This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware ksdsvc

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I need help with my startups to speed up windows; it is extremely slow.

Spybot found this "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride" in my computer. Every time I deleted it, the next time it will be there again. I always have ZoneAlarm and AVG running; however, recently Windows security center every now and then detects that there is either missing firewall or antivirus program.

Also, Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4139

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

5/24/2010 7:40:33 AM
mbam-log-2010-05-24 (07-40-33).txt

Scan type: Flash scan
Objects scanned: 26920
Time elapsed: 18 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ksdsvc (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

ksdsvc comes back on every reboot too.

Lastly, Adaware caught something like Admt; and it could not be removed either.

I need help on this. Thanks!
Hi and Welcome,

Please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT




Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 16:55:25.10 on 05/25/2010 Tue Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.936.86.1033.18.2039.1386 [GMT -10:00] AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: ZoneAlarm Pro Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe svchost.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe C:\Program Files\AVG\AVG9\avgam.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\Startup Faster 2004\sfAgent.exe C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\Program Files\reliz\akeys.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files\Kingsoft\PowerWord PE\ksdsvc.exe C:\WINDOWS\system32\conime.exe C:\Program Files\AVG\AVG9\avgui.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\Tom Clinic\Desktop\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.baidu.com/index.php?tn=avantcn_dg uSearch Page = hxxp://www.baidu.com/index.php?tn=avantcn_dg uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll BHO: DAPIELoader Class: {ff6c3cf0-4b15-11d1-abed-709549c10000} - c:\progra~1\dap\DAPIEL~1.DLL BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll mRun: [StartupFaster] "c:\program files\startup faster 2004\StrpFstCfg.exe" -run SFAURUN SFCURUN SFAUSTARTUP SFCUSTARTUP dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\startu~1\hp digital imaging monitor.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\documents and settings\all users.windows\start menu\programs\startup\startupfaster\StartupFaster.ini mPolicies-explorer: NoResolveTrack = 1 (0x1) IE: &Clean Traces - c:\program files\dap\privacy package\dapcleanerie.htm IE: &Download with &DAP - c:\program files\dap\dapextie.htm IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html IE: Download &all with DAP - c:\program files\dap\dapextie2.htm IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: Logoff - file://c:\program files\siber systems\ai roboform\RoboFormComLogoff.html IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: 导出到 Microsoft Office Excel(&X) - c:\progra~1\micros~3\office11\EXCEL.EXE/3000 IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll Hosts: 127.0.0.1 www.spywareinfo.com ============= SERVICES / DRIVERS =============== R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-5-21 52872] R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-5-22 64288] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-5-21 216200] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-5-21 29512] R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-5-21 242896] R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2010-5-21 353680] R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-5-21 916760] R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-5-21 308064] R2 KAVSafe;KAVSafe;c:\windows\system32\drivers\KAVSafe.sys [2010-5-22 60008] R2 KSDSVC;Kingsoft Common Content Service;c:\program files\kingsoft\powerword pe\ksdsvc.exe [2009-10-28 25240] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-4-26 304464] R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\common files\pc tools\smonitor\StartManSvc.exe [2010-4-24 583640] R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2010-5-21 87936] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-5-22 20952] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1314704] S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?] =============== Created Last 30 ================ 2010-05-26 02:03:38 0 d—–w- c:\docume~1\Tomzh~1\applic~1\Office Genuine Advantage 2010-05-24 00:44:46 274288 —-a-w- c:\windows\system32\mucltui.dll 2010-05-24 00:44:46 215920 —-a-w- c:\windows\system32\muweb.dll 2010-05-24 00:44:46 16736 —-a-w- c:\windows\system32\mucltui.dll.mui 2010-05-23 11:14:31 15880 —-a-w- c:\windows\system32\lsdelete.exe 2010-05-23 10:56:41 5632 —-a-w- c:\windows\system32\ptpusb.dll 2010-05-23 10:56:40 159232 —-a-w- c:\windows\system32\ptpusd.dll 2010-05-23 10:56:39 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys 2010-05-23 10:56:39 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys 2010-05-23 09:30:20 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys 2010-05-23 09:30:15 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2010-05-23 09:22:40 0 dc-h–w- c:\docume~1\alluse~1.win\applic~1\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6} 2010-05-23 09:20:34 0 d—–w- c:\program files\Foxit Software 2010-05-23 06:17:03 0 d—–w- c:\documents and settings\Tom Clinic\Tracing 2010-05-23 06:15:56 0 d—–w- c:\program files\Microsoft 2010-05-23 02:40:25 0 d—–w- c:\docume~1\alluse~1.win\applic~1\WEBREG 2010-05-23 02:18:53 271704 —-a-r- c:\windows\system32\hpzids01.dll 2010-05-23 02:18:52 117760 —-a-w- c:\windows\system32\hpzll5mu.dll 2010-05-23 02:15:49 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys 2010-05-23 02:15:49 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys 2010-05-23 02:15:45 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys 2010-05-23 02:15:45 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2010-05-23 02:10:55 168980 —-a-w- c:\windows\hphins27.dat 2010-05-23 02:10:54 787 ——w- c:\windows\hphmdl27.dat 2010-05-22 22:51:06 0 d—–w- c:\docume~1\Tomzh~1\applic~1\Tencent 2010-05-22 21:29:28 9553 —-a-w- c:\windows\ePrompter.ini 2010-05-22 20:36:09 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Tencent 2010-05-22 19:19:12 376 —-a-w- c:\windows\ODBC.INI 2010-05-22 19:19:05 28040 —-a-w- c:\windows\system32\mdimon.dll 2010-05-22 19:18:43 0 d—–w- c:\program files\Microsoft ActiveSync 2010-05-22 19:18:39 454656 —-a-w- c:\windows\system32\wps32.cnv 2010-05-22 13:27:39 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Spybot - Search & Destroy 2010-05-22 13:26:47 0 d—–w- c:\docume~1\Tomzh~1\applic~1\SolidDocuments 2010-05-22 13:25:35 56 —ha-w- c:\windows\system32\ezsidmv.dat 2010-05-22 13:14:49 0 d—–w- c:\program files\Raxco 2010-05-22 13:13:45 20 —-a-w- c:\windows\system32\pub_store.dat 2010-05-22 13:07:24 0 d—–w- c:\docume~1\Tomzh~1\applic~1\Meitu 2010-05-22 12:33:45 0 d—–w- c:\docume~1\Tomzh~1\applic~1\SogouPY.users 2010-05-22 12:33:11 0 d—–w- c:\docume~1\Tomzh~1\applic~1\SogouPY 2010-05-22 11:56:37 0 d—–w- c:\docume~1\Tomzh~1\applic~1\Malwarebytes 2010-05-22 11:56:27 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-05-22 11:56:21 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes 2010-05-22 11:56:20 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-05-22 11:52:34 0 d—–w- c:\docume~1\alluse~1.win\applic~1\SpeedBit 2010-05-22 11:52:18 172032 —-a-w- c:\windows\system32\AniGIF.ocx 2010-05-22 11:33:13 0 d—–w- c:\docume~1\Tomzh~1\applic~1\Registry Mechanic 2010-05-22 11:28:19 880640 —-a-w- c:\windows\system32\UniBox10.ocx 2010-05-22 11:28:19 212992 —-a-w- c:\windows\system32\UniBoxVB12.ocx 2010-05-22 11:28:19 1101824 —-a-w- c:\windows\system32\UniBox210.ocx 2010-05-22 11:28:19 1081616 —-a-w- c:\windows\system32\MSCOMCTL.OCX 2010-05-22 11:24:08 0 d—–w- c:\docume~1\Tomzh~1\applic~1\Trillian 2010-05-22 11:14:12 60008 —-a-w- c:\windows\system32\drivers\KAVSafe.sys 2010-05-22 11:14:08 0 d—–w- c:\docume~1\alluse~1.win\applic~1\kingsoft 2010-05-22 11:10:24 0 d—–w- c:\docume~1\Tomzh~1\applic~1\Avant Profiles 2010-05-22 11:08:09 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Fetion 2010-05-22 11:07:34 0 d—–w- c:\docume~1\Tomzh~1\applic~1\Fetion 2010-05-22 09:54:10 0 d—–w- c:\docume~1\Tomzh~1\applic~1\TeamViewer 2010-05-22 09:35:57 0 d—–w- c:\docume~1\Tomzh~1\applic~1\WinPatrol 2010-05-22 09:34:10 0 d—–w- c:\docume~1\Tomzh~1\applic~1\Softarium.com 2010-05-22 09:33:09 0 d—–w- c:\docume~1\Tomzh~1\applic~1\kingsoft 2010-05-22 09:26:59 0 d-sh–w- c:\documents and settings\Tom Clinic\IECompatCache 2010-05-22 09:26:17 0 d-sh–w- c:\documents and settings\Tom Clinic\PrivacIE 2010-05-22 09:22:56 0 d-sh–w- c:\documents and settings\Tom Clinic\IETldCache 2010-05-22 09:16:15 0 d—–w- c:\windows\system32\KB905474 2010-05-22 09:15:09 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll 2010-05-22 09:15:09 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll 2010-05-22 09:15:09 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll 2010-05-22 09:15:09 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll 2010-05-22 09:15:09 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll 2010-05-22 09:15:09 11070976 -c—-w- c:\windows\system32\dllcache\ieframe.dll 2010-05-22 09:00:12 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys 2010-05-22 09:00:12 272128 ——w- c:\windows\system32\drivers\bthport.sys 2010-05-22 08:59:34 455680 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys 2010-05-22 08:55:04 2189952 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe 2010-05-22 08:55:04 2146304 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe 2010-05-22 08:55:02 2024448 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe 2010-05-22 08:53:29 12464 —-a-w- c:\windows\system32\avgrsstx.dll 2010-05-22 08:44:38 4212 —ha-w- c:\windows\system32\zllictbl.dat 2010-05-22 08:44:10 1221008 —-a-w- c:\windows\system32\zpeng25.dll 2010-05-22 08:44:07 352606 —-a-w- c:\windows\system32\vsconfig.xml 2010-05-22 08:42:32 2560 ——w- c:\windows\system32\xpsp4res.dll 2010-05-22 08:38:47 26144 —-a-w- c:\windows\system32\spupdsvc.exe 2010-05-22 08:32:15 52872 —-a-w- c:\windows\system32\drivers\avgrkx86.sys 2010-05-22 08:32:14 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys 2010-05-22 08:32:09 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2010-05-22 08:32:02 0 d—–w- c:\docume~1\alluse~1.win\applic~1\AVG Security Toolbar 2010-05-22 08:31:46 0 d—–w- c:\docume~1\alluse~1.win\applic~1\avg9 2010-05-22 08:26:08 26368 -c–a-w- c:\windows\system32\dllcache\usbstor.sys 2010-05-22 08:23:31 81920 —-a-w- c:\windows\system32\igfxres.dll 2010-05-22 08:20:41 192512 ——w- c:\windows\system32\AegisI5.exe 2010-05-22 08:20:09 87936 —-a-r- c:\windows\system32\drivers\gtipci21.sys 2010-05-22 08:20:09 28672 —-a-r- c:\windows\cttib1.dll 2010-05-22 08:15:30 667648 —-a-w- c:\windows\system32\BCMLogon.dll 2010-05-22 08:14:01 5 —-a-w- c:\windows\system32\drivers\DELL_LAT_D610.MRK 2010-05-22 08:14:01 5 —-a-w- c:\windows\system32\drivers\1028_DELL_LAT_D610.MRK 2010-05-22 08:13:54 666 —-a-w- c:\windows\speed.reg 2010-05-22 08:08:37 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Novatel Wireless 2010-05-22 08:05:09 6272 -c–a-w- c:\windows\system32\dllcache\splitter.sys 2010-05-22 08:05:09 6272 —-a-w- c:\windows\system32\drivers\splitter.sys 2010-05-22 08:05:05 83072 -c–a-w- c:\windows\system32\dllcache\wdmaud.sys 2010-05-22 08:05:05 83072 —-a-w- c:\windows\system32\drivers\wdmaud.sys 2010-05-22 08:05:02 52864 -c–a-w- c:\windows\system32\dllcache\dmusic.sys 2010-05-22 08:05:02 52864 —-a-w- c:\windows\system32\drivers\DMusic.sys 2010-05-22 08:05:00 56576 -c–a-w- c:\windows\system32\dllcache\swmidi.sys 2010-05-22 08:05:00 56576 —-a-w- c:\windows\system32\drivers\swmidi.sys 2010-05-22 08:01:41 178 –sh–w- c:\documents and settings\Tom Clinic\ntuser.ini 2010-05-22 07:56:59 4096 -c–a-w- c:\windows\system32\dllcache\rpcref.dll 2010-05-22 07:55:58 56320 -c–a-w- c:\windows\system32\dllcache\convlog.exe 2010-05-22 07:54:56 2577 —-a-w- c:\windows\system32\CONFIG.NT 2010-05-22 07:54:56 0 —-a-w- c:\windows\control.ini 2010-05-22 07:54:46 23392 —-a-w- c:\windows\system32\nscompat.tlb 2010-05-22 07:54:46 16832 —-a-w- c:\windows\system32\amcompat.tlb 2010-05-22 07:54:44 316640 —-a-w- c:\windows\WMSysPr9.prx 2010-05-22 07:53:43 0 d-sh–w- c:\documents and settings\all users.windows\DRM 2010-05-22 07:53:29 488 —ha-r- c:\windows\system32\WindowsLogon.manifest 2010-05-22 07:53:29 488 —ha-r- c:\windows\system32\logonui.exe.manifest 2010-05-22 07:53:21 749 —ha-r- c:\windows\WindowsShell.Manifest 2010-05-22 07:53:21 749 —ha-r- c:\windows\system32\wuaucpl.cpl.manifest 2010-05-22 07:53:21 749 —ha-r- c:\windows\system32\sapi.cpl.manifest 2010-05-22 07:53:21 749 —ha-r- c:\windows\system32\nwc.cpl.manifest 2010-05-22 07:53:21 749 —ha-r- c:\windows\system32\ncpa.cpl.manifest 2010-05-22 07:53:21 749 —ha-r- c:\windows\system32\cdplayer.exe.manifest 2010-05-22 07:51:59 65536 -c–a-w- c:\windows\system32\dllcache\icwphbk.dll 2010-05-22 07:50:42 5632 -c–a-w- c:\windows\system32\dllcache\write.exe 2010-05-22 07:49:58 40840 —-a-w- c:\windows\system32\drivers\termdd.sys 2010-05-22 07:49:58 196224 —-a-w- c:\windows\system32\drivers\rdpdr.sys 2010-05-21 21:47:11 4444 —-a-w- c:\windows\system32\pid.PNF 2010-05-21 21:44:53 47066 -c–a-w- c:\windows\system32\dllcache\ksc.nls 2010-05-21 21:43:45 3072 —-a-w- c:\windows\system32\drivers\audstub.sys 2010-05-21 21:42:56 57600 —-a-w- c:\windows\system32\drivers\redbook.sys 2010-05-21 21:42:11 5504 —-a-w- c:\windows\system32\drivers\intelide.sys 2010-05-21 21:42:03 74240 -c–a-w- c:\windows\system32\dllcache\usbui.dll 2010-05-21 21:42:03 74240 —-a-w- c:\windows\system32\usbui.dll 2010-05-21 21:41:52 10240 —-a-w- c:\windows\system32\drivers\compbatt.sys 2010-05-21 21:41:51 14208 —-a-w- c:\windows\system32\drivers\battc.sys 2010-05-21 21:41:51 13952 —-a-w- c:\windows\system32\drivers\CmBatt.sys 2010-05-21 21:40:06 356120 —-a-w- c:\windows\system32\PerfStringBackup.INI 2010-05-21 21:40:04 4161 —-a-w- c:\windows\ODBCINST.INI 2010-05-21 21:40:01 19456 -c–a-w- c:\windows\system32\dllcache\agt041f.dll 2010-05-21 21:40:01 19456 -c–a-w- c:\windows\system32\dllcache\agt0419.dll 2010-05-21 21:40:00 66082 -c–a-w- c:\windows\system32\dllcache\c_28603.nls 2010-05-21 21:40:00 66082 —-a-w- c:\windows\system32\c_28603.nls 2010-05-21 21:40:00 22016 -c–a-w- c:\windows\system32\dllcache\agt0408.dll 2010-05-21 21:40:00 19968 -c–a-w- c:\windows\system32\dllcache\agt040e.dll 2010-05-21 21:40:00 19456 -c–a-w- c:\windows\system32\dllcache\agt0415.dll 2010-05-21 21:40:00 19456 -c–a-w- c:\windows\system32\dllcache\agt0405.dll 2010-05-21 21:39:34 0 d—–r- c:\documents and settings\all users.windows\Documents 2010-05-21 21:37:49 261 —-a-w- c:\windows\system32\$winnt$.inf 2010-05-15 03:21:39 0 d—–w- c:\program files\Trend Micro 2010-05-12 17:09:52 0 d—–w- c:\program files\Moffsoft FreeCalc 2010-05-11 23:18:31 0 d—–w- c:\program files\ICBCEbankTools 2010-05-08 04:56:52 0 d—–w- c:\program files\common files\rplsp 2010-05-08 00:01:35 0 d—–w- c:\windows\speech 2010-05-07 23:57:31 0 d—–w- c:\program files\WinMPG VideoConvert 2010-05-07 23:51:08 0 d—–w- c:\program files\calc450 2010-05-07 23:22:23 0 d—–w- c:\program files\MathType 2010-05-07 14:06:25 0 d—–w- c:\program files\图片无损放大.PhotoZoomPro2.3.4中文绿色单文件版 2010-05-06 22:23:40 0 d—–w- c:\program files\foxit_reader 2010-05-04 05:33:32 0 d—–w- c:\program files\3dhome40 2010-05-03 06:47:59 0 d—–w- c:\program files\WinPatrol 2010-05-02 17:51:33 0 d—–w- c:\windows\system32\ZoneLabs 2010-05-02 17:51:33 0 d—–w- c:\program files\Zone Labs 2010-05-02 17:50:12 0 d—–w- c:\windows\Internet Logs 2010-05-02 08:04:06 0 d—–w- c:\windows\system32\zh-CN 2010-05-02 08:01:19 0 d—–w- c:\windows\system32\XPSViewer 2010-05-02 08:00:20 0 d—–w- C:\3b402a29296d391eef78226f 2010-04-30 20:22:55 0 d—–w- c:\program files\Hard Drive Inspector Professional v3.70.337 2010-04-29 04:11:33 0 d—–w- c:\program files\SolidDocuments 2010-04-28 01:02:28 0 d—–w- c:\program files\腾讯游戏 2010-04-27 09:33:38 979824 —-a-w- c:\windows\system32\SogouPy.ime 2010-04-27 08:01:01 0 d—–w- c:\program files\StormII 2010-04-27 07:08:52 0 d—–w- c:\program files\Conew 2010-04-27 07:07:09 0 d—–w- c:\program files\Meitu 2010-04-27 07:04:18 0 d—–w- c:\program files\nEO iMAGING 2010-04-27 06:11:42 0 d–h–w- C:\$AVG 2010-04-26 20:46:14 0 d—–w- c:\program files\easyMule 2010-04-26 19:09:47 0 d—–w- c:\program files\common files\HP 2010-04-26 19:06:32 0 d—–w- c:\program files\HP 2010-04-26 13:39:46 0 d—–w- c:\program files\SogouExtension 2010-04-26 13:28:18 0 d—–w- c:\program files\Malwarebytes' Anti-Malware ==================== Find3M ==================== 2010-05-22 07:51:21 21640 —-a-w- c:\windows\system32\emptyregdb.dat 2010-04-17 08:12:18 48464 —-a-w- c:\windows\system32\sirenacm.dll 2010-03-10 06:15:52 420352 —-a-w- c:\windows\system32\vbscript.dll 2010-02-25 06:24:37 916480 —-a-w- c:\windows\system32\wininet.dll ============= FINISH: 16:56:20.48 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-03-17.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 5/21/2010 9:57:44 PM System Uptime: 5/25/2010 2:18:28 PM (2 hours ago) Motherboard: Dell Inc. | | Processor: Intel® Pentium® M processor 1.86GHz | Microprocessor | 1861/133mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 233 GiB total, 208.753 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1: 5/21/2010 10:02:09 PM - System Checkpoint RP2: 5/21/2010 10:05:10 PM - 已安装 C-Major Audio RP3: 5/21/2010 10:08:35 PM - Installed Dell Mobile Broadband Card Utility RP4: 5/21/2010 10:13:54 PM - 已安装 Dell System Software RP5: 5/21/2010 10:14:01 PM - 已安装 Notebook System Software RP6: 5/21/2010 10:17:19 PM - 已安装 Broadcom Gigabit Integrated Controller RP7: 5/21/2010 10:18:08 PM - 已安装 Dell System Software RP8: 5/21/2010 10:18:16 PM - 已安装 Notebook System Software RP9: 5/21/2010 10:19:50 PM - 已安装 TI_Inst RP10: 5/21/2010 10:31:45 PM - Installed AVG 9.0 RP11: 5/21/2010 10:38:54 PM - 已配置 Broadcom Gigabit Integrated Controller RP12: 5/21/2010 10:39:49 PM - Avg8 Update RP13: 5/21/2010 10:53:37 PM - Avg Update RP14: 5/21/2010 11:03:34 PM - Software Distribution Service 3.0 RP15: 5/21/2010 11:26:42 PM - Installed Windows XP WgaNotify. RP16: 5/22/2010 1:32:57 AM - Installed PerfectDisk 10 Professional. RP17: 5/22/2010 3:37:05 AM - Installed Windows Media Player 11 RP18: 5/22/2010 3:40:04 AM - Software Distribution Service 3.0 RP19: 5/22/2010 8:17:45 AM - Software Distribution Service 3.0 RP20: 5/22/2010 8:46:01 AM - Installed WinZip 14.5 RP21: 5/22/2010 8:59:25 AM - Removed WinZip 14.5 RP22: 5/22/2010 9:18:38 AM - 安装了 Microsoft Office Professional Edition 2003 RP23: 5/22/2010 6:26:16 PM - Software Distribution Service 3.0 RP24: 5/23/2010 2:57:37 PM - Software Distribution Service 3.0 RP25: 5/24/2010 7:36:21 PM - System Checkpoint RP26: 5/25/2010 3:35:35 PM - Software Distribution Service 3.0 ==== Installed Programs ====================== Ad-Aware Ad-Aware Email Scanner for Outlook Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin AI RoboForm (All Users) AVG 9.0 Broadcom Gigabit Integrated Controller BufferChm C-Major Audio CustomerResearchQFolder Dell Mobile Broadband Card Utility Dell Wireless WLAN Card DeviceDiscovery DeviceManagementQFolder DivX Pro 视频编解码器 DJ_SF_03_D4300_ProductContext DJ_SF_03_D4300_Software DJ_SF_03_D4300_Software_Min Download Accelerator Plus (DAP) ePrompter eSupportQFolder Foxit Reader GPBaseService HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HP Customer Participation Program 10.0 HP Deskjet D4300 Printer Driver Software 10.0 Rel .3 HP Imaging Device Functions 10.0 HP Photosmart Essential 2.5 HP Smart Web Printing HP Solution Center 10.0 HP Update HPProductAssistant HPSSupply Intel® Graphics Media Accelerator Driver for Mobile Malwarebytes' Anti-Malware MarketResearch Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office Professional Edition 2003 Microsoft Office Word 2003 稿纸加载项 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable MSVCRT OGA Notifier 2.0.0048.0 PerfectDisk 10 Professional PSSWCORE Registry Mechanic 9.0 Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB981332) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB979402) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB981349) Segoe UI Shop for HP Supplies Skype™ 4.2 SmartWebPrintingOC SolutionCenter Status Texas Instruments PCIxx21/x515 drivers. TI_Inst Toolbox TrayApp Trillian UnloadSupport Update for Windows Internet Explorer 8 (KB976662) Update for Windows Internet Explorer 8 (KB980182) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update for Windows XP (KB980182) VC 9.0 Runtime VideoToolkit01 Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WebFldrs XP WebReg Windows Genuine Advantage Notifications (KB905474) Windows Internet Explorer 8 Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Live Sign-in Assistant Windows Live Upload Tool Windows Media Format 11 runtime Windows Media Player 11 WinRAR archiver ZoneAlarm Pro 可牛影像 2.4.1.1003 正式版升级包 搜狗拼音输入法 5.0正式版 美图拍拍 1.1.7 美图看看 1.2.8 美图秀秀 2.2.9 ==== Event Viewer Messages From Past Week ======== 5/25/2010 9:32:31 AM, error: atapi [11] - The driver detected a controller error on \Device\Ide\IdePort0. 5/25/2010 9:30:35 AM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period. 5/25/2010 8:52:43 AM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. 5/25/2010 2:24:57 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. 5/24/2010 7:19:38 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. 5/24/2010 7:09:44 AM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. 5/23/2010 9:41:41 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. 5/23/2010 8:39:32 AM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. 5/23/2010 6:45:21 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. 5/23/2010 2:50:16 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: IntelIde 5/23/2010 2:50:16 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. 5/23/2010 11:33:48 AM, error: Service Control Manager [7001] - The Universal Plug and Play Device Host service depends on the SSDP Discovery Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 5/23/2010 11:33:47 AM, error: DCOM [10005] - DCOM got error "%1068" attempting to start the service upnphost with arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56} 5/22/2010 8:41:22 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. 5/22/2010 8:35:19 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 5/22/2010 8:32:16 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service hpqcxs08 with arguments "" in order to run the server: {1DAEDD8A-30ED-4585-9CF1-13BDF7791DDE} 5/22/2010 8:31:05 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip vsdatant 5/22/2010 8:31:05 PM, error: Service Control Manager [7001] - The TrueVector Internet Monitor service depends on the vsdatant service which failed to start because of the following error: A device attached to the system is not functioning. 5/22/2010 8:31:05 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 5/22/2010 8:31:05 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 5/22/2010 8:31:05 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 5/22/2010 8:31:05 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 5/22/2010 8:30:32 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 5/22/2010 8:30:29 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 5/22/2010 8:28:23 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. 5/22/2010 8:27:20 AM, error: Service Control Manager [7034] - The Kingsoft Antivirus WebShield Service service terminated unexpectedly. It has done this 1 time(s). 5/22/2010 8:23:30 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. 5/22/2010 6:36:39 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. 5/22/2010 5:44:07 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service BITS with arguments "" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097} 5/22/2010 4:27:58 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service SENS with arguments "" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E} 5/22/2010 4:27:57 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. 5/22/2010 11:41:50 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. 5/22/2010 11:36:21 PM, error: Service Control Manager [7022] - The HP CUE DeviceDiscovery 服务 service hung on starting. ==== End Of File ===========================
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-25 17:13:01
Windows 5.1.2600 Service Pack 3
Running: 5r4istu8.exe; Driver: C:\DOCUME~1\TomZH~1\LOCALS~1\Temp\aggcrpob.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwConnectPort [0xA48DB8D0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateFile [0xA48D86E0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateKey [0xA48E5490]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreatePort [0xA48DBE90]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateProcess [0xA48E2C80]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateProcessEx [0xA48E2E90]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateSection [0xA48E6D50]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0xA48DBF80]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDeleteFile [0xA48D8C70]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDeleteKey [0xA48E5D10]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDeleteValueKey [0xA48E5AC0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwDuplicateObject [0xA48E2600]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwLoadKey [0xA48E6230]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0xA48E62B0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwMapViewOfSection [0xA48E6FD0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwOpenFile [0xA48D8AD0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwOpenProcess [0xA48E44F0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwOpenThread [0xA48E42B0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRenameKey [0xA48E6970]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwReplaceKey [0xA48E63D0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0xA48DB4F0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwRestoreKey [0xA48E67C0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSecureConnectPort [0xA48DBAA0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0xA48D8EA0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSetValueKey [0xA48E5800]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwSystemDebugControl [0xA48E3580]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD) ZwTerminateProcess [0xA48E3400]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[284] [0xA3D732C0]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[285] [0xA3D73320]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[286] [0xA3D73370]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[287] [0xA3D733C0]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[288] [0xA3D73410]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[289] [0xA3D73460]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[290] [0xA3D734A0]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[291] [0xA3D734E0]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[292] [0xA3D73530]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[293] [0xA3D73580]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[294] [0xA3D735E0]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[295] [0xA3D73630]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[296] [0xA3D73680]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[297] [0xA3D736D0]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[298] [0xA3D73710]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[299] [0xA3D73770]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[300] [0xA3D737C0]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[301] [0xA3D73810]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[302] [0xA3D73850]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[303] [0xA3D73890]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[304] [0xA3D738D0]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[305] [0xA3D73940]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[306] [0xA3D73990]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[307] [0xA3D739D0]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[308] [0xA3D73A10]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[309] [0xA3D73A80]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[310] [0xA3D73AD0]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[311] [0xA3D73B20]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[312] [0xA3D73B80]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[313] [0xA3D73BE0]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[314] [0xA3D73C20]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[315] [0xA3D73C70]
SSDT \??\C:\WINDOWS\system32\Drivers\KAVSafe.sys (Kingsoft Antivirus Defend Engine Safe Module/Kingsoft Corporation) SSDT[316] [0xA3D73CC0]

—- Kernel code sections - GMER 1.0.15 —-

? srescan.sys The system cannot find the file specified. !

—- Devices - GMER 1.0.15 —-

Device \Driver\Tcpip \Device\Ip vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Tcpip \Device\Tcp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

Device \Driver\Tcpip \Device\Udp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp Lbd.sys (Boot Driver/Lavasoft AB)

Device \Driver\Tcpip \Device\RawIp vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp Lbd.sys (Boot Driver/Lavasoft AB)

Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (TrueVector Device Driver/Check Point Software Technologies LTD)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter@FriendlyName Indeo? video 5.10 Compression Filter
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter@CLSID {1F73E9B1-8C3A-11D0-A3BE-00A0C9244436}
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter@FilterData 0x02 0x00 0x00 0x00 …
Reg HKLM\SOFTWARE\Classes\CLSID\{33D9A760-90C8-11d0-BD43-00A0C911CE86}\Instance\Indeo?video 5.10 Compression Filter@EncoderType 1

—- EOF - GMER 1.0.15 —-
Hi Catbyte,

Thanks for helping me again. Could you please help me remove Kingsoft Antivirus first? I have no idea how to do that; it is not in the Add and Remove Programs. Thanks!
Use the Revo Uninstaller to remove kingsoft

Download and install the Revo Uninstaller
  • Double click the new Revo Uninstaller icon on your desktop to start the program
  • Scroll through the listed programs and Right Click on the program you wish to uninstall (Kingsoft Antivirus)
  • From the pop out menu choose Uninstall
  • Click Yes to the confirmation dialogue
  • In the next window select the Advanced mode
  • Click Next to start uninstalling the program
  • Answer Yes to confirm the uninstall
  • When the program has completed the four steps, click Next to allow the program to search for leftovers
  • Once complete, click Next, then Finish
  • Repeat the above steps for any other programs you wish to remove.


NEXT



Download ComboFix from either of these locations:
Link 1
Link 2


VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi Catbyte,

Firstly, Revo Uninstaller could not find kingsoft antivirus; I had done uninstallation of that couple weeks ago with CCleaner and the uninstall did not seem to be a complete one. I would still need help on this.

Secondly, after running Combofix and a reboot, Winpatrol imformed me something being changed: host location (127.000?); then "Microsoft Corporation rundll32.exe ieframe.dll OpenURL %1." I allowed the host location change and now hesitate on the DLL change. Also, after reboot, Windows is asking for a CD rom or removable disk in order to install "PSSWCORE" which I have no idea what it is about.

Lastly, below is the log.file. Thanks again!
ComboFix 10-05-26.01 - Tom Clinci 6/2010 Wed 7:44.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.936.86.1033.18.2039.1389 [GMT -10:00]
location: c:\documents and settings\Tom Clinci\Desktop\ComboFix.exe
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Pro Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( deleted files )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Tom Clinci\Favorites\常用
c:\documents and settings\Tom Clinci\Favorites\常用\★淘宝皇冠店★.url
c:\documents and settings\Tom Clinci\Favorites\常用\淘宝网 - 淘!我喜欢.url
c:\program files\StormII
c:\program files\StormII\_uninstall.cmd
c:\program files\StormII\_reg.cmd
c:\program files\StormII\BFThumbs.dll
c:\program files\StormII\BugReport.exe
c:\program files\StormII\codec\264be.dll
c:\program files\StormII\codec\264dmmx.dll
c:\program files\StormII\codec\264dsse.dll
c:\program files\StormII\codec\264dsse2.dll
c:\program files\StormII\codec\264dsse3.dll
c:\program files\StormII\codec\ac3filter.ax
c:\program files\StormII\codec\atidvcr.dll
c:\program files\StormII\codec\avcodec.dll
c:\program files\StormII\codec\avdevice.dll
c:\program files\StormII\codec\avformat.dll
c:\program files\StormII\codec\AviSplitter.ax
c:\program files\StormII\codec\avssplitter.ax
c:\program files\StormII\codec\avsvideo.ax
c:\program files\StormII\codec\avutil.dll
c:\program files\StormII\codec\bass.dll
c:\program files\StormII\codec\bass_aac.dll
c:\program files\StormII\codec\bass_alac.dll
c:\program files\StormII\codec\bass_ape.dll
c:\program files\StormII\codec\bass_flac.dll
c:\program files\StormII\codec\bass_mpc.dll
c:\program files\StormII\codec\bass_tta.dll
c:\program files\StormII\codec\bass_wv.dll
c:\program files\StormII\codec\binkw32.dll
c:\program files\StormII\codec\cddareader.ax
c:\program files\StormII\codec\cl264dec.ax
c:\program files\StormII\codec\CLVc1Dec.ax
c:\program files\StormII\codec\CLVsd.ax
c:\program files\StormII\codec\clvsdx.ax
c:\program files\StormII\codec\coreavc.ax
c:\program files\StormII\codec\CUDA_Filter.ax
c:\program files\StormII\codec\davsts.ax
c:\program files\StormII\codec\DCBassSource.ax
c:\program files\StormII\codec\DEC_StdMpeg4.dll
c:\program files\StormII\codec\divxdec.ax
c:\program files\StormII\codec\dxvadec.ax
c:\program files\StormII\codec\empgdmx.ax
c:\program files\StormII\codec\EmzAMRNBDec.dll
c:\program files\StormII\codec\EmzMp4Source.dll
c:\program files\StormII\codec\EzdAMRWBDec.dll
c:\program files\StormII\codec\ff_kernelDeint.dll
c:\program files\StormII\codec\ff_liba52.dll
c:\program files\StormII\codec\ff_libavcodec.dll
c:\program files\StormII\codec\ff_libdts.dll
c:\program files\StormII\codec\ff_libfaad2.dll
c:\program files\StormII\codec\ff_libmad.dll
c:\program files\StormII\codec\ff_libmpeg2.dll
c:\program files\StormII\codec\ff_libmplayer.dll
c:\program files\StormII\codec\ff_realaac.dll
c:\program files\StormII\codec\ff_samplerate.dll
c:\program files\StormII\codec\ff_theora.dll
c:\program files\StormII\codec\ff_TomsMoComp.dll
c:\program files\StormII\codec\ff_tremor.dll
c:\program files\StormII\codec\ff_unrar.dll
c:\program files\StormII\codec\ff_vfw.dll
c:\program files\StormII\codec\ff_wmv9.dll
c:\program files\StormII\codec\ff_xvidcore.dll
c:\program files\StormII\codec\ffavisynth.dll
c:\program files\StormII\codec\ffdshow.ax
c:\program files\StormII\codec\ffdshow.ax.manifest
c:\program files\StormII\codec\FFDShowAPI.dll
c:\program files\StormII\codec\ffmpeg.dll
c:\program files\StormII\codec\ffsource.ax
c:\program files\StormII\codec\ffSpkCfg.dll
c:\program files\StormII\codec\Flash.ocx
c:\program files\StormII\codec\FLT_ffdshow.dll
c:\program files\StormII\codec\FLVSplitter.ax
c:\program files\StormII\codec\H264VDEC.dll
c:\program files\StormII\codec\HikAudioDec.ax
c:\program files\StormII\codec\HikDataDump.ax
c:\program files\StormII\codec\HikFileSource.ax
c:\program files\StormII\codec\HikFileSplitter.ax
c:\program files\StormII\codec\HikH264Dec.ax
c:\program files\StormII\codec\HikMpeg4Dec.ax
c:\program files\StormII\codec\HikPSDemux.ax
c:\program files\StormII\codec\iconv.dll
c:\program files\StormII\codec\ir50_32.dll
c:\program files\StormII\codec\libavcodec.dll
c:\program files\StormII\codec\MatroskaSplitter.ax
c:\program files\StormII\codec\mfplat.dll
c:\program files\StormII\codec\Microsoft.VC90.CRT.manifest
c:\program files\StormII\codec\mkunicode.dll
c:\program files\StormII\codec\mkx.dll
c:\program files\StormII\codec\mkzlib.dll
c:\program files\StormII\codec\mmamrdmx.ax
c:\program files\StormII\codec\mp4.dll
c:\program files\StormII\codec\MP4Splitter.ax
c:\program files\StormII\codec\mpeg2dmx.ax
c:\program files\StormII\codec\MpegSplitter.ax
c:\program files\StormII\codec\mpg4ds32.ax
c:\program files\StormII\codec\MPlayer.exe
c:\program files\StormII\codec\msvcp71.dll
c:\program files\StormII\codec\msvcr71.dll
c:\program files\StormII\codec\msvcr90.dll
c:\program files\StormII\codec\NDParser.ax
c:\program files\StormII\codec\NeSplitter.ax
c:\program files\StormII\codec\nvviddec.ax
c:\program files\StormII\codec\OggSplitter.ax
c:\program files\StormII\codec\ogm.dll
c:\program files\StormII\codec\PmpSplt.ax
c:\program files\StormII\codec\pthreadVC2.dll
c:\program files\StormII\codec\qasf.dll
c:\program files\StormII\codec\RadGtSplitter.ax
c:\program files\StormII\codec\RenderFilter.ax
c:\program files\StormII\codec\RMSplt.ax
c:\program files\StormII\codec\skinsres.dll
c:\program files\StormII\codec\smackw32.dll
c:\program files\StormII\codec\splitter.ax
c:\program files\StormII\codec\swscale.dll
c:\program files\StormII\codec\ts.dll
c:\program files\StormII\codec\tsccvid.dll
c:\program files\StormII\codec\vc1dc.dll
c:\program files\StormII\codec\vc1dmmx.dll
c:\program files\StormII\codec\vc1dsse.dll
c:\program files\StormII\codec\vc1dsse2.dll
c:\program files\StormII\codec\vc1wp.ax
c:\program files\StormII\codec\vp6vfw.dll
c:\program files\StormII\codec\vp7vfw.dll
c:\program files\StormII\codec\WavSplitter.ax
c:\program files\StormII\codec\WMADMOD.dll
c:\program files\StormII\codec\WMVDECOD.dll
c:\program files\StormII\codec\wmvdmod.dll
c:\program files\StormII\codec\xavsdec.dll
c:\program files\StormII\codec\xvid.ax
c:\program files\StormII\codec\xvidcore.dll
c:\program files\StormII\Config.dll
c:\program files\StormII\CoreLog.dll
c:\program files\StormII\current.ecs
c:\program files\StormII\DXVACheck.dll
c:\program files\StormII\DXVAMgr.dll
c:\program files\StormII\FilterInfo.dll
c:\program files\StormII\FlashWindowDll.dll
c:\program files\StormII\GdiPlus.dll
c:\program files\StormII\GifParser.dll
c:\program files\StormII\HD\ATI UVD解决方案(Vista_Win7).xml
c:\program files\StormII\HD\ATI UVD解决方案.xml
c:\program files\StormII\HD\ATI UVD解决方案2.xml
c:\program files\StormII\HD\Intel解决方案(Vista_Win7).xml
c:\program files\StormII\HD\Intel解决方案.xml
c:\program files\StormII\HD\MPEG-2解决方案.xml
c:\program files\StormII\HD\NVidia CUDA解决方案.xml
c:\program files\StormII\HD\NVidia PureVideoHD解决方案(Vista_Win7).xml
c:\program files\StormII\HD\NVidia PureVideoHD解决方案.xml
c:\program files\StormII\HD\NVidia PureVideoHD解决方案2.xml
c:\program files\StormII\HD\PowerDVD解决方案.xml
c:\program files\StormII\HD\VIA解决方案.xml
c:\program files\StormII\HD\微软解决方案(Vista_Win7).xml
c:\program files\StormII\HD\暴风影音解决方案.xml
c:\program files\StormII\intr.dll
c:\program files\StormII\jscript.dll
c:\program files\StormII\kcheck2.dll
c:\program files\StormII\keys.dat
c:\program files\StormII\mcntr.dll
c:\program files\StormII\MediaInfo.dll
c:\program files\StormII\MediaLib.dll
c:\program files\StormII\mee.db
c:\program files\StormII\meedb.dll
c:\program files\StormII\minfo\MediaInfo2.dll
c:\program files\StormII\minfo\MInfo.dll
c:\program files\StormII\mps.dll
c:\program files\StormII\msscript.ocx
c:\program files\StormII\msvcp60.dll
c:\program files\StormII\Option.dll
c:\program files\StormII\p2p_player.swf
c:\program files\StormII\rndrmgr.dll
c:\program files\StormII\rplsp\pncrt.dll
c:\program files\StormII\rplsp\Rpl\Codecs\14_43260.dll
c:\program files\StormII\rplsp\Rpl\Codecs\28_83260.dll
c:\program files\StormII\rplsp\Rpl\Codecs\atrc.dll
c:\program files\StormII\rplsp\Rpl\Codecs\cook.dll
c:\program files\StormII\rplsp\Rpl\Codecs\dnet3260.dll
c:\program files\StormII\rplsp\Rpl\Codecs\drv2.dll
c:\program files\StormII\rplsp\Rpl\Codecs\drvc.dll
c:\program files\StormII\rplsp\Rpl\Codecs\raac.dll
c:\program files\StormII\rplsp\Rpl\Codecs\ralf.dll
c:\program files\StormII\rplsp\Rpl\Codecs\sipr.dll
c:\program files\StormII\Skin\大片风暴.bfsk
c:\program files\StormII\Skin\幽蓝墨韵.bfsk
c:\program files\StormII\Skin\暴风影音2012.bfsk
c:\program files\StormII\Skin\深宇之夜.bfsk
c:\program files\StormII\spfa.dll
c:\program files\StormII\splayers.dll
c:\program files\StormII\Storm.exe
c:\program files\StormII\StormRes.dll
c:\program files\StormII\StormSkinRes.dll
c:\program files\StormII\StormUpdate.dll
c:\program files\StormII\StormUpdate.exe
c:\program files\StormII\subdecoder.dll
c:\program files\StormII\swDirScaner.dll
c:\program files\StormII\Tips.dll
c:\program files\StormII\unrar.dll
c:\program files\StormII\使用说明.txt
c:\windows\system32\AbaleZip.dll

.
((((((((((((((((((((((((( 2010-04-26 to 2010-05-26 new files )))))))))))))))))))))))))))))))
.

2010-05-26 17:14 . 2010-05-26 17:14 ——– d—–w- c:\documents and settings\Tom Clinci\Local Settings\Application Data\VS Revo Group
2010-05-26 17:14 . 2010-05-26 17:14 ——– d—–w- c:\windows\LastGood
2010-05-26 17:14 . 2009-12-30 22:20 27064 —-a-w- c:\windows\system32\drivers\revoflt.sys
2010-05-26 17:14 . 2010-05-26 17:14 ——– d—–w- c:\program files\VS Revo Group
2010-05-26 08:14 . 2010-05-26 08:19 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\WeatherWatcherLive
2010-05-26 08:13 . 2010-05-26 08:14 ——– d—–w- c:\program files\Weather Watcher Live
2010-05-26 08:13 . 2004-05-27 11:32 102400 —-a-w- c:\windows\system32\unzip32.dll
2010-05-26 07:32 . 2010-05-26 07:32 ——– d—–w- c:\program files\X桌面软件
2010-05-26 02:03 . 2010-05-26 02:03 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Office Genuine Advantage
2010-05-26 02:03 . 2010-05-26 02:03 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\Office Genuine Advantage
2010-05-24 07:59 . 2010-05-24 07:59 ——– d—–w- c:\documents and settings\Tom Clinci\Local Settings\Application Data\Identities
2010-05-24 00:44 . 2009-08-07 05:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-05-24 00:44 . 2009-08-07 05:23 215920 —-a-w- c:\windows\system32\muweb.dll
2010-05-23 11:14 . 2010-04-27 15:16 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-05-23 10:56 . 2001-08-18 08:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2010-05-23 10:56 . 2008-04-14 15:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2010-05-23 10:56 . 2008-04-14 10:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2010-05-23 10:56 . 2008-04-14 10:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-05-23 09:30 . 2010-02-04 15:53 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-05-23 09:30 . 2010-05-23 09:30 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-23 09:23 . 2010-05-23 09:23 ——– d—–w- c:\documents and settings\Tom Clinci\Local Settings\Application Data\Sunbelt Software
2010-05-23 09:22 . 2010-05-23 09:22 ——– dc-h–w- c:\documents and settings\All Users.WINDOWS\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-23 09:22 . 2010-02-04 15:53 2954656 -c–a-w- c:\documents and settings\All Users.WINDOWS\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-05-23 09:22 . 2010-05-23 09:30 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2010-05-23 09:20 . 2010-05-23 09:20 ——– d—–w- c:\program files\Foxit Software
2010-05-23 08:41 . 2010-05-23 08:41 537088 —-a-w- c:\documents and settings\Tom Clinci\Application Data\Meitu\KanKan\PlugIns\facedetect\facedetect.dll
2010-05-23 06:17 . 2010-05-24 17:12 ——– d—–w- c:\documents and settings\Tom Clinci\Tracing
2010-05-23 06:15 . 2010-05-23 06:15 ——– d—–w- c:\program files\Microsoft
2010-05-23 02:40 . 2010-05-23 02:40 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\WEBREG
2010-05-23 02:28 . 2010-05-23 02:28 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\HP
2010-05-23 02:20 . 2010-05-23 02:22 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\HP
2010-05-23 02:20 . 2010-05-23 02:20 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\HP Product Assistant
2010-05-23 02:19 . 2010-05-23 02:19 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Hewlett-Packard
2010-05-23 02:18 . 2007-11-08 15:06 271704 —-a-r- c:\windows\system32\hpzids01.dll
2010-05-23 02:18 . 2007-10-21 04:25 117760 —-a-w- c:\windows\system32\hpzll5mu.dll
2010-05-23 02:18 . 2007-10-21 04:21 278016 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5mu.dll
2010-05-23 02:15 . 2008-04-14 10:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2010-05-23 02:15 . 2008-04-14 10:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2010-05-23 02:15 . 2008-04-14 10:15 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-05-23 02:15 . 2008-04-14 10:15 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2010-05-23 02:10 . 2010-05-23 02:41 168980 —-a-w- c:\windows\hphins27.dat
2010-05-23 02:10 . 2007-12-13 00:04 787 ——w- c:\windows\hphmdl27.dat
2010-05-23 01:41 . 2008-04-14 12:00 26624 —-a-w- c:\documents and settings\LocalService.NT AUTHORITY.000\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2010-05-22 22:51 . 2010-05-22 22:51 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\Tencent
2010-05-22 20:36 . 2010-05-22 20:36 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Tencent
2010-05-22 19:19 . 2010-05-22 19:19 7358 —-a-r- c:\documents and settings\Tom Clinci\Application Data\Microsoft\Installer\{C2182670-EEF5-4B1C-822F-66972FFDEAC7}\_69525f90.exe
2010-05-22 19:19 . 2007-04-09 05:23 28552 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2010-05-22 19:19 . 2007-04-09 05:23 28040 —-a-w- c:\windows\system32\mdimon.dll
2010-05-22 19:18 . 2010-05-22 19:18 ——– d—–w- c:\program files\Microsoft ActiveSync
2010-05-22 18:21 . 2010-05-22 18:21 ——– d-sh–w- c:\documents and settings\LocalService.NT AUTHORITY.000\IETldCache
2010-05-22 18:17 . 2010-05-22 18:17 95744 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\SpeedBit\DAP\SDCondition.dll
2010-05-22 13:37 . 2010-05-22 19:04 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\WinZip
2010-05-22 13:32 . 2010-05-22 13:32 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\DivX
2010-05-22 13:31 . 2010-05-26 02:02 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Storm
2010-05-22 13:27 . 2010-05-26 09:21 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2010-05-22 13:26 . 2010-05-22 13:27 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\SolidDocuments
2010-05-22 13:25 . 2010-05-22 13:25 56 —ha-w- c:\windows\system32\ezsidmv.dat
2010-05-22 13:25 . 2010-05-26 01:41 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\skypePM
2010-05-22 13:24 . 2010-05-22 13:25 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Skype
2010-05-22 13:19 . 2010-05-26 01:47 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\Skype
2010-05-22 13:14 . 2010-05-22 13:15 ——– d—–w- c:\program files\Raxco
2010-05-22 13:13 . 2010-05-22 13:13 20 —-a-w- c:\windows\system32\pub_store.dat
2010-05-22 13:07 . 2010-05-22 13:07 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\Meitu
2010-05-22 12:33 . 2010-05-22 12:33 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\SogouPY.users
2010-05-22 12:33 . 2010-05-26 08:42 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\SogouPY
2010-05-22 11:56 . 2010-05-22 11:56 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\Malwarebytes
2010-05-22 11:56 . 2010-04-30 01:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-22 11:56 . 2010-05-22 11:56 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2010-05-22 11:56 . 2010-04-30 01:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-05-22 11:52 . 2010-05-22 11:52 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\SpeedBit
2010-05-22 11:33 . 2010-05-22 11:33 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\Registry Mechanic
2010-05-22 11:33 . 2010-05-22 11:33 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Raxco
2010-05-22 11:24 . 2010-05-22 11:24 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\Trillian
2010-05-22 11:16 . 2010-05-23 23:23 ——– d—a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2010-05-22 11:14 . 2010-04-25 15:44 60008 —-a-w- c:\windows\system32\drivers\KAVSafe.sys
2010-05-22 11:14 . 2010-05-23 02:23 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\kingsoft
2010-05-22 11:13 . 2010-05-22 11:13 ——– d—–w- c:\documents and settings\Tom Clinci\Local Settings\Application Data\Opera
2010-05-22 11:10 . 2010-05-22 11:10 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\Avant Profiles
2010-05-22 11:08 . 2010-05-22 11:08 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Fetion
2010-05-22 11:07 . 2010-05-22 11:09 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\Fetion
2010-05-22 11:07 . 2010-05-23 06:16 24320 —-a-w- c:\documents and settings\Tom Clinci\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-22 10:19 . 2010-05-22 11:20 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\RoboForm
2010-05-22 10:09 . 2010-05-22 10:09 0 —-a-w- c:\windows\nsreg.dat
2010-05-22 10:08 . 2010-05-22 10:08 ——– d—–w- c:\documents and settings\Tom Clinci\Local Settings\Application Data\Mozilla
2010-05-22 09:54 . 2010-05-23 08:40 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\TeamViewer
2010-05-22 09:35 . 2010-05-22 09:35 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\WinPatrol
2010-05-22 09:35 . 2010-04-24 17:41 0 —-a-w- c:\documents and settings\Tom Clinci\Application Data\WinPatrol\Config.sys
2010-05-22 09:35 . 2010-04-24 17:41 0 —-a-w- c:\documents and settings\Tom Clinci\Application Data\WinPatrol\Autoexec.bat
2010-05-22 09:34 . 2010-05-22 09:34 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\Softarium.com
2010-05-22 09:33 . 2010-05-22 09:33 ——– d—–w- c:\documents and settings\Tom Clinci\Application Data\kingsoft
2010-05-22 09:26 . 2010-05-22 09:26 ——– d-sh–w- c:\documents and settings\Tom Clinci\IECompatCache
2010-05-22 09:26 . 2010-05-22 09:26 ——– d-sh–w- c:\documents and settings\Tom Clinci\PrivacIE
2010-05-22 09:26 . 2009-10-16 22:13 1115392 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-05-22 09:22 . 2010-05-22 09:22 ——– d-sh–w- c:\documents and settings\Tom Clinci\IETldCache
2010-05-22 09:16 . 2010-05-22 09:27 ——– d—–w- c:\windows\system32\KB905474
2010-05-22 09:15 . 2010-02-25 21:54 11070976 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2010-05-22 09:15 . 2010-02-25 06:24 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-05-22 09:15 . 2010-02-25 06:24 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-05-22 09:15 . 2010-02-25 06:24 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-05-22 09:15 . 2010-02-25 06:24 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-05-22 09:15 . 2010-02-25 06:24 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2010-05-22 09:00 . 2008-06-13 11:05 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2010-05-22 09:00 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2010-05-22 08:59 . 2010-02-24 13:11 455680 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2010-05-22 08:55 . 2010-02-17 19:10 2189952 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-05-22 08:55 . 2010-02-16 14:08 2146304 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-05-22 08:55 . 2010-02-16 13:25 2024448 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-05-22 08:53 . 2010-05-22 08:53 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-05-22 08:44 . 2010-05-22 14:03 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-05-22 08:44 . 2008-10-10 00:25 69008 —-a-w- c:\windows\system32\zlcomm.dll
2010-05-22 08:44 . 2008-10-10 00:25 106384 —-a-w- c:\windows\system32\zlcommdb.dll
2010-05-22 08:44 . 2008-10-10 00:25 1221008 —-a-w- c:\windows\system32\zpeng25.dll
2010-05-22 08:42 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2010-05-22 08:38 . 2009-01-08 04:21 26144 —-a-w- c:\windows\system32\spupdsvc.exe
2010-05-22 08:32 . 2010-05-22 08:53 52872 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-05-22 08:32 . 2010-05-22 08:53 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-22 08:32 . 2010-05-22 08:53 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-05-22 08:32 . 2010-05-22 08:53 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-22 08:32 . 2010-05-22 09:26 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar
2010-05-22 08:31 . 2010-05-22 08:31 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\avg9
2010-05-22 08:26 . 2008-04-14 10:15 26368 -c–a-w- c:\windows\system32\dllcache\usbstor.sys
2010-05-22 08:23 . 2005-09-20 17:36 81920 —-a-w- c:\windows\system32\igfxres.dll
2010-05-22 08:20 . 2005-02-23 18:04 192512 ——w- c:\windows\system32\AegisI5.exe
2010-05-22 08:20 . 2005-05-31 18:46 87936 —-a-r- c:\windows\system32\drivers\gtipci21.sys
2010-05-22 08:20 . 2004-03-23 19:45 28672 —-a-r- c:\windows\cttib1.dll

.
(((((((((((((((((((((((((((((((((((((((( Files changed within three months ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-23 23:22 . 2010-04-26 13:28 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-22 21:59 . 2010-04-24 20:41 ——– d—–w- c:\program files\Trillian
2010-05-22 21:59 . 2010-04-24 21:47 ——– d—–w- c:\program files\ePrompter
2010-05-22 18:17 . 2010-04-25 19:35 ——– d—–w- c:\program files\Startup Faster 2004
2010-05-22 13:29 . 2010-04-24 20:14 ——– d—–w- c:\program files\SpywareBlaster
2010-05-22 12:35 . 2010-04-24 22:49 ——– d—–w- c:\program files\SogouInput
2010-05-22 11:52 . 2010-04-24 20:09 ——– d—–w- c:\program files\DAP
2010-05-22 08:24 . 2010-04-24 18:14 ——– d—–w- c:\program files\Dell
2010-05-22 08:08 . 2010-04-24 18:14 ——– d—–w- c:\program files\Common Files\Zeepe Framework 7
2010-05-22 07:54 . 2010-05-22 07:53 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-05-22 07:51 . 2010-05-22 07:51 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-05-08 03:23 . 2010-04-24 20:37 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-05-05 06:15 . 2010-04-26 13:39 ——– d—–w- c:\program files\SogouExtension
2010-05-04 23:30 . 2010-04-24 20:13 ——– d—–w- c:\program files\CCleaner
2010-04-25 06:45 . 2010-04-25 06:45 ——– d—–w- c:\program files\Java
2010-04-25 06:05 . 2010-04-25 06:00 ——– d—–w- c:\program files\StartupFaster
2010-04-25 06:03 . 2010-04-25 06:03 ——– d—–w- c:\program files\Common Files\Java
2010-04-25 05:48 . 2010-04-25 05:47 ——– d—–w- c:\program files\Wisdom-soft ScreenHunter 5 Free
2010-04-25 01:28 . 2010-04-25 01:28 ——– d—–w- c:\program files\YourWare Solutions
2010-04-25 01:12 . 2010-04-25 01:12 ——– d—–w- c:\program files\Microsoft.NET
2010-04-25 00:30 . 2010-04-25 00:30 ——– d—–w- c:\program files\Siber Systems
2010-04-24 23:05 . 2010-04-24 23:05 ——– d—–w- c:\program files\CursorXP
2010-04-24 23:00 . 2010-04-24 23:00 ——– d—–w- c:\program files\Kingsoft
2010-04-24 21:38 . 2010-04-24 21:37 ——– d—–w- c:\program files\Windows Live
2010-04-24 21:38 . 2010-04-24 21:38 ——– d—–w- c:\program files\Windows Live SkyDrive
2010-04-24 21:33 . 2010-04-24 18:09 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-24 21:25 . 2010-04-24 21:25 ——– d—–w- c:\program files\Common Files\Windows Live
2010-04-24 21:22 . 2010-04-24 21:22 ——– d—–w- c:\program files\China Mobile
2010-04-24 21:10 . 2010-04-24 21:10 ——– d—–w- c:\program files\Avant Browser
2010-04-24 20:56 . 2010-04-24 20:55 ——– d—–r- c:\program files\Skype
2010-04-24 20:55 . 2010-04-24 20:55 ——– d—–w- c:\program files\Common Files\Skype
2010-04-24 20:51 . 2010-04-24 20:51 ——– d—–w- c:\program files\TeamViewer
2010-04-24 20:23 . 2010-04-24 20:23 ——– d—–w- c:\program files\Lavasoft
2010-04-24 20:20 . 2010-04-24 20:17 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-04-24 19:57 . 2010-04-24 19:57 ——– d—–w- c:\program files\Idailydiary
2010-04-24 19:49 . 2010-04-24 19:49 ——– d—–w- c:\program files\reliz
2010-04-24 19:44 . 2010-04-24 19:44 ——– d—–w- c:\program files\Common Files\PC Tools
2010-04-24 19:35 . 2010-04-24 19:35 ——– d—–w- c:\program files\Ashampoo
2010-04-24 19:04 . 2010-04-24 19:04 ——– d—–w- c:\program files\Windows Media Connect 2
2010-04-24 18:26 . 2010-04-24 18:26 ——– d—–w- c:\program files\Broadcom
2010-04-24 18:26 . 2010-04-24 18:09 ——– d—–w- c:\program files\Common Files\InstallShield
2010-04-24 18:15 . 2010-04-24 18:15 ——– d—–w- c:\program files\Intel
2010-04-24 18:09 . 2010-04-24 18:09 ——– d—–w- c:\program files\SigmaTel
2010-04-24 18:05 . 2010-04-24 18:05 ——– d—–w- c:\program files\AVG
2010-04-24 17:42 . 2010-04-24 17:42 ——– d—–w- c:\program files\microsoft frontpage
2010-04-17 08:12 . 2010-04-17 08:12 48464 —-a-w- c:\windows\system32\sirenacm.dll
2010-03-10 06:15 . 2008-04-14 12:00 420352 —-a-w- c:\windows\system32\vbscript.dll
.

((((((((((((((((((((((((((((((((((((( important log on sites ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Attention* some are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0A0DDBD3-6641-40B9-873F-BBDD26D6C14E}]
2010-05-20 09:41 147928 —-a-w- c:\program files\easyMule\modules\IE2EM.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 20:25 2117704 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartupFaster"="c:\program files\Startup Faster 2004\StrpFstCfg.exe" [2005-02-21 2198016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\StartupFaster
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
StartupFaster.ini [2010-5-24 353]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-05-22 08:53 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\SogouInput\\5.0.0.3912\\PinyinUp.exe"=
"c:\\Program Files\\Meitu\\KanKan\\KanKan\\KanKan.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [5/21/2010 10:32 PM 52872]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/22/2010 11:30 PM 64288]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/21/2010 10:32 PM 216200]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/21/2010 10:32 PM 242896]
R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [5/21/2010 10:53 PM 916760]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [5/21/2010 10:53 PM 308064]
R2 KAVSafe;KAVSafe;c:\windows\system32\drivers\KAVSafe.sys [5/22/2010 1:14 AM 60008]
R2 KSDSVC;Kingsoft Common Content Service;c:\program files\Kingsoft\PowerWord PE\ksdsvc.exe [10/28/2009 11:58 PM 25240]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [4/26/2010 3:28 AM 304464]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [4/24/2010 9:44 AM 583640]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [5/21/2010 10:20 PM 87936]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [5/22/2010 1:56 AM 20952]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 5:52 AM 1314704]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [5/26/2010 7:14 AM 27064]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
contain in ‘task schedule’ folder

2010-05-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 09:30]

2010-05-26 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-04 01:07]

2010-05-26 c:\windows\Tasks\SogouImeMgr.job
- c:\progra~1\SOGOUI~1\500~1.391\SGTool.exe [2010-04-27 09:33]
.
.
——- other scans ——-
.
uStart Page = hxxp://www.baidu.com/index.php?tn=avantcn_dg
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: Download by easyMule - c:\program files\easyMule\IE2EM.htm
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Logoff - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComLogoff.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: 导出到 Microsoft Office Excel(&X) - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-26 07:53
Windows 5.1.2600 Service Pack 3 NTFS

Scan in process 。。。

scan hidden startup group 。。。
scan hidden folders 。。。

scan complete
hidden documents: 0

**************************************************************************
.
complete time: 2010-05-26 07:57:25
ComboFix-quarantined-files.txt 2010-05-26 17:57

Pre-Run: 224,012,648,448 bytes free
Post-Run: 223,924,707,328 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-CHS.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 7D32B7A4A25B34A6453CA515A476852B
Hi,

Please go into add/remove programs and uninstall all the programs you are no longer using:

NEXT


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
c:\windows\system32\drivers\KAVSafe.sys
c:\program files\Kingsoft\PowerWord PE\ksdsvc.exe

Folder::
c:\documents and settings\All Users.WINDOWS\Application Data\kingsoft
c:\documents and settings\Tom Clinci\Application Data\kingsoft
c:\program files\Kingsoft

Driver::
KAVSafe
KSDSVC

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Download and run Auslogics Disc Defragmenter
Hi Catbyte,

Thanks for the instruction. Combofix has just finished its scan with a reboot and a report; however, I have just realized that it has already deleted couple software I like to use: 1). c:\program files\StormII and 2) c:\program files\Kingsoft\PowerWord. Could it be possible to remove only "c:\windows\system32\drivers\KAVSafe.sys" and "ksdsvc.exe" and still keep powerword working if it is installed again next time? Could you please also tell me a little bit why StormII got deleted? And where did Admt kind of spyware come from?–I got them all the time from Ad-aware scan.

You asked me to download and run Auslogics Disc Defragmenter; however, I already have a perfect disk defragmenter which I have been using almost once in every other day for the past several months. Let me know if it is better or necessary to run Auslogics Disc Defragmenter.

Lastly, Windows keeps on asking for a CD rom or removable disk in order to install "PSSWCORE"–could you please tell me what to do with this? Thanks very much!
ComboFix 10-05-26.01 - Tom Clinic 7/2010 Thu 9:16.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.936.86.1033.18.2039.1414 [GMT -10:00]
Execute location: c:\documents and settings\Tom Clinic\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Tom Clinic\Desktop\CFScript.txt
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Pro Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

FILE ::
"c:\program files\Kingsoft\PowerWord PE\ksdsvc.exe"
"c:\windows\system32\drivers\KAVSafe.sys"
.

((((((((((((((((((((((((((((((((((((((( deleted files )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users.WINDOWS\Application Data\kingsoft
c:\documents and settings\All Users.WINDOWS\Application Data\kingsoft\kis\log\uplive\kislive_dll.log
c:\documents and settings\All Users.WINDOWS\Application Data\kingsoft\kis\uplive\addin.dat
c:\documents and settings\All Users.WINDOWS\Application Data\kingsoft\KXEngine\Data\kwsupd.dat
c:\documents and settings\All Users.WINDOWS\Application Data\kingsoft\KXEngine\Data\kwsupd.log
c:\program files\Kingsoft
c:\program files\Kingsoft\PowerWord PE\cache\baikedata.dat
c:\program files\Kingsoft\PowerWord PE\cache\netdicdata.dat
c:\program files\Kingsoft\PowerWord PE\cache\spelldata.dat
c:\program files\Kingsoft\PowerWord PE\cache\WikiData.dat
c:\program files\Kingsoft\PowerWord PE\cb_sound.swf
c:\program files\Kingsoft\PowerWord PE\CBDBCoreplus.dll
c:\program files\Kingsoft\PowerWord PE\CBGrabConnect_x64.exe
c:\program files\Kingsoft\PowerWord PE\CBGrabModule_x64.dll
c:\program files\Kingsoft\PowerWord PE\CBGrabProxy.dll
c:\program files\Kingsoft\PowerWord PE\CBParser.dll
c:\program files\Kingsoft\PowerWord PE\CBSelectText.dll
c:\program files\Kingsoft\PowerWord PE\CBSelectText_x64.dll
c:\program files\Kingsoft\PowerWord PE\CBTray.exe
c:\program files\Kingsoft\PowerWord PE\CBUpdate.exe
c:\program files\Kingsoft\PowerWord PE\CBUpdateself.exe
c:\program files\Kingsoft\PowerWord PE\CBux.dll
c:\program files\Kingsoft\PowerWord PE\CibaPopo.dll
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)\CBUpdateLog.txt
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)\config\filelist.ini
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)\config\filelist.ini_bak
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)\download\1508ceb890bc0a0c42a2aa8ee426017e.zip
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)\unzip\Setup_update.EXE
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)0\CBUpdateLog.txt
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)0\config\filelist.ini
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)0\config\filelist.ini_bak
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)0\download\54d89bfc50c889e58ade5ef6f17fb7ba.zip
c:\program files\Kingsoft\PowerWord PE\cibaupdate (作废)0\unzip\Setup_update.EXE
c:\program files\Kingsoft\PowerWord PE\cibaupdate\CBUpdateLog.txt
c:\program files\Kingsoft\PowerWord PE\cibaupdate\config\filelist.ini
c:\program files\Kingsoft\PowerWord PE\cibaupdate\config\filelist.ini_bak
c:\program files\Kingsoft\PowerWord PE\config\CBSDisList.txt
c:\program files\Kingsoft\PowerWord PE\config\CBSDisList_64.txt
c:\program files\Kingsoft\PowerWord PE\config\Defaultsort.ini
c:\program files\Kingsoft\PowerWord PE\config\GrabOption.ini
c:\program files\Kingsoft\PowerWord PE\CoolWord.exe
c:\program files\Kingsoft\PowerWord PE\coolword\GMAT词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\GRE词汇表.txt
c:\program files\Kingsoft\PowerWord PE\coolword\IELTS词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\MBA词汇表.txt
c:\program files\Kingsoft\PowerWord PE\coolword\MPA专业词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\MPA公共词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\MPA词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\MPA词组.txt
c:\program files\Kingsoft\PowerWord PE\coolword\TOFEL词汇表.txt
c:\program files\Kingsoft\PowerWord PE\coolword\大学英语六级词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\大学英语四级词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\成人高考词汇表.txt
c:\program files\Kingsoft\PowerWord PE\coolword\研究生入学考试词汇表.txt
c:\program files\Kingsoft\PowerWord PE\coolword\自考非英语专业专科词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\自考非英语专业基础词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\自考非英语专业本科词汇.txt
c:\program files\Kingsoft\PowerWord PE\coolword\高中英语词汇表.txt
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_back.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_end.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_foremost.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_front.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_latch-down.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_latch-up.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_off.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_setting.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_sound.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\button_stop.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\lock_bk.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\lockwindow_skin.xml
c:\program files\Kingsoft\PowerWord PE\coolword_skin\logo.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\resouce.xml
c:\program files\Kingsoft\PowerWord PE\coolword_skin\skin_bg.png
c:\program files\Kingsoft\PowerWord PE\coolword_skin\toolbar_skin.xml
c:\program files\Kingsoft\PowerWord PE\coolword_skin\word_bg.png
c:\program files\Kingsoft\PowerWord PE\data\ciba_segment.index
c:\program files\Kingsoft\PowerWord PE\data\default.html
c:\program files\Kingsoft\PowerWord PE\data\default_skin
c:\program files\Kingsoft\PowerWord PE\data\dj_sound.swf
c:\program files\Kingsoft\PowerWord PE\data\hanyu.html
c:\program files\Kingsoft\PowerWord PE\data\history_words.js
c:\program files\Kingsoft\PowerWord PE\data\img\17_03.gif
c:\program files\Kingsoft\PowerWord PE\data\img\17_04.gif
c:\program files\Kingsoft\PowerWord PE\data\img\bk001.gif
c:\program files\Kingsoft\PowerWord PE\data\img\bk002.gif
c:\program files\Kingsoft\PowerWord PE\data\img\bk003.gif
c:\program files\Kingsoft\PowerWord PE\data\img\bk004.gif
c:\program files\Kingsoft\PowerWord PE\data\img\cbdic_net.gif
c:\program files\Kingsoft\PowerWord PE\data\img\cbdic_new.gif
c:\program files\Kingsoft\PowerWord PE\data\img\dict_name_bk.gif
c:\program files\Kingsoft\PowerWord PE\data\img\dict_name_line.gif
c:\program files\Kingsoft\PowerWord PE\data\img\dj.gif
c:\program files\Kingsoft\PowerWord PE\data\img\dot.gif
c:\program files\Kingsoft\PowerWord PE\data\img\error_tip.gif
c:\program files\Kingsoft\PowerWord PE\data\img\googlelogo.png
c:\program files\Kingsoft\PowerWord PE\data\img\kingsoftlogo.png
c:\program files\Kingsoft\PowerWord PE\data\img\loading.gif
c:\program files\Kingsoft\PowerWord PE\data\img\logo-icon.png
c:\program files\Kingsoft\PowerWord PE\data\img\logo.gif
c:\program files\Kingsoft\PowerWord PE\data\img\save_05.gif
c:\program files\Kingsoft\PowerWord PE\data\img\save_09.gif
c:\program files\Kingsoft\PowerWord PE\data\img\save_18.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\button_alt.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\end_main.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\end_more.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\Grab.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\han_feature.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\mini_feature.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\mini_skin.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\pro_inmages.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\pro_skin.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\qinging_skin.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\ttl_config.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\ttl_feature.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\ttl_feature_5.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\ttl_loaddict.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\ttl_mini.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\ttl_setdict.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\ttl_skin.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\xzmc_inmages.gif
c:\program files\Kingsoft\PowerWord PE\data\img\SettingGuide\随机.gif
c:\program files\Kingsoft\PowerWord PE\data\img\tag.gif
c:\program files\Kingsoft\PowerWord PE\data\jd_offline_no_found.htm
c:\program files\Kingsoft\PowerWord PE\data\license.txt
c:\program files\Kingsoft\PowerWord PE\data\loading.htm
c:\program files\Kingsoft\PowerWord PE\data\notes.js
c:\program files\Kingsoft\PowerWord PE\data\result_preview.html
c:\program files\Kingsoft\PowerWord PE\data\support.htm
c:\program files\Kingsoft\PowerWord PE\data\wiki_03_special.js
c:\program files\Kingsoft\PowerWord PE\data\xml_replace.ini
c:\program files\Kingsoft\PowerWord PE\DownloadData.dll
c:\program files\Kingsoft\PowerWord PE\filecache.dll
c:\program files\Kingsoft\PowerWord PE\google_service.dll
c:\program files\Kingsoft\PowerWord PE\HotFix.exe
c:\program files\Kingsoft\PowerWord PE\HotKeyControl.dll
c:\program files\Kingsoft\PowerWord PE\index.dll
c:\program files\Kingsoft\PowerWord PE\ksdcallcenter.dll
c:\program files\Kingsoft\PowerWord PE\KSDConfig.dll
c:\program files\Kingsoft\PowerWord PE\KSDIPC.dll
c:\program files\Kingsoft\PowerWord PE\KSDNettools.dll
c:\program files\Kingsoft\PowerWord PE\KSDRepair.exe
c:\program files\Kingsoft\PowerWord PE\KSDStatistic.dll
c:\program files\Kingsoft\PowerWord PE\ksdsvc.exe
c:\program files\Kingsoft\PowerWord PE\localdictmgr.dll
c:\program files\Kingsoft\PowerWord PE\mfc80u.dll
c:\program files\Kingsoft\PowerWord PE\microsoft.vc80.crt.manifest
c:\program files\Kingsoft\PowerWord PE\microsoft.vc80.mfc.manifest
c:\program files\Kingsoft\PowerWord PE\microsoft.vc80.mfcloc.manifest
c:\program files\Kingsoft\PowerWord PE\msvcp80.dll
c:\program files\Kingsoft\PowerWord PE\msvcr80.dll
c:\program files\Kingsoft\PowerWord PE\NetUtil.dll
c:\program files\Kingsoft\PowerWord PE\newword.dll
c:\program files\Kingsoft\PowerWord PE\Newword.exe
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\1.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\2.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\3.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\4.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\5.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\add.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\bottom.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\browse.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\browse_top.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\card.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\cardright.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\cardsetup.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\changePad.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\checkall.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\combobox_3state.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\config.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\delete.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\delete_disable.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\drop.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\edit.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\edit_disable.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\exam.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\help.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\manage.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\next.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\pre.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\print.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\printsetup.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\radio_inner.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\radio_outter.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\recite.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\reset.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\saveasnew.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\saveasnew_disable.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\scrollword.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\sep.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\shadow.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\shadow2.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\skin.xml
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\starttest.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\test_next.BMP
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\test_refer.BMP
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\test_repeat.BMP
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\test_report_ok.BMP
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\test_skin.xml
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\test_sound.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\test_spell_ok.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\testback.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\skin\cp936\top.bmp
c:\program files\Kingsoft\PowerWord PE\Newword\tpl\audio.tpl
c:\program files\Kingsoft\PowerWord PE\NewWordGuide.exe
c:\program files\Kingsoft\PowerWord PE\plugin\baikequery.dll
c:\program files\Kingsoft\PowerWord PE\plugin\baikequery\baikequerydictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\google\google_service.dll
c:\program files\Kingsoft\PowerWord PE\plugin\google\googlequerydictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\google\mfc80u.dll
c:\program files\Kingsoft\PowerWord PE\plugin\google\microsoft.vc80.crt.manifest
c:\program files\Kingsoft\PowerWord PE\plugin\google\microsoft.vc80.mfc.manifest
c:\program files\Kingsoft\PowerWord PE\plugin\google\microsoft.vc80.mfcloc.manifest
c:\program files\Kingsoft\PowerWord PE\plugin\google\msvcp80.dll
c:\program files\Kingsoft\PowerWord PE\plugin\google\msvcr80.dll
c:\program files\Kingsoft\PowerWord PE\plugin\google\MulTranslation.dll
c:\program files\Kingsoft\PowerWord PE\plugin\googlequery.dll
c:\program files\Kingsoft\PowerWord PE\plugin\huihuaquery.dll
c:\program files\Kingsoft\PowerWord PE\plugin\huihuaquery\huihuaquerydictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\image\default.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\eeaced.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\googlepic.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\hanyingt.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\pwdecmc.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\pwdecyf.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\pwdsyhr.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\pwdxrh.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\image\wordnet.bmp
c:\program files\Kingsoft\PowerWord PE\plugin\localquery.dll
c:\program files\Kingsoft\PowerWord PE\plugin\localquery\localquerydictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\mfc80u.dll
c:\program files\Kingsoft\PowerWord PE\plugin\microsoft.vc80.crt.manifest
c:\program files\Kingsoft\PowerWord PE\plugin\microsoft.vc80.mfc.manifest
c:\program files\Kingsoft\PowerWord PE\plugin\microsoft.vc80.mfcloc.manifest
c:\program files\Kingsoft\PowerWord PE\plugin\msvcp80.dll
c:\program files\Kingsoft\PowerWord PE\plugin\msvcr80.dll
c:\program files\Kingsoft\PowerWord PE\plugin\NetDicQuery.dll
c:\program files\Kingsoft\PowerWord PE\plugin\netdicquery\netdicquerydictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\netindex.dll
c:\program files\Kingsoft\PowerWord PE\plugin\netindex\netindexdictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\netquery.dll
c:\program files\Kingsoft\PowerWord PE\plugin\netquery\netquerydictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\situationsentence.dll
c:\program files\Kingsoft\PowerWord PE\plugin\situationsentence\situationsentencedictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\spellsuggest.dll
c:\program files\Kingsoft\PowerWord PE\plugin\spellsuggest\spellsuggestdictcfg.ini
c:\program files\Kingsoft\PowerWord PE\plugin\WikiQuery.dll
c:\program files\Kingsoft\PowerWord PE\plugin\WikiQuery\configure.ini
c:\program files\Kingsoft\PowerWord PE\PowerwordGrab.api
c:\program files\Kingsoft\PowerWord PE\queryprocesscenter.dll
c:\program files\Kingsoft\PowerWord PE\SelectForIE.dll
c:\program files\Kingsoft\PowerWord PE\SelectForOffice.dll
c:\program files\Kingsoft\PowerWord PE\SettingGuide.exe
c:\program files\Kingsoft\PowerWord PE\SettingUI.dll
c:\program files\Kingsoft\PowerWord PE\Setup_update.EXE
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\3state_tab.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\bottomleft.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\bottommiddle.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\bottomright.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\button_close_3state.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\close_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\combobox_dropstate.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\conversation.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\dic_guid.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\dict_ico_setting.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\droplist_skin.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\grab_sel_switch.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\GuidePreview.gif
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_button_fankui.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_button_language_down.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_button_search_down.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_button_switch.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_button_switch02.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_ico_green.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_ico_red.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_skin.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\index_sound.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\logo.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\lookup_word.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\main_view.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_bg.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_dict_ico.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_down.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_down_page-down.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_down_page-up.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_index_bk.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_index_button_jiantou.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_skin.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\mini_translate_b_t.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\minimize_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\next_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\previous_button.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\resouce.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\restore_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\restore2.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\Search_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\sentence.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\setting_button_download.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\setting_button_manage.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\sys_menu.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\tableback.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\Thumbs.db
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\topleft.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\topmiddle.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\topright.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\translate_bk.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\translate_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\translate_dropdown_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\translate_guide_ico_sentence.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\translate_sentence_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\translate_sentence_guide_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\tree_disable_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\tree_enable_bt.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\treeNodeImg.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\vmiddleleft.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\vmiddleright.png
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\xdict_chinese_page_skin.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\xdict_dic_guide_skin.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\xdict_index_dlg_skin.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\xdict_skin.xml
c:\program files\Kingsoft\PowerWord PE\skin\经典蓝\xdict_transpage_skin.xml
c:\program files\Kingsoft\PowerWord PE\sqlite3.dll
c:\program files\Kingsoft\PowerWord PE\styles\KSDBlack.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDBlack_big.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDBule.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDBule_big.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDDefault.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDDefault_big.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDGreen.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDGreen_big.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDRed.css
c:\program files\Kingsoft\PowerWord PE\styles\KSDRed_big.css
c:\program files\Kingsoft\PowerWord PE\TTsCheck.exe
c:\program files\Kingsoft\PowerWord PE\uninst.exe
c:\program files\Kingsoft\PowerWord PE\XDict.exe
c:\program files\Kingsoft\PowerWord PE\XGrab.dll
c:\program files\Kingsoft\PowerWord PE\XGrabDataService.dll
c:\program files\Kingsoft\PowerWord PE\zlib.dll
c:\windows\system32\drivers\KAVSafe.sys

.
((((((((((((((((((((((((((((((((((((((( drivers/services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_KAVSAFE
——-\Legacy_KSDSVC
——-\Service_KAVSafe
——-\Service_KSDSVC


((((((((((((((((((((((((( New files from 2010-04-27 to 2010-05-27 )))))))))))))))))))))))))))))))
.

2010-05-26 17:14 . 2010-05-26 17:14 ——– d—–w- c:\documents and settings\Tom Clinic\Local Settings\Application Data\VS Revo Group
2010-05-26 17:14 . 2009-12-30 22:20 27064 —-a-w- c:\windows\system32\drivers\revoflt.sys
2010-05-26 17:14 . 2010-05-26 17:14 ——– d—–w- c:\program files\VS Revo Group
2010-05-26 08:14 . 2010-05-26 08:19 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\WeatherWatcherLive
2010-05-26 08:13 . 2010-05-26 08:14 ——– d—–w- c:\program files\Weather Watcher Live
2010-05-26 08:13 . 2004-05-27 11:32 102400 —-a-w- c:\windows\system32\unzip32.dll
2010-05-26 07:32 . 2010-05-26 07:32 ——– d—–w- c:\program files\X桌面软件
2010-05-26 02:03 . 2010-05-26 02:03 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Office Genuine Advantage
2010-05-26 02:03 . 2010-05-26 02:03 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Office Genuine Advantage
2010-05-24 07:59 . 2010-05-24 07:59 ——– d—–w- c:\documents and settings\Tom Clinic\Local Settings\Application Data\Identities
2010-05-24 00:44 . 2009-08-07 05:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-05-24 00:44 . 2009-08-07 05:23 215920 —-a-w- c:\windows\system32\muweb.dll
2010-05-23 11:14 . 2010-04-27 15:16 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-05-23 10:56 . 2001-08-18 08:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2010-05-23 10:56 . 2008-04-14 15:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2010-05-23 10:56 . 2008-04-14 10:15 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2010-05-23 10:56 . 2008-04-14 10:15 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2010-05-23 09:30 . 2010-02-04 15:53 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-05-23 09:30 . 2010-05-23 09:30 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-23 09:23 . 2010-05-23 09:23 ——– d—–w- c:\documents and settings\Tom Clinic\Local Settings\Application Data\Sunbelt Software
2010-05-23 09:22 . 2010-05-23 09:22 ——– dc-h–w- c:\documents and settings\All Users.WINDOWS\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-23 09:22 . 2010-05-23 09:30 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2010-05-23 09:20 . 2010-05-23 09:20 ——– d—–w- c:\program files\Foxit Software
2010-05-23 06:17 . 2010-05-24 17:12 ——– d—–w- c:\documents and settings\Tom Clinic\Tracing
2010-05-23 06:15 . 2010-05-23 06:15 ——– d—–w- c:\program files\Microsoft
2010-05-23 02:40 . 2010-05-23 02:40 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\WEBREG
2010-05-23 02:28 . 2010-05-23 02:28 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\HP
2010-05-23 02:20 . 2010-05-23 02:22 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\HP
2010-05-23 02:20 . 2010-05-23 02:20 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\HP Product Assistant
2010-05-23 02:19 . 2010-05-23 02:19 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Hewlett-Packard
2010-05-23 02:18 . 2007-11-08 15:06 271704 —-a-r- c:\windows\system32\hpzids01.dll
2010-05-23 02:18 . 2007-10-21 04:25 117760 —-a-w- c:\windows\system32\hpzll5mu.dll
2010-05-23 02:18 . 2007-10-21 04:21 278016 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5mu.dll
2010-05-23 02:15 . 2008-04-14 10:17 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2010-05-23 02:15 . 2008-04-14 10:17 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2010-05-23 02:15 . 2008-04-14 10:15 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-05-23 02:15 . 2008-04-14 10:15 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2010-05-23 02:10 . 2010-05-23 02:41 168980 —-a-w- c:\windows\hphins27.dat
2010-05-23 02:10 . 2007-12-13 00:04 787 ——w- c:\windows\hphmdl27.dat
2010-05-22 22:51 . 2010-05-22 22:51 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Tencent
2010-05-22 20:36 . 2010-05-22 20:36 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Tencent
2010-05-22 19:19 . 2007-04-09 05:23 28552 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\mdippr.dll
2010-05-22 19:19 . 2007-04-09 05:23 28040 —-a-w- c:\windows\system32\mdimon.dll
2010-05-22 19:18 . 2010-05-22 19:18 ——– d—–w- c:\program files\Microsoft ActiveSync
2010-05-22 18:21 . 2010-05-22 18:21 ——– d-sh–w- c:\documents and settings\LocalService.NT AUTHORITY.000\IETldCache
2010-05-22 13:37 . 2010-05-22 19:04 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\WinZip
2010-05-22 13:32 . 2010-05-22 13:32 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\DivX
2010-05-22 13:31 . 2010-05-26 02:02 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Storm
2010-05-22 13:27 . 2010-05-27 09:55 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2010-05-22 13:26 . 2010-05-22 13:27 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\SolidDocuments
2010-05-22 13:25 . 2010-05-22 13:25 56 —ha-w- c:\windows\system32\ezsidmv.dat
2010-05-22 13:25 . 2010-05-27 08:40 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\skypePM
2010-05-22 13:24 . 2010-05-22 13:25 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Skype
2010-05-22 13:19 . 2010-05-27 08:41 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Skype
2010-05-22 13:14 . 2010-05-22 13:15 ——– d—–w- c:\program files\Raxco
2010-05-22 13:13 . 2010-05-22 13:13 20 —-a-w- c:\windows\system32\pub_store.dat
2010-05-22 13:07 . 2010-05-22 13:07 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Meitu
2010-05-22 12:33 . 2010-05-22 12:33 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\SogouPY.users
2010-05-22 12:33 . 2010-05-27 19:07 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\SogouPY
2010-05-22 11:56 . 2010-05-22 11:56 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Malwarebytes
2010-05-22 11:56 . 2010-04-30 01:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-22 11:56 . 2010-05-22 11:56 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2010-05-22 11:56 . 2010-04-30 01:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-05-22 11:52 . 2010-05-22 11:52 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\SpeedBit
2010-05-22 11:33 . 2010-05-22 11:33 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Registry Mechanic
2010-05-22 11:33 . 2010-05-22 11:33 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Raxco
2010-05-22 11:24 . 2010-05-22 11:24 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Trillian
2010-05-22 11:16 . 2010-05-23 23:23 ——– d—a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2010-05-22 11:13 . 2010-05-22 11:13 ——– d—–w- c:\documents and settings\Tom Clinic\Local Settings\Application Data\Opera
2010-05-22 11:10 . 2010-05-22 11:10 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Avant Profiles
2010-05-22 11:08 . 2010-05-22 11:08 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Fetion
2010-05-22 11:07 . 2010-05-22 11:09 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Fetion
2010-05-22 11:07 . 2010-05-23 06:16 24320 —-a-w- c:\documents and settings\Tom Clinic\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-22 10:19 . 2010-05-22 11:20 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\RoboForm
2010-05-22 10:09 . 2010-05-22 10:09 0 —-a-w- c:\windows\nsreg.dat
2010-05-22 10:08 . 2010-05-22 10:08 ——– d—–w- c:\documents and settings\Tom Clinic\Local Settings\Application Data\Mozilla
2010-05-22 09:54 . 2010-05-23 08:40 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\TeamViewer
2010-05-22 09:35 . 2010-05-22 09:35 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\WinPatrol
2010-05-22 09:34 . 2010-05-22 09:34 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\Softarium.com
2010-05-22 09:33 . 2010-05-22 09:33 ——– d—–w- c:\documents and settings\Tom Clinic\Application Data\kingsoft
2010-05-22 09:26 . 2010-05-22 09:26 ——– d-sh–w- c:\documents and settings\Tom Clinic\IECompatCache
2010-05-22 09:26 . 2010-05-22 09:26 ——– d-sh–w- c:\documents and settings\Tom Clinic\PrivacIE
2010-05-22 09:22 . 2010-05-22 09:22 ——– d-sh–w- c:\documents and settings\Tom Clinic\IETldCache
2010-05-22 09:16 . 2010-05-22 09:27 ——– d—–w- c:\windows\system32\KB905474
2010-05-22 09:15 . 2010-02-25 21:54 11070976 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2010-05-22 09:15 . 2010-02-25 06:24 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-05-22 09:15 . 2010-02-25 06:24 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-05-22 09:15 . 2010-02-25 06:24 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-05-22 09:15 . 2010-02-25 06:24 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-05-22 09:15 . 2010-02-25 06:24 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2010-05-22 09:00 . 2008-06-13 11:05 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2010-05-22 09:00 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2010-05-22 08:59 . 2010-02-24 13:11 455680 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2010-05-22 08:55 . 2010-02-17 19:10 2189952 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe
2010-05-22 08:55 . 2010-02-16 14:08 2146304 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-05-22 08:55 . 2010-02-16 13:25 2024448 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-05-22 08:53 . 2010-05-22 08:53 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-05-22 08:44 . 2010-05-22 14:03 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-05-22 08:44 . 2008-10-10 00:25 69008 —-a-w- c:\windows\system32\zlcomm.dll
2010-05-22 08:44 . 2008-10-10 00:25 106384 —-a-w- c:\windows\system32\zlcommdb.dll
2010-05-22 08:44 . 2008-10-10 00:25 1221008 —-a-w- c:\windows\system32\zpeng25.dll
2010-05-22 08:42 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2010-05-22 08:38 . 2009-01-08 04:21 26144 —-a-w- c:\windows\system32\spupdsvc.exe
2010-05-22 08:32 . 2010-05-22 08:53 52872 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-05-22 08:32 . 2010-05-22 08:53 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-22 08:32 . 2010-05-22 08:53 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-05-22 08:32 . 2010-05-22 08:53 29512 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-22 08:32 . 2010-05-22 09:26 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar
2010-05-22 08:31 . 2010-05-22 08:31 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\avg9
2010-05-22 08:26 . 2008-04-14 10:15 26368 -c–a-w- c:\windows\system32\dllcache\usbstor.sys
2010-05-22 08:23 . 2005-09-20 17:36 81920 —-a-w- c:\windows\system32\igfxres.dll
2010-05-22 08:20 . 2005-02-23 18:04 192512 ——w- c:\windows\system32\AegisI5.exe
2010-05-22 08:20 . 2005-05-31 18:46 87936 —-a-r- c:\windows\system32\drivers\gtipci21.sys
2010-05-22 08:20 . 2004-03-23 19:45 28672 —-a-r- c:\windows\cttib1.dll
2010-05-22 08:15 . 2005-12-19 19:08 667648 —-a-w- c:\windows\system32\BCMLogon.dll
2010-05-22 08:13 . 2005-07-08 23:19 666 —-a-w- c:\windows\speed.reg
2010-05-22 08:08 . 2010-05-22 08:08 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Novatel Wireless
2010-05-22 08:05 . 2008-04-14 10:15 6272 -c–a-w- c:\windows\system32\dllcache\splitter.sys
2010-05-22 08:05 . 2008-04-14 10:15 6272 —-a-w- c:\windows\system32\drivers\splitter.sys
2010-05-22 08:05 . 2008-04-14 10:47 83072 -c–a-w- c:\windows\system32\dllcache\wdmaud.sys
2010-05-22 08:05 . 2008-04-14 10:47 83072 —-a-w- c:\windows\system32\drivers\wdmaud.sys
2010-05-22 08:05 . 2008-04-14 10:15 52864 -c–a-w- c:\windows\system32\dllcache\dmusic.sys
2010-05-22 08:05 . 2008-04-14 10:15 52864 —-a-w- c:\windows\system32\drivers\DMusic.sys
2010-05-22 08:05 . 2008-04-14 10:15 56576 -c–a-w- c:\windows\system32\dllcache\swmidi.sys
2010-05-22 08:05 . 2008-04-14 10:15 56576 —-a-w- c:\windows\system32\drivers\swmidi.sys

.
(((((((((((((((((((((((((((((((((((((((( Files edited within last three months ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-27 09:54 . 2010-04-24 20:13 ——– d—–w- c:\program files\CCleaner
2010-05-27 07:48 . 2010-04-24 22:49 ——– d—–w- c:\program files\SogouInput
2010-05-26 21:20 . 2010-05-22 07:53 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-05-26 16:49 . 2010-04-26 20:46 ——– d—–w- c:\program files\easyMule
2010-05-23 23:22 . 2010-04-26 13:28 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-23 11:07 . 2010-04-27 07:04 ——– d—–w- c:\program files\nEO iMAGING
2010-05-23 08:41 . 2010-05-23 08:41 537088 —-a-w- c:\documents and settings\Tom Clinic\Application Data\Meitu\KanKan\PlugIns\facedetect\facedetect.dll
2010-05-22 21:59 . 2010-04-24 20:41 ——– d—–w- c:\program files\Trillian
2010-05-22 21:59 . 2010-04-24 21:47 ——– d—–w- c:\program files\ePrompter
2010-05-22 19:19 . 2010-05-22 19:19 7358 —-a-r- c:\documents and settings\Tom Clinic\Application Data\Microsoft\Installer\{C2182670-EEF5-4B1C-822F-66972FFDEAC7}\_69525f90.exe
2010-05-22 18:17 . 2010-05-22 18:17 95744 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\SpeedBit\DAP\SDCondition.dll
2010-05-22 18:17 . 2010-04-25 19:35 ——– d—–w- c:\program files\Startup Faster 2004
2010-05-22 13:29 . 2010-04-24 20:14 ——– d—–w- c:\program files\SpywareBlaster
2010-05-22 11:52 . 2010-04-24 20:09 ——– d—–w- c:\program files\DAP
2010-05-22 08:24 . 2010-04-24 18:14 ——– d—–w- c:\program files\Dell
2010-05-22 08:08 . 2010-04-24 18:14 ——– d—–w- c:\program files\Common Files\Zeepe Framework 7
2010-05-22 07:51 . 2010-05-22 07:51 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-05-08 03:23 . 2010-04-24 20:37 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-05-05 06:15 . 2010-04-26 13:39 ——– d—–w- c:\program files\SogouExtension
2010-04-27 07:09 . 2010-04-27 07:08 ——– d—–w- c:\program files\Conew
2010-04-27 07:07 . 2010-04-27 07:07 ——– d—–w- c:\program files\Meitu
2010-04-26 19:10 . 2010-04-26 19:06 ——– d—–w- c:\program files\HP
2010-04-26 19:09 . 2010-04-26 19:09 ——– d—–w- c:\program files\Common Files\HP
2010-04-25 06:45 . 2010-04-25 06:45 ——– d—–w- c:\program files\Java
2010-04-25 06:05 . 2010-04-25 06:00 ——– d—–w- c:\program files\StartupFaster
2010-04-25 06:03 . 2010-04-25 06:03 ——– d—–w- c:\program files\Common Files\Java
2010-04-25 05:48 . 2010-04-25 05:47 ——– d—–w- c:\program files\Wisdom-soft ScreenHunter 5 Free
2010-04-25 01:28 . 2010-04-25 01:28 ——– d—–w- c:\program files\YourWare Solutions
2010-04-25 01:12 . 2010-04-25 01:12 ——– d—–w- c:\program files\Microsoft.NET
2010-04-25 00:30 . 2010-04-25 00:30 ——– d—–w- c:\program files\Siber Systems
2010-04-24 23:05 . 2010-04-24 23:05 ——– d—–w- c:\program files\CursorXP
2010-04-24 21:38 . 2010-04-24 21:37 ——– d—–w- c:\program files\Windows Live
2010-04-24 21:38 . 2010-04-24 21:38 ——– d—–w- c:\program files\Windows Live SkyDrive
2010-04-24 21:33 . 2010-04-24 18:09 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-24 21:25 . 2010-04-24 21:25 ——– d—–w- c:\program files\Common Files\Windows Live
2010-04-24 21:22 . 2010-04-24 21:22 ——– d—–w- c:\program files\China Mobile
2010-04-24 21:10 . 2010-04-24 21:10 ——– d—–w- c:\program files\Avant Browser
2010-04-24 20:56 . 2010-04-24 20:55 ——– d—–r- c:\program files\Skype
2010-04-24 20:55 . 2010-04-24 20:55 ——– d—–w- c:\program files\Common Files\Skype
2010-04-24 20:51 . 2010-04-24 20:51 ——– d—–w- c:\program files\TeamViewer
2010-04-24 20:23 . 2010-04-24 20:23 ——– d—–w- c:\program files\Lavasoft
2010-04-24 20:20 . 2010-04-24 20:17 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-04-24 19:57 . 2010-04-24 19:57 ——– d—–w- c:\program files\Idailydiary
2010-04-24 19:49 . 2010-04-24 19:49 ——– d—–w- c:\program files\reliz
2010-04-24 19:44 . 2010-04-24 19:44 ——– d—–w- c:\program files\Common Files\PC Tools
2010-04-24 19:35 . 2010-04-24 19:35 ——– d—–w- c:\program files\Ashampoo
2010-04-24 19:04 . 2010-04-24 19:04 ——– d—–w- c:\program files\Windows Media Connect 2
2010-04-24 18:26 . 2010-04-24 18:26 ——– d—–w- c:\program files\Broadcom
2010-04-24 18:26 . 2010-04-24 18:09 ——– d—–w- c:\program files\Common Files\InstallShield
2010-04-24 18:15 . 2010-04-24 18:15 ——– d—–w- c:\program files\Intel
2010-04-24 18:09 . 2010-04-24 18:09 ——– d—–w- c:\program files\SigmaTel
2010-04-24 18:05 . 2010-04-24 18:05 ——– d—–w- c:\program files\AVG
2010-04-24 17:42 . 2010-04-24 17:42 ——– d—–w- c:\program files\microsoft frontpage
2010-04-24 17:41 . 2010-05-22 09:35 0 —-a-w- c:\documents and settings\Tom Clinic\Application Data\WinPatrol\Config.sys
2010-04-24 17:41 . 2010-05-22 09:35 0 —-a-w- c:\documents and settings\Tom Clinic\Application Data\WinPatrol\Autoexec.bat
2010-04-17 08:12 . 2010-04-17 08:12 48464 —-a-w- c:\windows\system32\sirenacm.dll
2010-03-10 06:15 . 2008-04-14 12:00 420352 —-a-w- c:\windows\system32\vbscript.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-05-26_17.53.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-05-22 07:58 . 2010-05-26 19:48 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2010-05-22 07:58 . 2010-05-25 05:42 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2010-05-22 07:58 . 2010-05-26 19:48 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-05-22 07:58 . 2010-05-25 05:42 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2010-05-23 09:44 . 2010-05-25 05:42 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2010-05-23 09:44 . 2010-05-26 19:48 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2010-05-26 19:48 . 2010-05-26 19:48 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2010-05-22 07:58 . 2010-05-25 05:42 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-05-22 07:53 . 2010-05-26 21:20 2850 c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
.
((((((((((((((((((((((((((((((((((((( important log in sites ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Attention* some are not shown:
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0A0DDBD3-6641-40B9-873F-BBDD26D6C14E}]
2010-05-20 09:41 147928 —-a-w- c:\program files\easyMule\modules\IE2EM.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 20:25 2117704 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartupFaster"="c:\program files\Startup Faster 2004\StrpFstCfg.exe" [2005-02-21 2198016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\StartupFaster
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
StartupFaster.ini [2010-5-24 353]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-05-22 08:53 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Meitu\\KanKan\\KanKan\\KanKan.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\SogouInput\\5.0.0.3912\\PinyinUp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [5/21/2010 10:32 PM 52872]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [5/22/2010 11:30 PM 64288]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/21/2010 10:32 PM 216200]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/21/2010 10:32 PM 242896]
R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [5/21/2010 10:53 PM 916760]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [5/21/2010 10:53 PM 308064]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 5:52 AM 1314704]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [4/26/2010 3:28 AM 304464]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [4/24/2010 9:44 AM 583640]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [5/21/2010 10:20 PM 87936]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [5/22/2010 1:56 AM 20952]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [5/26/2010 7:14 AM 27064]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents in ‘Task schedule’ foler

2010-05-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 09:30]

2010-05-27 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-04 01:07]

2010-05-27 c:\windows\Tasks\SogouImeMgr.job
- c:\progra~1\SOGOUI~1\500~1.391\SGTool.exe [2010-04-27 09:33]
.
.
——- other scan ——-
.
uStart Page = hxxp://www.baidu.com/index.php?tn=avantcn_dg
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: Download by easyMule - c:\program files\easyMule\IE2EM.htm
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Logoff - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComLogoff.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: 导出到 Microsoft Office Excel(&X) - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-27 09:39
Windows 5.1.2600 Service Pack 3 NTFS

process of scanning hidden files 。。。

scan hidden startup groups 。。。

scan hidden documents 。。。

scan complete
hidden files: 0

**************************************************************************
.
——————— links ———————

- - - - - - - > 'explorer.exe'(1792)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— other processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\conime.exe
c:\program files\Raxco\PerfectDisk10\PDAgent.exe
c:\program files\AVG\AVG9\avgam.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Startup Faster 2004\sfAgent.exe
c:\program files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
c:\progra~1\AVG\AVG9\avgtray.exe
c:\program files\reliz\akeys.exe
c:\windows\system32\igfxpers.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Raxco\PerfectDisk10\PDEngine.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Raxco\PerfectDisk10\PDAgentS1.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\MsiExec.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
complete time: 2010-05-27 09:49:23 - computer reboot
ComboFix-quarantined-files.txt 2010-05-27 19:49
ComboFix2.txt 2010-05-26 17:57

Pre-Run: 223,677,452,288 bytes free
Post-Run: 223,533,522,944 bytes free

- - End Of File - - 5015BC41D2283AF206290AB07CBF9894
Here is a Malwarebyte's scan from yesterday or before Combofix, please let me know if I need to do anything with this. Thanks!

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4146

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

5/26/2010 9:45:11 PM
mbam-log-2010-05-26 (21-45-11).txt

Scan type: Full scan (C:\|)
Objects scanned: 226624
Time elapsed: 5 hour(s), 34 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ksdsvc (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\System Volume Information\_restore{50B1B32B-57FA-49CC-8FE3-A5D4395451C7}\RP23\A0003671.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{50B1B32B-57FA-49CC-8FE3-A5D4395451C7}\RP30\A0006275.exe (Trojan.StartPage) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{50B1B32B-57FA-49CC-8FE3-A5D4395451C7}\RP30\A0006276.exe (Trojan.StartPage) -> Quarantined and deleted successfully.
Hi,

Do you have the installation disks for those programs?

There must have been something in the StormII program that may have indicated malware, but if you trust the source (ie purchased disk) then go ahead and reinstall that program, if you downloaded it from a torrent site, it was likely embedded with infected files.

As for the Kingsoft, do you have the installation disk for the portion of the program that you do want?

If so - reinstall it with a custom installation and choose only the portions of the program that you want.


let me know,

if it is too much trouble to re-install, let me know and I can take those files out of quarantine.



Use your own defragmenter if you are satisfied with the job it does.

NEXT


Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.


NEXT



  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.




NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply





    http://www.out-of-warranty.com/insert-pssw…ge-hp-software/

    this may answer the PSSWCORE message
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4150 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 5/27/2010 10:11:50 PM mbam-log-2010-05-27 (22-11-50).txt Scan type: Quick scan Objects scanned: 159579 Time elapsed: 9 minute(s), 57 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\Tom clinic\Application Data\SogouExplorer (Adware.Sogou) -> Quarantined and deleted successfully. Files Infected: C:\Documents and Settings\Tom clinic\Application Data\SogouExplorer\se_setup.ini (Adware.Sogou) -> Quarantined and deleted successfully.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI