Combo fix
-
Combo fix
For a while I have big problems with system32, notepads.exe, intranetexplorer.exe etc.
I use Bitdefender antivirus, but it showed nothing infected.
Then I used Malwarebytes' Anti Malware and it found infected files.
I run Combo fix.
This is txt file.
Please, help.
ComboFix 09-01-08.01 - VELEVI 2009-01-08 21:12:19.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1251.1.1033.18.1279.801 [GMT 1:00]
Running from: C:\Documents and Settings\VELEVI\Desktop\ComboFix.exe
AV: Bitdefender Antivirus *On-access scanning disabled* (Updated)
FW: Bitdefender Firewall *disabled*
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\i
F:\autorun.inf
----- BITS: Possible infected sites -----
hxxp://childhe.com
.
((((((((((((((((((((((((( Files Created from 2008-12-08 to 2009-01-08 )))))))))))))))))))))))))))))))
.
2009-01-08 20:30 . 2009-01-08 20:49 70,656 --a------ C:\main.exe
2009-01-08 20:19 . 2009-01-08 20:21 <DIR> d-------- C:\AMIGOSI
2009-01-08 20:00 . 2009-01-08 20:00 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Applicati on Data\HPAppData
2009-01-08 19:31 . 2009-01-08 19:31 <DIR> d-------- C:\Program Files\TeamViewer3
2009-01-08 19:18 . 2009-01-08 19:18 70,656 -r-hs---- C:\WINDOWS\usb_driver.exe
2009-01-04 21:07 . 2009-01-04 21:18 <DIR> d-------- C:\Documents and Settings\VELEVI\.housecall6.6
2009-01-04 21:07 . 2009-01-04 21:07 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2009-01-04 20:17 . 2009-01-08 20:56 34,861 --a------ C:\dial12_dialer.exe
2009-01-04 20:16 . 2009-01-04 20:16 36,015 --a------ C:\WINDOWS\system32\ub.exe
2009-01-04 20:16 . 2009-01-04 20:16 36,015 -r-hs---- C:\WINDOWS\notepads.exe
2009-01-04 09:11 . 2009-01-04 09:11 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-04 09:11 . 2009-01-04 09:11 <DIR> d-------- C:\Documents and Settings\VELEVI\Application Data\Malwarebytes
2009-01-04 09:11 . 2009-01-04 09:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-04 09:11 . 2008-12-03 19:59 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2009-01-04 09:11 . 2008-12-03 19:59 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2009-01-02 21:20 . 2009-01-02 21:40 559 --a------ C:\pf500.in
2009-01-02 21:20 . 2009-01-02 21:40 0 --a------ C:\pf500.out
2009-01-02 21:20 . 2009-01-02 21:40 0 --a------ C:\pf500.err
2009-01-02 21:02 . 2002-06-28 15:27 139,776 --a------ C:\FISCAL32.EXE
2009-01-02 21:02 . 2002-08-28 14:08 119 --a------ C:\FISKAL.INI
2009-01-02 20:11 . 2009-01-02 20:11 63,630 --------- C:\WINDOWS\system32\pm.exe
2009-01-02 20:01 . 2009-01-02 20:01 <DIR> d-------- C:\Documents and Settings\VELEVI\Application Data\TeamViewer
2009-01-02 20:00 . 2009-01-02 20:00 <DIR> d-------- C:\Documents and Settings\VELEVI\temp
2009-01-02 19:30 . 2009-01-08 19:53 <DIR> d-------- C:\RST
2009-01-02 19:18 . 2009-01-08 20:52 1,661,005 --a------ C:\ostanato.rar
2009-01-02 19:14 . 2009-01-02 19:15 <DIR> d-------- C:\ostanato
2009-01-02 19:13 . 2009-01-08 20:53 3,076,401 --a------ C:\SYS.rar
2009-01-02 19:12 . 2009-01-08 20:51 1,631,703 --a------ C:\ICO.rar
2008-12-28 21:15 . 2008-12-28 21:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-12-28 16:34 . 2008-12-28 21:15 <DIR> d-------- C:\RST(2)
2008-12-28 16:34 . 2008-12-28 16:34 <DIR> d-------- C:\Images
2008-12-28 11:10 . 2008-12-28 21:15 <DIR> d-------- C:\Program Files\RegCure
2008-12-15 18:51 . 2008-12-15 18:51 <DIR> d-------- C:\maja
2008-12-15 18:50 . 2008-12-28 21:15 <DIR> d-------- C:\se_za_rest
2008-12-12 19:56 . 2008-12-28 21:16 <DIR> d-------- C:\ICO
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-01-07 21:53 --------- d-----w C:\Program Files\Winamp Remote
2009-01-04 18:43 --------- d-----w C:\Program Files\Secured eMule
2009-01-04 08:38 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2009-01-02 21:01 --------- d-----w C:\Documents and Settings\VELEVI\Application Data\Skype
2009-01-02 17:57 --------- d-----w C:\Documents and Settings\VELEVI\Application Data\skypePM
2008-12-29 18:51 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-12-28 16:44 --------- d-----w C:\Program Files\eMule
2008-12-28 16:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-11-15 18:59 --------- d-----w C:\Documents and Settings\VELEVI\Application Data\CoSoSys
2008-11-15 16:31 --------- d-----w C:\Program Files\Microsoft Visual FoxPro 9
2008-11-14 09:32 95,774 ----a-w C:\vfpcalendar.zip
2008-11-11 19:21 0 ---ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01007_C oinstaller_Critical.Wdf
2008-11-11 19:21 0 ---ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_ccdcmb_010 07.Wdf
2008-11-11 19:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nokia
2008-11-11 19:16 --------- d-----w C:\Program Files\Nokia
2008-11-11 19:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2008-11-11 19:15 --------- d-----w C:\Program Files\Common Files\Nokia
2008-11-01 18:06 15 ----a-w C:\mapx.bat
2008-03-07 15:22 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-07-19 23:19 855,886 ----a-w C:\Program Files\AUG2007_d3dx10_35_x64.cab
2007-07-19 23:19 800,467 ----a-w C:\Program Files\AUG2007_d3dx10_35_x86.cab
2007-07-19 23:19 1,803,760 ----a-w C:\Program Files\AUG2007_d3dx9_35_x64.cab
2007-07-19 23:18 44,684 ----a-w C:\Program Files\dxdllreg_x86.cab
2007-07-19 23:18 201,696 ----a-w C:\Program Files\AUG2007_XACT_x64.cab
2007-07-19 23:18 156,612 ----a-w C:\Program Files\AUG2007_XACT_x86.cab
2007-07-19 23:18 1,711,752 ----a-w C:\Program Files\AUG2007_d3dx9_35_x86.cab
2007-03-18 16:54 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((( snapshot@2009-01-04_ 9.51.05,14 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-04 08:46:55 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
+ 2009-01-08 20:15:16 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
- 2008-09-20 15:09:04 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\i ndex.dat
+ 2009-01-08 19:00:45 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\i ndex.dat
- 2008-09-20 15:09:04 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-08 19:00:45 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-08 19:00:47 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012009010820090 109\index.dat
+ 2009-01-08 19:00:34 78,924 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat
- 2008-09-20 15:09:04 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-08 19:00:47 49,152 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-08 19:00:50 76,286 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\JY9Z7Y2X\filters[1].bin
+ 2009-01-08 19:00:53 54,999 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KJR94BB9\parameters[1].bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2008-07-16 21:51 1266992]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2006-09-26 22:09 1694208]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 16:23 111856]
"Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2008-01-07 21:02 495616]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe" [2008-04-21 08:54 36864]
"Search Protection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 16:23 111856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [2004-08-25 10:26 1465856]
"BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [2007-03-26 15:49 69632]
"BDMCon"="C:\Program Files\Softwin\BitDefender10\bdmcon.exe" [2007-11-01 18:52 290816]
"LVCOMSX"="C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-11-15 21:01 244512]
"QuickTime Task"="C:\Program Files\MpcStar\Codecs\QuickTime\QTSystem\qttask.exe " [2007-02-22 19:48 282624]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 01:38 34672]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 16:23 111856]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 21:34 49152]
"Microsoft USB Driver"="usb_driver.exe" [2009-01-08 19:18 70656 C:\WINDOWS\usb_driver.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:56 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 21:26:24 210520]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-04-21 08:54:07 196608]
-
If you still need help please post that information.