the combofix txt seem not have the - in the middle
i save as the log in desktop as log.txt also , both are uploaded
some details:
A) it asks me to install a "restore control panel" and ask me to connect to internet and download the stuff before the scan, and i did..
the desktop taskbar seems to be disappeared for a while durin the scan.
C) my IE (which i am using now) has its frontpage kidnapped before, but now it seems clean, but i have abandoned IE and been using firefox for 1 year before the crash yesterday
ComboFix 09-07-25.06 - Administrator /07/26 ¬P´Á¤é 21:07.1.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.950.886.1028.18.511.186 [GMT 8:00]
°õ¦æ¦ì¸m: c:\documents and settings\Administrator\®à±\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( ³Q§R°£ªºÀÉ®× )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\INSTALL.LOG
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\Installer\1169d77.msi
c:\windows\Installer\1169d7d.msi
c:\windows\Installer\2b7fe76.msi
c:\windows\system32\lo2.txtt
c:\windows\system32\uacinit.dll
.
((((((((((((((((((((((((( 2009-06-26 ¦Ü 2009-07-26 ªº·sªºÀÉ®× )))))))))))))))))))))))))))))))
.
2009-07-26 03:06 . 2009-07-26 03:06 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-25 11:51 . 2008-12-11 00:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-07-25 11:51 . 2009-04-03 03:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-07-25 11:51 . 2008-12-18 04:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-07-25 11:50 . 2009-07-25 11:50 -------- d-----w- c:\program files\Common Files\PC Tools
2009-07-25 11:50 . 2008-12-10 03:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-07-25 11:50 . 2009-07-25 11:50 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-07-25 09:24 . 2009-07-25 09:24 -------- d-----w- c:\program files\Trend Micro
2009-07-25 08:42 . 2009-07-25 08:42 20480 ----a-w- c:\windows\system32\UACoujaxtxupr.dll
2009-07-25 08:42 . 2009-07-25 08:42 30208 ----a-w- c:\windows\system32\UACuyjluxprip.dll
2009-07-25 08:41 . 2009-07-25 08:42 843776 ----a-w- c:\windows\system32\UACqjspxxnhml.dll
2009-07-25 08:41 . 2009-07-25 08:41 310 ----a-w- c:\windows\system32\UACkcdklnkktd.dat
2009-07-25 08:41 . 2009-07-25 08:41 74240 ----a-w- c:\windows\system32\UACktkconkvdq.dll
2009-07-25 08:41 . 2009-07-25 08:42 54784 ----a-w- c:\windows\system32\drivers\UACgypqvpcvlt.sys
2009-07-19 16:09 . 1997-06-09 06:57 92160 ----a-w- c:\windows\system32\dinoav.dll
2009-07-19 16:09 . 1997-06-09 06:56 78848 ----a-w- c:\windows\system32\Dino2d.dll
2009-07-19 16:09 . 1997-06-09 06:54 100352 ----a-w- c:\windows\system32\dmix.dll
2009-07-19 16:09 . 1997-10-16 06:57 43008 ----a-w- c:\windows\system32\RDXInst.dll
2009-07-19 16:09 . 1997-06-09 07:47 137728 ----a-w- c:\windows\system32\Rdxcom.dll
2009-07-19 16:09 . 1997-06-09 07:00 62976 ----a-w- c:\windows\system32\rdxam.dll
2009-07-19 16:09 . 1997-06-09 06:59 188928 ----a-w- c:\windows\system32\rdxmmx.dll
2009-07-19 16:09 . 1997-06-09 06:58 185856 ----a-w- c:\windows\system32\rdxp5.dll
2009-07-14 11:40 . 2009-07-14 11:40 -------- d-----w- c:\documents and settings\Administrator\Application Data\iSilo
2009-07-14 11:40 . 2009-07-14 11:40 -------- d-----w- c:\documents and settings\Administrator\¡u¶}©l¡v
2009-07-14 11:40 . 2009-07-14 11:40 -------- d-----w- c:\program files\iSilo
2009-07-06 12:26 . 2009-07-06 12:26 -------- d-----w- c:\program files\7-Zip
.
