Dear D-A-L,
my computer seems to be back to normal now. other then virus, i suspect it could be my internet service provider problem. i follow your instruction and still would like to post my combofix log. thanks you very much. your help is appreciated.
ComboFix 07-06-09.5 - C:\Documents and Settings\oem\Desktop\ComboFix.exe
"oem" - 2007-06-10 11:07:36 - Service Pack 2 NTFS
((((((((((((((((((((((((( Files Created from 2007-05-10 to 2007-06-10 )))))))))))))))))))))))))))))))
2007-06-10 10:57 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-09 17:54 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-05-25 02:27 <DIR> d--h----- C:\WINDOWS\PIF
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
2007-06-10 03:02:04 857 --sha-w C:\WINDOWS\system32\mmf.sys
2007-06-09 10:38:54 -------- d-----w C:\Program Files\HJT
2007-06-09 10:10:52 -------- d-----w C:\Program Files\SpywareGuard
2007-05-30 19:38:07 -------- d-----w C:\Program Files\MSN Messenger
2007-05-30 19:36:32 -------- d-----w C:\DOCUME~1\oem\APPLIC~1\ppstream
2007-05-18 18:23:38 -------- d-----w C:\Program Files\Cyanide
2007-05-11 05:23:11 -------- d-----w C:\Program Files\BitComet
2007-05-09 16:58:37 -------- d-----w C:\Program Files\PPStream
2007-05-06 03:27:46 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-05-03 17:05:09 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-05-03 17:01:29 -------- d-----w C:\DOCUME~1\oem\APPLIC~1\ICQ
2007-04-24 20:45:59 -------- d-----w C:\DOCUME~1\oem\APPLIC~1\Skype
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-16 14:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-16 14:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 14:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 14:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 14:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 14:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 14:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 14:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-12 02:23:58 -------- d-----w C:\Program Files\Google
2007-04-01 08:02:20 2,560 ----a-w C:\WINDOWS\system32\BitCometRes.dll
2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-15 01:35:49 664 ----a-w C:\WINDOWS\system32\d3d9caps.dat
2006-05-03 09:06:54 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47:16 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-13 09:38]
{31FF080D-12A3-439A-A2EF-4BA95A3148E8}=C:\Program Files\GetRight\xx2gr.dll [2006-09-11 17:37]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}=C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.19.dll [2007-03-19 16:47]
{4A368E80-174F-4872-96B5-0B27DDD11DB2}=C:\Program Files\SpywareGuard\dlprotect.dll [2003-08-03 12:24]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 14:04]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll [2006-12-15 03:23]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar3.dll [2007-01-19 23:55]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-11-05 21:59 C:\WINDOWS\SOUNDMAN.EXE]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-12-22 14:23]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-12-22 14:23]
"Power_Gear"="C:\Program Files\Generic\Power4 Gear\BatteryLife.exe" [2004-09-22 04:55]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-06-13 09:33]
"Wireless Console"="C:\Program Files\Generic\Wireless Console\wcourier.exe" [2005-06-21 07:16]
"RemoteControl"="C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe" [2003-11-01 07:42]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-04-04 06:12]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-26 07:20]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" [2006-12-15 03:23]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15:56]
"MtdAcq"="C:\Program Files\Creative\Shared Files\Media Sniffer\MtdAcq.exe" [2002-10-17 06:13]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\Go ogleToolbarNotifier.exe" []
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\ShellExecuteHooks]
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="C:\Program Files\ewido anti-malware\shellhook.dll" [2004-09-30 20:21]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
Contents of the 'Scheduled Tasks' folder
2007-06-09 17:41:03 C:\WINDOWS\tasks\MP Scheduled Scan.job
************************************************** ************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-10 11:08:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
Completion time: 2007-06-10 11:09:21
C:\ComboFix-quarantined-files.txt ... 2007-06-10 11:09
--- E O F ---