I disabled AVG free, shutdown PCTools Spyware Doctor and windows firewall prior to running combofix
(on a sidenote, I believe PCTool Spyware Doctor is malware; I downloaded soon after I became infected to run a scan; it asked me to pay $$ after identifying Windows Vista virus; I did not go forward from there. Any advice on uninstalling this program?)
Here is the combofix log (I translated the chinese into english; the program ran in chinese)
ComboFix 10-03-08.01 - markchu 8/2010 Mon 22:44:37.1.2 - x86
执行位置: c:\users\markchu\Downloads\ComboFix.exe
EXECUTED PLACE
.
((((((((((((((((((((((((((((((((((((((( 被删除的档案 )))))))))))))))))))))))))))))))))))))))))))))))))
DELETED FILES
.
c:\$recycle.bin\S-1-5-21-1738422755-998661840-641317060-500
c:\$recycle.bin\S-1-5-21-2365545147-1999384947-2466353664-500
c:\$recycle.bin\S-1-5-21-3918485295-3208370692-4232862009-500
c:\users\markchu\AppData\Roaming\.#
c:\users\Public\Google
c:\windows\system32\oem5.inf
.
((((((((((((((((((((((((( 2010-02-09 至 2010-03-09 的新的档案 )))))))))))))))))))))))))))))))
2010-02-09 UNTIL 2010-03-09 NEW FILES
.
2010-03-09 04:55 . 2010-03-09 04:55 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-03-09 04:42 . 2010-03-09 04:42 ——– d—–w- C:\32788R22FWJFW
2010-03-05 00:10 . 2010-03-05 00:10 ——– d—–w- c:\users\markchu\AppData\Roaming\TeamViewer
2010-03-05 00:09 . 2010-03-05 00:09 ——– d—–w- c:\users\markchu\temp
2010-03-03 01:13 . 2010-03-03 01:13 ——– d—–w- c:\program files\ERUNT
2010-03-02 07:39 . 2010-03-02 07:39 ——– d—–w- c:\users\markchu\AppData\Roaming\Malwarebytes
2010-03-02 07:39 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-02 07:39 . 2010-03-02 07:39 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-02 07:39 . 2010-03-02 07:39 ——– d—–w- c:\programdata\Malwarebytes
2010-03-02 07:39 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-02 07:12 . 2010-01-21 23:21 165840 —-a-w- c:\windows\PCTBDRes.dll
2010-03-02 07:12 . 2010-01-21 23:21 149456 —-a-w- c:\windows\SGDetectionTool.dll
2010-03-02 07:12 . 2010-01-21 23:21 1652688 —-a-w- c:\windows\PCTBDCore.dll
2010-03-02 07:12 . 2010-01-21 23:21 767952 —-a-w- c:\windows\BDTSupport.dll
2010-03-02 07:12 . 2009-10-28 07:36 1152444 —-a-w- c:\windows\UDB.zip
2010-03-02 07:12 . 2008-11-26 18:08 131 —-a-w- c:\windows\IDB.zip
2010-03-02 07:09 . 2010-02-05 15:18 100136 —-a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2010-03-02 07:09 . 2010-02-05 15:17 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-03-02 07:09 . 2009-10-06 22:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-03-02 07:09 . 2009-09-23 22:10 207280 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2010-03-02 07:09 . 2010-02-05 15:25 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2010-03-02 07:08 . 2010-03-02 07:12 ——– d—–w- c:\program files\Common Files\PC Tools
2010-03-02 07:08 . 2010-03-03 00:52 ——– d—–w- c:\program files\Spyware Doctor
2010-03-02 07:08 . 2010-03-02 07:08 ——– d—–w- c:\users\markchu\AppData\Roaming\PC Tools
2010-03-02 07:08 . 2010-03-02 07:08 ——– d—–w- c:\programdata\PC Tools
2010-02-24 03:05 . 2010-01-23 08:05 2048 —-a-w- c:\windows\system32\tzres.dll
2010-02-21 02:33 . 2010-02-21 02:33 ——– d—–w- c:\programdata\NCH Software
2010-02-21 02:33 . 2010-02-21 02:33 ——– d—–w- c:\program files\NCH Software
2010-02-21 02:33 . 2010-02-21 02:33 ——– d—–w- c:\users\markchu\AppData\Roaming\NCH Software
2010-02-21 02:08 . 2010-02-21 02:18 ——– d—–w- c:\users\markchu\AppData\Roaming\avidemux
2010-02-12 00:29 . 2010-02-12 00:29 ——– d—–w- c:\program files\Common Files\Crystal Decisions
2010-02-12 00:29 . 2010-02-12 00:29 ——– d—–w- c:\program files\Crystal Decisions
2010-02-12 00:29 . 2010-02-12 00:29 ——– d—–w- C:\MIR
.
(((((((((((((((((((((((((((((((((((((((( 在三个月内被修改的档案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
FILES MODIFIED WITHIN 3 MONTHS
.
2010-03-09 04:42 . 2009-08-23 01:47 ——– d—–w- c:\users\markchu\AppData\Roaming\Skype
2010-03-09 04:41 . 2010-02-06 02:16 2217968 —-a-w- c:\users\markchu\AppData\Roaming\Google\Google Pinyin 2\pinyin-2.2.11.69\GooglePinyinUpdater.exe
2010-03-08 23:38 . 2009-08-23 01:50 ——– d—–w- c:\users\markchu\AppData\Roaming\skypePM
2010-03-02 15:28 . 2009-03-12 02:50 12 —-a-w- c:\windows\bthservsdp.dat
2010-02-27 13:47 . 2008-06-08 15:38 9258944 —-a-w- c:\users\markchu\AppData\Roaming\PPLive\Update\Update.exe
2010-02-21 06:49 . 2008-03-08 04:11 86776 —-a-w- c:\users\markchu\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-05 02:46 . 2010-02-05 02:45 ——– d—–w- c:\program files\SpirXpert2009
2010-02-04 01:38 . 2010-01-09 21:23 1964528 —-a-w- c:\users\markchu\AppData\Roaming\Google\Google Pinyin 2\pinyin-2.1.10.65\GooglePinyinUpdater.exe
2010-01-28 03:44 . 2010-01-28 03:21 6735 —-a-w- C:\BdUninstallTool2010.01.27-09.21.05.reg
2010-01-26 03:41 . 2010-01-26 03:41 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-01-26 03:41 . 2010-01-26 03:41 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-26 03:41 . 2010-01-26 03:41 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-26 03:41 . 2010-01-26 03:41 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-26 03:40 . 2008-03-18 02:48 ——– d—–w- c:\program files\AVG
2010-01-26 03:40 . 2010-01-26 03:40 ——– d—–w- c:\programdata\avg9
2010-01-14 17:12 . 2009-10-17 02:40 181120 ——w- c:\windows\system32\MpSigStub.exe
2010-01-10 17:56 . 2010-01-09 15:53 ——– d—–w- c:\program files\HP
2010-01-10 17:56 . 2010-01-09 15:51 ——– d—–w- c:\programdata\HP
2010-01-10 03:08 . 2010-01-09 19:27 192209 —-a-w- c:\windows\hpwins20.dat
2010-01-10 03:07 . 2010-01-10 03:07 ——– d—–w- c:\users\markchu\AppData\Roaming\HP
2010-01-10 03:06 . 2010-01-10 03:04 104201 —-a-w- c:\windows\hpqins01.dat
2010-01-09 19:35 . 2010-01-09 19:35 ——– d—–w- c:\programdata\Hewlett-Packard
2010-01-09 19:32 . 2010-01-09 19:32 ——– d—–w- c:\program files\Common Files\HP
2010-01-09 19:32 . 2010-01-09 19:32 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2010-01-09 19:32 . 2010-01-09 19:32 ——– d—–w- c:\program files\Hewlett-Packard
2010-01-09 16:05 . 2010-01-09 16:05 242577 —-a-w- c:\programdata\HP\Installer\Temp\ENU-Package.exe
2010-01-06 05:23 . 2009-10-24 04:03 680 —-a-w- c:\users\markchu\AppData\Local\d3d9caps.dat
2009-12-28 12:36 . 2010-02-10 04:32 11776 —-a-w- c:\windows\system32\tsbyuv.dll
2009-12-28 12:34 . 2010-02-10 04:32 22528 —-a-w- c:\windows\system32\msyuv.dll
2009-12-28 12:34 . 2010-02-10 04:32 31232 —-a-w- c:\windows\system32\msvidc32.dll
2009-12-28 12:34 . 2010-02-10 04:32 123904 —-a-w- c:\windows\system32\msvfw32.dll
2009-12-28 12:34 . 2010-02-10 04:32 13312 —-a-w- c:\windows\system32\msrle32.dll
2009-12-28 12:33 . 2010-02-10 04:32 82944 —-a-w- c:\windows\system32\mciavi32.dll
2009-12-28 12:32 . 2010-02-10 04:32 50176 —-a-w- c:\windows\system32\iyuv_32.dll
2009-12-28 12:31 . 2010-02-10 04:32 1327616 —-a-w- c:\windows\system32\quartz.dll
2009-12-28 12:30 . 2010-02-10 04:32 88576 —-a-w- c:\windows\system32\avifil32.dll
2009-12-28 12:30 . 2010-02-10 04:32 65024 —-a-w- c:\windows\system32\avicap32.dll
2009-12-18 12:52 . 2010-01-25 00:00 832512 —-a-w- c:\windows\system32\wininet.dll
2009-12-18 12:48 . 2010-01-24 23:59 56320 —-a-w- c:\windows\system32\iesetup.dll
2009-12-18 12:48 . 2010-01-24 23:59 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-12-18 12:48 . 2010-01-24 23:59 52736 —-a-w- c:\windows\AppPatch\iebrshim.dll
2009-12-18 12:46 . 2010-01-24 23:59 72704 —-a-w- c:\windows\system32\admparse.dll
2009-12-18 10:18 . 2010-01-24 23:59 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-12-18 08:45 . 2010-01-24 23:59 48128 —-a-w- c:\windows\system32\mshtmler.dll
2009-12-11 12:15 . 2010-02-10 04:32 306688 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-11 12:15 . 2010-02-10 04:32 84992 —-a-w- c:\windows\system32\drivers\srvnet.sys
2008-03-03 16:03 . 2008-03-03 15:47 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( 重要登入点 ))))))))))))))))))))))))))))))))))))))))))))))))))
IMPORTANT ENTRY POINTS
.
.
*注意* 空白与合法缺省登录将不会被显示
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 2159104]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-07-16 25604904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-03-03 1006264]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-25 17920]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-05-24 857648]
"SigmatelSysTrayApp"="sttray.exe" [2007-04-24 303104]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-12 90112]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-12-08 3444736]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-10 16384]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-29 413696]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"Google Pinyin 2 Autoupdater"="c:\program files\Google\Google Pinyin 2\GooglePinyinDaemon.exe" [2009-09-12 1009648]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-3-3 50688]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2007-7-20 1180952]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-01-07 38224]
R3 MIRUSB;MIRUsb.Sys MIR driver;c:\windows\system32\Drivers\mirusb.sys [2006-07-12 16896]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-12-09 365280]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-09-23 207280]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-01-26 333192]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-01-26 360584]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-01-26 285392]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [2010-01-21 112592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
.
.
——- 而外的扫描 ——-
OUTLIER SCANS
.
uStart Page = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080303
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
Trusted Zone: cuhk.edu.hk\www.gradsch
Trusted Zone: turbotax.com
FF - ProfilePath - c:\users\markchu\AppData\Roaming\Mozilla\Firefox\Profiles\p63kp21y.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-08 22:55
Windows 6.0.6000 NTFS
扫描被隐藏的进程 。。。
SCANNING FOR HIDDEN PROCESS
扫描被隐藏的启动组 。。。
SCANNING FOR HIDDEN START UP GROUPS
扫描被隐藏的文件 。。。
SCANNING FOR HIDDEN PROGRAMS
扫描完成
被隐藏的档案: 0
HIDDEN FILES: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
完成时间: 2010-03-08 22:58:47
FINISHED TIME: 2010-03-08 22:58:47
ComboFix-quarantined-files.txt 2010-03-09 04:58
Pre-Run: 34,844,549,120 bytes free
Post-Run: 34,810,507,264 bytes free
- - End Of File - - 86480D8C6F7C7B21BF389C0A663CC28F
Here is the dds log:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 23:01:31.55 on 03/08/2010 Mon
Internet Explorer: 7.0.6000.16982
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spyware Doctor *enabled* (Updated) {1C3EDD79-273E-46ac-99F8-EFA9E7CBC301}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Windows\system32\lsm.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\bcmwltry.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k HPService
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\sttray.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Google\Google Pinyin 2\GooglePinyinDaemon.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conime.exe
C:\Windows\explorer.exe
C:\Windows\system32\rundll32.exe
C:\Users\markchu\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=6080303
uURLSearchHooks: Yahoo! 导航条: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
TB: Yahoo! 导航条: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SigmatelSysTrayApp] sttray.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe"
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [dscactivate] c:\program files\dell support center\gs_agent\custom\dsca.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
mRun: [Google Pinyin 2 Autoupdater] "c:\program files\google\google pinyin 2\GooglePinyinDaemon.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: {95B3F550-91C4-4627-BCC4-521288C52977} - c:\program files\pplive\PPLive.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
Trusted Zone: cuhk.edu.hk\www.gradsch
Trusted Zone: turbotax.com
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://picasaweb.google.com/s/v/34.09/uploader2.cab
DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} - hxxp://christinash.spaces.live.com/PhotoUpload/VistaMsnPUplden-us.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\windows\system32\avgrsstx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\markchu\appdata\roaming\mozilla\firefox\profiles\p63kp21y.default\
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npoji610.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-3-2 207280]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-1-25 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-1-25 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-25 285392]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\spyware doctor\bdt\BDTUpdateService.exe [2010-3-2 112592]
R2 datunidr;DellAutomatedPCTuneUp UniDriver;c:\windows\system32\drivers\datunidr.sys [2007-8-23 5376]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-3-2 38224]
S3 MIRUSB;MIRUsb.Sys MIR driver;c:\windows\system32\drivers\mirusb.sys [2006-7-11 16896]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-3-2 365280]
=============== Created Last 30 ================
2010-03-08 22:58 –dsh— C:\$RECYCLE.BIN
2010-03-08 22:43 261,632 a——- c:\windows\PEV.exe
2010-03-08 22:43 161,792 a——- c:\windows\SWREG.exe
2010-03-08 22:43 98,816 a——- c:\windows\sed.exe
2010-03-08 22:43 77,312 a——- c:\windows\MBR.exe
2010-03-08 22:42 –d—– C:\ComboFix
2010-03-04 18:10 –d—– c:\users\markchu\appdata\roaming\TeamViewer
2010-03-04 18:09 –d—– c:\users\markchu\temp
2010-03-02 01:39 –d—– c:\users\markchu\appdata\roaming\Malwarebytes
2010-03-02 01:39 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-02 01:39 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-03-02 01:39 –d—– c:\programdata\Malwarebytes
2010-03-02 01:39 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-03-02 01:39 –d—– c:\progra~2\Malwarebytes
2010-03-02 01:12 1,652,688 a——- c:\windows\PCTBDCore.dll
2010-03-02 01:12 1,640,400 a——- c:\windows\PCTBDCore.dll.old
2010-03-02 01:12 1,152,444 a——- c:\windows\UDB.zip
2010-03-02 01:12 767,952 a——- c:\windows\BDTSupport.dll
2010-03-02 01:12 165,840 a——- c:\windows\PCTBDRes.dll
2010-03-02 01:12 149,456 a——- c:\windows\SGDetectionTool.dll
2010-03-02 01:12 882 a——- c:\windows\RegSDImport.xml
2010-03-02 01:12 879 a——- c:\windows\RegISSImport.xml
2010-03-02 01:12 131 a——- c:\windows\IDB.zip
2010-03-02 01:09 233,136 a——- c:\windows\system32\drivers\pctgntdi.sys
2010-03-02 01:09 100,136 a——- c:\windows\system32\drivers\pctwfpfilter.sys
2010-03-02 01:09 7,387 a——- c:\windows\system32\drivers\pctgntdi.cat
2010-03-02 01:09 207,280 a——- c:\windows\system32\drivers\PCTCore.sys
2010-03-02 01:09 87,784 a——- c:\windows\system32\drivers\PCTAppEvent.sys
2010-03-02 01:09 7,412 a——- c:\windows\system32\drivers\PCTAppEvent.cat
2010-03-02 01:09 7,383 a——- c:\windows\system32\drivers\pctcore.cat
2010-03-02 01:09 70,408 a——- c:\windows\system32\drivers\pctplsg.sys
2010-03-02 01:09 7,383 a——- c:\windows\system32\drivers\pctplsg.cat
2010-03-02 01:08 –d—– c:\program files\common files\PC Tools
2010-03-02 01:08 –d—– c:\users\markchu\appdata\roaming\PC Tools
2010-03-02 01:08 –d—– c:\programdata\PC Tools
2010-03-02 01:08 –d—– c:\program files\Spyware Doctor
2010-03-02 01:08 –d—– c:\progra~2\PC Tools
2010-02-23 21:05 2,048 a——- c:\windows\system32\tzres.dll
2010-02-20 20:33 –d—– c:\programdata\NCH Software
2010-02-20 20:33 –d—– c:\program files\NCH Software
2010-02-20 20:33 –d—– c:\users\markchu\appdata\roaming\NCH Software
2010-02-20 20:08 –d—– c:\users\markchu\appdata\roaming\avidemux
2010-02-11 18:29 –d—– c:\program files\common files\Crystal Decisions
2010-02-11 18:29 –d—– c:\program files\Crystal Decisions
2010-02-11 18:29 –d—– C:\MIR
==================== Find3M ====================
2010-02-11 18:38 86,016 a——- c:\windows\inf\infstrng.dat
2010-02-11 18:38 51,200 a——- c:\windows\inf\infpub.dat
2010-02-11 18:38 86,016 a——- c:\windows\inf\infstor.dat
2010-01-27 21:44 6,735 a——- C:\BdUninstallTool2010.01.27-09.21.05.reg
2010-01-25 21:41 12,464 a——- c:\windows\system32\avgrsstx.dll
2010-01-25 21:41 360,584 a——- c:\windows\system32\drivers\avgtdix.sys
2010-01-25 21:41 333,192 a——- c:\windows\system32\drivers\avgldx86.sys
2010-01-14 11:12 181,120 ——– c:\windows\system32\MpSigStub.exe
2010-01-09 21:08 192,209 a——- c:\windows\hpwins20.dat
2010-01-09 21:06 104,201 a——- c:\windows\hpqins01.dat
2009-12-28 06:36 11,776 a——- c:\windows\system32\tsbyuv.dll
2009-12-28 06:34 22,528 a——- c:\windows\system32\msyuv.dll
2009-12-28 06:34 123,904 a——- c:\windows\system32\msvfw32.dll
2009-12-28 06:34 31,232 a——- c:\windows\system32\msvidc32.dll
2009-12-28 06:34 13,312 a——- c:\windows\system32\msrle32.dll
2009-12-28 06:33 82,944 a——- c:\windows\system32\mciavi32.dll
2009-12-28 06:32 50,176 a——- c:\windows\system32\iyuv_32.dll
2009-12-28 06:31 1,327,616 a——- c:\windows\system32\quartz.dll
2009-12-28 06:30 88,576 a——- c:\windows\system32\avifil32.dll
2009-12-28 06:30 65,024 a——- c:\windows\system32\avicap32.dll
2009-12-18 06:52 832,512 a——- c:\windows\system32\wininet.dll
2009-12-18 06:48 56,320 a——- c:\windows\system32\iesetup.dll
2009-12-18 06:48 78,336 a——- c:\windows\system32\ieencode.dll
2009-12-18 06:48 52,736 a——- c:\windows\apppatch\iebrshim.dll
2009-12-18 06:46 72,704 a——- c:\windows\system32\admparse.dll
2009-12-18 04:18 26,624 a——- c:\windows\system32\ieUnatt.exe
2009-12-18 02:45 48,128 a——- c:\windows\system32\mshtmler.dll
2009-08-22 19:50 56 a—h— c:\programdata\ezsidmv.dat
2009-08-22 19:50 56 a—h— c:\progra~2\ezsidmv.dat
2008-12-12 03:21 174 a–sh— c:\program files\desktop.ini
2008-06-12 07:25 665,600 a——- c:\windows\inf\drvindex.dat
2006-11-02 06:39 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 06:39 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 06:39 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 06:39 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2008-03-03 10:03 8,192 a–sh— c:\windows\users\default\NTUSER.DAT
============= FINISH: 23:02:51.16 ===============