basically i have the same problem as use Hilary had.
here is my COMBFIX LOG...please help...thanks in advance
=======================================
ComboFix 09-03-04.01 - Michael 2009-03-04 23:01:39.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.950.1.1033.18.1535.896 [GMT -8:00]
執行位置: c:\documents and settings\Michael\Desktop\ComboFix.exe
AV: NOD32防毒系統 2.51 *On-access scanning enabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
* 成功創造新還原點
* Resident AV is active
注意 - 這台電腦沒有安裝恢復控制台 !!
.
((((((((((((((((((((((((((((((((((((((( 被刪除的檔案 )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Michael\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
----- BITS: Possible infected sites -----
hxxp://vestepau.cn
.
((((((((((((((((((((((((( 2009-02-05 至 2009-03-05 的新的檔案 )))))))))))))))))))))))))))))))
.
2009-03-04 22:42 . 2009-03-04 22:42 <DIR> d-------- c:\program files\a-squared Free
2009-03-02 18:53 . 2008-04-13 17:12 26,112 --a------ c:\windows\system32\stu2.exe
2009-02-28 22:41 . 2009-02-28 22:41 <DIR> d-------- c:\program files\FormatFactory
2009-02-28 22:41 . 2009-02-28 22:41 <DIR> d-------- c:\documents and settings\Michael\Application Data\Desktopicon
2009-02-27 23:54 . 2009-02-27 23:54 <DIR> d-------- C:\Downloads
2009-02-20 17:33 . 2009-02-20 17:33 <DIR> d-------- c:\program files\7-Zip
2009-02-16 18:06 . 2008-04-13 11:45 26,112 --a------ c:\windows\system32\drivers\usbser.sys
2009-02-16 18:06 . 2008-04-13 11:45 26,112 --a------ c:\windows\system32\dllcache\usbser.sys
2009-02-16 18:06 . 2009-02-16 18:06 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-02-16 18:06 . 2009-02-16 18:06 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2009-02-16 18:02 . 2009-02-16 18:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Suite
2009-02-15 22:43 . 2009-02-15 22:43 664 --a------ c:\windows\system32\d3d9caps.dat
2009-02-15 22:40 . 2009-02-15 22:40 <DIR> d-------- c:\program files\Windows Media Connect 2
2009-02-15 22:27 . 2009-02-15 22:27 <DIR> d-------- c:\program files\MSXML 6.0
2009-02-15 22:27 . 2009-02-15 22:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\Installations
2009-02-15 22:25 . 2009-02-15 22:25 <DIR> d-------- c:\program files\Common Files\muvee Technologies
2009-02-15 22:24 . 2009-02-15 22:24 <DIR> d-------- c:\windows\Globalization
2009-02-15 22:24 . 2009-02-15 22:24 <DIR> d-------- c:\program files\Common Files\Nokia
2009-02-15 22:24 . 2009-02-15 22:24 <DIR> d-------- c:\documents and settings\Michael\Application Data\Nokia
2009-02-15 22:23 . 2009-02-15 22:23 <DIR> d-------- c:\program files\Nokia
2009-02-15 22:23 . 2009-02-15 22:23 <DIR> d-------- c:\program files\DIFX
2009-02-15 22:23 . 2009-02-15 22:23 <DIR> d-------- c:\program files\Common Files\PCSuite
2009-02-15 22:23 . 2009-02-15 22:23 <DIR> d-------- c:\documents and settings\Michael\Application Data\PC Suite
2009-02-15 22:23 . 2007-11-29 10:33 1,419,232 --a------ c:\windows\system32\wdfcoinstaller01005.dll
2009-02-15 22:23 . 2007-11-29 10:39 95,744 --a------ c:\windows\system32\nmwcdcocls.dll
2009-02-15 22:23 . 2007-11-29 10:32 48,128 --a------ c:\windows\system32\nmwcdcls.dll
2009-02-15 22:23 . 2007-09-17 14:53 21,632 --a------ c:\windows\system32\drivers\pccsmcfd.sys