(((((((((((((((((((((((((((((((((((((((( ¦b¤TӤ뤺³Qק諸ÀÉ®× ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-25 09:02 . 2002-08-26 04:55 90112 ----a-w- c:\windows\DUMP59ef.tmp
2009-07-25 09:00 . 2002-08-26 04:55 90112 ----a-w- c:\windows\DUMP3a35.tmp
2009-07-25 08:59 . 2002-08-26 04:55 90112 ----a-w- c:\windows\DUMP955a.tmp
2009-07-25 08:57 . 2002-08-26 04:55 90112 ----a-w- c:\windows\DUMP95ab.tmp
2009-07-25 08:56 . 2002-08-26 04:55 90112 ----a-w- c:\windows\DUMP9655.tmp
2009-07-24 17:59 . 2002-08-26 04:55 90112 ----a-w- c:\windows\DUMP9564.tmp
2008-12-20 16:03 . 2005-07-16 02:31 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-12-20 16:03 . 2005-07-16 02:31 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-20 16:03 . 2007-12-21 23:56 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-12-20 16:03 . 2007-12-21 23:56 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-12-20 16:04 . 2005-07-16 02:31 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2005-07-06 17:25 . 2005-07-06 17:25 56 --sh--r- c:\windows\system32\D782B1A6B6.sys
.
------- Sigcheck -------
[-] 2008-06-20 10:45 360320 01D5EAAFF224415A7FF513E4C882BE30 c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 10:45 360320 2A5554FC5B1E04E131230E3CE035C3F9 c:\windows\system32\dllcache\tcpip.sys
[7] 2005-05-25 19:04 359808 88763A98A4C26C409741B4AA162720C9 c:\windows\$NtUninstallKB913446$\tcpip.sys
[7] 2005-05-25 19:07 359936 63FDFEA54EB53DE2D863EE454937CE1E c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[7] 2006-01-13 17:07 360448 5562CC0A47B2AEF06D3417B733F3C195 c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[7] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[7] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[-] 2001-09-17 04:00 327168 E7774698BB0D14B0710A9A31E209F9B6 c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2004-08-04 06:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB893066$\tcpip.sys
[7] 2004-08-04 06:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\ServicePackFiles\i386\tcpip.sys
[7] 2006-01-13 02:28 359808 583E063FDC888CA30D05C2724B0D7EF4 c:\windows\$NtUninstallKB917953$\tcpip.sys
[7] 2006-04-20 11:51 359808 1DBF125862891817F374F407626967F4 c:\windows\$NtUninstallKB941644$\tcpip.sys
[7] 2007-10-30 17:20 360064 90CAFF4B094573449A0872A0F919B178 c:\windows\$NtUninstallKB951748$\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( «nµn¤JÂI ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*ª`·N* ªÅ¥Õ»P¦Xªk¯Ê¬Ùµn¿ý±N¤£·|³QÅã¥Ü
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-12 15360]
"RealPlayer"="c:\program files\Real\RealOne Player\realplay.exe" [2006-06-06 1003520]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2005-08-18 307200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-12 455168]
"PHIME2002A"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-12 455168]
"00THotkey"="c:\windows\System32\00THotkey.exe" [2002-01-08 245760]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2001-08-16 94208]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2001-08-16 376832]
"TosHKCW.exe"="c:\program files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" [2002-01-22 49152]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2002-10-17 151597]
"LWBMOUSE"="c:\program files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe" [2001-03-26 429568]
"gcasServ"="c:\program files\Microsoft AntiSpyware\gcasServ.exe" [2005-11-15 473928]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-05-19 59040]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2006-01-12 100056]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-26 148888]
"000StTHK"="000StTHK.exe" - c:\windows\system32\000StTHK.exe [2001-06-23 24576]
"Tpwrtray"="TPWRTRAY.EXE" - c:\windows\system32\TPWRTRAY.EXE [2002-01-25 196608]
"TFncKy"="TFncKy.exe" [BU]
"SxgTkBar"="SxgTkBar.exe" - c:\windows\system32\Sxgtkbar.exe [2001-07-11 53248]
"TFNF5"="TFNF5.exe" - c:\windows\system32\TFNF5.exe [2001-08-03 73728]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\System32\ctfmon.exe" [2004-08-12 15360]
c:\documents and settings\Administrator\¡u¶}©l¡v¥\¯àªí\µ{¦¡¶°\±Ò°Ê\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-2-15 575488]
c:\documents and settings\Administrator\¡u¶}©l¡v¥\¯àªí\µ{¦¡¶°\±Ò°Ê\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-2-15 575488]
c:\documents and settings\All Users\¡u¶}©l¡v¥\¯àªí\µ{¦¡¶°\±Ò°Ê\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\bf1942.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\Documents and Settings\\Administrator\\®à±\\Å]?1.07\\Warcraft III.exe"=
"g:\\CQ Design Institute\\GEO\\Å]?1.07\\Warcraft III.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\NextLink\\GOGOBOX\\gfscagent.exe"=
"c:\\Program Files\\NextLink\\GOGOBOX\\gogobox.exe"=
R0 pciSm;pciSm;c:\windows\system32\drivers\tossmpci.sys [2002/7/31 ¤W¤È 11:47 45803]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009/7/25 ¤U¤È 07:51 130936]
R0 TVALDX;Toshiba ACPI-Based Value Added Logical Device Extension Driver;c:\windows\system32\drivers\TVALDX.SYS [2002/7/31 ¤W¤È 11:43 6082]
R2 ¦Û°Ê LiveUpdate ±Æµ{¾¹;¦Û°Ê LiveUpdate ±Æµ{¾¹;c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2006/12/29 ¤U¤È 11:13 100032]
R3 SOFTXG;YAMAHA XG WDM SoftSynthesizer;c:\windows\system32\drivers\sxgxgwdm.sys [2002/7/31 ¤W¤È 11:51 966784]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008/10/12 ¤U¤È 05:12 348752]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - JAVAQUICKSTARTERSERVICE
*NewlyCreated* - PCTCORE
*NewlyCreated* - WEAOTOKP
*Deregistered* - mchInjDrv
*Deregistered* - weaotokp
.
¡¥p¹º¥ô°È¡¦ ¤å¥ó§¨ ¸Ìªº¤º®e
2009-07-24 c:\windows\Tasks\Norton AntiVirus - ±½´y§Úªº¹q¸£ - Administrator.job
- c:\progra~1\NORTON~1\Navw32.exe [2004-09-01 10:36]
2009-07-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 04:34]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-lphc5mnj0ee33 - c:\windows\system32\lphc5mnj0ee33.exe
.
------- ¦Ó¥~ªº±½´y -------
.
uStart Page = about:blank
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
IE: &Download with &DAP - c:\progra~1\DAP\dapextie.htm
IE: Download &all with DAP - c:\progra~1\DAP\dapextie2.htm
IE: ¶×¥X¦Ü Microsoft Excel(&X) - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {9B69C40C-4719-4BCA-85F7-49A8AFC67880} = 218.102.32.208 205.252.144.126
Name-Space Handler: HTTPS\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
DPF: Microsoft XML Parser for Java
DPF: {A22B8FD2-4CAA-4EFB-82F7-680CD656D9B0} - hxxp://www.gogobox.com.tw/neo.fld/GNowStarter.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uhgh87ld.Default User\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=https%3A%2F%2Fmail.google.com%2Fmail%2F%3Fnsr%3D1%26ui%3Dhtml%26zy%3Dl<mpl=default<mplcache=2
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-26 21:15
Windows 5.1.2600 Service Pack 2 FAT NTAPI
±½´y³QÁôÂ꺶iµ{ ...
±½´y³QÁôÂêº±Ò°Ê²Õ ...
±½´y³QÁôÂ꺤å¥ó ...
±½´y§¹¦¨
³QÁôÂêºÀÉ®×: 0
**************************************************************************
Binary file temp00 matches
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\AppEvents\Schemes\Apps\Conf\ºNáT*úQ\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_USERS\LocalService\AppEvents\Schemes\Apps\Conf\ºNáT*úQ\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_USERS\S-1-5-20\AppEvents\Schemes\Apps\Conf\ºNáT*úQ\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_USERS\S-1-5-21-1605616401-71594873-1131426265-500\AppEvents\Schemes\Apps\Conf\ºNáT*úQ\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
[HKEY_USERS\S-1-5-21-1605616401-71594873-1131426265-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\ N_*8n_*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"Order"=hex:08,00,00,00,02,00,00,00,da,01,00,00,01,00,00,00,04,00,00,00,74,00,
00,00,00,00,00,00,66,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,54,00,32,\
[HKEY_USERS\S-1-5-21-1605616401-71594873-1131426265-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\wc‘_ *-* * *D–l\Éa(uz_]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1605616401-71594873-1131426265-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\nndto@Y,n3*"{E`3U]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"Order"=hex:08,00,00,00,02,00,00,00,14,01,00,00,01,00,00,00,02,00,00,00,86,00,
00,00,00,00,00,00,78,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,66,00,36,\
[HKEY_USERS\S-1-5-21-1605616401-71594873-1131426265-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\èrR€l–Ò_5*‘Pˆ^^tX]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"Order"=hex:08,00,00,00,02,00,00,00,0c,00,00,00,01,00,00,00,00,00,00,00
[HKEY_USERS\S-1-5-21-1605616401-71594873-1131426265-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\At|T*\3*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"Order"=hex:08,00,00,00,02,00,00,00,0c,00,00,00,01,00,00,00,00,00,00,00
[HKEY_USERS\S-1-5-21-299502267-1606980848-854245398-500_Classes\O*v*e*r*t*u*r*e* *j\‹]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-299502267-1606980848-854245398-500_Classes\O*v*e*r*t*u*r*e* *j\‹\DefaultIcon]
@=expand:"%APPDATA%\\Microsoft\\Installer\\{50ADDF79-3249-4679-B527-3FB8C5EA99E5}\\_294823.exe,0"
[HKEY_USERS\S-1-5-21-299502267-1606980848-854245398-500_Classes\O*v*e*r*t*u*r*e* *j\‹\shell]
@="open"
[HKEY_USERS\S-1-5-21-299502267-1606980848-854245398-500_Classes\O*v*e*r*t*u*r*e* *j\‹\shell\open]
@="¶}±Ò(&O)"
[HKEY_USERS\S-1-5-21-299502267-1606980848-854245398-500_Classes\O*v*e*r*t*u*r*e* *j\‹\shell\open\command]
@="\"c:\\Program Files\\Overture 4.0 ÁcÅ餤¤åª©\\Overture.exe\" \"%1\""
"command"=multi:"%_(xAdi9`=RGK6dXKNlr>?%)duR)D9Xu~OSIW`PT- \"%1\"\00\00"
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQöN\CLSID]
@="{809B6661-94C4-49E6-B6EC-3F0F862215AA}"
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQöN\CurVer]
@="BDATuner.¤¸¥ó.1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\èrR€l–Ò_5*‘Pˆ^^tX]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,40,10,
3f,a7,97,c6,01,18,00,00,00,43,00,3a,00,5c,00,47,00,54,00,41,00,20,00,56,00,\
"Changed"=dword:00000000
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Print\Printers\êÕR A N Y O N E - 3 D C F 4 6 2 0
N„v H P D e s k J e t 9 3 0 C / 9 3 2 C / 9 3 5 C \DsDriver]
"printBinNames"=multi:"¦Û°Ê¿ï¨ú\00¤W¤è¯È§X\00¤â°Ê°e¯È\00«H«Ê, ¤â°Ê°e¯È\00\00"
"printCollate"=hex:01
"printColor"=hex:01
"printDuplexSupported"=hex:00
"printStaplingSupported"=hex:00
"printMaxXExtent"=dword:0000086f
"printMaxYExtent"=dword:00000de4
"printMinXExtent"=dword:000003e8
"printMinYExtent"=dword:000005b4
"printMediaSupported"=multi:"Letter\00Legal\00Executive\00A4\00A5\00B5 (JIS)\00Envelope #10\00Envelope DL\00Envelope C6\00Japanese Postcard\00A6\00Envelope A2\00US Index Card 4x6\00US Index Card 5x8\00\00"
"printMediaReady"=multi:"A4\00\00"
"printNumberUp"=dword:00000006
"printOrientationsSupported"=multi:"PORTRAIT\00LANDSCAPE\00\00"
"printMaxResolutionSupported"=dword:000004b0
"printLanguage"=multi:"PCL\00\00"
"printRate"=dword:00000009
"printRateUnit"="PagesPerMinute"
"printPagesPerMinute"=dword:00000009
"driverVersion"=dword:00000401
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Print\Printers\êÕR A N Y O N E - 3 D C F 4 6 2 0
N„v H P D e s k J e t 9 3 0 C / 9 3 2 C / 9 3 5 C \DsSpooler]
"description"=""
"driverName"="HP DeskJet 930C/932C/935C"
"location"=""
"portName"=multi:"\\\\ANYONE-3DCF4620\\¥´¦LÉó\00\00"
"printStartTime"=dword:00000000
"printEndTime"=dword:00000000
"printerName"="¦Û°Ê ANYONE-3DCF4620 ¤Wªº HP DeskJet 930C/932C/935C"
"printKeepPrintedJobs"=hex:00
"printSeparatorFile"=""
"printShareName"=""
"printSpooling"="PrintWhileSpooling"
"priority"=dword:00000001
"uNCName"="\\\\LEE-YV2R7VX5FBM\\¦Û°Ê ANYONE-3DCF4620 ¤Wªº HP DeskJet 930C/932C/935C"
"versionNumber"=dword:00000004
"serverName"="LEE-YV2R7VX5FBM"
"shortServerName"="LEE-YV2R7VX5FBM"
"flags"=dword:00000000
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Print\Printers\êÕR A N Y O N E - 3 D C F 4 6 2 0
N„v H P D e s k J e t 9 3 0 C / 9 3 2 C / 9 3 5 C \PrinterDriverData]
"InitDriverVersion"=dword:00000500
"Model"="HP DeskJet 930C/932C/935C"
"PrinterDataSize"=dword:00000230
"PrinterData"=hex:00,05,30,02,81,08,00,00,80,1a,06,00,00,00,00,00,00,00,00,00,
64,00,58,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,f4,0c,86,d1,01,\
"FeatureKeywordSize"=dword:0000001d
"FeatureKeyword"=hex:48,50,44,75,70,6c,65,78,55,6e,69,74,00,4e,6f,74,49,6e,73,
74,61,6c,6c,65,64,00,0a,00,00
"Forms?"=dword:d1860cf4
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\êÕR *L*i*v*e*U*p*d*a*t*e* *’czhV\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
.
§¹¦¨®É¶¡: 2009-07-26 21:19
ComboFix-quarantined-files.txt 2009-07-26 13:19
Pre-Run: 1,177,911,296 ¦ì¤¸²Õ¥i¥Î
Post-Run: 1,148,321,792 ¦ì¤¸²Õ¥i¥Î
WindowsXP-KB310994-SP2-Pro-BootDisk-CHT.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
365 --- E O F --- 2008-11-16 16:44