I did the way you said again
Before that My Internet Client loader is not coming now. before this tests it was opening properly
here is the log:
ComboFix 08-12-17.01 - Gaurang 2008-12-18 9:34:48.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2030.1523 [GMT 5.5:30]
Running from: c:\documents and settings\Gaurang\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\jestertb.dll
c:\windows\system32\28463
c:\windows\system32\28463\svchost.001
c:\windows\system32\28463\svchost.002
c:\windows\system32\setting.ini
c:\windows\system32\setup.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3360PR
-------\Service_asc3360pr
((((((((((((((((((((((((( Files Created from 2008-11-18 to 2008-12-18 )))))))))))))))))))))))))))))))
.
2008-12-18 02:34 . 2008-12-18 02:34 <DIR> d-------- c:\program files\Trend Micro
2008-12-18 00:01 . 2008-12-18 00:01 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-18 00:01 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-18 00:01 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-17 22:59 . 2008-12-17 22:59 <DIR> d-------- c:\documents and settings\Gaurang\Application Data\Malwarebytes
2008-12-17 22:58 . 2008-12-17 22:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-17 22:48 . 2008-12-17 22:48 <DIR> d-------- c:\program files\CCleaner
2008-12-17 22:40 . 2008-12-17 22:44 <DIR> d-------- C:\SDFix
2008-12-17 20:23 . 2008-12-17 20:25 <DIR> d-------- c:\program files\Error Repair Professional
2008-12-17 15:39 . 2008-12-17 15:39 <DIR> d-------- c:\program files\TeraCopy
2008-12-17 15:39 . 2008-12-18 09:20 <DIR> d-------- c:\documents and settings\Gaurang\Application Data\TeraCopy
2008-12-16 11:37 . 2008-12-16 11:37 <DIR> d-------- c:\program files\AccuTrans 3D
2008-12-16 10:48 . 2008-12-16 10:56 40 --a------ c:\windows\devcap.ini
2008-12-14 17:29 . 2008-12-14 17:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\GRETECH
2008-12-14 17:28 . 2008-12-14 17:28 <DIR> d-------- c:\documents and settings\Gaurang\Application Data\GRETECH
2008-12-14 17:15 . 2008-12-14 17:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\SRSLabs
2008-12-14 17:13 . 2008-12-14 17:13 <DIR> d-------- c:\program files\SRSLabs
2008-12-14 17:13 . 2008-12-14 17:13 <DIR> d-------- c:\program files\Common Files\SRS
2008-12-10 18:19 . 2008-12-10 18:19 <DIR> d-------- c:\program files\Common Files\SWF Studio
2008-12-08 16:50 . 2008-12-08 16:50 <DIR> d-------- c:\program files\Alcohol Soft
2008-12-06 12:07 . 2008-12-06 20:49 <DIR> d-------- c:\program files\Internet Download Manager
2008-12-06 12:07 . 2008-12-18 02:45 <DIR> d-------- c:\documents and settings\Gaurang\Application Data\IDM
2008-12-04 23:39 . 2008-12-04 23:39 <DIR> d-------- c:\program files\Topro
2008-12-04 23:39 . 2003-09-08 14:01 1,523,712 --a------ c:\windows\system32\ToproVC.dll
2008-12-04 23:39 . 2005-03-04 10:27 221,184 --a------ c:\windows\ToproUI.exe
2008-12-04 23:39 . 2006-05-08 15:55 198,316 --a------ c:\windows\system32\drivers\TP6800.sys
2008-12-04 23:39 . 2003-09-01 14:16 65,536 --a------ c:\windows\system32\camlib.dll
2008-12-04 23:39 . 2006-02-21 10:35 49,152 --a------ c:\windows\system32\drivers\CustPage.ax
2008-12-04 23:39 . 2005-02-25 10:24 28,672 --a------ c:\windows\tpsti.exe
2008-12-03 16:28 . 2008-12-03 16:28 <DIR> d-------- c:\documents and settings\Gaurang\Application Data\Alien Skin
2008-12-02 21:57 . 2008-12-02 21:57 <DIR> d-------- c:\program files\Good Shot
2008-12-02 00:09 . 2008-12-02 00:09 <DIR> d-------- c:\program files\Smart Virus Remover
2008-12-01 23:55 . 2008-12-01 23:55 <DIR> d-------- c:\windows\system32\Flashy.exe
2008-12-01 15:00 . 2008-12-01 15:00 <DIR> d-------- c:\program files\Web Page Maker
2008-12-01 15:00 . 2008-12-01 15:10 <DIR> d-------- c:\documents and settings\Gaurang\Application Data\Web Page Maker
2008-12-01 13:25 . 2008-12-01 13:39 <DIR> d-------- c:\program files\Avanquest update
2008-12-01 13:25 . 2008-12-01 13:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\BVRP Software
2008-12-01 11:17 . 2008-12-01 11:17 <DIR> d-------- c:\program files\GlobalSCAPE
2008-12-01 11:17 . 2008-12-01 11:17 <DIR> d-------- c:\documents and settings\Gaurang\Application Data\GlobalSCAPE
2008-11-29 16:14 . 2008-11-29 16:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\MumboJumbo
2008-11-29 16:13 . 2008-11-29 16:13 <DIR> d-------- c:\windows\Elf Bowling - Hawaiian Vacation
2008-11-29 16:13 . 2008-11-29 16:13 <DIR> d-------- c:\program files\Elf Bowling - Hawaiian Vacation
2008-11-28 11:56 . 2008-11-28 11:56 <DIR> d-------- c:\program files\uTorrent
2008-11-28 11:56 . 2008-12-16 01:04 <DIR> d-------- c:\documents and settings\Gaurang\Application Data\uTorrent
2008-11-19 10:38 . 2004-09-17 15:07 61,440 -ra------ c:\windows\system32\vuins32.dll
2008-11-19 10:38 . 2005-01-19 12:15 43,008 -ra------ c:\windows\system32\drivers\dlkfet5b.sys
2008-11-19 10:10 . 2004-08-03 22:31 20,992 --a------ c:\windows\system32\drivers\RTL8139.sys
2008-11-19 10:10 . 2004-08-03 22:31 20,992 --a--c--- c:\windows\system32\dllcache\rtl8139.sys
2008-11-19 00:15 . 1997-07-19 21:30 155,920 --------- c:\windows\system32\comct232.ocx
2008-11-19 00:15 . 1997-07-19 21:30 129,808 --------- c:\windows\system32\comdlg32.ocx
2008-11-19 00:15 . 1997-06-13 15:26 56,832 --------- c:\windows\system32\iyvu9_32.dll
2008-11-19 00:06 . 2008-11-19 00:06 <DIR> d-------- c:\windows\BBSTORE
2008-11-19 00:06 . 2008-11-19 00:06 <DIR> d-------- c:\program files\The Learning Company
2008-11-19 00:06 . 2008-11-21 00:01 382 --a------ c:\windows\ereg077.dat
2008-11-19 00:05 . 2008-11-19 00:05 0 --a------ c:\windows\SETUP32.INI
2008-11-18 20:46 . 2007-03-02 14:07 1,904 --------- c:\windows\system32\SetupBD.din
2008-11-18 20:42 . 2008-11-18 20:46 <DIR> d-------- c:\program files\Intel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-18 04:07 --------- d-----w c:\program files\Symantec AntiVirus
2008-12-18 04:07 --------- d-----w c:\program files\DNA
2008-12-18 04:07 --------- d-----w c:\documents and settings\Gaurang\Application Data\DNA
2008-12-18 04:04 --------- d-----w c:\documents and settings\Gaurang\Application Data\DMCache
2008-12-18 03:53 --------- d-----w c:\documents and settings\Gaurang\Application Data\Broadband
2008-12-17 14:51 --------- d-----w c:\program files\Common Files\Adobe
2008-12-17 11:04 --------- d-----w c:\program files\Winamp
2008-12-17 09:56 --------- d-----w c:\program files\Folder Lock
2008-12-17 09:55 --------- d-----w c:\program files\Any FLV Player
2008-12-17 09:53 --------- d-----w c:\program files\DivX
2008-12-17 09:50 --------- d-----w c:\program files\VideoLAN
2008-12-17 09:49 --------- d-----w c:\program files\Common Files\Real
2008-12-17 09:48 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-17 09:48 --------- d-----w c:\program files\CyberLink
2008-12-17 09:46 --------- d-----w c:\program files\Google
2008-12-16 17:32 --------- d-----w c:\program files\Yahoo!
2008-12-16 05:42 --------- d-----w c:\program files\QuickTime
2008-12-15 20:26 --------- d-----w c:\program files\VideoMach-4.0.3
2008-12-15 20:26 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-12-15 20:26 --------- d-----w c:\program files\Apple Software Update
2008-12-15 09:36 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-14 11:58 --------- d-----w c:\program files\GRETECH
2008-11-19 05:18 --------- d-----w c:\program files\Internet Cyclone
2008-11-15 16:49 --------- d-----w c:\program files\Sify Broadband
2008-11-10 05:32 --------- d-----w c:\documents and settings\Gaurang\Application Data\Uniblue
2008-11-10 05:30 --------- d-----w c:\program files\PopCap Games
2008-11-10 05:30 --------- d-----w c:\program files\GameHouse
2008-11-09 09:51 --------- d-----w c:\program files\Zeallsoft
2008-11-07 14:23 --------- d-----w c:\documents and settings\All Users\Application Data\Downloaded Installations
2008-11-07 13:54 --------- d-----w c:\documents and settings\Gaurang\Application Data\MSNInstaller
2008-11-07 04:57 --------- d-----w c:\program files\Reflexive Arcade Games - Action
2008-11-06 15:08 --------- d-----w c:\documents and settings\Gaurang\Application Data\Yahoo!
2008-11-05 11:50 --------- d-----w c:\program files\UnHackMe
2008-11-05 10:52 522,240 ----a-w c:\windows\system32\libcurl.dll
2008-11-05 10:52 41,472 ----a-w c:\windows\system32\hengine.dll
2008-11-05 10:52 22,016 ----a-w c:\windows\system32\ndisprot.sys
2008-11-05 10:52 16,000 ----a-w c:\windows\system32\passthru.sys
2008-11-05 05:46 --------- d-----w c:\program files\Total Video Converter
2008-10-26 18:17 193 ----a-w C:\aw.dat
2008-10-26 17:38 --------- d-----w c:\program files\Autodesk
2008-10-14 10:30 16,896 ----a-w c:\windows\system32\RASPPPOE.EXE
2008-10-04 19:28 166,989 ----a-w c:\windows\Cam 3D Webmaster Edition Uninstaller.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SifyBB"="c:\program files\Sify Broadband\BBImpSec.exe" [2006-04-21 127085]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-11-12 342336]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2008-12-06 931248]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-12-17 3810544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-03-13 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-03-13 86016]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2006-09-21 9138176]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2008-12-01 193760]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 624248]
"DSS"="c:\windows\BBSTORE\DSS\DSSAGENT.EXE" [1999-10-12 590336]
"tppoll"="c:\program files\Topro\tppoll.exe" [2005-03-02 24576]
"nwiz"="nwiz.exe" [2007-03-13 c:\windows\system32\nwiz.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"LvHidSvc"="c:\windows\system32\lvhidsvc.exe" [2004-10-10 33280]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
TVR Schedule.lnk - c:\windows\Installer\{E4C3B10E-E277-4458-8440-DAE332D50BF3}\_4ae13d6c.exe [2008-12-16 1078]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"SENTINEL"= snti386.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\windows\system32\DRIVERS\RMSPPPOE.SYS [2008-09-23 33792]
S2 MCIDRV_2600_6_0;MCIDRV_2600_6_0;\??\c:\windows\system32\drivers\hsrnqs.sys []
S3 DCamUSBIntel;Webcam;c:\windows\system32\Drivers\TP6800.sys [2008-12-04 198316]
S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" [2004-03-12 169192]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{324fb291-b07c-11dd-8c3b-0019d1fd5b3b}]
\Shell\Auto\command - asp.net
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL asp.net
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{324fb292-b07c-11dd-8c3b-0019d1fd5b3b}]
\Shell\Auto\command - asp.net
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL asp.net
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{74120564-a4be-11dd-8c02-0019d1fd5b3b}]
\Shell\AutoRun\command - I:\Secret.exe
\Shell\explore\Command - I:\Secret.exe
\Shell\open\Command - I:\Secret.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d555c774-2f16-11dd-8a4d-0019d1fd5b3b}]
\Shell\AutoRun\command - I:\i.bat
\Shell\explore\Command - I:\i.bat
\Shell\open\Command - I:\i.bat
.
Contents of the 'Scheduled Tasks' folder
2008-12-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe []
2008-11-10 c:\windows\Tasks\Uniblue SpyEraser.job
- c:\program files\Uniblue\SpyEraser\SpyEraser.exe []
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://gmail.com/
uSearch Page = hxxp://in.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*https://in.search.yahoo.com
mDefault_Page_URL = hxxp://in.yahoo.com
mDefault_Search_URL = hxxp://in.rd.yahoo.com/customize/ie/defaults/su/msgr9/*https://in.search.yahoo.com
mSearch Page = hxxp://in.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*https://in.search.yahoo.com
mStart Page = hxxp://in.yahoo.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://in.rd.yahoo.com/customize/ie/defaults/su/msgr9/*https://in.search.yahoo.com
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\idmmbc.dll
TCP: {645E7729-C10C-4216-B058-8938EB93DC1A} = 202.144.115.4,202.144.66.6
TCP: {AF954329-909A-4D7E-AAC3-3A0BD1906306} = 202.144.115.4,202.144.66.6
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
https://www.gmer.net
Rootkit scan 2008-12-18 09:37:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(1380)
c:\windows\system32\idmmbc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\Internet Download Manager\IEMonitor.exe
.
**************************************************************************
.
Completion time: 2008-12-18 9:43:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-18 04:13:33
Pre-Run: 9,769,009,152 bytes free
Post-Run: 9,605,132,288 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
253 --- E O F --- 2008-11-04 18:11:04