Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\cxmddlnb
*******************
Script file located at: \??\C:\fbqwwgra.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Driver ServerAC unloaded successfully.
File C:\WINDOWS\SMSS.EXE deleted successfully.
File C:\WINDOWS\SVCHOST.EXE deleted successfully.
File C:\WINDOWS\RUNDLL32.exe deleted successfully.
File C:\WINDOWS\system32\49400M.BMP not found!
Deletion of file C:\WINDOWS\system32\49400M.BMP failed!
Could not process line:
C:\WINDOWS\system32\49400M.BMP
Status: 0xc0000034
File C:\WINDOWS\system32\Security.exe deleted successfully.
Completed script processing.
*******************
Finished! Terminate.作者: ALEXYUI 時間: 07-1-8 11:36 PM
Logfile of HijackThis v1.99.1
Scan saved at 23:35:44, on 8/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
[Scan path] c:\documents and settings\all users\「開(c)l」功能表\程式集\啟動\desktop.ini
[Scan path] c:\documents and settings\hp_owner.your-6a15acd7c6\local settings\temp\rarsfx0\_start.exe
[Scan path] c:\documents and settings\hp_owner.your-6a15acd7c6\local settings\temp\rarsfx0\cureit.exe
[Scan path] c:\documents and settings\hp_owner.your-6a15acd7c6\「開(c)l」功能表\程式集\啟動\desktop.ini
[Scan path] c:\documents and settings\hp_owner.your-6a15acd7c6\(R)酯崤crossgatepuk3\crossgatepuk3\cg_5006.exe
c:\documents and settings\hp_owner.your-6a15acd7c6\(R)酯崤crossgatepuk3\crossgatepuk3\cg_5006.exe probably infected with DLOADER.Trojan
[Scan path] c:\documents and settings\all users\「開(c)l」功能表\程式集\啟動\desktop.ini
[Scan path] c:\documents and settings\hp_owner.your-6a15acd7c6\local settings\temp\rarsfx0\_start.exe
[Scan path] c:\documents and settings\hp_owner.your-6a15acd7c6\local settings\temp\rarsfx0\cureit.exe
[Scan path] c:\documents and settings\hp_owner.your-6a15acd7c6\「開(c)l」功能表\程式集\啟動\desktop.ini
[Scan path] c:\documents and settings\hp_owner.your-6a15acd7c6\(R)酯崤crossgatepuk3\crossgatepuk3\cg_5006.exe
c:\documents and settings\hp_owner.your-6a15acd7c6\(R)酯崤crossgatepuk3\crossgatepuk3\cg_5006.exe probably infected with DLOADER.Trojan
=============================================================================
Dr.Web(R) Scanner for Windows v4.33.2 (4.33.2.10060)
Copyright (c) Igor Daniloff, 1992-2006
Log generated on: 2007-01-11, 00:53:54 [HP_Owner]
Command-line: "C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\cureit.exe" /lng /ini:cureit_XP.ini
Operating system:Windows XP Home Edition x86 (Build 2600), Service Pack 2
=============================================================================作者: ALEXYUI 時間: 07-1-11 09:24 PM
Engine version: 4.33 (4.33.5.10110)
Engine API version: 2.01
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crwtoday.cdb - 582 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43369.cdb - 687 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43368.cdb - 1099 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43367.cdb - 1834 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43366.cdb - 4015 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43365.cdb - 1342 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43364.cdb - 1335 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43363.cdb - 1152 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43362.cdb - 1006 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43361.cdb - 879 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43360.cdb - 988 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43359.cdb - 1205 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43358.cdb - 1139 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43357.cdb - 1302 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43356.cdb - 1332 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43355.cdb - 2456 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43354.cdb - 1283 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43353.cdb - 795 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43352.cdb - 2016 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43351.cdb - 941 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43350.cdb - 1020 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43349.cdb - 1008 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43348.cdb - 1096 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43347.cdb - 707 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43346.cdb - 1428 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43345.cdb - 1358 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43344.cdb - 694 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43343.cdb - 1186 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43342.cdb - 744 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43341.cdb - 841 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43340.cdb - 822 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43339.cdb - 1071 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43338.cdb - 989 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43337.cdb - 855 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43336.cdb - 1297 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43335.cdb - 1195 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43334.cdb - 900 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43333.cdb - 1381 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43332.cdb - 1340 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43331.cdb - 2735 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43330.cdb - 2078 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43329.cdb - 2490 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43328.cdb - 743 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43327.cdb - 958 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43326.cdb - 793 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43325.cdb - 713 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43324.cdb - 655 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43323.cdb - 655 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43322.cdb - 778 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43321.cdb - 846 virus records作者: ALEXYUI 時間: 07-1-11 09:25 PM
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43320.cdb - 808 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43319.cdb - 764 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43318.cdb - 838 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43317.cdb - 363 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43316.cdb - 730 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43315.cdb - 627 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43314.cdb - 824 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43313.cdb - 842 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43312.cdb - 830 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43311.cdb - 862 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43310.cdb - 853 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43309.cdb - 733 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43308.cdb - 708 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43307.cdb - 839 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43306.cdb - 930 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43305.cdb - 759 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43304.cdb - 721 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43303.cdb - 638 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43302.cdb - 806 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43301.cdb - 504 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crw43300.cdb - 24 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crwebase.cdb - 78674 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\cwrtoday.cdb - 380 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\cwr43301.cdb - 697 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crwrisky.cdb - 1271 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\cwntoday.cdb - 371 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\cwn43306.cdb - 781 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\cwn43305.cdb - 752 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\cwn43304.cdb - 793 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\cwn43303.cdb - 766 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\cwn43302.cdb - 850 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\cwn43301.cdb - 772 virus records
[Virus base] C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\crwnasty.cdb - 4867 virus records
Total virus records: 166741
Key file: C:\DOCUME~1\HP_OWN~1.YOU\LOCALS~1\Temp\RarSFX0\cureit.key
License key number: 0000000010
Registered to: Dr.Web CureIt Project
License key activates: 2005-03-05
License key expires: 2007-03-05