I follow all the steps you gave me.
So here r the report
btw, thanks for your kind assistances. Hope this fix my pc.
thanks
HijackThisLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:05:06 AM, on 4/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.id/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://appldnld.appl...ex/qtplugin.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1207410668734O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.mi...b?1200753704796O17 - HKLM\System\CCS\Services\Tcpip\..\{3FB5E79B-8419-4B38-8ED3-8237BC5EF01B}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS1\Services\Tcpip\..\{3FB5E79B-8419-4B38-8ED3-8237BC5EF01B}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS2\Services\Tcpip\..\{3FB5E79B-8419-4B38-8ED3-8237BC5EF01B}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CS3\Services\Tcpip\..\{3FB5E79B-8419-4B38-8ED3-8237BC5EF01B}: NameServer = 208.67.222.222,208.67.220.220
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
--
End of file - 5762 bytes
FixwereoutUsername "Bintang" - 04/10/2008 8:58:34 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
"SoundMan"="SOUNDMAN.EXE"
"igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe"
"igfxpers"="C:\\WINDOWS\\system32\\igfxpers.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Uniblue RegistryBooster 2"="C:\\Program Files\\Uniblue\\RegistryBooster 2\\RegistryBooster.exe /S"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"ccleaner"="\"C:\\Program Files\\CCleaner\\CCleaner.exe\" /AUTO"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe\" -quiet"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~
ComboFixComboFix 08-04-08.7 - Bintang 2008-04-10 8:54:53.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.291 [GMT 7:00]
Running from: C:\Documents and Settings\Bintang\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Bintang\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\config.ini
C:\WINDOWS\zysalwhkkw.exe
C:\WINDOWS\zysaoxcjiy.exe
C:\WINDOWS\zysapghucv.exe
C:\WINDOWS\zysaxyczld.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\config.ini
C:\WINDOWS\zysalwhkkw.exe
C:\WINDOWS\zysaoxcjiy.exe
C:\WINDOWS\zysapghucv.exe
C:\WINDOWS\zysaxyczld.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-10 to 2008-04-10 )))))))))))))))))))))))))))))))
.
2008-04-10 08:47 . 2008-04-10 08:47 <DIR> d-------- C:\WINDOWS\LastGood
2008-04-08 15:55 . 2008-04-08 15:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-08 14:18 . 2008-04-08 14:18 <DIR> d----c--- C:\VundoFix Backups
2008-04-08 13:26 . 2008-04-08 13:26 <DIR> d-------- C:\Documents and Settings\Bintang\Application Data\InstallShield
2008-04-07 20:35 . 2008-04-07 20:35 <DIR> d-------- C:\Documents and Settings\Bintang\Application Data\ACD Systems
2008-04-07 12:31 . 2008-04-07 12:31 50 --a------ C:\WINDOWS\cdplayer.ini
2008-04-07 02:32 . 2008-04-07 02:32 <DIR> d-------- C:\Program Files\Common Files\Scanner
2008-04-07 02:32 . 2008-04-07 02:36 <DIR> d-------- C:\Program Files\CA Yahoo! Anti-Spy
2008-04-07 01:08 . 2008-04-07 01:08 <DIR> d-------- C:\WINDOWS\system32\3com_dmi
2008-04-07 00:48 . 2008-04-07 00:48 13,414 --a------ C:\WINDOWS\cc_20080407_0048.reg
2008-04-06 19:27 . 2008-04-07 14:06 <DIR> d-------- C:\Program Files\Doctor Spyware Cleaner
2008-04-06 18:36 . 2005-09-20 10:31 135,168 --a------ C:\WINDOWS\system32\igfxres.dll
2008-04-06 18:33 . 2004-08-03 22:04 156,672 --a--c--- C:\WINDOWS\system32\dllcache\winzm.ime
2008-04-06 18:33 . 2004-08-03 22:04 156,672 --a--c--- C:\WINDOWS\system32\dllcache\winsp.ime
2008-04-06 18:33 . 2004-08-03 22:04 156,672 --a--c--- C:\WINDOWS\system32\dllcache\winpy.ime
2008-04-06 18:33 . 2004-08-03 22:04 65,536 --a--c--- C:\WINDOWS\system32\dllcache\winime.ime
2008-04-06 18:33 . 2001-08-23 19:00 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
2008-04-06 18:31 . 2001-08-23 19:00 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-04-06 18:30 . 2001-08-23 19:00 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-04-06 18:28 . 2008-04-06 18:28 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-04-06 18:27 . 2008-04-06 18:27 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-04-06 18:27 . 2008-04-06 18:27 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-04-06 18:27 . 2008-04-06 18:27 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-04-06 18:27 . 2008-04-06 18:27 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-04-06 18:27 . 2008-04-06 18:27 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-04-06 18:22 . 2004-08-03 22:31 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys
2008-04-06 16:35 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-04-06 16:15 . 2008-04-06 16:15 <DIR> d-------- C:\Documents and Settings\Bintang\Application Data\XemiComputers
2008-04-06 16:15 . 2008-04-06 16:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\XemiComputers
2008-04-06 16:13 . 2008-04-06 17:41 <DIR> d-------- C:\Program Files\Netcom3 Cleaner
2008-04-06 14:55 . 2008-04-06 14:55 397,214 --a------ C:\WINDOWS\cc_20080406_1454.reg
2008-04-06 14:24 . 2008-04-06 14:25 <DIR> d-------- C:\Program Files\Common Files\ACD Systems
2008-04-06 14:08 . 2008-04-06 18:27 608 --a------ C:\WINDOWS\win.tmp
2008-04-06 14:08 . 2008-04-06 18:19 227 --a------ C:\WINDOWS\system.tmp
2008-04-06 13:09 . 2008-04-06 13:26 <DIR> d-------- C:\Documents and Settings\Bintang\Application Data\Uniblue
2008-04-06 01:19 . 2008-04-06 01:19 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-06 01:19 . 2008-04-07 08:00 <DIR> d-------- C:\Documents and Settings\Bintang\Application Data\AVG7
2008-04-05 23:46 . 2008-04-05 23:49 <DIR> d-------- C:\kav
2008-04-05 22:39 . 2008-04-05 22:39 <DIR> d---s---- C:\Documents and Settings\Bintang\UserData
2008-04-05 22:22 . 2008-04-05 22:22 0 --a------ C:\WINDOWS\frontpg.ini
2008-04-05 22:21 . 2008-04-05 22:21 <DIR> d-------- C:\WINDOWS\IIS Temporary Compressed Files
2008-04-05 22:18 . 2001-08-23 19:00 2,178,131 --a--c--- C:\WINDOWS\system32\dllcache\shvlres.dll
2008-04-05 22:17 . 2001-08-23 19:00 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2008-04-05 22:16 . 2004-08-03 23:56 2,134,528 --a--c--- C:\WINDOWS\system32\dllcache\smtpsnap.dll
2008-04-05 22:15 . 2008-04-05 22:24 <DIR> d-------- C:\Inetpub
2008-04-05 19:58 . 2008-04-05 19:58 <DIR> d-------- C:\Documents and Settings\Bintang\Application Data\Yahoo!
2008-04-05 19:34 . 2008-04-05 19:34 <DIR> d-------- C:\Documents and Settings\Bintang\Application Data\PC Tools
2008-04-05 18:44 . 2008-04-05 18:50 <DIR> d-------- C:\Program Files\TweakNow RegCleaner Std
2008-04-05 16:49 . 2008-04-05 16:49 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\PC Tools
2008-04-05 16:35 . 2008-04-05 18:03 <DIR> d-------- C:\Program Files\tuEagles
2008-04-05 16:35 . 2008-04-05 16:35 9,522 --a------ C:\WINDOWS\Retaften.bmp
2008-04-05 16:35 . 2008-04-05 17:31 0 --a------ C:\WINDOWS\system32\drivers\IsDrv118.sys
2008-04-05 14:52 . 2008-04-05 21:08 <DIR> dr-h----- C:\Documents and Settings\All Users\Application Data\yahoo!
2008-04-05 14:27 . 2008-04-07 09:37 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-05 12:49 . 2008-04-05 14:20 <DIR> d-------- C:\Program Files\Common Files\PC Tools
2008-04-05 12:49 . 2008-04-05 12:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-04-05 12:49 . 2008-03-04 17:49 159,112 --a------ C:\WINDOWS\system32\drivers\pctfw2.sys
2008-03-27 22:15 . 2008-03-27 22:19 <DIR> d-------- C:\Program Files\iTrader
2008-03-27 22:06 . 2008-03-29 13:21 <DIR> d-------- C:\iTrader
2008-03-27 22:00 . 2006-12-15 03:09 49,265 --a------ C:\WINDOWS\system32\jpicpl32.cpl
2008-03-27 18:18 . 2008-04-06 17:38 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-13 17:22 . 2008-03-17 22:23 <DIR> d-------- C:\Program Files\Straighthold Trader
2008-03-13 12:19 . 2008-04-03 17:51 <DIR> d-------- C:\Program Files\BIG Trader
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-09 03:39 --------- d-----w C:\Program Files\Norman
2008-04-07 02:04 --------- d-----w C:\Program Files\Uniblue
2008-04-07 02:04 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Uniblue
2008-04-06 07:32 --------- d-----w C:\Program Files\Google
2008-04-06 07:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-04-06 07:24 --------- d-----w C:\Program Files\ACD Systems
2008-04-05 14:09 --------- d-----w C:\Program Files\Yahoo!
2008-04-05 14:05 --------- d-----w C:\Program Files\HP
2008-04-05 14:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-04-05 11:48 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-05 07:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-03 02:55 --------- d-----w C:\Program Files\MetaTrader - Askap
2008-03-27 15:00 --------- d-----w C:\Program Files\Java
2008-03-21 11:20 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Yahoo!
2008-03-11 07:58 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-11 07:56 --------- d-----w C:\Program Files\Foxit
2008-03-09 07:04 --------- d-----w C:\Program Files\Foxit Software
2008-02-29 16:18 --------- d-----w C:\Program Files\Common Files\xing shared
2008-02-29 16:18 --------- d-----w C:\Program Files\Common Files\Real
2008-02-29 16:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-02-29 16:15 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-02-27 15:06 --------- d-----w C:\Documents and Settings\Administrator\Application Data\vlc
2008-02-21 05:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-19 14:46 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2008-01-11 12:57 6,026,816 ----a-w C:\Program Files\Firefox Setup 2.0.0.11.exe
.
((((((((((((((((((((((((((((( snapshot@2008-04-09_10.46.53.03 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-09 03:41:06 8,192 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{D49817FC-298D-4F91-B886-6046A119DEDE}.bin
+ 2008-04-10 01:47:56 3,728 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{D49817FC-298D-4F91-B886-6046A119DEDE}.bin
- 2008-04-09 03:45:46 220,299 ----a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin
+ 2008-04-10 01:46:21 220,297 ----a-w C:\WINDOWS\system32\inetsrv\MetaBase.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-04-06 14:07 171448]
"ccleaner"="C:\Program Files\CCleaner\CCleaner.exe" [ ]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [2005-12-08 13:55 3096576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-12 12:02 286720]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-29 23:18 185632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23 75520]
"SoundMan"="SOUNDMAN.EXE" [2005-10-24 14:45 90112 C:\WINDOWS\soundman.exe]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36 114688]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 12:05:56 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\javaw.exe"=
"C:\\WINDOWS\\explorer.exe"=
"C:\\WINDOWS\\system32\\dllhost.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 pctfw2;pctfw2;C:\WINDOWS\system32\drivers\pctfw2.sys [2008-03-04 17:49]
R2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\system32\inetsrv\inetinfo.exe [2004-08-03 23:56]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [2004-08-03 23:56]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [2004-08-03 23:56]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [2004-08-03 23:56]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [2004-08-03 23:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
"2008-04-02 01:18:00 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-01-11 13:33:57 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2008-04-06 07:09:35 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-10 08:56:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-10 8:56:32
ComboFix-quarantined-files.txt 2008-04-10 01:56:16
ComboFix2.txt 2008-04-09 03:47:58
Pre-Run: 35,741,265,920 bytes free
Post-Run: 35,733,204,992 bytes free
.
2008-04-09 10:17:23 --- E O F ---
Edited by faried, 09 April 2008 - 08:22 PM.