Thanks for your reply.
Here is the log.
Some came up in Chinese so I have no clue what it means.
ComboFix 09-06-05.07 - winxp 6/2009 Sun 18:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.936.86.1033.18.3070.2181 [GMT 10:00]
执行位置: c:\documents and settings\winxp\Desktop\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
((((((((((((((((((((((((((((((((((((((( 被删除的档案 )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\LocalService\Application Data\twain_32
c:\documents and settings\LocalService\Application Data\twain_32\user.ds
c:\documents and settings\NetworkService\Application Data\twain_32
c:\documents and settings\NetworkService\Application Data\twain_32\user.ds
c:\windows\patchw32.dll
c:\windows\pw32a.dll
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
c:\windows\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\SystemsHook.dll
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( 驱动/服务 )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_gaopdxserv.sys
-------\Service_NPF
((((((((((((((((((((((((( 2009-05-06 至 2009-06-06 的新的档案 )))))))))))))))))))))))))))))))
.
2009-06-06 06:47 . 2009-06-06 06:47 -------- d-----w- c:\documents and settings\All Users\Application Data\vsosdk
2009-06-06 06:12 . 2009-06-06 06:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Sibelius Software
2009-06-06 06:12 . 2009-06-06 06:13 -------- d-----w- c:\documents and settings\winxp\Application Data\Sibelius Software
2009-06-06 06:11 . 2009-06-06 06:11 -------- d-----w- c:\program files\Sibelius Software
2009-06-06 02:14 . 2009-06-06 02:14 -------- d-----w- c:\program files\Trend Micro
2009-06-05 23:18 . 2009-06-06 00:04 -------- d-----w- C:\Rooter$
2009-06-04 11:08 . 2009-06-04 11:08 -------- d-----w- c:\documents and settings\James\Local Settings\Application Data\Mozilla
2009-06-04 11:08 . 2009-06-04 11:08 -------- d-sh--w- c:\documents and settings\James\PrivacIE
2009-06-04 11:07 . 2009-06-04 11:28 -------- d-----w- c:\documents and settings\James\Tracing
2009-06-04 11:07 . 2009-06-04 11:07 -------- d-----w- c:\documents and settings\James\Application Data\ESET
2009-06-04 11:07 . 2009-06-04 11:07 -------- d-----w- c:\documents and settings\James\Local Settings\Application Data\LogiShrd
2009-06-04 11:06 . 2008-11-12 11:48 -------- d-----w- c:\documents and settings\James\Local Settings\Application Data\Microsoft Help
2009-06-04 11:06 . 2008-07-01 11:02 -------- d-----w- c:\documents and settings\James\Local Settings\Application Data\Apple Computer
2009-06-04 11:06 . 2008-07-01 11:02 -------- d-----w- c:\documents and settings\James\Application Data\Apple Computer
2009-06-04 11:02 . 2008-11-12 11:48 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Microsoft Help
2009-06-04 11:02 . 2008-07-01 11:02 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Apple Computer
2009-06-04 11:02 . 2008-07-01 11:02 -------- d-----w- c:\documents and settings\Guest\Application Data\Apple Computer
2009-06-04 07:24 . 2009-06-04 07:24 1878984 ----a-w- c:\documents and settings\winxp\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-06-03 11:29 . 2009-06-03 11:29 3371383 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-03 06:45 . 2009-06-03 06:45 -------- d-----w- c:\documents and settings\winxp\Application Data\DVDFab
2009-05-30 11:52 . 2009-05-30 11:52 -------- d-----w- c:\program files\CleanUp!
2009-05-21 11:27 . 2009-05-21 11:28 -------- d-----w- c:\program files\Password Protect
.
(((((((((((((((((((((((((((((((((((((((( 在三个月内被修改的档案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-06 06:13 . 2009-03-28 06:09 97200 ----a-w- c:\documents and settings\winxp\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-06 06:12 . 2009-06-06 06:12 604 ---ha-w- c:\program files\STLL Notifier
2009-06-06 06:12 . 2008-11-11 07:28 -------- d-----w- c:\documents and settings\winxp\Application Data\uTorrent
2009-06-04 11:07 . 2009-06-04 11:07 83088 ----a-w- c:\documents and settings\James\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-04 11:03 . 2009-06-04 11:03 -------- d-----w- c:\documents and settings\Guest\Application Data\ESET
2009-06-04 11:03 . 2009-06-04 11:03 83088 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-03 06:38 . 2008-06-10 10:31 -------- d-----w- c:\documents and settings\winxp\Application Data\U3
2009-05-26 03:20 . 2009-03-27 06:47 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 03:19 . 2009-03-27 06:47 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-16 22:18 . 2008-08-16 23:16 24944 ----a-w- c:\windows\system32\drivers\GVTDrv.sys
2009-05-16 10:36 . 2009-03-27 07:53 207504 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-14 10:12 . 2008-06-08 03:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-11 08:24 . 2008-07-23 06:20 139280 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-05-11 08:24 . 2008-07-23 06:20 202000 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-05-09 23:55 . 2008-08-12 11:15 -------- d-----w- c:\documents and settings\winxp\Application Data\LimeWire
2009-04-30 10:15 . 2009-04-30 10:15 -------- d-----w- c:\program files\GoldWave
2009-04-30 10:05 . 2009-04-30 10:05 36104 ----a-w- c:\windows\system32\SpoonUninstall-dBpowerAMP Music Converter.dat
2009-04-30 10:05 . 2008-08-15 05:36 131072 ----a-w- c:\windows\system32\SpoonUninstall.exe
2009-04-24 05:06 . 2008-06-14 05:09 -------- d-----w- c:\program files\Windows Live Safety Center
2009-04-24 04:39 . 2009-04-24 04:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-04-24 04:37 . 2008-08-22 05:53 -------- d-----w- c:\program files\SystemRequirementsLab
2009-04-24 04:37 . 2009-04-24 04:37 255488 ----a-w- c:\documents and settings\winxp\Application Data\SystemRequirementsLab\SRLProxy_srl_4_0_0_4_d.dll
2009-04-24 04:37 . 2009-04-24 04:37 255488 ----a-w- c:\documents and settings\winxp\Application Data\SystemRequirementsLab\SRLProxy_srl_4_0_0_4_c.dll
2009-04-24 04:37 . 2009-04-24 04:37 255488 ----a-w- c:\documents and settings\winxp\Application Data\SystemRequirementsLab\SRLProxy_srl_4_0_0_4_b.dll
2009-04-24 04:37 . 2009-04-24 04:37 255488 ----a-w- c:\documents and settings\winxp\Application Data\SystemRequirementsLab\SRLProxy_srl_4_0_0_4_a.dll
2009-04-24 04:37 . 2008-11-12 08:07 -------- d-----w- c:\documents and settings\winxp\Application Data\SystemRequirementsLab
2009-04-23 01:49 . 2008-06-08 03:10 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-04-21 11:49 . 2009-04-21 03:09 -------- d-----w- c:\program files\Hotspot Shield
2009-04-21 00:03 . 2009-03-12 07:23 -------- d-----w- c:\program files\SpeedBit Video Accelerator
2009-04-21 00:03 . 2008-09-28 06:03 -------- d-----w- c:\program files\DAP
2009-04-21 00:03 . 2008-10-14 05:00 -------- d-----w- c:\program files\iTunes
2009-04-19 07:00 . 2008-07-06 11:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-04-18 06:58 . 2009-03-14 09:39 -------- d-----w- c:\program files\Microsoft
2009-04-18 06:58 . 2008-06-10 02:04 -------- d-----w- c:\program files\Windows Live
2009-04-16 11:57 . 2008-09-26 07:37 -------- d-----w- c:\documents and settings\winxp\Application Data\Xfire
2009-04-16 03:38 . 2009-04-16 03:38 -------- d-----w- c:\program files\TVAnts
2009-04-15 23:04 . 2009-04-15 23:04 -------- d-----w- c:\program files\World of Warcraft
2009-04-12 05:22 . 2009-04-12 05:22 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-12 05:22 . 2009-04-12 05:22 -------- d-----w- c:\program files\iPod
2009-04-12 05:22 . 2008-06-10 12:09 -------- d-----w- c:\program files\Common Files\Apple
2009-04-12 05:18 . 2009-04-12 05:18 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-04-03 18:18 . 2009-04-21 03:09 33256 ----a-w- c:\windows\system32\drivers\hssdrv.sys
2009-04-03 09:32 . 2008-08-23 03:23 335872 ----a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMResource.dll
2009-03-29 00:06 . 2009-03-29 00:06 5510306 ----a-w- c:\documents and settings\winxp\Application Data\Uniblue\DriverScanner\Download\pci_ven_10ec_dev_8169_subsys_816910ec6_213_1110_2008.exe
2009-03-29 00:05 . 2009-03-29 00:05 2873880 ----a-w- c:\documents and settings\winxp\Application Data\Uniblue\DriverScanner\Download\pci_ven_8086_dev_29309_0_0_1009.exe
2009-03-29 00:05 . 2009-03-29 00:05 2824728 ----a-w- c:\documents and settings\winxp\Application Data\Uniblue\DriverScanner\Download\pci_ven_8086_dev_29218_6_1_1001.exe
2009-03-28 07:14 . 2008-06-08 03:06 15600 -c--a-w- c:\windows\gdrv.sys
2009-03-26 03:11 . 2009-03-26 03:11 2082104 ----a-w- c:\documents and settings\winxp\Application Data\Mozilla\Firefox\Profiles\qu1t21p8.default\extensions\
[email protected]\plugins\npTVUAx.dll
2009-03-25 09:39 . 2009-03-25 09:39 -------- d-----w- c:\windows\Fonts\Fonts
2009-03-25 09:38 . 2009-03-25 09:38 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-03-25 09:38 . 2009-03-25 09:38 116472 ------w- c:\windows\system32\pxcpyi64.exe
2009-03-19 06:32 . 2009-03-19 06:32 23400 ----a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 06:32 . 2008-09-27 06:21 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-19 06:22 . 2009-03-19 06:22 65536 ----a-r- c:\documents and settings\winxp\Application Data\Microsoft\Installer\{627EAB2D-F5AE-4815-AD8E-79129D7959E7}\MSFileRescue.exe_627EAB2DF5AE4815AD8E79129D7959E7.exe
2009-03-19 06:22 . 2009-03-19 06:22 65536 ----a-r- c:\documents and settings\winxp\Application Data\Microsoft\Installer\{627EAB2D-F5AE-4815-AD8E-79129D7959E7}\ARPPRODUCTICON.exe
2009-03-19 06:22 . 2009-03-19 06:22 4846 ----a-r- c:\documents and settings\winxp\Application Data\Microsoft\Installer\{627EAB2D-F5AE-4815-AD8E-79129D7959E7}\NewShortcut1_627EAB2DF5AE4815AD8E79129D7959E7_1.exe
2009-03-19 06:22 . 2009-03-19 06:22 4846 ----a-r- c:\documents and settings\winxp\Application Data\Microsoft\Installer\{627EAB2D-F5AE-4815-AD8E-79129D7959E7}\MSFileRescue.chm17_627EAB2DF5AE4815AD8E79129D7959E7.exe
2009-03-19 06:22 . 2009-03-19 06:22 4846 ----a-r- c:\documents and settings\winxp\Application Data\Microsoft\Installer\{627EAB2D-F5AE-4815-AD8E-79129D7959E7}\MSFileRescue.chm16_627EAB2DF5AE4815AD8E79129D7959E7.exe
2009-03-19 06:22 . 2009-03-19 06:22 4846 ----a-r- c:\documents and settings\winxp\Application Data\Microsoft\Installer\{627EAB2D-F5AE-4815-AD8E-79129D7959E7}\MSFileRescue.chm15_627EAB2DF5AE4815AD8E79129D7959E7.exe
2009-03-19 06:22 . 2009-03-19 06:22 4846 ----a-r- c:\documents and settings\winxp\Application Data\Microsoft\Installer\{627EAB2D-F5AE-4815-AD8E-79129D7959E7}\MSFileRescue.chm14_627EAB2DF5AE4815AD8E79129D7959E7.exe
2009-03-19 06:22 . 2009-03-19 06:22 4846 ----a-r- c:\documents and settings\winxp\Application Data\Microsoft\Installer\{627EAB2D-F5AE-4815-AD8E-79129D7959E7}\MSFileRescue.chm13_627EAB2DF5AE4815AD8E79129D7959E7.exe
2009-03-19 06:22 . 2009-03-19 06:22 4846 ----a-r- c:\documents and settings\winxp\Application Data\Microsoft\Installer\{627EAB2D-F5AE-4815-AD8E-79129D7959E7}\MSFileRescue.chm12_627EAB2DF5AE4815AD8E79129D7959E7.exe
2009-03-19 06:22 . 2009-03-19 06:22 4846 ----a-r- c:\documents and settings\winxp\Application Data\Microsoft\Installer\{627EAB2D-F5AE-4815-AD8E-79129D7959E7}\MSFileRescue.chm11_627EAB2DF5AE4815AD8E79129D7959E7.exe
2009-03-19 06:22 . 2009-03-19 06:22 4846 ----a-r- c:\documents and settings\winxp\Application Data\Microsoft\Installer\{627EAB2D-F5AE-4815-AD8E-79129D7959E7}\MSFileRescue.chm1_627EAB2DF5AE4815AD8E79129D7959E7.exe
2009-03-19 01:45 . 2009-03-19 01:45 55768 ----a-w- c:\windows\system32\drivers\epfwtdi.sys
2009-03-19 01:45 . 2009-03-19 01:45 33096 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2009-03-19 01:45 . 2009-03-19 01:45 131976 ----a-w- c:\windows\system32\drivers\epfw.sys
2009-03-19 01:44 . 2009-03-19 01:44 107256 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-03-19 01:41 . 2009-03-19 01:41 113960 ----a-w- c:\windows\system32\drivers\eamon.sys
.
------- Sigcheck -------
[-] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 10:45 360320 2A5554FC5B1E04E131230E3CE035C3F9 c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2004-08-04 12:00 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB941644$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys
[-] 2007-10-30 17:20 360064 90CAFF4B094573449A0872A0F919B178 c:\windows\$NtUninstallKB951748_0$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\ServicePackFiles\i386\TCPIP.SYS
[-] 2008-11-08 23:06 361600 D24EA301E2B36C4E975FD216CA85D8E7 c:\windows\system32\dllcache\TCPIP.SYS
[-] 2008-11-08 23:06 361600 D24EA301E2B36C4E975FD216CA85D8E7 c:\windows\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( 重要登入点 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白与合法缺省登录将不会被显示
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DownloadAccelerator"="c:\program files\DAP\DAP.EXE" [2008-10-18 4555776]
"Steam"="e:\program files\steam\steam.exe" [2009-05-19 1217784]
"NVIDIA nTune"="c:\program files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-09-04 81920]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpeedBitVideoAccelerator"="c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe" [2009-03-12 2823784]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Echovoice Gamer Statistics"="c:\program files\Echovoice\Gamer Statistics\G15 Echovoice Gamer Statistics.exe" [2006-11-28 53248]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"Launch LCDMon"="c:\program files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" [2007-07-17 1687824]
"Launch LGDCore"="c:\program files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" [2007-07-18 2094352]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"egui"="e:\program files\ESET\ESET Smart Security\egui.exe" [2009-03-19 2029640]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-10-10 69632]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-12-26 18081280]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
SetPointII.lnk - e:\program files\Logitech\SetPoint II\SetpointII.exe [2008-11-13 323584]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
2008-11-24 10:35 210168 ----a-w- c:\program files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^winxp^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^winxp^Start Menu^Programs^Startup^Raptr.lnk]
backup=c:\windows\pss\Raptr.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Warez
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"StarWindServiceAE"=2 (0x2)
"RichVideo"=2 (0x2)
"ose"=3 (0x3)
"odserv"=3 (0x3)
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)
"Microsoft Office Groove Audit Service"=3 (0x3)
"iPod Service"=3 (0x3)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"CLTNetCnService"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"Adobe LM Service"=3 (0x3)
"SymSnapService"=3 (0x3)
"Norton Ghost"=2 (0x2)
"LiveUpdate"=3 (0x3)
"TapiSrv"=3 (0x3)
"ServiceLayer"=3 (0x3)
"AdobeActiveFileMonitor7.0"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"e:\\Program Files\\Counter-Strike Source [NON STEAM]\\hl2.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\Program Files\\Steam\\steamapps\\jeff_liu\\condition zero\\hl.exe"=
"e:\\Program Files\\Steam\\steamapps\\jeff_liu\\counter-strike source\\hl2.exe"=
"e:\\Program Files\\Steam\\steamapps\\jeff_liu\\counter-strike\\hl.exe"=
"e:\\Program Files\\Steam\\steamapps\\jeff_liu\\condition zero deleted scenes\\hl.exe"=
"e:\\Program Files\\Steam\\steamapps\\jeff_liu\\source sdk base\\hl2.exe"=
"e:\\Program Files\\Steam\\steamapps\\jeff_liu\\garrysmod\\hl2.exe"=
"e:\\Program Files\\Steam\\steamapps\\jeff_liu\\day of defeat\\hl.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"e:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"e:\\Program Files\\Steam\\Steam.exe"=
"e:\\Program Files\\Steam\\steamapps\\jeff_liu\\source dedicated server\\srcds.exe"=
"e:\\Program Files\\Steam\\steamapps\\jeff_liu\\age of chivalry\\hl2.exe"=
"c:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"d:\\Program Files\\Electronic Arts\\Crytek\\Crysis Wars\\Bin32\\Crysis.exe"=
"c:\\Program Files\\GameSpy\\Comrade\\Comrade.exe"=
"e:\\Program Files\\Steam\\steamapps\\jeff_liu\\insurgency\\hl2.exe"=
"e:\\Program Files\\Steam\\steamapps\\jeff_liu\\deathmatch classic\\hl.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\Program Files\\Steam\\steamapps\\jeff_liu\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"e:\\Program Files\\Steam\\steamapps\\jeff_liu\\day of defeat source\\hl2.exe"=
"e:\\Program Files\\Steam\\steamapps\\jeff_liu\\half-life 2 deathmatch\\hl2.exe"=
"e:\\Program Files\\Steam\\steamapps\\common\\hitman blood money demo\\HitmanBloodMoney.exe"=
"e:\\Program Files\\Steam\\steamapps\\common\\peggle extreme\\PeggleExtreme.exe"=
"c:\\Program Files\\SpeedBit Video Accelerator\\VideoAccelerator.exe"=
"e:\\Program Files\\Rockstar Games\\GTAIV\\GTAIV.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\Program Files\\Steam\\steamapps\\common\\tom clancy's h.a.w.x - demo\\HAWX.exe"=
"e:\\Program Files\\Ubisoft\\Demo\\Tom Clancy's H.A.W.X\\HAWX.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"e:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"41679:TCP"= 41679:TCP:72.20.34.145
"22286:TCP"= 22286:TCP:22286
"22286:UDP"= 22286:UDP:22286
"5353:TCP"= 5353:TCP:*:Disabled:Adobe CSI CS4
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [19/03/2009 11:44 AM 107256]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [12/06/2008 6:22 PM 66048]
R2 ekrn;ESET Service;e:\program files\ESET\ESET Smart Security\ekrn.exe [19/03/2009 11:44 AM 731840]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [6/03/2009 7:54 PM 10384]
R2 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [4/08/2004 10:00 PM 5120]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm --> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
R3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120;c:\windows\system32\drivers\libusb0.sys [20/02/2009 4:54 PM 29184]
S3 CEDRIVER53;CEDRIVER53;c:\program files\Cheat Engine\dbk32.sys [15/06/2008 5:14 PM 25984]
S3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [17/08/2008 9:16 AM 24944]
S3 HssDrv;Hotspot Shield Helper Miniport;c:\windows\system32\drivers\hssdrv.sys [21/04/2009 1:09 PM 33256]
S3 MarkFun_NT;MarkFun_NT;c:\program files\Gigabyte\ET5Pro\MARKFUN.W32 [17/08/2008 9:12 AM 17912]
S3 OZUEXGKCJT;OZUEXGKCJT;c:\docume~1\winxp\LOCALS~1\Temp\OZUEXGKCJT.exe --> c:\docume~1\winxp\LOCALS~1\Temp\OZUEXGKCJT.exe [?]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys --> c:\windows\system32\DRIVERS\wg111v2.sys [?]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys --> c:\windows\system32\drivers\ScreamingBAudio.sys [?]
S4 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;e:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [16/09/2008 1:02 PM 163840]
S4 SymSnapService;SymSnapService;"c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe" --> c:\program files\Norton Ghost\Shared\Drivers\SymSnapService.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
‘计划任务’ 文件夹 里的内容
2009-06-06 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 06:04]
2009-06-06 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 06:04]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- 而外的扫描 -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: Download Link Using Mega Manager... - e:\program files\Megaupload\Mega Manager\mm_file.htm
LSP: c:\progra~1\SPEEDB~1\sblsp.dll
FF - ProfilePath - c:\documents and settings\winxp\Application Data\Mozilla\Firefox\Profiles\qu1t21p8.default\
FF - component: c:\documents and settings\winxp\Application Data\Mozilla\Firefox\Profiles\qu1t21p8.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - component: e:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\winxp\Application Data\Mozilla\Firefox\Profiles\qu1t21p8.default\extensions\
[email protected]\plugins\npTVUAx.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-06 18:16
Windows 5.1.2600 Service Pack 3 NTFS
扫描被隐藏的进程 。。。
扫描被隐藏的启动组 。。。
扫描被隐藏的文件 。。。
扫描完成
被隐藏的档案: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MarkFun_NT]
"ImagePath"="\??\c:\program files\Gigabyte\ET5Pro\markfun.w32"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-682003330-1417001333-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
[HKEY_USERS\S-1-5-21-682003330-1417001333-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:21,62,1f,ab,25,56,c4,8f,0c,8e,db,39,9c,ab,3a,88,fa,d7,6d,3c,dc,
76,fd,eb,4d,68,14,e1,d6,3e,3a,71,39,5f,2d,b4,5b,37,68,09,41,71,e3,06,b4,e9,\
"rkeysecu"=hex:34,ff,98,8f,58,23,be,a7,ab,97,5c,1e,92,3a,a8,e1
[HKEY_LOCAL_MACHINE\software\Ellusionist\Ellusionist TROUBL_MAKER*]
"HTML"="c:\\Program Files\\Ellusionist TROUBL_MAKER\\HTML"
"VIDEO"="c:\\Program Files\\Ellusionist TROUBL_MAKER\\HTML\\VIDEO"
"Shortcut Folder"="c:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Ellusionist Video Player"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\燨譾sf廗b4*ck_Hr]
"SlowInfoCache"=hex:28,02,00,00,00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,00,00,
00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
"Changed"=dword:00000000
.
--------------------- 运行进程下的动态链接库 ---------------------
- - - - - - - > 'winlogon.exe'(612)
c:\program files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
- - - - - - - > 'explorer.exe'(3140)
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
e:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
e:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
e:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
e:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ 其他运行进程 ------------------------
.
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe
c:\windows\system32\msdtc.exe
c:\windows\system32\conime.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe
c:\windows\system32\rundll32.exe
c:\program files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\dwwin.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
.
**************************************************************************
.
完成时间: 2009-06-07 18:20 - 电脑已重新启动
ComboFix-quarantined-files.txt 2009-06-07 08:20
Pre-Run: 19,096,834,048 bytes free
Post-Run: 18,951,897,088 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-CHS.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /numproc=2
404 --- E O F --- 2009-05-14 10:12