ComboFix 11-11-24.01 - Administrator 5/2011 Fri 11:09:41.7.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.936.86.1033.18.2038.1326 [GMT 8:00]
执行位置: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((( 2011-10-25 至 2011-11-25 的新的档案 )))))))))))))))))))))))))))))))
.
.
2011-11-24 09:18 . 2011-11-25 02:41 -------- d-----w- c:\documents and settings\Administrator\Application Data\Skype
2011-11-24 09:18 . 2011-11-24 09:18 -------- d-----r- c:\program files\Skype
2011-11-24 09:18 . 2011-11-24 09:18 -------- d--h--w- c:\documents and settings\All Users\Application Data\Skype
2011-11-23 06:23 . 2011-11-23 06:23 -------- d-----w- c:\documents and settings\Administrator\ChikkaV5
2011-11-23 06:10 . 2011-11-23 06:13 -------- d-----w- C:\UniScan
2011-11-23 06:10 . 2008-04-13 16:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2011-11-23 06:10 . 2008-04-13 16:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2011-11-23 06:07 . 2011-11-23 06:07 82380 ----a-w- c:\windows\system32\drivers\AFS2K.SYS
2011-11-23 06:07 . 2011-11-23 06:07 -------- d-----w- c:\documents and settings\Administrator\Application Data\Share-to-Web 上载文件夹
2011-11-23 06:06 . 2011-11-23 06:06 -------- d--h--w- c:\program files\Common Files\Hewlett-Packard
2011-11-23 06:06 . 2011-11-23 06:07 -------- d-----w- c:\program files\Hewlett-Packard
2011-11-22 06:29 . 2011-11-22 06:29 -------- d-----w- c:\program files\calicomtech
2011-11-22 06:28 . 2011-11-22 06:28 -------- d-----w- c:\windows\Downloaded Installations
2011-11-22 06:27 . 2011-11-22 07:41 9216 ----a-w- c:\windows\system32\IOCTLVDD.DLL
2011-11-22 05:24 . 2011-11-22 05:24 -------- d-----w- c:\documents and settings\Administrator\Application Data\Corel
2011-11-22 05:10 . 2011-11-22 05:10 -------- d-----w- c:\documents and settings\Administrator\Application Data\Avira
2011-11-22 05:10 . 2011-09-18 00:39 134344 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-11-22 05:10 . 2011-09-15 15:55 74640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-11-22 05:10 . 2011-11-22 05:10 -------- d-----w- c:\program files\Avira
2011-11-22 05:09 . 2011-11-22 05:09 -------- d-----w- c:\windows\system32\LogFiles
2011-11-22 04:52 . 2011-11-22 04:52 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2011-11-22 04:52 . 2011-11-22 04:52 -------- d--h--w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-22 04:52 . 2011-11-22 04:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-22 04:52 . 2011-08-31 09:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-22 04:44 . 2011-11-22 04:44 -------- d-----w- c:\program files\InstallShield Installation Information
2011-11-22 04:44 . 2011-11-22 04:44 -------- d--h--w- c:\program files\Common Files\Corel
2011-11-22 04:43 . 2011-11-22 04:43 -------- d-----w- c:\program files\Corel
2011-11-22 04:42 . 2011-11-22 04:44 -------- d--h--w- c:\program files\Common Files\InstallShield
2011-11-22 04:34 . 2011-11-25 02:17 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Digsby
2011-11-22 04:34 . 2011-11-22 10:06 -------- d--h--w- c:\documents and settings\All Users\Application Data\Digsby
2011-11-22 04:34 . 2011-11-22 10:06 -------- d-----w- c:\documents and settings\Administrator\Application Data\Digsby
2011-11-22 04:32 . 2011-11-22 04:32 -------- d-----w- c:\program files\Digsby
2011-11-22 04:18 . 2011-09-15 15:55 36000 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2011-11-22 03:29 . 2011-11-22 03:31 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Temp
2011-11-22 02:42 . 2011-11-22 02:42 -------- d-sh--w- c:\documents and settings\Administrator\IECompatCache
2011-11-22 02:41 . 2011-11-22 02:41 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2011-11-22 02:40 . 2011-11-22 02:40 -------- d--h--w- c:\documents and settings\NetworkService\IETldCache
2011-11-22 02:39 . 2011-11-22 02:39 -------- d-----w- c:\documents and settings\Administrator\IETldCache
2011-11-22 02:37 . 2009-01-07 10:21 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2011-11-22 02:36 . 2011-11-22 02:37 -------- dc----w- c:\windows\ie8
2011-11-22 02:36 . 2011-11-22 02:36 -------- d-----w- c:\windows\system32\x64
2011-11-22 02:36 . 2008-07-01 02:47 920088 ----a-w- c:\windows\system32\igxpun.exe
2011-11-22 02:36 . 2011-11-22 02:36 -------- dc----w- c:\windows\system32\DRVSTORE
2011-11-22 02:36 . 2006-11-10 01:25 319456 ----a-w- c:\windows\system32\difxapi.dll
2011-11-22 02:36 . 2011-11-22 02:37 -------- d-----w- c:\windows\msdownld.tmp
2011-11-22 02:35 . 2001-12-28 19:55 24035 ----a-r- c:\windows\system32\drivers\eaps2kbd.sys
2011-11-22 02:35 . 2001-09-05 03:25 40960 ----a-r- c:\windows\LoadDll.dll
2011-11-22 02:35 . 2000-03-13 20:16 18841 ----a-r- c:\windows\system32\FltrCoi.dll
2011-11-22 02:35 . 1999-10-29 20:35 24348 ----a-r- c:\windows\system32\drivers\EAWDMFD.SYS
2011-11-22 02:35 . 2011-11-22 02:35 -------- d-----w- c:\windows\system32\RTCOM
2011-11-22 02:35 . 2008-04-14 08:17 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2011-11-22 02:35 . 2008-07-01 03:27 108800 ----a-w- c:\windows\system32\drivers\Rtenicxp.sys
2011-11-22 02:35 . 2008-07-21 16:14 9728 ----a-w- c:\windows\system32\RtNicProp32.dll
2011-11-22 02:30 . 2011-11-22 02:30 -------- d-----w- c:\documents and settings\Administrator\UserData
2011-11-22 02:29 . 2011-11-22 02:29 -------- d--h--w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-11-22 02:24 . 2011-11-22 03:31 -------- d--h--w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2011-11-22 02:24 . 2011-11-22 02:30 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Google
2011-11-22 02:24 . 2011-11-22 02:24 -------- d-----w- c:\program files\Google
2011-11-22 02:02 . 2011-11-22 02:02 -------- d-----w- c:\documents and settings\Administrator\Application Data\vlc
2011-11-22 02:01 . 2011-11-22 02:01 -------- d-----w- c:\program files\Easy Media Player
2011-11-22 01:52 . 2011-11-22 01:53 -------- d--h--w- c:\documents and settings\All Users\Application Data\SweetIM
2011-11-22 01:52 . 2011-11-22 01:52 -------- d-----w- c:\program files\SweetIM
2011-11-22 00:49 . 2011-11-22 00:50 -------- d-----w- c:\documents and settings\Administrator\Application Data\AskToolbar
2011-11-22 00:29 . 2011-11-22 00:29 -------- d-----w- C:\logs
2011-11-22 00:29 . 2011-11-23 06:23 -------- d-----w- c:\program files\Chikka Messenger
2011-11-22 00:28 . 2011-11-22 00:28 -------- d-----w- c:\program files\IPMsg
2011-11-21 23:43 . 2011-11-25 01:48 -------- d-----w- c:\windows\system32\NtmsData
2011-11-21 23:43 . 2011-11-21 23:43 -------- d---a-w- c:\windows\Repair
2011-11-21 13:04 . 2011-11-24 03:04 -------- d-----w- c:\program files\Ask.com
2011-11-21 13:04 . 2011-11-25 03:01 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AskToolbar
2011-11-21 13:03 . 2011-11-22 05:10 -------- d--h--w- c:\documents and settings\All Users\Application Data\Avira
2011-11-21 11:54 . 2011-11-23 01:02 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
2011-11-21 11:46 . 2011-11-22 07:41 4032 ----a-w- c:\windows\system32\drivers\hostnt.sys
2011-11-21 11:46 . 2011-11-22 07:41 29056 ----a-w- c:\windows\system32\drivers\gsmhwdm.sys
2011-11-21 11:46 . 2011-11-22 07:41 27696 ----a-w- c:\windows\system32\drivers\mhdrv.sys
2011-11-21 11:46 . 2011-11-22 07:41 26060 ----a-w- c:\windows\system32\drivers\rcmhdog.sys
2011-11-21 11:46 . 2011-11-22 07:41 25904 ----a-w- c:\windows\system32\drivers\rcusbwdm.sys
2011-11-21 11:42 . 2011-11-21 11:42 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-21 11:42 . 2011-11-21 11:42 -------- d--h--w- c:\documents and settings\All Users\Application Data\McAfee
2011-11-21 11:39 . 2011-11-21 11:39 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-11-21 11:33 . 2011-11-21 11:40 -------- d-----w- C:\account
2011-11-21 11:32 . 2011-11-21 11:32 -------- d--h--w- c:\program files\Common Files\Adobe
2011-11-21 11:28 . 2009-02-27 16:23 450560 ----a-w- c:\windows\system32\GDS32.DLL
2011-11-21 11:28 . 2009-02-27 07:34 462848 ----a-w- c:\windows\system32\Firebird2Control.cpl
2011-11-21 11:28 . 2011-11-21 11:28 -------- d-----w- c:\program files\Firebird
2011-11-21 11:26 . 2011-11-21 11:26 69632 ----a-w- c:\windows\system32\MY3L_EX.DLL
2011-11-21 11:26 . 2011-11-21 11:26 53248 ----a-w- c:\windows\system32\NT_DLL2.DLL
2011-11-21 11:26 . 2011-11-21 11:26 135168 ----a-w- c:\windows\system32\YutianEx.DLL
2011-11-21 11:26 . 2005-09-05 14:33 413696 ----a-w- c:\windows\system32\SetUp_Pro.dll
2011-11-21 11:14 . 2006-10-26 11:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2011-11-21 11:14 . 2006-10-26 11:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2011-11-21 11:14 . 2011-11-21 11:14 -------- d-----w- c:\program files\Microsoft Works
2011-11-21 11:14 . 2011-11-21 11:14 -------- d-----w- c:\program files\MSBuild
2011-11-21 11:12 . 2011-11-21 11:14 -------- d-----w- c:\windows\SHELLNEW
2011-11-21 11:12 . 2011-11-21 11:12 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft Help
2011-11-21 11:12 . 2011-11-21 11:15 -------- d--h--w- c:\documents and settings\All Users\Application Data\Microsoft Help
2011-11-21 11:12 . 2011-11-21 11:12 -------- d-----r- C:\MSOCache
2011-11-21 11:11 . 2008-04-13 16:15 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2011-11-21 10:39 . 2011-11-21 10:39 -------- d-----w- c:\documents and settings\Administrator\Bluebirds
2011-11-21 10:39 . 2011-11-21 10:39 -------- d-----w- c:\windows\system32\Lang
2011-11-21 10:38 . 2011-11-21 10:38 -------- d-----w- c:\windows\system32\oobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( 在三个月内被修改的档案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((( SnapShot_2011-11-23_01.49.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-23 06:07 . 2011-11-23 06:10 45056 c:\windows\Installer\{6F7ECD56-E224-4263-9B7E-158E5CECC43B}\_486AD40031E5_4A05_BAE5_67FC693FE0EF.exe
+ 2011-11-23 06:07 . 2011-11-23 06:07 4150 c:\windows\Installer\{B376402D-58EA-45EA-BD50-DD924EB67A70}\hpmd.exe
+ 2003-04-16 11:31 . 2003-04-16 11:31 258048 c:\windows\system32\hpsjvset.dll
+ 2003-04-15 16:31 . 2003-04-15 16:31 274432 c:\windows\system32\hpgwiamd.dll
+ 2003-04-15 16:33 . 2003-04-15 16:33 401408 c:\windows\system32\hpgt2436.dll
+ 2011-11-24 09:18 . 2011-11-24 09:18 371272 c:\windows\Installer\{AA59DDE4-B672-4621-A016-4C248204957A}\SkypeIcon.exe
- 2011-11-21 13:04 . 2011-11-21 13:04 102400 c:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ARPPRODUCTICON.exe
+ 2011-11-21 13:04 . 2011-11-24 03:04 102400 c:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ARPPRODUCTICON.exe
+ 2011-11-24 03:04 . 2011-11-24 03:04 2144768 c:\windows\Installer\9d962b.msi
+ 2011-11-24 09:18 . 2011-11-24 09:18 1252864 c:\windows\Installer\1f48519.msi
+ 2011-11-24 09:18 . 2011-11-24 09:18 1527808 c:\windows\Installer\1f48513.msi
+ 2011-11-23 06:07 . 2011-11-23 06:07 4006400 c:\windows\Installer\111b3ea.msi
+ 2011-11-23 06:07 . 2011-11-23 06:07 2932224 c:\windows\Installer\111b3e3.msi
.
((((((((((((((((((((((((((((((((((((( 重要登入点 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白与合法缺省登录将不会被显示
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2011-08-24 130864]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-11-20 18:18 1515688 ---ha-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2011-08-24 10:21 1299248 ----a-r- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-11-20 1515688]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2011-08-24 1299248]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-11-20 1515688]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2011-08-24 1299248]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.IEToolbar]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"bluebirds"="c:\documents and settings\Administrator\Bluebirds\BlueBirds.exe" [2009-04-29 270336]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-11-22 39408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-10-13 17351304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-23 16804864]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-01 141848]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2011-09-08 888488]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2011-08-01 114992]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-09-23 258512]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Digsby.lnk - c:\program files\Digsby\digsby.exe [2010-3-3 141488]
IPMSG for Win32.lnk - c:\program files\IPMsg\ipmsg.exe [2011-11-22 210432]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\IPMsg\\ipmsg.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 amdagp8p;AMD NB AGP Bus Filter;c:\windows\system32\drivers\amdagp8p.sys [8/30/2008 12:31 PM 27648]
R0 dontgo;Promise Removable Disk Control Driver;c:\windows\system32\drivers\dontgo.sys [8/30/2008 12:31 PM 7680]
R0 tmagp;Transmeta TM 8000 AGP Filter Driver;c:\windows\system32\drivers\TMAGP.SYS [8/30/2008 12:32 PM 27648]
R0 ULiAGP;ULi AGP Controller Bus Filter Driver;c:\windows\system32\drivers\ULiAGP.SYS [8/30/2008 12:32 PM 33408]
R0 uliagpkx;ULi AGP Bus Filter Driver;c:\windows\system32\drivers\AGPKX.SYS [8/30/2008 12:31 PM 45056]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [11/22/2011 12:18 PM 36000]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [11/22/2011 1:10 PM 86224]
R2 AntiVirWebService;Avira Web Protection;c:\program files\Avira\AntiVir Desktop\avwebgrd.exe [11/22/2011 1:10 PM 463824]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe [11/21/2011 7:28 PM 81920]
R2 HOSTNT;Hostnt;c:\windows\system32\drivers\hostnt.sys [11/21/2011 7:46 PM 4032]
R2 MHDRV;Mhdrv;c:\windows\system32\drivers\mhdrv.sys [11/21/2011 7:46 PM 27696]
R2 RCMHDOG;RCMHDOG;c:\windows\system32\drivers\rcmhdog.sys [11/21/2011 7:46 PM 26060]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe [11/21/2011 7:28 PM 2732032]
S0 hptpro;hptpro;c:\windows\system32\drivers\hptpro.sys [8/30/2008 12:31 PM 9809]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/22/2011 10:24 AM 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [11/22/2011 10:24 AM 136176]
.
‘计划任务’ 文件夹 里的内容
.
2011-11-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-11-22 02:24]
.
2011-11-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-11-22 02:24]
.
2011-11-25 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2011-11-20 18:18]
.
2011-11-25 c:\windows\Tasks\User_Feed_Synchronization-{494232BA-F10B-4C2D-910D-DD06DB7D7733}.job
- c:\windows\system32\msfeedssync.exe [2009-03-07 20:31]
.
.
------- 而外的扫描 -------
.
uStart Page = hxxp://www.ask.com/?l=dis&o=APN10023&gct=hp
uInternet Connection Wizard,ShellNext = hxxp://www.firebirdsql.org//afterinstall
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Search the Web - c:\program files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 124.106.5.2 124.106.6.2
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\obpr90mx.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://home.sweetim.com
FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype Click to Call: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - Ext: Avira SearchFree Toolbar plus Web Protection:
toolbar@ask.com - %profile%\extensions\toolbar@ask.com
FF - Ext: SweetIM Toolbar for Firefox: {EEE6C361-6118-11DC-9C72-001320C79847} - %profile%\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-11-25 11:11
Windows 5.1.2600 Service Pack 3 NTFS
.
扫描被隐藏的进程 。。。
.
扫描被隐藏的启动组 。。。
.
扫描被隐藏的文件 。。。
.
扫描完成
被隐藏的档案: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1757981266-113007714-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,21,6b,12,05,0e,63,54,48,be,53,c8,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,21,6b,12,05,0e,63,54,48,be,53,c8,\
.
--------------------- 运行进程下的动态链接库 ---------------------
.
- - - - - - - > 'lsass.exe'(772)
c:\program files\Avira\AntiVir Desktop\avsda.dll
.
- - - - - - - > 'explorer.exe'(1016)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
完成时间: 2011-11-25 11:11:52
ComboFix-quarantined-files.txt 2011-11-25 03:11
ComboFix2.txt 2011-11-25 02:22
ComboFix3.txt 2011-11-23 03:01
ComboFix4.txt 2011-11-23 01:59
ComboFix5.txt 2011-11-25 03:09
.
Pre-Run: 125,197,451,264 bytes free
Post-Run: 125,183,225,856 bytes free
.
- - End Of File - - 10D2F0A6B2790DFDB3A3D1A692E0C823