please HELP my log was:
---- Previous Run -------
.
c:\documents and settings\User\Local Settings\Temporary Internet Files\TestBrowser.html
.
((((((((((((((((((((((((( Files Created from 2009-11-26 to 2009-12-26 )))))))))))))))))))))))))))))))
.
2009-12-26 05:33 . 2009-12-26 05:33 -------- d-----w- c:\documents and settings\TEMP\Local Settings\Application Data\Google
2009-12-26 05:33 . 2009-12-26 05:33 -------- d-----w- c:\documents and settings\TEMP\Local Settings\Application Data\Microsoft
2009-12-26 05:33 . 2009-12-26 05:33 -------- d-sh--w- c:\documents and settings\TEMP
2009-12-26 05:32 . 2009-12-26 05:32 -------- d-----w- c:\windows\system32\xircom
2009-12-26 05:32 . 2009-12-26 05:32 -------- d-----w- c:\windows\system32\wbem\snmp
2009-12-26 05:32 . 2009-12-26 05:32 -------- d-----w- c:\program files\microsoft frontpage
2009-12-26 04:57 . 2009-12-26 05:16 79488 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-26 04:27 . 2006-09-07 01:43 22752 ----a-w- c:\windows\system32\spupdsvc.exe
2009-12-26 04:26 . 2009-12-26 04:26 -------- d--h--w- c:\windows\$hf_mig$
2009-12-26 03:38 . 2009-12-26 03:58 -------- d-----w- c:\program files\Sony
2009-12-26 03:38 . 2009-12-26 03:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Sony Corporation
2009-12-26 03:27 . 2009-12-26 03:27 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Downloaded Installations
2009-12-26 03:25 . 2009-12-26 03:25 -------- d-----w- c:\program files\QuickTime
2009-12-26 03:25 . 2009-12-26 03:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-26 03:23 . 2009-12-26 03:23 -------- d-----w- c:\program files\Common Files\Apple
2009-12-26 03:23 . 2009-12-26 03:23 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Apple
2009-12-26 03:23 . 2009-12-26 03:23 -------- d-----w- c:\program files\Apple Software Update
2009-12-26 03:23 . 2009-12-26 03:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-12-26 03:23 . 2009-12-26 03:23 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Apple Computer
2009-12-26 02:56 . 2009-12-26 05:51 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\PMB Files
2009-12-26 02:56 . 2009-12-26 02:56 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2009-12-26 02:53 . 2009-12-26 03:22 32494896 ----a-w- c:\documents and settings\User\Application Data\Sony Setup\9234765D-29DF-48d0-93FB-284B7B6009B9\QuickTimeInstaller.exe
2009-12-26 02:53 . 2009-12-26 02:53 -------- d-----w- c:\program files\Pando Networks
2009-12-26 02:50 . 2009-12-26 04:57 -------- d-----w- c:\documents and settings\User\Application Data\Sony Setup
2009-12-26 02:50 . 2009-12-26 02:50 -------- d-----w- c:\documents and settings\User\Application Data\Sony
2009-12-26 02:50 . 2009-12-26 02:50 -------- d-----w- c:\program files\Sony Setup
2009-12-18 03:35 . 2009-12-18 03:35 -------- d-----w- C:\CloneDVDTemp
2009-12-17 15:07 . 2009-12-17 15:08 -------- d-----w- c:\program files\Sony Ericsson
2009-12-10 17:00 . 2009-12-10 17:00 -------- d-----w- c:\program files\Elaborate Bytes
2009-12-10 15:54 . 2009-12-10 15:54 -------- d-----w- c:\program files\Best Buy Digital Music Store Powered by Rhapsody
2009-12-03 18:55 . 2009-12-10 23:20 -------- d-----w- c:\documents and settings\User\Application Data\virtualmoon
2009-12-03 18:50 . 2009-12-10 23:20 -------- d-----w- c:\program files\VirtualMoon
2009-12-03 16:29 . 2009-12-03 16:29 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Identities
2009-11-29 05:29 . 2009-11-29 05:29 -------- d-----w- c:\documents and settings\All Users\Application Data\SweetIM
2009-11-29 05:29 . 2009-11-29 05:29 -------- d-----w- c:\program files\SweetIM
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-22 05:22 . 2009-09-07 05:43 -------- d-----w- c:\documents and settings\User\Application Data\U3
2009-12-21 03:40 . 2009-11-13 04:30 -------- d-----w- c:\program files\Google
2009-12-10 23:33 . 2009-11-16 01:18 -------- d-----w- c:\program files\Zylom Games
2009-12-10 23:19 . 2009-11-08 19:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-12-10 16:06 . 2009-11-08 19:59 -------- d-----w- c:\documents and settings\User\Application Data\skypePM
2009-12-03 18:42 . 2009-09-07 05:40 331752 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-16 01:18 . 2009-11-16 01:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Zylom
2009-11-08 19:59 . 2009-11-08 19:59 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-10-30 23:12 . 2009-10-30 22:51 -------- d-----w- c:\documents and settings\User\Application Data\MSNInstaller
2009-10-23 23:01 . 2009-11-16 01:18 102400 ----a-w- c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
2009-10-22 01:50 . 2009-10-22 01:50 107272 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-10-22 01:50 . 2009-10-22 01:50 10520 ----a-w- c:\windows\system32\avgrsstx.dll
2009-10-22 01:50 . 2009-10-22 01:50 325128 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-22 01:50 . 2009-10-22 01:50 27656 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-12 14:50 . 2009-10-12 14:50 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-10-12 14:49 . 2009-10-12 14:49 152576 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2008-04-09 17:19 . 2008-04-09 17:17 757248 ----a-w- c:\program files\YouTubeDownloadConvert.exe
2006-01-13 14:07 . 2008-04-09 17:17 200704 ----a-w- c:\program files\ssleay32.dll
2006-01-13 14:07 . 2008-04-09 17:17 1089536 ----a-w- c:\program files\libeay32.dll
2007-12-15 21:32 . 2007-12-15 21:32 162941 --sha-r- c:\windows\system32\qzvfb.dll
.
------- Sigcheck -------
[-] 2007-12-15 . 409B44CE625776DB74EAA63F24E9D4E4 . 360704 . . [5.1.2600.3002] . . c:\windows\system32\drivers\tcpip.sys
[-] 2007-12-15 . 837E25C89935C3CB144DD757D7FFF719 . 2302464 . . [5.1.2600.3181] . . c:\windows\system32\ntoskrnl.exe
[-] 2007-12-15 . 3F57F13786678214051DF97A1423BDCC . 2182144 . . [5.1.2600.3181] . . c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-12-26_05.30.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-26 05:33 . 2009-12-26 05:33 16384 c:\windows\Temp\Perflib_Perfdata_6b4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{236bd960-2fab-4645-9bc1-dae85904734e}"= "c:\program files\BlackXP\tbBlac.dll" [2007-11-08 1502232]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2009-10-20 187192]
[HKEY_CLASSES_ROOT\clsid\{236bd960-2fab-4645-9bc1-dae85904734e}]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{236bd960-2fab-4645-9bc1-dae85904734e}]
2007-11-08 19:11 1502232 ----a-w- c:\program files\BlackXP\tbBlac.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2009-10-20 00:15 1345336 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{236bd960-2fab-4645-9bc1-dae85904734e}"= "c:\program files\BlackXP\tbBlac.dll" [2007-11-08 1502232]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-20 1345336]
[HKEY_CLASSES_ROOT\clsid\{236bd960-2fab-4645-9bc1-dae85904734e}]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{236BD960-2FAB-4645-9BC1-DAE85904734E}"= "c:\program files\BlackXP\tbBlac.dll" [2007-11-08 1502232]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2009-10-20 1345336]
[HKEY_CLASSES_ROOT\clsid\{236bd960-2fab-4645-9bc1-dae85904734e}]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"MsnMsgr"="~c:\program files\MSN Messenger\MsnMsgr.Exe" [BU]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2009-12-26 2935480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-11-06 16855552]
"SkyTel"="SkyTel.EXE" [2007-10-11 1826816]
"AAWTray"="c:\program files\Security\Ad-Aware 2007\AAWTray.exe" [2007-08-08 88024]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-12 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-10-22 1601304]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-10-20 111928]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_3"="advpack.dll" [2007-12-15 124928]
c:\documents and settings\User\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
Styler.lnk - c:\documents and settings\User\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2009-9-6 15086]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Shortcut to RocketDock.lnk - c:\program files\RocketDock\RocketDock.exe [2009-9-6 495616]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-22 01:50 10520 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2005-12-21 05:57 176128 ----a-w- c:\progra~1\Stardock\OBJECT~1\WINDOW~1\WbSrv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Professional Business XII\\Win32\\RpcDataSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Professional Business XII\\RpcSandraSrv.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9625:TCP"= 9625:TCP:gllxlyfe
"58964:TCP"= 58964:TCP:Pando Media Booster
"58964:UDP"= 58964:UDP:Pando Media Booster
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/21/2009 5:50 PM 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/21/2009 5:50 PM 107272]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/21/2009 5:50 PM 298264]
R3 QCEmerald;Logitech QuickCam Web;c:\windows\system32\drivers\OVCE.sys [11/18/2009 8:37 AM 31872]
S2 ajflhl;Update Time;c:\windows\system32\svchost.exe -k netsvcs [8/3/2004 8:00 PM 14336]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/12/2009 8:30 PM 135664]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ajflhl
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\xspb3qkt.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1682929&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - WEFI
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT1682929&SearchSource=13
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-25 21:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ajflhl]
"ServiceDll"="c:\windows\system32\qzvfb.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(696)
c:\progra~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
- - - - - - - > 'explorer.exe'(3076)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\msi.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
Completion time: 2009-12-25 21:52:48
ComboFix-quarantined-files.txt 2009-12-26 05:52
Pre-Run: 219,420,377,088 bytes free
Post-Run: 219,402,964,992 bytes free
- - End Of File - - CD24A8B60067097210990CE6F8C73902
Edited by omegawolf19, 25 December 2009 - 08:03 PM.