This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help on deleting virus / malware

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear Experts,

I think that i went into a strange site and caught onto a virus or malware of somekind. I am not sure what to do with it. I have trend micro pc-cillin as my antivirus, but it only get rid of 2 troj virus, and the problem still continue. At first i thought it was just having a lot of advertisement popup, but it came out that it isn't what all it does. My antivirus does mark some of the websites dangerous and prevent it from showing, but other ad sites still come out. It sometimes comes out and sometimes doesn't when i use my IE browser. Could i have multiple virus? or only 1?

Some of the effects they did on my computer is:

- Can't run anything on the sites of Windows update / Live onecare program
- Anytime I tried to go into website that contain antispyware or things like that, it redirects it automatically to other ad sites i donno.
- I think it disables my firewall and windows update.

Please help!

Sincerly,
ifeelgood

just more additional detail on virus….

i think it is start to force me to connect to internet (but those internet aren't usually the working ones) and close all antivirus and detections i can to detect the virus. It is also opening up programs without my command. My home page and hardware is also poping up… i think the virus deleted the driver for my wireless card?
Please help! thanks!

here is my hijackThis.log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 上午 08:13:40, on 2009/3/3
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\Internet Security\UfNavi.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live 登入小幫手 - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {e7a2aa93-8f32-4c9a-ad03-c1bd8dc4c7bb} - C:\WINDOWS\system32\vuvujake.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [CJIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync
O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [CPMdba4e900] Rundll32.exe "c:\windows\system32\hufopogi.dll",a
O4 - HKLM\..\Run: [d897da9c] rundll32.exe "C:\WINDOWS\system32\yepupoji.dll",b
O4 - HKLM\..\Run: [zawivugozi] Rundll32.exe "C:\WINDOWS\system32\zapekoge.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [zawivugozi] Rundll32.exe "C:\WINDOWS\system32\zapekoge.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] ctfmon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] ctfmon.exe (User 'Default user')
O9 - Extra button: 運行迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 運行迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: 參考資料 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=7&ar=msnhome
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {15AB0590-D322-4440-B129-BFC893FB3CC2} (AFCStarter_17FunTv Control) - http://live.17funtv.com:8057/AFCStarter_17funtv.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/ZH-TW/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5036.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1213927759390
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {9D8CCE0F-2E2C-41EB-B37F-9852DB989CAC} (WebLauncher Control) - http://www.ace-onlines.com/game/WebLauncher.cab
O16 - DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} (NowStarter Control) - http://www.gogobox.com.tw/neo.fld/GNowStarter.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\windows\system32\hufopogi.dll,C:\WINDOWS\system32\bubagike.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\hufopogi.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\hufopogi.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe

–
End of file - 8612 bytes

here is my hijackThis.log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 上午 08:13:40, on 2009/3/3
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\NETGEAR\WPN111\wpn111.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\Internet Security\UfNavi.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live 登入小幫手 - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {e7a2aa93-8f32-4c9a-ad03-c1bd8dc4c7bb} - C:\WINDOWS\system32\vuvujake.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [CJIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync
O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [CPMdba4e900] Rundll32.exe "c:\windows\system32\hufopogi.dll",a
O4 - HKLM\..\Run: [d897da9c] rundll32.exe "C:\WINDOWS\system32\yepupoji.dll",b
O4 - HKLM\..\Run: [zawivugozi] Rundll32.exe "C:\WINDOWS\system32\zapekoge.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [ctfmon.exe] ctfmon.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [zawivugozi] Rundll32.exe "C:\WINDOWS\system32\zapekoge.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [ctfmon.exe] ctfmon.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] ctfmon.exe (User 'Default user')
O9 - Extra button: 運行迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 運行迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: 參考資料 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=7&ar=msnhome
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {15AB0590-D322-4440-B129-BFC893FB3CC2} (AFCStarter_17FunTv Control) - http://live.17funtv.com:8057/AFCStarter_17funtv.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/ZH-TW/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5036.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1213927759390
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {9D8CCE0F-2E2C-41EB-B37F-9852DB989CAC} (WebLauncher Control) - http://www.ace-onlines.com/game/WebLauncher.cab
O16 - DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} (NowStarter Control) - http://www.gogobox.com.tw/neo.fld/GNowStarter.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\windows\system32\hufopogi.dll,C:\WINDOWS\system32\bubagike.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\hufopogi.dll
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\hufopogi.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe

–
End of file - 8612 bytes
Hi,

Download ComboFix by sUBs from here or here

Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

**Save it to your desktop**

Double click on ComboFix.exe & follow the prompts. If you are prompted to install the Recovery Console I recommend you go ahead and hit yes.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Notes:
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.
  • ComboFix disconnects your machine from the internet when it runs. This connection should be automatically restored when ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
I need to see another log from HijackThis.
  • Run Hijackthis.
  • Click on Open the Misc Tools section.
  • Next click on Open uninstall manager.
  • Press the Save list button.
  • Save the file to your desktop, with the default name of uninstall_list
  • Copy & Paste the entire contents of that file in your in your next post.
Thanks.
Thank you so much!! i donno how i am able to repay the debt
Here are both of the logs you requested, (my XP system is in trad. chinese.. which i think the reports came out in chinese,
I am very sorry about that >_>. didn't know that it would happen.) Also, i accidentally closed the Combofix log.. so i did a second scan,
so the log i paste now is the result from second scan… hope it doesn't have too much difference >_>…..

Combofix:

ComboFix 09-03-02.03 - user 2009-03-04 11:25:55.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.950.1.1028.18.2047.1579 [GMT 8:00]
執行位置: c:\documents and settings\user\桌面\ComboFix.exe
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated)
FW: 趨勢科技主控式個人防火牆 *disabled*
.

((((((((((((((((((((((((( 2009-02-04 至 2009-03-04 的新的檔案 )))))))))))))))))))))))))))))))
.

2009-03-03 20:27 . 2009-03-04 11:29 1,629,068 —hs—- c:\windows\system32\igagipak.ini
2009-03-03 08:27 . 2009-03-03 08:48 1,629,035 —hs—- c:\windows\system32\agiziway.ini
2009-03-02 09:10 . 2009-03-02 09:10 121 —hs—- c:\windows\system32\ijopupey.ini
2009-02-28 12:42 . 2008-06-18 03:01 8,321,536 —–c— c:\windows\system32\dllcache\shell32.dll
2009-02-26 20:12 . 2009-02-26 20:12 d——– c:\program files\MP3 Player Utilities 4.00
2009-02-24 22:04 . 2009-02-15 12:15 d——– c:\program files\AviSynth 2.5
2009-02-12 19:27 . 2009-02-12 19:27 d——– c:\program files\feng

.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-04 03:28 0 —-a-w c:\windows\system32\drivers\lvuvc.hs
2009-03-04 03:28 0 —-a-w c:\windows\system32\drivers\logiflt.iad
2009-03-03 00:13 ——— d—–w c:\program files\Trend Micro
2009-03-02 04:20 ——— d—–w c:\program files\Cheat Engine
2009-03-01 09:41 ——— d—–w c:\documents and settings\user\Application Data\Skype
2009-03-01 08:32 ——— d—–w c:\documents and settings\user\Application Data\skypePM
2009-02-26 00:34 ——— d—–w c:\program files\NextLink
2009-02-15 04:22 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-15 03:06 ——— d—–w c:\program files\捃濘儂桵Online
2009-01-17 22:46 ——— d—–w c:\program files\DAEMON Tools Toolbar
2009-01-08 01:26 ——— d—–w c:\documents and settings\user\Application Data\Media Player Classic
2008-12-22 09:15 31 —-a-w c:\documents and settings\user\jagex_runescape_preferences.dat
2006-05-03 09:06 163,328 –sh–r c:\windows\system32\flvDX.dll
2007-02-21 10:47 31,232 –sh–r c:\windows\system32\msfDX.dll
1601-01-01 00:12 47,616 –sha-w c:\windows\system32\zapekoge.dll
.

——- Sigcheck ——-

2008-06-20 19:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2006-03-02 20:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtServicePackUninstall$\tcpip.sys
2008-04-14 03:20 361344 607c976b22aeb2fcf8a7486bcca1e3bf c:\windows\$NtUninstallKB951748$\tcpip.sys
2008-04-14 03:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\ServicePackFiles\i386\tcpip.sys
2008-06-20 19:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\system32\dllcache\tcpip.sys
2008-06-20 19:51 361600 4afb3b0919649f95c1964aa1fad27d73 c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-03-04_11.08.03.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-04 03:28:37 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_b0.dat
.
((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e7a2aa93-8f32-4c9a-ad03-c1bd8dc4c7bb}]
c:\windows\system32\vuvujake.dll [BU]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Gadwin PrintScreen"="c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2007-08-20 495616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-03-02 208952]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-30 196608]
"CJIMETIPSYNC"="c:\program files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE" [2007-03-22 66400]
"PHIMETIPSYNC"="c:\program files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE" [2007-03-22 98656]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-19 136600]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1393928]
"zawivugozi"="c:\windows\system32\zapekoge.dll" [1601-01-01 47616]
"d897da9c"="c:\windows\system32\kapigagi.dll" [2009-03-03 79872]
"CPMdba4e900"="c:\windows\system32\kunuzavi.dll" [2009-03-03 84992]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-16 185896]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-18 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [2008-04-15 c:\windows\system32\ctfmon.exe]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}"= "c:\windows\system32\kunuzavi.dll" [2009-03-03 84992]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"= {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\kunuzavi.dll [2009-03-03 84992]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\kunuzavi.dll,c:\windows\system32\bubagike.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"msacm.divxa32"= divxa32.acm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\windows\system32\bubagike.dll

[HKLM\~\startupfolder\C:^Documents and Settings^user^「開始」功能表^程式集^啟動^Adobe Gamma.lnk]
path=c:\documents and settings\user\「開始」功能表\程式集\啟動\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
–a—— 2007-06-20 12:49 451872 c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-01 15:57 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-10-16 12:12 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\NextLink\\GOGOBOX\\gogobox.exe"=
"c:\\Program Files\\NextLink\\GOGOBOX\\gfscagent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Thunder Network\\Thunder\\Program\\Thunder5.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Trend Micro\\Internet Security\\TmProxy.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\VS7DEBUG\\MDM.EXE"=
"c:\\WINDOWS\\explorer.exe"=

R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-03-11 36368]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2008-03-11 333328]
R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [2008-07-19 362944]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2008-07-25 52240]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;\??\c:\windows\system32\DNINDIS5.SYS –> c:\windows\system32\DNINDIS5.SYS [?]
S3 dump_wmimmc;dump_wmimmc;\??\c:\program files\softnyx\GunboundWC\GameGuard\dump_wmimmc.sys –> c:\program files\softnyx\GunboundWC\GameGuard\dump_wmimmc.sys [?]
S3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2008-07-25 488768]
S3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-07-25 648456]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e7e8548-c580-11dd-91c2-001e2ae2c72d}]
\Shell\Auto\command - auto.exe
\Shell\AutoRun\command - auto.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
‘計劃任務’ 文件夾 裡的內容

2009-02-12 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []

2008-08-04 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
.
——- 而外的掃描 ——-
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://www.synnex.com.tw/
uInternet Settings,ProxyOverride = local
IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - c:\program files\Thunder Network\Thunder\Thunder.exe
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\CoreFTP\pftpns.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {15AB0590-D322-4440-B129-BFC893FB3CC2} - hxxp://live.17funtv.com:8057/AFCStarter_17funtv.cab
DPF: {9D8CCE0F-2E2C-41EB-B37F-9852DB989CAC} - hxxp://www.ace-onlines.com/game/WebLauncher.cab
DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} - hxxp://www.gogobox.com.tw/neo.fld/GNowStarter.cab
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\8jddzzr5.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-04 11:29:32
Windows 5.1.2600 Service Pack 3 NTFS

掃描被隱藏的進程 。。。

掃描被隱藏的啟動組 。。。

掃描被隱藏的文件 。。。

掃描完成
被隱藏的檔案: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1547161642-1580436667-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\a*悐kuUO悐+o N 
"Order"=hex:08,00,00,00,02,00,00,00,fe,02,00,00,01,00,00,00,06,00,00,00,ba,00,
00,00,00,00,00,00,ac,00,32,00,c2,01,00,00,18,39,68,1c,20,00,38,43,4f,4d,49,\

[HKEY_USERS\S-1-5-21-1547161642-1580436667-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\m*悐kuUO悐+o N 
"Order"=hex:08,00,00,00,02,00,00,00,0a,02,00,00,01,00,00,00,04,00,00,00,ba,00,
00,00,00,00,00,00,ac,00,32,00,c2,01,00,00,18,39,68,1c,20,00,38,43,4f,4d,49,\

[HKEY_USERS\S-1-5-21-1547161642-1580436667-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\v*悐kuUO悐+o N 
"Order"=hex:08,00,00,00,02,00,00,00,96,02,00,00,01,00,00,00,05,00,00,00,ba,00,
00,00,00,00,00,00,ac,00,32,00,c2,01,00,00,18,39,68,1c,20,00,38,43,4f,4d,49,\

[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ譸\CLSID]
@="{809B6661-94C4-49E6-B6EC-3F0F862215AA}"

