Hi MFDnSC,
sorry I forgot to post the hijack this log...
I just ran combofix again and here's the log:
Ivy - 06-12-06 0:08:03.04 Service Pack 1
ComboFix 06.12.01W - Running from: "C:\Documents and Settings\Ivy\桌面"
((((((((((((((((((((((((((((((( Files Created from 2006-11-06 to 2006-12-06 ))))))))))))))))))))))))))))))))))
2006-12-05 15:38 <DIR> d-------- C:\Documents and Settings\Ivy\Application Data\SUPERAntiSpyware.com
2006-12-05 15:35 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2006-12-05 15:16 <DIR> d-------- C:\WINDOWS\temp
2006-12-05 15:14 <DIR> d-------- C:\WINDOWS\erdnt
2006-12-05 06:52 <DIR> d-------- C:\Documents and Settings\Ivy\Application Data\Uniblue
2006-12-05 02:48 24,322 --a------ C:\WINDOWS\L_xy30.exe
2006-12-01 19:55 25,472 --a------ C:\WINDOWS\system32\drivers\AGP440.SYS
2006-11-29 22:51 <DIR> d-------- C:\Program Files\Mozilla Firefox
2006-11-29 16:53 <DIR> dr-h----- C:\$VAULT$.AVG
2006-11-29 16:51 816,672 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-11-29 16:51 4,224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-11-29 16:51 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys
2006-11-29 16:51 28,416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-11-29 16:51 <DIR> d-------- C:\Program Files\Grisoft
2006-11-29 16:51 <DIR> d-------- C:\Documents and Settings\Ivy\Application Data\AVG7
2006-11-29 15:59 <DIR> d-------- C:\Documents and Settings\Ivy\Application Data\PC Suite
2006-11-29 15:03 <DIR> d-------- C:\WINDOWS\uninstall
2006-11-29 15:03 <DIR> d-------- C:\WINDOWS\Download
2006-11-29 15:03 <DIR> d-------- C:\WINDOWS\down
2006-11-29 15:03 <DIR> d-------- C:\Program Files\Microsoft
2006-11-26 01:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MSN6
2006-11-25 10:56 <DIR> d--hs---- C:\WINDOWS\ftpcache
2006-11-25 10:40 <DIR> d-------- C:\Program Files\DIFX
2006-11-25 10:40 <DIR> d-------- C:\Program Files\Common Files\Nokia
2006-11-25 10:39 8,704 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
2006-11-25 10:39 50,688 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2006-11-25 10:39 4,608 --a------ C:\WINDOWS\system32\nmwcdlog.dll
2006-11-25 10:39 30,720 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2006-11-25 10:39 13,312 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2006-11-25 10:39 13,312 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys
2006-11-25 10:39 127,488 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2006-11-25 10:39 <DIR> d-------- C:\Program Files\Nokia
2006-11-25 10:39 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2006-11-25 10:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Suite
2006-11-25 10:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2006-11-20 23:51 <DIR> d-------- C:\Intel
2006-11-20 03:06 <DIR> d--hs---- C:\FOUND.001
2006-11-18 00:59 9,181 --a------ C:\WINDOWS\system32\E13D94A0.DLL
2006-11-18 00:59 30,814 --a------ C:\WINDOWS\system32\60A72DC0T.EXE
2006-11-18 00:59 26,607 --a------ C:\WINDOWS\system32\60A72DC0.DLL
2006-11-18 00:59 16,523 --a------ C:\WINDOWS\system32\AdsWin.dll
2006-11-18 00:59 <DIR> d--hs---- C:\FOUND.000
2006-11-17 22:26 <DIR> dr------- C:\WINDOWS\Favorites
2006-11-17 13:30 30,814 --a------ C:\WINDOWS\system32\60A72DC0.EXE
2006-11-15 01:13 <DIR> d-------- C:\Program Files\MSN Messenger
2006-11-13 01:58 <DIR> d-------- C:\Program Files\MSN Apps
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-29 23:43 29999 --a------ C:\WINDOWS\system32\PluginENLOG.DLL
2006-11-29 23:43 27790 --a------ C:\WINDOWS\system32\PluginCNLOG.DLL
2006-11-06 23:09 494672 --a------ C:\WINDOWS\system32\alexa.exe
2006-10-19 01:33 -------- d-------- C:\Program Files\eRightSoft
2006-10-19 01:33 -------- d-------- C:\Program Files\AviSynth 2.5
2006-10-13 18:01 -------- d-------- C:\Program Files\WinAVI MP4 Converter
2006-09-28 01:40 908288 -r-hs---- C:\WINDOWS\Hacker.com.cn.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\System32\\ctfmon.exe"
"SUPERAntiSpyware"="D:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"PHIME2002ASync"="C:\\WINDOWS\\System32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"PHIME2002A"="C:\\WINDOWS\\System32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
"ItMonitor"="C:\\WINDOWS\\WASAY\\MONITOR.EXE"
"IMEKRMIG6.1"="C:\\WINDOWS\\ime\\imkr6_1\\IMEKRMIG.EXE"
"MSPY2002"="C:\\WINDOWS\\System32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb09.exe"
"SoundMan"="SOUNDMAN.EXE"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Easy-PrintToolBox"="C:\\Program Files\\Canon\\Easy-PrintToolBox\\BJPSMAIN.EXE /logon"
"PCSuiteTrayApplication"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\LAUNCH~1.EXE -startup"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="目前的首頁"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,12,03,00,00,23,00,00,00,dc,00,00,00,d2,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\System32\\ctfmon.exe"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\System32\\ctfmon.exe"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{F7A67C5F-7C5F-7A60-5F7A-C5FA6C5F7A60}"=""
"{AF7AA607-607C-7C60-5F7A-C5C5FA607C7A}"=""
"{1A404685-7563-4d02-B0F6-58B308A406A9}"=""
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"AdobePDF"="{D92D666A-0F7B-5892-A7E8-29340333F07E}"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Completion time: 06-12-06 0:14:12.95
C:\ComboFix3.txt ... 06-12-05 14:59
C:\ComboFix2.txt ... 06-12-05 15:23
C:\ComboFix.txt ... 06-12-06 00:14
and then I ran hijack this and got this log:
Logfile of HijackThis v1.99.1
Scan saved at 12:56:01 AM, on 12/6/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\Com\LSASS.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\WINDOWS\System32\conime.exe
D:\Program Files\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\zh-tw\msntb.dll
O3 - Toolbar: |?-μ?÷(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\zh-tw\msntb.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ItMonitor] C:\WINDOWS\WASAY\MONITOR.EXE
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O16 - DPF: i.Game MJImpressYHK -
http://202.43.223.14...JImpressYHK.cabO16 - DPF: {3AC7F64E-6154-47B0-82B5-764ED4077F77} (DataStorage Class) -
http://txn.hkjc.com/.../HKJCSecKey.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1160929999484O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1160929935031O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) -
http://us.dl1.yimg.c...ropper1_7us.cabO16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} (pCastPanel Class) -
http://itv.5qzone.ne...82_20060329.cabO18 - Protocol: ipp - (no CLSID) - (no file)
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O21 - SSODL: AdobePDF - {D92D666A-0F7B-5892-A7E8-29340333F07E} - "C:\Program Files\Internet Explorer\PLUGINS\nppdf.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
so what should I do next?