HI:
i didnt catch the the type of infection …sorry
and, the combofix make my laptop hanged 4times!!!
but finally, I make it.
ComboFix 08-05-07.1 - gigi 2008-05-09 10:18:23.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\FffgPXbc.ini2
.
—- Previous Run ——-
.
C:\WINDOWS\rs.txt
C:\WINDOWS\system32\iexp_log.txt
C:\WINDOWS\system32\sexit.dat
.
((((((((((((((((((((((((( Files Created from 2008-04-09 to 2008-05-09 )))))))))))))))))))))))))))))))
.
2008-06-28 15:22 . 2008-06-28 15:22 d——– C:\Program Files\Enigma Software Group
2008-06-28 14:26 . 2008-06-28 14:26 d——– C:\Documents and Settings\gigi\Application Data\TrojanHunter
2008-06-28 12:56 . 2008-06-28 13:00 d——– C:\Program Files\Iparmor
2008-06-28 12:55 . 2008-06-28 12:55 d——– C:\Documents and Settings\gigi\update
2008-06-28 12:51 . 2001-01-17 07:01 260,096 –a—— C:\WINDOWS\system32\RICHTX32.OCX
2008-06-28 12:51 . 2000-12-06 00:00 211,968 –a—— C:\WINDOWS\system32\TABCTL32.OCX
2008-06-28 12:51 . 2000-05-22 00:00 117,248 –a—— C:\WINDOWS\system32\MSINET.OCX
2008-06-28 12:44 . 2008-06-28 13:04 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2008-06-28 12:31 . 2008-04-28 20:33 d——– C:\Documents and Settings\gigi\Application Data\TmpRecentIcons
2008-06-28 11:47 . 2008-06-28 11:47 d——– C:\WINDOWS\empty
2008-06-27 17:24 . 2008-06-27 17:24 d——– C:\Documents and Settings\gigi\Application Data\tmp
2008-06-27 17:24 . 2008-06-27 17:24 d——– C:\Documents and Settings\gigi\Application Data\Reallusion
2008-06-27 12:01 . 2008-02-22 02:33 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-05-06 23:12 . 2008-05-06 23:12 d——– C:\Documents and Settings\gigi\Application Data\Malwarebytes
2008-05-06 23:11 . 2008-05-06 23:12 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-05-06 23:11 . 2008-05-06 23:11 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-06 23:11 . 2008-05-05 20:46 27,048 –a—— C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-06 23:11 . 2008-05-05 20:46 15,864 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-05-05 19:40 . 2008-05-07 17:26 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2008-05-05 19:40 . 2008-05-05 19:40 1,409 –a—— C:\WINDOWS\QTFont.for
2008-05-05 17:29 . 2008-05-05 17:29 d——– C:\_OTMoveIt
2008-05-04 21:34 . 2008-05-04 21:34 d——– C:\Program Files\GB18030Tools
2008-05-04 21:34 . 2008-05-04 21:34 d——– C:\Program Files\Common Files\Sonic Shared
2008-05-04 21:33 . 2008-05-04 21:37 d——– C:\WINDOWS\system32\DLA
2008-05-04 21:33 . 2008-05-04 21:33 d——– C:\Program Files\Roxio
2008-05-04 21:33 . 2008-05-04 21:33 d——– C:\Program Files\Common Files\SureThing Shared
2008-05-04 21:33 . 2006-07-21 11:21 99,176 –a—— C:\WINDOWS\system32\drivers\DRVMCDB.SYS
2008-05-04 21:33 . 2006-08-18 13:17 92,920 –a—— C:\WINDOWS\DLA.EXE
2008-05-04 21:33 . 2006-08-18 13:17 56,056 –a—— C:\WINDOWS\system32\DLAAPI_W.DLL
2008-05-04 21:33 . 2006-08-11 11:05 51,768 –a—— C:\WINDOWS\system32\drivers\DRVNDDM.SYS
2008-05-04 21:33 . 2006-08-11 10:35 28,184 –a—— C:\WINDOWS\system32\drivers\DLARTL_M.SYS
2008-05-04 21:33 . 2006-08-11 10:35 12,920 –a—— C:\WINDOWS\system32\drivers\DLACDBHM.SYS
2008-05-04 11:46 . 2008-05-04 11:46 d——– C:\Program Files\jdssoftware
2008-05-04 11:34 . 2008-05-04 11:34 d——– C:\Documents and Settings\gigi\Application Data\WebCatcher
2008-05-03 17:27 . 2008-05-03 17:27 d——– C:\temp
