Hi. I'm trying to show my hijackthis file but when I go to save log file it just shuts down the program. Is it getting saved to somewhere else? Thank you.
Click start then search type in hijackthis that should give you the location if the text doc.
Thank you for your help. It says it's a "PF" file and it won't let me open it for some reason. Do you know any way around that? Thanks
When the program launches, hit the "Scan and save log" button
Press that, do not close the file.
Go to Edit > Select all, then to Edit > copy.
Now you've copied the entire text to the Windows Clipboard
Open this thread and click "Add Reply".
In an empty area click your RIGHT mouse button, and choose 'Paste' from the context menu.
There's your Hijack This log.
There isn't a "Scan and save log" button. There is just a button that says "Scan" and then after it scans that button turns into "save log". When I press that, the application just closes. Also, there isn't an "edit" tab. Maybe I downloaded a bogus version? Thank you.
Sounds like you are using an older version.
Download this version.
http://security-central.us/downloads/HJTsetup.exe
Excellent! Sorry for being a pain. I have used AVG, Spybot and Adaware and they all find problems, fix them and then when I restart the computer, the viruses and stuff are still there. Also, my IE got hijacked but I got Firefox and it seems much better. Here is my log. Thank you again.
Logfile of HijackThis v1.99.1
Scan saved at 下午 11:31:32, on 2007/2/14
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATK0100\Hcontrol.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Progra~1\ASUS\Power4 Gear\BatteryLife.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe
C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe
C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe
C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\System\Updaterun.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
c:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
C:\program files\internet explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Hijackthis\HijackThis.exe
O3 - Toolbar: 收音機(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Dr.eye WebPage Translation - {92B255FE-94E2-4BCA-958D-3926CE38913F} - D:\DreyeMT\DREYEI~1.DLL
O3 - Toolbar: 妗蚚刲坰馱撿沭2.0 - {03465FF5-00AE-411a-9C34-960ED566EC03} - C:\Program Files\superutilbar\superutilbar.dll
O3 - Toolbar: 啃僅閉撰刲啪 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\BaiduBar.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\ATK0100\Hcontrol.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Progra~1\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [pccguide.exe] "c:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "c:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "c:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: 匯出至 Microsoft Excel(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com.tw
O17 - HKLM\System\CCS\Services\Tcpip\..\{D7F6F443-2BE8-4B18-9CA1-9BAD19AB6FA2}: NameServer = 202.106.195.68 202.106.46.151
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - c:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - c:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
O23 - Service: Windows_ServerDdos - Unknown owner - C:\WINDOWS\System32\ddos.exe
O23 - Service: zhengtu928 - Unknown owner - C:\WINDOWS\win32.exe
Are you using an english based version of windows?
Please go
HERE and do a online scan.
Let me know what is found.
Download and install AVG Anti-Spyware (ewido). Then scan and post the report here.
Instructions and download link can be found
here .
I'm using a Chinese Language version which I bought here in Beijing, China. (Sorry, perhaps I should've mentioned that)
I'm doing those scans you mentioned now.
I couldn't get the f-secure scan to work because it only works on IE and I'm using firefox. (If I try to use IE, it redirects me to a shopping site and then a popup comes up telling me to download "ErrorSafe" and then it just shuts down.) I can run the AVG virus one that I have if you think that will help.. Here is the report from AVG Anti-Spyware:
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 上午 01:38:48 2007/2/15
+ Scan result:
HKLM\SOFTWARE\Classes\MimeFilter.AdFilter -> Adware.CnsMin : Cleaned.
HKLM\SOFTWARE\Classes\MimeFilter.AdFilter.1 -> Adware.CnsMin : Cleaned.
HKLM\SOFTWARE\Classes\MimeFilter.AdFilter\CLSID -> Adware.CnsMin : Cleaned.
HKLM\SOFTWARE\Classes\MimeFilter.AdFilter\CurVer -> Adware.CnsMin : Cleaned.
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP18\A0010642.dll -> Adware.SpywareStorm : Cleaned.
:mozilla.209:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.229:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.86:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.87:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.101:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.405:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.406:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.64:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Currans\Cookies\currans@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.129:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.364:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Currans\Cookies\currans@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Currans\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.100:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.99:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\Currans\Cookies\[removed][1].txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.141:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Currans\Cookies\currans@com[1].txt -> TrackingCookie.Com : Cleaned.
:mozilla.109:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Gamershell : Cleaned.
:mozilla.110:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Gamershell : Cleaned.
:mozilla.167:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Gamershell : Cleaned.
:mozilla.168:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Gamershell : Cleaned.
C:\Documents and Settings\Currans\Cookies\[removed][1].txt -> TrackingCookie.Gamershell : Cleaned.
C:\Documents and Settings\Currans\Cookies\currans@gamershell[1].txt -> TrackingCookie.Gamershell : Cleaned.
:mozilla.60:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Currans\Cookies\currans@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Currans\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
:mozilla.14:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.15:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.16:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.17:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Currans\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.108:C:\Documents and Settings\Currans\Application Data\Mozilla\Firefox\Profiles\d6apypul.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Currans\Cookies\[removed][1].txt -> TrackingCookie.Specificclick : Cleaned.
::Report end
Rescan with HJT and post a new log here.
Also please describe how your computer behaves at the moment.
I got the F-Secure to work and here is the result from that: (it's pretty long)
I will restart my computer now and then re post a hijackthis log.
Computer name: TRACY
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\ D:\
Result: 46 malware found
Adware.BHO(generic) (spyware)
* System
Adware.Baidu (spyware)
* System
BDSearch Plugin (spyware)
* System
Backdoor.Win32.SdBot.aad (virus)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009506.EXE (Renamed & Submitted)
* C:\WINDOWS\TEMP\ERASEME_48231.EXE (Renamed & Submitted)
* C:\WINDOWS\SYSTEM32\SPOOLVC.EXE (Renamed & Submitted)
NetworkWorm.ND (virus)
* C:\DOCUMENTS AND SETTINGS\CURRANS\LOCAL SETTINGS\TEMP\ZSDN.EXE (Submitted)
Text/BotFTP.gen (virus)
* C:\WINDOWS\SYSTEM32\DL.INF (Submitted)
Tracking Cookie (spyware)
* System (Disinfected)
* System (Submitted)
Trojan-Downloader.BAT.Ftp.ab (virus)
* C:\WINDOWS\SYSTEM32\I (Renamed & Submitted)
Trojan-Downloader.Win32.QQHelper.uo (virus)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP18\A0010566.EXE (Renamed & Submitted)
Trojan-Dropper.Win32.Agent.ayy (virus)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP21\A0011881.EXE (Renamed & Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP20\A0010829.EXE (Renamed & Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP20\A0010869.EXE (Renamed & Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP18\A0010685.EXE (Renamed & Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP18\A0010709.EXE (Renamed & Submitted)
Trojan-PSW.Win32.OnLineGames.gw (virus)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP21\A0011859.SYS (Renamed & Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP21\A0012001.SYS (Renamed & Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP20\A0010839.SYS (Renamed & Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP20\A0010859.SYS (Renamed & Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP18\A0010535.SYS (Renamed & Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP18\A0010666.SYS (Renamed & Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP18\A0010694.SYS (Renamed & Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008871.SYS (Renamed & Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009490.SYS (Renamed & Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007852.SYS (Renamed & Submitted)
W32/Kut.gen1 (virus)
* C:\WINDOWS\HEH.EXE (Submitted)
W32/Malware (virus)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP21\A0012013.DLL (Submitted)
* C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\MSINFO\IEINFO5.DLL (Submitted)
* C:\DOCUMENTS AND SETTINGS\CURRANS\LOCAL SETTINGS\TEMP\HELPER.EXE (Submitted)
* C:\DOCUMENTS AND SETTINGS\CURRANS\LOCAL SETTINGS\TEMP\SVCHOST.EXE (Submitted)
W32/Malware.JED (virus)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006845.EXE (Submitted)
W32/Malware.JWY (virus)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP21\A0011888.EXE (Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP21\A0011996.EXE (Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP21\A0012019.EXE (Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP20\A0010835.EXE (Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP20\A0010875.EXE (Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP18\A0010689.EXE (Submitted)
* C:\SYSTEM VOLUME INFORMATION\_RESTORE{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP18\A0010714.EXE (Submitted)
* C:\WINDOWS\G3.EXE (Submitted)
W32/Smalltroj.NYS (virus)
* C:\WINDOWS\SYSTEM32\VGQEFMGF.EXE (Submitted)
* C:\WINDOWS\SYSTEM32\RMQRQFKU.EXE (Submitted)
* C:\WINDOWS\SYSTEM32\RIVUNXPP.EXE (Submitted)
* C:\WINDOWS\SYSTEM32\KVTAREOF.EXE (Submitted)
Win32.Trojan-PSW.Lineage (spyware)
* System
Statistics
Scanned:
* Files: 24645
* System: 3926
* Not scanned: 5
Actions:
* Disinfected: 1
* Renamed: 20
* Deleted: 0
* None: 25
* Submitted: 41
Files not scanned:
* C:\PAGEFILE.SYS
* C:\WINDOWS\WIN32.DLL
* C:\WINDOWS\SYSTEM32\EAEGX.DLL
* C:\WINDOWS\SYSTEM32\DRIVERS\MBDUJ.SYS
* C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
Options
Download
SDFix and save it to your Desktop.
Double click
SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
Please then reboot your computer in
Safe Mode by doing the following :
Restart your computer After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually; Instead of Windows loading as normal, the Advanced Options Menu should appear; Select the first option, to run Windows in Safe Mode, then press Enter . Choose your usual account. Open the extracted SDFix folder and double click RunThis.bat to start the script. Type Y to begin the cleanup process. It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot. Press any Key and it will restart the PC. When the PC restarts the Fixtool will run again and complete the removal process then display Finished , press any key to end the script and load your desktop icons. Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum). Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
After the computer reboots, Windows gives me a message saying there's the virus: TROJ_PSW.CARA TROJ_BLA.5_2
Also, AVG always pops up and says there is a virus: Backdoor.Generic4.FYY
I always "HEAL" it but it always comes back on reboot. The computer is pretty much acting the same.
Here is the SDFIX log:
SDFix: Version 1.65
Run by: Currans - 2007/02/15 星期四 @ 3:20:09.32
Microsoft Windows XP [版本 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
Path:
Restoring Windows Registry Entries
Restoring Default Hosts File
Rebooting…
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\DOCUME~1\Currans\LOCALS~1\Temp\svchost.exe - Deleted
C:\WINDOWS\Temp\removalfile.bat - Deleted
ADS Check:
C:\WINDOWS\system32
No streams found.
Final Check:
Remaining Files:
—————
Backups Folder: - C:\SDFix\backups\backups.zip
Checking For Files with Hidden Attributes :
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP12\A0003697.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP12\A0003698.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP12\A0003699.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP12\A0003700.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP12\A0003701.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP12\A0003702.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP12\A0003703.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP12\A0003710.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP12\A0003711.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP12\A0003712.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP12\A0003713.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP12\A0003714.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP12\A0003715.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP12\A0003716.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0004710.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0004711.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0004712.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0004713.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0004714.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0004715.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0004716.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005710.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005711.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005712.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005713.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005714.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005715.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005716.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005781.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005782.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005783.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005784.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005785.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005786.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005787.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005796.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005797.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005798.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005799.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005800.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005801.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP14\A0005802.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006796.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006797.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006798.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006799.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006800.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006801.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006802.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006811.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006812.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006813.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006814.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006815.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006816.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006817.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006830.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006831.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006832.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006833.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006834.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006835.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006836.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006855.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006856.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006857.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006858.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006859.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006860.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0006861.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007856.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007857.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007858.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007859.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007860.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007861.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007862.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007876.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007877.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007878.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007879.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007880.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007881.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP16\A0007882.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008875.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008876.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008877.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008878.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008879.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008880.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008881.com
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008898.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008899.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008900.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008901.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008902.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008903.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0008904.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009495.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009496.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009497.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009498.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009499.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009500.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009501.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009518.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009519.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009520.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009521.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009522.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009523.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009524.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009534.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009535.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009536.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009537.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009538.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009539.COM
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP17\A0009540.COM
C:\WINDOWS\system32\awtqp.dll
C:\WINDOWS\system32\wvussrp.dll
C:\Program Files\Common Files\Microsoft Shared\MSInfo\IEINFO5.dll
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP21\A0012013.dll
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP21\A0012056.dll
C:\WINDOWS\win32.exe
C:\Documents and Settings\Currans\Local Settings\Temp\bb.exe
C:\Documents and Settings\Currans\Local Settings\Temp\helper.exe
C:\Documents and Settings\Currans\Local Settings\Temp\juexiao.exe
C:\Documents and Settings\Currans\Local Settings\Temp\zsdn.exe
C:\Program Files\Common Files\Microsoft Shared\MSInfo\IEINFO5.sys
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP21\A0012023.SYS
C:\System Volume Information\_restore{028CF5E1-CC5B-427E-B48E-AD0F37FC2820}\RP21\A0012068.SYS
Finished
And the HIJACKThis Log:
Logfile of HijackThis v1.99.1
Scan saved at 上午 03:30:34, on 2007/2/15
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\conime.exe
C:\WINDOWS\ATK0100\Hcontrol.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Progra~1\ASUS\Power4 Gear\BatteryLife.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe
C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe
C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
c:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
C:\program files\internet explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe
O3 - Toolbar: 收音機(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Dr.eye WebPage Translation - {92B255FE-94E2-4BCA-958D-3926CE38913F} - D:\DreyeMT\DREYEI~1.DLL
O3 - Toolbar: 妗蚚刲坰馱撿沭2.0 - {03465FF5-00AE-411a-9C34-960ED566EC03} - C:\Program Files\superutilbar\superutilbar.dll
O3 - Toolbar: 啃僅閉撰刲啪 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\BaiduBar.dll (file missing)
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\ATK0100\Hcontrol.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Progra~1\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [pccguide.exe] "c:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "c:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "c:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: 匯出至 Microsoft Excel(&X) - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com.tw
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D7F6F443-2BE8-4B18-9CA1-9BAD19AB6FA2}: NameServer = 202.106.195.68 202.106.46.151
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - c:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - c:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe
O23 - Service: Windows_ServerDdos - Unknown owner - C:\WINDOWS\System32\ddos.exe
O23 - Service: zhengtu928 - Unknown owner - C:\WINDOWS\win32.exe