-12-22 05:08 71,720 ac—— c:\docume~1\paul\applic~1\GDIPFONTCACHEV1.DAT 2008-10-10 02:07 60,744 a——- c:\documents and settings\paul\g2mdlhlpx.exe 2008-09-19 01:44 2,258 a——- c:\docume~1\paul\applic~1\wklnhst.dat 2008-08-17 05:45 9,700 a——- c:\docume~1\paul\applic~1\unins000.dat 2008-08-17 05:45 683,801 a——- c:\docume~1\paul\applic~1\unins000.exe 2008-08-15 17:16 61,224 a——- c:\documents and settings\paul\GoToAssistDownloadHelper.exe 2002-07-31 20:55 104 —sh— c:\windows\WSYS049.SYS ============= FINISH: 20:43:20.10 ===============

Attachments:

Hi,

Well, we took out the small one (Firefox redirector), but it looks like there's way more on there than I thought.

Download ComboFix by sUBs from here or here

Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

**Save it to your desktop**

We need to disable one or more of your security programs so that they do not interfere with ComboFix.

Make sure ZoneAlarm is disabled when you run this.

Double click on ComboFix.exe & follow the prompts. If you are prompted to install the Recovery Console I recommend you go ahead and hit yes.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Notes:
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.
  • ComboFix disconnects your machine from the internet when it runs. This connection should be automatically restored when ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Oh Lordy… the nightmares I have gone through to send this post. Following the instructions to run combofix, my computer restarted, and after that… the entire windows was slowed down to an absolute crawl. Windows took 25 mins plus to load. firefox took 10 mins to load. I noticed that on the CPU usage was constantly near 100%.

And the internet didnt work at all. I could connect wirelessly to my local network, but firefox and IE just wouldnt connect to the pages.

To get round this and to get back on the internet, I installed a new copy of Windows XP Home Edition into a separate folder. It was installed into the same partition as the old Windows (against Windows advice). And it's actually a slightly older version of XP (this version is Home Edition). And that's what I'm using to make this post. A fresh installation of Windows.


So now I think I have to still clean out the old, malware-riddled version of Windows. I think then I will migrate everything over to this new installation anyway, because it runs much faster. But I dont want any infected files coming into this new Windows. So I still have to clean the old installation.

Thanks again for your help :-)


Here's the Combofix for the old installation:

ComboFix 09-06-05.09 - Paul 07/06/2009 16:25.3 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.382.176 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 )))))))))))))))))))))))))))))))
.

2009-06-07 00:24 . 2009-06-07 00:24 ——– d-sh–w- C:\found.000
2009-06-04 13:39 . 2009-06-04 13:40 537918 —-a-w- c:\windows\system32\pv_install.exe
2009-06-02 22:11 . 2009-06-02 22:11 ——– dc—-w- c:\program files\Trend Micro
2009-06-01 17:28 . 2009-06-01 17:28 ——– d—–w- C:\Market Samurai
2009-05-30 19:37 . 2009-06-02 22:12 111271 —-a-w- c:\windows\system32\install.48025.exe
2009-05-29 00:52 . 2009-05-29 00:52 ——– d—–w- c:\documents and settings\Paul\Application Data\Anonymizer
2009-05-29 00:51 . 2008-11-17 20:58 2759408 —-a-w- c:\documents and settings\All Users\Application Data\{773E7240-B347-4DFF-A6EF-6E829EDD59DF}\Anonymizer_Software.exe
2009-05-29 00:50 . 2009-05-29 00:50 ——– dc—-w- c:\program files\Anonymizer
2009-05-29 00:50 . 2009-05-29 00:50 ——– dc—-w- c:\documents and settings\All Users\Application Data\Anonymizer
2009-05-29 00:49 . 2009-05-29 00:51 ——– d–h–w- c:\documents and settings\All Users\Application Data\{773E7240-B347-4DFF-A6EF-6E829EDD59DF}
2009-05-26 21:41 . 2009-05-26 21:41 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2009-05-26 20:58 . 2009-05-31 10:47 192 -c–a-w- C:\487656.bat
2009-05-26 20:42 . 2009-05-26 03:18 105 -c–a-w- C:\tj.vbs
2009-05-18 05:02 . 2009-05-18 05:21 ——– dc—-w- c:\program files\PromoSoft
2009-05-18 04:26 . 2009-05-18 04:26 ——– d—–w- c:\documents and settings\Paul\Application Data\PADGen
2009-05-18 04:26 . 2009-05-18 04:26 ——– dc—-w- c:\program files\PADGen
2009-05-14 01:23 . 2009-05-14 01:45 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-05-13 04:23 . 2009-03-21 18:40 1310720 —-a-w- c:\windows\system32\ChilkatUpload.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-07 11:47 . 2009-06-07 13:21 1350144 —-a-w- c:\windows\Internet Logs\xDB137.tmp
2009-06-07 08:38 . 2009-06-07 11:47 1350144 —-a-w- c:\windows\Internet Logs\xDB10A.tmp
2009-06-07 08:38 . 2009-06-07 11:47 9728 —-a-w- c:\windows\Internet Logs\xDBE0.tmp
2009-06-07 08:36 . 2009-06-07 08:38 9216 —-a-w- c:\windows\Internet Logs\xDBDF.tmp
2009-06-07 08:36 . 2009-06-07 08:36 9728 —-a-w- c:\windows\Internet Logs\xDB136.tmp
2009-06-07 08:35 . 2009-06-07 08:36 1350144 —-a-w- c:\windows\Internet Logs\xDB135.tmp
2009-06-07 08:35 . 2009-06-07 08:35 9216 —-a-w- c:\windows\Internet Logs\xDB134.tmp
2009-06-07 08:35 . 2007-04-27 22:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Kontiki
2009-06-07 08:35 . 2009-06-07 08:35 1350144 —-a-w- c:\windows\Internet Logs\xDB133.tmp
2009-06-07 08:34 . 2009-06-07 08:34 1350144 —-a-w- c:\windows\Internet Logs\xDB132.tmp
2009-06-07 08:34 . 2009-06-07 08:34 9216 —-a-w- c:\windows\Internet Logs\xDB131.tmp
2009-06-07 08:33 . 2009-06-07 08:33 9728 —-a-w- c:\windows\Internet Logs\xDB12F.tmp
2009-06-07 08:33 . 2009-06-07 08:33 1350144 —-a-w- c:\windows\Internet Logs\xDB130.tmp
2009-06-07 08:30 . 2009-06-07 08:30 1350144 —-a-w- c:\windows\Internet Logs\xDB12E.tmp
2009-06-07 08:29 . 2009-06-07 08:29 9728 —-a-w- c:\windows\Internet Logs\xDB12D.tmp
2009-06-07 08:28 . 2009-06-07 08:28 9216 —-a-w- c:\windows\Internet Logs\xDB12C.tmp
2009-06-07 08:27 . 2009-06-07 08:27 9728 —-a-w- c:\windows\Internet Logs\xDB12B.tmp
2009-06-07 08:26 . 2009-06-07 08:26 1350144 —-a-w- c:\windows\Internet Logs\xDB12A.tmp
2009-06-07 08:25 . 2009-06-07 08:25 1350144 —-a-w- c:\windows\Internet Logs\xDB129.tmp
2009-06-07 08:25 . 2009-06-07 08:25 9216 —-a-w- c:\windows\Internet Logs\xDB128.tmp
2009-06-07 08:24 . 2009-06-07 08:24 9728 —-a-w- c:\windows\Internet Logs\xDB127.tmp
2009-06-07 08:23 . 2009-06-07 08:23 1350144 —-a-w- c:\windows\Internet Logs\xDB126.tmp
2009-06-07 08:23 . 2009-06-07 08:23 9216 —-a-w- c:\windows\Internet Logs\xDB125.tmp
2009-06-07 08:22 . 2009-06-07 08:22 1350144 —-a-w- c:\windows\Internet Logs\xDB124.tmp
2009-06-07 08:22 . 2009-06-07 08:22 9728 —-a-w- c:\windows\Internet Logs\xDB123.tmp
2009-06-07 08:20 . 2009-06-07 08:20 9216 —-a-w- c:\windows\Internet Logs\xDB122.tmp
2009-06-07 08:19 . 2009-06-07 08:19 9728 —-a-w- c:\windows\Internet Logs\xDB121.tmp
2009-06-07 08:13 . 2009-06-07 08:13 1350144 —-a-w- c:\windows\Internet Logs\xDB120.tmp
2009-06-07 08:13 . 2009-06-07 08:13 9728 —-a-w- c:\windows\Internet Logs\xDB11F.tmp
2009-06-07 08:12 . 2009-06-07 08:12 1350144 —-a-w- c:\windows\Internet Logs\xDB11E.tmp
2009-06-07 08:11 . 2009-06-07 08:11 9728 —-a-w- c:\windows\Internet Logs\xDB11D.tmp
2009-06-07 08:10 . 2009-06-07 08:10 9728 —-a-w- c:\windows\Internet Logs\xDB11C.tmp
2009-06-07 08:09 . 2009-06-07 08:09 9216 —-a-w- c:\windows\Internet Logs\xDB11B.tmp
2009-06-07 08:05 . 2009-06-07 08:06 9728 —-a-w- c:\windows\Internet Logs\xDB11A.tmp
2009-06-07 08:04 . 2009-06-07 08:04 9216 —-a-w- c:\windows\Internet Logs\xDB119.tmp
2009-06-07 08:04 . 2009-06-07 08:04 1350144 —-a-w- c:\windows\Internet Logs\xDB118.tmp
2009-06-07 08:02 . 2009-06-07 08:02 1350144 —-a-w- c:\windows\Internet Logs\xDB117.tmp
2009-06-07 08:02 . 2009-06-07 08:02 9216 —-a-w- c:\windows\Internet Logs\xDB116.tmp
2009-06-07 07:59 . 2009-06-07 08:00 1350144 —-a-w- c:\windows\Internet Logs\xDB115.tmp
2009-06-07 07:59 . 2009-06-07 07:59 1350144 —-a-w- c:\windows\Internet Logs\xDB114.tmp
2009-06-07 07:59 . 2009-06-07 07:59 9728 —-a-w- c:\windows\Internet Logs\xDB113.tmp
2009-06-07 07:58 . 2009-06-07 07:58 9728 —-a-w- c:\windows\Internet Logs\xDB111.tmp
2009-06-07 07:58 . 2009-06-07 07:58 1350144 —-a-w- c:\windows\Internet Logs\xDB112.tmp
2009-06-07 07:57 . 2009-06-07 07:57 1350144 —-a-w- c:\windows\Internet Logs\xDB110.tmp
2009-06-07 07:57 . 2009-06-07 07:57 9216 —-a-w- c:\windows\Internet Logs\xDB10F.tmp
2009-06-07 07:56 . 2009-06-07 07:56 1350144 —-a-w- c:\windows\Internet Logs\xDB10E.tmp
2009-06-07 07:56 . 2009-06-07 07:56 9216 —-a-w- c:\windows\Internet Logs\xDB10D.tmp
2009-06-07 07:55 . 2009-06-07 07:55 1350144 —-a-w- c:\windows\Internet Logs\xDB10C.tmp
2009-06-07 07:55 . 2009-06-07 07:55 9216 —-a-w- c:\windows\Internet Logs\xDB10B.tmp
2009-06-07 07:53 . 2009-06-07 07:53 1350144 —-a-w- c:\windows\Internet Logs\xDB109.tmp
2009-06-07 07:53 . 2009-06-07 07:53 9216 —-a-w- c:\windows\Internet Logs\xDB108.tmp
2009-06-07 07:52 . 2009-06-07 07:52 1350144 —-a-w- c:\windows\Internet Logs\xDB107.tmp
2009-06-07 07:52 . 2009-06-07 07:52 9728 —-a-w- c:\windows\Internet Logs\xDB106.tmp
2009-06-07 07:51 . 2009-06-07 07:51 1350144 —-a-w- c:\windows\Internet Logs\xDB105.tmp
2009-06-07 07:51 . 2009-06-07 07:51 9728 —-a-w- c:\windows\Internet Logs\xDB104.tmp
2009-06-07 07:50 . 2009-06-07 07:50 1350144 —-a-w- c:\windows\Internet Logs\xDB103.tmp
2009-06-07 07:50 . 2009-06-07 07:50 9216 —-a-w- c:\windows\Internet Logs\xDB102.tmp
2009-06-07 07:49 . 2009-06-07 07:49 1350144 —-a-w- c:\windows\Internet Logs\xDB101.tmp
2009-06-07 07:49 . 2009-06-07 07:49 9216 —-a-w- c:\windows\Internet Logs\xDB100.tmp
2009-06-07 07:48 . 2009-06-07 07:49 1350144 —-a-w- c:\windows\Internet Logs\xDBFF.tmp
2009-06-07 07:48 . 2009-06-07 07:48 9728 —-a-w- c:\windows\Internet Logs\xDBFE.tmp
2009-06-07 07:48 . 2009-06-07 07:48 1350144 —-a-w- c:\windows\Internet Logs\xDBFD.tmp
2009-06-07 07:48 . 2009-06-07 07:48 9728 —-a-w- c:\windows\Internet Logs\xDBFC.tmp
2009-06-07 07:47 . 2009-06-07 07:47 9216 —-a-w- c:\windows\Internet Logs\xDBFB.tmp
2009-06-07 07:47 . 2009-06-07 07:47 9728 —-a-w- c:\windows\Internet Logs\xDBFA.tmp
2009-06-07 07:46 . 2009-06-07 07:46 9728 —-a-w- c:\windows\Internet Logs\xDBF9.tmp
2009-06-07 07:42 . 2009-06-07 07:42 9728 —-a-w- c:\windows\Internet Logs\xDBF8.tmp
2009-06-07 07:42 . 2009-06-07 07:42 1350144 —-a-w- c:\windows\Internet Logs\xDBF7.tmp
2009-06-07 07:41 . 2009-06-07 07:41 9728 —-a-w- c:\windows\Internet Logs\xDBF6.tmp
2009-06-07 07:40 . 2009-06-07 07:41 1350144 —-a-w- c:\windows\Internet Logs\xDBF5.tmp
2009-06-07 07:40 . 2009-06-07 07:40 9728 —-a-w- c:\windows\Internet Logs\xDBF4.tmp
2009-06-07 07:40 . 2009-06-07 07:40 9728 —-a-w- c:\windows\Internet Logs\xDBF3.tmp
2009-06-07 07:39 . 2009-06-07 07:39 9728 —-a-w- c:\windows\Internet Logs\xDBF2.tmp
2009-06-07 07:39 . 2009-06-07 07:39 1350144 —-a-w- c:\windows\Internet Logs\xDBF1.tmp
2009-06-07 07:38 . 2009-06-07 07:38 1350144 —-a-w- c:\windows\Internet Logs\xDBF0.tmp
2009-06-07 07:38 . 2009-06-07 07:38 9216 —-a-w- c:\windows\Internet Logs\xDBEF.tmp
2009-06-07 07:34 . 2009-06-07 07:34 1350144 —-a-w- c:\windows\Internet Logs\xDBEE.tmp
2009-06-07 07:33 . 2009-06-07 07:33 1350144 —-a-w- c:\windows\Internet Logs\xDBED.tmp
2009-06-07 07:33 . 2009-06-07 07:33 9728 —-a-w- c:\windows\Internet Logs\xDBEC.tmp
2009-06-07 07:33 . 2009-06-07 07:33 9728 —-a-w- c:\windows\Internet Logs\xDBEB.tmp
2009-06-07 07:32 . 2009-06-07 07:33 1350144 —-a-w- c:\windows\Internet Logs\xDBEA.tmp
2009-06-07 07:31 . 2009-06-07 07:31 1350144 —-a-w- c:\windows\Internet Logs\xDBE9.tmp
2009-06-07 07:31 . 2009-06-07 07:31 9728 —-a-w- c:\windows\Internet Logs\xDBE8.tmp
2009-06-07 07:30 . 2009-06-07 07:30 9728 —-a-w- c:\windows\Internet Logs\xDBE7.tmp
2009-06-07 07:30 . 2009-06-07 07:30 9728 —-a-w- c:\windows\Internet Logs\xDBE5.tmp
2009-06-07 07:30 . 2009-06-07 07:30 1350144 —-a-w- c:\windows\Internet Logs\xDBE6.tmp
2009-06-07 07:28 . 2009-06-07 07:29 1350144 —-a-w- c:\windows\Internet Logs\xDBE4.tmp
2009-06-07 07:28 . 2009-06-07 07:28 1350144 —-a-w- c:\windows\Internet Logs\xDBE3.tmp
2009-06-07 07:28 . 2009-06-07 07:28 9728 —-a-w- c:\windows\Internet Logs\xDBE2.tmp
2009-06-07 07:26 . 2009-06-07 07:26 9728 —-a-w- c:\windows\Internet Logs\xDBE1.tmp
2009-06-07 07:25 . 2009-06-07 07:25 9216 —-a-w- c:\windows\Internet Logs\xDBDE.tmp
2009-06-07 07:24 . 2009-06-07 07:25 1350144 —-a-w- c:\windows\Internet Logs\xDBDD.tmp
2009-06-07 07:24 . 2009-06-07 07:25 9728 —-a-w- c:\windows\Internet Logs\xDBDC.tmp
2009-06-07 07:24 . 2009-06-07 07:24 1350144 —-a-w- c:\windows\Internet Logs\xDBDB.tmp
2009-06-07 07:24 . 2009-06-07 07:24 9728 —-a-w- c:\windows\Internet Logs\xDBDA.tmp
2009-06-07 07:23 . 2009-06-07 07:23 9216 —-a-w- c:\windows\Internet Logs\xDBD8.tmp
2009-06-07 07:23 . 2009-06-07 07:23 1350144 —-a-w- c:\windows\Internet Logs\xDBD9.tmp
2009-06-07 07:22 . 2009-06-07 07:23 9216 —-a-w- c:\windows\Internet Logs\xDBD7.tmp
2009-06-07 07:21 . 2009-06-07 07:21 9728 —-a-w- c:\windows\Internet Logs\xDBD6.tmp
2009-06-07 07:21 . 2009-06-07 07:21 1350144 —-a-w- c:\windows\Internet Logs\xDBD5.tmp
2007-01-19 21:47 . 2007-01-19 21:47 141824 -c–a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-01-27 01:34 . 2009-01-27 01:34 1044480 -c–a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:34 . 2009-01-27 01:34 200704 -c–a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2002-07-31 19:55 . 2008-01-23 20:01 104 –sh–w- c:\windows\WSYS049.SYS
.

((((((((((((((((((((((((((((( SnapShot@2009-06-07_05.13.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-08-15 18:22 . 2009-06-07 07:18 4212 c:\windows\system32\zllictbl.dat
- 2006-08-15 18:22 . 2009-06-07 05:01 4212 c:\windows\system32\zllictbl.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2008-12-04 16:38 3431224 —-a-w- c:\program files\MozyHome\mozyshell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2008-12-04 16:38 3431224 —-a-w- c:\program files\MozyHome\mozyshell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-07-11 160832]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-11-13 981904]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"86:TCP"= 86:TCP:BroadCam Web Server
"89:TCP"= 89:TCP:screenstream 89

R3 gttap1;GoTrusted TAP Adapter;c:\windows\system32\drivers\gttap1.sys [31/08/2007 02:55 20480]
S0 aprb;aprb;c:\windows\system32\drivers\gfpbd.sys –> c:\windows\system32\drivers\gfpbd.sys [?]
S0 bubh;bubh;c:\windows\system32\drivers\tcgwget.sys –> c:\windows\system32\drivers\tcgwget.sys [?]
S0 snIxrb;snIxrb;c:\windows\system32\drivers\cuospx.sys –> c:\windows\system32\drivers\cuospx.sys [?]
S0 xshts;xshts;c:\windows\system32\drivers\jffpc.sys –> c:\windows\system32\drivers\jffpc.sys [?]
S1 mozyFilter;mozyFilter;c:\windows\system32\drivers\mozy.sys [11/12/2008 14:46 53752]
S2 AnonMgmtSvc;Anonymizer Management Service;c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe [17/11/2008 21:58 37560]
S3 dopewars-server;dopewars server;c:\program files\dopewars-1.5.12\dopewars.exe -N –> c:\program files\dopewars-1.5.12\dopewars.exe -N [?]
S3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [15/12/2004 16:18 200192]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-05-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 14:42]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=laptop
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: &Save Flash In This Page by Flash Saver - c:\progra~1\FLASHS~1\save.htm
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\auzstdwt.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\auzstdwt.default\extensions\{22119944-ED35-4ab1-910B-E619EA06A115}\components\rfproxy_27.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\auzstdwt.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07074039.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPEyeCheck.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPGetRt.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPZoneSB.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-07 16:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,57,ba,f2,36,ea,e7,ce,46,ae,24,b6,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,57,ba,f2,36,ea,e7,ce,46,ae,24,b6,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):58,71,9d,d3,fd,f0,16,f5,f5,4b,37,60,13,54,1d,dd,23,4f,fe,c8,41,
e0,43,f9,5f,c8,6b,69,09,3b,18,ea,a6,d4,a1,b3,f1,e3,16,56,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6b3bf1ab-66b0-4c49-83fb-1e2362bfd148}]
@Denied: (Full) (Everyone)
"Model"=dword:00000156
"Therad"=dword:0000001f
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(792)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(1948)
c:\program files\MozyHome\mozyshell.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2009-06-07 16:39
ComboFix-quarantined-files.txt 2009-06-07 15:37
ComboFix2.txt 2009-06-07 05:23

Pre-Run: 14,268,825,600 bytes free
Post-Run: 14,268,026,880 bytes free

Current=4 Default=4 Failed=3 LastKnownGood=5 Sets=1,2,3,4,5
275 — E O F — 2009-05-14 12:24



Here's the fresh HJT log for the old Windows installation:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 03:05:10, on 09/06/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: StatsJunky - {1D417F37-A1EF-4D7B-AFEB-8FC8B2A404F6} - C:\Program Files\StatsJunky\StatsJunkyTool.dll
O3 - Toolbar: SpeedBit - {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - C:\Program Files\SpeedBit Toolbar\Toolbar\SpeedBit.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: &Save Flash In This Page by Flash Saver - C:\PROGRA~1\FLASHS~1\save.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra 'Tools' menuitem: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Send to Mindjet MindManager - {531B9DC0-D8EE-4c76-A6EE-6C1E50569655} - C:\Program Files\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: RapidReader - {C062F84F-428F-42f7-B6A4-73AE08326339} - C:\PROGRA~1\SOFTOL~1\RAPIDR~2\RAPIDR~1.DLL (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=laptop
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Anonymizer Management Service (AnonMgmtSvc) - Anonymizer - C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: dopewars server (dopewars-server) - Unknown owner - C:\Program Files\dopewars-1.5.12\dopewars.exe (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\Shared\hpqwmi.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Unknown owner - C:\Program Files\MozyHome\mozybackup.exe
O23 - Service: PEVSystemStart - Unknown owner - cmd /k start /i "/dC:" "C:\ComboFix\HIDEC.exe" "C:\WINDOWS\system32\CF23342.exe" /c RD /S/Q \$RECYCLE.bin \RECYCLER \RECYCLED (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 8921 bytes






Also… here is a HJT from the new Windows installation, just in case you need it (i hope this new installation isnt infected in any way:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:21:18, on 09/06/2009
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS2\System32\smss.exe
C:\WINDOWS2\system32\winlogon.exe
C:\WINDOWS2\system32\services.exe
C:\WINDOWS2\system32\lsass.exe
C:\WINDOWS2\system32\svchost.exe
C:\WINDOWS2\System32\svchost.exe
C:\WINDOWS2\Explorer.EXE
C:\WINDOWS2\system32\spoolsv.exe
C:\WINDOWS2\System32\ctfmon.exe
C:\WINDOWS2\System32\wpabaln.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS2\System32\wuauclt.exe
C:\DOCUME~1\PaulPaul\LOCALS~1\Temp\GDM18.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS2\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS2\System32\msdxm.ocx
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS2\System32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS2\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS2\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS2\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS2\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS2\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS2\web\related.htm

–
End of file - 1602 bytes
Hi,

I'm sorry to hear things took a turn for the worse. Let's clean up the rest of what I can see. First, please post the content of this log:
C:\QooBox\ComboFix2.txt


From the old Windows:

1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
c:\windows\system32\install.48025.exe
C:\487656.bat
C:\tj.vbs
c:\windows\system32\drivers\gfpbd.sys
c:\windows\system32\drivers\tcgwget.sys
c:\windows\system32\drivers\cuospx.sys
c:\windows\system32\drivers\jffpc.sys

Driver::
aprb
bubh
snIxrb
xshts

RegLockDel::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6b3bf1ab-66b0-4c49-83fb-1e2362bfd148}]
3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt.

The new install looks fairly clean, but we may as well have a look just in case. Please run DDS from the new Windows and post DDS.txt in your next reply.
Hi!


First off… Here's the combofix2.txt from the Qoobox folder:

ComboFix 09-06-05.09 - Paul 07/06/2009 6:05.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.382.71 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\docume~1\Paul\LOCALS~1\Temp\_PASFX845\7Z.DLL
c:\docume~1\Paul\LOCALS~1\Temp\_PASFX913\7Z.DLL
c:\docume~1\Paul\LOCALS~1\Temp\STBRINST\BrowserSet.dll
c:\docume~1\Paul\LOCALS~1\Temp\STBRINST\Speedbit.dll
c:\docume~1\Paul\LOCALS~1\Temp\STBRINST\tbhelper.dll
c:\docume~1\Paul\LOCALS~1\Temp\STBRINST\uninstall.exe
c:\docume~1\Paul\LOCALS~1\Temp\STBRINST\update.exe
c:\docume~1\Paul\LOCALS~1\Temp\VSD563.tmp\DotNetFX35\dotNetFx35setup.exe
c:\docume~1\Paul\LOCALS~1\Temp\VSD563.tmp\setup.exe
c:\docume~1\Paul\LOCALS~1\Temp\VSD696.tmp\DotNetFX\dotnetchk.exe
c:\documents and settings\All Users\Application Data\11047184
c:\documents and settings\All Users\Application Data\11047184\11047184.exe
c:\documents and settings\All Users\Application Data\11047184\11047184.glu
c:\documents and settings\All Users\Application Data\11047184\pc11047184cnf
c:\documents and settings\All Users\Application Data\11047184\pc11047184ins
c:\documents and settings\All Users\Application Data\91057176
c:\documents and settings\All Users\Application Data\91057176\91057176.exe
c:\documents and settings\LocalService\Application Data\twain_32
c:\documents and settings\LocalService\Application Data\twain_32\user.ds
c:\documents and settings\NetworkService\Application Data\twain_32
c:\documents and settings\NetworkService\Application Data\twain_32\user.ds
c:\documents and settings\Paul\Local Settings\Temp\_PASFX845\7Z.DLL
c:\documents and settings\Paul\Local Settings\Temp\_PASFX913\7Z.DLL
c:\documents and settings\Paul\Local Settings\Temp\STBRINST\BrowserSet.dll
c:\documents and settings\Paul\Local Settings\Temp\STBRINST\Speedbit.dll
c:\documents and settings\Paul\Local Settings\Temp\STBRINST\tbhelper.dll
c:\documents and settings\Paul\Local Settings\Temp\STBRINST\uninstall.exe
c:\documents and settings\Paul\Local Settings\Temp\STBRINST\update.exe
c:\documents and settings\Paul\Local Settings\Temp\VSD563.tmp\DotNetFX35\dotNetFx35setup.exe
c:\documents and settings\Paul\Local Settings\Temp\VSD563.tmp\setup.exe
c:\documents and settings\Paul\Local Settings\Temp\VSD696.tmp\DotNetFX\dotnetchk.exe
c:\windows\system32\_000110_.tmp.dll
c:\windows\system32\config\systemprofile\protect.dll
c:\windows\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.lnk
c:\windows\system32\drivers\jclbqkj.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\drivers\ovfsthkkdntxalajagvavmmpflpsyautlwqerp.sys
c:\windows\system32\drivers\TDSSmqct.sys
c:\windows\system32\drivers\TDSSrfdc.sys
c:\windows\system32\Ijl11.dll
c:\windows\system32\ovfsthancjvsqrkutgoekiaqbiotoyheixukfl.dat
c:\windows\system32\ovfsthasantccdhudjbgrhxeogykilcnpwopxp.dll
c:\windows\system32\ovfsthcjnvuxatpwvjgoyomodgunfskdelrura.dat
c:\windows\system32\ovfsthhsfbwmxsaphayvmphttvrayampaksssi.dll
c:\windows\system32\ovfsthnetpsxfddrogxsilpmlvnlpxsgmauiql.dll
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\TDSSarxx.dll
c:\windows\system32\TDSSbeat.dat
c:\windows\system32\TDSScfmm.dll
c:\windows\system32\TDSScuhh.log
c:\windows\system32\TDSSkfkl.dll
c:\windows\system32\TDSSkkai.log
c:\windows\system32\TDSSlxcp.dll
c:\windows\system32\TDSSmtve.dat
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSotub.dll
c:\windows\system32\TDSSovba.dll
c:\windows\system32\TDSSqkhc.dll
c:\windows\system32\TDSSqomd.log
c:\windows\system32\TDSSsahc.dll
c:\windows\system32\TDSSshbr.log
c:\windows\system32\TDSStnyq.dll
c:\windows\system32\TDSSurkv.dll
c:\windows\system32\TDSSvkql.dll
c:\windows\system32\TDSSxhyf.dll
c:\windows\system32\TDSSxnpb.dll
c:\windows\system32\uniq.tll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
C:\xcrashdump.dat
D:\Autorun.inf
D:\Desktop.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_TDSSSERV
——-\Legacy_TDSSSERV
——-\Service_TDSSSERV.SYS
——-\Legacy_TDSSSERV.SYS
——-\Legacy_ASHEVTSVC
——-\Legacy_AVAST!ANTIVIRUS
——-\Legacy_NPF
——-\Service_NPF
——-\Service_ovfsthndwyejkelifrokbsoklostudmykjxyjd


((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 )))))))))))))))))))))))))))))))
.

2009-06-07 00:24 . 2009-06-07 00:24 ——– d-sh–w- C:\found.000
2009-06-04 13:39 . 2009-06-04 13:40 537918 —-a-w- c:\windows\system32\pv_install.exe
2009-06-02 22:11 . 2009-06-02 22:11 ——– d—–w- c:\program files\Trend Micro
2009-06-01 17:28 . 2009-06-01 17:28 ——– d—–w- C:\Market Samurai
2009-05-30 19:37 . 2009-06-02 22:12 111271 —-a-w- c:\windows\system32\install.48025.exe
2009-05-29 00:52 . 2009-05-29 00:52 ——– d—–w- c:\documents and settings\Paul\Application Data\Anonymizer
2009-05-29 00:51 . 2008-11-17 20:58 2759408 —-a-w- c:\documents and settings\All Users\Application Data\{773E7240-B347-4DFF-A6EF-6E829EDD59DF}\Anonymizer_Software.exe
2009-05-29 00:50 . 2009-05-29 00:50 ——– d—–w- c:\program files\Anonymizer
2009-05-29 00:50 . 2009-05-29 00:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Anonymizer
2009-05-29 00:49 . 2009-05-29 00:51 ——– d–h–w- c:\documents and settings\All Users\Application Data\{773E7240-B347-4DFF-A6EF-6E829EDD59DF}
2009-05-26 21:41 . 2009-05-26 21:41 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2009-05-26 20:58 . 2009-05-31 10:47 192 —-a-w- C:\487656.bat
2009-05-26 20:42 . 2009-05-26 03:18 105 —-a-w- C:\tj.vbs
2009-05-18 05:02 . 2009-05-18 05:21 ——– d—–w- c:\program files\PromoSoft
2009-05-18 04:26 . 2009-05-18 04:26 ——– d—–w- c:\documents and settings\Paul\Application Data\PADGen
2009-05-18 04:26 . 2009-05-18 04:26 ——– d—–w- c:\program files\PADGen
2009-05-14 01:23 . 2009-05-14 01:45 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-05-13 04:23 . 2009-03-21 18:40 1310720 —-a-w- c:\windows\system32\ChilkatUpload.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-07 05:15 . 2007-04-27 22:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Kontiki
2009-06-07 05:01 . 2006-08-15 18:22 4212 —ha-w- c:\windows\system32\zllictbl.dat
2009-06-07 04:08 . 2009-06-07 04:08 9728 —-a-w- c:\windows\Internet Logs\xDBC8.tmp
2009-06-07 04:08 . 2009-06-07 04:08 9216 —-a-w- c:\windows\Internet Logs\xDBC7.tmp
2009-06-07 04:08 . 2009-06-07 04:08 9728 —-a-w- c:\windows\Internet Logs\xDBC6.tmp
2009-06-07 04:07 . 2009-06-07 04:08 1350144 —-a-w- c:\windows\Internet Logs\xDBC5.tmp
2009-06-07 04:07 . 2009-06-07 04:07 9728 —-a-w- c:\windows\Internet Logs\xDBC4.tmp
2009-06-07 04:06 . 2009-06-07 04:07 1350144 —-a-w- c:\windows\Internet Logs\xDBC3.tmp
2009-06-07 04:06 . 2009-06-07 04:06 9728 —-a-w- c:\windows\Internet Logs\xDBC2.tmp
2009-06-07 04:05 . 2009-06-07 04:05 1350144 —-a-w- c:\windows\Internet Logs\xDBC1.tmp
2009-06-07 04:04 . 2009-06-07 04:04 1350144 —-a-w- c:\windows\Internet Logs\xDBC0.tmp
2009-06-07 04:04 . 2009-06-07 04:04 9728 —-a-w- c:\windows\Internet Logs\xDBBF.tmp
2009-06-07 04:03 . 2009-06-07 04:03 9728 —-a-w- c:\windows\Internet Logs\xDBBD.tmp
2009-06-07 04:03 . 2009-06-07 04:04 1350144 —-a-w- c:\windows\Internet Logs\xDBBE.tmp
2009-06-07 04:02 . 2009-06-07 04:03 1350144 —-a-w- c:\windows\Internet Logs\xDBBC.tmp
2009-06-07 04:02 . 2009-06-07 04:03 9728 —-a-w- c:\windows\Internet Logs\xDBBB.tmp
2009-06-07 04:01 . 2009-06-07 04:01 9728 —-a-w- c:\windows\Internet Logs\xDBB9.tmp
2009-06-07 04:01 . 2009-06-07 04:01 1350144 —-a-w- c:\windows\Internet Logs\xDBBA.tmp
2009-06-07 03:59 . 2009-06-07 04:00 1350144 —-a-w- c:\windows\Internet Logs\xDBB8.tmp
2009-06-07 03:59 . 2009-06-07 03:59 9216 —-a-w- c:\windows\Internet Logs\xDBB7.tmp
2009-06-07 03:59 . 2009-06-07 03:59 9728 —-a-w- c:\windows\Internet Logs\xDBB6.tmp
2009-06-07 03:59 . 2009-06-07 03:59 1350144 —-a-w- c:\windows\Internet Logs\xDBB5.tmp
2009-06-07 03:59 . 2009-06-07 03:59 9728 —-a-w- c:\windows\Internet Logs\xDBB4.tmp
2009-06-07 03:58 . 2009-06-07 03:58 9728 —-a-w- c:\windows\Internet Logs\xDBB3.tmp
2009-06-07 03:58 . 2009-06-07 03:58 1350144 —-a-w- c:\windows\Internet Logs\xDBB2.tmp
2009-06-07 03:58 . 2009-06-07 03:58 9728 —-a-w- c:\windows\Internet Logs\xDBB1.tmp
2009-06-07 03:56 . 2009-06-07 03:57 9728 —-a-w- c:\windows\Internet Logs\xDBB0.tmp
2009-06-07 03:56 . 2009-06-07 03:56 9216 —-a-w- c:\windows\Internet Logs\xDBAF.tmp
2009-06-07 03:56 . 2009-06-07 03:56 1350144 —-a-w- c:\windows\Internet Logs\xDBAE.tmp
2009-06-07 03:55 . 2009-06-07 03:55 1350144 —-a-w- c:\windows\Internet Logs\xDBAD.tmp
2009-06-07 03:55 . 2009-06-07 03:55 9216 —-a-w- c:\windows\Internet Logs\xDBAC.tmp
2009-06-07 03:54 . 2009-06-07 03:54 1350144 —-a-w- c:\windows\Internet Logs\xDBAB.tmp
2009-06-07 03:52 . 2009-06-07 03:52 1350144 —-a-w- c:\windows\Internet Logs\xDBAA.tmp
2009-06-07 03:52 . 2009-06-07 03:52 10240 —-a-w- c:\windows\Internet Logs\xDBA9.tmp
2009-06-07 03:51 . 2009-06-07 03:51 9728 —-a-w- c:\windows\Internet Logs\xDBA8.tmp
2009-06-07 03:49 . 2009-06-07 03:49 9728 —-a-w- c:\windows\Internet Logs\xDBA7.tmp
2009-06-07 03:48 . 2009-06-07 03:48 9728 —-a-w- c:\windows\Internet Logs\xDBA6.tmp
2009-06-07 03:47 . 2009-06-07 03:47 1350144 —-a-w- c:\windows\Internet Logs\xDBA5.tmp
2009-06-07 03:46 . 2009-06-07 03:47 1350144 —-a-w- c:\windows\Internet Logs\xDBA4.tmp
2009-06-07 03:46 . 2009-06-07 03:46 1350144 —-a-w- c:\windows\Internet Logs\xDBA3.tmp
2009-06-07 03:45 . 2009-06-07 03:46 9216 —-a-w- c:\windows\Internet Logs\xDBA2.tmp
2009-06-07 03:45 . 2009-06-07 03:45 9728 —-a-w- c:\windows\Internet Logs\xDBA1.tmp
2009-06-07 03:44 . 2009-06-07 03:44 9728 —-a-w- c:\windows\Internet Logs\xDBA0.tmp
2009-06-07 03:44 . 2009-06-07 03:44 1350144 —-a-w- c:\windows\Internet Logs\xDB9F.tmp
2009-06-07 03:44 . 2009-06-07 03:44 9216 —-a-w- c:\windows\Internet Logs\xDB9E.tmp
2009-06-07 03:44 . 2009-06-07 03:44 9728 —-a-w- c:\windows\Internet Logs\xDB9D.tmp
2009-06-07 03:43 . 2009-06-07 03:43 9728 —-a-w- c:\windows\Internet Logs\xDB9B.tmp
2009-06-07 03:43 . 2009-06-07 03:44 1350144 —-a-w- c:\windows\Internet Logs\xDB9C.tmp
2009-06-07 03:43 . 2009-06-07 03:43 9216 —-a-w- c:\windows\Internet Logs\xDB9A.tmp
2009-06-07 03:42 . 2009-06-07 03:42 1350144 —-a-w- c:\windows\Internet Logs\xDB99.tmp
2009-06-07 03:42 . 2009-06-07 03:42 9216 —-a-w- c:\windows\Internet Logs\xDB98.tmp
2009-06-07 03:42 . 2009-06-07 03:42 1350144 —-a-w- c:\windows\Internet Logs\xDB97.tmp
2009-06-07 03:41 . 2009-06-07 03:41 9728 —-a-w- c:\windows\Internet Logs\xDB95.tmp
2009-06-07 03:41 . 2009-06-07 03:41 1350144 —-a-w- c:\windows\Internet Logs\xDB96.tmp
2009-06-07 03:41 . 2009-06-07 03:41 9728 —-a-w- c:\windows\Internet Logs\xDB94.tmp
2009-06-07 03:40 . 2009-06-07 03:40 1350144 —-a-w- c:\windows\Internet Logs\xDB93.tmp
2009-06-07 03:40 . 2009-06-07 03:40 9728 —-a-w- c:\windows\Internet Logs\xDB92.tmp
2009-06-07 03:40 . 2009-06-07 03:40 9728 —-a-w- c:\windows\Internet Logs\xDB91.tmp
2009-06-07 03:39 . 2009-06-07 03:39 9728 —-a-w- c:\windows\Internet Logs\xDB8F.tmp
2009-06-07 03:39 . 2009-06-07 03:39 1350144 —-a-w- c:\windows\Internet Logs\xDB90.tmp
2009-06-07 03:38 . 2009-06-07 03:39 1350144 —-a-w- c:\windows\Internet Logs\xDB8E.tmp
2009-06-07 03:38 . 2009-06-07 03:38 9728 —-a-w- c:\windows\Internet Logs\xDB8D.tmp
2009-06-07 03:38 . 2009-06-07 03:38 9216 —-a-w- c:\windows\Internet Logs\xDB8C.tmp
2009-06-07 03:37 . 2009-06-07 03:38 9216 —-a-w- c:\windows\Internet Logs\xDB8B.tmp
2009-06-07 03:37 . 2009-06-07 03:37 9728 —-a-w- c:\windows\Internet Logs\xDB8A.tmp
2009-06-07 03:37 . 2009-06-07 03:37 1350144 —-a-w- c:\windows\Internet Logs\xDB89.tmp
2009-06-07 03:35 . 2009-06-07 03:35 9216 —-a-w- c:\windows\Internet Logs\xDB88.tmp
2009-06-07 03:35 . 2009-06-07 03:35 9728 —-a-w- c:\windows\Internet Logs\xDB86.tmp
2009-06-07 03:35 . 2009-06-07 03:35 1350144 —-a-w- c:\windows\Internet Logs\xDB87.tmp
2009-06-07 03:33 . 2009-06-07 03:33 1350144 —-a-w- c:\windows\Internet Logs\xDB85.tmp
2009-06-07 03:32 . 2009-06-07 03:32 9728 —-a-w- c:\windows\Internet Logs\xDB84.tmp
2009-06-07 03:32 . 2009-06-07 03:32 1350144 —-a-w- c:\windows\Internet Logs\xDB83.tmp
2009-06-07 03:31 . 2009-06-07 03:32 10752 —-a-w- c:\windows\Internet Logs\xDB81.tmp
2009-06-07 03:31 . 2009-06-07 03:32 1350144 —-a-w- c:\windows\Internet Logs\xDB82.tmp
2009-06-07 03:20 . 2009-06-07 03:29 1350144 —-a-w- c:\windows\Internet Logs\xDB80.tmp
2009-06-07 02:30 . 2009-06-07 03:20 1350656 —-a-w- c:\windows\Internet Logs\xDB7F.tmp
2009-06-07 02:30 . 2009-06-07 03:20 10752 —-a-w- c:\windows\Internet Logs\xDB7E.tmp
2009-06-07 02:28 . 2009-06-07 02:30 1350144 —-a-w- c:\windows\Internet Logs\xDB7D.tmp
2009-06-07 02:27 . 2009-06-07 02:27 1350144 —-a-w- c:\windows\Internet Logs\xDB7C.tmp
2009-06-07 02:27 . 2009-06-07 02:27 1350144 —-a-w- c:\windows\Internet Logs\xDB7B.tmp
2009-06-07 01:38 . 2009-06-07 01:38 9728 —-a-w- c:\windows\Internet Logs\xDB79.tmp
2009-06-07 01:38 . 2009-06-07 01:39 1350144 —-a-w- c:\windows\Internet Logs\xDB7A.tmp
2009-06-07 01:37 . 2009-06-07 01:37 9216 —-a-w- c:\windows\Internet Logs\xDB78.tmp
2009-06-07 01:36 . 2009-06-07 01:36 1350144 —-a-w- c:\windows\Internet Logs\xDB77.tmp
2009-06-07 01:36 . 2009-06-07 01:36 9728 —-a-w- c:\windows\Internet Logs\xDB76.tmp
2009-06-07 01:35 . 2009-06-07 01:35 1350144 —-a-w- c:\windows\Internet Logs\xDB75.tmp
2009-06-07 01:35 . 2009-06-07 01:35 9728 —-a-w- c:\windows\Internet Logs\xDB74.tmp
2009-06-07 01:35 . 2009-06-07 01:35 1350144 —-a-w- c:\windows\Internet Logs\xDB73.tmp
2009-06-07 01:35 . 2009-06-07 01:35 9728 —-a-w- c:\windows\Internet Logs\xDB72.tmp
2009-06-07 01:33 . 2009-06-07 01:34 1350144 —-a-w- c:\windows\Internet Logs\xDB71.tmp
2009-06-07 01:33 . 2009-06-07 01:33 9728 —-a-w- c:\windows\Internet Logs\xDB70.tmp
2009-06-07 01:32 . 2009-06-07 01:32 10240 —-a-w- c:\windows\Internet Logs\xDB61.tmp
2009-06-07 01:22 . 2006-12-03 23:24 38568587 -c–a-w- c:\windows\Internet Logs\tvDebug.zip
2009-06-07 01:20 . 2009-06-07 01:22 9216 —-a-w- c:\windows\Internet Logs\xDB60.tmp
2009-06-07 01:20 . 2009-06-07 01:20 9216 —-a-w- c:\windows\Internet Logs\xDB6F.tmp
2009-06-07 01:20 . 2009-06-07 01:20 1350144 —-a-w- c:\windows\Internet Logs\xDB6E.tmp
2009-06-07 01:20 . 2009-06-07 01:20 9728 —-a-w- c:\windows\Internet Logs\xDB6D.tmp
2009-06-07 01:20 . 2009-06-07 01:20 9728 —-a-w- c:\windows\Internet Logs\xDB6B.tmp
2009-06-07 01:19 . 2009-06-07 01:20 1350144 —-a-w- c:\windows\Internet Logs\xDB6C.tmp
2009-06-07 01:17 . 2009-06-07 01:18 9728 —-a-w- c:\windows\Internet Logs\xDB69.tmp
2007-01-19 21:47 . 2007-01-19 21:47 141824 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-01-27 01:34 . 2009-01-27 01:34 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:34 . 2009-01-27 01:34 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2002-07-31 19:55 . 2008-01-23 20:01 104 –sh–w- c:\windows\WSYS049.SYS
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2008-12-04 16:38 3431224 —-a-w- c:\program files\MozyHome\mozyshell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2008-12-04 16:38 3431224 —-a-w- c:\program files\MozyHome\mozyshell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2007-07-11 160832]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Anonymizer"="c:\program files\Anonymizer\Anonymizer Software\Anonymizer.exe" [2008-11-17 1557176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-11-13 981904]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-25 180269]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"86:TCP"= 86:TCP:BroadCam Web Server
"89:TCP"= 89:TCP:screenstream 89

R1 mozyFilter;mozyFilter;c:\windows\system32\drivers\mozy.sys [11/12/2008 14:46 53752]
R2 AnonMgmtSvc;Anonymizer Management Service;c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe [17/11/2008 21:58 37560]
R3 gttap1;GoTrusted TAP Adapter;c:\windows\system32\drivers\gttap1.sys [31/08/2007 02:55 20480]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [15/12/2004 16:18 200192]
S0 aprb;aprb;c:\windows\system32\drivers\gfpbd.sys –> c:\windows\system32\drivers\gfpbd.sys [?]
S0 snIxrb;snIxrb;c:\windows\system32\drivers\cuospx.sys –> c:\windows\system32\drivers\cuospx.sys [?]
S0 xshts;xshts;c:\windows\system32\drivers\jffpc.sys –> c:\windows\system32\drivers\jffpc.sys [?]
S3 dopewars-server;dopewars server;c:\program files\dopewars-1.5.12\dopewars.exe -N –> c:\program files\dopewars-1.5.12\dopewars.exe -N [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-05-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 14:42]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-11047184 - c:\documents and settings\All Users\Application Data\11047184\11047184.exe
HKLM-Run-91057176 - c:\documents and settings\All Users\Application Data\91057176\91057176.exe
HKU-Default-Run-brastk - c:\windows\system32\brastk.exe
HKU-Default-Run-autochk - c:\windows\system32\config\SYSTEM~1\protect.dll
SafeBoot-procexp90.Sys
SafeBoot-TDSSmqct.sys


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=laptop
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: &Save Flash In This Page by Flash Saver - c:\progra~1\FLASHS~1\save.htm
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\auzstdwt.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\auzstdwt.default\extensions\{22119944-ED35-4ab1-910B-E619EA06A115}\components\rfproxy_27.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\auzstdwt.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07074039.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPEyeCheck.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPGetRt.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPZoneSB.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-07 06:13
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,57,ba,f2,36,ea,e7,ce,46,ae,24,b6,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,57,ba,f2,36,ea,e7,ce,46,ae,24,b6,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):58,71,9d,d3,fd,f0,16,f5,f5,4b,37,60,13,54,1d,dd,23,4f,fe,c8,41,
e0,43,f9,5f,c8,6b,69,09,3b,18,ea,a6,d4,a1,b3,f1,e3,16,56,00,00,00,00,00,00,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6b3bf1ab-66b0-4c49-83fb-1e2362bfd148}]
@Denied: (Full) (Everyone)
"Model"=dword:00000156
"Therad"=dword:0000001f
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(852)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3324)
c:\program files\MozyHome\mozyshell.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-06-07 6:23
ComboFix-quarantined-files.txt 2009-06-07 05:21

Pre-Run: 3,633,680,384 bytes free
Post-Run: 3,622,735,872 bytes free

Current=4 Default=4 Failed=3 LastKnownGood=5 Sets=1,2,3,4,5
372 — E O F — 2009-05-14 12:24




Secondly, here is the new combofix log I got from running those special notepad commands with combofix:

ComboFix 09-06-05.09 - Paul 10/06/2009 0:28.3 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\DESKTOP FOLDER\ComboFix.exe
Command switches used :: C:\CFScript.txt
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

FILE ::
"C:\487656.bat"
"C:\tj.vbs"
"c:\windows\system32\drivers\cuospx.sys"
"c:\windows\system32\drivers\gfpbd.sys"
"c:\windows\system32\drivers\jffpc.sys"
"c:\windows\system32\drivers\tcgwget.sys"
"c:\windows\system32\install.48025.exe"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\487656.bat
C:\tj.vbs
c:\windows\system32\install.48025.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_aprb
——-\Service_bubh
——-\Service_snIxrb
——-\Service_xshts


((((((((((((((((((((((((( Files Created from 2009-05-10 to 2009-06-10 )))))))))))))))))))))))))))))))
.

2009-06-09 05:54 . 2009-06-09 05:55 ——– dc—-w- c:\program files\DivX2
2009-06-09 05:19 . 2009-06-09 10:24 ——– dc—-w- c:\program files\SENuke2
2009-06-09 05:06 . 2009-06-09 05:06 ——– dc—-w- c:\program files\WinRAR2
2009-06-09 00:53 . 2009-06-09 00:53 ——– dc—-w- c:\program files\Broadcom
2009-06-08 05:17 . 2009-06-08 04:31 ——– dc-h–w- c:\documents and settings\Default User.WINDOWS2
2009-06-08 05:17 . 2009-06-08 04:29 ——– dc—-w- c:\documents and settings\All Users.WINDOWS2
2009-06-08 04:38 . 2009-06-09 01:00 ——– dc—-w- c:\documents and settings\PaulPaul
2009-06-08 04:36 . 2009-06-08 04:36 ——– dcsh–w- c:\documents and settings\LocalService.NT AUTHORITY
2009-06-08 04:36 . 2009-06-08 04:36 ——– dcsh–w- c:\documents and settings\NetworkService.NT AUTHORITY
2009-06-08 03:03 . 2009-06-09 23:58 ——– dc—-w- C:\WINDOWS2
2009-06-07 22:54 . 2009-06-07 22:54 ——– dc—-w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-06-07 00:24 . 2009-06-07 00:24 ——– d-sh–w- C:\found.000
2009-06-04 13:39 . 2009-06-04 13:40 537918 —-a-w- c:\windows\system32\pv_install.exe
2009-06-02 22:11 . 2009-06-02 22:11 ——– dc—-w- c:\program files\Trend Micro
2009-06-01 17:28 . 2009-06-01 17:28 ——– d—–w- C:\Market Samurai
2009-05-29 00:52 . 2009-05-29 00:52 ——– d—–w- c:\documents and settings\Paul\Application Data\Anonymizer
2009-05-29 00:51 . 2008-11-17 20:58 2759408 —-a-w- c:\documents and settings\All Users\Application Data\{773E7240-B347-4DFF-A6EF-6E829EDD59DF}\Anonymizer_Software.exe
2009-05-29 00:50 . 2009-05-29 00:50 ——– dc—-w- c:\program files\Anonymizer
2009-05-29 00:50 . 2009-05-29 00:50 ——– dc—-w- c:\documents and settings\All Users\Application Data\Anonymizer
2009-05-29 00:49 . 2009-05-29 00:51 ——– d–h–w- c:\documents and settings\All Users\Application Data\{773E7240-B347-4DFF-A6EF-6E829EDD59DF}
2009-05-26 21:41 . 2009-05-26 21:41 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2009-05-18 05:02 . 2009-05-18 05:21 ——– dc—-w- c:\program files\PromoSoft
2009-05-18 04:26 . 2009-05-18 04:26 ——– d—–w- c:\documents and settings\Paul\Application Data\PADGen
2009-05-18 04:26 . 2009-05-18 04:26 ——– dc—-w- c:\program files\PADGen
2009-05-14 01:23 . 2009-06-08 03:28 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-05-13 04:23 . 2009-03-21 18:40 1310720 —-a-w- c:\windows\system32\ChilkatUpload.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-10 00:18 . 2007-04-27 22:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Kontiki
2009-06-10 00:14 . 2009-06-10 00:14 1350144 —-a-w- c:\windows\Internet Logs\xDB1F2.tmp
2009-06-10 00:12 . 2006-08-15 18:22 4212 —ha-w- c:\windows\system32\zllictbl.dat
2009-06-09 23:56 . 2009-06-10 00:02 1350144 —-a-w- c:\windows\Internet Logs\xDB1F0.tmp
2009-06-09 23:56 . 2009-06-09 23:56 1350144 —-a-w- c:\windows\Internet Logs\xDB1EF.tmp
2009-06-09 23:55 . 2009-06-09 23:55 1350144 —-a-w- c:\windows\Internet Logs\xDB1EE.tmp
2009-06-09 23:54 . 2009-06-09 23:54 1350144 —-a-w- c:\windows\Internet Logs\xDB1ED.tmp
2009-06-09 23:52 . 2009-06-09 23:52 1350144 —-a-w- c:\windows\Internet Logs\xDB1EC.tmp
2009-06-09 23:52 . 2009-06-09 23:52 1350144 —-a-w- c:\windows\Internet Logs\xDB1EB.tmp
2009-06-09 23:51 . 2009-06-09 23:51 1350144 —-a-w- c:\windows\Internet Logs\xDB1EA.tmp
2009-06-09 23:50 . 2009-06-09 23:50 1350144 —-a-w- c:\windows\Internet Logs\xDB1E9.tmp
2009-06-09 23:50 . 2009-06-09 23:50 1350144 —-a-w- c:\windows\Internet Logs\xDB1E8.tmp
2009-06-09 23:49 . 2009-06-09 23:49 1350144 —-a-w- c:\windows\Internet Logs\xDB1E7.tmp
2009-06-09 23:48 . 2009-06-09 23:48 1350144 —-a-w- c:\windows\Internet Logs\xDB1E6.tmp
2009-06-09 23:48 . 2009-06-09 23:48 1350144 —-a-w- c:\windows\Internet Logs\xDB1E5.tmp
2009-06-09 23:47 . 2009-06-09 23:47 1350144 —-a-w- c:\windows\Internet Logs\xDB1E4.tmp
2009-06-09 23:46 . 2009-06-09 23:46 1350144 —-a-w- c:\windows\Internet Logs\xDB1E3.tmp
2009-06-09 23:45 . 2009-06-09 23:45 1350144 —-a-w- c:\windows\Internet Logs\xDB1E2.tmp
2009-06-09 23:41 . 2009-06-09 23:42 1350144 —-a-w- c:\windows\Internet Logs\xDB1E1.tmp
2009-06-09 23:40 . 2009-06-09 23:41 1350144 —-a-w- c:\windows\Internet Logs\xDB1E0.tmp
2009-06-09 23:40 . 2009-06-09 23:40 1350144 —-a-w- c:\windows\Internet Logs\xDB1DF.tmp
2009-06-09 23:37 . 2009-06-09 23:38 1350144 —-a-w- c:\windows\Internet Logs\xDB1DE.tmp
2009-06-09 23:37 . 2009-06-09 23:37 1350144 —-a-w- c:\windows\Internet Logs\xDB1DD.tmp
2009-06-09 23:35 . 2009-06-09 23:35 1350144 —-a-w- c:\windows\Internet Logs\xDB1DC.tmp
2009-06-09 23:33 . 2009-06-09 23:33 1350144 —-a-w- c:\windows\Internet Logs\xDB1DB.tmp
2009-06-09 23:31 . 2009-06-09 23:31 1350144 —-a-w- c:\windows\Internet Logs\xDB1DA.tmp
2009-06-09 23:30 . 2009-06-09 23:30 1350144 —-a-w- c:\windows\Internet Logs\xDB1D9.tmp
2009-06-09 23:28 . 2009-06-09 23:29 1350144 —-a-w- c:\windows\Internet Logs\xDB1D8.tmp
2009-06-09 23:27 . 2009-06-09 23:27 1350144 —-a-w- c:\windows\Internet Logs\xDB1D7.tmp
2009-06-09 23:26 . 2009-06-09 23:27 1350144 —-a-w- c:\windows\Internet Logs\xDB1D6.tmp
2009-06-09 23:26 . 2009-06-09 23:26 1350144 —-a-w- c:\windows\Internet Logs\xDB1D5.tmp
2009-06-09 23:25 . 2009-06-09 23:25 1350144 —-a-w- c:\windows\Internet Logs\xDB1D4.tmp
2009-06-09 23:25 . 2009-06-09 23:25 1350144 —-a-w- c:\windows\Internet Logs\xDB1D3.tmp
2009-06-09 23:23 . 2009-06-09 23:23 1350144 —-a-w- c:\windows\Internet Logs\xDB1D2.tmp
2009-06-09 23:23 . 2009-06-09 23:23 1350144 —-a-w- c:\windows\Internet Logs\xDB1D1.tmp
2009-06-09 23:21 . 2009-06-09 23:22 1350656 —-a-w- c:\windows\Internet Logs\xDB1D0.tmp
2009-06-09 23:20 . 2009-06-09 23:21 1350144 —-a-w- c:\windows\Internet Logs\xDB1CF.tmp
2009-06-09 23:18 . 2009-06-09 23:19 1350144 —-a-w- c:\windows\Internet Logs\xDB1CE.tmp
2009-06-09 23:18 . 2009-06-09 23:18 1350144 —-a-w- c:\windows\Internet Logs\xDB1CD.tmp
2009-06-09 23:18 . 2009-06-09 23:18 1350144 —-a-w- c:\windows\Internet Logs\xDB1CC.tmp
2009-06-09 23:17 . 2009-06-09 23:17 1350144 —-a-w- c:\windows\Internet Logs\xDB1CB.tmp
2009-06-09 23:16 . 2009-06-09 23:16 1350144 —-a-w- c:\windows\Internet Logs\xDB1CA.tmp
2009-06-09 23:13 . 2009-06-09 23:13 1350144 —-a-w- c:\windows\Internet Logs\xDB1C9.tmp
2009-06-09 23:12 . 2009-06-09 23:13 1350144 —-a-w- c:\windows\Internet Logs\xDB1C8.tmp
2009-06-09 23:12 . 2009-06-09 23:12 1350144 —-a-w- c:\windows\Internet Logs\xDB1C7.tmp
2009-06-09 23:10 . 2009-06-09 23:10 1350144 —-a-w- c:\windows\Internet Logs\xDB1C6.tmp
2009-06-09 23:09 . 2009-06-09 23:09 1350144 —-a-w- c:\windows\Internet Logs\xDB1C5.tmp
2009-06-09 23:08 . 2009-06-09 23:08 1350144 —-a-w- c:\windows\Internet Logs\xDB1C4.tmp
2009-06-09 23:07 . 2009-06-09 23:07 1350144 —-a-w- c:\windows\Internet Logs\xDB1C3.tmp
2009-06-09 23:06 . 2009-06-09 23:06 1350144 —-a-w- c:\windows\Internet Logs\xDB1C2.tmp
2009-06-09 23:03 . 2009-06-09 23:03 1350144 —-a-w- c:\windows\Internet Logs\xDB1C1.tmp
2009-06-09 22:57 . 2009-06-09 22:57 1350144 —-a-w- c:\windows\Internet Logs\xDB1C0.tmp
2009-06-09 22:54 . 2009-06-09 22:54 1350144 —-a-w- c:\windows\Internet Logs\xDB1BF.tmp
2009-06-09 22:52 . 2009-06-09 22:53 1350144 —-a-w- c:\windows\Internet Logs\xDB1BE.tmp
2009-06-09 05:54 . 2009-03-15 00:53 ——– dc—-w- c:\program files\Common Files\DivX Shared
2009-06-09 05:51 . 2006-11-28 13:50 ——– dc—-w- c:\program files\GetRight
2009-06-09 05:14 . 2006-04-20 05:02 ——– dc—-w- c:\program files\ATI Technologies
2009-06-09 05:14 . 2006-04-20 05:02 ——– dc-h–w- c:\program files\InstallShield Installation Information
2009-06-09 02:09 . 2009-06-09 02:09 1350144 —-a-w- c:\windows\Internet Logs\xDB1BD.tmp
2009-06-09 02:08 . 2009-06-09 02:08 1350144 —-a-w- c:\windows\Internet Logs\xDB1BC.tmp
2009-06-09 02:06 . 2009-06-09 02:07 1350144 —-a-w- c:\windows\Internet Logs\xDB1BB.tmp
2009-06-09 02:05 . 2009-06-09 02:05 1350144 —-a-w- c:\windows\Internet Logs\xDB1BA.tmp
2009-06-09 02:03 . 2009-06-09 02:03 1350144 —-a-w- c:\windows\Internet Logs\xDB1B9.tmp
2009-06-09 02:02 . 2009-06-09 02:03 1350144 —-a-w- c:\windows\Internet Logs\xDB1B8.tmp
2009-06-09 02:02 . 2009-06-09 02:02 1350144 —-a-w- c:\windows\Internet Logs\xDB1B7.tmp
2009-06-09 02:01 . 2009-06-09 02:01 1350144 —-a-w- c:\windows\Internet Logs\xDB1B6.tmp
2009-06-09 01:56 . 2009-06-09 01:56 1350144 —-a-w- c:\windows\Internet Logs\xDB1B5.tmp
2009-06-09 01:53 . 2009-06-09 01:53 1350144 —-a-w- c:\windows\Internet Logs\xDB1B4.tmp
2009-06-09 01:51 . 2009-06-09 01:52 1350144 —-a-w- c:\windows\Internet Logs\xDB1B3.tmp
2009-06-09 01:50 . 2009-06-09 01:51 1350144 —-a-w- c:\windows\Internet Logs\xDB1B2.tmp
2009-06-09 01:48 . 2009-06-09 01:49 1350144 —-a-w- c:\windows\Internet Logs\xDB1B1.tmp
2009-06-09 01:47 . 2009-06-09 01:48 1350144 —-a-w- c:\windows\Internet Logs\xDB1B0.tmp
2009-06-09 01:46 . 2009-06-09 01:47 1350144 —-a-w- c:\windows\Internet Logs\xDB1AF.tmp
2009-06-09 01:39 . 2009-06-09 01:40 1350656 —-a-w- c:\windows\Internet Logs\xDB1AE.tmp
2009-06-09 00:33 . 2009-06-09 00:34 1350144 —-a-w- c:\windows\Internet Logs\xDB1AD.tmp
2009-06-09 00:26 . 2009-06-09 00:26 1350144 —-a-w- c:\windows\Internet Logs\xDB1AC.tmp
2009-06-09 00:23 . 2009-06-09 00:23 1350144 —-a-w- c:\windows\Internet Logs\xDB1AB.tmp
2009-06-09 00:21 . 2009-06-09 00:22 1350144 —-a-w- c:\windows\Internet Logs\xDB1AA.tmp
2009-06-08 03:04 . 2009-06-09 00:09 1350144 —-a-w- c:\windows\Internet Logs\xDB1A9.tmp
2009-06-08 00:11 . 2009-06-08 03:04 1350144 —-a-w- c:\windows\Internet Logs\xDB1A8.tmp
2009-06-07 23:31 . 2009-06-07 23:32 1350144 —-a-w- c:\windows\Internet Logs\xDB1A7.tmp
2009-06-07 23:30 . 2009-06-07 23:31 1350144 —-a-w- c:\windows\Internet Logs\xDB1A6.tmp
2009-06-07 23:27 . 2009-06-07 23:27 1350144 —-a-w- c:\windows\Internet Logs\xDB1A5.tmp
2009-06-07 23:26 . 2009-06-07 23:26 1350144 —-a-w- c:\windows\Internet Logs\xDB1A4.tmp
2009-06-07 23:25 . 2009-06-07 23:26 1350144 —-a-w- c:\windows\Internet Logs\xDB1A3.tmp
2009-06-07 23:23 . 2009-06-07 23:23 1350144 —-a-w- c:\windows\Internet Logs\xDB1A2.tmp
2009-06-07 23:22 . 2009-06-07 23:22 1350144 —-a-w- c:\windows\Internet Logs\xDB1A1.tmp
2009-06-07 23:21 . 2009-06-07 23:22 1350144 —-a-w- c:\windows\Internet Logs\xDB1A0.tmp
2009-06-07 23:21 . 2009-06-07 23:21 1350144 —-a-w- c:\windows\Internet Logs\xDB19F.tmp
2009-06-07 23:21 . 2009-06-07 23:21 1350144 —-a-w- c:\windows\Internet Logs\xDB19E.tmp
2009-06-07 23:10 . 2009-06-07 23:20 1350144 —-a-w- c:\windows\Internet Logs\xDB19D.tmp
2009-06-07 22:46 . 2009-06-07 23:10 1350144 —-a-w- c:\windows\Internet Logs\xDB199.tmp
2009-06-07 22:33 . 2009-06-07 22:33 1350144 —-a-w- c:\windows\Internet Logs\xDB19C.tmp
2009-06-07 22:31 . 2009-06-07 22:31 1350144 —-a-w- c:\windows\Internet Logs\xDB19B.tmp
2009-06-07 22:30 . 2009-06-07 22:31 1350144 —-a-w- c:\windows\Internet Logs\xDB19A.tmp
2009-06-07 22:25 . 2009-06-07 22:25 1350144 —-a-w- c:\windows\Internet Logs\xDB198.tmp
2009-06-07 22:24 . 2009-06-07 22:24 1350144 —-a-w- c:\windows\Internet Logs\xDB197.tmp
2009-06-07 22:18 . 2009-06-07 22:18 1350144 —-a-w- c:\windows\Internet Logs\xDB196.tmp
2009-06-07 22:16 . 2006-12-03 23:24 1219651 —-a-w- c:\windows\Internet Logs\tvDebug.Zip
2009-06-07 22:15 . 2009-06-07 22:16 1350144 —-a-w- c:\windows\Internet Logs\xDB195.tmp
2007-01-19 21:47 . 2007-01-19 21:47 141824 -c–a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-01-27 01:34 . 2009-01-27 01:34 1044480 -c–a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:34 . 2009-01-27 01:34 200704 -c–a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2002-07-31 19:55 . 2008-01-23 20:01 104 –sh–w- c:\windows\WSYS049.SYS
.

((((((((((((((((((((((((((((( SnapShot@2009-06-07_05.13.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-09 22:49 . 2009-06-09 22:49 16384 c:\windows\temp\Perflib_Perfdata_7c8.dat
+ 2009-06-09 22:49 . 2009-06-09 22:49 16384 c:\windows\temp\Perflib_Perfdata_6a4.dat
+ 2009-06-10 00:08 . 2009-06-10 00:08 16384 c:\windows\temp\Perflib_Perfdata_228.dat
+ 2009-06-10 00:08 . 2009-06-10 00:08 16384 c:\windows\temp\Perflib_Perfdata_17c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2008-12-04 16:38 3431224 —-a-w- c:\program files\MozyHome\mozyshell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2008-12-04 16:38 3431224 —-a-w- c:\program files\MozyHome\mozyshell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-06-09 160592]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-11-13 981904]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2006-10-26 434528]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"c:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"86:TCP"= 86:TCP:BroadCam Web Server
"89:TCP"= 89:TCP:screenstream 89

R3 dopewars-server;dopewars server;c:\program files\dopewars-1.5.12\dopewars.exe [x]
S1 mozyFilter;mozyFilter;c:\windows\system32\DRIVERS\mozy.sys [2008-12-04 53752]
S3 gttap1;GoTrusted TAP Adapter;c:\windows\system32\DRIVERS\gttap1.sys [2007-08-31 20480]
S3 HSFHWATI;HSFHWATI;c:\windows\system32\DRIVERS\HSFHWATI.sys [2004-12-15 200192]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-05-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 14:42]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=laptop
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: &Save Flash In This Page by Flash Saver - c:\progra~1\FLASHS~1\save.htm
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\auzstdwt.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\auzstdwt.default\extensions\{22119944-ED35-4ab1-910B-E619EA06A115}\components\rfproxy_27.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\auzstdwt.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp07074039.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPEyeCheck.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPGetRt.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPZoneSB.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-10 01:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,57,ba,f2,36,ea,e7,ce,46,ae,24,b6,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,57,ba,f2,36,ea,e7,ce,46,ae,24,b6,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(860)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(1520)
c:\program files\MozyHome\mozyshell.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
c:\program files\Kontiki\KService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\MozyHome\mozybackup.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-06-10 1:48 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-10 00:46
ComboFix2.txt 2009-06-07 15:39
ComboFix3.txt 2009-06-07 05:23

Pre-Run: 12,769,103,872 bytes free
Post-Run: 12,894,691,328 bytes free

Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
312 — E O F — 2009-05-14 12:24



Thirdly, here is a fresh HJT log for the old, infected version of Windows (just in case you need it):

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:03:11, on 10/06/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\MozyHome\mozybackup.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi…fo/bt_side.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi…arch.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: StatsJunky - {1D417F37-A1EF-4D7B-AFEB-8FC8B2A404F6} - C:\Program Files\StatsJunky\StatsJunkyTool.dll
O3 - Toolbar: SpeedBit - {EBFCD017-BCAD-42C3-9ED5-89DBDFC59171} - C:\Program Files\SpeedBit Toolbar\Toolbar\SpeedBit.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: &Save Flash In This Page by Flash Saver - C:\PROGRA~1\FLASHS~1\save.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra 'Tools' menuitem: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Send to Mindjet MindManager - {531B9DC0-D8EE-4c76-A6EE-6C1E50569655} - C:\Program Files\Mindjet\MindManager 6\Mm6InternetExplorer.dll
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: RapidReader - {C062F84F-428F-42f7-B6A4-73AE08326339} - C:\PROGRA~1\SOFTOL~1\RAPIDR~2\RAPIDR~1.DLL (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=laptop
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Anonymizer Management Service (AnonMgmtSvc) - Anonymizer - C:\Program Files\Anonymizer\Anonymizer Software\Common\AnonMgmtSvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: dopewars server (dopewars-server) - Unknown owner - C:\Program Files\dopewars-1.5.12\dopewars.exe (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\Shared\hpqwmi.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: KService - Unknown owner - C:\Program Files\Kontiki\KService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Unknown owner - C:\Program Files\MozyHome\mozybackup.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 8691 bytes



Fourthly, here is the DDS file for the new, (hopefully) clean version of Windows:


DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 2:16:46.21 on 10/06/2009
Internet Explorer: 6.0.2800.1106
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.382.113 [GMT 1:00]


============== Running Processes ===============

C:\WINDOWS2\System32\Ati2evxx.exe
C:\WINDOWS2\system32\svchost -k rpcss
C:\WINDOWS2\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS2\system32\spoolsv.exe
C:\WINDOWS2\system32\Ati2evxx.exe
C:\WINDOWS2\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS2\System32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\WINDOWS2\System32\wuauclt.exe
C:\WINDOWS2\System32\wpabaln.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS2\system32\NOTEPAD.EXE
C:\Documents and Settings\PaulPaul\Desktop\dds.scr

============== Pseudo HJT Report ===============

BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\System32\browseui.dll
uRun: [CTFMON.EXE] c:\windows2\system32\ctfmon.exe
uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
dRun: [CTFMON.EXE] c:\windows2\system32\CTFMON.EXE
IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
DPF: DirectAnimation Java Classes - file://c:\windows2\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows2\java\classes\xmldso.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll

============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2009-06-09 06:54 -cd—– c:\program files\DivX2
2009-06-09 06:37 25 ac—— c:\windows2\cdplayer.ini
2009-06-09 06:34 499,712 ac—— c:\windows2\system32\msvcp71.dll
2009-06-09 06:34 348,160 ac—— c:\windows2\system32\msvcr71.dll
2009-06-09 06:19 -cd—– c:\program files\SENuke2
2009-06-09 06:13 134,272 ac—— c:\windows2\system32\drivers\portcls.sys
2009-06-09 06:13 134,272 ac—— c:\windows2\system32\dllcache\portcls.sys
2009-06-09 06:13 131,712 ac—— c:\windows2\system32\drivers\ks.sys
2009-06-09 06:13 131,712 ac—— c:\windows2\system32\dllcache\ks.sys
2009-06-09 06:13 57,856 ac—— c:\windows2\system32\drivers\drmk.sys
2009-06-09 06:13 57,856 ac—— c:\windows2\system32\dllcache\drmk.sys
2009-06-09 06:13 44,416 ac—— c:\windows2\system32\drivers\stream.sys
2009-06-09 06:13 44,416 ac—— c:\windows2\system32\dllcache\stream.sys
2009-06-09 06:13 117,248 ac—— c:\windows2\system32\ksproxy.ax
2009-06-09 06:13 117,248 ac—— c:\windows2\system32\dllcache\ksproxy.ax
2009-06-09 06:13 4,096 ac—— c:\windows2\system32\ksuser.dll
2009-06-09 06:13 4,096 ac—— c:\windows2\system32\dllcache\ksuser.dll
2009-06-09 06:12 59 ac—— c:\windows2\WININIT.INI
2009-06-09 06:11 5,888 ac—— c:\windows2\system32\drivers\splitter.sys
2009-06-09 06:11 5,888 ac—— c:\windows2\system32\dllcache\splitter.sys
2009-06-09 06:11 77,440 ac—— c:\windows2\system32\drivers\wdmaud.sys
2009-06-09 06:11 77,440 ac—— c:\windows2\system32\dllcache\wdmaud.sys
2009-06-09 06:06 -cd—– c:\program files\WinRAR2
2009-06-09 03:33 46 ac—— c:\windows2\.pod
2009-06-09 03:12 -cd—– c:\windows2\Internet Logs
2009-06-09 02:00 -cds—- c:\documents and settings\paulpaul\UserData
2009-06-09 01:53 424,320 ac—— c:\windows2\system32\drivers\BCMWL5.SYS
2009-06-09 01:53 -cd—– c:\program files\Broadcom
2009-06-09 01:52 -cd—– c:\windows2\system32\ReinstallBackups
2009-06-09 01:52 74,496 ac—— c:\windows2\system32\drivers\Rtlnicxp.sys
2009-06-09 01:52 -cd—– c:\windows2\OPTIONS
2009-06-08 06:19 -cd–r– c:\documents and settings\all users.windows2\Documents
2009-06-08 06:19 13,608 ac—r– c:\windows2\SET31.tmp
2009-06-08 06:18 1,086,182 ac—r– c:\windows2\SET1C.tmp
2009-06-08 05:45 -cds—- c:\windows2\system32\Microsoft
2009-06-08 05:39 -cdsh— c:\windows2\Installer
2009-06-08 05:38 -cd—– c:\documents and settings\PaulPaul
2009-06-08 05:35 8,192 ac—— c:\windows2\REGLOCS.OLD
2009-06-08 05:34 150,016 ac—— c:\windows2\system32\dllcache\winzm.ime
2009-06-08 05:34 150,016 ac—— c:\windows2\system32\dllcache\winsp.ime
2009-06-08 05:34 150,016 ac—— c:\windows2\system32\dllcache\winpy.ime
2009-06-08 05:34 61,952 ac—— c:\windows2\system32\dllcache\winime.ime
2009-06-08 05:34 74,752 ac—— c:\windows2\system32\dllcache\winar30.ime
2009-06-08 05:34 69,120 ac—— c:\windows2\system32\dllcache\wingb.ime
2009-06-08 05:34 41,600 ac—— c:\windows2\system32\dllcache\weitekp9.dll
2009-06-08 05:34 31,232 ac—— c:\windows2\system32\dllcache\weitekp9.sys
2009-06-08 05:34 86,074 ac—— c:\windows2\system32\dllcache\voicesub.dll
2009-06-08 05:34 48,256 ac—— c:\windows2\system32\dllcache\w32.dll
2009-06-08 05:34 426,042 ac—— c:\windows2\system32\dllcache\voicepad.dll
2009-06-08 05:32 6,656 ac—— c:\windows2\system32\dllcache\migregdb.exe
2009-06-08 05:31 74,752 ac—— c:\windows2\system32\dllcache\dayi.ime
2009-06-08 05:30 2,577 ac—— c:\windows2\system32\CONFIG.NT
2009-06-08 05:30 0 ac—— c:\windows2\control.ini
2009-06-08 05:30 25,065 ac—— c:\windows2\system32\wmpscheme.xml
2009-06-08 05:30 23,392 ac—— c:\windows2\system32\nscompat.tlb
2009-06-08 05:30 16,832 ac—— c:\windows2\system32\amcompat.tlb
2009-06-08 05:30 299,552 ac—— c:\windows2\WMSysPrx.prx
2009-06-08 05:29 -cdsh— c:\documents and settings\all users.windows2\DRM
2009-06-08 05:29 488 ac–hr– c:\windows2\system32\WindowsLogon.manifest
2009-06-08 05:29 488 ac–hr– c:\windows2\system32\logonui.exe.manifest
2009-06-08 05:29 -cds—- c:\windows2\Downloaded Program Files
2009-06-08 05:29 -cd–r– c:\windows2\Offline Web Pages
2009-06-08 05:29 749 ac–hr– c:\windows2\WindowsShell.Manifest
2009-06-08 05:29 749 ac–hr– c:\windows2\system32\wuaucpl.cpl.manifest
2009-06-08 05:29 749 ac–hr– c:\windows2\system32\sapi.cpl.manifest
2009-06-08 05:29 749 ac–hr– c:\windows2\system32\nwc.cpl.manifest
2009-06-08 05:29 749 ac–hr– c:\windows2\system32\ncpa.cpl.manifest
2009-06-08 05:29 749 ac–hr– c:\windows2\system32\cdplayer.exe.manifest
2009-06-02 23:11 -cd—– c:\program files\Trend Micro
2009-05-29 01:50 -cd—– c:\program files\Anonymizer
2009-05-18 06:02 -cd—– c:\program files\PromoSoft
2009-05-18 05:26 -cd—– c:\program files\PADGen

==================== Find3M ====================

2009-06-08 05:30 2,678 ac—— c:\windows2\java\packages\data\WXJF9ZXZ.DAT
2009-06-08 05:30 558,142 ac—— c:\windows2\java\packages\3DRRLNFV.ZIP
2009-06-08 05:30 155,995 ac—— c:\windows2\java\packages\3737DF13.ZIP
2009-06-08 05:30 2,678 ac—— c:\windows2\java\packages\data\RJL7T3J7.DAT
2009-06-08 05:30 2,678 ac—— c:\windows2\java\packages\data\VF3XZ1F7.DAT
2009-06-08 05:30 2,678 ac—— c:\windows2\java\packages\data\TNZHBVVV.DAT
2009-06-08 05:30 2,678 ac—— c:\windows2\java\packages\data\KCPJX3X3.DAT
2009-06-08 05:30 70,697 ac—— c:\windows2\pchealth\helpctr\offlinecache\index.dat
2009-06-08 05:27 21,640 ac—— c:\windows2\system32\emptyregdb.dat
2009-06-05 04:56 512 ac—— C:\drmHeader.bin
2009-05-01 22:03 129,784 -c—— c:\windows2\system32\pxafs.dll
2009-05-01 22:03 120,056 -c—— c:\windows2\system32\pxcpyi64.exe
2009-05-01 22:03 118,520 -c—— c:\windows2\system32\pxinsi64.exe
2009-05-01 22:03 43,528 -c—— c:\windows2\system32\drivers\PxHelp20.sys
2009-05-01 22:03 9,464 -c—— c:\windows2\system32\drivers\cdralw2k.sys
2009-05-01 22:03 9,336 -c—— c:\windows2\system32\drivers\cdr4_xp.sys
2009-05-01 22:02 90,112 ac—— c:\windows2\system32\dpl100.dll
2009-05-01 22:02 823,296 ac—— c:\windows2\system32\divx_xx0c.dll
2009-05-01 22:02 823,296 ac—— c:\windows2\system32\divx_xx07.dll
2009-05-01 22:02 815,104 ac—— c:\windows2\system32\divx_xx0a.dll
2009-05-01 22:02 811,008 ac—— c:\windows2\system32\divx_xx16.dll
2009-05-01 22:02 802,816 ac—— c:\windows2\system32\divx_xx11.dll
2009-05-01 22:02 685,056 ac—— c:\windows2\system32\DivX.dll
2009-03-21 19:40 1,310,720 ac—— c:\windows2\system32\ChilkatUpload.dll

============= FINISH: 2:16:55.45 ===============



Fifthly, I have attached the attach.txt file for the new version of Windows to this post.


Sixthly, just in case you need it, here is a fresh HJT log for the new Windows version:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:19:59, on 10/06/2009
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS2\System32\smss.exe
C:\WINDOWS2\system32\winlogon.exe
C:\WINDOWS2\system32\services.exe
C:\WINDOWS2\system32\lsass.exe
C:\WINDOWS2\System32\Ati2evxx.exe
C:\WINDOWS2\system32\svchost.exe
C:\WINDOWS2\System32\svchost.exe
C:\WINDOWS2\system32\spoolsv.exe
C:\WINDOWS2\system32\Ati2evxx.exe
C:\WINDOWS2\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS2\System32\ctfmon.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\WINDOWS2\System32\wuauclt.exe
C:\WINDOWS2\System32\wpabaln.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS2\system32\NOTEPAD.EXE
C:\WINDOWS2\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro2\HijackThis2\HijackThis.exe

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS2\System32\msdxm.ocx
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS2\System32\ctfmon.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS2\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS2\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS2\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS2\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS2\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS2\web\related.htm
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS2\System32\Ati2evxx.exe

–
End of file - 4031 bytes



Seventhly, (this is getting a bit silly now :-) ) .. thanks for your help again! I really do appreciate it!

:-)

Attachments:

OK, both the old and the new install are now looking clean. You need to get that new installation updated as soon as you can, its a couple of Service Packs behind at the moment.

(Old installation)
Click Start >> Run. Type the following into the Run box and hit enter;
ComboFix /u

That'll clean up after ComboFix and set a new, clean Restore point.


Now, you should secure the new install as soon as you can. As well as the updates I mentioned above, there are a couple of other things it could do with.

Install Anti-Virus software! Without any anti-virus software, your computer is wide open to infection. If you don't have any Anti-Virus software I strongly recommend you download Avast! or AVG Free


You don't appear to be running any third party Firewall software.

Install a firewall! Without a firewall you are very susceptible to being hacked, and people could gain access to your computer. If you don't have a firewall I strongly recommend you download ONE of the following:
1) Comodo
2) Agnitum
3) Sunbelt/Kerio


Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:

Download Spybot Search and Destroy 1.5 from here
Check for Updates/ Immunize and run a Full System Scan on a regular basis.

SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
Freely available: Download SpywareBlaster

Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.


Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI