This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

System running very slow and detecting Trojan Horse with Norton! [

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Yes, will run it and let you know the results. Can you please let me know the findings till now (if you don't bother)?
Sure. It doesn't look like there is an infection on your system. ComboFix removed a few things, but they aren't serious. If you could also post the results of the Norton scan or a screenshot of it, that would help a lot.
Sorry for the late reply NoodleTech, Malwarebytes Anti-Malware (Trial) 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.16.12 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 8.0.7601.17514 Vijay :: VIJAY-LAPTOP [administrator] Protection: Enabled 17-07-2012 AM 08:49:53 mbam-log-2012-07-17 (08-49-53).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 236202 Time elapsed: 4 minute(s), 57 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d09094b3-b426-4f16-a6d9-e211fe222127} (PUP.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 2 C:\Program Files\64res.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully. C:\Program Files\64res.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully. (end) Result of ESET Scan: C:\Users\Vijay\AppData\Local\Babylon\Setup\Setup.exe Win32/Toolbar.Babylon application C:\Users\Vijay\AppData\LocalLow\FestiveBar_3gEI\Installr\Cache\0072C44A.exe a variant of Win32/Toolbar.MyWebSearch.O application C:\Users\Vijay\AppData\LocalLow\FunWebProducts\Installr\Cache\0067DDB3.exe a variant of Win32/Toolbar.MyWebSearch.O application C:\Users\Vijay\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\83caddf-2c3db59a multiple threats C:\Users\Vijay\AppData\LocalLow\TelevisionFanaticEI\Installr\Cache\00299E23.exe a variant of Win32/Toolbar.MyWebSearch.O application D:\dumps\SkipScreen-Setup_a.exe Win32/Toolbar.Zugo application
Hi vijay.gupta,

It looks like Norton already quarantined those infected files. Are you experiencing any other problems?

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 7 Update 5.
  • After the download completes, close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Double click the Java setup file you just downloaded and follow the prompts to begin the installation.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settingsโ€ฆ button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
===================================================

Your Internet Explorer is out of date. Please download and install the latest version here.
I have IE8. Can't I keep that? Also, can the following be cleaned? C:\Users\Vijay\AppData\Local\Babylon\Setup\Setup.exe Win32/Toolbar.Babylon application C:\Users\Vijay\AppData\LocalLow\FestiveBar_3gEI\Installr\Cache\0072C44A.exe a variant of Win32/Toolbar.MyWebSearch.O application C:\Users\Vijay\AppData\LocalLow\FunWebProducts\Installr\Cache\0067DDB3.exe a variant of Win32/Toolbar.MyWebSearch.O application C:\Users\Vijay\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\83caddf-2c3db59a multiple threats C:\Users\Vijay\AppData\LocalLow\TelevisionFanaticEI\Installr\Cache\00299E23.exe a variant of Win32/Toolbar.MyWebSearch.O application D:\dumps\SkipScreen-Setup_a.exe Win32/Toolbar.Zugo application Also, if I go to Java.com and Verify Java Version, then it shows that you have Recommended Version installed(Version 6 Update 33). However, it shows that Latest Version is Version 7 Update 5. I will upgrade to latest one. Shouldn't the process of Java Update and clear Java cache be automatic when I download latest version of Java? Also, should there be different versions of Java installed for different browsers?
Hi vijay.gupta,

It is not a good idea to keep IE 8 because it has security holes that make your computer vulnerable to threats and infection. Have you updated and cleared the Java cache yet? Doing so will get rid of some of the threats in the ESET log. The other threats are not very serious. They are just setup files that come bundled with toolbars. I can delete them for you if you would like.

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
C:\Users\Vijay\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\83caddf-2c3db59a
D:\dumps\SkipScreen-Setup_a.exe

Folder::
C:\Users\Vijay\AppData\Local\Babylon
C:\Users\Vijay\AppData\LocalLow\FestiveBar_3gEI
C:\Users\Vijay\AppData\LocalLow\FunWebProducts
C:\Users\Vijay\AppData\LocalLow\TelevisionFanaticEI
Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save Asโ€ฆ Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save โ€ฆ


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe



Then post the results log using Copy / Paste
ComboFix 12-07-24.01 - Vijay 23-07-2012 23:36:18.3.2 - x86 Microsoft Windows 7 Home Basic 6.1.7601.1.1252.91.1033.18.3039.1661 [GMT 5.5:30] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Vijay\Desktop\CFScript.txt SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\users\Vijay\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31\83caddf-2c3db59a" "d:\dumps\SkipScreen-Setup_a.exe" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Vijay\AppData\Local\Babylon c:\users\Vijay\AppData\Local\Babylon\Setup\bab033.tbinst.dat c:\users\Vijay\AppData\Local\Babylon\Setup\bab091.norecovericon.dat c:\users\Vijay\AppData\Local\Babylon\Setup\Babylon.dat c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\common.js c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\eula.html c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\page2.css c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\page2.html c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\page2.js c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\page2Lrg.css c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\page9.html c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\pBar.gif c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\title2.png c:\users\Vijay\AppData\Local\Babylon\Setup\HtmlScreens\toolBar.jpg c:\users\Vijay\AppData\Local\Babylon\Setup\Setup-tbmntr903-9.0.3.19.zpb c:\users\Vijay\AppData\Local\Babylon\Setup\Setup.exe c:\users\Vijay\AppData\Local\Babylon\Setup\SetupStrings.dat c:\users\Vijay\AppData\Local\Babylon\Setup\sqlite3.dll c:\users\Vijay\AppData\LocalLow\FestiveBar_3gEI c:\users\Vijay\AppData\LocalLow\FestiveBar_3gEI\Installr\Cache\0072C44A.exe c:\users\Vijay\AppData\LocalLow\FestiveBar_3gEI\Installr\Cache\files.ini c:\users\Vijay\AppData\LocalLow\FunWebProducts c:\users\Vijay\AppData\LocalLow\FunWebProducts\Installr\Cache\0067DDB3.exe c:\users\Vijay\AppData\LocalLow\FunWebProducts\Installr\Cache\files.ini c:\users\Vijay\AppData\LocalLow\TelevisionFanaticEI c:\users\Vijay\AppData\LocalLow\TelevisionFanaticEI\Installr\Cache\00299E23.exe c:\users\Vijay\AppData\LocalLow\TelevisionFanaticEI\Installr\Cache\files.ini . . ((((((((((((((((((((((((( Files Created from 2012-06-23 to 2012-07-23 ))))))))))))))))))))))))))))))) . . 2012-07-23 18:16 . 2012-07-23 18:16 โ€”โ€”โ€“ dโ€”โ€“w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2012-07-23 18:16 . 2012-07-23 18:16 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\UpdatusUser\AppData\Local\temp 2012-07-23 18:16 . 2012-07-23 18:16 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Public\AppData\Local\temp 2012-07-23 18:16 . 2012-07-23 18:16 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Default\AppData\Local\temp 2012-07-23 17:56 . 2012-07-23 17:56 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Common Files\Java 2012-07-23 17:54 . 2012-07-23 17:54 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Java 2012-07-17 03:18 . 2012-07-17 03:18 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Malwarebytes' Anti-Malware 2012-07-17 03:18 . 2012-07-03 08:16 22344 โ€”-a-w- c:\windows\system32\drivers\mbam.sys 2012-07-15 17:06 . 2012-07-15 17:06 388096 โ€”-a-r- c:\users\Vijay\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2012-07-15 16:59 . 2012-07-15 16:59 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Trend Micro 2012-07-15 14:38 . 2012-07-15 14:38 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Vijay\AppData\Roaming\Yahoo! 2012-07-15 13:22 . 2012-07-15 13:22 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Vijay\VirtualBox VMs 2012-07-15 08:30 . 2012-07-16 20:13 56200 โ€”-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43C4B7CE-EA77-498B-B24D-4A5B2812B24E}\offreg.dll 2012-07-15 08:29 . 2012-07-22 04:34 โ€”โ€”โ€“ dโ€”โ€“w- c:\users\Vijay\.VirtualBox 2012-07-15 08:27 . 2012-06-05 11:03 158552 โ€”-a-w- c:\windows\system32\drivers\VBoxDrv.sys 2012-07-15 08:27 . 2012-06-05 11:03 91992 โ€”-a-w- c:\windows\system32\drivers\VBoxUSBMon.sys 2012-07-15 08:27 . 2012-07-23 17:56 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Oracle 2012-07-13 18:50 . 2012-06-17 21:44 6762896 โ€”-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43C4B7CE-EA77-498B-B24D-4A5B2812B24E}\mpengine.dll 2012-07-13 18:50 . 2012-05-31 06:55 237072 โ€”โ€”w- c:\windows\system32\MpSigStub.exe 2012-07-12 04:41 . 2012-06-12 02:40 2345984 โ€”-a-w- c:\windows\system32\win32k.sys 2012-07-05 17:56 . 2012-07-05 17:56 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Gophoto.it 2012-07-05 17:55 . 2012-07-05 18:39 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\1ClickDownload 2012-07-05 05:08 . 2012-07-05 05:08 โ€”โ€”โ€“ dโ€”โ€“w- C:\garg 2012-06-30 19:32 . 2012-07-06 07:00 โ€”โ€”โ€“ dโ€”โ€“w- C:\f2820a3e66ec22977737ae 2012-06-27 18:28 . 2012-06-27 18:34 โ€”โ€”โ€“ dโ€”โ€“w- c:\programdata\FarmFrenzy-PizzaParty 2012-06-26 17:49 . 2012-06-26 17:49 770384 โ€”-a-w- c:\program files\Mozilla Firefox\msvcr100.dll 2012-06-26 17:49 . 2012-06-26 17:49 421200 โ€”-a-w- c:\program files\Mozilla Firefox\msvcp100.dll 2012-06-25 18:01 . 2012-06-02 22:19 53784 โ€”-a-w- c:\windows\system32\wuauclt.exe 2012-06-25 18:01 . 2012-06-02 22:19 45080 โ€”-a-w- c:\windows\system32\wups2.dll 2012-06-25 18:01 . 2012-06-02 22:19 1933848 โ€”-a-w- c:\windows\system32\wuaueng.dll 2012-06-25 18:01 . 2012-06-02 22:12 2422272 โ€”-a-w- c:\windows\system32\wucltux.dll 2012-06-25 18:01 . 2012-06-02 22:19 35864 โ€”-a-w- c:\windows\system32\wups.dll 2012-06-25 18:01 . 2012-06-02 22:19 577048 โ€”-a-w- c:\windows\system32\wuapi.dll 2012-06-25 18:01 . 2012-06-02 22:12 88576 โ€”-a-w- c:\windows\system32\wudriver.dll 2012-06-25 18:01 . 2012-06-02 09:49 171904 โ€”-a-w- c:\windows\system32\wuwebv.dll 2012-06-25 18:01 . 2012-06-02 09:42 33792 โ€”-a-w- c:\windows\system32\wuapp.exe 2012-06-25 10:34 . 2012-06-25 10:34 1394248 โ€”-a-w- c:\windows\system32\msxml4.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-12 05:35 . 2012-04-01 04:38 426184 โ€”-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-07-12 05:35 . 2011-06-19 18:26 70344 โ€”-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-07-05 16:36 . 2012-06-16 21:59 772544 โ€”-a-w- c:\windows\system32\npdeployJava1.dll 2012-07-05 16:36 . 2010-10-02 06:59 687544 โ€”-a-w- c:\windows\system32\deployJava1.dll 2012-06-05 11:03 . 2012-06-05 11:03 116056 โ€”-a-w- c:\windows\system32\drivers\VBoxNetFlt.sys 2012-06-05 11:03 . 2012-06-05 11:03 104792 โ€”-a-w- c:\windows\system32\drivers\VBoxNetAdp.sys 2012-06-05 11:02 . 2012-06-05 11:02 135512 โ€”-a-w- c:\windows\system32\VBoxNetFltNobj.dll 2012-05-21 19:23 . 2010-06-24 06:03 19736 โ€”-a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2012-05-15 03:03 . 2012-06-13 04:44 981504 โ€”-a-w- c:\windows\system32\wininet.dll 2012-05-04 09:59 . 2012-06-13 04:45 514560 โ€”-a-w- c:\windows\system32\qdvd.dll 2012-05-01 04:44 . 2012-06-13 04:43 164352 โ€”-a-w- c:\windows\system32\profsvc.dll 2012-04-28 03:17 . 2012-06-13 04:44 183808 โ€”-a-w- c:\windows\system32\drivers\rdpwd.sys 2012-04-26 04:45 . 2012-06-13 04:43 58880 โ€”-a-w- c:\windows\system32\rdpwsx.dll 2012-04-26 04:45 . 2012-06-13 04:43 129536 โ€”-a-w- c:\windows\system32\rdpcorekmts.dll 2012-04-26 04:41 . 2012-06-13 04:43 8192 โ€”-a-w- c:\windows\system32\rdrmemptylst.exe 2012-06-26 17:49 . 2011-03-26 10:22 85472 โ€”-a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-06-17 2363392] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-05-15 282624] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-10-13 95848] "vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-10-14 134856] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2010-03-23 495708] "HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576] "vmware-tray"="c:\program files\VMware\VMware Workstation\vmware-tray.exe" [2007-05-01 68400] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-31 795936] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) "HideFastUserSwitching"= 1 (0x1) . [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system] "WallpaperStyle"= 2 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) . [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKLM\~\startupfolder\C:^Users^Vijay^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^IDrive Tray.lnk] path=c:\users\Vijay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IDrive Tray.lnk backup=c:\windows\pss\IDrive Tray.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2012-01-03 07:37 843712 โ€”-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] 2012-06-14 17:52 116648 โ€”-atw- c:\users\Vijay\AppData\Local\Google\Update\GoogleUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR] 2009-07-16 00:51 1668664 โ€”-a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesHelper] 2011-04-28 19:54 934800 โ€”-a-w- c:\program files\Samsung\Kies\KiesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesPDLR] 2011-04-28 19:54 19856 โ€”-a-w- c:\program files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiesTrayAgent] 2011-04-28 19:54 3373968 โ€”-a-w- c:\program files\Samsung\Kies\KiesTrayAgent.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe] 2009-06-24 21:57 320056 โ€”-a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2012-01-17 05:37 252296 โ€”-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu] 2009-02-18 04:21 218408 โ€”โ€”w- c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdatePRCShortCut] 2009-05-20 05:16 222504 โ€”-a-w- c:\program files\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VMware hqtray] 2007-05-01 17:22 56112 โ€”-a-w- c:\program files\VMware\VMware Workstation\hqtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmware-tray] 2007-05-01 17:22 68400 โ€”-a-w- c:\program files\VMware\VMware Workstation\vmware-tray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WirelessAssistant] 2009-07-23 18:04 498744 โ€”-a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R2 Change Modem Device Service;Change Modem Device Service;c:\windows\system32\ChgService.exe [x] R2 HWDeviceService.exe;HWDeviceService.exe;c:\programdata\DatacardService\HWDeviceService.exe [x] R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x] R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys [x] R3 cmnsusbser;Mobile Connector USB Device for Legacy Serial Communication LCT2053s;c:\windows\system32\DRIVERS\cmnsusbser.sys [x] R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [x] R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x] R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x] R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [x] R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [x] R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x] R3 massfilter;MBB Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [x] R3 netw5v32;Intelยฎ Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [x] R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [x] R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [x] R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [x] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [x] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [x] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [x] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys [x] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys [x] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [x] R3 ssudobex;SAMSUNG Mobile USB OBEX Serial Port(DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudobex.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x] R3 wirelessusbser;Wireless USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\3GDatausbser.sys [x] R3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\DRIVERS\ZTEusbvoice.sys [x] R4 ICM_UpdaterService;ICM_UpdaterService Disp;c:\program files\SAMSUNG\Samsung Networking Wizard\ICM_Service.exe [x] R4 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S1 PSSDK42;PSSDK42;c:\windows\system32\Drivers\pssdk42.sys [x] S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [x] S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\aestsrv.exe [x] S2 CP_OMDRV;Check Point Office Mode Module;c:\windows\system32\drivers\omdrv.sys [x] S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [x] S2 VNASC;Check Point Virtual Network Adapter - SecureClient;c:\windows\system32\DRIVERS\vnasc.sys [x] S2 VPN-1;VPN-1 Module;c:\windows\System32\drivers\vpn.sys [x] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [x] S3 FW1;SecuRemote Miniport;c:\windows\system32\DRIVERS\fw.sys [x] S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [x] S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [x] S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] 2009-06-17 19:11 451872 โ€”-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe . Contents of the 'Scheduled Tasks' folder . 2012-07-23 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-01 05:35] . 2012-07-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-818653106-4120140212-1750785515-1000Core.job - c:\users\Vijay\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-14 17:52] . 2012-07-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-818653106-4120140212-1750785515-1000UA.job - c:\users\Vijay\AppData\Local\Google\Update\GoogleUpdate.exe [2012-06-14 17:52] . . โ€”โ€”- Supplementary Scan โ€”โ€”- . uStart Page = about:blank mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_IN&c=94&bd=Presario&pf=cnnb uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 TCP: Interfaces\{48330B93-88E8-47AB-9FFA-1F1BC113E19E}: NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{98A2A3BA-92DA-4C9C-8253-A96B6738C3F2}: NameServer = 172.16.16.1,4.2.2.2 FF - ProfilePath - c:\users\Vijay\AppData\Roaming\Mozilla\Firefox\Profiles\c3pzohvf.default\ FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q= . . โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€” . [HKEY_USERS\S-1-5-21-818653106-4120140212-1750785515-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-818653106-4120140212-1750785515-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) @Denied: (2) (S-1-5-21-818653106-4120140212-1750785515-1000) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0011\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0012\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0014\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0015\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0023\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-07-23 23:50:15 ComboFix-quarantined-files.txt 2012-07-23 18:20 ComboFix2.txt 2012-07-16 20:34 ComboFix3.txt 2011-04-09 08:51 . Pre-Run: 4,070,166,528 bytes free Post-Run: 3,739,811,840 bytes free . - - End Of File - - 6BAEC376BB864E71BDE87B0A44EA2547
Excellent! Your logs appear to be malware free. Now let's clean up the tools we used and send you on your way.

===================================================

Please delete DDS, GMER, TDSSKiller, and aswMBR from your desktop.

===================================================

Follow these steps to uninstall Combofix

* Click START
* Now type ComboFix /Uninstall in the searchbox and hit ENTER. Note the space between the X and the /, it needs to be there.
(Note: There is a space between the ..X and the /U that needs to be there.)

[external image: Posted Image]

===================================================

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean
===================================================

Here are some tips to reduce the potential for spyware infection in the future:

Updates
  • It is very important that you keep your Operating System and applications up to date so that you will be less susceptible to malware.
  • It's a good idea to have Windows Update automatically download and install updates as they become available.
  • Secunia Online Software Inspector is a great tool that will tell you which of your applications are outdated and vulnerable to attack.
Run Anti-Virus Software
  • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.
  • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system.
  • When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
  • Once complete, remember to re-engage your resident security before going online.
Passwords
  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection.
  • Refer to this Microsoft article
    Strong passwords: How to create and use them and consider a password keeper, to keep all your passwords safe.
Spyware Protection
  • This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
  • How to Prevent Malware by miekiemoes
  • PC Safety and Securityโ€“What Do I Need?
Additional Software
  • To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements.
  • Google Chrome is a great alternative to Internet Explorer and Firefox.
Follow these steps, keep your antivirus program and antispyware programs updated, and scan with them on a regular basis. By doing so, your potential for being infected again will reduce dramatically. 

Hopefully this should take care of your problems! Good luck.

Do you have any further questions? 

**Please respond one more time to confirm your problem is resolved so I can close this thread.
Thanks Noodle Tech, I have done that. Now, can I delete all the other things that are not mentioned above like: MalwareBytes anti Malware etc installed in this process? Can you please provide me the link that explains different terminology like virus, spyware, malware etc? Also, I have Norton Antivirus Corporate Edition, then also do I need separate Anti-Spyware?
Hi vijay.gupta,

You may uninstall Malwarebytes if you want. I keep it on my system and run a scan with it from time to time.

You can read all about malware here.

Symantec Antivirus Corporate Edition should provide spyware protection as well. Just make sure to keep it up to date.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI