Hello, yes I made
C:\Documents and Settings\All Users\Start Menu\Programs\γCAXΆΩ'c, it's just a game.
Here's the FRST Fix Logs also the logs said I needed to reboot so I did:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 16-12-2013 02
Ran by HP_Administrator at 2013-12-16 12:40:34 Run:1
Running from C:\Documents and Settings\HP_Administrator\Desktop
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] ()
C:\WINDOWS\system32\hkcmd.exe
HKLM\...\Run: [KernelFaultCheck] - %systemroot%\system32\dumprep 0 -k
%systemroot%\system32\dumprep
HKCU\...\Run: [] - [x]
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [369200 2009-10-30] (DT Soft Ltd)
C:\Program Files\DAEMON Tools Lite
MountPoints2: {489d45bb-311d-11e1-94d1-000f66ef5b22} - M:\setupSNK.exe
MountPoints2: {a6916568-31c7-11e1-94d2-000f66ef5b22} - L:\setupSNK.exe
BHO: No Name - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - No File
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8}
https://secure.gopet...v/GoPetsWeb.cabFF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
C:\Program Files\Pando Networks
FF SearchPlugin: C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\91b5e42t.default\searchplugins\aol-search.xml
S2 awkxzbde; C:\WINDOWS\system32\cwlfb.dll [x]
S2 kfkya; C:\WINDOWS\system32\cwlfb.dll [x]
S2 yhfixnoho; C:\WINDOWS\system32\cwlfb.dll [x]
C:\WINDOWS\system32\cwlfb.dll
End
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HotKeysCmds => Value deleted successfully.
C:\WINDOWS\system32\hkcmd.exe => Moved successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\ => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => Value deleted successfully.
C:\Program Files\DAEMON Tools Lite => Moved successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{489d45bb-311d-11e1-94d1-000f66ef5b22} => Key deleted successfully.
HKCR\CLSID\{489d45bb-311d-11e1-94d1-000f66ef5b22} => Key not found.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a6916568-31c7-11e1-94d2-000f66ef5b22} => Key deleted successfully.
HKCR\CLSID\{a6916568-31c7-11e1-94d2-000f66ef5b22} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} => Key deleted successfully.
HKCR\CLSID\{4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} => Key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB} => Key deleted successfully.
HKCR\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB} => Key not found.
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} => Key deleted successfully.
HKCR\CLSID\{F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} => Key deleted successfully.
HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin => Key deleted successfully.
C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll not found.
C:\Program Files\Pando Networks => Moved successfully.
C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\91b5e42t.default\searchplugins\aol-search.xml => Moved successfully.
awkxzbde => Service deleted successfully.
kfkya => Service deleted successfully.
yhfixnoho => Service deleted successfully.
"C:\WINDOWS\system32\cwlfb.dll" => File/Directory not found.
The system needs a manual reboot.
==== End of Fixlog ====
Here's the RogueKiller Report:
RogueKiller V8.7.12 [Dec 14 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback :
http://www.adlice.com/forum/Website :
http://www.adlice.co...es/roguekiller/Blog :
http://www.adlice.comOperating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : HP_Administrator [Admin rights]
Mode : Scan -- Date : 12/16/2013 12:58:54
| ARK || FAK || MBR |
€€€ Bad processes : 1 €€€
[SUSP PATH] ALCWZRD.EXE -- C:\WINDOWS\ALCWZRD.EXE [7] -> KILLED [TermProc]
€€€ Registry Entries : 0 €€€
€€€ Scheduled tasks : 0 €€€
€€€ Startup Entries : 0 €€€
€€€ Web browsers : 0 €€€
€€€ Particular Files / Folders: €€€
€€€ Driver : [NOT LOADED 0xc0000033] €€€
€€€ External Hives: €€€
€€€ Infection : €€€
€€€ HOSTS File: €€€
--> %SystemRoot%\System32\drivers\etc\hosts
127.0.0.1 localhost
€€€ MBR Check: €€€
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST3200822AS +++++
--- User ---
[MBR] b7ed535f510e2322b581a5a9a100d7fd
[BSP] 8a7884da59e414827f91c43dcf324e78 : Toshiba MBR Code
Partition table:
0 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 63 | Size: 8202 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 16798320 | Size: 182576 Mo
User = LL1 ... OK!
User = LL2 ... OK!
Finished : << RKreport[0]_S_12162013_125854.txt >>
RKreport[0]_S_12162013_124738.txt