Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Power Lifting Lever Belt
SkullVamp
Updated:
Saturday at 10:32 PM
Ad icon
port.lk Domain for sale
Lankan-Tech
Updated:
Saturday at 3:55 PM
Colombo
Kaduwela - Two Storey House for Sale
dilrasan
Updated:
Thursday at 2:23 PM
Ad icon
Wechat qr verification
Pawan2005
Updated:
Thursday at 1:28 AM
🚀 GOOGLE AI PRO 18 MONTHS ACTIVATION 🚀
sayuru bandara
Updated:
Wednesday at 5:34 PM
Electronics
Vehicles
Property
Search
Reply to thread
Forums
General
ElaKiri Talk!
Virus Problem Plz help me.
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="Hayao" data-source="post: 5533950" data-attributes="member: 238183"><p>I used it. This is what I got. What shd i do now????</p><p></p><p>ComboFix 09-09-14.02 - Poorna Yap 09/16/2009 21:35.1.1 - NTFSx86</p><p>Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.447.137 [GMT 6:00]</p><p>Running from: c:\documents and settings\Poorna Yap\Desktop\ComboFix.exe</p><p>AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}</p><p>.</p><p></p><p>((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))</p><p>.</p><p></p><p>c:\documents and settings\All Users\Application Data\vinorasomy._sy</p><p>c:\documents and settings\All Users\Documents\luvobu.vbs</p><p>c:\documents and settings\All Users\Documents\ozotohiri.vbs</p><p>c:\documents and settings\Poorna Yap\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk</p><p>c:\documents and settings\Poorna Yap\Application Data\osenapicyv.dll</p><p>c:\documents and settings\Poorna Yap\Application Data\wiaserva.log</p><p>c:\documents and settings\Poorna Yap\Application Data\ypyqy.dll</p><p>c:\documents and settings\Poorna Yap\Cookies\atuhux.inf</p><p>c:\documents and settings\Poorna Yap\Cookies\avyjofapuh.com</p><p>c:\documents and settings\Poorna Yap\Cookies\diheh.bin</p><p>c:\documents and settings\Poorna Yap\Cookies\luqed.bin</p><p>c:\documents and settings\Poorna Yap\delself.bat</p><p>c:\documents and settings\Poorna Yap\Desktop\AntivirusPro_2010.lnk</p><p>c:\documents and settings\Poorna Yap\Local Settings\Application Data\agov.inf</p><p>c:\documents and settings\Poorna Yap\Local Settings\Application Data\weqocavam.ban</p><p>c:\documents and settings\Poorna Yap\Local Settings\Temporary Internet Files\huhek.db</p><p>c:\documents and settings\Poorna Yap\Local Settings\Temporary Internet Files\idomyzucav.bat</p><p>c:\documents and settings\Poorna Yap\Start Menu\Programs\AntivirusPro_2010</p><p>c:\documents and settings\Poorna Yap\Start Menu\Programs\AntivirusPro_2010\AntivirusPro_2010.lnk</p><p>c:\documents and settings\Poorna Yap\Start Menu\Programs\AntivirusPro_2010\Uninstall.lnk</p><p>c:\documents and settings\Poorna Yap\Start Menu\Programs\Startup\ikowin32.exe</p><p>c:\documents and settings\Poorna Yap\sys32_nov.exe</p><p>c:\program files\AntivirusPro_2010</p><p>c:\program files\AntivirusPro_2010\AntivirusPro_2010.cfg</p><p>c:\program files\AntivirusPro_2010\AntivirusPro_2010.exe</p><p>c:\program files\AntivirusPro_2010\AVEngn.dll</p><p>c:\program files\AntivirusPro_2010\data\daily.cvd</p><p>c:\program files\AntivirusPro_2010\htmlayout.dll</p><p>c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest</p><p>c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcm80.dll</p><p>c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcp80.dll</p><p>c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcr80.dll</p><p>c:\program files\AntivirusPro_2010\pthreadVC2.dll</p><p>c:\program files\AntivirusPro_2010\Uninstall.exe</p><p>c:\program files\AntivirusPro_2010\wscui.cpl</p><p>c:\program files\Common Files\aveqekavi._dl</p><p>c:\program files\Common Files\jagador.inf</p><p>c:\program files\Common Files\kisimihovi.vbs</p><p>c:\program files\Common Files\onawopofem.dll</p><p>c:\program files\Common Files\xikoty.com</p><p>c:\windows\gykirys.reg</p><p>c:\windows\idyki.inf</p><p>c:\windows\Installer\52a69.msi</p><p>c:\windows\ivohoga.exe</p><p>c:\windows\olprosys.dll</p><p>c:\windows\system32\_scui.cpl</p><p>c:\windows\system32\braviax.exe</p><p>c:\windows\system32\sys32_nov.exe</p><p>c:\windows\system32\wisdstr.exe</p><p></p><p>.</p><p>((((((((((((((((((((((((( Files Created from 2009-08-16 to 2009-09-16 )))))))))))))))))))))))))))))))</p><p>.</p><p></p><p>2009-09-16 15:13 . 2009-09-16 15:13 -------- d-----w- c:\documents and settings\Poorna Yap\Application Data\Malwarebytes</p><p>2009-09-16 15:13 . 2009-09-10 08:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys</p><p>2009-09-16 15:13 . 2009-09-16 15:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes</p><p>2009-09-16 15:13 . 2009-09-10 08:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys</p><p>2009-09-16 15:13 . 2009-09-16 15:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware</p><p>2009-09-16 15:09 . 2009-09-16 15:09 17043 ----a-w- c:\windows\epop.com</p><p>2009-09-16 14:55 . 2009-09-16 14:55 28672 ----a-w- c:\windows\system32\drivers\beep.sys.vir</p><p>2009-09-16 14:53 . 2009-09-16 15:14 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP</p><p>2009-09-16 14:53 . 2006-06-19 07:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll</p><p>2009-09-16 14:53 . 2006-05-25 09:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll</p><p>2009-09-16 14:53 . 2005-08-25 19:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll</p><p>2009-09-16 14:53 . 2003-02-02 14:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll</p><p>2009-09-16 14:53 . 2002-03-05 19:00 75264 ----a-w- c:\windows\system32\unacev2.dll</p><p>2009-09-16 14:53 . 2009-09-16 14:53 -------- d-----w- c:\program files\Trojan Remover</p><p>2009-09-16 14:53 . 2009-09-16 14:53 -------- d-----w- c:\documents and settings\Poorna Yap\Application Data\Simply Super Software</p><p>2009-09-16 14:53 . 2009-09-16 14:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Simply Super Software</p><p>2009-09-16 14:49 . 2009-09-16 14:49 -------- d-----w- c:\program files\Trend Micro</p><p>2009-09-16 11:26 . 2009-09-16 11:26 28672 -c--a-w- c:\windows\system32\dllcache\figaro.sys.vir</p><p>2009-09-16 06:54 . 2009-09-16 06:56 177968 ----a-w- c:\windows\system32\wisdstr.exe.vir</p><p>2009-09-16 06:54 . 2009-09-16 11:26 10752 ----a-w- c:\windows\system32\braviax.exe.vir</p><p>2009-09-16 06:51 . 2009-09-16 06:51 -------- d-----w- c:\windows\Sun</p><p>2009-09-13 13:05 . 2009-09-13 13:05 -------- d-----w- c:\windows\I386</p><p>2009-09-13 13:05 . 2005-01-16 17:47 988400 ----a-w- c:\windows\SinhalaQFE.exe</p><p>2009-09-13 13:01 . 2009-09-16 10:55 -------- d-----w- c:\documents and settings\Poorna Yap\Application Data\IObit</p><p>2009ffice\Office12\GrooveMonitor.exe" [2006-10-26 31016]</p><p>"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]</p><p>"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]</p><p>"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]</p><p>"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-26 161328]</p><p>"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-08-26 111928]</p><p>"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-09-15 1069960]</p><p>"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-10-03 16269312]</p><p>"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2007-10-03 2879488]</p><p></p><p>c:\documents and settings\Poorna Yap\Start Menu\Programs\Startup\</p><p>Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]</p><p>Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2009-8-19 344064]</p><p></p><p>c:\documents and settings\All Users\Start Menu\Programs\Startup\</p><p>SinhalaKit.lnk - c:\program files\SinhalaTamil Kit\SinhalaKit.exe [2009-9-12 98304]</p><p>SinhalaTamil Kit.lnk - c:\program files\SinhalaTamil Kit\TamilKit.exe [2009-9-12 94208]</p><p></p><p>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]</p><p>"ForceClassicControlPanel"= 1 (0x1)</p><p></p><p>[HKEY_LOCAL_MACHINE\software\microsoft\security center]</p><p>"UpdatesDisableNotify"=dword:00000001</p><p></p><p>[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]</p><p>"DisableMonitoring"=dword:00000001</p><p></p><p>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]</p><p>"EnableFirewall"= 0 (0x0)</p><p></p><p>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]</p><p>"%windir%\\system32\\sessmgr.exe"=</p><p>"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=</p><p>"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=</p><p>"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=</p><p>"c:\\Program Files\\Vuze\\Azureus.exe"=</p><p>"c:\\Program Files\\Java\\jre1.6.0_03\\bin\\java.exe"=</p><p>"c:\\Program Files\\Java\\jdk1.6.0_03\\bin\\java.exe"=</p><p></p><p>[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]</p><p>"3389:TCP"= 3389:TCP<img src="data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7" class="smilie smilie--sprite smilie--sprite4" alt=":mad:" title="Mad :mad:" loading="lazy" data-shortname=":mad:" />xpsp2res.dll,-22009</p><p></p><p>R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [7/17/2009 1:03 PM 603904]</p><p>S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [8/6/2004 2:48 PM 169192]</p><p></p><p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs</p><p>UxTuneUp</p><p>.</p><p>Contents of the 'Scheduled Tasks' folder</p><p></p><p>2009-09-16 c:\windows\Tasks\1-Click Maintenance.job</p><p>- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 10:28]</p><p></p><p>2009-09-16 c:\windows\Tasks\AWC AutoSweep.job</p><p>- c:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2009-09-16 09:35]</p><p>.</p><p>.</p><p>------- Supplementary Scan -------</p><p>.</p><p>uStart Page = hxxp://www.google.com</p><p>mStart Page = hxxp://www.google.com</p><p>TCP: {F5F7E0C0-D32C-4B73-9189-9B33032AAA70} = 203.115.0.46,203.115.0.47</p><p>FF - ProfilePath - c:\documents and settings\Poorna Yap\Application Data\Mozilla\Firefox\Profiles\ndy55q8c.default\</p><p>FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q=</p><p>FF - prefs.js: network.proxy.type - 4</p><p></p><p>---- FIREFOX POLICIES ----</p><p>FF - user.js: network.http.max-persistent-connections-per-server - 4</p><p>FF - user.js: nglayout.initialpaint.delay - 600</p><p>FF - user.js: content.notify.interval - 600000</p><p>FF - user.js: content.max.tokenizing.time - 1800000</p><p>FF - user.js: content.switch.threshold - 600000</p><p>.</p><p></p><p>**************************************************************************</p><p></p><p>catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, <a href="http://www.gmer.net" target="_blank">http://www.gmer.net</a></p><p>Rootkit scan 2009-09-16 21:40</p><p>Windows 5.1.2600 Service Pack 2 NTFS</p><p></p><p>scanning hidden processes ... </p><p></p><p>scanning hidden autostart entries ... </p><p></p><p>scanning hidden files ... </p><p></p><p>scan completed successfully</p><p>hidden files: 0</p><p></p><p>**************************************************************************</p><p>.</p><p>--------------------- DLLs Loaded Under Running Processes ---------------------</p><p></p><p>- - - - - - - > 'winlogon.exe'(848)</p><p>c:\windows\system32\Ati2evxx.dll</p><p>.</p><p>Completion time: 2009-09-16 21:41</p><p>ComboFix-quarantined-files.txt 2009-09-16 15:41</p><p></p><p>Pre-Run: 5,627,256,832 bytes free</p><p>Post-Run: 5,694,898,176 bytes free</p><p></p><p>WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe</p><p>[boot loader]</p><p>timeout=2</p><p>default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS</p><p>[operating systems]</p><p>c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons</p><p>multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect</p><p>C:\wubildr.mbr = "Ubuntu"</p><p></p><p>280</p></blockquote><p></p>
[QUOTE="Hayao, post: 5533950, member: 238183"] I used it. This is what I got. What shd i do now???? ComboFix 09-09-14.02 - Poorna Yap 09/16/2009 21:35.1.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.447.137 [GMT 6:00] Running from: c:\documents and settings\Poorna Yap\Desktop\ComboFix.exe AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\vinorasomy._sy c:\documents and settings\All Users\Documents\luvobu.vbs c:\documents and settings\All Users\Documents\ozotohiri.vbs c:\documents and settings\Poorna Yap\Application Data\Microsoft\Internet Explorer\Quick Launch\AntivirusPro_2010.lnk c:\documents and settings\Poorna Yap\Application Data\osenapicyv.dll c:\documents and settings\Poorna Yap\Application Data\wiaserva.log c:\documents and settings\Poorna Yap\Application Data\ypyqy.dll c:\documents and settings\Poorna Yap\Cookies\atuhux.inf c:\documents and settings\Poorna Yap\Cookies\avyjofapuh.com c:\documents and settings\Poorna Yap\Cookies\diheh.bin c:\documents and settings\Poorna Yap\Cookies\luqed.bin c:\documents and settings\Poorna Yap\delself.bat c:\documents and settings\Poorna Yap\Desktop\AntivirusPro_2010.lnk c:\documents and settings\Poorna Yap\Local Settings\Application Data\agov.inf c:\documents and settings\Poorna Yap\Local Settings\Application Data\weqocavam.ban c:\documents and settings\Poorna Yap\Local Settings\Temporary Internet Files\huhek.db c:\documents and settings\Poorna Yap\Local Settings\Temporary Internet Files\idomyzucav.bat c:\documents and settings\Poorna Yap\Start Menu\Programs\AntivirusPro_2010 c:\documents and settings\Poorna Yap\Start Menu\Programs\AntivirusPro_2010\AntivirusPro_2010.lnk c:\documents and settings\Poorna Yap\Start Menu\Programs\AntivirusPro_2010\Uninstall.lnk c:\documents and settings\Poorna Yap\Start Menu\Programs\Startup\ikowin32.exe c:\documents and settings\Poorna Yap\sys32_nov.exe c:\program files\AntivirusPro_2010 c:\program files\AntivirusPro_2010\AntivirusPro_2010.cfg c:\program files\AntivirusPro_2010\AntivirusPro_2010.exe c:\program files\AntivirusPro_2010\AVEngn.dll c:\program files\AntivirusPro_2010\data\daily.cvd c:\program files\AntivirusPro_2010\htmlayout.dll c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcm80.dll c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcp80.dll c:\program files\AntivirusPro_2010\Microsoft.VC80.CRT\msvcr80.dll c:\program files\AntivirusPro_2010\pthreadVC2.dll c:\program files\AntivirusPro_2010\Uninstall.exe c:\program files\AntivirusPro_2010\wscui.cpl c:\program files\Common Files\aveqekavi._dl c:\program files\Common Files\jagador.inf c:\program files\Common Files\kisimihovi.vbs c:\program files\Common Files\onawopofem.dll c:\program files\Common Files\xikoty.com c:\windows\gykirys.reg c:\windows\idyki.inf c:\windows\Installer\52a69.msi c:\windows\ivohoga.exe c:\windows\olprosys.dll c:\windows\system32\_scui.cpl c:\windows\system32\braviax.exe c:\windows\system32\sys32_nov.exe c:\windows\system32\wisdstr.exe . ((((((((((((((((((((((((( Files Created from 2009-08-16 to 2009-09-16 ))))))))))))))))))))))))))))))) . 2009-09-16 15:13 . 2009-09-16 15:13 -------- d-----w- c:\documents and settings\Poorna Yap\Application Data\Malwarebytes 2009-09-16 15:13 . 2009-09-10 08:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-16 15:13 . 2009-09-16 15:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-09-16 15:13 . 2009-09-10 08:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-09-16 15:13 . 2009-09-16 15:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-09-16 15:09 . 2009-09-16 15:09 17043 ----a-w- c:\windows\epop.com 2009-09-16 14:55 . 2009-09-16 14:55 28672 ----a-w- c:\windows\system32\drivers\beep.sys.vir 2009-09-16 14:53 . 2009-09-16 15:14 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-09-16 14:53 . 2006-06-19 07:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll 2009-09-16 14:53 . 2006-05-25 09:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll 2009-09-16 14:53 . 2005-08-25 19:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll 2009-09-16 14:53 . 2003-02-02 14:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll 2009-09-16 14:53 . 2002-03-05 19:00 75264 ----a-w- c:\windows\system32\unacev2.dll 2009-09-16 14:53 . 2009-09-16 14:53 -------- d-----w- c:\program files\Trojan Remover 2009-09-16 14:53 . 2009-09-16 14:53 -------- d-----w- c:\documents and settings\Poorna Yap\Application Data\Simply Super Software 2009-09-16 14:53 . 2009-09-16 14:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Simply Super Software 2009-09-16 14:49 . 2009-09-16 14:49 -------- d-----w- c:\program files\Trend Micro 2009-09-16 11:26 . 2009-09-16 11:26 28672 -c--a-w- c:\windows\system32\dllcache\figaro.sys.vir 2009-09-16 06:54 . 2009-09-16 06:56 177968 ----a-w- c:\windows\system32\wisdstr.exe.vir 2009-09-16 06:54 . 2009-09-16 11:26 10752 ----a-w- c:\windows\system32\braviax.exe.vir 2009-09-16 06:51 . 2009-09-16 06:51 -------- d-----w- c:\windows\Sun 2009-09-13 13:05 . 2009-09-13 13:05 -------- d-----w- c:\windows\I386 2009-09-13 13:05 . 2005-01-16 17:47 988400 ----a-w- c:\windows\SinhalaQFE.exe 2009-09-13 13:01 . 2009-09-16 10:55 -------- d-----w- c:\documents and settings\Poorna Yap\Application Data\IObit 2009ffice\Office12\GrooveMonitor.exe" [2006-10-26 31016] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928] "LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-26 161328] "SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-08-26 111928] "TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-09-15 1069960] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-10-03 16269312] "SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2007-10-03 2879488] c:\documents and settings\Poorna Yap\Start Menu\Programs\Startup\ Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2009-8-19 344064] c:\documents and settings\All Users\Start Menu\Programs\Startup\ SinhalaKit.lnk - c:\program files\SinhalaTamil Kit\SinhalaKit.exe [2009-9-12 98304] SinhalaTamil Kit.lnk - c:\program files\SinhalaTamil Kit\TamilKit.exe [2009-9-12 94208] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "ForceClassicControlPanel"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Vuze\\Azureus.exe"= "c:\\Program Files\\Java\\jre1.6.0_03\\bin\\java.exe"= "c:\\Program Files\\Java\\jdk1.6.0_03\\bin\\java.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [7/17/2009 1:03 PM 603904] S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [8/6/2004 2:48 PM 169192] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the 'Scheduled Tasks' folder 2009-09-16 c:\windows\Tasks\1-Click Maintenance.job - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 10:28] 2009-09-16 c:\windows\Tasks\AWC AutoSweep.job - c:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2009-09-16 09:35] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com mStart Page = hxxp://www.google.com TCP: {F5F7E0C0-D32C-4B73-9189-9B33032AAA70} = 203.115.0.46,203.115.0.47 FF - ProfilePath - c:\documents and settings\Poorna Yap\Application Data\Mozilla\Firefox\Profiles\ndy55q8c.default\ FF - prefs.js: keyword.URL - hxxp://search.sweetim.com/search.asp?src=2&q= FF - prefs.js: network.proxy.type - 4 ---- FIREFOX POLICIES ---- FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [url]http://www.gmer.net[/url] Rootkit scan 2009-09-16 21:40 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(848) c:\windows\system32\Ati2evxx.dll . Completion time: 2009-09-16 21:41 ComboFix-quarantined-files.txt 2009-09-16 15:41 Pre-Run: 5,627,256,832 bytes free Post-Run: 5,694,898,176 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect C:\wubildr.mbr = "Ubuntu" 280 [/QUOTE]
Insert quotes…
Verification
Payakata winadi keeyak tibeda?
Post reply
Top
Bottom