This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware removal with ComboFix

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

As suggested by ComboFix I herewith submit ComboFix report for instruction what to do next.
Please, help, Zoran
Thank You



ComboFix 10-08-23.02 - Boza 08/24/2010 8:39.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1574 [GMT 2:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: Emsisoft Anti-Malware *On-access scanning disabled* (Outdated) {0F8591BB-342B-4493-91C3-4E948ED21255}
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\_000018_.tmp.dll

.
((((((((((((((((((((((((( Files Created from 2010-07-24 to 2010-08-24 )))))))))))))))))))))))))))))))
.

2010-08-23 12:36 . 2010-08-23 12:36 ——– d—–w- c:\windows\system32\wbem\Repository
2010-08-23 12:34 . 2010-08-23 12:34 ——– d—–w- c:\documents and settings\All Users\Application Data\RegCure
2010-08-19 06:57 . 2010-08-23 12:24 ——– d—–w- c:\program files\Security Task Manager
2010-08-16 06:51 . 2010-08-24 05:58 ——– d—–w- c:\program files\Apophysis 2.0
2010-08-12 07:22 . 2010-08-12 07:22 ——– d—–w- c:\documents and settings\Boza\Application Data\Philipp Winterberg
2010-08-12 07:21 . 2010-08-12 07:21 ——– d—–w- c:\program files\Free RAR Extract Frog
2010-08-11 13:29 . 2010-08-19 11:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-08-11 13:29 . 2010-08-11 13:31 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-08-10 15:04 . 2010-08-10 15:04 ——– d—–w- c:\documents and settings\Boza\Application Data\Yahoo!
2010-08-10 15:04 . 2010-08-11 15:29 ——– d—–w- c:\program files\Yahoo!
2010-08-10 09:39 . 2010-08-10 09:39 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-08-10 09:39 . 2010-08-10 09:39 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-08-04 11:10 . 2010-08-10 09:39 ——– d—–w- c:\documents and settings\Boza\Local Settings\Application Data\Adobe
2010-07-29 09:27 . 2010-08-05 07:57 ——– d—–w- c:\program files\HeatexSelect
2010-07-28 10:50 . 2007-11-06 07:06 11568 —-a-w- c:\windows\system32\drivers\UimFIO.sys
2010-07-28 10:50 . 2007-11-06 07:06 32080 —-a-w- c:\windows\system32\drivers\UimBus.sys
2010-07-28 10:50 . 2007-11-06 07:06 131672 —-a-w- c:\windows\system32\drivers\Uim_IM.sys
2010-07-28 10:50 . 2008-01-21 15:43 4244744 —-a-w- c:\windows\system32\qtp-mt334.dll
2010-07-28 10:50 . 2008-01-21 15:43 13576 —-a-w- c:\windows\system32\wnaspi32.dll
2010-07-28 10:50 . 2008-01-21 15:43 247560 —-a-w- c:\windows\system32\prgiso.dll
2010-07-28 10:50 . 2007-11-06 07:06 39472 —-a-w- c:\windows\system32\drivers\hotcore3.sys
2010-07-28 10:49 . 2010-07-28 10:50 ——– d—–w- c:\program files\Paragon Software
2010-07-26 11:37 . 2010-06-14 14:30 743936 -c—-w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-26 08:05 . 2010-07-26 08:51 ——– d—–w- c:\documents and settings\Boza\Local Settings\Application Data\Conduit
2010-07-26 08:05 . 2010-07-26 08:05 ——– d—–w- c:\program files\Conduit
2010-07-26 08:05 . 2010-07-26 08:51 ——– d—–w- c:\documents and settings\Boza\Local Settings\Application Data\Softonic-Eng7
2010-07-26 08:05 . 2010-07-26 08:05 ——– d—–w- c:\program files\Softonic-Eng7

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-23 12:42 . 2010-07-03 16:34 2828 –sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2010-08-23 12:42 . 2010-07-03 16:34 2828 –sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2010-08-23 12:35 . 2010-07-13 13:38 ——– d—–w- c:\program files\ParetoLogic
2010-08-23 12:34 . 2010-06-28 12:26 ——– d—–w- c:\documents and settings\Boza\Application Data\uTorrent
2010-08-19 09:48 . 2010-08-19 07:05 ——– d—–w- c:\documents and settings\All Users\Application Data\SecTaskMan
2010-08-19 06:53 . 2010-06-28 12:27 ——– d—–w- c:\program files\uTorrent
2010-08-13 07:52 . 2010-06-29 14:09 ——– d—–w- c:\program files\Opera
2010-08-11 12:14 . 2010-06-28 11:46 ——– d—–w- c:\program files\Emsisoft Anti-Malware
2010-08-10 15:05 . 2010-06-28 14:36 ——– d—–w- c:\program files\CCleaner
2010-08-10 09:44 . 2010-06-28 07:07 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-08-10 09:39 . 2010-06-28 07:07 77184 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-08-05 09:30 . 2010-06-28 07:08 ——– d—–w- c:\program files\Common Files\Adobe
2010-07-28 10:50 . 2010-06-02 10:03 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-07-27 07:01 . 2010-06-02 11:45 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-18 07:29 . 2010-07-12 09:58 ——– d—–w- c:\program files\Hard Disk Sentinel
2010-07-15 13:37 . 2010-07-15 13:36 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-15 13:36 . 2010-07-15 13:36 ——– d—–w- c:\documents and settings\Boza\Application Data\Malwarebytes
2010-07-15 13:36 . 2010-07-15 13:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-14 06:00 . 2010-07-12 10:29 ——– d—–w- c:\program files\ASUS
2010-07-13 13:05 . 2010-07-13 13:05 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-07-13 11:46 . 2010-07-13 11:46 87552 –sha-r- c:\windows\system32\NtmsDatab.dll
2010-07-13 07:14 . 2010-07-13 07:14 ——– d—–w- c:\program files\DesktopNerds
2010-07-13 06:32 . 2010-07-13 06:31 ——– d—–w- c:\program files\SIW
2010-07-12 10:31 . 2010-07-12 10:30 455534 —-a-w- c:\windows\ppvm1007.zip
2010-07-12 10:15 . 2010-07-12 10:02 ——– d—–w- c:\program files\ASUS Drivers Update Utility
2010-07-12 10:03 . 2010-07-12 10:03 ——– d—–w- c:\documents and settings\Boza\Application Data\ASUS Drivers Update Utility
2010-07-07 12:01 . 2010-07-07 12:01 ——– d—–w- c:\program files\Common Files\onOne Software Shared
2010-07-07 12:01 . 2010-07-07 12:01 ——– d—–w- c:\program files\onOne Software
2010-07-07 11:58 . 2010-06-28 11:22 ——– d—–w- c:\program files\VS Revo Group
2010-07-05 10:07 . 2010-07-05 10:07 ——– d—–w- c:\documents and settings\Boza\Application Data\Uniblue
2010-07-05 10:07 . 2010-07-05 10:07 ——– d—–w- c:\program files\Uniblue
2010-07-05 08:09 . 2010-07-05 08:09 ——– d—–w- c:\documents and settings\Boza\Application Data\onOne Software
2010-07-03 16:38 . 2010-06-02 11:42 100800 —-a-w- c:\documents and settings\Boza\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-03 16:34 . 2010-07-03 16:34 ——– d—–w- c:\documents and settings\Boza\Application Data\Corel
2010-07-03 16:34 . 2010-07-03 16:34 8 –sh–r- c:\documents and settings\All Users\Application Data\24BE4DB15A.sys
2010-07-03 16:34 . 2010-07-03 16:34 8 –sh–r- c:\documents and settings\All Users\Application Data\24BE4DB15A.sys
2010-07-03 16:34 . 2010-07-03 16:34 ——– d—–w- c:\program files\Common Files\Corel
2010-07-03 16:33 . 2010-07-03 16:33 ——– d—–w- c:\program files\Common Files\Protexis
2010-07-03 16:33 . 2010-07-03 16:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Corel
2010-07-03 16:32 . 2010-07-03 16:32 ——– d—–w- c:\program files\Corel
2010-07-01 12:14 . 2010-07-01 12:14 ——– d—–w- c:\documents and settings\Boza\Application Data\Nik Software
2010-06-30 08:23 . 2010-06-30 08:23 ——– d—–w- c:\program files\MSXML 4.0
2010-06-29 13:03 . 2010-06-29 13:03 ——– d—–w- c:\program files\Common Files\Adobe Systems Shared
2010-06-29 11:49 . 2010-06-29 11:49 ——– d—–w- c:\program files\IrfanView
2010-06-29 11:37 . 2010-06-02 10:03 ——– d—–w- c:\program files\Common Files\InstallShield
2010-06-29 06:49 . 2010-06-29 06:49 388096 —-a-r- c:\documents and settings\Boza\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-29 06:48 . 2010-06-29 06:48 ——– d—–w- c:\program files\Trend Micro
2010-06-29 06:00 . 2010-06-29 06:00 ——– d—–w- c:\program files\ESET
2010-06-29 06:00 . 2010-06-29 06:00 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2010-06-29 05:48 . 2010-06-29 05:48 ——– d—–w- c:\program files\7-Zip
2010-06-28 08:57 . 2010-06-28 08:57 ——– d—–w- c:\documents and settings\Boza\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-06-25 09:57 . 2010-06-25 09:52 ——– d—–w- c:\program files\Common Files\Autodesk Shared
2010-06-25 09:57 . 2010-06-25 09:54 ——– d—–w- c:\program files\AutoCAD 2007
2010-06-25 09:56 . 2010-06-25 09:56 ——– d—–w- c:\program files\AnswerWorks 4.0
2010-06-25 09:54 . 2010-06-25 09:54 ——– d—–w- c:\documents and settings\Boza\Application Data\Autodesk
2010-06-25 09:54 . 2010-06-25 09:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Autodesk
2010-06-25 09:52 . 2010-06-25 09:52 ——– d—–w- c:\program files\Autodesk
2010-06-14 14:30 . 2010-06-02 08:48 743936 —-a-w- c:\windows\PCHEALTH\HELPCTR\Binaries\helpsvc.exe
2010-06-02 11:38 . 2010-06-02 08:50 86327 —-a-w- c:\windows\PCHEALTH\HELPCTR\OfflineCache\index.dat
2010-06-02 08:48 . 2010-06-02 08:48 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-04-22 08:56 . 2010-07-01 12:43 10867648 —-a-w- c:\program files\RevoUninPro.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]
Register Genuine Fractals PrintPro 5.0.lnk - c:\program files\onOne Software\Genuine Fractals\Register Genuine Fractals PrintPro 5.0.exe [2010-7-7 233472]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Opera\\opera.exe"=

R0 hotcore3;hotcore3;c:\windows\system32\drivers\hotcore3.sys [7/28/2010 12:50 PM 39472]
R1 a2injectiondriver;a2injectiondriver;c:\program files\Emsisoft Anti-Malware\a2dix86.sys [6/28/2010 1:46 PM 41912]
R1 a2util;a-squared Malware-IDS utility driver;c:\program files\Emsisoft Anti-Malware\a2util32.sys [6/28/2010 1:46 PM 11776]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2/20/2008 11:11 AM 33800]
R1 fanio;FanIO driver;c:\windows\system32\drivers\fanio.sys [7/14/2010 10:42 AM 14464]
R2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [6/28/2010 1:46 PM 1935656]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2/20/2008 11:08 AM 472320]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [7/15/2010 3:36 PM 304464]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [7/15/2010 3:36 PM 20952]
S2 HDD & SSD access service;HDD & SSD access service; [x]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [8/23/2001 2:00 PM 3584]
S3 a2acc;a2acc;c:\program files\Emsisoft Anti-Malware\a2accx86.sys [6/28/2010 1:46 PM 71008]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [7/7/2010 1:58 PM 27064]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = 192.168.1.3:8080
.
.
——- File Associations ——-
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{414B6D9D-4A95-4E8D-B5B1-149DD2D93BB3} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-24 08:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(652)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-08-24 08:48:51
ComboFix-quarantined-files.txt 2010-08-24 06:48

Pre-Run: 84,606,439,424 bytes free
Post-Run: 84,625,047,552 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - 1B44E1708435C1D86ACF5D415C16C0BF

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI