paulcheung
Active Member
Hi John,
When I run the combofix. the top of the windows said, c: administrator. Combofix find 3M. what is that mean? does it find a virus or malware?
Thank you.
Thia is the new combo fix log just re-run after I use cccleaner delete any thing at all it can delete.
ComboFix 10-09-01.04 - Ken-Chun Cheung 09/02/2010 23:14:23.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3454.2576 [GMT -5:00]
Running from: c:\users\Ken-Chun Cheung\Downloads\ComboFix.exe
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
.
((((((((((((((((((((((((( Files Created from 2010-08-03 to 2010-09-03 )))))))))))))))))))))))))))))))
.
2010-09-03 04:19 . 2010-09-03 04:19 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-03 04:19 . 2010-09-03 04:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-03 04:13 . 2010-09-03 04:13 -------- d-----w- C:\32788R22FWJFW
2010-09-03 03:57 . 2010-09-03 03:57 -------- d-----w- c:\program files\CCleaner
2010-09-03 02:47 . 2010-09-03 04:19 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Local\temp
2010-09-02 19:19 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-02 19:19 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-02 17:36 . 2009-05-26 16:43 1710392 ------w- c:\programdata\HP\Installer\Temp\hpzmsi01.exe
2010-09-02 17:36 . 2009-05-21 15:12 121344 ------w- c:\programdata\HP\Installer\Temp\hpqrrx08.exe
2010-09-02 12:18 . 2010-09-02 12:18 -------- d-----w- c:\windows\system32\Wat
2010-09-02 05:36 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-09-02 05:35 . 2009-11-25 17:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-09-02 05:35 . 2009-11-25 17:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-09-02 05:35 . 2009-11-25 17:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-09-02 05:35 . 2009-11-25 17:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-09-02 05:35 . 2009-11-25 17:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-09-02 05:28 . 2010-03-04 07:33 740864 ----a-w- c:\windows\system32\inetcomm.dll
2010-09-02 05:23 . 2010-09-02 05:23 388096 ----a-r- c:\users\Ken-Chun Cheung\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-02 05:21 . 2009-10-31 05:45 2614272 ----a-w- c:\windows\explorer.exe
2010-09-02 05:21 . 2009-10-28 06:17 285696 ----a-w- c:\windows\system32\winlogon.exe
2010-09-02 05:21 . 2009-08-29 06:57 34816 ----a-w- c:\windows\system32\msasn1.dll
2010-09-02 05:19 . 2009-10-02 04:06 728648 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2010-09-02 05:19 . 2009-09-03 07:04 1320960 ----a-w- c:\windows\system32\CertEnroll.dll
2010-09-02 05:19 . 2009-08-19 07:20 442920 ----a-w- c:\windows\system32\winresume.exe
2010-09-02 05:19 . 2009-08-19 07:20 507568 ----a-w- c:\windows\system32\winload.exe
2010-09-02 05:19 . 2009-08-29 06:54 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-09-02 05:16 . 2010-07-29 06:30 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-09-02 05:16 . 2010-07-29 06:30 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-09-02 05:15 . 2010-06-19 06:23 37376 ----a-w- c:\windows\system32\rtutils.dll
2010-09-02 05:15 . 2010-06-08 06:02 1233920 ----a-w- c:\windows\system32\msxml3.dll
2010-09-02 05:10 . 2010-06-22 02:47 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-09-02 05:10 . 2010-06-22 02:47 307200 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-09-02 05:10 . 2010-06-22 02:47 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-09-02 05:09 . 2009-12-08 11:40 3955288 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-09-02 05:09 . 2009-12-08 11:40 3899464 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-09-02 05:09 . 2009-12-08 11:32 292864 ----a-w- c:\windows\system32\apphelp.dll
2010-09-01 03:53 . 2010-09-02 02:38 2048 ----a-w- C:\Uninstall.dat
2010-09-01 03:49 . 2010-09-01 03:49 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\Malwarebytes
2010-09-01 03:49 . 2010-09-01 03:49 -------- d-----w- c:\programdata\Malwarebytes
2010-09-01 03:49 . 2010-09-02 19:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-01 02:57 . 2010-09-01 02:57 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\FXTS2
2010-08-21 04:08 . 2010-08-21 04:08 -------- d-----w- c:\program files\CPUID
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-02 19:44 . 2010-06-14 03:19 131728 ----a-w- c:\users\Ken-Chun Cheung\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-02 19:22 . 2010-04-29 12:13 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\vlc
2010-09-02 18:08 . 2010-03-16 12:38 -------- d-----w- c:\program files\HP
2010-09-02 18:06 . 2009-01-28 21:18 -------- d-----w- c:\program files\Yahoo!
2010-09-02 18:02 . 2008-02-21 00:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-02 18:02 . 2008-02-21 01:52 -------- d-----w- c:\programdata\Napster
2010-09-02 17:55 . 2008-02-21 01:54 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-09-02 17:52 . 2010-06-16 05:19 -------- d-----w- c:\programdata\Norton
2010-09-02 17:36 . 2008-05-22 21:38 -------- d-----w- c:\program files\321Studios
2010-09-02 17:16 . 2009-07-14 02:37 -------- d-----w- c:\program files\Windows Mail
2010-09-02 05:36 . 2008-02-24 01:11 -------- d-----w- c:\programdata\Microsoft Help
2010-09-02 05:08 . 2010-09-01 04:06 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-09-02 05:08 . 2010-09-02 05:08 52224 ----a-w- c:\users\Ken-Chun Cheung\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-09-02 05:08 . 2010-09-02 05:08 63488 ----a-w- c:\users\Ken-Chun Cheung\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-09-02 05:08 . 2010-09-02 05:08 117760 ----a-w- c:\users\Ken-Chun Cheung\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-09-02 04:35 . 2009-06-12 04:21 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\dvdcss
2010-09-02 04:35 . 2008-06-03 05:04 -------- d-----w- c:\programdata\Nero
2010-09-02 04:35 . 2008-02-24 01:16 -------- d-----w- c:\program files\Microsoft Works
2010-09-02 04:35 . 2008-06-03 05:04 -------- d-----w- c:\program files\Common Files\Nero
2010-09-02 04:35 . 2008-02-21 00:40 -------- d-----w- c:\program files\Common Files\InstallShield
2010-09-02 04:35 . 2010-06-16 19:39 -------- d-----w- c:\program files\Ask.com
2010-09-02 04:35 . 2010-06-16 01:13 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\mjusbsp
2010-09-02 04:35 . 2010-06-16 19:38 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\uTorrent
2010-09-02 04:30 . 2008-06-03 05:04 -------- d-----w- c:\program files\Nero
2010-09-02 01:51 . 2010-09-02 01:51 -------- d-----w- c:\program files\Trend Micro
2010-09-01 04:25 . 2010-07-29 03:11 -------- d-----w- c:\program files\Wipeer
2010-09-01 04:06 . 2010-09-01 04:06 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\SUPERAntiSpyware.com
2010-09-01 04:06 . 2010-09-01 04:06 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-08-22 04:08 . 2008-05-23 22:07 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\TOSHIBA
2010-07-29 03:11 . 2010-07-29 03:11 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\WiPeer
2010-06-19 04:07 . 2010-09-02 04:59 2326016 ----a-w- c:\windows\system32\win32k.sys
2010-06-16 05:48 . 2010-09-02 05:08 224256 ----a-w- c:\windows\system32\schannel.dll
2010-06-14 06:12 . 2010-09-02 05:18 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-06-13 22:52 . 2010-06-13 22:52 21316 ----a-w- c:\windows\system32\emptyregdb.dat
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2008-05-22 18:00 . 2008-05-22 18:00 14 --sha-r- c:\windows\System32\drivers\fbd.sys
2008-05-22 18:00 . 2008-05-22 18:00 5 --sha-r- c:\windows\System32\drivers\taishop.sys
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-01-24 4363504]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-08-25 2424560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-09-11 180224]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-30 4911104]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-29 75136]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-23 438272]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456]
c:\users\Ken-Chun Cheung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Lotus Organizer EasyClip.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Lotus Organizer EasyClip.lnk
backup=c:\windows\pss\Lotus Organizer EasyClip.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Lotus QuickStart.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Lotus QuickStart.lnk
backup=c:\windows\pss\Lotus QuickStart.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-09-20 20:35 202024 ----a-w- c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 20:57 153136 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Net-It Launcher]
1998-02-06 00:16 24576 ----a-w- c:\windows\System32\NILaunch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-03-29 04:37 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"StartCCC"=c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwf.sys [2007-09-01 20352]
R3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [2007-10-30 937984]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-02 1343400]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2007-12-25 40960]
S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-04 126976]
--- Other Services/Drivers In Memory ---
*Deregistered* - EraserUtilRebootDrv
*Deregistered* - SYMDNS
*Deregistered* - SymEvent
*Deregistered* - SYMFW
*Deregistered* - SYMIDS
*Deregistered* - SYMREDRV
*Deregistered* - SYMTDI
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder
2008-05-23 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 16:20]
.
.
------- Supplementary Scan -------
.
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-09-02 23:21:49
ComboFix-quarantined-files.txt 2010-09-03 04:21
ComboFix2.txt 2010-09-03 02:58
ComboFix3.txt 2010-09-01 12:35
Pre-Run: 37,686,296,576 bytes free
Post-Run: 37,662,273,536 bytes free
- - End Of File - - 1449E08161758D58EE7129FB25FD721B
When I run the combofix. the top of the windows said, c: administrator. Combofix find 3M. what is that mean? does it find a virus or malware?
Thank you.
Thia is the new combo fix log just re-run after I use cccleaner delete any thing at all it can delete.
ComboFix 10-09-01.04 - Ken-Chun Cheung 09/02/2010 23:14:23.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3454.2576 [GMT -5:00]
Running from: c:\users\Ken-Chun Cheung\Downloads\ComboFix.exe
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
.
((((((((((((((((((((((((( Files Created from 2010-08-03 to 2010-09-03 )))))))))))))))))))))))))))))))
.
2010-09-03 04:19 . 2010-09-03 04:19 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-09-03 04:19 . 2010-09-03 04:19 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-09-03 04:13 . 2010-09-03 04:13 -------- d-----w- C:\32788R22FWJFW
2010-09-03 03:57 . 2010-09-03 03:57 -------- d-----w- c:\program files\CCleaner
2010-09-03 02:47 . 2010-09-03 04:19 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Local\temp
2010-09-02 19:19 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-02 19:19 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-02 17:36 . 2009-05-26 16:43 1710392 ------w- c:\programdata\HP\Installer\Temp\hpzmsi01.exe
2010-09-02 17:36 . 2009-05-21 15:12 121344 ------w- c:\programdata\HP\Installer\Temp\hpqrrx08.exe
2010-09-02 12:18 . 2010-09-02 12:18 -------- d-----w- c:\windows\system32\Wat
2010-09-02 05:36 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2010-09-02 05:35 . 2009-11-25 17:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-09-02 05:35 . 2009-11-25 17:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-09-02 05:35 . 2009-11-25 17:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-09-02 05:35 . 2009-11-25 17:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-09-02 05:35 . 2009-11-25 17:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-09-02 05:28 . 2010-03-04 07:33 740864 ----a-w- c:\windows\system32\inetcomm.dll
2010-09-02 05:23 . 2010-09-02 05:23 388096 ----a-r- c:\users\Ken-Chun Cheung\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-02 05:21 . 2009-10-31 05:45 2614272 ----a-w- c:\windows\explorer.exe
2010-09-02 05:21 . 2009-10-28 06:17 285696 ----a-w- c:\windows\system32\winlogon.exe
2010-09-02 05:21 . 2009-08-29 06:57 34816 ----a-w- c:\windows\system32\msasn1.dll
2010-09-02 05:19 . 2009-10-02 04:06 728648 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2010-09-02 05:19 . 2009-09-03 07:04 1320960 ----a-w- c:\windows\system32\CertEnroll.dll
2010-09-02 05:19 . 2009-08-19 07:20 442920 ----a-w- c:\windows\system32\winresume.exe
2010-09-02 05:19 . 2009-08-19 07:20 507568 ----a-w- c:\windows\system32\winload.exe
2010-09-02 05:19 . 2009-08-29 06:54 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-09-02 05:16 . 2010-07-29 06:30 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-09-02 05:16 . 2010-07-29 06:30 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-09-02 05:15 . 2010-06-19 06:23 37376 ----a-w- c:\windows\system32\rtutils.dll
2010-09-02 05:15 . 2010-06-08 06:02 1233920 ----a-w- c:\windows\system32\msxml3.dll
2010-09-02 05:10 . 2010-06-22 02:47 310784 ----a-w- c:\windows\system32\drivers\srv.sys
2010-09-02 05:10 . 2010-06-22 02:47 307200 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-09-02 05:10 . 2010-06-22 02:47 113664 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-09-02 05:09 . 2009-12-08 11:40 3955288 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-09-02 05:09 . 2009-12-08 11:40 3899464 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-09-02 05:09 . 2009-12-08 11:32 292864 ----a-w- c:\windows\system32\apphelp.dll
2010-09-01 03:53 . 2010-09-02 02:38 2048 ----a-w- C:\Uninstall.dat
2010-09-01 03:49 . 2010-09-01 03:49 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\Malwarebytes
2010-09-01 03:49 . 2010-09-01 03:49 -------- d-----w- c:\programdata\Malwarebytes
2010-09-01 03:49 . 2010-09-02 19:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-01 02:57 . 2010-09-01 02:57 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\FXTS2
2010-08-21 04:08 . 2010-08-21 04:08 -------- d-----w- c:\program files\CPUID
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-02 19:44 . 2010-06-14 03:19 131728 ----a-w- c:\users\Ken-Chun Cheung\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-02 19:22 . 2010-04-29 12:13 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\vlc
2010-09-02 18:08 . 2010-03-16 12:38 -------- d-----w- c:\program files\HP
2010-09-02 18:06 . 2009-01-28 21:18 -------- d-----w- c:\program files\Yahoo!
2010-09-02 18:02 . 2008-02-21 00:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-02 18:02 . 2008-02-21 01:52 -------- d-----w- c:\programdata\Napster
2010-09-02 17:55 . 2008-02-21 01:54 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-09-02 17:52 . 2010-06-16 05:19 -------- d-----w- c:\programdata\Norton
2010-09-02 17:36 . 2008-05-22 21:38 -------- d-----w- c:\program files\321Studios
2010-09-02 17:16 . 2009-07-14 02:37 -------- d-----w- c:\program files\Windows Mail
2010-09-02 05:36 . 2008-02-24 01:11 -------- d-----w- c:\programdata\Microsoft Help
2010-09-02 05:08 . 2010-09-01 04:06 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-09-02 05:08 . 2010-09-02 05:08 52224 ----a-w- c:\users\Ken-Chun Cheung\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-09-02 05:08 . 2010-09-02 05:08 63488 ----a-w- c:\users\Ken-Chun Cheung\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-09-02 05:08 . 2010-09-02 05:08 117760 ----a-w- c:\users\Ken-Chun Cheung\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-09-02 04:35 . 2009-06-12 04:21 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\dvdcss
2010-09-02 04:35 . 2008-06-03 05:04 -------- d-----w- c:\programdata\Nero
2010-09-02 04:35 . 2008-02-24 01:16 -------- d-----w- c:\program files\Microsoft Works
2010-09-02 04:35 . 2008-06-03 05:04 -------- d-----w- c:\program files\Common Files\Nero
2010-09-02 04:35 . 2008-02-21 00:40 -------- d-----w- c:\program files\Common Files\InstallShield
2010-09-02 04:35 . 2010-06-16 19:39 -------- d-----w- c:\program files\Ask.com
2010-09-02 04:35 . 2010-06-16 01:13 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\mjusbsp
2010-09-02 04:35 . 2010-06-16 19:38 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\uTorrent
2010-09-02 04:30 . 2008-06-03 05:04 -------- d-----w- c:\program files\Nero
2010-09-02 01:51 . 2010-09-02 01:51 -------- d-----w- c:\program files\Trend Micro
2010-09-01 04:25 . 2010-07-29 03:11 -------- d-----w- c:\program files\Wipeer
2010-09-01 04:06 . 2010-09-01 04:06 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\SUPERAntiSpyware.com
2010-09-01 04:06 . 2010-09-01 04:06 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-08-22 04:08 . 2008-05-23 22:07 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\TOSHIBA
2010-07-29 03:11 . 2010-07-29 03:11 -------- d-----w- c:\users\Ken-Chun Cheung\AppData\Roaming\WiPeer
2010-06-19 04:07 . 2010-09-02 04:59 2326016 ----a-w- c:\windows\system32\win32k.sys
2010-06-16 05:48 . 2010-09-02 05:08 224256 ----a-w- c:\windows\system32\schannel.dll
2010-06-14 06:12 . 2010-09-02 05:18 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-06-13 22:52 . 2010-06-13 22:52 21316 ----a-w- c:\windows\system32\emptyregdb.dat
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2008-05-22 18:00 . 2008-05-22 18:00 14 --sha-r- c:\windows\System32\drivers\fbd.sys
2008-05-22 18:00 . 2008-05-22 18:00 5 --sha-r- c:\windows\System32\drivers\taishop.sys
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-01-24 4363504]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-08-25 2424560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-09-11 180224]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-30 4911104]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704]
"ITSecMng"="c:\program files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe" [2007-09-29 75136]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-03-23 438272]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456]
c:\users\Ken-Chun Cheung\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Lotus Organizer EasyClip.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Lotus Organizer EasyClip.lnk
backup=c:\windows\pss\Lotus Organizer EasyClip.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Lotus QuickStart.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Lotus QuickStart.lnk
backup=c:\windows\pss\Lotus QuickStart.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-09-20 20:35 202024 ----a-w- c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 20:57 153136 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Net-It Launcher]
1998-02-06 00:16 24576 ----a-w- c:\windows\System32\NILaunch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-03-29 04:37 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"StartCCC"=c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwf.sys [2007-09-01 20352]
R3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [2007-10-30 937984]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-09-02 1343400]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2007-12-25 40960]
S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-04 126976]
--- Other Services/Drivers In Memory ---
*Deregistered* - EraserUtilRebootDrv
*Deregistered* - SYMDNS
*Deregistered* - SymEvent
*Deregistered* - SYMFW
*Deregistered* - SYMIDS
*Deregistered* - SYMREDRV
*Deregistered* - SYMTDI
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
.
Contents of the 'Scheduled Tasks' folder
2008-05-23 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 16:20]
.
.
------- Supplementary Scan -------
.
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-09-02 23:21:49
ComboFix-quarantined-files.txt 2010-09-03 04:21
ComboFix2.txt 2010-09-03 02:58
ComboFix3.txt 2010-09-01 12:35
Pre-Run: 37,686,296,576 bytes free
Post-Run: 37,662,273,536 bytes free
- - End Of File - - 1449E08161758D58EE7129FB25FD721B