I hope I didn't do something wrong, but this is what did. After re-installing, the program still froze for hours, so instead of dragging the entire folder: cfscript.txt, I went into that folder and dragged the text file with all the info you sent into combofix and it worked...I think?! Here's the log file in two parts:
ComboFix 09-01-08.01 - Marty Rosengarten 2009-01-08 21:45:13.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2975 [GMT -5:00]
Running from: c:\documents and settings\Marty Rosengarten\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Marty Rosengarten\Desktop\CFscript.txt\CFscript.txt
AV: AntiVir PersonalEdition Classic Virus Protection *On-access scanning disabled* (Updated)
AV: AntiVir PersonalEdition Classic Virus Protection *On-access scanning enabled* (Updated)
FW: *disabled*
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-12-09 to 2009-01-09 )))))))))))))))))))))))))))))))
.
2009-01-07 18:00 . 2009-01-07 18:00 <DIR> d-------- c:\documents and settings\Marty Rosengarten\Application Data\Grisoft
2009-01-07 18:00 . 2007-05-30 07:10 10,872 --a------ c:\windows\system32\drivers\AvgAsCln.sys
2009-01-06 14:14 . 2009-01-06 14:14 685,056 --a------ c:\windows\isRS-000.tmp
2009-01-06 14:14 . 2009-01-04 18:38 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-06 02:54 . 2009-01-06 02:54 90,112 --a------ C:\zcxxfilse.exe
2009-01-06 02:54 . 2009-01-06 02:54 90,112 -r-hs---- c:\windows\windsvc.exe
2009-01-06 00:40 . 2009-01-06 00:46 108,516,963 --ah----- C:\Maxthon.html
2009-01-06 00:38 . 2009-01-07 00:26 831,421,626 --ah----- C:\Opera.html
2009-01-06 00:37 . 2009-01-06 00:34 344,064 -rahs---- c:\documents and settings\Marty Rosengarten\Application Data\mchost.exe
2009-01-06 00:37 . 2009-01-06 00:38 14,336 --a------ C:\qjfrlys.exe
2009-01-06 00:36 . 2009-01-07 00:26 800,535,260 --ah----- C:\Mozilla.html
2009-01-06 00:35 . 2009-01-06 00:34 344,064 -rahs---- c:\windows\mchost.exe
2009-01-06 00:34 . 2009-01-06 00:34 344,064 --ah----- C:\windll_v354.exe
2008-12-16 00:53 . 2008-12-16 00:53 <DIR> d-------- c:\program files\SmartFTP Client 3.0 Setup Files
2008-12-16 00:53 . 2008-12-16 00:53 <DIR> d-------- c:\program files\SmartFTP Client
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-09 02:45 --------- d-----w c:\documents and settings\Marty Rosengarten\Application Data\skypePM
2009-01-09 02:45 --------- d-----w c:\documents and settings\Marty Rosengarten\Application Data\Skype
2009-01-09 00:42 --------- d-----w c:\program files\Mozilla Thunderbird
2009-01-08 21:29 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-07 21:31 --------- d-----w c:\program files\Lavasoft
2009-01-06 19:15 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-06 06:36 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-05 23:20 --------- d-----w c:\program files\SpywareBlaster
2009-01-05 22:35 --------- d-----w c:\program files\fotoQuote
2009-01-04 23:38 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-03 08:02 --------- d-----w c:\program files\CCleaner
2009-01-03 07:58 --------- d-----w c:\documents and settings\All Users\Application Data\Avg7
2008-12-22 04:32 --------- d-----w c:\documents and settings\Marty Rosengarten\Application Data\Lasersoft Imaging
2008-12-17 12:58 --------- d-----w c:\documents and settings\Marty Rosengarten\Application Data\FileZilla
2008-12-16 05:54 --------- d-----w c:\documents and settings\Marty Rosengarten\Application Data\SmartFTP
2008-12-12 17:01 3,067,904 ------w c:\windows\system32\dllcache\mshtml.dll
2008-11-26 06:09 --------- d-----w c:\program files\RegCure
2008-11-25 08:53 --------- d-----w c:\documents and settings\Marty Rosengarten\Application Data\LumaPix
2008-11-13 04:12 --------- d-----w c:\program files\MSXML 4.0
2008-10-26 17:18 273,264 ----a-w c:\windows\FotoFusionV4 Uninstaller.exe
2008-10-26 03:24 5,423,104 ----a-w c:\windows\system32\tlpsplib10.dll
2008-10-24 11:21 455,296 ------w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-23 12:36 286,720 ------w c:\windows\system32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 01:00 666,112 ----a-w c:\windows\system32\wininet.dll
2008-10-16 01:00 666,112 ------w c:\windows\system32\dllcache\wininet.dll
2008-10-16 01:00 619,520 ------w c:\windows\system32\dllcache\urlmon.dll
2008-10-16 01:00 1,499,136 ------w c:\windows\system32\dllcache\shdocvw.dll
2008-10-15 16:34 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
2006-10-08 05:39 2,388 -c--a-w c:\program files\uninstalcwp2.log
2006-02-28 01:10 48,472 -c--a-w c:\documents and settings\Marty Rosengarten\Application Data\GDIPFONTCACHEV1.DAT
2005-09-10 00:55 7,155,864 -c--a-w c:\program files\NGhost10.msi
2005-09-10 00:55 37,766,164 -c--a-w c:\program files\Data1.cab
2005-09-10 00:55 35 -c--a-w c:\program files\SCSSDist.ini
2005-02-22 14:16 1,867 -c--a-w c:\documents and settings\Marty Rosengarten\CountCorners.vbs
2003-11-18 18:37 241,664 ----a-w c:\program files\npmusicn.dll
2002-07-26 21:02 153,088 ----a-w c:\program files\UNWISE.EXE
2008-09-18 21:39 56 --sh--r c:\windows\system32\01758A4BD5.sys
2007-01-03 10:12 88 --sha-r c:\windows\system32\83BE6B67B2.sys
2008-09-18 21:39 1,682 --sha-w c:\windows\system32\KGyGaAvL.sys
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- c:\documents and settings\Marty Rosengarten\Application Data\mchost.exe ----
Company:
File Description:
File Version: 1.00
Product Name:
Copyright:
Original file name: Application.exe
MD5: e93527b115490081dfd3c43ee722bfc7
C:\qjfrlys.exe -- Unable to find Resource table header.
MD5: 21405dd01269a7700ae6380a9f10fd33
---- C:\windll_v354.exe ----
Company:
File Description:
File Version: 1.00
Product Name:
Copyright:
Original file name: Application.exe
MD5: e93527b115490081dfd3c43ee722bfc7
---- c:\windows\mchost.exe ----
Company:
File Description:
File Version: 1.00
Product Name:
Copyright:
Original file name: Application.exe
MD5: e93527b115490081dfd3c43ee722bfc7
---- c:\windows\windsvc.exe ----
Company:
File Description:
File Version: 1.00
Product Name:
Copyright:
Original file name: Application.exe
MD5: e26a9804057a4cafc7053bc1b1328200
---- C:\zcxxfilse.exe ----
Company:
File Description:
File Version: 1.00
Product Name:
Copyright:
Original file name: Application.exe
MD5: e26a9804057a4cafc7053bc1b1328200
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"BitComet"="c:\program files\BitComet\BitComet.exe" [2008-07-17 2599224]
"settings"="c:\windows\mchost.exe" [2009-01-06 344064]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe" [2008-03-24 218496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-04-25 139264]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2006-04-05 2177256]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-12-15 180269]
"PrettyMay"="c:\program files\PrettyMay\PrettyMay.exe" [2008-04-23 2715648]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-10 385024]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"StxTrayMenu"="c:\program files\Seagate\SystemTray\StxMenuMgr.exe" [2007-01-18 190008]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"settings"="c:\windows\mchost.exe" [2009-01-06 344064]
c:\documents and settings\Marty Rosengarten\Start Menu\Programs\Startup\
PANTONE(R) colorist.lnk - c:\program files\Pantone, Inc\PANTONE(R) colorist\PANTONE(R) colorist.exe [2003-10-28 98304]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ColorVisionStartup.lnk - c:\program files\PANTONE COLORVISION\Startup\ColorVisionStartup.exe [2004-12-21 385024]
MonacoGamma.lnk - c:\program files\Monaco Systems\MonacoEZcolor 2.6\MonacoGamma.exe [2005-10-28 102400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=ssvchn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"VIDC.MJPG"= Pvmjpg30.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\k:\0autocheck autochk *\0lsdelete
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Forget Me Not.lnk]
backup=c:\windows\pss\Forget Me Not.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-15 03:22 267048 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-10 15:27 385024 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a--c--- 2006-11-09 15:07 49263 c:\program files\Java\jre1.5.0_10\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
--a------ 2005-05-03 19:38 64512 c:\windows\system32\P17.dll
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" /startup
"dlmMgr"="c:\program files\Common Files\Adobe\ESD\AdobeDownloadManager.exe" restart=1
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_7 -reboot 1
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"MediaFace Integration"=c:\program files\Fellowes\MediaFACE 4.0\SetHook.exe
"Ink Monitor"=c:\program files\EPSON\Ink Monitor\InkMonitor.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"UpdReg"=c:\windows\UpdReg.EXE
"ehTray"=c:\windows\ehome\ehtray.exe
"P17Helper"=Rundll32 P17.dll,P17Helper
"IntelMeM"=c:\program files\Intel\Modem Event Monitor\IntelMEM.exe
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe"
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"ATIPTA"=c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
"CTSysVol"=c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
"WD Button Manager"=WDBtnMgr.exe
"DLA"=c:\windows\System32\DLA\DLACTRLW.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Intuit\\QuickBooks Pro\\QBDBMgrN.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupXu.exe"=
"c:\\Program Files\\FileZilla\\FileZilla.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Documents and Settings\\Marty Rosengarten\\My Documents\\Download Start-up files\\utorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 11\\programs\\umi.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Adobe\\Adobe Bridge CS3\\Bridge.exe"=
"c:\\Program Files\\Adobe\\Adobe Device Central CS3\\DeviceCentral.exe"=
"c:\\Program Files\\Common Files\\Adobe\\ESD\\AdobeDownloadManager.exe"=
"c:\\Program Files\\Adobe\\Adobe Utilities\\ExtendScript Toolkit 2\\ExtendScript Toolkit 2.exe"=
"c:\\Program Files\\Adobe\\Adobe Help Center\\ahc.exe"=
"c:\\Program Files\\Adobe\\Adobe Photoshop CS2\\Photoshop.exe"=
"c:\\Program Files\\Adobe\\Adobe Photoshop CS3\\Photoshop.exe"=
"c:\\Program Files\\Adobe\\Adobe Stock Photos CS3\\Adobe Stock Photos CS3.exe"=
"c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\fotoQuote\\My Product Name\\FotoQuote Pro\\FotoQuote Pro.EXE"=
"c:\\Program Files\\BitPim\\bitpimw.exe"=
"c:\\Program Files\\Quicken\\qw.exe"=
"c:\\Program Files\\WinSCP\\WinSCP.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12283:TCP"= 12283:TCP:BitComet 12283 TCP
"12283:UDP"= 12283:UDP:BitComet 12283 UDP
"14461:TCP"= 14461:TCP:BitComet 14461 TCP
"14461:UDP"= 14461:UDP:BitComet 14461 UDP
"9881:TCP"= 9881:TCP:BitComet 9881 TCP
"9881:UDP"= 9881:UDP:BitComet 9881 UDP
"6346:TCP"= 6346:TCP:Shareaza
"8192:TCP"= 8192:TCP:BitComet 8192 TCP
"8192:UDP"= 8192:UDP:BitComet 8192 UDP
"13946:TCP"= 13946:TCP:BitComet 13946 TCP
"13946:UDP"= 13946:UDP:BitComet 13946 UDP
R4 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [2007-01-24 14976]
S1 bf324a68;bf324a68;c:\windows\system32\drivers\bf324a68.sys --> c:\windows\system32\drivers\bf324a68.sys [?]
S3 ICDUSB2;Sony IC Recorder (P);c:\windows\system32\drivers\IcdUsb2.sys [2006-06-24 39048]
S4 HPFECP06;HPFECP06;c:\windows\system32\drivers\HPFECP06.SYS --> c:\windows\system32\drivers\HPFECP06.SYS [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{NQQ5L861-82LC-FV28-BC5R-EK164PT2UCAG}]
"c:\windows\mchost.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-01-02 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe []
2009-01-08 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-11-26 00:06]
2009-01-01 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-11-26 00:06]
2009-01-08 c:\windows\Tasks\xoowsmum.job
- c:\windows\system32\rundll32.exe [2008-04-13 19:12]
.
- - - - ORPHANS REMOVED - - - -
BHO-{56525793-8408-4ED2-8F6C-F195B775570B} - (no file)
Notify-fccyaBUM - (no file)
