Yes, will run it and let you know the results. Can you please let me know the findings till now (if you don't bother)?
Sure.
It doesn't look like there is an infection on your system. ComboFix removed a few things, but they aren't serious. If you could also post the results of the Norton scan or a screenshot of it, that would help a lot.
Sure. I will attach the screenshot of Norton Quarantined Items also.
Sorry for the late reply NoodleTech,
Malwarebytes Anti-Malware (Trial) 1.62.0.1300
www.malwarebytes.org
Database version: v2012.07.16.12
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
Vijay :: VIJAY-LAPTOP [administrator]
Protection: Enabled
17-07-2012 AM 08:49:53
mbam-log-2012-07-17 (08-49-53).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 236202
Time elapsed: 4 minute(s), 57 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d09094b3-b426-4f16-a6d9-e211fe222127} (PUP.MyWebSearch) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Program Files\64res.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\64res.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
(end)
Result of ESET Scan:
C:\Users\Vijay\AppData\Local\Babylon\Setup\Setup.exe Win32/Toolbar.Babylon application
C:\Users\Vijay\AppData\LocalLow\FestiveBar_3gEI\Installr\Cache\0072C44A.exe a variant of Win32/Toolbar.MyWebSearch.O application
C:\Users\Vijay\AppData\LocalLow\FunWebProducts\Installr\Cache\0067DDB3.exe a variant of Win32/Toolbar.MyWebSearch.O application
C:\Users\Vijay\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\83caddf-2c3db59a multiple threats
C:\Users\Vijay\AppData\LocalLow\TelevisionFanaticEI\Installr\Cache\00299E23.exe a variant of Win32/Toolbar.MyWebSearch.O application
D:\dumps\SkipScreen-Setup_a.exe Win32/Toolbar.Zugo application
Hi vijay.gupta,
It looks like Norton already quarantined those infected files. Are you experiencing any other problems?
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.
Updating Java:
Download the latest version of Java Runtime Environment (JRE) 7 Update 5. After the download completes, close any programs you may have running - especially your web browser. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java. Check any item with Java Runtime Environment (JRE or J2SE) in the name. Click the Remove or Change/Remove button. Repeat as many times as necessary to remove each Java versions. Reboot your computer once all Java components are removed. Double click the Java setup file you just downloaded and follow the prompts to begin the installation.
Now to
Clean out the Java cache:
Go into the Control Panel and double-click the Java Icon.
[external image: Posted Image]
Under Temporary Internet Files, click the Settingsโฆ button click the Delete Files button. There are three options in the window to clear the cache - Leave all 3 Checked
Downloaded Applets
Downloaded Applications
Other Files Click OK on Delete Temporary Files Window
Note: This deletes ALL the Downloaded Applications and Applets from the CACHE. Click OK to leave the Temporary Files Settings
Click OK to leave the Java Control Panel. ===================================================
Your Internet Explorer is out of date. Please download and install the latest version
here .
I have IE8. Can't I keep that?
Also, can the following be cleaned?
C:\Users\Vijay\AppData\Local\Babylon\Setup\Setup.exe Win32/Toolbar.Babylon application
C:\Users\Vijay\AppData\LocalLow\FestiveBar_3gEI\Installr\Cache\0072C44A.exe a variant of Win32/Toolbar.MyWebSearch.O application
C:\Users\Vijay\AppData\LocalLow\FunWebProducts\Installr\Cache\0067DDB3.exe a variant of Win32/Toolbar.MyWebSearch.O application
C:\Users\Vijay\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\83caddf-2c3db59a multiple threats
C:\Users\Vijay\AppData\LocalLow\TelevisionFanaticEI\Installr\Cache\00299E23.exe a variant of Win32/Toolbar.MyWebSearch.O application
D:\dumps\SkipScreen-Setup_a.exe Win32/Toolbar.Zugo application
Also, if I go to Java.com and Verify Java Version, then it shows that you have Recommended Version installed(Version 6 Update 33). However, it shows that Latest Version is Version 7 Update 5. I will upgrade to latest one.
Shouldn't the process of Java Update and clear Java cache be automatic when I download latest version of Java?
Also, should there be different versions of Java installed for different browsers?
Hi vijay.gupta,
It is not a good idea to keep IE 8 because it has security holes that make your computer vulnerable to threats and infection. Have you updated and cleared the Java cache yet? Doing so will get rid of some of the threats in the ESET log. The other threats are not very serious. They are just setup files that come bundled with toolbars. I can delete them for you if you would like.
Copy/paste the text in the Codebox below into notepad:
Here's how to do that:
Click
Start >
Run type
Notepad click OK.
This will open an empty
notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the
left mouse button , while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text,
right click the mouse for options, and select 'copy'. Now over the empty Notepad box,
right click your mouse again, and select 'paste' and you will have copied and pasted the text.
File::
C:\Users\Vijay\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\83caddf-2c3db59a
D:\dumps\SkipScreen-Setup_a.exe
Folder::
C:\Users\Vijay\AppData\Local\Babylon
C:\Users\Vijay\AppData\LocalLow\FestiveBar_3gEI
C:\Users\Vijay\AppData\LocalLow\FunWebProducts
C:\Users\Vijay\AppData\LocalLow\TelevisionFanaticEI
Save this file to your desktop,
Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save Asโฆ Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save โฆ
[external image: Posted Image]
Drag CFScript.txt into ComboFix.exe
Then post the results log using Copy / Paste
ComboFix 12-07-24.01 - Vijay 23-07-2012 23:36:18.3.2 - x86
Microsoft Windows 7 Home Basic 6.1.7601.1.1252.91.1033.18.3039.1661 [GMT 5.5:30]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Vijay\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\users\Vijay\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\83caddf-2c3db59a"
"d:\dumps\SkipScreen-Setup_a.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Vijay\AppData\Local\Babylon
c:\users\Vijay\AppData\Local\Babylon\Setup\bab033.tbinst.dat
c:\users\Vijay\AppData\Local\Babylon\Setup\bab091.norecovericon.dat
c:\users\Vijay\AppData\Local\Babylon\Setup\Babylon.dat
c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\common.js
c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\eula.html
c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\page2.css
c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\page2.html
c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\page2.js
c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\page2Lrg.css
c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\page9.html
c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\pBar.gif
c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\title2.png
c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\toolBar.jpg
c:\users\Vijay\AppData\Local\Babylon\Setup\Setup-tbmntr903-9.0.3.19.zpb
c:\users\Vijay\AppData\Local\Babylon\Setup\Setup.exe
c:\users\Vijay\AppData\Local\Babylon\Setup\SetupStrings.dat
c:\users\Vijay\AppData\Local\Babylon\Setup\sqlite3.dll
c:\users\Vijay\AppData\LocalLow\FestiveBar_3gEI
c:\users\Vijay\AppData\LocalLow\FestiveBar_3gEI\Installr\Cache\0072C44A.exe
c:\users\Vijay\AppData\LocalLow\FestiveBar_3gEI\Installr\Cache\files.ini
c:\users\Vijay\AppData\LocalLow\FunWebProducts
c:\users\Vijay\AppData\LocalLow\FunWebProducts\Installr\Cache\0067DDB3.exe
c:\users\Vijay\AppData\LocalLow\FunWebProducts\Installr\Cache\files.ini
c:\users\Vijay\AppData\LocalLow\TelevisionFanaticEI
c:\users\Vijay\AppData\LocalLow\TelevisionFanaticEI\Installr\Cache\00299E23.exe
c:\users\Vijay\AppData\LocalLow\TelevisionFanaticEI\Installr\Cache\files.ini
.
.
((((((((((((((((((((((((( Files Created from 2012-06-23 to 2012-07-23 )))))))))))))))))))))))))))))))
.
.
2012-07-23 18:16 . 2012-07-23 18:16 โโโ dโโw- c:\windows\system32\config\systemprofile\AppData\Local\temp
2012-07-23 18:16 . 2012-07-23 18:16 โโโ dโโw- c:\users\UpdatusUser\AppData\Local\temp
2012-07-23 18:16 . 2012-07-23 18:16 โโโ dโโw- c:\users\Public\AppData\Local\temp
2012-07-23 18:16 . 2012-07-23 18:16 โโโ dโโw- c:\users\Default\AppData\Local\temp
2012-07-23 17:56 . 2012-07-23 17:56 โโโ dโโw- c:\program files\Common Files\Java
2012-07-23 17:54 . 2012-07-23 17:54 โโโ dโโw- c:\program files\Java
2012-07-17 03:18 . 2012-07-17 03:18 โโโ dโโw- c:\program files\Malwarebytes' Anti-Malware
2012-07-17 03:18 . 2012-07-03 08:16 22344 โ-a-w- c:\windows\system32\drivers\mbam.sys
2012-07-15 17:06 . 2012-07-15 17:06 388096 โ-a-r- c:\users\Vijay\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-07-15 16:59 . 2012-07-15 16:59 โโโ dโโw- c:\program files\Trend Micro
2012-07-15 14:38 . 2012-07-15 14:38 โโโ dโโw- c:\users\Vijay\AppData\Roaming\Yahoo!
2012-07-15 13:22 . 2012-07-15 13:22 โโโ dโโw- c:\users\Vijay\VirtualBox VMs
2012-07-15 08:30 . 2012-07-16 20:13 56200 โ-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43C4B7CE-EA77-498B-B24D-4A5B2812B24E}\offreg.dll
2012-07-15 08:29 . 2012-07-22 04:34 โโโ dโโw- c:\users\Vijay\.VirtualBox
2012-07-15 08:27 . 2012-06-05 11:03 158552 โ-a-w- c:\windows\system32\drivers\VBoxDrv.sys
2012-07-15 08:27 . 2012-06-05 11:03 91992 โ-a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2012-07-15 08:27 . 2012-07-23 17:56 โโโ dโโw- c:\program files\Oracle
2012-07-13 18:50 . 2012-06-17 21:44 6762896 โ-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43C4B7CE-EA77-498B-B24D-4A5B2812B24E}\mpengine.dll
2012-07-13 18:50 . 2012-05-31 06:55 237072 โโw- c:\windows\system32\MpSigStub.exe
2012-07-12 04:41 . 2012-06-12 02:40 2345984 โ-a-w- c:\windows\system32\win32k.sys
2012-07-05 17:56 . 2012-07-05 17:56 โโโ dโโw- c:\program files\Gophoto.it
2012-07-05 17:55 . 2012-07-05 18:39 โโโ dโโw- c:\program files\1ClickDownload
2012-07-05 05:08 . 2012-07-05 05:08 โโโ dโโw- C:\garg
2012-06-30 19:32 . 2012-07-06 07:00 โโโ dโโw- C:\f2820a3e66ec22977737ae
2012-06-27 18:28 . 2012-06-27 18:34 โโโ dโโw- c:\programdata\FarmFrenzy-PizzaParty
2012-06-26 17:49 . 2012-06-26 17:49 770384 โ-a-w- c:\program files\Mozilla Firefox\msvcr100.dll
2012-06-26 17:49 . 2012-06-26 17:49 421200 โ-a-w- c:\program files\Mozilla Firefox\msvcp100.dll
2012-06-25 18:01 . 2012-06-02 22:19 53784 โ-a-w- c:\windows\system32\wuauclt.exe
2012-06-25 18:01 . 2012-06-02 22:19 45080 โ-a-w- c:\windows\system32\wups2.dll
2012-06-25 18:01 . 2012-06-02 22:19 1933848 โ-a-w- c:\windows\system32\wuaueng.dll
2012-06-25 18:01 . 2012-06-02 22:12 2422272 โ-a-w- c:\windows\system32\wucltux.dll
2012-06-25 18:01 . 2012-06-02 22:19 35864 โ-a-w- c:\windows\system32\wups.dll
2012-06-25 18:01 . 2012-06-02 22:19 577048 โ-a-w- c:\windows\system32\wuapi.dll
2012-06-25 18:01 . 2012-06-02 22:12 88576 โ-a-w- c:\windows\system32\wudriver.dll
2012-06-25 18:01 . 2012-06-02 09:49 171904 โ-a-w- c:\windows\system32\wuwebv.dll
2012-06-25 18:01 . 2012-06-02 09:42 33792 โ-a-w- c:\windows\system32\wuapp.exe
2012-06-25 10:34 . 2012-06-25 10:34 1394248 โ-a-w- c:\windows\system32\msxml4.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-12 05:35 . 2012-04-01 04:38 426184 โ-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-12 05:35 . 2011-06-19 18:26 70344 โ-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-05 16:36 . 2012-06-16 21:59 772544 โ-a-w- c:\windows\system32\npdeployJava1.dll
2012-07-05 16:36 . 2010-10-02 06:59 687544 โ-a-w- c:\windows\system32\deployJava1.dll
2012-06-05 11:03 . 2012-06-05 11:03 116056 โ-a-w- c:\windows\system32\drivers\VBoxNetFlt.sys
2012-06-05 11:03 . 2012-06-05 11:03 104792 โ-a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2012-06-05 11:02 . 2012-06-05 11:02 135512 โ-a-w- c:\windows\system32\VBoxNetFltNobj.dll
2012-05-21 19:23 . 2010-06-24 06:03 19736 โ-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-05-15 03:03 . 2012-06-13 04:44 981504 โ-a-w- c:\windows\system32\wininet.dll
2012-05-04 09:59 . 2012-06-13 04:45 514560 โ-a-w- c:\windows\system32\qdvd.dll
2012-05-01 04:44 . 2012-06-13 04:43 164352 โ-a-w- c:\windows\system32\profsvc.dll
2012-04-28 03:17 . 2012-06-13 04:44 183808 โ-a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-26 04:45 . 2012-06-13 04:43 58880 โ-a-w- c:\windows\system32\rdpwsx.dll
2012-04-26 04:45 . 2012-06-13 04:43 129536 โ-a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-26 04:41 . 2012-06-13 04:43 8192 โ-a-w- c:\windows\system32\rdrmemptylst.exe
2012-06-26 17:49 . 2011-03-26 10:22 85472 โ-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-05-15 282624]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-10-13 95848]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-10-14 134856]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2010-03-23 495708]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"vmware-tray"="c:\program files\VMware\VMware Workstation\vmware-tray.exe" [2007-05-01 68400]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-31 795936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"HideFastUserSwitching"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"WallpaperStyle"= 2
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Users^Vijay^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^IDrive Tray.lnk]
path=c:\users\Vijay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IDrive Tray.lnk
backup=c:\windows\pss\IDrive Tray.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 โ-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-06-14 17:52 116648 โ-atw- c:\users\Vijay\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR]
2009-07-16 00:51 1668664 โ-a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper]
2011-04-28 19:54 934800 โ-a-w- c:\program files\Samsung\Kies\KiesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR]
2011-04-28 19:54 19856 โ-a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent]
2011-04-28 19:54 3373968 โ-a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
2009-06-24 21:57 320056 โ-a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 05:37 252296 โ-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2009-02-18 04:21 218408 โโw- c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePRCShortCut]
2009-05-20 05:16 222504 โ-a-w- c:\program files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VMware hqtray]
2007-05-01 17:22 56112 โ-a-w- c:\program files\VMware\VMware Workstation\hqtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmware-tray]
2007-05-01 17:22 68400 โ-a-w- c:\program files\VMware\VMware Workstation\vmware-tray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WirelessAssistant]
2009-07-23 18:04 498744 โ-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 Change Modem Device Service;Change Modem Device Service;c:\windows\system32\ChgService.exe [x]
R2 HWDeviceService.exe;HWDeviceService.exe;c:\programdata\DatacardService\HWDeviceService.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [x]
R3 cmnsusbser;Mobile Connector USB Device for Legacy Serial Communication LCT2053s;c:\windows\system32\DRIVERS\cmnsusbser.sys [x]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [x]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [x]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x]
R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x]
R3 massfilter;MBB Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [x]
R3 netw5v32;Intelยฎ Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [x]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [x]
R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [x]
R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [x]
R3 ssudobex;SAMSUNG Mobile USB OBEX Serial Port(DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudobex.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 wirelessusbser;Wireless USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\3GDatausbser.sys [x]
R3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\DRIVERS\ZTEusbvoice.sys [x]
R4 ICM_UpdaterService;ICM_UpdaterService Disp;c:\program files\SAMSUNG\Samsung Networking Wizard\ICM_Service.exe [x]
R4 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S1 PSSDK42;PSSDK42;c:\windows\system32\Drivers\pssdk42.sys [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\aestsrv.exe [x]
S2 CP_OMDRV;Check Point Office Mode Module;c:\windows\system32\drivers\omdrv.sys [x]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [x]
S2 VNASC;Check Point Virtual Network Adapter - SecureClient;c:\windows\system32\DRIVERS\vnasc.sys [x]
S2 VPN-1;VPN-1 Module;c:\windows\System32\drivers\vpn.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x]
S3 FW1;SecuRemote Miniport;c:\windows\system32\DRIVERS\fw.sys [x]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-06-17 19:11 451872 โ-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 05:35]
.
2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-818653106-4120140212-1750785515-1000Core.job
- c:\users\Vijay\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-14 17:52]
.
2012-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-818653106-4120140212-1750785515-1000UA.job
- c:\users\Vijay\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-14 17:52]
.
.
โโ- Supplementary Scan โโ-
.
uStart Page = about:blank
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_IN&c=94&bd=Presario&pf=cnnb
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: Interfaces\{48330B93-88E8-47AB-9FFA-1F1BC113E19E}: NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{98A2A3BA-92DA-4C9C-8253-A96B6738C3F2}: NameServer = 172.16.16.1,4.2.2.2
FF - ProfilePath - c:\users\Vijay\AppData\Roaming\Mozilla\Firefox\Profiles\c3pzohvf.default\
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
.
.
โโโโโโโ LOCKED REGISTRY KEYS โโโโโโโ
.
[HKEY_USERS\S-1-5-21-818653106-4120140212-1750785515-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-818653106-4120140212-1750785515-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
@Denied: (2) (S-1-5-21-818653106-4120140212-1750785515-1000)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0011\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0012\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0014\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0015\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0023\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-07-23 23:50:15
ComboFix-quarantined-files.txt 2012-07-23 18:20
ComboFix2.txt 2012-07-16 20:34
ComboFix3.txt 2011-04-09 08:51
.
Pre-Run: 4,070,166,528 bytes free
Post-Run: 3,739,811,840 bytes free
.
- - End Of File - - 6BAEC376BB864E71BDE87B0A44EA2547
Excellent! Your logs appear to be malware free. Now let's clean up the tools we used and send you on your way.
===================================================
Please delete
DDS, GMER, TDSSKiller, and aswMBR from your desktop .
===================================================
Follow these steps to uninstall Combofix
*
Click START
* Now type
ComboFix /Uninstall in the searchbox and hit
ENTER . Note the space between the X and the /, it needs to be there.
(Note: There is a space between the ..X and the /U that needs to be there.)
[external image: Posted Image]
===================================================
Download
TFC to your desktop
Open the file and close any other windows. It will close all programs itself when run, make sure to let it run uninterrupted. Click the Start button to begin the process. The program should not take long to finish its job Once its finished it should reboot your machine , if not, do this yourself to ensure a complete clean ===================================================
Here are some tips to reduce the potential for spyware infection in the future :
Updates
It is very important that you keep your Operating System and applications up to date so that you will be less susceptible to malware. It's a good idea to have Windows Update automatically download and install updates as they become available. Secunia Online Software Inspector is a great tool that will tell you which of your applications are outdated and vulnerable to attack.Run Anti-Virus Software
For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here . IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system. When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan. Once complete, remember to re-engage your resident security before going online. Passwords
It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them and consider a password keeper , to keep all your passwords safe. Spyware Protection
This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles: How to Prevent Malware by miekiemoesPC Safety and SecurityโWhat Do I Need?
Additional Software
To help protect your computer in the future I recommend that you get the following free programs if you do not already have them: SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements.Google Chrome is a great alternative to Internet Explorer and Firefox.
Follow these steps, keep your antivirus program and antispyware programs updated, and scan with them on a regular basis. By doing so, your potential for being infected again will reduce dramatically.
Hopefully this should take care of your problems! Good luck.
Do you have any further questions?
**Please respond one more time to confirm your problem is resolved so I can close this thread.
Thanks Noodle Tech,
I have done that. Now, can I delete all the other things that are not mentioned above like: MalwareBytes anti Malware etc installed in this process?
Can you please provide me the link that explains different terminology like virus, spyware, malware etc?
Also, I have Norton Antivirus Corporate Edition, then also do I need separate Anti-Spyware?
Hi vijay.gupta,
You may uninstall Malwarebytes if you want. I keep it on my system and run a scan with it from time to time.
You can read all about malware
here .
Symantec Antivirus Corporate Edition should provide spyware protection as well. Just make sure to keep it up to date.
Thanks Noodle Tech. I will let you know if the problem arises again.
Since this issue appears to be resolved โฆ this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.