2008-05-03 17:27 . 2008-05-03 17:27 1,409 –a—— C:\WINDOWS\system\ksphonet.fot
2008-05-03 15:29 . 2008-05-03 15:29 d——– C:\WINDOWS\speech
2008-05-03 15:29 . 2008-05-03 15:29 288 –a—— C:\WINDOWS\ODBC.INI
2008-05-03 11:39 . 2008-05-03 11:39 d——– C:\WINDOWS\新托福词汇王
2008-05-02 21:44 . 2008-05-02 21:44 d——– C:\Deckard
2008-05-02 21:34 . 2007-09-06 00:22 289,144 –a—— C:\WINDOWS\system32\VCCLSID.exe
2008-05-02 21:34 . 2006-04-27 17:49 288,417 –a—— C:\WINDOWS\system32\SrchSTS.exe
2008-05-02 21:34 . 2008-04-24 08:10 86,528 –a—— C:\WINDOWS\system32\VACFix.exe
2008-05-02 21:34 . 2008-04-28 08:03 82,944 –a—— C:\WINDOWS\system32\IEDFix.exe
2008-05-02 21:34 . 2008-04-28 08:03 82,944 –a—— C:\WINDOWS\system32\404Fix.exe
2008-05-02 21:34 . 2003-06-05 21:13 53,248 –a—— C:\WINDOWS\system32\Process.exe
2008-05-02 21:34 . 2004-07-31 18:50 51,200 –a—— C:\WINDOWS\system32\dumphive.exe
2008-05-02 21:34 . 2007-10-04 00:36 25,600 –a—— C:\WINDOWS\system32\WS2Fix.exe
2008-05-02 21:34 . 2008-05-05 17:07 5,090 –a—— C:\WINDOWS\system32\tmp.reg
2008-05-02 20:29 . 2008-05-03 09:57 d——– C:\Documents and Settings\gigi\Application Data\skypePM
2008-05-02 20:29 . 2008-05-02 20:29 56 –ah—– C:\WINDOWS\system32\ezsidmv.dat
2008-05-02 20:25 . 2008-05-02 20:25 d——– C:\Program Files\Skype
2008-05-02 20:25 . 2008-05-02 20:25 d——– C:\Program Files\Common Files\Skype
2008-05-02 20:25 . 2008-05-03 09:57 d——– C:\Documents and Settings\gigi\Application Data\Skype
2008-05-02 20:25 . 2008-05-02 20:25 d——– C:\Documents and Settings\All Users\Application Data\Skype
2008-05-02 14:29 . 2008-05-02 14:29 d——– C:\KuGoo
2008-05-02 14:26 . 2007-08-14 09:21 503,808 –a—— C:\WINDOWS\system32\KuGoo3DownXControl.ocx
2008-05-02 14:26 . 2008-05-02 14:33 33,280 –a—— C:\WINDOWS\LoginUsers.idx
2008-05-02 14:26 . 2008-05-02 14:33 6,096 –a—— C:\WINDOWS\LoginUsers.dat
2008-05-02 14:26 . 2008-05-02 14:26 25 –ah—– C:\WINDOWS\dbisam.lck
2008-05-01 22:03 . 2008-05-01 22:03 d——– C:\Program Files\Universal
2008-04-30 16:07 . 2008-05-05 01:15 d——– C:\Program Files\Spyware Doctor
2008-04-30 16:07 . 2008-04-30 16:07 d——– C:\Documents and Settings\gigi\Application Data\PC Tools
2008-04-30 16:07 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-04-30 16:07 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-04-30 16:07 . 2008-02-01 12:55 42,376 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-04-30 16:07 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-04-29 12:18 . 2008-05-09 10:07 d——– C:\Program Files\Mozilla Firefox 3 Beta 5
2008-04-29 12:18 . 2008-04-29 12:18 0 –a—— C:\WINDOWS\nsreg.dat
2008-04-28 22:41 . 2008-04-28 22:41 0 –a—— C:\WINDOWS\system32\cid_store.dat
2008-04-28 19:23 . 2008-04-28 19:23 d——– C:\Documents and Settings\gigi\Application Data\Grisoft
2008-04-28 19:22 . 2008-04-28 19:22 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-28 19:22 . 2007-05-30 05:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-28 19:18 . 2008-04-28 22:43 d——– C:\Documents and Settings\gigi\Application Data\MxBoost
2008-04-26 23:04 . 2008-04-26 23:04 d——– C:\Program Files\Common Files\Adobe Systems Shared
2008-04-26 23:04 . 2008-04-26 23:04 d——– C:\Documents and Settings\All Users\Application Data\Macrovision
2008-04-26 11:55 . 2008-04-26 11:58 d——– C:\Program Files\Microsoft Student
2008-04-26 11:54 . 2008-04-26 11:54 d——– C:\Program Files\Learning Essentials
2008-04-26 11:54 . 2005-05-26 15:34 2,297,552 –a—— C:\WINDOWS\system32\d3dx9_26.dll
2008-04-26 11:08 . 2008-04-26 11:08 d——– C:\Program Files\Windows Media Connect 2
2008-04-26 11:08 . 2006-10-04 07:06 1,197,294 ——— C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-04-26 11:08 . 2006-10-04 07:06 764,868 ——— C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-04-26 11:08 . 2006-10-04 07:06 217,118 ——— C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-04-26 11:07 . 2008-04-26 11:07 d——– C:\WINDOWS\system32\drivers\UMDF
2008-04-26 10:14 . 2008-04-26 10:14 d——– C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-04-24 22:48 . 2008-04-24 22:48 d——– C:\Documents and Settings\gigi\Application Data\Apple Computer
2008-04-24 21:49 . 2008-04-24 21:50 d——– C:\Program Files\QuickTime
2008-04-24 21:49 . 2008-04-24 21:49 d——– C:\Program Files\Apple Software Update
2008-04-24 21:49 . 2008-04-24 21:49 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-24 21:40 . 2008-04-24 21:40 d–h—– C:\Program Files\Zero G Registry
2008-04-24 21:40 . 2008-04-24 21:52 d——– C:\Program Files\Britannica 8.0
2008-04-24 21:38 . 2008-04-24 21:38 d–h—– C:\Documents and Settings\gigi\InstallAnywhere
2008-04-24 12:41 . 2008-04-24 12:41 d——– C:\Program Files\Tudou
2008-04-22 14:24 . 2008-04-22 14:24 d——– C:\Program Files\EPSON
2008-04-22 14:24 . 2002-09-02 23:02 166,400 –a—— C:\WINDOWS\system32\EBAPI3.DLL
2008-04-22 14:24 . 2002-02-28 23:00 69,120 –a—— C:\WINDOWS\system32\EAL.EXE
2008-04-22 14:24 . 2002-06-26 23:02 60,969 –a—— C:\WINDOWS\system32\EBPMON3.DLL
2008-04-22 14:24 . 2002-02-28 23:00 44,544 –a—— C:\WINDOWS\system32\EAL32.DLL
2008-04-22 14:24 . 2000-06-06 23:01 34,304 –a—— C:\WINDOWS\system32\EBPCHP.DLL
2008-04-22 14:24 . 2001-03-08 08:23 145 –a—— C:\WINDOWS\system32\EBPPORT3.DAT
2008-04-22 14:21 . 2008-04-22 14:21 91,002 –a—— C:\WINDOWS\EPSTPLOG.BAK
2008-04-22 14:14 . 2004-08-03 21:01 25,856 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2008-04-22 14:14 . 2004-08-03 21:01 25,856 –a—— C:\WINDOWS\system32\dllcache\usbprint.sys
2008-04-22 08:25 . 2008-04-26 11:07 d——– C:\WINDOWS\system32\LogFiles
2008-04-20 20:00 . 2007-03-20 09:26 227 –a—— C:\WINDOWS\sosuo.col
2008-04-19 10:46 . 2008-04-19 10:46 7,904 –a—— C:\WINDOWS\system32\BDGuardS.DAT
2008-04-19 10:46 . 2008-04-19 10:46 1,464 –a—— C:\WINDOWS\system32\BDGuard.DAT
2008-04-18 22:51 . 2008-04-18 22:51 d——– C:\Program Files\eREAD
2008-04-18 22:27 . 2008-04-18 22:27 d——– C:\Program Files\MSXML 4.0
2008-04-18 20:34 . 2000-09-08 09:00 24,480 -ra—— C:\WINDOWS\system\Ksphonet.ttf
2008-04-18 20:26 . 2008-04-18 21:13 d——– C:\Program Files\DAEMON Tools Lite
2008-04-18 12:39 . 2008-04-18 12:39 d——– C:\Documents and Settings\gigi\Application Data\DAEMON Tools
2008-04-18 12:39 . 2008-04-18 12:39 717,296 –a—— C:\WINDOWS\system32\drivers\sptd.sys
2008-04-18 09:30 . 2008-04-18 09:30 d——– C:\Program Files\Common Files\Kingsoft
2008-04-15 20:47 . 2008-04-15 20:47 d——– C:\Program Files\Common Files\Real
2008-04-15 20:46 . 2008-04-22 08:25 d——– C:\Program Files\StormII
2008-04-15 20:46 . 2008-04-15 20:46 d——– C:\Documents and Settings\gigi\Application Data\Application Data
2008-04-15 20:46 . 2008-04-29 11:04 d——– C:\Documents and Settings\All Users\Application Data\Storm
2008-04-15 20:37 . 2008-05-04 11:42 d——– C:\Program Files\eMule
2008-04-13 09:28 . 2008-04-13 09:28 d——– C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-04-12 21:54 . 2008-04-12 21:54 d——– C:\Documents and Settings\gigi\Application Data\Simply Super Software
2008-04-12 21:54 . 2006-05-25 13:52 162,304 –a—— C:\WINDOWS\system32\ztvunrar36.dll
2008-04-12 21:54 . 2003-02-02 18:06 153,088 –a—— C:\WINDOWS\system32\UNRAR3.dll
2008-04-12 21:54 . 2005-08-25 23:50 77,312 –a—— C:\WINDOWS\system32\ztvunace26.dll
2008-04-12 21:54 . 2002-03-05 23:00 75,264 –a—— C:\WINDOWS\system32\unacev2.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-28 20:03 ——— d—–w C:\Program Files\Google
2008-06-28 20:03 ——— d—–w C:\Program Files\Creative
2008-06-28 19:47 ——— d—–w C:\Program Files\Dell
2008-06-27 22:16 ——— d—–w C:\Program Files\Common Files\Adobe
2008-06-27 19:01 ——— d—–w C:\Program Files\Java
2008-06-27 18:51 ——— d—–w C:\Documents and Settings\gigi\Application Data\QQDoctor
2008-05-09 17:17 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-05-09 08:58 ——— d—–w C:\Documents and Settings\gigi\Application Data\BITS
2008-05-09 05:17 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-05 04:35 ——— d—–w C:\Program Files\Common Files\InstallShield
2008-05-05 04:34 ——— d—–w C:\Program Files\Common Files\Roxio Shared
2008-05-04 18:47 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-05-03 23:39 2,110 —-a-w C:\Documents and Settings\gigi\Application Data\wklnhst.dat
2008-04-24 02:51 ——— d—–w C:\Documents and Settings\gigi\Application Data\SogouPY
2008-04-18 16:33 ——— d—–w C:\Program Files\Kingsoft
2008-04-15 03:52 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-04-10 04:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-09 05:02 ——— d—–w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2008-04-05 15:56 ——— d—–w C:\Documents and Settings\gigi\Application Data\QQUpdate
2008-04-05 15:38 ——— d—–w C:\Program Files\FlashGet Network
2008-04-05 15:26 ——— d—–w C:\Program Files\Symantec
2008-04-05 15:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-05 15:19 ——— d—–w C:\Documents and Settings\gigi\Application Data\Kingsoft
2008-04-05 14:59 ——— d—–w C:\Documents and Settings\NetworkService\Application Data\SogouPY.users
2008-04-05 14:59 ——— d—–w C:\Documents and Settings\NetworkService\Application Data\SogouPY
2008-04-05 05:38 ——— d—–w C:\Program Files\Tencent
2008-04-05 05:38 ——— d—–w C:\Documents and Settings\gigi\Application Data\Tencent
2008-04-05 05:38 ——— d—–w C:\Documents and Settings\gigi\Application Data\QQ
2008-04-05 05:32 ——— d—–w C:\Documents and Settings\LocalService\Application Data\SogouPY.users
2008-04-05 05:32 ——— d—–w C:\Documents and Settings\LocalService\Application Data\SogouPY
2008-04-05 05:13 ——— d—–w C:\Program Files\SogouInput
2008-04-05 05:13 ——— d—–w C:\Documents and Settings\gigi\Application Data\SogouPY.users
2008-04-05 04:32 ——— dcsh–w C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-05 04:32 ——— d—–w C:\Program Files\Windows Live
2008-04-05 04:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-05 03:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\Dell
2008-04-02 23:13 ——— d—–w C:\Documents and Settings\gigi\Application Data\MSNInstaller
2008-04-01 21:40 ——— d—–w C:\Documents and Settings\gigi\Application Data\CyberLink
2008-04-01 21:23 ——— d–h–w C:\Documents and Settings\gigi\Application Data\GTek
2008-04-01 20:48 ——— d—–w C:\Documents and Settings\gigi\Application Data\Dell
2008-04-01 20:01 ——— d—–w C:\Documents and Settings\gigi\Application Data\Template
2008-04-01 19:42 ——— d—–w C:\Documents and Settings\gigi\Application Data\Roxio
2008-04-01 19:31 ——— d—–w C:\Documents and Settings\gigi\Application Data\Creative
2008-03-28 18:29 ——— d—–w C:\Program Files\Microsoft Works
2008-03-28 18:28 ——— d–h–w C:\WINDOWS\system32\config\systemprofile\Application Data\GTek
2008-03-28 18:28 ——— d—–w C:\Program Files\DellAutomatedPCTuneUp
2008-03-28 18:28 ——— d—–w C:\Documents and Settings\All Users\Application Data\Gtek
2008-03-28 18:27 ——— d—–w C:\Program Files\MSECache
2008-03-28 18:27 ——— d—–w C:\Program Files\CyberLink
2008-03-28 18:26 ——— d—–w C:\Program Files\Dell Support Center
2008-03-28 18:26 ——— d—–w C:\Program Files\Dell DataSafe Online
2008-03-28 18:26 ——— d—–w C:\Program Files\Common Files\supportsoft
2008-03-28 18:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-03-28 18:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-03-28 18:24 ——— d—–w C:\Program Files\Dell Network Assistant
2008-03-28 18:24 ——— d—–w C:\Documents and Settings\All Users\Application Data\SingleClick Systems
2008-03-28 18:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sonic
2008-03-28 18:23 ——— d—–w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-03-28 18:22 ——— d—–w C:\Program Files\Sigmatel
2008-03-28 18:21 ——— d—–w C:\Program Files\CONEXANT
2008-03-28 18:20 ——— d—–w C:\Program Files\NetWaiting
2008-03-28 18:20 ——— d—–w C:\Program Files\Modem Diagnostic Tool
2008-03-28 18:20 ——— d—–w C:\Program Files\Digital Line Detect
2008-03-28 18:19 ——— d—–w C:\Program Files\Creative Live! Cam
2008-03-28 18:19 ——— d—–w C:\Program Files\Common Files\Reallusion
2008-03-28 18:19 ——— d—–w C:\Program Files\Common Files\Creative
2008-03-28 18:18 ——— d—–w C:\WINDOWS\system32\config\systemprofile\Application Data\InstallShield
2008-03-28 18:18 ——— d—–w C:\Documents and Settings\gigi\Application Data\InstallShield
2008-03-28 18:16 ——— d—–w C:\Program Files\Common Files\Java
2008-03-28 18:15 ——— d—–w C:\Program Files\MSXML 6.0
2008-03-28 18:03 0 —ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-03-28 18:03 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_Apfiltr_01005.Wdf
2008-03-28 18:02 ——— d—–w C:\Program Files\DellTPad
2008-03-28 17:57 7,265 —-a-w C:\WINDOWS\system32\drivers\1028_Dell_VOS_VOSTRO_1400.mrk
2008-03-19 09:47 1,845,248 —-a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ——w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-01 23:36 3,591,680 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:55 70,656 ——w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-02-29 08:55 625,664 ——w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-22 10:00 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 —-a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 06:51 282,624 ——w C:\WINDOWS\system32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 —-a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 05:32 45,568 ——w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ——w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-02-15 05:44 161,792 ——w C:\WINDOWS\system32\dllcache\ieakui.dll
.
—-a-w 98,606 2008-01-05 01:59:20 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\AVGantiSpyware7.5.1.43-3399-path .exe
——- Sigcheck ——-
2007-10-30 09:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2007-10-30 10:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 10:20 360064 ef7834c1d9ddf4c7da697d8c24a03791 C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-12C9-4305-82F9-43058F20E8D2}]
2008-04-20 22:11 255296 –a—— C:\Program Files\Tencent\QQDownload\QQIEHelper01.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1F364306-AA45-47B5-9F9D-39A8B94E7EF1}]
2008-04-05 04:54 104008 –a—— C:\Program Files\FlashGet Network\Flashget\ComDlls\bhoCATCH.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6A19C29D-ED45-4483-8999-9F939C8161F2}]
2008-03-10 10:08 81920 –a—— C:\Program Files\eREAD\eREAD\WebHook.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellAutomatedPCTuneUp"="C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 07:49 465136]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-02-13 17:21 202544]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"Dell DataSafe Scheduler"="C:\Program Files\Dell DataSafe Online\Bin\DataSafeOnlineScheduler.exe" [2007-12-02 14:30 308464]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24 1694208]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 02:39 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\DellTPad\Apoint.exe" [2007-09-23 17:27 159744]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-23 20:12 8466432]
"nwiz"="nwiz.exe" [2007-09-23 20:12 1626112 C:\WINDOWS\system32\nwiz.exe]
"NVHotkey"="nvHotkey.dll" [2007-09-23 20:12 67584 C:\WINDOWS\system32\nvhotkey.dll]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-09-23 20:12 81920]
"OEM02Mon.exe"="C:\WINDOWS\OEM02Mon.exe" [2007-08-28 13:54 36864]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2007-03-16 02:10 1392640]
"DELL Webcam Manager"="C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 14:43 118784]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2007-09-07 15:49 1236992]
"SigmatelSysTrayApp"="stsystra.exe" [2007-09-16 13:44 405504 C:\WINDOWS\stsystra.exe]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50 81920]
"ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2008-01-17 19:41 17920]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-02-13 17:21 16384]
"PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-11-01 13:39 189736]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-04-05 07:25 66680]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-04-19 16:07 124160]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54 282624]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"JdsEnglishSpirit"="C:\Program Files\jdssoftware\wabdc8\flyenglishspirit.exe" [ ]
"RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 09:00 1116920]
"stup.exe"="C:\PROGRA~1\TENCENT\SSPlus\SPlus.dll" [2008-03-27 07:42 173376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 04:00 53760 C:\WINDOWS\system32\narrator.exe]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Tencent\\QQDownload\\QQDownload.exe"=
"C:\\Program Files\\Tencent\\QQDownload\\QDAutoUpdate.exe"=
"C:\\Program Files\\FlashGet Network\\Flashget\\FlashGet.exe"=
"C:\\Program Files\\FlashGet Network\\Flashget\\LiveUpdate.exe"=
"C:\\Program Files\\FlashGet Network\\Flashget\\LiveUpdateEx.exe"=
"C:\\Program Files\\Tencent\\QQ\\QQ.exe"=
"C:\\Program Files\\Tencent\\QQ\\QZone\\Qzone.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\StormII\\Storm.exe"=
"C:\\Program Files\\StormII\\stormliv.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Kingsoft\\Powerword 2007\\xdict.exe"=
"C:\\Program Files\\Kingsoft\\Powerword 2007\\update.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
.
Contents of the 'Scheduled Tasks' folder
"2008-05-02 21:19:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-09 10:19:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-09 10:20:32
ComboFix-quarantined-files.txt 2008-05-09 17:20:21
Pre-Run: 81,920,368,640 bytes free
Post-Run: 81,908,592,640 bytes free
327 — E O F — 2008-06-28 20:18:45