2009-02-15 22:23 . 2007-11-29 10:39 19,328 --a------ c:\windows\system32\drivers\ccdcmbo.sys
2009-02-15 22:23 . 2007-11-29 10:39 16,896 --a------ c:\windows\system32\drivers\ccdcmb.sys
2009-02-15 22:23 . 2007-11-29 10:39 8,064 --a------ c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-02-15 22:23 . 2007-11-29 10:39 8,064 --a------ c:\windows\system32\drivers\usbser_lowerflt.sys
2009-02-15 22:22 . 2009-02-15 22:22 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-02-15 22:15 . 2009-02-15 22:15 <DIR> d-------- c:\program files\MSBuild
2009-02-15 22:14 . 2009-02-15 22:14 <DIR> d-------- c:\windows\system32\XPSViewer
2009-02-15 22:13 . 2009-02-15 22:13 <DIR> d-------- c:\program files\Reference Assemblies
2009-02-15 22:13 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll
2009-02-07 22:06 . 2008-04-13 11:45 32,128 --a------ c:\windows\system32\drivers\usbccgp.sys
2009-02-07 22:06 . 2008-04-13 11:45 32,128 --a------ c:\windows\system32\dllcache\usbccgp.sys
2009-02-07 22:06 . 2008-04-13 11:39 14,592 --a------ c:\windows\system32\drivers\kbdhid.sys
2009-02-07 22:06 . 2008-04-13 11:39 14,592 --a------ c:\windows\system32\dllcache\kbdhid.sys
2009-02-07 22:06 . 2008-04-13 11:45 10,368 --a------ c:\windows\system32\drivers\hidusb.sys
2009-02-07 22:06 . 2008-04-13 11:45 10,368 --a------ c:\windows\system32\dllcache\hidusb.sys
.
(((((((((((((((((((((((((((((((((((((((( 在三個月內被修改的檔案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-03 02:53 17,920 ----a-w c:\windows\system32\userinit.exe
2009-01-21 03:27 502,368 ----a-w c:\windows\system32\drivers\amon.sys
2009-01-21 03:27 270,336 ----a-w c:\windows\system32\imon.dll
2009-01-21 03:27 --------- d-----w c:\program files\Eset
2009-01-21 03:18 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-21 03:18 --------- d-----w c:\documents and settings\Michael\Application Data\Malwarebytes
2009-01-21 03:18 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-21 02:38 --------- d-----w c:\program files\ATS2
2009-01-21 02:13 --------- d-----w c:\program files\BeatTrojan2008
2009-01-21 01:56 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-01-17 05:35 3,594,752 ----a-w c:\windows\system32\dllcache\mshtml.dll
2009-01-15 00:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-15 00:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-12-19 09:10 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ----a-w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2008-12-11 10:57 333,952 ------w c:\windows\system32\dllcache\srv.sys
2008-12-07 23:22 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-09-17 04:49 358 ----a-w c:\program files\Shortcut to Skype.lnk
2008-02-28 04:13 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2008-07-30 05:42 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008072920080730\index.dat
.
------- Sigcheck -------
2009-03-02 18:53 17920 3d2deea032afd945261542b345733a5f c:\windows\system32\userinit.exe
2004-08-04 20:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\$NtServicePackUninstall$\userinit.exe
2008-04-13 17:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\ServicePackFiles\i386\userinit.exe
.
((((((((((((((((((((((((((((((((((((( 重要登入點 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白與合法缺省登錄將不會被顯示
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Secure Disks]
@="{666C7836-A9B6-4AB4-94ED-DC238C81E925}"
[HKEY_CLASSES_ROOT\CLSID\{666C7836-A9B6-4AB4-94ED-DC238C81E925}]
2006-04-02 17:08 381952 -ra------ c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\SFSShell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-01-19 4670968]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2008-07-21 2752512]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-01-20 342848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"HControl"="c:\windows\ATK0100\HControl.exe" [2006-02-23 106496]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-02-08 7405568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-02-08 86016]
"ASUS Live Update"="c:\program files\ASUS\ASUS Live Update\ALU.exe" [2006-02-21 180224]
"CognizanceTS"="c:\progra~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll" [2003-12-22 17920]
"Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
"ACMON"="c:\program files\ASUS\Splendid\ACMON.exe" [2006-05-30 811008]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-25 786521]
"ABLKSR"="c:\windows\ABLKSR\ABLKSR.exe" [2006-01-03 61440]
"Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-14 90112]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-02 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-02 696320]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"RemoteControl"="c:\program files\ASUSTek\ASUSDVD\PDVDServ.exe" [2005-01-12 32768]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-10-11 180269]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-07 136600]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="c:\program files\K-Lite Codec Pack\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-10 289064]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2008-07-22 909392]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2008-07-17 177448]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-01-20 921600]
"nwiz"="nwiz.exe" [2006-02-08 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-13 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
"SMSERIAL"="sm56hlpr.exe" [2006-01-19 c:\windows\sm56hlpr.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
MultiFrame.lnk - c:\program files\ASUS\Asus MultiFrame\MultiFrame.exe [2007-02-03 491520]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-06-07 553021]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Nokia Nseries PC Suite.lnk - c:\program files\Nokia\NNPCS\RunLauncher.exe [2008-05-08 943568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
2006-05-02 22:23 40448 c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
2006-03-10 08:20 434176 c:\windows\system32\IfxWlxEN.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=APSHook.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli ASWLNPkg
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 17:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-12-26 20:48 1410296 c:\program files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\FreeStyle\\FSLauncher.exe"=
"c:\\Program Files\\Steam\\SteamApps\\formula_zero\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
R1 ItSDisk;ItSDisk;c:\windows\system32\drivers\itsdisk.sys [2006-05-16 17840]
R1 PersonalSecureDrive;PersonalSecureDrive;c:\windows\system32\drivers\psd.sys [2005-11-29 36768]
R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Cognizance [2004-08-20 14336]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2008-07-17 161064]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-08-27 24652]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2007-02-03 36352]
S2 BeatTrojanHelperOne;BeatTrojanHelperOne;\??\c:\program files\BeatTrojan2008\BeatTrojanHelperOne.sys --> c:\program files\BeatTrojan2008\BeatTrojanHelperOne.sys [?]
S2 木馬清除大師即時監控;木馬清除大師即時監控; [x]
S3 ipswuio;ipswuio;c:\windows\system32\drivers\ipswuio.sys [2007-02-03 34944]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASChannel
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Zshutdown - c:\sysprep\patch\sysprep.cmd
.
------- 而外的掃描 -------
.
uStart Page = hxxp://www.google.com/ig?hl=en
uInternet Settings,ProxyOverride = *.local
IE: &使用 FlashGet 下載 - c:\program files\FlashGet\jc_link.htm
IE: &全部使用 FlashGet 下載 - c:\program files\FlashGet\jc_all.htm
IE: 下載編碼內容(S&martGet) - c:\documents and settings\Michael\Desktop\SmartGet1.45.2\SmartGet1.45.2\dl_text.html
IE: 使用S&martGet下載 - c:\documents and settings\Michael\Desktop\SmartGet1.45.2\SmartGet1.45.2\dl_link.htm
IE: 全部使用Smart&Get下載 - c:\documents and settings\Michael\Desktop\SmartGet1.45.2\SmartGet1.45.2\dl_all.htm
LSP: c:\windows\system32\imon.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-04 23:08:17
Windows 5.1.2600 Service Pack 3 FAT NTAPI
掃描被隱藏的進程 。。。
掃描被隱藏的啟動組 。。。
掃描被隱藏的文件 。。。
掃描完成
被隱藏的檔案: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\(g?nd?Y+^sSBf綮呃]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1555759637-3371167190-2748196404-1004\Software\ACD Systems\EditLib\Presets\p_/*?IQ]
"上次使用"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,
3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,4c,43,45,3c,2f,6e,61,6d,65,3e,\
"僅限調亮"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,
3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,4c,43,45,3c,2f,6e,61,6d,65,3e,\
"僅限調暗"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,
3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,4c,43,45,3c,2f,6e,61,6d,65,3e,\
"預設值"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,3c,
63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,4c,43,45,3c,2f,6e,61,6d,65,3e,3c,\
"調亮/調暗"=hex:3c,3f,78,6d,6c,20,76,65,72,73,69,6f,6e,3d,22,31,2e,30,22,3f,3e,
3c,63,6f,6d,6d,61,6e,64,3e,3c,6e,61,6d,65,3e,4c,43,45,3c,2f,6e,61,6d,65,3e,\
.
--------------------- 運行進程下的動態鏈接庫 ---------------------
- - - - - - - > 'winlogon.exe'(996)
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
c:\windows\system32\IfxWlxEN.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsChnl.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItMsg.dll
- - - - - - - > 'lsass.exe'(1052)
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\ASWLNPkg.dll
c:\windows\system32\imon.dll
c:\program files\Eset\pr_imon.dll
.
------------------------ 其他運行進程 ------------------------
.
c:\program files\INTEL\WIRELESS\BIN\EVTENG.EXE
c:\windows\SYSTEM32\DLLHOST.EXE
c:\program files\INTEL\WIRELESS\BIN\S24EVMON.EXE
c:\program files\a-squared Free\a2service.exe
c:\program files\COMMON FILES\APPLE\MOBILE DEVICE SUPPORT\BIN\APPLEMOBILEDEVICESERVICE.EXE
c:\program files\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE
c:\program files\BONJOUR\MDNSRESPONDER.EXE
c:\program files\WIDCOMM\BLUETOOTH SOFTWARE\BIN\BTWDINS.EXE
c:\windows\SYSTEM32\IFXSPMGT.EXE
c:\windows\SYSTEM32\IFXTCS.EXE
c:\program files\JAVA\JRE6\BIN\JQS.EXE
c:\program files\ESET\NOD32KRN.EXE
c:\windows\SYSTEM32\NVSVC32.EXE
c:\program files\INFINEON\SECURITY PLATFORM SOFTWARE\PSDSRVC.EXE
c:\program files\INTEL\WIRELESS\BIN\REGSRVC.EXE
c:\program files\ALCOHOL SOFT\ALCOHOL 120\STARWIND\STARWINDSERVICEAE.EXE
c:\program files\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
c:\windows\SYSTEM32\SCARDSVR.EXE
c:\program files\ASUS SECURITY CENTER\ASUS SECURITY PROTECT MANAGER\BIN\ASGHOST.EXE
c:\program files\INFINEON\SECURITY PLATFORM SOFTWARE\PSDRT.EXE
c:\program files\INFINEON\SECURITY PLATFORM SOFTWARE\SPTNA.EXE
c:\windows\system32\conime.exe
c:\windows\SYSTEM32\RUNDLL32.EXE
c:\windows\SYSTEM32\RUNDLL32.EXE
c:\windows\ATK0100\ATKOSD.exe
c:\windows\system32\ACEngSvr.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\iPod\bin\iPodService.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
c:\windows\system32\wscntfy.exe
c:\program files\Symantec\LiveUpdate\AUpdate.exe
c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
.
**************************************************************************
.
完成時間: 2009-03-04 23:09:43 - 電腦已重新啟動
ComboFix-quarantined-files.txt 2009-03-05 07:09:42
Pre-Run: 11,974,082,560 bytes free
Post-Run: 14,773,452,800 bytes free
285 --- E O F --- 2009-02-26 06:08:57

