This is the combo fix log
ComboFix 11-06-29.06 - R 0/2011 Thu 21:29:38.1.2 - x86
执行位置: c:\users\R\Desktop\1\ComboFix.exe
AV: ESET Smart Security 4.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* 防毒软件还在运行中
.
.
.
((((((((((((((((((((((((((((((((((((((( 被删除的档案 )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Setup.exe
c:\windows\ST6UNST.000
c:\windows\system32\CoreFLACDecoder-uninstall.exe
.
.
((((((((((((((((((((((((( 2011-05-28 至 2011-06-30 的新的档案 )))))))))))))))))))))))))))))))
.
.
2011-06-30 13:26 . 2011-06-30 13:26 -------- d-----w- C:\32788R22FWJFW
2011-06-20 13:39 . 2011-06-20 13:39 -------- d-----w- c:\users\R\AppData\Roaming\Malwarebytes
2011-06-20 13:38 . 2011-05-29 01:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-20 13:38 . 2011-06-20 13:38 -------- d-----w- c:\programdata\Malwarebytes
2011-06-20 13:38 . 2011-05-29 01:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-19 13:56 . 2011-06-19 13:56 -------- d-----w- c:\program files\WinPcap
2011-06-19 13:55 . 2011-06-19 13:56 -------- d-----w- c:\program files\netcut
2011-06-19 13:55 . 2006-09-21 05:59 389120 ----a-w- c:\windows\system32\actskn43.ocx
2011-06-19 12:54 . 2011-06-19 12:55 -------- d-----w- c:\users\R\Cisco Packet Tracer 5.3.1
2011-06-19 12:54 . 2011-06-19 12:54 -------- d-----w- c:\program files\Cisco Packet Tracer 5.3.1
2011-06-19 12:33 . 2011-06-19 12:33 -------- d-----w- c:\program files\TeamViewer
2011-06-19 12:25 . 2008-07-28 07:53 919552 ----a-w- c:\windows\system32\drivers\athr.sys
2011-06-19 12:24 . 2011-06-19 12:24 -------- d-----w- c:\users\R\AppData\Roaming\InstallShield
2011-06-19 10:05 . 1998-06-18 03:58 299008 ----a-w- c:\windows\system32\msdbrptr.dll
2011-06-19 10:03 . 1998-06-17 17:00 77824 ----a-w- c:\windows\system32\msbind.dll
2011-06-17 07:16 . 2011-05-09 20:46 6962000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8E7DB9D0-5F91-4323-AAA6-B88136396ADF}\mpengine.dll
2011-06-15 15:26 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-06-15 15:26 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-06-15 15:26 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-06-15 14:35 . 2011-05-02 12:02 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-06-15 14:20 . 2010-12-20 16:35 563712 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-15 14:20 . 2011-04-29 13:24 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-15 14:20 . 2011-04-29 13:24 79872 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-15 14:20 . 2011-04-29 13:24 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-15 14:19 . 2011-04-21 13:58 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-15 14:19 . 2011-04-29 13:25 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-15 14:19 . 2011-05-02 17:16 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-15 14:19 . 2011-04-29 13:25 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-15 14:19 . 2011-04-14 14:59 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-06-12 09:44 . 2011-06-12 09:44 286720 ------w- c:\windows\Setup1.exe
2011-06-12 09:16 . 2011-06-12 09:16 469256 ----a-w- c:\program files\Common Files\Windows Live\.cache\6049dda51cc28e112\InstallManager_WLE_WLE.exe
2011-06-12 09:15 . 2011-06-12 09:15 15712 ----a-w- c:\program files\Common Files\Windows Live\.cache\56e8be251cc28e106\MeshBetaRemover.exe
2011-06-10 09:47 . 2011-06-10 11:04 -------- d-----w- c:\program files\Free Window Registry Repair
2011-06-05 12:24 . 2011-06-05 12:24 103424 ----a-w- c:\windows\system32\uxtheme.manifest
2011-06-05 05:26 . 2011-06-05 05:26 -------- d-----w- c:\users\R\AppData\Local\Garena
.
.
.
(((((((((((((((((((((((((((((((((((((((( 在三个月内被修改的档案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-21 08:51 . 2011-05-21 08:51 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-16 05:55 . 2011-05-18 11:13 557440 ----a-w- c:\windows\system32\KuGoo3DownXControl.ocx
2011-05-12 10:52 . 2011-05-12 10:52 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-12 10:52 . 2011-05-12 10:52 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-05-12 10:52 . 2011-05-12 10:52 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-05-12 10:52 . 2011-05-12 10:52 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-05-12 10:52 . 2011-05-12 10:52 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-05-12 10:52 . 2011-05-12 10:52 161792 ----a-w- c:\windows\system32\msls31.dll
2011-05-12 10:52 . 2011-05-12 10:52 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-05-12 10:52 . 2011-05-12 10:52 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-05-12 10:52 . 2011-05-12 10:52 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-05-12 10:52 . 2011-05-12 10:52 367104 ----a-w- c:\windows\system32\html.iec
2011-05-12 10:52 . 2011-05-12 10:52 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-12 10:52 . 2011-05-12 10:52 152064 ----a-w- c:\windows\system32\wextract.exe
2011-05-12 10:52 . 2011-05-12 10:52 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-05-12 10:52 . 2011-05-12 10:52 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-12 10:52 . 2011-05-12 10:52 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-12 10:52 . 2011-05-12 10:52 11776 ----a-w- c:\windows\system32\mshta.exe
2011-05-12 10:52 . 2011-05-12 10:52 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-05-12 10:52 . 2011-05-12 10:52 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-12 10:52 . 2011-05-12 10:52 101888 ----a-w- c:\windows\system32\admparse.dll
2011-05-11 09:37 . 2011-05-11 09:37 319456 ----a-w- c:\windows\DIFxAPI.dll
2011-05-11 09:37 . 2011-05-11 09:37 315392 ----a-w- c:\windows\HideWin.exe
2011-04-14 16:26 . 2011-05-11 05:02 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( 重要登入点 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白与合法缺省登录将不会被显示
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0A0DDBD3-6641-40B9-873F-BBDD26D6C14E}]
2011-01-26 04:04 180696 ----a-w- c:\program files\easyMule\modules\IE2EM.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"PPS Accelerator"="c:\progra~1\PPStream\ppsap.exe" [2010-02-24 214408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2008-01-23 7766016]
"RtHDVCpl"="RtHDVCpl.exe" [2008-06-13 6183456]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-11-16 1029416]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2008-02-01 61440]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2011-01-12 2219184]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-01 13789728]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-4-10 752168]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ST6UNST Uninstaller.LNK]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ST6UNST Uninstaller.LNK
backup=c:\windows\pss\ST6UNST Uninstaller.LNK.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PPS Accelerator]
2010-02-24 03:25 214408 ----a-w- c:\progra~1\PPStream\PPSAP.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 MBAMService;MBAMService;f:\malwarebytes' anti-malware\mbamservice.exe [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-01-29 29736]
R3 GGSAFERDriver;GGSAFER Driver;f:\garena\safedrv.sys [x]
R3 tcphoc;tcphoc;c:\program files\Thunder Network\Thunder\Program\tcphoc.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-12-21 115008]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-12-21 137144]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2011-01-12 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-12-21 41336]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-06-25 35088]
S3 DCamUSBET;USB2.0 1.3M UVC WebCam;c:\windows\system32\DRIVERS\etDevice.sys [2007-09-06 474624]
S3 FiltUSBET;ET USB Device Lower Filter;c:\windows\system32\DRIVERS\etFilter.sys [2007-10-15 206336]
S3 itecir;ITECIR Infrared Receiver;c:\windows\system32\DRIVERS\itecir.sys [2010-03-08 62496]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-05-29 22712]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-06-08 43040]
S3 ScanUSBET;ET USB Still Image Capture Device;c:\windows\system32\DRIVERS\etScan.sys [2007-09-06 6656]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- 而外的扫描 -------
.
uStart Page = about:blank
IE: Download by easyMule - c:\program files\easyMule\IE2EM.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436}
Trusted Zone: pps.tv
Trusted Zone: ppstream.com
Trusted Zone: webscache.com
TCP: DhcpNameServer = 192.168.1.1
Handler: KuGoo - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - c:\windows\System32\KuGoo3DownXControl.ocx
Handler: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - c:\windows\System32\KuGoo3DownXControl.ocx
FF - ProfilePath - c:\users\R\AppData\Roaming\Mozilla\Firefox\Profiles\zqu9h4gy.default\
FF - prefs.js: browser.search.selectedEngine - Search the web (Babylon)
FF - prefs.js: browser.startup.homepage - about:blank
FF - prefs.js: keyword.URL - hxxp://search.babylon.com/?babsrc=SP_ss&mntrId=4c3bc37b000000000000002243a3aa5a&tlver=1.4.19.19&instlRef=sst&affID=17159&q=
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{88c7f2aa-f93f-432c-8f0e-b7d85967a527} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-Malwarebytes' Anti-Malware - f:\malwarebytes' anti-malware\mbamgui.exe
MSConfigStartUp-antinetcut2 - c:\program files\Anti Netcut\Anti NetCut.exe
AddRemove-CoreFLAC Audio Decoder+Source Filter - c:\windows\system32\CoreFLACDecoder-uninstall.exe
AddRemove-Malwarebytes' Anti-Malware_is1 - f:\malwarebytes' anti-malware\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-06-30 21:37
Windows 6.0.6002 Service Pack 2 NTFS
.
扫描被隐藏的进程 。。。
.
扫描被隐藏的启动组 。。。
.
扫描被隐藏的文件 。。。
.
扫描完成
被隐藏的档案: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
完成时间: 2011-06-30 21:40:41
ComboFix-quarantined-files.txt 2011-06-30 13:40
.
Pre-Run: 203,380,785,152 bytes free
Post-Run: 203,952,525,312 bytes free
.
- - End Of File - - 4739BEC838255EC1503AE4536562E448
=============Line of separation==============================
I could not get the update for the ESET Online Scanner.
It's shown that : Can not get update. Is proxy configured?