Link to home
Start Free TrialLog in
Avatar of davdawg765
davdawg765

asked on

think ive got a virus/bug what do i do

Heres the deal. i start up my laptop. i see the windows logo and i get to my desktop.  however, my mouse just goes into hourglass mode and i cant do anything. when i hit control alt delete to see whats running, i see that "Kjtsbhl85n" and "21rcf5jys" are running and seem to be replicating. i dont know what these are and im thinking that i have a bug.  i dont know what to do to get rid or it. please help.
Avatar of Luc Franken
Luc Franken
Flag of Netherlands image

Hi davdawg765,

Try something like http://housecall.antivirus.com

Greetings,

LucF
SOLUTION
Avatar of sunray_2003
sunray_2003
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Btw, do that from safe mode, you probably won't be able to do it in normal mode.
Avatar of davdawg765
davdawg765

ASKER

i cant connect to the internet while im in safe mode.
Then, may I suggest to first download (with another computer) some of the tools listed by sunray (ad-aware and spybot) and run them in safe mode.
Or, ask some friend if he/she has a bootable Norton Antivirus cd-rom, to scan your computer with.
well i did a litle search but nothing if it is a bug then not a new one


wel maybe try this software (reg cleaner) it wil help you to edit startup and registry mayby thear is some aplicationn runig that you dont know abaut
 eny way you can disable suspishus ((; startup aplicatins and if when you restart are in start up agin than defenetly it is a virus

http://download.times.lv/mega/main.php?pad=10&file_id=1453&level=433


if you are sucsefull in runig eny adware than it will give you the name of the virus .........plz report it and solution will be on its way in a minute




nakedghost, what's the use of spamming such a list if
1) those virusscanners can't be used as stated by davdawg765
2) the most important ad/spyware removal tools are listed allready (for your information, hijackthis has no use in safe.)
sory for spam i won do tha again
are thear any problems with my second post too ???
and again sory police oficer i feel wery gulty for posting iformatin
eny way all those links are ok un neht time  davdawg765 wont need to search for stuf like that
Not that I know of... seems ok to me... maybe you have another link to that software as I'm unable to open the link (don't know why..)
hmmlink works for me


try to disable pop up blocking soft und chenge to culiric code page in you explorer
most of the pages contents are in rusian

i hope that helps thet is last known link to old reg cleaner wersion un that sof kicks ass i mean it is realy good

wery small un esay to use also dont do eny conflicts with diferent os


and if all above dosnt help than just go to www.times.lv then search for reg cleaner

that shold doo police oficer
If you can't read Russian, that link might be a little problematic.  Is lv = Latvia?
yes i live in latvia ((;

and whear ar you camming from ??((; how polite isnt it ??


hmmm culiric code page if prety default for most brosers i men if it isn't uncheked then it wil be instaled

just example if you dont know explorer/view/encoding/culiric(windows)
Check people's profiles to see if they specify where they live or work.  Sorry, Cyrillic is not in my default installation, and my employer isn't going to install it.
do you know what  encoding is ???
come on it got nothig to do with windows ((;
 internet explorer <------------ and i is quite simple to instal new languages for it

Callandor is my link working for you ???
Just to get over with it...
Reg cleaner is sold to IOLO soft, and is now called registry mechanic:
http://www.winguides.com/regmech/
ok but the old reg cleaner is free !!!! wow !!!!! ((;

and does prety much
still it is har for me to anderstand howe could rusina languge be mising !! in ie 6
i cheked standart instalatin and it was thear

i olso cheked and page is working without culiric code page ((; well mos of it  (example the download buton is wery easy to spot)
and plz dont think that i am rusian or samthenig ((;

ok ok i got ower it
I don't know, but here the page you linked to just doesn't open, I waited for over two minutes with a 8Mbit internet connection, so I don't know if I would be able to see the site when I have culiric installed??
did you tried just www.times.lv ???

and do you realy dont have rusian language suport in ie6 ??? it is standart

weel if problem would be in encoding then   you should be able to open page
it would only show you unrecognized chars

doo you have sam sort of fire wall or popup blocker ??
LucF  just to chek try this site www.narod.ru (it got nothig to doo with sys it is only to chek)
That one did open, but it took 95 seconds... (might be my proxy...)
yea now try this www.tvnet.lv if it wont open then lok for prblems in your conection
(this page needs baltic encoding but it must open or i will have to work ((;)

and did www.narod.ru opened corectly ??? did you see rusian text ??
within 2 seconds...
thats great i can sleep tonight ((;

so the www.times.lv still not opening ??
Nope :( I'll check my ISP if they're having problems with the range in wich 193.108.185.101 fits.

davdawg765, sorry for cluttering up your Q

LucF
i agree with that ---->davdawg765, sorry for cluttering up your Q

davdawg765 is www.times.lv  working for you ??
previusly nobody had eny complains abut it

I tried to download ad-aware and spybot to a disk but they were too big.  since my laptop is old it doesnt have a separate zip drive.  a zip disk wont work in a regular 3.5 floppy drive will it?  i cant find a bootable norton antivirus cd either.  any other tips would be greatly appreciated.
You can use a tool like winzip to compress the files and put them on more than one disk. Make it a self extracting archive so you don't have to install winzip on the laptop: http://www.winzip.com
If none of the above works or you cannot use any of the above because the computer OS now won't allow you to, contact the manufacturer of your computer and have them walk you through doing a recovery/restore of your operating system. It's a drastic step, but very efficient for a problem like this.  Or you can do a low level format of the hard drive and reload everything. Even more drastic.

Pat
hi, its me the guy with the computer problem.  
can someone email me that spy-ware stuff that is listed above, in the win-zip self-extracting archive?  on the computer im on now, i dont have enough space to download win-zip so i cant use it.  let me know.  thanks.
dave
You have to et us know what your email is (you are only allowed to post it in your profile; they will delete it if you post it here).  Use "at" instead of "@" to avoid spammers who harvest emails.
ive posted my email address
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
heres my logfile.  its pretty big and i know the stuff in the middle should go, but im not sure what i need to keep.  help please.

Logfile of HijackThis v1.97.7
Scan saved at 5:06:01 PM, on 3/19/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
A:\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmyrequest.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = C:\WINDOWS\system32\searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchmyrequest.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchmyrequest.com/sp.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://searchmyrequest.com/hp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\system32\blank.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = C:\WINDOWS\system32\blank.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmyrequest.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = C:\WINDOWS\system32\searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchdot.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = C:\WINDOWS\system32\searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmyrequest.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Twinhead
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://e-plus.cc/search.php?aff_id=46&keyword=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.30.159.1:1085
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.searchalot.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.searchalot.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://searchmyrequest.com/hp.php
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://acc.count-all.com/--/?ydtfs (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://acc.count-all.com/--/?ydtfs (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\system32\searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = http://www.search-1.net/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = http://www.search-1.net/search.html
O2 - BHO: DNSErr object - {1E1B2879-88FF-11D2-8D96-D7ACAC95951F} - C:\WINDOWS\DNSE.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [labset.exe] labset.exe
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [EnsoniqMixer] 9x8start.exe
O4 - HKLM\..\Run: [boh34nwg27] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [574ubddyxd] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [nllv3mamuk] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [xtpu3k7xpg] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ym2dngbosr] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [r50ywjn1k2] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [sycl8slcvo] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [gaasbnczey] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [9u7gzan8pc] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [zznef7c6dm] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [9azva20pee] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [m571ns9s4s] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [e2anem3gck] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [c5vdz2tsj5] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [9v10ft00ce] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ukm07ve3v4] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [fcc90rhdm4] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [s4p66fssp7] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [x8sjtjm7xp] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [6364zamy19] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [ndo4d7g9c0] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [x0vegxuzo7] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [j6fp70mj2o] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [frmwtv1dvc] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [5sg24t1cyy] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [sc286ce71u] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [nnzw2y6yy2] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [7rjozpxhyi] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [symtdwovta] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [n8papiguly] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [eoctflrrn8] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [1wyc6otb2r] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [9c8xoa9bls] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [unri77t26a] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [aicmiey1ex] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ljkgpb2ag1] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [u01d55h2yy] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [1faw2h3hom] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [433msm22fu] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [z30prmxh1m] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [29f7jmn4r8] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ie6bpfk7jk] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [aa7khlgxez] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [vxnllurh0t] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [5kzl208cls] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [9t3y70w831] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ldrc5bfdg1] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [vszgx7zvjo] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [z9t67et4rd] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [i6cuyklriu] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [bz9hd7xzu8] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [jclb8rhhge] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [dfhk6shd2o] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [nmmm1k933i] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [5kgz7l7iax] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [o65ppkma3d] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [10g5lmpbxz] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [2zwentsvsz] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [igkcfv3iwv] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [zzxh0rmwg8] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [15udbgc8ac] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [275yobgzdl] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [cy7mvkhtuw] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [5j1rld3dvp] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [cc72bc6i5i] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [x4kri1pp1l] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [kv97rjkvzz] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [drteoj2bg3] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [1zc5t9t92f] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [n04zgymnzg] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [kcym78b00x] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [tb6k3193ey] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [cmtjje00ux] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [p891bze6ra] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [gxwstvp3tk] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [bztfgopupt] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [zitpzu1o02] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [cyy7pgmixa] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [oilugs7naa] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [h39a3dinlo] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [0xdwxrd03g] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ypcp65c6th] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [9rtbm28nvm] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [tnaf5pk52g] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [wsav18er60] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [niwj4rl8f4] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [zsfy089dtt] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [t6clbxypwx] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [8ssldg81io] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [hcxi5jpcef] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [1nkhlwh9ue] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [ueh9uvoete] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [c45gsxsisp] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [4ft553gilp] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [az10x63fvn] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [rum9xy67dv] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [25x72zn53t] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [exfzov6yze] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [oopov48sgn] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [0e4fo6ll4x] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [lshkj693rp] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [6x8s2lxz60] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [2f7l4kfmi7] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [hzlas8tb0e] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [uxttvafk03] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [353lchco01] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [6ygdmadhzt] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [of17wsrynj] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [fnpzwahd1p] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [dg60i2j2wd] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [o4zg1gs3cy] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [xrg05j3nsn] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [xfiuuo9nlc] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [9y4r15j2gf] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [upgo8vu8kj] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [mzpu05i7al] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [0o2ns7rgtn] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [arcoa2mopd] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [maomhs63th] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [n7v99385f3] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [lbow85yggj] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [s7htnc1l2a] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [537j6v0va4] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [8h54g7bb8d] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [e7ijlrily2] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [o6y61znyve] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [isxld7tejx] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [su0dp3x5l7] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [g04yn5onul] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [bc7ryf97o0] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [wh7p4sze4v] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [5ajhon3665] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [3mvy54pu8j] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [7fogfbukbs] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [uh1is8m1fo] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [rssdyefmev] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [2j4b53r1hz] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [1p9hf1j4lp] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ifivo9n8nm] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [jhun95szpx] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [v17kgv2eu0] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [fskimbdko3] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [a0kyb46nuh] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [vsyvilh2yk] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [8dm6rdakep] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [k504y2kzau] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [9fyyc96jg0] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [hs5nycwdhb] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [62vabiozgh] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [s5d59aho8b] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [17pxv6dfil] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [p8ka4db8lu] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [kgdz4w89l6] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [gx81k8m5n4] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [9j09kh251t] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [i0f5wplo8a] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [mmkfr0ufdt] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [x8ojwi93gd] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [6g4syjzmpu] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [x7u20adbue] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [jtsak364jr] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [3rk5t37ygj] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [7jzigrbkhn] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [gl2a1mfbjy] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ep3osx4wkf] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [rggmzdn2oi] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [a72itwvbym] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [osdras14i4] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [1irnh9jal8] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [22xp5w0fsj] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [36v735jemu] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [elfhs0a8n4] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [vnr88obawf] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [al5y0hdldh] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [b8a7c8ibpn] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [hzmjpfuosr] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [9hdure9dwb] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [bsigbtz66k] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [0552c2oham] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [0r7oaj2jxy] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [33b84mmtk2] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [na455njn98] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [tlejsr6bor] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [jsguefhh7t] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [kdo13pvkri] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [bjjf2ko1za] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [jbnu12wglr] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [zd5ny5xxuj] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [iutes7arit] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [jspx244dae] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [5nc3ft9c83] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [bftol5hteo] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [cn7j8721gt] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [guexrdu6t6] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [e68bgfiium] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [xw2orfs340] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [v0vbpphn5h] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [gkuvzhtx3t] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [3xt67dhevn] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [zp2feaizrp] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [205nnz71pe] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [xw5u2e9rwj] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [r24b195lr4] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [hzvefx7730] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [k39nsv0m00] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [pfa9dym2fi] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [0mfb9rnjfc] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [c610fgyyaf] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [aivn6inakw] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [7tkhjxgwi3] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [jd9zbhw1og] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [74wc2o1loi] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [dl5ebxh74m] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [cy52gy008i] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [oprzenif3l] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [184xl5tl6p] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [88irxpvizs] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [c5o1llrnrr] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [dtzy9r5osd] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ybcwfgfvmg] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [rd986uiw5c] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [x5otbej42r] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [wau0mckf5h] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [303a6o66lu] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ynmjbxo4th] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [960ghmzixk] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [wmvwuwkl45] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [0e1d62lunv] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [k8wki2pxgs] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [509hos13kv] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [mj582udtmk] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [5pn0ooflxg] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [pl5h1v9egb] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [gj8w1pbvg3] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [d8127nakrg] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [had7iweua3] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [eeflhy4ebj] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [zrrnixxvez] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [n1pix3i7c5] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [w2blenkl8n] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [w2fv6uhg36] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [h97se3zsnt] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [xy16gt7ck2] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [5gnlgili4u] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [wddovzm4op] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [88acn9oei7] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [wxd4l7ouwt] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [3wl3h8lx1u] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [1or33eri1y] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [gn9njmtgcg] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [34ywax7wh0] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [1tulnufwxb] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [dj7ivjyase] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [w15o511xrw] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [8timcrbbmz] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [x3ghpx5ou6] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [pbepddum69] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [1vr8uhb7ze] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [euhckg1ele] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [9j5vrzgauc] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [y82reuo949] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [htud0k3jhu] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [12iawuhot8] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [4lm7lg0rpx] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [9prazev5eb] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [4yrzrysd6o] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [19hl5ccydv] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [o898mcmael] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [t8rzrkpkr3] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [t0ktmyw4ak] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [5jyplf7idn] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [kxi5yep6pv] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [zvxcf1x3ii] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [65iz98loug] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [vf9unef9tm] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [49cd8ab8vx] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [lfr14p0xbk] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [grr2g4jcid] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ksv2xolmjk] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [nm5o6yjit8] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [1ttjtj8rpx] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [amx3dfchs7] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [8vuvc735dd] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [peplhhfm73] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [262jo7p1b6] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [p2xz8zsh6u] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [gwi7m5uewe] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [ttf7sur354] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [boanv7wkv3] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [eplx9ife76] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [5uoeuyczuc] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [0ro9bykvkf] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [momyzz9bc2] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [o63jkamval] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [fnvodk7vub] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ly929fzz89] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [82lna2gix0] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [wve7xfw6u7] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [6rlru7wxzs] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [orgiawmx9z] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [gd3xfcbfvt] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ai4yfpwf31] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [57tti7g42u] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [xmoykaytt0] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [0v1m18ozty] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ogs8apfevr] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [9855g6rtyu] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [928pt2vk04] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [yczk7gf5za] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [89b0xlp8rb] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [maoxbig478] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [irjytv41h6] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [x61nl8mbmv] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [eot5y62pk1] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [kdzbypgrfa] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [s54yx7m6ap] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [4mgof61c31] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [gm2ixvub5l] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [pod29ry27w] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [wsn3g1zib9] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ct501oytlm] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [58ux3zfhbu] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [3978dpvzkz] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [tmtco5ngef] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [hxj72b81cm] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ugw591sfgp] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [rssu3lcf8d] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [e2rogs60ek] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [gwjohtacdw] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [eco75dyvx3] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [v45gh3wxhf] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [ss56o59ipu] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [6yvz1kztwi] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [fj0t02l75m] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [r9hxhpppbh] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [y4kzu6uv9u] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [u5kyalr28h] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [zgti8nixo2] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [utpigw629i] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [1zzkx2z235] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [sdto8hjrwl] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [eoitc9dprw] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [j6ozcujil4] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [92gtjt72bc] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [r90a3fwdcg] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [mjr5hugzbn] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [e2ofikwve8] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [3cfao0oglf] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [oxwsgc4djt] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [z2v2otwzjo] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [500g0rpamg] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [fv6txhy1s0] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [7pvtxixgrv] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [68zpxpiipw] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [viokbxb4o2] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [i9fjdme0j0] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [nmfprry483] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [xgjabm2vbd] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [wek4yz4i3j] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [cb5mev6vi0] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [e45yzghrta] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [rniw56s5nd] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [3ewtcv3crh] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [zplfr1wxpn] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [j0czwzdho7] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [6izd9xyr1k] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [o9j7ieb7pb] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [fhgri52l3h] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [y7r30t64ab] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [gki6nyx96v] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [r8u554630u] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [4j7mwgsew8] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [obuz751w3d] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [uo75e4sak5] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [acoxtr5lh7] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [4p7smjc2ug] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [g9tou9w9yj] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [5jjj7fguwr] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [a5ualtsg9a] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [o2hh2fzd3y] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [36s556usor] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ymmfui8ozo] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [63x0c4xxip] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [zbiht38sko] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [k3o46fd3jx] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [6vk6odge7b] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [znlww4opd9] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [a7hgjayxkk] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [wekmjzfjpb] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [d5b2h6ork6] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [pxo0ovzxf9] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [zpsj1r3ohj] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [za5f7tr7lx] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [lgtcmgafiz] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [rdx84k8ruc] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [s7yn0nluk2] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [i0wae9ww53] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [vj97lr6a86] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [yc80jkaf4w] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [xjbae46bv3] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ja19hmg8r1] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [4aj2b9glvn] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [d31crxgl9z] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [43vs24gc4k] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [u9l9kjg8th] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [tro6lsubri] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [o7k8a3g72g] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [5dz3ni9fsh] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [2npp2p21zo] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [itck7xv1op] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [vbphdl5ftt] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [y1xuc6hawo] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [kt19jekksi] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [a38ijbi1ip] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [4o0vg4x25z] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [exj69mmh4j] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [row3gb5n8m] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [n38hw4jyv5] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [mt9chhmkmb] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [yibhcb10g5] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [x8hr235ryr] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [8azkh0a8sv] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [6msz82zktb] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [zsntppuw42] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [12k79cjo6b] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [pcj2nj5aci] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [4s7lwcn72n] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ncpligy0y9] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [rlsryv015j] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [xs30o7t09s] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [wdk08kov9i] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [jb347mxlm1] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [san25gs50i] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [411sb5ajvm] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [k19pzy8m8n] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [gzcrtj04af] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [t8rrk62tem] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [esnv1rz37f] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [6fotwy90dk] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [vjhkhxxrko] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [cm54bp2kva] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [1xvrgwnx1g] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [jhfh615hvl] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [68xg8igepj] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [u7mp71bjgx] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [7446t7eb0r] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [moozjswxsy] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [v8z1ufcm4u] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [ofyewz2ogu] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [o9whgl49va] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [iv035jf5l3] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [9a18182fcd] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [8jfih14uns] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ym2ubk9nyc] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [z8217werp2] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [jyy3n5p49g] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [6nipg75dsj] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [f8vjbyhv5p] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [hgw7zibya3] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [6rl2dpxj9a] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [od6we89iiv] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [b0pdiosfri] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [cy2ho0mp8k] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ogf7np64bn] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [n57jj2nf8e] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [8ezrio45n3] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [1v6ei4j549] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [wb1fzgy2e6] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [xkdrlwzy24] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [bctufs3dch] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ne52nft8j5] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [atuy33lh98] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [enzx7kmfcs] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [e1vhl2etsj] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [zoo5nims9t] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [mbgfbgx7si] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [0gz0hwutvr] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [w7z11kutrl] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [09znkg17fo] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [7g7mhhyalp] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [tst4a5z76s] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [i0n3mvwbv0] C:\WINDOWS\KJTSBHL85N.EXE
O4 - HKLM\..\Run: [izeam4swz6] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [ad1c360zi0] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [e14prva1bz] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKLM\..\Run: [p8rl33zl3r] C:\WINDOWS\21KRCF5JYS.EXE
O4 - HKCU\..\Run: [Weather] C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Disk Master] C:\windows\diskserv.exe
O4 - HKCU\..\Run: [aimboot] %SystemRoot%\winrar.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra 'Tools' menuitem: Free Software Downloads (HKLM)
O9 - Extra 'Tools' menuitem: Search the Internet (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Kill popup (HKLM)
O9 - Extra 'Tools' menuitem: Kill popup (HKLM)
O9 - Extra button: WeatherBug (HKCU)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37893.854375
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potc_x.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {A7798D6C-C6B5-4F26-9363-F7CDBBFFA607} (download Class) - http://www.gigex.com/ActiveX/vxpspeeddelivery.dll
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v5.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - https://www.stopzilla.com/_download/Auto_Installer/dwnldr.cab
O19 - User stylesheet: C:\WINDOWS\Web\win.def
O19 - User stylesheet: C:\WINDOWS\default.css (HKLM)

Aaarggghhh!! that really looks bad...

It seems like this log was not made in normal windows mode...
... but, please run CoolWebShredder first:
CWShredder: http://www.merijn.org/files/CWShredder.exe
In case it's down: http://www.zerosrealm.com/downloads/CWShredder.zip

afterwards, run an online virusscan like:
http://www3.ca.com/virusinfo/virusscan.aspx

Run hijackthis again and get rid of all those stupid lines...
I personally think you have an IRC bot running (several)

This line might be the cause of all the troubles, get rid of it:
O4 - HKCU\..\Run: [aimboot] %SystemRoot%\winrar.exe
(make sure to delete this file also)