fishgal2
2008-07-25, 17:38
My pc infected with AntivirusXP 2008 and have been using the ComboFix method and below is the report of the log file. Is my pc are now clean?
ComboFix 08-07-24.3 - Admin 2008-07-25 22:16:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.936.1.1033.18.280 [GMT 8:00]
Running from: C:\Documents and Settings\Admin\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Admin\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Admin\Application Data\macromedia\Flash Player\#SharedObjects\9CPTBUY3\www.inter-focus.cn
C:\Documents and Settings\Admin\Application Data\macromedia\Flash Player\#SharedObjects\9CPTBUY3\www.inter-focus.cn\IFFLASHAD_PLAYER.sol
C:\Documents and Settings\Admin\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.inter-focus.cn
C:\Documents and Settings\Admin\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.inter-focus.cn\settings.sol
C:\Documents and Settings\Admin\Application Data\rhcl9qj0e53j
C:\Documents and Settings\Administrator\Application Data\rhcl9qj0e53j
C:\WINDOWS\BM271101ba.txt
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\jikTuBeg.ini
C:\WINDOWS\system32\jikTuBeg.ini2
C:\WINDOWS\system32\mcrh.tmp
.
((((((((((((((((((((((((( Files Created from 2008-06-25 to 2008-07-25 )))))))))))))))))))))))))))))))
.
2008-07-24 23:00 . 2008-07-24 23:00 <DIR> d-------- C:\WINDOWS\ERUNT
2008-07-24 22:57 . 2008-07-24 23:35 <DIR> d-------- C:\SDFix
2008-07-24 21:33 . 2008-07-24 21:33 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-07-24 21:31 . 2008-07-24 21:32 182 --a------ C:\WINDOWS\wininit.ini
2008-07-24 20:49 . 2008-07-24 20:49 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-24 08:40 . 2008-07-24 08:40 110,080 --a------ C:\WINDOWS\system32\lphcg9qj0e53j.exe
2008-07-21 21:08 . 2008-07-21 21:08 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-07-21 01:26 . 2008-07-21 01:26 <DIR> d-------- C:\Program Files\8 Interactive
2008-07-09 21:19 . 2008-07-13 08:03 <DIR> d-------- C:\Program Files\PokerStars
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-24 16:03 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-24 16:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-24 16:01 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-24 16:01 --------- d-----w C:\Program Files\SpywareBlaster
2008-07-24 13:09 --------- d-----w C:\Program Files\Shockwave.com
2008-07-24 00:39 --------- d-----w C:\Documents and Settings\Admin\Application Data\uTorrent
2008-07-23 14:06 --------- d-----w C:\Program Files\QvodPlayer
2008-07-21 13:07 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-20 13:27 --------- d-----w C:\Program Files\Warcraft III
2008-06-11 06:58 --------- d-----w C:\Program Files\MSN Messenger
2008-06-11 01:25 --------- d-----w C:\Program Files\StormII
2008-06-10 16:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-10 14:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-05-29 02:17 --------- d-----w C:\Program Files\uTorrent
2008-05-29 01:37 --------- d-----w C:\Program Files\Tencent
2008-05-29 01:33 --------- d-----w C:\Documents and Settings\Admin\Application Data\QQUpdate
2008-05-29 01:33 --------- d-----w C:\Documents and Settings\Admin\Application Data\QQ
2008-05-28 10:05 139,398 --s---r C:\WINDOWS\WindowsUpdateService.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 22:32 208952]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE" [2002-08-29 05:39 455168]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE" [2002-08-29 05:39 455168]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-09 15:29 7561216]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-03-09 15:29 86016]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-05-16 10:58 86960]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24 286720]
"nwiz"="nwiz.exe" [2006-03-09 15:29 1519616 C:\WINDOWS\system32\nwiz.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
C:\Documents and Settings\Admin\Start Menu\Programs\Startup\
QQ游戏启动加速程序.lnk.disabled [2008-01-09 18:05:49 803]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.xivd"= C:\Program Files\StormII\codec\xvidvfw.dll
"vidc.tscc"= C:\WINDOWS\system32\tsccvid.dll
"vidc.VP70"= C:\WINDOWS\system32\vp7vfw.dll
"vidc.aasc"= aasc32.dll
"vidc.aas4"= aasc32.dll
"vidc.UCDO"= clrviddd.dll
"vidc.avrn"= avidavicodec.dll
"vidc.advj"= avidavicodec.dll
"vidc.asv1"= asusasv1.dll
"vidc.asv2"= asusasv2.dll
"vidc.asvx"= asusasv2.dll
"vidc.vdom"= vdowave.drv
"vidc.I263"= i263_32.drv
"vidc.VCR2"= ativcr2.dll
"vidc.lsvx"= lsvxdec.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Start Menu^Programs^Startup^腾讯QQ.lnk.disabled]
path=C:\Documents and Settings\Admin\Start Menu\Programs\Startup\腾讯QQ.lnk.disabled
backup=C:\WINDOWS\pss\腾讯QQ.lnk.disabledStartup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"QQDownload"="C:\Program Files\Tencent\QQDownload\QQDownload.exe" autostart
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"Storm2Set"=C:\WINDOWS\system32\rundll32.exe "C:\PROGRA~1\StormII\StormSet.dll",CheckEnv
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"UpdateSys"=WindowsUpdateService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\AhnlabAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\QvodPlayer\\QvodTerminal.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\English\\setup.exe"=
R0 d343port;d343port;C:\WINDOWS\system32\DRIVERS\d343port.sys [2003-12-17 13:48]
R1 AnfdTDnt;AnfdTDnt;C:\WINDOWS\system32\drivers\AnfdTDnt.sys [2006-09-12 02:58]
R2 AnfdIont;AnfdIont;C:\WINDOWS\system32\drivers\AnfdIont.sys [2006-08-08 10:02]
S2 V3NfeNt;V3NfeNt;C:\Program Files\Ahnlab\V3\V3NfeNt.sys []
S3 msloop;Microsoft Loopback Adapter Driver;C:\WINDOWS\system32\DRIVERS\loop.sys [2001-08-17 13:53]
S3 npkycryp;npkycryp;C:\Program Files\Tencent\QQ\npkycryp.sys []
S3 Qvod Terminal;Qvod Terminal;C:\Program Files\QvodPlayer\QvodTerminal.exe [2008-01-15 12:06]
.
Contents of the 'Scheduled Tasks' folder
"2008-07-23 14:26:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -
BHO-{BF0CA4FC-6378-4062-B546-3CDE8A28B1E0} - (no file)
BHO-{EC815BE4-E70A-4EF0-9ED3-3E17BA6DC8CB} - C:\WINDOWS\system32\geBuTkij.dll
HKLM-Run-ISUSPM Startup - C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe
Notify-hgGxXRiG - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.my/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
R0 -: HKLM-Main,Local Page = hxxp://www.bb2000.net
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: C:\Program Files\Tencent\QQ\SendMMS.htm
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 -: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 -: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 -: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 -: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 -: {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O16 -: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} - hxxp://game.qq.com/QQGame2.cab
C:\WINDOWS\Downloaded Program Files\WebActivater.inf
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\mfc42.dll
C:\WINDOWS\system32\olepro32.dll
C:\WINDOWS\system32\WebActivater.ocx
O16 -: {9ADACAA6-533E-4383-AFA7-F0A66650B6D8} - hxxp://im.qq.com/vqqsdl1230.cab
C:\WINDOWS\Downloaded Program Files\vqqsdl.inf
C:\WINDOWS\vqqsdl10.exe
C:\WINDOWS\TNProxy.dll
C:\WINDOWS\vqqsdl10.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-25 22:20:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-07-25 22:24:16 - machine was rebooted [Admin]
ComboFix-quarantined-files.txt 2008-07-25 14:24:07
Pre-Run: 13,694,451,712 bytes free
Post-Run: 13,926,977,536 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
192 --- E O F --- 2008-05-21 17:02:33
ComboFix 08-07-24.3 - Admin 2008-07-25 22:16:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.936.1.1033.18.280 [GMT 8:00]
Running from: C:\Documents and Settings\Admin\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Admin\Desktop\WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Admin\Application Data\macromedia\Flash Player\#SharedObjects\9CPTBUY3\www.inter-focus.cn
C:\Documents and Settings\Admin\Application Data\macromedia\Flash Player\#SharedObjects\9CPTBUY3\www.inter-focus.cn\IFFLASHAD_PLAYER.sol
C:\Documents and Settings\Admin\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.inter-focus.cn
C:\Documents and Settings\Admin\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.inter-focus.cn\settings.sol
C:\Documents and Settings\Admin\Application Data\rhcl9qj0e53j
C:\Documents and Settings\Administrator\Application Data\rhcl9qj0e53j
C:\WINDOWS\BM271101ba.txt
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\jikTuBeg.ini
C:\WINDOWS\system32\jikTuBeg.ini2
C:\WINDOWS\system32\mcrh.tmp
.
((((((((((((((((((((((((( Files Created from 2008-06-25 to 2008-07-25 )))))))))))))))))))))))))))))))
.
2008-07-24 23:00 . 2008-07-24 23:00 <DIR> d-------- C:\WINDOWS\ERUNT
2008-07-24 22:57 . 2008-07-24 23:35 <DIR> d-------- C:\SDFix
2008-07-24 21:33 . 2008-07-24 21:33 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Lavasoft
2008-07-24 21:31 . 2008-07-24 21:32 182 --a------ C:\WINDOWS\wininit.ini
2008-07-24 20:49 . 2008-07-24 20:49 <DIR> d-------- C:\Documents and Settings\Administrator
2008-07-24 08:40 . 2008-07-24 08:40 110,080 --a------ C:\WINDOWS\system32\lphcg9qj0e53j.exe
2008-07-21 21:08 . 2008-07-21 21:08 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-07-21 01:26 . 2008-07-21 01:26 <DIR> d-------- C:\Program Files\8 Interactive
2008-07-09 21:19 . 2008-07-13 08:03 <DIR> d-------- C:\Program Files\PokerStars
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-24 16:03 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-24 16:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-24 16:01 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-24 16:01 --------- d-----w C:\Program Files\SpywareBlaster
2008-07-24 13:09 --------- d-----w C:\Program Files\Shockwave.com
2008-07-24 00:39 --------- d-----w C:\Documents and Settings\Admin\Application Data\uTorrent
2008-07-23 14:06 --------- d-----w C:\Program Files\QvodPlayer
2008-07-21 13:07 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-20 13:27 --------- d-----w C:\Program Files\Warcraft III
2008-06-11 06:58 --------- d-----w C:\Program Files\MSN Messenger
2008-06-11 01:25 --------- d-----w C:\Program Files\StormII
2008-06-10 16:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-10 14:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-05-29 02:17 --------- d-----w C:\Program Files\uTorrent
2008-05-29 01:37 --------- d-----w C:\Program Files\Tencent
2008-05-29 01:33 --------- d-----w C:\Documents and Settings\Admin\Application Data\QQUpdate
2008-05-29 01:33 --------- d-----w C:\Documents and Settings\Admin\Application Data\QQ
2008-05-28 10:05 139,398 --s---r C:\WINDOWS\WindowsUpdateService.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 22:32 208952]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE" [2002-08-29 05:39 455168]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE" [2002-08-29 05:39 455168]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-03-09 15:29 7561216]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-03-09 15:29 86016]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-05-16 10:58 86960]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24 286720]
"nwiz"="nwiz.exe" [2006-03-09 15:29 1519616 C:\WINDOWS\system32\nwiz.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
C:\Documents and Settings\Admin\Start Menu\Programs\Startup\
QQ游戏启动加速程序.lnk.disabled [2008-01-09 18:05:49 803]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.xivd"= C:\Program Files\StormII\codec\xvidvfw.dll
"vidc.tscc"= C:\WINDOWS\system32\tsccvid.dll
"vidc.VP70"= C:\WINDOWS\system32\vp7vfw.dll
"vidc.aasc"= aasc32.dll
"vidc.aas4"= aasc32.dll
"vidc.UCDO"= clrviddd.dll
"vidc.avrn"= avidavicodec.dll
"vidc.advj"= avidavicodec.dll
"vidc.asv1"= asusasv1.dll
"vidc.asv2"= asusasv2.dll
"vidc.asvx"= asusasv2.dll
"vidc.vdom"= vdowave.drv
"vidc.I263"= i263_32.drv
"vidc.VCR2"= ativcr2.dll
"vidc.lsvx"= lsvxdec.dll
[HKLM\~\startupfolder\C:^Documents and Settings^Admin^Start Menu^Programs^Startup^腾讯QQ.lnk.disabled]
path=C:\Documents and Settings\Admin\Start Menu\Programs\Startup\腾讯QQ.lnk.disabled
backup=C:\WINDOWS\pss\腾讯QQ.lnk.disabledStartup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"QQDownload"="C:\Program Files\Tencent\QQDownload\QQDownload.exe" autostart
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"Storm2Set"=C:\WINDOWS\system32\rundll32.exe "C:\PROGRA~1\StormII\StormSet.dll",CheckEnv
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"UpdateSys"=WindowsUpdateService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\AhnlabAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\QvodPlayer\\QvodTerminal.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\English\\setup.exe"=
R0 d343port;d343port;C:\WINDOWS\system32\DRIVERS\d343port.sys [2003-12-17 13:48]
R1 AnfdTDnt;AnfdTDnt;C:\WINDOWS\system32\drivers\AnfdTDnt.sys [2006-09-12 02:58]
R2 AnfdIont;AnfdIont;C:\WINDOWS\system32\drivers\AnfdIont.sys [2006-08-08 10:02]
S2 V3NfeNt;V3NfeNt;C:\Program Files\Ahnlab\V3\V3NfeNt.sys []
S3 msloop;Microsoft Loopback Adapter Driver;C:\WINDOWS\system32\DRIVERS\loop.sys [2001-08-17 13:53]
S3 npkycryp;npkycryp;C:\Program Files\Tencent\QQ\npkycryp.sys []
S3 Qvod Terminal;Qvod Terminal;C:\Program Files\QvodPlayer\QvodTerminal.exe [2008-01-15 12:06]
.
Contents of the 'Scheduled Tasks' folder
"2008-07-23 14:26:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -
BHO-{BF0CA4FC-6378-4062-B546-3CDE8A28B1E0} - (no file)
BHO-{EC815BE4-E70A-4EF0-9ED3-3E17BA6DC8CB} - C:\WINDOWS\system32\geBuTkij.dll
HKLM-Run-ISUSPM Startup - C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe
Notify-hgGxXRiG - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com.my/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
R0 -: HKLM-Main,Local Page = hxxp://www.bb2000.net
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: C:\Program Files\Tencent\QQ\SendMMS.htm
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 -: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 -: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 -: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 -: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 -: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 -: {c95fe080-8f5d-11d2-a20b-00aa003c157b} - C:\Program Files\Tencent\QQ\QQ.EXE
O16 -: {3D8F74EE-8692-4F8F-B8D2-7522E732519E} - hxxp://game.qq.com/QQGame2.cab
C:\WINDOWS\Downloaded Program Files\WebActivater.inf
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\mfc42.dll
C:\WINDOWS\system32\olepro32.dll
C:\WINDOWS\system32\WebActivater.ocx
O16 -: {9ADACAA6-533E-4383-AFA7-F0A66650B6D8} - hxxp://im.qq.com/vqqsdl1230.cab
C:\WINDOWS\Downloaded Program Files\vqqsdl.inf
C:\WINDOWS\vqqsdl10.exe
C:\WINDOWS\TNProxy.dll
C:\WINDOWS\vqqsdl10.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-25 22:20:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-07-25 22:24:16 - machine was rebooted [Admin]
ComboFix-quarantined-files.txt 2008-07-25 14:24:07
Pre-Run: 13,694,451,712 bytes free
Post-Run: 13,926,977,536 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
192 --- E O F --- 2008-05-21 17:02:33