[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ譸\CurVer]
@="BDATuner.元件.1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\SUPER *]
"DisplayName"="SUPER ?Version 2007.bld.23 (July 4, 2007)"
"UninstallString"="c:\\PROGRA~1\\ERIGHT~1\\SUPER\\Setup.exe /remove /q0"
"InstallDate"="2008-08-06 06:36:01"
"InstallLocation"="c:\\Program Files\\eRightSoft\\SUPER"
"InstallSource"="k:\\Backup\\軟體"
"DisplayIcon"="c:\\Program Files\\eRightSoft\\SUPER\\SUPER.exe"
"DisplayVersion"="Version 2007.bld.23 (July 4, 2007)"
"VersionMajor"=dword:00000000
"VersionMinor"=dword:00000000
"Publisher"="eRightSoft"
"HelpLink"="http://www.eRightSoft.com"
"URLInfoAbout"="http://www.eRightSoft.com"
"URLUpdateInfo"="http://www.eRightSoft.com"
"Contact"="[removed]"
.
———————— 其他運行進程 ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\conime.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Windows Live\Messenger\usnsvc.exe
.
**************************************************************************
.
完成時間: 2009-03-04 11:31:21 - 電腦已重新啟動
ComboFix-quarantined-files.txt 2009-03-04 03:31:19
ComboFix2.txt 2009-03-04 03:08:52

Pre-Run: 100,184,387,584 位元組可用
Post-Run: 100,173,541,376 位元組可用

212 — E O F — 2008-12-19 15:09:31

Hijack This uninstall log:

Adobe Bridge 1.0
Adobe Common File Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 8.1.2 - Chinese Traditional
Adobe Shockwave Player 11
Adobe Stock Photos 1.0
Brother MFL-Pro Suite
Cheat Engine 5.4
Core FTP LE 2.1
Gadwin PrintScreen
GOGOBOX
Halo CE Cracked Setup
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
hp deskjet 970c series
hp deskjet 970c series (僅限移除)
Intel® Graphics Media Accelerator Driver
iTunes
Java™ 6 Update 11
Java™ 6 Update 2
Java™ 6 Update 7
Little Fighter 2 version 2.0
Logitech QuickCam 驅動程式套裝軟體
Macromedia Dreamweaver 8
Macromedia Extension Manager
Macromedia Fireworks 8
Macromedia Flash 8
Macromedia Flash 8 Video Encoder
Microsoft AppLocale
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Office Standard Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Windows Application Compatibility Database
Mozilla Firefox (3.0.6)
MP3 Player Utilities 4.00
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 Parser and SDK
Nero 7 Essentials
neroxml
NETGEAR RangeMax™ Wireless USB 2.0 Adapter WPN111
NVIDIA Drivers
PowerDVD
QuickTime
Ragnarok Online
Ragnarok Sakray
RealPlayer
Realtek High Definition Audio Driver
Samsung PC Studio 7
SamsungConnectivityCableDriver
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Skype™ 3.8
Trend Micro Internet Security
Trend Micro Internet Security
Vista Codec Package
Windows Internet Explorer 7
Windows Internet Explorer 7 安全性更新 (KB938127-v2)
Windows Internet Explorer 7 安全性更新 (KB950759)
Windows Internet Explorer 7 安全性更新 (KB953838)
Windows Internet Explorer 7 安全性更新 (KB956390)
Windows Internet Explorer 7 安全性更新 (KB958215)
Windows Internet Explorer 7 安全性更新 (KB960714)
Windows Internet Explorer 7 安全性更新 (KB961260)
Windows Live installer
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live 登入小幫手
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Media Player 11 Hotfix (KB939683)
Windows Media Player 11 安全性更新 (KB936782)
Windows Media Player 11 安全性更新 (KB954154)
Windows Media Player 安全性更新 (KB952069)
Windows XP Hotfix (KB952287)
Windows XP Service Pack 3
Windows XP 安全性更新 (KB923789)
Windows XP 安全性更新 (KB938464)
Windows XP 安全性更新 (KB941569)
Windows XP 安全性更新 (KB950759)
Windows XP 安全性更新 (KB950760)
Windows XP 安全性更新 (KB950762)
Windows XP 安全性更新 (KB950974)
Windows XP 安全性更新 (KB951066)
Windows XP 安全性更新 (KB951376-v2)
Windows XP 安全性更新 (KB951698)
Windows XP 安全性更新 (KB951748)
Windows XP 安全性更新 (KB952954)
Windows XP 安全性更新 (KB953839)
Windows XP 安全性更新 (KB954211)
Windows XP 安全性更新 (KB954459)
Windows XP 安全性更新 (KB954600)
Windows XP 安全性更新 (KB955069)
Windows XP 安全性更新 (KB956391)
Windows XP 安全性更新 (KB956802)
Windows XP 安全性更新 (KB956803)
Windows XP 安全性更新 (KB956841)
Windows XP 安全性更新 (KB957095)
Windows XP 安全性更新 (KB957097)
Windows XP 安全性更新 (KB958644)
Windows XP 安全性更新 (KB958687)
Windows XP 安全性更新 (KB960715)
Windows XP 更新 (KB942763)
Windows XP 更新 (KB951072-v2)
Windows XP 更新 (KB951978)
Windows XP 更新 (KB955839)
Windows XP 更新 (KB967715)
WinRAR 壓縮工具
迅雷5
迅雷机?Online

I would also like to ask a question…
Is it ok for me to backup stuff? or would like the virus infect into my external hard drive also?
And if that's the case (i think i plugged in the hard drive some time when i notice i caught the virus),
do i also need to plug in my hard drive on the next test?

Thank you so MUCH for your help!
Hi,

You can plug your harddrive in and have Trend Micro scan it to check it out.

Please click Start >> Control Panel >> Add or Remove Programs.
Find each of the below items on the list and click remove on each one.
Java™ 6 Update 2
Java™ 6 Update 7



1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

file::
c:\windows\system32\igagipak.ini
c:\windows\system32\agiziway.ini
c:\windows\system32\ijopupey.ini
c:\windows\system32\drivers\lvuvc.hs
c:\windows\system32\drivers\logiflt.iad
c:\windows\system32\flvDX.dll
c:\windows\system32\msfDX.dll
c:\windows\system32\zapekoge.dll
c:\windows\system32\vuvujake.dll
c:\windows\system32\zapekoge.dll
c:\windows\system32\kapigagi.dll
c:\windows\system32\kunuzavi.dll
c:\windows\system32\bubagike.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e7a2aa93-8f32-4c9a-ad03-c1bd8dc4c7bb}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"zawivugozi"=-
"d897da9c"=-
"CPMdba4e900"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SSODL"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"=hex(7):73,63,65,63,6c,69,00,00
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e7e8548-c580-11dd-91c2-001e2ae2c72d}]

DDS::
DPF: {15AB0590-D322-4440-B129-BFC893FB3CC2} - hxxp://live.17funtv.com:8057/AFCStarter_17funtv.cab
DPF: {9D8CCE0F-2E2C-41EB-B37F-9852DB989CAC} - hxxp://www.ace-onlines.com/game/WebLauncher.cab
DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} - hxxp://www.gogobox.com.tw/neo.fld/GNowStarter.cab

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Let me know how the computer is running now.

Thanks.
Thanks a lot!! I felt like my computer is clear of virus :thumbup:
The previous problem I have with pop-up that always have the website "… adtrgt.com……" didn't pop up or get intercepted by my Pc-cillin antivirus
this time when i open my browser. Also, the microsoft warning sign on firewall, and windows update popped up!
My internet is also faster than before. But the only problem i still have is that i use a program called "Netgear" to search
for routers, and i can no longer open it. Also, when i open the wireless internet connection, the thing doesn't let me
find any other router. I am currently using one of the free internet on what the wireless adapter finds.

Here is my virus scan (before combofix …. (tell me if you need a newer one, i think i got the steps wrong)

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Wednesday, March 4, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, March 04, 2009 13:15:53
Records in database: 1868277
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\

Scan statistics:
Files scanned: 93613
Threat name: 2
Infected objects: 5
Suspicious objects: 0
Duration of the scan: 01:26:00


File name / Threat name / Threats count
C:\Documents and Settings\user\桌面\AMV_Convert_400.zip Infected: not-a-virus:RiskTool.Win32.Deleter.e 1
C:\Program Files\MP3 Player Utilities 4.00\DelDrv.exe Infected: not-a-virus:RiskTool.Win32.Deleter.e 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekakpsvaiwj.dll.vir Infected: Packed.Win32.Tdss.c 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekanruuyodr.dll.vir Infected: Packed.Win32.Tdss.c 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\senekaowqersad.dll.vir Infected: Packed.Win32.Tdss.c 1

The selected area was scanned.


Combofix log:

ComboFix 09-03-03.01 - user 2009-03-04 23:09:02.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.950.1.1028.18.2047.1351 [GMT 8:00]
執行位置: c:\documents and settings\user\桌面\ComboFix.exe
Command switches used :: c:\documents and settings\user\桌面\CFScript.txt
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated)
FW: 趨勢科技主控式個人防火牆 *disabled*
* 成功創造新還原點

FILE ::
c:\windows\system32\agiziway.ini
c:\windows\system32\bubagike.dll
c:\windows\system32\drivers\logiflt.iad
c:\windows\system32\drivers\lvuvc.hs
c:\windows\system32\flvDX.dll
c:\windows\system32\igagipak.ini
c:\windows\system32\ijopupey.ini
c:\windows\system32\kapigagi.dll
c:\windows\system32\kunuzavi.dll
c:\windows\system32\msfDX.dll
c:\windows\system32\vuvujake.dll
c:\windows\system32\zapekoge.dll
.

((((((((((((((((((((((((((((((((((((((( 被刪除的檔案 )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\agiziway.ini
c:\windows\system32\drivers\logiflt.iad
c:\windows\system32\drivers\lvuvc.hs
c:\windows\system32\flvDX.dll
c:\windows\system32\igagipak.ini
c:\windows\system32\ijopupey.ini
c:\windows\system32\kajorila.dll
c:\windows\system32\kapigagi.dll
c:\windows\system32\kunuzavi.dll
c:\windows\system32\msfDX.dll
c:\windows\system32\quttwn.dll
c:\windows\system32\zapekoge.dll

.
((((((((((((((((((((((((( 2009-02-04 至 2009-03-04 的新的檔案 )))))))))))))))))))))))))))))))
.

2009-03-04 22:06 . 2009-03-04 22:29 1,800,745 —hs—- c:\windows\system32\ewulebik.ini
2009-02-28 12:42 . 2008-06-18 03:01 8,321,536 —–c— c:\windows\system32\dllcache\shell32.dll
2009-02-26 20:12 . 2009-02-26 20:12 d——– c:\program files\MP3 Player Utilities 4.00
2009-02-24 22:04 . 2009-02-15 12:15 d——– c:\program files\AviSynth 2.5
2009-02-12 19:27 . 2009-02-12 19:27 d——– c:\program files\feng

.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-04 12:21 ——— d—–w c:\program files\Java
2009-03-03 00:13 ——— d—–w c:\program files\Trend Micro
2009-03-02 04:20 ——— d—–w c:\program files\Cheat Engine
2009-03-01 09:41 ——— d—–w c:\documents and settings\user\Application Data\Skype
2009-03-01 08:32 ——— d—–w c:\documents and settings\user\Application Data\skypePM
2009-02-26 00:34 ——— d—–w c:\program files\NextLink
2009-02-15 04:22 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-15 03:06 ——— d—–w c:\program files\捃濘儂桵Online
2009-01-17 22:46 ——— d—–w c:\program files\DAEMON Tools Toolbar
2009-01-08 01:26 ——— d—–w c:\documents and settings\user\Application Data\Media Player Classic
2008-12-22 09:15 31 —-a-w c:\documents and settings\user\jagex_runescape_preferences.dat
.

——- Sigcheck ——-

2008-06-20 19:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2006-03-02 20:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtServicePackUninstall$\tcpip.sys
2008-04-14 03:20 361344 607c976b22aeb2fcf8a7486bcca1e3bf c:\windows\$NtUninstallKB951748$\tcpip.sys
2008-04-14 03:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\ServicePackFiles\i386\tcpip.sys
2008-06-20 19:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\system32\dllcache\tcpip.sys
2008-06-20 19:51 361600 4afb3b0919649f95c1964aa1fad27d73 c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-03-04_11.08.03.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-04 14:06:31 79,872 –sha-w c:\windows\system32\kibeluwe.dll
+ 2009-03-04 14:06:33 84,992 –sha-w c:\windows\system32\lanabiya.dll
+ 2009-03-04 15:12:01 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_94.dat
.
((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Gadwin PrintScreen"="c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2007-08-20 495616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-03-02 208952]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-30 196608]
"CJIMETIPSYNC"="c:\program files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE" [2007-03-22 66400]
"PHIMETIPSYNC"="c:\program files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE" [2007-03-22 98656]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1393928]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-16 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-19 136600]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-18 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [2008-04-15 c:\windows\system32\ctfmon.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm

[HKLM\~\startupfolder\C:^Documents and Settings^user^「開始」功能表^程式集^啟動^Adobe Gamma.lnk]
path=c:\documents and settings\user\「開始」功能表\程式集\啟動\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
–a—— 2007-06-20 12:49 451872 c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-01 15:57 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-10-16 12:12 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\NextLink\\GOGOBOX\\gogobox.exe"=
"c:\\Program Files\\NextLink\\GOGOBOX\\gfscagent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Thunder Network\\Thunder\\Program\\Thunder5.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Trend Micro\\Internet Security\\TmProxy.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\VS7DEBUG\\MDM.EXE"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=

R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-03-11 36368]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2008-03-11 333328]
R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [2008-07-19 362944]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2008-07-25 52240]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;\??\c:\windows\system32\DNINDIS5.SYS –> c:\windows\system32\DNINDIS5.SYS [?]
S3 dump_wmimmc;dump_wmimmc;\??\c:\program files\softnyx\GunboundWC\GameGuard\dump_wmimmc.sys –> c:\program files\softnyx\GunboundWC\GameGuard\dump_wmimmc.sys [?]
S3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2008-07-25 488768]
S3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-07-25 648456]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
‘計劃任務’ 文件夾 裡的內容

2009-02-12 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []

2008-08-04 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
- - - - ORPHANS REMOVED - - - -

BHO-{6d6b3126-ba68-40d3-aa4c-df4903b82f2c} - c:\windows\system32\quttwn.dll


.
——- 而外的掃描 ——-
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://www.synnex.com.tw/
uInternet Settings,ProxyOverride = local
IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - c:\program files\Thunder Network\Thunder\Thunder.exe
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\CoreFTP\pftpns.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {15AB0590-D322-4440-B129-BFC893FB3CC2} - hxxp://live.17funtv.com:8057/AFCStarter_17funtv.cab
DPF: {9D8CCE0F-2E2C-41EB-B37F-9852DB989CAC} - hxxp://www.ace-onlines.com/game/WebLauncher.cab
DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} - hxxp://www.gogobox.com.tw/neo.fld/GNowStarter.cab
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\8jddzzr5.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-04 23:13:13
Windows 5.1.2600 Service Pack 3 NTFS

掃描被隱藏的進程 。。。

掃描被隱藏的啟動組 。。。

掃描被隱藏的文件 。。。

掃描完成
被隱藏的檔案: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1547161642-1580436667-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\a*悐kuUO悐+o N 
"Order"=hex:08,00,00,00,02,00,00,00,fe,02,00,00,01,00,00,00,06,00,00,00,ba,00,
00,00,00,00,00,00,ac,00,32,00,c2,01,00,00,18,39,68,1c,20,00,38,43,4f,4d,49,\

[HKEY_USERS\S-1-5-21-1547161642-1580436667-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\m*悐kuUO悐+o N 
"Order"=hex:08,00,00,00,02,00,00,00,0a,02,00,00,01,00,00,00,04,00,00,00,ba,00,
00,00,00,00,00,00,ac,00,32,00,c2,01,00,00,18,39,68,1c,20,00,38,43,4f,4d,49,\

[HKEY_USERS\S-1-5-21-1547161642-1580436667-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\v*悐kuUO悐+o N 
"Order"=hex:08,00,00,00,02,00,00,00,96,02,00,00,01,00,00,00,05,00,00,00,ba,00,
00,00,00,00,00,00,ac,00,32,00,c2,01,00,00,18,39,68,1c,20,00,38,43,4f,4d,49,\

[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ譸\CLSID]
@="{809B6661-94C4-49E6-B6EC-3F0F862215AA}"

[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ譸\CurVer]
@="BDATuner.元件.1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\SUPER *]
"DisplayName"="SUPER ?Version 2007.bld.23 (July 4, 2007)"
"UninstallString"="c:\\PROGRA~1\\ERIGHT~1\\SUPER\\Setup.exe /remove /q0"
"InstallDate"="2008-08-06 06:36:01"
"InstallLocation"="c:\\Program Files\\eRightSoft\\SUPER"
"InstallSource"="k:\\Backup\\軟體"
"DisplayIcon"="c:\\Program Files\\eRightSoft\\SUPER\\SUPER.exe"
"DisplayVersion"="Version 2007.bld.23 (July 4, 2007)"
"VersionMajor"=dword:00000000
"VersionMinor"=dword:00000000
"Publisher"="eRightSoft"
"HelpLink"="http://www.eRightSoft.com"
"URLInfoAbout"="http://www.eRightSoft.com"
"URLUpdateInfo"="http://www.eRightSoft.com"
"Contact"="[removed]"
.
———————— 其他運行進程 ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\conime.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
完成時間: 2009-03-04 23:15:02 - 電腦已重新啟動
ComboFix-quarantined-files.txt 2009-03-04 15:14:59
ComboFix2.txt 2009-03-04 03:31:22
ComboFix3.txt 2009-03-04 03:08:52

Pre-Run: 100,183,371,776 位元組可用
Post-Run: 100,233,568,256 位元組可用

223 — E O F — 2008-12-19 15:09:31



I also have like a question……
While running combo fix, it says in chinese something about changing original files.
Is that going to affect my computer in the future when i use the previous option i have
inside my computer on "restore back to factory settings"? or it doesn't?

Once again! thanks a lot :notworthy:
Hi,

Did the Netgear problem start happening with the infections or only since we started cleaning it?

Hmm, I'm not sure what "changing original files" is referring to. It shouldn't affect "restore back to factory settings" whatever it is.

We need to run ComboFix again, like last time. Please use this script:
File::
c:\windows\system32\ewulebik.ini
c:\windows\system32\kibeluwe.dll
c:\windows\system32\lanabiya.dll

DDS::
DPF: {15AB0590-D322-4440-B129-BFC893FB3CC2}
DPF: {9D8CCE0F-2E2C-41EB-B37F-9852DB989CAC}
DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0}
Use the same steps as before.

Let me know how things are running after this.

Please also do this. Please go to this site:
Bleeping Computer Submission

Please paste a link to this topic in the first field. Browse to the following file:
C:\Qoobox\Quarantine\C\WINDOWS\system32\msfDx.dll

Click Send File.

Thanks.
Hi! thanks again, my computer seems functioning back to normal.

The Netgear problem started to happen 2 days after i notice the unusual popup of adtrgt.com thing
and being blocked by trend mico pc-cillin program. Then it started to ask me, until now, everytime when
i open the computer for the driver for that wireless adapter. I hope i can find the disk, but internet
still works fine without the driver… just that i can't choose which internet connection router i want.

Also, i submitted the sample you requested below.. but i didn't find that file, other than with a ".vir" in it.
Is that the correct file you want me to send for submission?

I also found a new problem just now…. my CD rom's E and F (i think that's what their previous name setting are)
are gone >_>…. i can no longer get them out, is that due to the virus? I tried to put in CD, but there was no response from the computer.


Here is the ComboFix Log :

ComboFix 09-03-03.01 - user 2009-03-05 9:14:43.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.950.1.1028.18.2047.1608 [GMT 8:00]
執行位置: c:\documents and settings\user\桌面\ComboFix.exe
Command switches used :: c:\documents and settings\user\桌面\CFScript.txt
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated)
FW: 趨勢科技主控式個人防火牆 *disabled*
* 成功創造新還原點

FILE ::
c:\windows\system32\ewulebik.ini
c:\windows\system32\kibeluwe.dll
c:\windows\system32\lanabiya.dll
.

((((((((((((((((((((((((((((((((((((((( 被刪除的檔案 )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\ewulebik.ini
c:\windows\system32\kibeluwe.dll
c:\windows\system32\lanabiya.dll

.
((((((((((((((((((((((((( 2009-02-05 至 2009-03-05 的新的檔案 )))))))))))))))))))))))))))))))
.

2009-03-05 08:06 . 2009-03-05 08:06 0 –a—— c:\windows\system32\drivers\lvuvc.hs
2009-02-28 12:42 . 2008-06-18 03:01 8,321,536 —–c— c:\windows\system32\dllcache\shell32.dll
2009-02-26 20:12 . 2009-02-26 20:12 d——– c:\program files\MP3 Player Utilities 4.00
2009-02-24 22:04 . 2009-02-15 12:15 d——– c:\program files\AviSynth 2.5
2009-02-12 19:27 . 2009-02-12 19:27 d——– c:\program files\feng

.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-04 12:21 ——— d—–w c:\program files\Java
2009-03-03 00:27 84,992 –sha-w c:\windows\system32\bijukotu.dll
2009-03-03 00:27 79,872 ——w c:\windows\system32\yawiziga.dll
2009-03-03 00:13 ——— d—–w c:\program files\Trend Micro
2009-03-02 04:20 ——— d—–w c:\program files\Cheat Engine
2009-03-02 01:10 84,992 –sha-w c:\windows\system32\hufopogi.dll
2009-03-02 01:10 79,872 ——w c:\windows\system32\yepupoji.dll
2009-03-01 09:41 ——— d—–w c:\documents and settings\user\Application Data\Skype
2009-03-01 08:32 ——— d—–w c:\documents and settings\user\Application Data\skypePM
2009-02-26 00:34 ——— d—–w c:\program files\NextLink
2009-02-15 04:22 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-15 03:06 ——— d—–w c:\program files\捃濘儂桵Online
2009-01-17 22:46 ——— d—–w c:\program files\DAEMON Tools Toolbar
2009-01-08 01:26 ——— d—–w c:\documents and settings\user\Application Data\Media Player Classic
2008-12-22 09:15 31 —-a-w c:\documents and settings\user\jagex_runescape_preferences.dat
2008-12-20 22:31 826,368 —-a-w c:\windows\system32\wininet.dll
2008-12-18 23:53 410,984 —-a-w c:\windows\system32\deploytk.dll
.

——- Sigcheck ——-

2008-06-20 19:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2006-03-02 20:00 359040 9f4b36614a0fc234525ba224957de55c c:\windows\$NtServicePackUninstall$\tcpip.sys
2008-04-14 03:20 361344 607c976b22aeb2fcf8a7486bcca1e3bf c:\windows\$NtUninstallKB951748$\tcpip.sys
2008-04-14 03:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\ServicePackFiles\i386\tcpip.sys
2008-06-20 19:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\system32\dllcache\tcpip.sys
2008-06-20 19:51 361600 4afb3b0919649f95c1964aa1fad27d73 c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-03-04_11.08.03.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-05 00:06:39 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_80.dat
.
((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Gadwin PrintScreen"="c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2007-08-20 495616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-03-02 208952]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-30 196608]
"CJIMETIPSYNC"="c:\program files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE" [2007-03-22 66400]
"PHIMETIPSYNC"="c:\program files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE" [2007-03-22 98656]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1393928]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-16 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-19 136600]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-18 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [2008-04-15 c:\windows\system32\ctfmon.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm

[HKLM\~\startupfolder\C:^Documents and Settings^user^「開始」功能表^程式集^啟動^Adobe Gamma.lnk]
path=c:\documents and settings\user\「開始」功能表\程式集\啟動\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
–a—— 2007-06-20 12:49 451872 c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-01 15:57 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-10-16 12:12 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\NextLink\\GOGOBOX\\gogobox.exe"=
"c:\\Program Files\\NextLink\\GOGOBOX\\gfscagent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Thunder Network\\Thunder\\Program\\Thunder5.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Trend Micro\\Internet Security\\TmProxy.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\VS7DEBUG\\MDM.EXE"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=

R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-03-11 36368]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2008-03-11 333328]
R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [2008-07-19 362944]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2008-07-25 52240]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;\??\c:\windows\system32\DNINDIS5.SYS –> c:\windows\system32\DNINDIS5.SYS [?]
S3 dump_wmimmc;dump_wmimmc;\??\c:\program files\softnyx\GunboundWC\GameGuard\dump_wmimmc.sys –> c:\program files\softnyx\GunboundWC\GameGuard\dump_wmimmc.sys [?]
S3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2008-07-25 488768]
S3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-07-25 648456]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
‘計劃任務’ 文件夾 裡的內容

2009-02-12 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []

2008-08-04 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
.
——- 而外的掃描 ——-
.
uStart Page = hxxp://www.google.com.tw/
uInternet Connection Wizard,ShellNext = hxxp://www.synnex.com.tw/
uInternet Settings,ProxyOverride = local
IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - c:\program files\Thunder Network\Thunder\Thunder.exe
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\CoreFTP\pftpns.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {15AB0590-D322-4440-B129-BFC893FB3CC2} - hxxp://live.17funtv.com:8057/AFCStarter_17funtv.cab
DPF: {9D8CCE0F-2E2C-41EB-B37F-9852DB989CAC} - hxxp://www.ace-onlines.com/game/WebLauncher.cab
DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} - hxxp://www.gogobox.com.tw/neo.fld/GNowStarter.cab
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\8jddzzr5.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-05 09:16:01
Windows 5.1.2600 Service Pack 3 NTFS

掃描被隱藏的進程 。。。

掃描被隱藏的啟動組 。。。

掃描被隱藏的文件 。。。

掃描完成
被隱藏的檔案: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1547161642-1580436667-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\a*悐kuUO悐+o N 
"Order"=hex:08,00,00,00,02,00,00,00,fe,02,00,00,01,00,00,00,06,00,00,00,ba,00,
00,00,00,00,00,00,ac,00,32,00,c2,01,00,00,18,39,68,1c,20,00,38,43,4f,4d,49,\

[HKEY_USERS\S-1-5-21-1547161642-1580436667-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\m*悐kuUO悐+o N 
"Order"=hex:08,00,00,00,02,00,00,00,0a,02,00,00,01,00,00,00,04,00,00,00,ba,00,
00,00,00,00,00,00,ac,00,32,00,c2,01,00,00,18,39,68,1c,20,00,38,43,4f,4d,49,\

[HKEY_USERS\S-1-5-21-1547161642-1580436667-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\v*悐kuUO悐+o N 
"Order"=hex:08,00,00,00,02,00,00,00,96,02,00,00,01,00,00,00,05,00,00,00,ba,00,
00,00,00,00,00,00,ac,00,32,00,c2,01,00,00,18,39,68,1c,20,00,38,43,4f,4d,49,\

[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ譸\CLSID]
@="{809B6661-94C4-49E6-B6EC-3F0F862215AA}"

[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ譸\CurVer]
@="BDATuner.元件.1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\SUPER *]
"DisplayName"="SUPER ?Version 2007.bld.23 (July 4, 2007)"
"UninstallString"="c:\\PROGRA~1\\ERIGHT~1\\SUPER\\Setup.exe /remove /q0"
"InstallDate"="2008-08-06 06:36:01"
"InstallLocation"="c:\\Program Files\\eRightSoft\\SUPER"
"InstallSource"="k:\\Backup\\軟體"
"DisplayIcon"="c:\\Program Files\\eRightSoft\\SUPER\\SUPER.exe"
"DisplayVersion"="Version 2007.bld.23 (July 4, 2007)"
"VersionMajor"=dword:00000000
"VersionMinor"=dword:00000000
"Publisher"="eRightSoft"
"HelpLink"="http://www.eRightSoft.com"
"URLInfoAbout"="http://www.eRightSoft.com"
"URLUpdateInfo"="http://www.eRightSoft.com"
"Contact"="[removed]"
.
完成時間: 2009-03-05 9:17:03
ComboFix-quarantined-files.txt 2009-03-05 01:17:00
ComboFix2.txt 2009-03-04 15:15:03
ComboFix3.txt 2009-03-04 03:31:22
ComboFix4.txt 2009-03-04 03:08:52

Pre-Run: 100,234,670,080 位元組可用
Post-Run: 100,219,826,176 位元組可用

196 — E O F — 2008-12-19 15:09:31


Thank you so much :D without you, my computer might be dead by now already XD.

Also, do u want me to have a Kaspersky scan also?? or it's ok without it?

Also…. Is combofix a program that u can run to help you delete malware?
Or it works as a program to send reports and details on computer condition?
Hi,

No need for another Kaspersky scan. I think I know where the problem is. ComboFix is very powerful program that should only be run under supervision.

This thing keeps coming back but I think I've got where its spawning from. One more CFScript please:
File::
c:\windows\system32\drivers\lvuvc.hs
c:\windows\system32\bijukotu.dll
c:\windows\system32\yawiziga.dll
c:\windows\system32\yepupoji.dll
c:\windows\system32\hufopogi.dll

FCOPY::
C:\windows\system32\dllcache\tcpip.sys | c:\windows\system32\drivers\tcpip.sys

DEQUARANTINE::
C:\Qoobox\Quarantine\C\Windows\system32\msfDx.dll.vir
C:\Qoobox\Quarantine\C\Windows\system32\flvDx.dll.vir
Post the log as usual.

Thanks.
Thanks a lot!!
Here is my Combo Fix log

ComboFix 09-03-04.01 - user 2009-03-05 16:08:52.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.950.1.1028.18.2047.1435 [GMT 8:00]
執行位置: c:\documents and settings\user\桌面\ComboFix.exe
Command switches used :: c:\documents and settings\user\桌面\CFScript.txt
AV: Trend Micro Internet Security *On-access scanning disabled* (Updated)
FW: 趨勢科技主控式個人防火牆 *disabled*
* 成功創造新還原點

FILE ::
c:\windows\system32\bijukotu.dll
c:\windows\system32\drivers\lvuvc.hs
c:\windows\system32\hufopogi.dll
c:\windows\system32\yawiziga.dll
c:\windows\system32\yepupoji.dll
.

((((((((((((((((((((((((((((((((((((((( 被刪除的檔案 )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\bijukotu.dll
c:\windows\system32\drivers\lvuvc.hs
c:\windows\system32\hufopogi.dll
c:\windows\system32\yawiziga.dll
c:\windows\system32\yepupoji.dll

.
————— FCopy —————

c:\windows\system32\dllcache\tcpip.sys –> c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((( 2009-02-05 至 2009-03-05 的新的檔案 )))))))))))))))))))))))))))))))
.

2009-03-05 16:08 . 2009-03-05 16:08 163,328 –a—— c:\windows\system32\flvDx.dll
2009-03-05 16:08 . 2009-03-05 16:08 31,232 –a—— c:\windows\system32\msfDx.dll
2009-02-28 12:42 . 2008-06-18 03:01 8,321,536 —–c— c:\windows\system32\dllcache\shell32.dll
2009-02-26 20:12 . 2009-02-26 20:12 d——– c:\program files\MP3 Player Utilities 4.00
2009-02-24 22:04 . 2009-02-15 12:15 d——– c:\program files\AviSynth 2.5
2009-02-12 19:27 . 2009-02-12 19:27 d——– c:\program files\feng

.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-04 12:21 ——— d—–w c:\program files\Java
2009-03-03 00:13 ——— d—–w c:\program files\Trend Micro
2009-03-02 04:20 ——— d—–w c:\program files\Cheat Engine
2009-03-01 09:41 ——— d—–w c:\documents and settings\user\Application Data\Skype
2009-03-01 08:32 ——— d—–w c:\documents and settings\user\Application Data\skypePM
2009-02-26 00:34 ——— d—–w c:\program files\NextLink
2009-02-15 04:22 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-15 03:06 ——— d—–w c:\program files\捃濘儂桵Online
2009-01-17 22:46 ——— d—–w c:\program files\DAEMON Tools Toolbar
2009-01-08 01:26 ——— d—–w c:\documents and settings\user\Application Data\Media Player Classic
2008-12-22 09:15 31 —-a-w c:\documents and settings\user\jagex_runescape_preferences.dat
2008-12-20 22:31 826,368 —-a-w c:\windows\system32\wininet.dll
2008-12-18 23:53 410,984 —-a-w c:\windows\system32\deploytk.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-03-04_11.08.03.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-05 00:06:39 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_80.dat
.
((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-15 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Gadwin PrintScreen"="c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2007-08-20 495616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2006-03-02 208952]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-28 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-28 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-30 196608]
"CJIMETIPSYNC"="c:\program files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE" [2007-03-22 66400]
"PHIMETIPSYNC"="c:\program files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE" [2007-03-22 98656]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1393928]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-16 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-19 136600]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-18 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [2008-04-15 c:\windows\system32\ctfmon.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm

[HKLM\~\startupfolder\C:^Documents and Settings^user^「開始」功能表^程式集^啟動^Adobe Gamma.lnk]
path=c:\documents and settings\user\「開始」功能表\程式集\啟動\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
–a—— 2007-06-20 12:49 451872 c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-01 15:57 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-10-16 12:12 185896 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\NextLink\\GOGOBOX\\gogobox.exe"=
"c:\\Program Files\\NextLink\\GOGOBOX\\gfscagent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Thunder Network\\Thunder\\Program\\Thunder5.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Trend Micro\\Internet Security\\TmProxy.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\VS7DEBUG\\MDM.EXE"=
"c:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe"=

R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2008-03-11 36368]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2008-03-11 333328]
R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [2008-07-19 362944]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2008-07-25 52240]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;\??\c:\windows\system32\DNINDIS5.SYS –> c:\windows\system32\DNINDIS5.SYS [?]
S3 dump_wmimmc;dump_wmimmc;\??\c:\program files\softnyx\GunboundWC\GameGuard\dump_wmimmc.sys –> c:\program files\softnyx\GunboundWC\GameGuard\dump_wmimmc.sys [?]
S3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [2008-07-25 488768]
S3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [2008-07-25 648456]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
‘計劃任務’ 文件夾 裡的內容

2009-02-12 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []

2008-08-04 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
.
——- 而外的掃描 ——-
.
uStart Page = hxxp://www.google.com.tw/
uInternet Connection Wizard,ShellNext = hxxp://www.synnex.com.tw/
uInternet Settings,ProxyOverride = local
IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - c:\program files\Thunder Network\Thunder\Thunder.exe
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\CoreFTP\pftpns.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {15AB0590-D322-4440-B129-BFC893FB3CC2} - hxxp://live.17funtv.com:8057/AFCStarter_17funtv.cab
DPF: {9D8CCE0F-2E2C-41EB-B37F-9852DB989CAC} - hxxp://www.ace-onlines.com/game/WebLauncher.cab
DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} - hxxp://www.gogobox.com.tw/neo.fld/GNowStarter.cab
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\8jddzzr5.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-05 16:09:56
Windows 5.1.2600 Service Pack 3 NTFS

掃描被隱藏的進程 。。。

掃描被隱藏的啟動組 。。。

掃描被隱藏的文件 。。。

掃描完成
被隱藏的檔案: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1547161642-1580436667-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\a*悐kuUO悐+o N 
"Order"=hex:08,00,00,00,02,00,00,00,fe,02,00,00,01,00,00,00,06,00,00,00,ba,00,
00,00,00,00,00,00,ac,00,32,00,c2,01,00,00,18,39,68,1c,20,00,38,43,4f,4d,49,\

[HKEY_USERS\S-1-5-21-1547161642-1580436667-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\m*悐kuUO悐+o N 
"Order"=hex:08,00,00,00,02,00,00,00,0a,02,00,00,01,00,00,00,04,00,00,00,ba,00,
00,00,00,00,00,00,ac,00,32,00,c2,01,00,00,18,39,68,1c,20,00,38,43,4f,4d,49,\

[HKEY_USERS\S-1-5-21-1547161642-1580436667-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\v*悐kuUO悐+o N 
"Order"=hex:08,00,00,00,02,00,00,00,96,02,00,00,01,00,00,00,05,00,00,00,ba,00,
00,00,00,00,00,00,ac,00,32,00,c2,01,00,00,18,39,68,1c,20,00,38,43,4f,4d,49,\

[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ譸\CLSID]
@="{809B6661-94C4-49E6-B6EC-3F0F862215AA}"

[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ譸\CurVer]
@="BDATuner.元件.1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\SUPER *]
"DisplayName"="SUPER ?Version 2007.bld.23 (July 4, 2007)"
"UninstallString"="c:\\PROGRA~1\\ERIGHT~1\\SUPER\\Setup.exe /remove /q0"
"InstallDate"="2008-08-06 06:36:01"
"InstallLocation"="c:\\Program Files\\eRightSoft\\SUPER"
"InstallSource"="k:\\Backup\\軟體"
"DisplayIcon"="c:\\Program Files\\eRightSoft\\SUPER\\SUPER.exe"
"DisplayVersion"="Version 2007.bld.23 (July 4, 2007)"
"VersionMajor"=dword:00000000
"VersionMinor"=dword:00000000
"Publisher"="eRightSoft"
"HelpLink"="http://www.eRightSoft.com"
"URLInfoAbout"="http://www.eRightSoft.com"
"URLUpdateInfo"="http://www.eRightSoft.com"
"Contact"="[removed]"
.
完成時間: 2009-03-05 16:10:56
ComboFix-quarantined-files.txt 2009-03-05 08:10:54
ComboFix2.txt 2009-03-05 01:17:04
ComboFix3.txt 2009-03-04 15:15:03
ComboFix4.txt 2009-03-04 03:31:22
ComboFix5.txt 2009-03-05 08:08:18
C:\DeQuarantine.txt

Pre-Run: 100,183,490,560 位元組可用
Post-Run: 100,178,079,744 位元組可用

194 — E O F — 2008-12-19 15:09:31
Hi,

OK, looks like that did the trick. How are things now - which of the problems are you still having? Please also post a fresh HijackThis log.

FYI - ComboFix disables AutoRun for your media drives, so that's why your CD-ROM drives won't be auto-playing.

Cheers.
Thanks a lot!!

Also, for Hijack This log, do i press on "Do system scan and save logfile" thingy?

You also said about ComboFix stopping the programs, will i be able to start back the programs later?

Here is my Hijack This Log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 下午 08:32:59, on 2009/3/6
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live 登入小幫手 - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [CJIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\CHANGJIE\CINTLCFG.EXE /CJIMETIPSync
O4 - HKLM\..\Run: [PHIMETIPSYNC] C:\Program Files\Common Files\Microsoft Shared\IME\IMTC65\PHONETIC\TINTLCFG.EXE /PHIMETIPSync
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Gadwin PrintScreen] "C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe" /nosplash
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] ctfmon.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_11.dll
O9 - Extra 'Tools' menuitem: Sun Java 主控台 - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_11.dll
O9 - Extra button: 運行迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra 'Tools' menuitem: 運行迅雷5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: 參考資料 - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=7&ar=msnhome
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {15AB0590-D322-4440-B129-BFC893FB3CC2} (AFCStarter_17FunTv Control) - http://live.17funtv.com:8057/AFCStarter_17funtv.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/ZH-TW/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5036.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1213927759390
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {9D8CCE0F-2E2C-41EB-B37F-9852DB989CAC} (WebLauncher Control) - http://www.ace-onlines.com/game/WebLauncher.cab
O16 - DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} (NowStarter Control) - http://www.gogobox.com.tw/neo.fld/GNowStarter.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll
O18 - Protocol: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll
O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe

–
End of file - 10772 bytes
Hi,

Yeah, "Do a System Scan and Save a Logfile" is the right option to pick.

Well, you can manually start programs from media via "My Computer" >> "". If you really need them to autoplay then we could poke around in your registry to change the settings.

How is the computer running?

Thanks.
Thank you SOOO much!!! :woot: The post i did before is on "Do a System Scan and Save a Logfile" My computer, I really… Felt like it's better than when i first bought it :D Thanks a lot! I am able to use microsoft's internet driver to connect to my wireless adapter to work, so internet is back to normal. I would… well if you don't mind, get the auto play back…. cuz my parents might sometimes use my computer and they really donno how to do those stuff… I still can't find my CD-rom under My computer… so i donno where i can launch that, other than that, everything is okie :D Thanks again!!!
Hi,

OK, let sort out the AutoRun.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    HKLM\Software\Microsoft\Windows\CurrentVersion\policies\explorer
    HKCU\Software\Microsoft\Windows\CurrentVersion\policies\explorer
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


Next, let's see if we can find out why your drives aren't showing. Right-click on My Computer and select Properties. Navigate to the Hardware tab and click the Device Manager button. Expand the entry that says DVD/CD-Rom Drives. You should now have a list of your DVD/CD-ROM drives. First, check they are there, and then check if any of them have little yellow exclamation marks next to them. Let me know.

Thanks.
Thanks a lot! also did you wrote that program? So cool :D here is the log from the scan: SystemLook v1.0 by jpshortstuff (02.03.09) Log created at 07:43 on 08/03/2009 by user (Administrator - Elevation successful) No Context: HKLM\Software\Microsoft\Windows\CurrentVersion\policies\explorer No Context: HKCU\Software\Microsoft\Windows\CurrentVersion\policies\explorer -=End Of File=- Also, i see yellow exclamation marks with the 3 stuff under "DVD/CD Rom" section (but i remember i only have 2 CD roms >_>) ( I don't remember having that KFE, is that something to do with my Daemon tools? ) and 1 under "internet card (donno how to say it in english)" with ethernet card having a yellow exclamtion mark over it Here is a print screen under attachment file. Once again… THANK you so much for your help !!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI