This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

lots of website are redirecting me to qbyrd or other search engine

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i don't know much about computer but this is my only computer pls help me to save it. this few days i were playing online games and watching movies at internet. and i wanna check something at google.com and i realise google.com was redirecting me to a search page called qbyrd.com oh and this is the stuff i get from the OTL thing.

OTL logfile created on: 12/17/2010 5:01:19 AM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Terence\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,022.00 Mb Total Physical Memory | 489.00 Mb Available Physical Memory | 48.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 17.47 Gb Total Space | 2.24 Gb Free Space | 12.82% Space Free | Partition Type: NTFS
Drive F: | 19.77 Gb Total Space | 4.07 Gb Free Space | 20.59% Space Free | Partition Type: NTFS

Computer Name: HOME-47627E8BE5 | User Name: Terence | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Terence\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
PRC - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
PRC - C:\Program Files\Tudou\滄厒Tudou\TudouVa.exe (土豆网)
PRC - C:\Program Files\TortoiseSVN\bin\TSVNCache.exe (http://tortoisesvn.net)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Program Files\AskBarDis\bar\bin\AskService.exe ()
PRC - C:\Program Files\VIAudioi\SBADeck\ADeck.exe (VIA Technologies, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\fpplock.exe (ZQS Software Team)
PRC - C:\WINDOWS\MMKeybd.exe (Netropa Corp.)
PRC - C:\WINDOWS\Nhksrv.exe ()
PRC - C:\Program Files\Netropa\OSD.exe (Netropa Corp.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Terence\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\windows\System32\hidserv.dll File not found
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe File not found
SRV - (gupdate1c9e2c0a93c19ba) Google Update Service (gupdate1c9e2c0a93c19ba) – C:\Program Files\Google\Update\GoogleUpdate.exe File not found
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe File not found
SRV - (Hamachi2Svc) – C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (HssWd) – C:\Program Files\Hotspot Shield\bin\hsswd.exe ()
SRV - (HssSrv) – C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe (AnchorFree Inc.)
SRV - (npggsvc) – C:\windows\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (wampmysqld) – c:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe ()
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (wampapache) – c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe (Apache Software Foundation)
SRV - (ASKUpgrade) – C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe ()
SRV - (ASKService) – C:\Program Files\AskBarDis\bar\bin\AskService.exe ()
SRV - (Nhksrv) – C:\WINDOWS\Nhksrv.exe ()


========== Driver Services (SafeList) ==========

DRV - (XDva285) – C:\windows\System32\XDva285.sys File not found
DRV - (XDva219) – C:\windows\System32\XDva219.sys File not found
DRV - (XDva215) – C:\windows\System32\XDva215.sys File not found
DRV - (XDva208) – C:\windows\System32\XDva208.sys File not found
DRV - (npkcrypt) – F:\Program Files\WIZET\MapleStory\npkcrypt.sys File not found
DRV - (MSJDrvr) – C:\Documents and Settings\Terence\Desktop\NMbot 2nd Edition\NMbot 2nd Edition\MSJDrvr.sys File not found
DRV - (GarenaPEngine) – C:\DOCUME~1\Terence\LOCALS~1\Temp\GCLAD.tmp File not found
DRV - (EagleNT) – C:\windows\System32\drivers\EagleNT.sys File not found
DRV - (taphss) – C:\WINDOWS\system32\drivers\taphss.sys (AnchorFree Inc)
DRV - (sptd) – C:\windows\System32\Drivers\sptd.sys ()
DRV - (vaxscsi) – C:\windows\System32\Drivers\vaxscsi.sys (Alcohol Soft Co., Ltd.)
DRV - (Mkd2kfNt) – C:\WINDOWS\system32\drivers\Mkd2kfNT.sys (AhnLab, Inc.)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (Mkd2Nadr) – C:\WINDOWS\system32\drivers\Mkd2Nadr.sys (AhnLab, Inc.)
DRV - (MQAC) – C:\WINDOWS\system32\drivers\mqac.sys (Microsoft Corporation)
DRV - (hwusbfake) – C:\WINDOWS\system32\drivers\ewusbfake.sys (Huawei Technologies Co., Ltd.)
DRV - (hwdatacard) – C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (RMCAST) – C:\WINDOWS\system32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (VIAudio) Vinyl AC'97 Audio Controller (WDM) – C:\WINDOWS\system32\drivers\vinyl97.sys (VIA Technologies, Inc.)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)
DRV - (Msikbd2k) – C:\WINDOWS\system32\drivers\Msikbd2k.sys (Netropa Corporation)
DRV - (FsVga) – C:\WINDOWS\system32\drivers\fsvga.sys (Microsoft Corporation)
DRV - (msloop) – C:\WINDOWS\system32\drivers\loop.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\..\URLSearchHook: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\tbBit1.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\BigSeekPro Toolbar\tbhelper.dll ()
IE - HKCU\..\URLSearchHook: {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Dealio Toolbar\SearchSettings.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = http://127.0.0.1:9415/tudouva.pac

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "Veoh Web Player Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=836624"
FF - prefs.js..browser.search.selectedEngine: "Veoh Web Player Customized Web Search"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..capability.principal.codebase.p124.subjectName: "");user_pref("network.proxy.type", 2
FF - prefs.js..network.proxy.autoconfig_url: "http://127.0.0.1:9415/tudouva.pac"

FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/16 16:41:47 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/29 12:14:03 | 000,000,000 | —D | M]

[2009/12/20 21:11:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\Mozilla\Extensions
[2010/12/04 16:14:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\Mozilla\Firefox\Profiles\ypa8xrb1.default\extensions
[2010/08/19 15:23:01 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Terence\Application Data\Mozilla\Firefox\Profiles\ypa8xrb1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/19 15:23:00 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Terence\Application Data\Mozilla\Firefox\Profiles\ypa8xrb1.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/06/29 17:22:34 | 000,000,933 | —- | M] () – C:\Documents and Settings\Terence\Application Data\Mozilla\Firefox\Profiles\ypa8xrb1.default\searchplugins\conduit.xml
[2010/04/04 09:17:40 | 000,002,055 | —- | M] () – C:\Documents and Settings\Terence\Application Data\Mozilla\Firefox\Profiles\ypa8xrb1.default\searchplugins\daemon-search.xml
[2010/12/13 12:28:46 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2009/12/05 01:24:10 | 000,000,000 | —D | M] (Dealio Toolbar Plugin) – C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
[2010/05/22 10:21:38 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/16 15:30:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/25 13:40:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/13 12:28:47 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2009/12/05 01:24:10 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010/06/12 02:05:14 | 000,253,952 | —- | M] () – C:\Program Files\Mozilla Firefox\components\CheckTudouVa.dll
[2010/09/15 04:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/04/02 15:48:03 | 000,001,207 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\search.xml

O1 HOSTS File: ([2010/04/02 15:47:54 | 000,002,752 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 74.125.45.100 4-open-davinci.com
O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getavplusnow.com
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 94.75.207.107 www.google.com
O1 - Hosts: 94.75.207.107 google.com
O1 - Hosts: 94.75.207.107 google.com.au
O1 - Hosts: 94.75.207.107 www.google.com.au
O1 - Hosts: 94.75.207.107 google.be
O1 - Hosts: 94.75.207.107 www.google.be
O1 - Hosts: 94.75.207.107 google.com.br
O1 - Hosts: 94.75.207.107 www.google.com.br
O1 - Hosts: 94.75.207.107 google.ca
O1 - Hosts: 38 more lines…
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - Reg Error: Value error. File not found
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngin0.dll (Conduit Ltd.)
O2 - BHO: (SBCONVERT Class) - {31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B} - Reg Error: Value error. File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - Reg Error: Value error. File not found
O2 - BHO: (WebDetectorBHO Class) - {43BEAFD9-E005-483D-A367-146BA6C8A32E} - C:\Program Files\Tudou\滄厒Tudou\tudouDetector.dll (土豆网)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\tbBit1.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - Reg Error: Value error. File not found
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - Reg Error: Value error. File not found
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - Reg Error: Value error. File not found
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Dealio Toolbar\SearchSettings.dll (Spigot, Inc.)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O2 - BHO: (XBTBPos00 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\BigSeekPro Toolbar\tbcore3.dll ()
O2 - BHO: (GrabberObj Class) - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (BigSeekPro Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\BigSeekPro Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Reg Error: Value error. File not found
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngin0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (BitTorrentBar Toolbar) - {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - C:\Program Files\BitTorrentBar\tbBit1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (BigSeekPro Toolbar) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - C:\Program Files\BigSeekPro Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (BitTorrentBar Toolbar) - {88C7F2AA-F93F-432C-8F0E-B7D85967A527} - C:\Program Files\BitTorrentBar\tbBit1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe (VIA Technologies, Inc.)
O4 - HKLM..\Run: [bat remote exit list] C:\Documents and Settings\All Users\Application Data\mapi nurb bat remote\each coal.exe (Micoumbe Speed)
O4 - HKLM..\Run: [Cmaudio] File not found
O4 - HKLM..\Run: [DellTouch] C:\WINDOWS\MMKeybd.exe (Netropa Corp.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Google Pinyin 2 Autoupdater] C:\Program Files\Google\Google Pinyin 2\GooglePinyinDaemon.exe (Google Inc.)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [MsmqIntCert] C:\windows\System32\mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\windows\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\windows\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Dealio Toolbar\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [Warning: do not remove it!] C:\windows\System32\fpplock.exe (ZQS Software Team)
O4 - HKLM..\Run: [憤厒蹄6] C:\Program Files\蹄6厙\憤厒蹄6\Ku6SpeedUpper.exe (酷6网(北京)信息技术有限公司)
O4 - HKLM..\Run: [极速酷6] C:\Program Files\蹄6厙\憤厒蹄6\Ku6SpeedUpper.exe (酷6网(北京)信息技术有限公司)
O4 - HKCU..\Run: [Advanced SystemCare 3] C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [VeohPlugin] C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe (Veoh Networks)
O4 - Startup: C:\Documents and Settings\Terence\Start Menu\Programs\Startup\ViiKiiDesktopPlugin.lnk = File not found
O4 - Startup: C:\Documents and Settings\Terence\Start Menu\Programs\Startup\雄滄厒芩飪.lnk = C:\Program Files\Tudou\滄厒Tudou\TudouVa.exe (土豆网)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - Reg Error: Value error. File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Value error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/8/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {4A85DBE0-BFB2-4119-8401-186A7C6EB653} http://messenger.zone.msn.com/MessengerGam…S.cab109791.cab ()
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-SG/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} http://www.acclaim.com/cabs/acclaim_v5.cab (GameLauncher Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flash…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D84EB4B0-BFA9-4B0C-B75A-17ABAD45ABB7} http://images.friendster.com/200910A-023/j…ageUploader.cab (Friendster Image Uploader Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Reg Error: Value error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Value error. File not found
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Value error. File not found
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Value error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - File not found
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\windows\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Terence\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Terence\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\windows\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: SSHNAS - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - F:\Program Files\WIZET\MapleStory\l3codeca.acm File not found
Drivers32: msacm.siren - sirenacm.dll File not found
Drivers32: msacm.sl_anet - C:\windows\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\windows\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FPS1 - C:\windows\System32\frapsvid.dll (Beepa P/L)
Drivers32: vidc.iv31 - C:\windows\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\windows\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\windows\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56590081070202880)

========== Files/Folders - Created Within 30 Days ==========

[2010/12/17 04:57:13 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Terence\Desktop\OTL.exe
[2010/12/16 15:45:23 | 007,622,112 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Terence\Desktop\mbam-setup-1.50.0.0.exe
[2010/12/15 14:47:50 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\hssff
[2010/12/15 02:30:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Terence\Application Data\PriceGong
[2010/12/13 12:28:52 | 000,000,000 | —D | C] – C:\Hotspot Shield
[2010/12/13 12:28:41 | 000,000,000 | —D | C] – C:\Program Files\Hotspot Shield
[2010/12/11 15:23:56 | 000,000,000 | —D | C] – C:\Program Files\LogMeIn Hamachi
[2010/12/09 05:29:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Terence\Application Data\MSN6
[2010/12/01 05:12:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Terence\Local Settings\Application Data\Conduit
[2010/12/01 05:12:35 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2010/12/01 05:12:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Terence\Local Settings\Application Data\BitTorrentBar
[2010/12/01 05:12:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Terence\Local Settings\Application Data\ConduitEngine
[2010/12/01 05:12:18 | 000,000,000 | —D | C] – C:\Program Files\ConduitEngine
[2010/12/01 05:12:03 | 000,000,000 | —D | C] – C:\Program Files\BitTorrentBar
[2010/12/01 05:12:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Terence\Local Settings\Application Data\Temp
[2010/11/25 20:29:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NexonSG
[2010/11/25 20:29:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Nexon
[2010/11/25 20:27:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Terence\Local Settings\Application Data\CSO
[2010/11/25 13:40:27 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\windows\System32\javaws.exe
[2010/11/25 13:40:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\windows\System32\javaw.exe
[2010/11/25 13:40:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\windows\System32\java.exe
[2009/12/05 00:53:47 | 010,783,584 | —- | C] (Microsoft Corporation) – C:\Program Files\Install_MSN_Messenger.exe
[2009/12/05 00:42:01 | 020,549,448 | —- | C] (Microsoft Corporation) – C:\Program Files\msnsetup_full.exe
[2004/07/09 04:08:36 | 000,472,576 | —- | C] (Microsoft Corporation) – C:\Program Files\dxsetup.exe
[2004/07/09 04:08:34 | 002,242,560 | —- | C] (Microsoft Corporation) – C:\Program Files\dsetup32.dll
[2004/07/09 03:03:10 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Program Files\DSETUP.dll
[4 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[14 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/12/17 05:00:00 | 000,000,286 | -H– | M] () – C:\windows\tasks\AF5330929188A23E.job
[2010/12/17 05:00:00 | 000,000,282 | -H– | M] () – C:\windows\tasks\A5F7188291488A86.job
[2010/12/17 04:57:18 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Terence\Desktop\OTL.exe
[2010/12/17 04:32:37 | 000,000,269 | —- | M] () – C:\windows\MSIOSD.INI
[2010/12/17 04:29:00 | 000,000,886 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/17 04:17:00 | 000,001,018 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1647877149-725345543-1008UA.job
[2010/12/17 00:40:41 | 000,000,117 | —- | M] () – C:\Documents and Settings\Terence\jagex_runescape_preferences2.dat
[2010/12/17 00:40:12 | 000,000,046 | —- | M] () – C:\Documents and Settings\Terence\jagex_runescape_preferences.dat
[2010/12/16 23:17:01 | 000,000,966 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1647877149-725345543-1008Core.job
[2010/12/16 16:41:34 | 000,000,774 | —- | M] () – C:\Documents and Settings\Terence\Start Menu\Programs\Startup\雄滄厒芩飪.lnk
[2010/12/16 16:40:51 | 000,000,157 | —- | M] () – C:\windows\System32\Ku6Kss.ini
[2010/12/16 16:40:28 | 000,000,882 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/16 16:40:08 | 000,002,048 | –S- | M] () – C:\windows\bootstat.dat
[2010/12/16 15:47:26 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/16 15:46:01 | 007,622,112 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Terence\Desktop\mbam-setup-1.50.0.0.exe
[2010/12/15 14:41:56 | 000,002,206 | —- | M] () – C:\windows\System32\wpa.dbl
[2010/12/15 03:10:24 | 000,012,800 | —- | M] () – C:\Documents and Settings\Terence\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/14 17:24:02 | 000,001,568 | —- | M] () – C:\windows\System32\msexcr.ini
[2010/12/14 03:25:10 | 002,359,350 | —- | M] () – C:\Documents and Settings\Terence\Desktop\untitled.bmp
[2010/12/12 03:05:00 | 000,000,456 | —- | M] () – C:\windows\tasks\Driver Robot.job
[2010/12/11 15:23:57 | 000,000,685 | —- | M] () – C:\Documents and Settings\All Users\Desktop\LogMeIn Hamachi.lnk
[2010/12/07 15:58:17 | 000,000,108 | —- | M] () – C:\Documents and Settings\Terence\Application Data\RSBot_Accounts.ini
[2010/12/03 18:37:30 | 000,000,712 | —- | M] () – C:\Documents and Settings\Terence\Desktop\Shortcut to amped_directx.lnk
[2010/12/02 19:43:35 | 000,000,717 | —- | M] () – C:\Documents and Settings\Terence\Desktop\GetampedSEA.lnk
[2010/11/29 17:42:18 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbamswissarmy.sys
[2010/11/29 17:42:06 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\windows\System32\drivers\mbam.sys
[2010/11/25 20:23:32 | 000,000,677 | —- | M] () – C:\Documents and Settings\Terence\Desktop\CSOLauncher.exe.lnk
[2010/11/25 20:23:32 | 000,000,677 | —- | M] () – C:\Documents and Settings\Terence\Application Data\Microsoft\Internet Explorer\Quick Launch\Counter-Strike Online.lnk
[4 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
[14 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/12/14 17:24:01 | 000,001,568 | —- | C] () – C:\windows\System32\msexcr.ini
[2010/12/07 15:49:40 | 000,000,108 | —- | C] () – C:\Documents and Settings\Terence\Application Data\RSBot_Accounts.ini
[2010/12/03 18:37:30 | 000,000,712 | —- | C] () – C:\Documents and Settings\Terence\Desktop\Shortcut to amped_directx.lnk
[2010/11/25 20:23:32 | 000,000,677 | —- | C] () – C:\Documents and Settings\Terence\Desktop\CSOLauncher.exe.lnk
[2010/11/25 20:23:32 | 000,000,677 | —- | C] () – C:\Documents and Settings\Terence\Application Data\Microsoft\Internet Explorer\Quick Launch\Counter-Strike Online.lnk
[2010/11/19 02:19:22 | 002,359,350 | —- | C] () – C:\Documents and Settings\Terence\Desktop\untitled.bmp
[2010/03/08 16:06:42 | 000,000,086 | —- | C] () – C:\Documents and Settings\Terence\Application Data\RSBot Accounts.ini
[2010/01/20 18:54:00 | 000,012,800 | —- | C] () – C:\Documents and Settings\Terence\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/25 15:44:21 | 000,000,157 | —- | C] () – C:\windows\System32\Ku6Kss.ini
[2009/10/19 22:17:37 | 000,000,754 | —- | C] () – C:\windows\WORDPAD.INI
[2009/10/16 13:05:52 | 000,691,696 | —- | C] () – C:\windows\System32\drivers\sptd.sys
[2009/09/13 15:42:15 | 000,000,399 | —- | C] () – C:\windows\NJCOM.INI
[2009/08/25 10:38:44 | 000,001,573 | —- | C] () – C:\windows\System32\Ku6Ksw.dll
[2009/06/24 21:29:25 | 001,970,176 | —- | C] () – C:\windows\System32\d3dx9.dll
[2009/06/01 16:54:15 | 000,000,110 | —- | C] () – C:\windows\GMouse.ini
[2008/11/30 21:31:45 | 000,000,382 | —- | C] () – C:\Program Files\Shortcut to Program Files.lnk
[2008/10/24 17:57:52 | 000,000,000 | —- | C] () – C:\windows\galaxy.ini
[2008/10/16 10:42:31 | 000,000,045 | —- | C] () – C:\windows\msgtn.ini
[2008/09/11 20:46:03 | 000,028,672 | R— | C] () – C:\windows\System32\cmirmdrv.dll
[2008/09/11 20:45:33 | 000,000,092 | —- | C] () – C:\windows\CMISETUP.INI
[2008/09/11 20:45:32 | 000,000,026 | —- | C] () – C:\windows\CMCDPLAY.INI
[2008/09/11 20:45:29 | 000,028,672 | —- | C] () – C:\windows\CMIRmDriver.dll
[2008/09/11 20:37:46 | 000,000,311 | —- | C] () – C:\windows\MMKEYBD.INI
[2008/09/11 20:37:46 | 000,000,269 | —- | C] () – C:\windows\MSIOSD.INI
[2008/09/11 20:37:44 | 000,028,672 | —- | C] () – C:\windows\System32\msiosd32.dll
[2008/09/11 20:37:44 | 000,000,000 | —- | C] () – C:\windows\WININIT.INI
[2008/09/10 06:20:13 | 000,004,161 | —- | C] () – C:\windows\ODBCINST.INI
[2004/07/22 10:51:34 | 003,432,656 | —- | C] () – C:\Program Files\ManagedDX.CAB
[2004/07/19 22:58:36 | 001,156,363 | —- | C] () – C:\Program Files\BDANT.cab
[2004/07/19 22:53:26 | 000,976,020 | —- | C] () – C:\Program Files\BDAXP.cab
[2004/07/09 14:17:16 | 013,265,040 | —- | C] () – C:\Program Files\dxnt.cab
[2004/07/09 09:13:48 | 015,493,481 | —- | C] () – C:\Program Files\DirectX.cab
[2004/07/09 09:13:46 | 000,703,080 | —- | C] () – C:\Program Files\BDA.cab

========== LOP Check ==========

[2010/04/02 22:29:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/04/02 13:59:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/10/16 15:27:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2009/08/14 17:54:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2010/12/15 14:47:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\hssff
[2008/12/04 21:42:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Insight Software
[2008/12/04 21:42:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Insight Software Solutions
[2009/12/19 13:48:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\mapi nurb bat remote
[2009/08/31 14:18:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2010/11/25 20:29:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nexon
[2010/11/25 20:29:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonSG
[2010/10/10 12:58:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2009/08/24 21:30:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2009/12/20 20:33:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpeedBit
[2010/04/02 08:40:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/10/19 11:07:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Toolbar4
[2009/09/15 17:00:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/12/02 19:40:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\BitTorrent
[2010/02/24 16:52:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\CasinoOnNet
[2010/04/04 09:34:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\DAEMON Tools Lite
[2009/12/18 22:31:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\Dealio
[2010/09/26 01:33:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\FFSJ
[2010/10/09 19:55:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\Gygan
[2010/08/29 03:33:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\Hoyle
[2010/08/29 03:19:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\Hoyle FaceCreator
[2010/04/02 20:14:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\IObit
[2009/12/18 22:13:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\messdeafcorn
[2010/06/05 18:23:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\MySQL
[2010/01/15 12:49:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\Nexon
[2010/12/17 04:30:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\PriceGong
[2009/12/18 22:31:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\Search Settings
[2010/03/07 15:00:41 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\Subversion
[2010/12/16 16:41:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\uTorrent
[2010/10/10 17:58:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Terence\Application Data\ViiKiiDesktopPlugin.5E22EA0FF243470AB5EDDF282C0A5B52E9909C36.1
[2010/12/17 05:00:00 | 000,000,282 | -H– | M] () – C:\windows\Tasks\A5F7188291488A86.job
[2010/12/17 05:00:00 | 000,000,286 | -H– | M] () – C:\windows\Tasks\AF5330929188A23E.job
[2010/12/12 03:05:00 | 000,000,456 | —- | M] () – C:\windows\Tasks\Driver Robot.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/09/09 22:47:58 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/09/09 22:47:58 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2009/06/18 12:48:03 | 000,005,174 | —- | M] () – C:\newaccs.bmp
[2004/08/03 22:38:34 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/11/19 10:43:57 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/12/16 16:39:58 | 1607,462,912 | -HS- | M] () – C:\pagefile.sys
[2009/06/22 20:40:21 | 000,005,120 | -H– | M] () – C:\photothumb.db
[2010/03/11 17:59:41 | 000,000,000 | —- | M] () – C:\s9817212a.txt
[2009/03/11 00:25:24 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009/03/11 18:05:16 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009/03/11 23:21:33 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009/03/12 19:48:58 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009/03/12 23:49:20 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2009/03/14 02:05:13 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009/03/14 11:10:10 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2009/03/14 12:03:45 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2009/03/14 12:26:36 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009/03/15 02:13:58 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/03/16 21:51:35 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/03/17 00:08:45 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/03/17 11:10:10 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009/03/17 17:43:18 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2009/03/17 23:00:11 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2009/04/02 23:10:44 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2009/03/09 00:08:55 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2009/03/09 15:51:34 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2009/03/09 23:53:57 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2009/03/10 11:22:56 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2009/03/11 00:25:24 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/03/11 18:05:16 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/03/11 23:21:33 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/03/12 19:48:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/03/12 23:49:20 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/03/14 02:05:12 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/03/14 11:10:10 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/03/14 12:03:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/03/14 12:26:36 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/03/15 02:13:58 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/03/16 21:51:35 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/03/17 00:08:45 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/03/17 11:10:10 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/03/17 17:43:18 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/03/17 23:00:11 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/04/02 23:10:43 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/03/09 00:08:54 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/03/09 15:51:34 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/03/09 23:53:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/03/10 11:22:56 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2010/01/15 09:31:41 | 000,000,000 | —- | M] () – C:\Tech_Vista.log
[2009/07/25 02:11:49 | 000,004,096 | -HS- | M] () – C:\Thumbs.db
[2010/04/03 17:47:41 | 000,000,097 | —- | M] () – C:\tudouva.ini

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2008/09/09 22:47:09 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 20:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 18:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/07/10 12:15:46 | 000,306,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[4 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2004/07/09 09:13:46 | 000,703,080 | —- | M] () – C:\Program Files\BDA.cab
[2004/07/19 22:58:36 | 001,156,363 | —- | M] () – C:\Program Files\BDANT.cab
[2004/07/19 22:53:26 | 000,976,020 | —- | M] () – C:\Program Files\BDAXP.cab
[2004/07/09 09:13:48 | 015,493,481 | —- | M] () – C:\Program Files\DirectX.cab
[2004/07/09 03:03:10 | 000,062,976 | —- | M] (Microsoft Corporation) – C:\Program Files\DSETUP.dll
[2004/07/09 04:08:34 | 002,242,560 | —- | M] (Microsoft Corporation) – C:\Program Files\dsetup32.dll
[2004/07/09 14:17:16 | 013,265,040 | —- | M] () – C:\Program Files\dxnt.cab
[2004/07/09 04:08:36 | 000,472,576 | —- | M] (Microsoft Corporation) – C:\Program Files\dxsetup.exe
[2009/12/05 00:54:01 | 010,783,584 | —- | M] (Microsoft Corporation) – C:\Program Files\Install_MSN_Messenger.exe
[2004/07/22 10:51:34 | 003,432,656 | —- | M] () – C:\Program Files\ManagedDX.CAB
[2009/12/05 00:42:26 | 020,549,448 | —- | M] (Microsoft Corporation) – C:\Program Files\msnsetup_full.exe
[2008/11/30 21:31:45 | 000,000,382 | —- | M] () – C:\Program Files\Shortcut to Program Files.lnk

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/09/10 06:17:34 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008/09/10 06:17:34 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008/09/10 06:17:34 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/09/09 22:48:06 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/12/18 22:08:05 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\Terence\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2009/12/18 22:08:05 | 000,000,079 | —- | M] () – C:\Documents and Settings\Terence\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/09/26 00:56:45 | 001,116,646 | —- | M] (Le Minh Hoang ) – C:\Documents and Settings\Terence\Desktop\FSJSetup.exe
[2010/11/10 18:54:47 | 000,237,776 | —- | M] () – C:\Documents and Settings\Terence\Desktop\immobileoberonsea97.exe
[2010/12/16 15:46:01 | 007,622,112 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Terence\Desktop\mbam-setup-1.50.0.0.exe
[2010/12/17 04:57:18 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Terence\Desktop\OTL.exe
[2010/06/14 02:04:16 | 001,045,148 | —- | M] (PragmaDigm, Inc. ) – C:\Documents and Settings\Terence\Desktop\prkdisk1.exe
[2010/03/05 11:10:33 | 000,061,440 | —- | M] (Gary's Hood) – C:\Documents and Settings\Terence\Desktop\rsclient.exe
[2010/04/03 21:10:55 | 003,178,547 | —- | M] () – C:\Documents and Settings\Terence\Desktop\TudouVa1.40_1300B.exe
[2010/09/22 22:30:40 | 003,184,055 | —- | M] () – C:\Documents and Settings\Terence\Desktop\TudouVa_1.40.19.0_Release_Build.exe
[2010/06/15 01:29:28 | 018,015,723 | —- | M] () – C:\Documents and Settings\Terence\Desktop\vlc-1.0.1-win32.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-16 20:28:47

========== Files - Unicode (All) ==========
[2010/11/25 20:29:37 | 000,000,000 | —D | M](C:\Documents and Settings\Terence\My Documents\?? ???) – C:\Documents and Settings\Terence\My Documents\넥슨 플러그
[2010/11/25 20:29:37 | 000,000,000 | —D | C](C:\Documents and Settings\Terence\My Documents\?? ???) – C:\Documents and Settings\Terence\My Documents\넥슨 플러그
[2009/12/26 15:07:31 | 000,000,000 | —D | M](C:\Documents and Settings\Terence\My Documents\酷6??) – C:\Documents and Settings\Terence\My Documents\酷6视频
[2009/12/26 15:07:31 | 000,000,000 | —D | C](C:\Documents and Settings\Terence\My Documents\酷6??) – C:\Documents and Settings\Terence\My Documents\酷6视频

========== Alternate Data Streams ==========

@Alternate Data Stream - 48 bytes -> C:\Documents and Settings\All Users\DRM:مايكروسوفت
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6D6C4572
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D74B6CF5
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:53C9FE0C
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:61A065F2
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3AE3CF4E

< End of report >
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Next:


Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step

Next:

Note: if the Cure option is not there, please select 'Skip'.

Please read carefully and follow these steps.
  • Please download TDSSKiller.zip
    • Extract it to your desktop
    • Double click TDSSKiller.exe
    • Press Start Scan
      • Only if Malicious objects are found then ensure Cure is selected
      • Then click Continue > Reboot now
    • Copy and paste the log in your next reply
      • A copy of the log will be saved automatically to the root directory, root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
    please post the contents of that log TDSSKiller and GooredFix log.


    Also please describe how your computer behaves at the moment.
My computer is behaving normal just like before. but whenever i type google.com it bring me to a search page called qbyrd.com and some youtube links were also redirected to it.

this is the gooredfix log.


GooredFix by jpshortstuff (03.07.10.1)
Log created at 14:00 on 17/12/2010 (Terence)
Firefox version 3.6.12 (en-US)

========== GooredScan ==========

Removing Orphan:
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG9\Firefox" -> Success!

========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
[removed] [04:28 13/12/2010]
[removed] [17:24 04/12/2009]
{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} [17:24 04/12/2009]
{972ce4c6-7e08-4474-a285-3208198ce6fd} [03:28 20/10/2009]
{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} [10:04 07/03/2010]
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [02:21 22/05/2010]
{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} [07:30 16/09/2010]
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [05:40 25/11/2010]

C:\Documents and Settings\Terence\Application Data\Mozilla\Firefox\Profiles\ypa8xrb1.default\extensions\
{20a82645-c095-46ed-80e3-08825760534b} [07:23 19/08/2010]
{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [07:23 19/08/2010]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="C:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [11:05 18/10/2009]
"[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [10:04 07/03/2010]

-=E.O.F=-


this is the TDSSkiller log.

2010/12/17 14:05:01.0312 TDSS rootkit removing tool 2.4.11.0 Dec 8 2010 14:46:40
2010/12/17 14:05:01.0312 ================================================================================
2010/12/17 14:05:01.0312 SystemInfo:
2010/12/17 14:05:01.0312
2010/12/17 14:05:01.0312 OS Version: 5.1.2600 ServicePack: 2.0
2010/12/17 14:05:01.0312 Product type: Workstation
2010/12/17 14:05:01.0312 ComputerName: HOME-47627E8BE5
2010/12/17 14:05:01.0312 UserName: Terence
2010/12/17 14:05:01.0312 Windows directory: C:\windows
2010/12/17 14:05:01.0312 System windows directory: C:\windows
2010/12/17 14:05:01.0312 Processor architecture: Intel x86
2010/12/17 14:05:01.0312 Number of processors: 1
2010/12/17 14:05:01.0312 Page size: 0x1000
2010/12/17 14:05:01.0312 Boot type: Normal boot
2010/12/17 14:05:01.0312 ================================================================================
2010/12/17 14:05:03.0140 Initialize success
2010/12/17 14:05:16.0609 ================================================================================
2010/12/17 14:05:16.0609 Scan started
2010/12/17 14:05:16.0609 Mode: Manual;
2010/12/17 14:05:16.0609 ================================================================================
2010/12/17 14:05:17.0890 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\windows\system32\DRIVERS\ACPI.sys
2010/12/17 14:05:18.0328 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\windows\system32\drivers\ACPIEC.sys
2010/12/17 14:05:19.0000 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\windows\system32\drivers\aec.sys
2010/12/17 14:05:19.0453 AFD (55e6e1c51b6d30e54335750955453702) C:\windows\System32\drivers\afd.sys
2010/12/17 14:05:22.0421 AsyncMac (02000abf34af4c218c35d257024807d6) C:\windows\system32\DRIVERS\asyncmac.sys
2010/12/17 14:05:22.0843 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\windows\system32\DRIVERS\atapi.sys
2010/12/17 14:05:23.0500 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\windows\system32\DRIVERS\atmarpc.sys
2010/12/17 14:05:23.0875 audstub (d9f724aa26c010a217c97606b160ed68) C:\windows\system32\DRIVERS\audstub.sys
2010/12/17 14:05:24.0218 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\windows\system32\drivers\Beep.sys
2010/12/17 14:05:24.0593 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\windows\system32\drivers\cbidf2k.sys
2010/12/17 14:05:25.0234 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\windows\system32\drivers\Cdaudio.sys
2010/12/17 14:05:25.0625 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\windows\system32\drivers\Cdfs.sys
2010/12/17 14:05:26.0031 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\windows\system32\DRIVERS\cdrom.sys
2010/12/17 14:05:27.0218 cmuda (9776539378fd13c76c8dc982ed8608e3) C:\windows\system32\drivers\cmuda.sys
2010/12/17 14:05:28.0750 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\windows\system32\DRIVERS\disk.sys
2010/12/17 14:05:29.0203 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\windows\system32\drivers\dmboot.sys
2010/12/17 14:05:29.0718 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\windows\system32\drivers\dmio.sys
2010/12/17 14:05:30.0078 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\windows\system32\drivers\dmload.sys
2010/12/17 14:05:30.0453 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\windows\system32\drivers\DMusic.sys
2010/12/17 14:05:31.0187 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\windows\system32\drivers\drmkaud.sys
2010/12/17 14:05:31.0562 E1000 (854293999e91bf2eb9e786166de4a35f) C:\windows\system32\DRIVERS\e1000325.sys
2010/12/17 14:05:32.0343 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\windows\system32\drivers\Fastfat.sys
2010/12/17 14:05:32.0796 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\windows\system32\DRIVERS\fdc.sys
2010/12/17 14:05:33.0171 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\windows\system32\drivers\Fips.sys
2010/12/17 14:05:33.0546 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\windows\system32\DRIVERS\flpydisk.sys
2010/12/17 14:05:33.0968 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\windows\system32\DRIVERS\fltMgr.sys
2010/12/17 14:05:34.0390 fssfltr (c6ee3a87fe609d3e1db9dbd072a248de) C:\windows\system32\DRIVERS\fssfltr_tdi.sys
2010/12/17 14:05:34.0750 FsVga (455f778ee14368468560bd7cb8c854d0) C:\windows\system32\DRIVERS\fsvga.sys
2010/12/17 14:05:35.0093 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\windows\system32\drivers\Fs_Rec.sys
2010/12/17 14:05:35.0453 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\windows\system32\DRIVERS\ftdisk.sys
2010/12/17 14:05:36.0109 Gpc (c0f1d4a21de5a415df8170616703debf) C:\windows\system32\DRIVERS\msgpc.sys
2010/12/17 14:05:36.0500 hamachi (833051c6c6c42117191935f734cfbd97) C:\windows\system32\DRIVERS\hamachi.sys
2010/12/17 14:05:36.0906 hidusb (1de6783b918f540149aa69943bdfeba8) C:\windows\system32\DRIVERS\hidusb.sys
2010/12/17 14:05:37.0703 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\windows\system32\Drivers\HTTP.sys
2010/12/17 14:05:38.0218 hwdatacard (8adf5ef39e896a65beded878494ee2b6) C:\windows\system32\DRIVERS\ewusbmdm.sys
2010/12/17 14:05:38.0671 hwusbfake (9be5caeabc6b2eb98b3a4839a55d47a0) C:\windows\system32\DRIVERS\ewusbfake.sys
2010/12/17 14:05:39.0703 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\windows\system32\DRIVERS\i8042prt.sys
2010/12/17 14:05:40.0359 ialm (44b7d5a4f2bd9fe21aea0bb0bace38c4) C:\windows\system32\DRIVERS\ialmnt5.sys
2010/12/17 14:05:41.0062 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\windows\system32\DRIVERS\imapi.sys
2010/12/17 14:05:41.0750 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\windows\system32\DRIVERS\intelide.sys
2010/12/17 14:05:42.0140 intelppm (279fb78702454dff2bb445f238c048d2) C:\windows\system32\DRIVERS\intelppm.sys
2010/12/17 14:05:42.0515 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\windows\system32\DRIVERS\Ip6Fw.sys
2010/12/17 14:05:42.0906 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\windows\system32\DRIVERS\ipfltdrv.sys
2010/12/17 14:05:43.0312 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\windows\system32\DRIVERS\ipinip.sys
2010/12/17 14:05:43.0734 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\windows\system32\DRIVERS\ipnat.sys
2010/12/17 14:05:44.0140 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\windows\system32\DRIVERS\ipsec.sys
2010/12/17 14:05:44.0531 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\windows\system32\DRIVERS\irenum.sys
2010/12/17 14:05:44.0937 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\windows\system32\DRIVERS\isapnp.sys
2010/12/17 14:05:45.0312 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\windows\system32\DRIVERS\kbdclass.sys
2010/12/17 14:05:45.0734 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\windows\system32\drivers\kmixer.sys
2010/12/17 14:05:46.0171 KSecDD (674d3e5a593475915dc6643317192403) C:\windows\system32\drivers\KSecDD.sys
2010/12/17 14:05:46.0968 Mkd2kfNt (6f4d79ea861137ef2f9078e265c2aa83) C:\windows\system32\drivers\Mkd2kfNt.sys
2010/12/17 14:05:47.0390 Mkd2Nadr (fe7925784f6801e983b41ec118ef62ac) C:\windows\system32\drivers\Mkd2Nadr.sys
2010/12/17 14:05:47.0781 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\windows\system32\drivers\mnmdd.sys
2010/12/17 14:05:48.0187 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\windows\system32\drivers\Modem.sys
2010/12/17 14:05:48.0578 Mouclass (34e1f0031153e491910e12551400192c) C:\windows\system32\DRIVERS\mouclass.sys
2010/12/17 14:05:48.0937 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\windows\system32\DRIVERS\mouhid.sys
2010/12/17 14:05:49.0328 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\windows\system32\drivers\MountMgr.sys
2010/12/17 14:05:49.0718 MQAC (eee50bf24caeedb515a8f3b22756d3bb) C:\windows\system32\drivers\mqac.sys
2010/12/17 14:05:50.0453 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\windows\system32\DRIVERS\mrxdav.sys
2010/12/17 14:05:51.0046 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\windows\system32\DRIVERS\mrxsmb.sys
2010/12/17 14:05:51.0593 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\windows\system32\drivers\Msfs.sys
2010/12/17 14:05:51.0968 Msikbd2k (9b99b04c28ccd19741dbbed64480195c) C:\windows\system32\DRIVERS\msikbd2k.sys
2010/12/17 14:05:52.0500 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\windows\system32\drivers\MSKSSRV.sys
2010/12/17 14:05:52.0843 msloop (64e8b7c65eb4796939c0f64f8170821b) C:\windows\system32\DRIVERS\loop.sys
2010/12/17 14:05:53.0234 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\windows\system32\drivers\MSPCLOCK.sys
2010/12/17 14:05:53.0593 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\windows\system32\drivers\MSPQM.sys
2010/12/17 14:05:53.0953 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\windows\system32\DRIVERS\mssmbios.sys
2010/12/17 14:05:54.0375 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\windows\system32\drivers\Mup.sys
2010/12/17 14:05:54.0828 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\windows\system32\drivers\NDIS.sys
2010/12/17 14:05:55.0281 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\windows\system32\DRIVERS\ndistapi.sys
2010/12/17 14:05:55.0640 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\windows\system32\DRIVERS\ndisuio.sys
2010/12/17 14:05:56.0078 NdisWan (0b90e255a9490166ab368cd55a529893) C:\windows\system32\DRIVERS\ndiswan.sys
2010/12/17 14:05:56.0468 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\windows\system32\drivers\NDProxy.sys
2010/12/17 14:05:56.0843 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\windows\system32\DRIVERS\netbios.sys
2010/12/17 14:05:57.0265 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\windows\system32\DRIVERS\netbt.sys
2010/12/17 14:05:57.0765 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\windows\system32\drivers\Npfs.sys
2010/12/17 14:05:58.0390 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\windows\system32\drivers\Ntfs.sys
2010/12/17 14:05:58.0984 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\windows\system32\drivers\Null.sys
2010/12/17 14:05:59.0328 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\windows\system32\DRIVERS\nwlnkflt.sys
2010/12/17 14:05:59.0703 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\windows\system32\DRIVERS\nwlnkfwd.sys
2010/12/17 14:06:00.0093 omci (1d98907d80461371437a7c898c58c8ae) C:\windows\system32\DRIVERS\omci.sys
2010/12/17 14:06:00.0500 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\windows\system32\DRIVERS\parport.sys
2010/12/17 14:06:01.0031 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\windows\system32\drivers\PartMgr.sys
2010/12/17 14:06:01.0406 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\windows\system32\drivers\ParVdm.sys
2010/12/17 14:06:01.0906 PCI (8086d9979234b603ad5bc2f5d890b234) C:\windows\system32\DRIVERS\pci.sys
2010/12/17 14:06:02.0687 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\windows\system32\DRIVERS\pciide.sys
2010/12/17 14:06:03.0078 Pcmcia (82a087207decec8456fbe8537947d579) C:\windows\system32\drivers\Pcmcia.sys
2010/12/17 14:06:05.0343 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\windows\system32\DRIVERS\raspptp.sys
2010/12/17 14:06:05.0765 PSched (48671f327553dcf1d27f6197f622a668) C:\windows\system32\DRIVERS\psched.sys
2010/12/17 14:06:06.0156 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\windows\system32\DRIVERS\ptilink.sys
2010/12/17 14:06:06.0531 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\windows\system32\Drivers\PxHelp20.sys
2010/12/17 14:06:08.0421 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\windows\system32\DRIVERS\rasacd.sys
2010/12/17 14:06:08.0812 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\windows\system32\DRIVERS\rasl2tp.sys
2010/12/17 14:06:09.0218 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\windows\system32\DRIVERS\raspppoe.sys
2010/12/17 14:06:09.0578 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\windows\system32\DRIVERS\raspti.sys
2010/12/17 14:06:10.0000 Rdbss (29d66245adba878fff574cd66abd2884) C:\windows\system32\DRIVERS\rdbss.sys
2010/12/17 14:06:10.0390 RDPCDD (4912d5b403614ce99c28420f75353332) C:\windows\system32\DRIVERS\RDPCDD.sys
2010/12/17 14:06:10.0812 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\windows\system32\DRIVERS\rdpdr.sys
2010/12/17 14:06:11.0296 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\windows\system32\drivers\RDPWD.sys
2010/12/17 14:06:11.0734 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\windows\system32\DRIVERS\redbook.sys
2010/12/17 14:06:12.0234 RMCAST (d18208ed6c768663b08c972eaa7a8b60) C:\windows\system32\drivers\RMCast.sys
2010/12/17 14:06:12.0734 Secdrv (ba0d892d2f786bcebdf03b0a252b47f3) C:\windows\system32\DRIVERS\secdrv.sys
2010/12/17 14:06:13.0125 serenum (a2d868aeeff612e70e213c451a70cafb) C:\windows\system32\DRIVERS\serenum.sys
2010/12/17 14:06:13.0500 Serial (cd9404d115a00d249f70a371b46d5a26) C:\windows\system32\DRIVERS\serial.sys
2010/12/17 14:06:13.0906 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\windows\system32\drivers\Sfloppy.sys
2010/12/17 14:06:14.0906 splitter (8e186b8f23295d1e42c573b82b80d548) C:\windows\system32\drivers\splitter.sys
2010/12/17 14:06:15.0531 sptd (cdddec541bc3c96f91ecb48759673505) C:\windows\system32\Drivers\sptd.sys
2010/12/17 14:06:15.0531 Suspicious file (NoAccess): C:\windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2010/12/17 14:06:15.0562 sptd - detected Locked file (1)
2010/12/17 14:06:15.0968 sr (e41b6d037d6cd08461470af04500dc24) C:\windows\system32\DRIVERS\sr.sys
2010/12/17 14:06:16.0500 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\windows\system32\DRIVERS\srv.sys
2010/12/17 14:06:17.0000 swenum (03c1bae4766e2450219d20b993d6e046) C:\windows\system32\DRIVERS\swenum.sys
2010/12/17 14:06:17.0375 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\windows\system32\drivers\swmidi.sys
2010/12/17 14:06:18.0953 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\windows\system32\drivers\sysaudio.sys
2010/12/17 14:06:19.0343 taphss (0c3b2a9c4bd2dd9a6c2e4084314dd719) C:\windows\system32\DRIVERS\taphss.sys
2010/12/17 14:06:19.0875 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\windows\system32\DRIVERS\tcpip.sys
2010/12/17 14:06:20.0343 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\windows\system32\drivers\TDPIPE.sys
2010/12/17 14:06:20.0718 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\windows\system32\drivers\TDTCP.sys
2010/12/17 14:06:21.0140 TermDD (a540a99c281d933f3d69d55e48727f47) C:\windows\system32\DRIVERS\termdd.sys
2010/12/17 14:06:21.0875 Udfs (12f70256f140cd7d52c58c7048fde657) C:\windows\system32\drivers\Udfs.sys
2010/12/17 14:06:22.0687 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\windows\system32\DRIVERS\update.sys
2010/12/17 14:06:23.0125 usbbus (5aadc9297c39aa249cd994acdba19034) C:\windows\system32\DRIVERS\lgusbbus.sys
2010/12/17 14:06:23.0484 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\windows\system32\DRIVERS\usbccgp.sys
2010/12/17 14:06:23.0843 UsbDiag (4650ffe04e5922399b0e932319e6b215) C:\windows\system32\DRIVERS\lgusbdiag.sys
2010/12/17 14:06:24.0250 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\windows\system32\DRIVERS\usbehci.sys
2010/12/17 14:06:24.0609 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\windows\system32\DRIVERS\usbhub.sys
2010/12/17 14:06:25.0015 USBModem (2666fe171e0c2e7085ccd5fe0bac09e3) C:\windows\system32\DRIVERS\lgusbmodem.sys
2010/12/17 14:06:25.0375 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\windows\system32\DRIVERS\usbscan.sys
2010/12/17 14:06:25.0765 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\windows\system32\DRIVERS\USBSTOR.SYS
2010/12/17 14:06:26.0140 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\windows\system32\DRIVERS\usbuhci.sys
2010/12/17 14:06:26.0578 vaxscsi (92cebc2bc7be2c8d49391b365569f306) C:\windows\System32\Drivers\vaxscsi.sys
2010/12/17 14:06:27.0015 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\windows\System32\drivers\vga.sys
2010/12/17 14:06:27.0734 VIAudio (a6fcca426660d3fc5a5cb7c0623a257b) C:\windows\system32\drivers\vinyl97.sys
2010/12/17 14:06:28.0171 VolSnap (ee4660083deba849ff6c485d944b379b) C:\windows\system32\drivers\VolSnap.sys
2010/12/17 14:06:28.0609 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\windows\system32\DRIVERS\wanarp.sys
2010/12/17 14:06:29.0312 wdmaud (2797f33ebf50466020c430ee4f037933) C:\windows\system32\drivers\wdmaud.sys
2010/12/17 14:06:29.0828 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\windows\system32\DRIVERS\wpdusb.sys
2010/12/17 14:06:30.0218 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\windows\System32\drivers\ws2ifsl.sys
2010/12/17 14:06:30.0625 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\windows\system32\DRIVERS\WudfPf.sys
2010/12/17 14:06:31.0031 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\windows\system32\DRIVERS\wudfrd.sys
2010/12/17 14:06:32.0578 ================================================================================
2010/12/17 14:06:32.0578 Scan finished
2010/12/17 14:06:32.0578 ================================================================================
2010/12/17 14:06:32.0625 Detected object count: 1
2010/12/17 14:07:49.0796 Locked file(sptd) - User select action: Skip
2010/12/17 14:08:26.0109 Deinitialize success
Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Did you download it from the first link? Delete combofix from your desktop and download it from the first link
ComboFix 10-12-16.04 - Terence 7/2010 Fri 20:59:03.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.2.[removed].18.1022.613 [GMT 8:00] 執行位置: c:\documents and settings\Terence\Desktop\ComboFix.exe 注意 - 這台電腦沒有安裝恢復控制台 !! . ((((((((((((((((((((((((((((((((((((((( 被刪除的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\Toolbar4 c:\documents and settings\All Users\Application Data\Toolbar4\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}\cache\c86bb7eaf721397aef16880cb0330314 c:\documents and settings\All Users\Application Data\Toolbar4\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}\cache\CustomXMLKeywords c:\documents and settings\All Users\Application Data\Toolbar4\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}\cache\e971ff48de7507e570cd799fb4cb3ee1 c:\documents and settings\All Users\Application Data\Toolbar4\{1BB22D38-A411-4B13-A746-C2A4F4EC7344}\cache\ea5580f4a302fc3984e75841a38f7415 c:\documents and settings\Asthina.HOME-47627E8BE5\Application Data\Dealio c:\documents and settings\Asthina.HOME-47627E8BE5\Application Data\Dealio\res\widgets.xml c:\documents and settings\Asthina.HOME-47627E8BE5\Application Data\Dealio\temp\http___www_dealio_com_rss_coupons-deals_dotd_.xml c:\documents and settings\Loves\Application Data\Dealio c:\documents and settings\Loves\Application Data\Dealio\res\widgets.xml c:\documents and settings\Loves\Application Data\Dealio\temp\http___www_dealio_com_rss_coupons-deals_dotd_.xml c:\documents and settings\meow\Application Data\Dealio c:\documents and settings\meow\Application Data\Dealio\res\widgets.xml c:\documents and settings\meow\Application Data\Dealio\temp\http___www_dealio_com_rss_coupons-deals_dotd_.xml c:\documents and settings\Terence\Application Data\Dealio c:\documents and settings\Terence\Application Data\Dealio\res\widgets.xml c:\documents and settings\Terence\Application Data\Dealio\temp\~wtA7.tmp c:\documents and settings\Terence\Application Data\Dealio\temp\http___www_dealio_com_rss_coupons-deals_dotd_.xml c:\documents and settings\Terence\Application Data\PriceGong c:\documents and settings\Terence\Application Data\PriceGong\Data\1.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\a.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\b.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\c.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\d.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\e.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\f.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\g.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\h.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\i.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\J.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\k.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\l.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\m.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\mru.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\n.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\o.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\p.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\q.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\r.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\s.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\t.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\u.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\v.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\w.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\x.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\y.xml c:\documents and settings\Terence\Application Data\PriceGong\Data\z.xml c:\documents and settings\Terence\Recent\energy.tmp c:\documents and settings\Terence\Recent\SICKBOY.tmp c:\documents and settings\Terence\Recent\SM.tmp c:\documents and settings\Terence\Recent\tjd.tmp c:\program files\AskSearch\bin\DefaultSearch.dll c:\program files\BigSeekPro Toolbar\tbHElper.dll c:\program files\Dealio Toolbar c:\program files\Dealio Toolbar\config.ini c:\program files\Dealio Toolbar\Res\amazon.gif c:\program files\Dealio Toolbar\Res\apple.gif c:\program files\Dealio Toolbar\Res\barnes.gif c:\program files\Dealio Toolbar\Res\bestbuy.gif c:\program files\Dealio Toolbar\Res\dealio_logo.gif c:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif c:\program files\Dealio Toolbar\Res\ebay.gif c:\program files\Dealio Toolbar\Res\icon_settings.gif c:\program files\Dealio Toolbar\Res\macys.gif c:\program files\Dealio Toolbar\Res\newegg.gif c:\program files\Dealio Toolbar\Res\overstock.gif c:\program files\Dealio Toolbar\Res\search-button-hover.gif c:\program files\Dealio Toolbar\Res\search-button.gif c:\program files\Dealio Toolbar\Res\search-chevron-hover.gif c:\program files\Dealio Toolbar\Res\search-chevron.gif c:\program files\Dealio Toolbar\Res\search_amazon.gif c:\program files\Dealio Toolbar\Res\search_dealio.gif c:\program files\Dealio Toolbar\Res\search_ebay.gif c:\program files\Dealio Toolbar\Res\search_yahoo.gif c:\program files\Dealio Toolbar\Res\separator.gif c:\program files\Dealio Toolbar\Res\target.gif c:\program files\Dealio Toolbar\Res\walmart.gif c:\program files\Dealio Toolbar\Res\widgets.xml c:\program files\Dealio Toolbar\SeARchsettings.dll c:\program files\Dealio Toolbar\SearchSettings.exe c:\program files\Dealio Toolbar\SearchSettingsRes409.dll c:\program files\Dealio Toolbar\sscfg.ini c:\program files\Dealio Toolbar\WidgiHelper.exe c:\program files\Mozilla Firefox\searchplugins\search.xml C:\Thumbs.db c:\windows\explorer(2).exe c:\windows\system32\3833516466.dat . ((((((((((((((((((((((((((((((((((((((( 驅動/服務 ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Legacy_MYWEBSEARCHSERVICE ——-\Legacy_SSHNAS ((((((((((((((((((((((((( 2010-11-17 至 2010-12-17 的新的檔案 ))))))))))))))))))))))))))))))) . 2010-12-13 04:28 . 2010-12-13 04:28 ——– dc—-w- C:\Hotspot Shield 2010-12-13 04:28 . 2010-11-04 18:43 506880 —-a-w- c:\program files\Mozilla Firefox\extensions\[removed]\components\afurladvisor.dll 2010-12-13 04:28 . 2010-12-16 21:12 ——– d—–w- c:\program files\Hotspot Shield 2010-12-11 07:23 . 2010-12-11 07:23 ——– d—–w- c:\program files\LogMeIn Hamachi 2010-11-30 21:12 . 2010-12-14 18:29 ——– dc—-w- c:\documents and settings\Terence\Local Settings\Application Data\Conduit 2010-11-30 21:12 . 2010-11-30 21:12 ——– d—–w- c:\program files\Conduit 2010-11-30 21:12 . 2010-12-14 18:30 ——– dc—-w- c:\documents and settings\Terence\Local Settings\Application Data\BitTorrentBar 2010-11-30 21:12 . 2010-12-14 18:30 ——– d—–w- c:\program files\BitTorrentBar 2010-11-30 21:12 . 2010-11-30 21:12 ——– dc—-w- c:\documents and settings\Terence\Local Settings\Application Data\Temp 2010-11-25 12:27 . 2010-12-16 20:17 ——– dc—-w- c:\documents and settings\Terence\Local Settings\Application Data\CSO . (((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-11-29 09:42 . 2010-04-02 14:38 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-11-29 09:42 . 2010-04-02 14:38 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-09-25 16:57 . 2010-09-25 16:58 794906 —-a-w- c:\windows\unins000.exe 2010-09-22 19:19 . 2010-09-22 19:19 37376 —-a-w- c:\windows\system32\drivers\HssDrv.sys 2010-09-22 19:19 . 2010-09-22 19:19 32768 —-a-w- c:\windows\system32\drivers\taphss.sys 2009-12-04 16:54 . 2009-12-04 16:53 10783584 -c–a-w- c:\program files\Install_MSN_Messenger.exe 2009-12-04 16:42 . 2009-12-04 16:42 20549448 -c–a-w- c:\program files\msnsetup_full.exe 2004-07-08 20:08 . 2004-07-08 20:08 472576 —-a-w- c:\program files\dxsetup.exe 2004-07-08 20:08 . 2004-07-08 20:08 2242560 -c–a-w- c:\program files\dsetup32.dll 2004-07-08 19:03 . 2004-07-08 19:03 62976 —-a-w- c:\program files\DSETUP.dll 2010-06-11 18:05 . 2009-12-10 16:39 253952 —-a-w- c:\program files\mozilla firefox\components\CheckTudouVa.dll 2003-12-06 14:12 121856 –sha-w- c:\windows\system32\fpplock.exe . ((((((((((((((((((((((((((((((((((((( 重要登入點 )))))))))))))))))))))))))))))))))))))))))))))))))) . . *注意* 空白與合法缺省登錄將不會被顯示 REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\tbBit1.dll" [2010-12-14 3908192] [HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}] 2008-11-24 12:25 333192 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] 2010-12-14 18:31 3908192 —-a-w- c:\program files\ConduitEngine\ConduitEngin0.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{43BEAFD9-E005-483D-A367-146BA6C8A32E}] 2010-04-19 22:08 312896 —-a-w- c:\program files\Tudou\滄厒Tudou\tudouDetector.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}] 2010-12-14 18:31 3908192 —-a-w- c:\program files\BitTorrentBar\tbBit1.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-24 333192] "{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\tbBit1.dll" [2010-12-14 3908192] "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngin0.dll" [2010-12-14 3908192] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}] [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{88C7F2AA-F93F-432C-8F0E-B7D85967A527}"= "c:\program files\BitTorrentBar\tbBit1.dll" [2010-12-14 3908192] "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-24 333192] [HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal] @="{C5994560-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}] 2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified] @="{C5994561-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}] 2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict] @="{C5994562-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}] 2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked] @="{C5994563-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}] 2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly] @="{C5994564-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}] 2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted] @="{C5994565-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}] 2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded] @="{C5994566-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}] 2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored] @="{C5994567-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}] 2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned] @="{C5994568-53D9-4125-87C9-F193FC689CB2}" [HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}] 2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Ku6KssService] @="{1CE908E9-4E19-4A42-9E8F-5BBFB1080E9B}" [HKEY_CLASSES_ROOT\CLSID\{1CE908E9-4E19-4A42-9E8F-5BBFB1080E9B}] 2009-08-28 08:25 308840 —-a-w- c:\windows\system32\Ku6Kss.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2010-07-06 2634048] "Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-02-08 2343632] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696] "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-11-30 328056] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952] "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168] "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976] "DellTouch"="c:\windows\MMKeybd.exe" [2002-01-16 163840] "AudioDeck"="c:\program files\VIAudioi\SBADeck\ADeck.exe" [2005-12-12 454656] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920] "Google Pinyin 2 Autoupdater"="c:\program files\Google\Google Pinyin 2\GooglePinyinDaemon.exe" [2009-09-13 1119728] "bat remote exit list"="c:\documents and settings\All Users\Application Data\mapi nurb bat remote\each coal.exe" [2010-12-17 761856] "MsmqIntCert"="mqrt.dll" [2009-06-25 177152] "憤厒蹄6"="c:\program files\蹄6厙\憤厒蹄6\Ku6SpeedUpper.exe" [2009-09-10 1214048] "极速酷6"="c:\program files\蹄6厙\憤厒蹄6\Ku6SpeedUpper.exe" [2009-09-10 1214048] "Warning: do not remove it!"="fpplock.exe" [2003-12-06 121856] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-08-20 1164584] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552] "LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-12-06 1910152] c:\documents and settings\Terence\Start Menu\Programs\Startup\ ViiKiiDesktopPlugin.lnk - [N/A] 雄滄厒芩飪.lnk - c:\program files\Tudou\滄厒Tudou\TudouVa.exe [2010-6-12 1404928] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\java.exe"= "c:\\Program Files\\Java\\jre6\\bin\\java.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Java\\jdk1.6.0_16\\bin\\java.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Garena\\Garena.exe"= "c:\\Documents and Settings\\Administrator\\Desktop\\utorrent.exe"= "c:\\WINDOWS\\system32\\dplaysvr.exe"= "c:\\Program Files\\Tudou\\滄厒Tudou\\TudouVa.exe"= "c:\\WINDOWS\\system32\\mqsvc.exe"= "f:\\Portable_CS1.6\\Portable_CS1.6\\hl.exe"= "f:\\Portable_CS1.6\\Portable_CS1.6\\hlds.exe"= "c:\\Program Files\\BitTorrent\\bittorrent.exe"= "c:\\wamp\\bin\\apache\\Apache2.2.11\\bin\\httpd.exe"= "f:\\Counter Strike 1.6\\hl.exe"= "c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"= "f:\\Program Files\\AsiasoftSEA\\GetampedSEA\\amped_directx.exe"= "f:\\New Folder\\Age-of-Empires-II\\age2_x1.exe"= "f:\\Warrior Kings\\Warrior Kings\\warrior_kings.exe"= "c:\\WINDOWS\\system32\\dpnsvr.exe"= "c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"= "f:\\IAHGames\\Counter-Strike Online\\Bin\\cstrike-online.exe"= "f:\\IAHGames\\Counter-Strike Online\\Bin\\NMService.exe"= "f:\\IAHGames\\Counter-Strike Online\\cstrike-online.exe"= "f:\\IAHGames\\Counter-Strike Online\\NMService.exe"= "f:\\IAHGames\\Counter-Strike Online\\Bin\\CSOLauncher.exe"= "f:\\Program Files\\AsiasoftSEA\\GetampedSEA\\amped.exe"= "c:\\Program Files\\蹄6厙\\憤厒蹄6\\Ku6SpeedUpper.exe"= "c:\\Program Files\\Tudou\\·EEUTudou\\TudouVa.exe"= "c:\\Program Files\\?a6Io\\??EU?a6\\Ku6SpeedUpper.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "9949:TCP"= 9949:TCP:BitComet 9949 TCP "9949:UDP"= 9949:UDP:BitComet 9949 UDP "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724 . ‘計劃任務’ 文件夾 裡的內容 2010-12-17 c:\windows\Tasks\A5F7188291488A86.job - c:\docume~1\asthin~1.hom\applic~1\messde~1\ping bold send.exe [2009-12-04 09:09] 2010-12-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1647877149-725345543-1008Core.job - c:\documents and settings\Asthina.HOME-47627E8BE5\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-15 15:07] 2010-12-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1647877149-725345543-1008UA.job - c:\documents and settings\Asthina.HOME-47627E8BE5\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-15 15:07] . . ——- 而外的掃描 ——- . uInternet Connection Wizard,ShellNext = hxxp://advertising.marketnetwork.com/au/www/delivery/ck.php?oaparams=2__bannerid=5336__zoneid=633__cb=a04d56a5c5__maxdest=http://wixawin.com/pages/Default.aspx?lan=SG&tid=104_iqc2&affiliateid=afun uInternet Settings,ProxyOverride = local DPF: {D84EB4B0-BFA9-4B0C-B75A-17ABAD45ABB7} - hxxp://images.friendster.com/200910A-023/js/aurigma/FriendsterImageUploader.cab FF - ProfilePath - c:\documents and settings\Terence\Application Data\Mozilla\Firefox\Profiles\ypa8xrb1.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Veoh Web Player Customized Web Search FF - prefs.js: network.proxy.type - 2 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: afurladvisor: [removed] - c:\program files\Mozilla Firefox\extensions\[removed] FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} . - - - - ORPHANS REMOVED - - - - BHO-{31B27F2D-6BC6-451B-B3D2-4EAB36B2FC3B} - (no file) Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) HKLM-Run-Cmaudio - cmicnfg.cpl HKLM-Run-SearchSettings - c:\program files\Dealio Toolbar\SearchSettings.exe Notify-avgrsstarter - avgrsstx.dll AddRemove-CABAL Online (SG MY)_is1 - f:\program files\AsiasoftSEA\CABAL Online (SG MY)\unins000.exe AddRemove-Folder Password Expert 2.1_is1 - c:\documents and settings\Terence\Desktop\Folder Password Expert\unins000.exe AddRemove-Graboid Video - c:\program files\Graboid\uninst.exe AddRemove-HotspotShield - c:\program files\Hotspot Shield\Uninstall.exe AddRemove-Hoyle Casino 2010 - f:\hoyle casino 2010\Uninstall.exe AddRemove-Mafia - f:\mafia - the city of lost heaven [pc-game]\Mafia\MafiaSetup.exe AddRemove-Restaurant Empire_is1 - f:\restaurant empire\ReflexiveArcade\unins000.exe AddRemove-{3F0D0ABE-CDAF-431A-00BC-CBBE018EA74E} - f:\simcity 4 deluxe\EAUninstall.exe ************************************************************************** 掃描被隱藏的進程 … 掃描被隱藏的啟動組 … 掃描被隱藏的文件 … 掃描完成 被隱藏的檔案: ************************************************************************** . ——————— 運行進程下的動態鏈接庫 ——————— - - - - - - - > 'explorer.exe'(2372) c:\windows\system32\WININET.dll c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll c:\program files\TortoiseSVN\bin\TortoiseStub.dll c:\program files\TortoiseSVN\bin\TortoiseSVN.dll c:\program files\TortoiseSVN\bin\intl3_tsvn.dll c:\windows\system32\Ku6Kss.dll c:\windows\system32\msi.dll c:\windows\system32\ieframe.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ———————— 其他運行進程 ———————— . c:\windows\Nhksrv.exe c:\windows\system32\msdtc.exe c:\program files\AskBarDis\bar\bin\AskService.exe c:\program files\LogMeIn Hamachi\hamachi-2.exe c:\program files\Hotspot Shield\HssWPR\hsssrv.exe c:\program files\Hotspot Shield\bin\hsswd.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\windows\system32\conime.exe c:\program files\TortoiseSVN\bin\TSVNCache.exe c:\windows\system32\msiexec.exe c:\program files\Netropa\OSD.exe c:\program files\Internet Explorer\IEXPLORE.EXE c:\windows\system32\fpplock.exe c:\windows\system32\rundll32.exe . ************************************************************************** . 完成時間: 2010-12-17 21:29:00 - 電腦已重新啟動 ComboFix-quarantined-files.txt 2010-12-17 13:28 Pre-Run: 2,375,319,552 bytes free Post-Run: 4,982,775,808 bytes free - - End Of File - - 6B042779DAFB3AFD943623CE750AC60E i think it is becuz of the hotpotshield files in my computer and i can't seems to delete it no matter what. it keep on running as a process when i end it
You have a mess.
Lets start here.

OTL Fix
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    C:\Documents and Settings\Terence\Start Menu\Programs\Startup\雄滄厒芩飪.lnk
    
    :Files
    C:\windows\System32\msexcr.ini
    
    :Commands
    [EmptyFlash]
    [EmptyTemp]
    [RESETHOSTS] 
    [purity]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
uTorrent
Tudou
BitTorrent
AskBarDis
IObit


Reboot

Run a new Combofix scan
this is the log from combofix scan, oh ya can you teach me how to remove hotspotshield from my computer? i can't seem to delete the folder and its not in add/remove thing there is a process of it keep running nonstop even when i close the process it just open back up itself.

ComboFix 10-12-16.05 - Terence 7/2010 Fri 23:42:39.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.[removed].18.1022.667 [GMT 8:00]
執行位置: c:\documents and settings\Terence\Desktop\ComboFix.exe

注意 - 這台電腦沒有安裝恢復控制台 !!
.

((((((((((((((((((((((((( 2010-11-17 至 2010-12-17 的新的檔案 )))))))))))))))))))))))))))))))
.

2010-12-17 14:07 . 2010-12-17 14:07 ——– dc—-w- C:\_OTL
2010-12-15 06:47 . 2010-12-15 06:47 ——– d—–w- c:\documents and settings\All Users\Application Data\hssff
2010-12-13 04:28 . 2010-12-13 04:28 ——– dc—-w- C:\Hotspot Shield
2010-12-13 04:28 . 2010-11-04 18:43 506880 —-a-w- c:\program files\Mozilla Firefox\extensions\[removed]\components\afurladvisor.dll
2010-12-13 04:28 . 2010-12-16 21:12 ——– d—–w- c:\program files\Hotspot Shield
2010-12-08 21:29 . 2010-12-08 21:29 ——– dc—-w- c:\documents and settings\Terence\Application Data\MSN6
2010-11-30 21:12 . 2010-12-17 15:11 ——– dc—-w- c:\documents and settings\Terence\Local Settings\Application Data\Conduit
2010-11-30 21:12 . 2010-11-30 21:12 ——– dc—-w- c:\documents and settings\Terence\Local Settings\Application Data\Temp
2010-11-25 12:29 . 2010-11-25 12:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Nexon
2010-11-25 12:27 . 2010-12-16 20:17 ——– dc—-w- c:\documents and settings\Terence\Local Settings\Application Data\CSO

.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-29 09:42 . 2010-04-02 14:38 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-29 09:42 . 2010-04-02 14:38 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-09-25 16:57 . 2010-09-25 16:58 794906 —-a-w- c:\windows\unins000.exe
2010-09-22 19:19 . 2010-09-22 19:19 37376 —-a-w- c:\windows\system32\drivers\HssDrv.sys
2010-09-22 19:19 . 2010-09-22 19:19 32768 —-a-w- c:\windows\system32\drivers\taphss.sys
2009-12-04 16:54 . 2009-12-04 16:53 10783584 -c–a-w- c:\program files\Install_MSN_Messenger.exe
2009-12-04 16:42 . 2009-12-04 16:42 20549448 -c–a-w- c:\program files\msnsetup_full.exe
2004-07-08 20:08 . 2004-07-08 20:08 472576 —-a-w- c:\program files\dxsetup.exe
2004-07-08 20:08 . 2004-07-08 20:08 2242560 -c–a-w- c:\program files\dsetup32.dll
2004-07-08 19:03 . 2004-07-08 19:03 62976 —-a-w- c:\program files\DSETUP.dll
2010-06-11 18:05 . 2009-12-10 16:39 253952 —-a-w- c:\program files\mozilla firefox\components\CheckTudouVa.dll
2003-12-06 14:12 121856 –sha-w- c:\windows\system32\fpplock.exe
.

((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-24 12:25 333192 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-24 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-24 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2010-07-06 2634048]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-02-08 2343632]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"DellTouch"="c:\windows\MMKeybd.exe" [2002-01-16 163840]
"AudioDeck"="c:\program files\VIAudioi\SBADeck\ADeck.exe" [2005-12-12 454656]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"Google Pinyin 2 Autoupdater"="c:\program files\Google\Google Pinyin 2\GooglePinyinDaemon.exe" [2009-09-13 1119728]
"bat remote exit list"="c:\documents and settings\All Users\Application Data\mapi nurb bat remote\each coal.exe" [2010-12-17 761856]
"MsmqIntCert"="mqrt.dll" [2009-06-25 177152]
"Warning: do not remove it!"="fpplock.exe" [2003-12-06 121856]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-08-20 1164584]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\documents and settings\Terence\Start Menu\Programs\Startup\
ViiKiiDesktopPlugin.lnk - [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_16\\bin\\java.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Documents and Settings\\Administrator\\Desktop\\utorrent.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Tudou\\滄厒Tudou\\TudouVa.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"f:\\Portable_CS1.6\\Portable_CS1.6\\hl.exe"=
"f:\\Portable_CS1.6\\Portable_CS1.6\\hlds.exe"=
"c:\\wamp\\bin\\apache\\Apache2.2.11\\bin\\httpd.exe"=
"f:\\Counter Strike 1.6\\hl.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"f:\\Program Files\\AsiasoftSEA\\GetampedSEA\\amped_directx.exe"=
"f:\\New Folder\\Age-of-Empires-II\\age2_x1.exe"=
"f:\\Warrior Kings\\Warrior Kings\\warrior_kings.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"f:\\IAHGames\\Counter-Strike Online\\Bin\\cstrike-online.exe"=
"f:\\IAHGames\\Counter-Strike Online\\Bin\\NMService.exe"=
"f:\\IAHGames\\Counter-Strike Online\\cstrike-online.exe"=
"f:\\IAHGames\\Counter-Strike Online\\NMService.exe"=
"f:\\IAHGames\\Counter-Strike Online\\Bin\\CSOLauncher.exe"=
"f:\\Program Files\\AsiasoftSEA\\GetampedSEA\\amped.exe"=
"c:\\Program Files\\蹄6厙\\憤厒蹄6\\Ku6SpeedUpper.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9949:TCP"= 9949:TCP:BitComet 9949 TCP
"9949:UDP"= 9949:UDP:BitComet 9949 UDP
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10/16/2009 1:05 PM 691696]
R2 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [5/23/2009 2:29 PM 464264]
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS –> c:\program files\Hotspot Shield\bin\hsswd.exe -product HSS [?]
R2 Nhksrv;Netropa NHK Server;c:\windows\Nhksrv.exe [9/11/2008 8:37 PM 28672]
R3 Msikbd2k;DellTouch;c:\windows\system32\drivers\Msikbd2k.sys [9/11/2008 8:37 PM 6656]
S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [5/23/2009 2:29 PM 234888]
S2 gupdate1c9e2c0a93c19ba;Google Update Service (gupdate1c9e2c0a93c19ba);"c:\program files\Google\Update\GoogleUpdate.exe" /svc –> c:\program files\Google\Update\GoogleUpdate.exe [?]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Terence\LOCALS~1\Temp\GCLAD.tmp –> c:\docume~1\Terence\LOCALS~1\Temp\GCLAD.tmp [?]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [12/25/2009 3:36 PM 102656]
S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [4/22/2009 4:24 PM 133632]
S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [4/22/2009 4:24 PM 79360]
S3 MSJDrvr;MSJDrvr;\??\c:\documents and settings\Terence\Desktop\NMbot 2nd Edition\NMbot 2nd Edition\MSJDrvr.sys –> c:\documents and settings\Terence\Desktop\NMbot 2nd Edition\NMbot 2nd Edition\MSJDrvr.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [10/23/2009 12:32 PM 223128]
S3 XDva208;XDva208;\??\c:\windows\system32\XDva208.sys –> c:\windows\system32\XDva208.sys [?]
S3 XDva215;XDva215;\??\c:\windows\system32\XDva215.sys –> c:\windows\system32\XDva215.sys [?]
S3 XDva219;XDva219;\??\c:\windows\system32\XDva219.sys –> c:\windows\system32\XDva219.sys [?]
S3 XDva285;XDva285;\??\c:\windows\system32\XDva285.sys –> c:\windows\system32\XDva285.sys [?]
.
‘計劃任務’ 文件夾 裡的內容

2010-12-17 c:\windows\Tasks\A5F7188291488A86.job
- c:\docume~1\asthin~1.hom\applic~1\messde~1\ping bold send.exe [2009-12-04 09:09]

2010-12-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1647877149-725345543-1008Core.job
- c:\documents and settings\Asthina.HOME-47627E8BE5\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-15 15:07]

2010-12-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1647877149-725345543-1008UA.job
- c:\documents and settings\Asthina.HOME-47627E8BE5\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-15 15:07]
.
.
——- 而外的掃描 ——-
.
uInternet Connection Wizard,ShellNext = hxxp://advertising.marketnetwork.com/au/www/delivery/ck.php?oaparams=2__bannerid=5336__zoneid=633__cb=a04d56a5c5__maxdest=http://wixawin.com/pages/Default.aspx?lan=SG&tid=104_iqc2&affiliateid=afun
uInternet Settings,ProxyOverride = local
DPF: {D84EB4B0-BFA9-4B0C-B75A-17ABAD45ABB7} - hxxp://images.friendster.com/200910A-023/js/aurigma/FriendsterImageUploader.cab
FF - ProfilePath - c:\documents and settings\Terence\Application Data\Mozilla\Firefox\Profiles\ypa8xrb1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Veoh Web Player Customized Web Search
FF - prefs.js: network.proxy.type - 2
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: afurladvisor: [removed] - c:\program files\Mozilla Firefox\extensions\[removed]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-极速酷6 - c:\program files\蹄6厙\憤厒蹄6\Ku6SpeedUpper.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-17 23:50
Windows 5.1.2600 Service Pack 2 NTFS

掃描被隱藏的進程 …

掃描被隱藏的啟動組 …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AudioDeck = c:\program files\VIAudioi\SBADeck\ADeck.exe 1?$??????i?|????$i?|????` $??????????????????

掃描被隱藏的文件 …

掃描完成
被隱藏的檔案: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\Terence\LOCALS~1\Temp\GCLAD.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-682003330-1647877149-725345543-1009\Software\SecuROM\License information*]
"datasecu"=hex:31,5a,59,99,84,2e,bf,f3,7a,10,b8,b9,e0,e0,64,9f,a1,14,dc,96,9e,
06,82,b9,be,b1,00,30,5c,88,a1,ce,ee,d7,e8,d2,79,b5,37,de,f1,86,81,10,4e,9b,\
"rkeysecu"=hex:e6,0b,cf,9d,d3,83,e9,01,cc,63,28,ed,52,3a,aa,95
.
——————— 運行進程下的動態鏈接庫 ———————

- - - - - - - > 'explorer.exe'(3400)
c:\windows\system32\WININET.dll
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
完成時間: 2010-12-17 23:54:07
ComboFix-quarantined-files.txt 2010-12-17 15:53

Pre-Run: 6,707,400,704 bytes free
Post-Run: 6,712,524,800 bytes free

- - End Of File - - 56FFA92321A7C90BACD773EFD4ACBE2A
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

KillAll::

File::
c:\documents and settings\All Users\Application Data\mapi nurb bat remote\each coal.exe
c:\documents and settings\Terence\Start Menu\Programs\Startup\ViiKiiDesktopPlugin.lnk 
c:\Documents and Settings\Administrator\Desktop\utorrent.exe

Folder::
C:\Hotspot Shield
c:\program files\Hotspot Shield
c:\program files\AskBarDis
c:\program files\IObit
c:\Program Files\Tudou

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9949:TCP"=- 
"9949:UDP"=- 
"3724:TCP"=-

DDS::
uInternet Connection Wizard,ShellNext = hxxp://advertising.marketnetwork.com/au/www/delivery/ck.php
oaparams=2__bannerid=5336__zoneid=633__cb=a04d56a5c5__maxdest=http://wixawin.com/pages/Default.aspx

FireFox::
Ext: afurladvisor: [removed]
prefs.js: network.proxy.type - 2

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
the redirection thing have seems to stop. but it was like that b4 if its still there tmr i'll post a reply here and this is the log of combofix.

ComboFix 10-12-16.05 - Terence 8/2010 Sat 0:48.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.[removed].18.1022.675 [GMT 8:00]
執行位置: c:\documents and settings\Terence\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Terence\Desktop\CFScript.txt

注意 - 這台電腦沒有安裝恢復控制台 !!

FILE ::
"c:\documents and settings\Administrator\Desktop\utorrent.exe"
"c:\documents and settings\All Users\Application Data\mapi nurb bat remote\each coal.exe"
"c:\documents and settings\Terence\Start Menu\Programs\Startup\ViiKiiDesktopPlugin.lnk"
.

((((((((((((((((((((((((((((((((((((((( 被刪除的檔案 )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Desktop\utorrent.exe
c:\documents and settings\All Users\Application Data\mapi nurb bat remote\each coal.exe
c:\documents and settings\Terence\Start Menu\Programs\Startup\ViiKiiDesktopPlugin.lnk
C:\Hotspot Shield
c:\program files\AskBarDis
c:\program files\AskBarDis\bar\bin\askBar.dll
c:\program files\AskBarDis\bar\bin\askPopStp.dll
c:\program files\AskBarDis\bar\bin\AskService.exe
c:\program files\AskBarDis\bar\bin\AskSplash.exe
c:\program files\AskBarDis\bar\bin\AskTBApp.exe
c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe
c:\program files\AskBarDis\bar\bin\psvince.dll
c:\program files\AskBarDis\bar\Cache\000949FD.bin
c:\program files\AskBarDis\bar\Cache\00094EB0.bin
c:\program files\AskBarDis\bar\Cache\00095671.bin
c:\program files\AskBarDis\bar\Cache\000964F7.bin
c:\program files\AskBarDis\bar\Cache\000966AD.bin
c:\program files\AskBarDis\bar\Cache\000969E9.bin
c:\program files\AskBarDis\bar\Cache\00096DD1.bin
c:\program files\AskBarDis\bar\Cache\00B9C4A4
c:\program files\AskBarDis\bar\Cache\00B9C88C
c:\program files\AskBarDis\bar\Cache\014406FD
c:\program files\AskBarDis\bar\Cache\files.ini
c:\program files\AskBarDis\bar\History\search
c:\program files\AskBarDis\bar\Settings\AskLogo.ico
c:\program files\AskBarDis\bar\Settings\config.dat
c:\program files\AskBarDis\bar\Settings\config.dat.bak
c:\program files\AskBarDis\bar\Settings\prevcfg.htm
c:\program files\AskBarDis\unins000.dat
c:\program files\AskBarDis\unins000.exe
c:\program files\Hotspot Shield
c:\program files\Hotspot Shield\bin\curl-ca-bundle.crt
c:\program files\Hotspot Shield\bin\ffinst.exe
c:\program files\Hotspot Shield\bin\hssinst.dll
c:\program files\Hotspot Shield\bin\HssInstaller.exe
c:\program files\Hotspot Shield\bin\hsswd.exe
c:\program files\Hotspot Shield\bin\lang\gui-ara.dll
c:\program files\Hotspot Shield\bin\lang\gui-bur.dll
c:\program files\Hotspot Shield\bin\lang\gui-chi.dll
c:\program files\Hotspot Shield\bin\lang\gui-eng.dll
c:\program files\Hotspot Shield\bin\lang\gui-fre.dll
c:\program files\Hotspot Shield\bin\lang\gui-ger.dll
c:\program files\Hotspot Shield\bin\lang\gui-per.dll
c:\program files\Hotspot Shield\bin\lang\gui-rus.dll
c:\program files\Hotspot Shield\bin\lang\gui-spa.dll
c:\program files\Hotspot Shield\bin\lang\gui-vie.dll
c:\program files\Hotspot Shield\bin\libcurl.dll
c:\program files\Hotspot Shield\bin\libeay32.dll
c:\program files\Hotspot Shield\bin\libidn-11.dll
c:\program files\Hotspot Shield\bin\libpkcs11-helper-1.dll
c:\program files\Hotspot Shield\bin\libssl32.dll
c:\program files\Hotspot Shield\bin\openvpn.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Hotspot Shield\bin\openvpntray.exe
c:\program files\Hotspot Shield\bin\reginstall.exe
c:\program files\Hotspot Shield\bin\tapinstall.exe
c:\program files\Hotspot Shield\config\config.hvpn
c:\program files\Hotspot Shield\config\sd-info-direct.cfg
c:\program files\Hotspot Shield\config\sd-info-main.cfg
c:\program files\Hotspot Shield\driver\OemWin2k.inf
c:\program files\Hotspot Shield\driver\taphss.cat
c:\program files\Hotspot Shield\driver\taphss.sys
c:\program files\Hotspot Shield\hss.ico
c:\program files\Hotspot Shield\HssFF\config_ff.txt
c:\program files\Hotspot Shield\HssFF\config_ff_srch.txt
c:\program files\Hotspot Shield\HssIE\config.txt
c:\program files\Hotspot Shield\HssIE\config_srch.txt
c:\program files\Hotspot Shield\HssIE\HssIE.dll
c:\program files\Hotspot Shield\hsswd\default\default.cfg
c:\program files\Hotspot Shield\HssWPR\hssdrv.cat
c:\program files\Hotspot Shield\HssWPR\hssdrv.sys
c:\program files\Hotspot Shield\HssWPR\hssdrv_m.cat
c:\program files\Hotspot Shield\HssWPR\hssinst.dll
c:\program files\Hotspot Shield\HssWPR\HssInstaller.exe
c:\program files\Hotspot Shield\HssWPR\hsssrv.exe
c:\program files\Hotspot Shield\HssWPR\nethss.inf
c:\program files\Hotspot Shield\HssWPR\nethss_m.inf
c:\program files\Hotspot Shield\HssWPR\wpr.conf
c:\program files\Hotspot Shield\htdocs\check.js
c:\program files\Hotspot Shield\htdocs\conect.png
c:\program files\Hotspot Shield\htdocs\connect_original.png
c:\program files\Hotspot Shield\htdocs\connect_stay.png
c:\program files\Hotspot Shield\htdocs\disconnect.html
c:\program files\Hotspot Shield\htdocs\disconnect_original.png
c:\program files\Hotspot Shield\htdocs\greenico.png
c:\program files\Hotspot Shield\htdocs\HSS_logo.png
c:\program files\Hotspot Shield\htdocs\lang.js
c:\program files\Hotspot Shield\htdocs\logo.png
c:\program files\Hotspot Shield\htdocs\message.html
c:\program files\Hotspot Shield\htdocs\nsidefs.js
c:\program files\Hotspot Shield\htdocs\oac.html
c:\program files\Hotspot Shield\htdocs\oac.js
c:\program files\Hotspot Shield\htdocs\redico.png
c:\program files\Hotspot Shield\htdocs\restart.html
c:\program files\Hotspot Shield\htdocs\Thumbs.db
c:\program files\Hotspot Shield\htdocs\turnoff.png
c:\program files\Hotspot Shield\htdocs\turnon.png
c:\program files\Hotspot Shield\Thumbs.db
c:\program files\IObit
c:\program files\IObit\Advanced SystemCare 3\AutoCare.exe
c:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe
c:\program files\IObit\Advanced SystemCare 3\AWC.exe
c:\program files\IObit\Advanced SystemCare 3\AWCInit.exe
c:\program files\IObit\Advanced SystemCare 3\AwcSchedule.dll
c:\program files\IObit\Advanced SystemCare 3\ContextMenu.exe
c:\program files\IObit\Advanced SystemCare 3\CookiesBK.pln
c:\program files\IObit\Advanced SystemCare 3\CoolTrayIcon_D6plus.bpl
c:\program files\IObit\Advanced SystemCare 3\Def.dbd
c:\program files\IObit\Advanced SystemCare 3\ESR.exe
c:\program files\IObit\Advanced SystemCare 3\EULA.rtf
c:\program files\IObit\Advanced SystemCare 3\FFSweep.dll
c:\program files\IObit\Advanced SystemCare 3\FileSweep.dll
c:\program files\IObit\Advanced SystemCare 3\Help.html
c:\program files\IObit\Advanced SystemCare 3\IEFavBK.pln
c:\program files\IObit\Advanced SystemCare 3\Images\care.png
c:\program files\IObit\Advanced SystemCare 3\Images\ds.png
c:\program files\IObit\Advanced SystemCare 3\Images\home.png
c:\program files\IObit\Advanced SystemCare 3\Images\mw.png
c:\program files\IObit\Advanced SystemCare 3\Images\tips.jpg
c:\program files\IObit\Advanced SystemCare 3\Images\tips2.jpg
c:\program files\IObit\Advanced SystemCare 3\Images\ut.png
c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe
c:\program files\IObit\Advanced SystemCare 3\Language\Albanian.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Brasil.lng
c:\program files\IObit\Advanced SystemCare 3\Language\ChineseSimp.lng
c:\program files\IObit\Advanced SystemCare 3\Language\ChineseTrad.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Czech.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Dansk.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Dutch.lng
c:\program files\IObit\Advanced SystemCare 3\Language\English.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Finnish.lng
c:\program files\IObit\Advanced SystemCare 3\Language\French.lng
c:\program files\IObit\Advanced SystemCare 3\Language\German.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Hebrew.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Hungarian.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Italiano.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Japanese.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Korean.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Persian.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Polish.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Romanian.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Russian.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Spanish.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Srpski.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Svenska.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Swedish.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Turkish.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Ukrainian.lng
c:\program files\IObit\Advanced SystemCare 3\Language\Valencian.lng
c:\program files\IObit\Advanced SystemCare 3\License.dat
c:\program files\IObit\Advanced SystemCare 3\News\bnews.html
c:\program files\IObit\Advanced SystemCare 3\News\Css\bstyle.css
c:\program files\IObit\Advanced SystemCare 3\News\Css\wstyle.css
c:\program files\IObit\Advanced SystemCare 3\News\wnews.html
c:\program files\IObit\Advanced SystemCare 3\NtfsData.dll
c:\program files\IObit\Advanced SystemCare 3\RegeditBK.pln
c:\program files\IObit\Advanced SystemCare 3\Registration.exe
c:\program files\IObit\Advanced SystemCare 3\Routine.dll
c:\program files\IObit\Advanced SystemCare 3\rtl70.bpl
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_01.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_01_mouseover.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_02.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_02_mouseover.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_03.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_03_mouseover.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_04.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\4C_Btn_04_mouseover.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\4C_Button_bg_down.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\4C_Button_bg_left.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\4C_Button_bg_right.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\4C_Button_bg_up.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Bg_Content.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\BG_Main.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Care_Button_1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Care_Button_2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Care_Button_3.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Care_Button_en_1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Care_Button_en_2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Care_Button_en_3.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Check.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Checked.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Close1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Close2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Content_bg_1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Content_bg_2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Content_bg_3.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Flag.ico
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Layout.ini
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Min1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Min2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\scan.avi
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Shadow.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Tab_Bottom.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Tab_Selected_1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Tab_Selected_2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Tab_Selected_3.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Tab_UnSelected_1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Tab_UnSelected_2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Tab_UnSelected_3.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Title.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\UnCheck.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Unchecked.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Upgrade1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\Black\Upgrade2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_01.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_01_mouseover.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_02.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_02_mouseover.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_03.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_03_mouseover.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_04.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\4C_Btn_04_mouseover.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\4C_Button_bg_down.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\4C_Button_bg_left.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\4C_Button_bg_right.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\4C_Button_bg_up.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Bg_Content.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\BG_Main.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Care_Button_1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Care_Button_2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Care_Button_3.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Care_Button_en_1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Care_Button_en_2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Care_Button_en_3.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Check.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Checked.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Close1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Close2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Content_bg_1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Content_bg_2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Content_bg_3.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Flag.ico
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Layout.ini
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Min1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Min2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\scan.avi
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Shadow.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Tab_Bottom.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Tab_BottomLine.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Tab_Selected_1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Tab_Selected_2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Tab_Selected_3.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Tab_UnSelected_1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Tab_UnSelected_2.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Tab_UnSelected_3.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Title.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\UnCheck.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Unchecked.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Upgrade1.png
c:\program files\IObit\Advanced SystemCare 3\Skin\White\Upgrade2.png
c:\program files\IObit\Advanced SystemCare 3\sqlite3.dll
c:\program files\IObit\Advanced SystemCare 3\STFix.dll
c:\program files\IObit\Advanced SystemCare 3\Sup_DiskChk.exe
c:\program files\IObit\Advanced SystemCare 3\Sup_DiskCleaner.exe
c:\program files\IObit\Advanced SystemCare 3\Sup_GameBooster.exe
c:\program files\IObit\Advanced SystemCare 3\Sup_InternetBooster.exe
c:\program files\IObit\Advanced SystemCare 3\Sup_IS360.exe
c:\program files\IObit\Advanced SystemCare 3\Sup_ISD.exe
c:\program files\IObit\Advanced SystemCare 3\Sup_RegistryDefrag.exe
c:\program files\IObit\Advanced SystemCare 3\Sup_ShortcutsFixer.exe
c:\program files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe
c:\program files\IObit\Advanced SystemCare 3\Sus_DriverBackUp.exe
c:\program files\IObit\Advanced SystemCare 3\Sus_PIeHelp.exe
c:\program files\IObit\Advanced SystemCare 3\Sus_SystemBackup.exe
c:\program files\IObit\Advanced SystemCare 3\Sus_SystemFileScan.exe
c:\program files\IObit\Advanced SystemCare 3\Sut_AutoShutDown.exe
c:\program files\IObit\Advanced SystemCare 3\Sut_ClonedFilesFinder.exe
c:\program files\IObit\Advanced SystemCare 3\Sut_ContextManager.exe
c:\program files\IObit\Advanced SystemCare 3\Sut_DiskExplorer.exe
c:\program files\IObit\Advanced SystemCare 3\Sut_RestoreCenter.exe
c:\program files\IObit\Advanced SystemCare 3\Sut_SoftUninstaller.exe
c:\program files\IObit\Advanced SystemCare 3\Sut_StartUpManager.exe
c:\program files\IObit\Advanced SystemCare 3\Sut_SysInfo.exe
c:\program files\IObit\Advanced SystemCare 3\Sut_WinManager.exe
c:\program files\IObit\Advanced SystemCare 3\TurboBoost.exe
c:\program files\IObit\Advanced SystemCare 3\unins000.dat
c:\program files\IObit\Advanced SystemCare 3\unins000.exe
c:\program files\IObit\Advanced SystemCare 3\unins000.msg
c:\program files\IObit\Advanced SystemCare 3\Update History.txt
c:\program files\IObit\Advanced SystemCare 3\Update\awc3check.upt
c:\program files\IObit\Advanced SystemCare 3\vcl70.bpl
c:\program files\IObit\Advanced SystemCare 3\vclx70.bpl
c:\program files\IObit\Advanced SystemCare 3\winSkinD7R.bpl
c:\program files\IObit\Advanced SystemCare 3\Wizard.exe
c:\program files\Tudou

.
((((((((((((((((((((((((((((((((((((((( 驅動/服務 )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ASKService
——-\Legacy_ASKUpgrade
——-\Legacy_HssSrv
——-\Legacy_HssWd
——-\Legacy_ASKService
——-\Legacy_ASKUpgrade
——-\Legacy_HssSrv
——-\Legacy_HssWd
——-\Service_ASKService
——-\Service_ASKUpgrade
——-\Service_HssSrv
——-\Service_HssWd
——-\Service_ASKService
——-\Service_ASKUpgrade
——-\Service_HssSrv
——-\Service_HssWd


((((((((((((((((((((((((( 2010-11-17 至 2010-12-17 的新的檔案 )))))))))))))))))))))))))))))))
.

2010-12-15 06:47 . 2010-12-15 06:47 ——– d—–w- c:\documents and settings\All Users\Application Data\hssff
2010-12-13 04:28 . 2010-11-04 18:43 506880 —-a-w- c:\program files\Mozilla Firefox\extensions\[removed]\components\afurladvisor.dll
2010-12-08 21:29 . 2010-12-08 21:29 ——– dc—-w- c:\documents and settings\Terence\Application Data\MSN6
2010-11-30 21:12 . 2010-12-17 15:11 ——– dc—-w- c:\documents and settings\Terence\Local Settings\Application Data\Conduit
2010-11-30 21:12 . 2010-11-30 21:12 ——– dc—-w- c:\documents and settings\Terence\Local Settings\Application Data\Temp
2010-11-25 12:29 . 2010-11-25 12:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Nexon
2010-11-25 12:27 . 2010-12-16 20:17 ——– dc—-w- c:\documents and settings\Terence\Local Settings\Application Data\CSO

.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-29 09:42 . 2010-04-02 14:38 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-11-29 09:42 . 2010-04-02 14:38 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-09-25 16:57 . 2010-09-25 16:58 794906 —-a-w- c:\windows\unins000.exe
2010-09-22 19:19 . 2010-09-22 19:19 37376 —-a-w- c:\windows\system32\drivers\HssDrv.sys
2010-09-22 19:19 . 2010-09-22 19:19 32768 —-a-w- c:\windows\system32\drivers\taphss.sys
2009-12-04 16:54 . 2009-12-04 16:53 10783584 -c–a-w- c:\program files\Install_MSN_Messenger.exe
2009-12-04 16:42 . 2009-12-04 16:42 20549448 -c–a-w- c:\program files\msnsetup_full.exe
2004-07-08 20:08 . 2004-07-08 20:08 472576 —-a-w- c:\program files\dxsetup.exe
2004-07-08 20:08 . 2004-07-08 20:08 2242560 -c–a-w- c:\program files\dsetup32.dll
2004-07-08 19:03 . 2004-07-08 19:03 62976 —-a-w- c:\program files\DSETUP.dll
2010-06-11 18:05 . 2009-12-10 16:39 253952 —-a-w- c:\program files\mozilla firefox\components\CheckTudouVa.dll
2003-12-06 14:12 121856 –sha-w- c:\windows\system32\fpplock.exe
.

((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2010-01-18 11:12 86280 —-a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2010-07-06 2634048]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"DellTouch"="c:\windows\MMKeybd.exe" [2002-01-16 163840]
"AudioDeck"="c:\program files\VIAudioi\SBADeck\ADeck.exe" [2005-12-12 454656]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"Google Pinyin 2 Autoupdater"="c:\program files\Google\Google Pinyin 2\GooglePinyinDaemon.exe" [2009-09-13 1119728]
"MsmqIntCert"="mqrt.dll" [2009-06-25 177152]
"极速酷6"="c:\program files\蹄6厙\憤厒蹄6\Ku6SpeedUpper.exe" [BU]
"Warning: do not remove it!"="fpplock.exe" [2003-12-06 121856]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-08-20 1164584]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Java\\jdk1.6.0_16\\bin\\java.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Tudou\\滄厒Tudou\\TudouVa.exe"=
"c:\\WINDOWS\\system32\\mqsvc.exe"=
"f:\\Portable_CS1.6\\Portable_CS1.6\\hl.exe"=
"f:\\Portable_CS1.6\\Portable_CS1.6\\hlds.exe"=
"c:\\wamp\\bin\\apache\\Apache2.2.11\\bin\\httpd.exe"=
"f:\\Counter Strike 1.6\\hl.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"f:\\Program Files\\AsiasoftSEA\\GetampedSEA\\amped_directx.exe"=
"f:\\New Folder\\Age-of-Empires-II\\age2_x1.exe"=
"f:\\Warrior Kings\\Warrior Kings\\warrior_kings.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"f:\\IAHGames\\Counter-Strike Online\\Bin\\cstrike-online.exe"=
"f:\\IAHGames\\Counter-Strike Online\\Bin\\NMService.exe"=
"f:\\IAHGames\\Counter-Strike Online\\cstrike-online.exe"=
"f:\\IAHGames\\Counter-Strike Online\\NMService.exe"=
"f:\\IAHGames\\Counter-Strike Online\\Bin\\CSOLauncher.exe"=
"f:\\Program Files\\AsiasoftSEA\\GetampedSEA\\amped.exe"=
"c:\\Program Files\\蹄6厙\\憤厒蹄6\\Ku6SpeedUpper.exe"=

R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [10/16/2009 1:05 PM 691696]
R2 Nhksrv;Netropa NHK Server;c:\windows\Nhksrv.exe [9/11/2008 8:37 PM 28672]
R3 Msikbd2k;DellTouch;c:\windows\system32\drivers\Msikbd2k.sys [9/11/2008 8:37 PM 6656]
S2 gupdate1c9e2c0a93c19ba;Google Update Service (gupdate1c9e2c0a93c19ba);"c:\program files\Google\Update\GoogleUpdate.exe" /svc –> c:\program files\Google\Update\GoogleUpdate.exe [?]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Terence\LOCALS~1\Temp\GCLAD.tmp –> c:\docume~1\Terence\LOCALS~1\Temp\GCLAD.tmp [?]
S3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\drivers\ewusbfake.sys [12/25/2009 3:36 PM 102656]
S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [4/22/2009 4:24 PM 133632]
S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [4/22/2009 4:24 PM 79360]
S3 MSJDrvr;MSJDrvr;\??\c:\documents and settings\Terence\Desktop\NMbot 2nd Edition\NMbot 2nd Edition\MSJDrvr.sys –> c:\documents and settings\Terence\Desktop\NMbot 2nd Edition\NMbot 2nd Edition\MSJDrvr.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [10/23/2009 12:32 PM 223128]
S3 XDva208;XDva208;\??\c:\windows\system32\XDva208.sys –> c:\windows\system32\XDva208.sys [?]
S3 XDva215;XDva215;\??\c:\windows\system32\XDva215.sys –> c:\windows\system32\XDva215.sys [?]
S3 XDva219;XDva219;\??\c:\windows\system32\XDva219.sys –> c:\windows\system32\XDva219.sys [?]
S3 XDva285;XDva285;\??\c:\windows\system32\XDva285.sys –> c:\windows\system32\XDva285.sys [?]
.
‘計劃任務’ 文件夾 裡的內容

2010-12-17 c:\windows\Tasks\A5F7188291488A86.job
- c:\docume~1\asthin~1.hom\applic~1\messde~1\ping bold send.exe [2009-12-04 09:09]

2010-12-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1647877149-725345543-1008Core.job
- c:\documents and settings\Asthina.HOME-47627E8BE5\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-15 15:07]

2010-12-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1647877149-725345543-1008UA.job
- c:\documents and settings\Asthina.HOME-47627E8BE5\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-15 15:07]
.
.
——- 而外的掃描 ——-
.
uInternet Settings,ProxyOverride = local
DPF: {D84EB4B0-BFA9-4B0C-B75A-17ABAD45ABB7} - hxxp://images.friendster.com/200910A-023/js/aurigma/FriendsterImageUploader.cab
FF - ProfilePath - c:\documents and settings\Terence\Application Data\Mozilla\Firefox\Profiles\ypa8xrb1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2653012&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Veoh Web Player Customized Web Search
FF - prefs.js: network.proxy.type - 2
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: afurladvisor: [removed] - c:\program files\Mozilla Firefox\extensions\[removed]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
.
- - - - ORPHANS REMOVED - - - -

BHO-{201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\AskBarDis\bar\bin\askBar.dll
Toolbar-{3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\AskBarDis\bar\bin\askBar.dll
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - c:\program files\AskBarDis\bar\bin\askBar.dll
HKCU-Run-Advanced SystemCare 3 - c:\program files\IObit\Advanced SystemCare 3\AWC.exe
HKLM-Run-bat remote exit list - c:\documents and settings\All Users\Application Data\mapi nurb bat remote\each coal.exe
AddRemove-Advanced SystemCare 3_is1 - c:\program files\IObit\Advanced SystemCare 3\unins000.exe
AddRemove-Ask Toolbar_is1 - c:\program files\AskBarDis\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-18 01:01
Windows 5.1.2600 Service Pack 2 NTFS

掃描被隱藏的進程 …

掃描被隱藏的啟動組 …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AudioDeck = c:\program files\VIAudioi\SBADeck\ADeck.exe 1?$??????i?|????$i?|????` $??????????????????

掃描被隱藏的文件 …

掃描完成
被隱藏的檔案: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\Terence\LOCALS~1\Temp\GCLAD.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-682003330-1647877149-725345543-1009\Software\SecuROM\License information*]
"datasecu"=hex:31,5a,59,99,84,2e,bf,f3,7a,10,b8,b9,e0,e0,64,9f,a1,14,dc,96,9e,
06,82,b9,be,b1,00,30,5c,88,a1,ce,ee,d7,e8,d2,79,b5,37,de,f1,86,81,10,4e,9b,\
"rkeysecu"=hex:e6,0b,cf,9d,d3,83,e9,01,cc,63,28,ed,52,3a,aa,95
.
——————— 運行進程下的動態鏈接庫 ———————

- - - - - - - > 'explorer.exe'(2224)
c:\windows\system32\WININET.dll
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— 其他運行進程 ————————
.
c:\windows\system32\msdtc.exe
c:\windows\system32\conime.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\windows\system32\fpplock.exe
c:\windows\system32\msiexec.exe
c:\program files\Netropa\OSD.exe
c:\windows\system32\MsiExec.exe
.
**************************************************************************
.
完成時間: 2010-12-18 01:07:54 - 電腦已重新啟動
ComboFix-quarantined-files.txt 2010-12-17 17:07
ComboFix2.txt 2010-12-17 15:54

Pre-Run: 6,661,054,464 bytes free
Post-Run: 6,660,005,888 bytes free

- - End Of File - - 7168BF3F62B5BEEA3EE7B92A16B42DA2
Be sure to do this before leaving your topic…

Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

For XP:
  • Click START run
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.

For Vista / Windows 7
  • Click START Search
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.


Here's my usual all clean post

To be on the safe side, I would also change all my passwords.

This infection appears to have been cleaned, but as the malware could be configured to run any program a remote attacker requires, it's impossible to be 100% sure that any machine is clean.


Log looks good :D


  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.


  • WOT , Web of Trust, As 'Googling' is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    Green to go
    Yellow for caution
    Red to stop
    WOT has an addon available for both Firefox and IE.



  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

Only run one Anti-Virus and Firewall program.


I would suggest you read:
PC Safety and Security–What Do I Need?.
How to Prevent Malware:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI