Hi..my computer are infected with VBS:Malware-gen virus...avast detects it..but can't delete it...pls help!!!
I ran Combofix and here is the log:
ComboFix 11-09-18.03 - User -09-19 星期一 10:57:09.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.936.86.1033.18.1014.507 [GMT 8:00]
执行位置: c:\documents and settings\User\My Documents\Downloads\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
注意 - 这台电脑没有安装恢复控制台 !!
.
.
((((((((((((((((((((((((((((((((((((((( 被删除的档案 )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\autorun.inf
c:\documents and settings\User\My Documents\My Music\My Music.exe
c:\documents and settings\User\My Documents\My Pictures\My Pictures.exe
c:\documents and settings\User\My Documents\new folder.exe
c:\new folder\New Folder.exe
c:\program files\INSTALL.LOG
c:\program files\UNWISE.EXE
C:\setup.exe
c:\windows\ST6UNST.000
D:\autorun.inf
Pass LEGAL for license information. Built Sat Jun 25 23:20 2011c:\documents and settings\User\My Documents\2005.xls
.
.
((((((((((((((((((((((((((((((((((((((( 驱动/服务 )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_RKHIT
-------\Service_RkHit
.
.
((((((((((((((((((((((((( 2011-08-19 至 2011-09-19 的新的档案 )))))))))))))))))))))))))))))))
.
.
2011-09-17 06:12 . 2004-11-17 09:11 65536 ----a-w- c:\windows\system32\EEBUtil.dll
2011-09-17 06:12 . 2004-11-17 08:04 110592 ----a-w- c:\windows\system32\EEBDSCVR.dll
2011-09-17 06:12 . 2004-11-17 07:56 131072 ----a-w- c:\windows\system32\EEBAPI.dll
2011-09-17 06:12 . 2004-11-17 07:37 69632 ----a-w- c:\windows\system32\EBAPI.dll
2011-09-17 06:12 . 2003-12-16 17:01 55808 ----a-w- c:\windows\system32\EEBSDKIF.dll
2011-09-17 06:12 . 2011-09-17 06:12 -------- d-----w- c:\program files\Common Files\EPSON
2011-09-17 06:10 . 2004-08-03 15:01 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2011-09-17 06:10 . 2004-08-03 15:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2011-09-17 01:41 . 2007-09-26 00:18 249994 --sha-r- C:\SSCVIIHOST.exe
2011-09-16 04:46 . 2011-09-16 04:46 -------- d-----w- c:\documents and settings\User\Application Data\searchqutoolbar
2011-09-16 04:46 . 2011-09-16 05:26 -------- d-----w- c:\documents and settings\All Users\Application Data\boost_interprocess
2011-09-16 03:55 . 2011-09-16 03:55 -------- d-----w- c:\documents and settings\User\Application Data\Bandoo
2011-09-16 03:54 . 2011-09-16 03:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Bandoo
2011-09-16 03:54 . 2011-09-16 03:54 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Ilivid Player
2011-09-16 03:53 . 2011-09-16 03:54 -------- d-----w- c:\program files\Bandoo
2011-09-16 03:50 . 2011-09-16 03:50 -------- d--h--w- c:\documents and settings\All Users\Application Data\{94D867E5-DFF5-4374-ADEE-C3F5BE97F03A}
2011-09-16 03:48 . 2011-09-16 03:49 -------- d-----w- c:\program files\Windows iLivid Toolbar
2011-09-16 03:48 . 2011-09-16 03:48 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\PackageAware
2011-09-14 06:53 . 2011-09-17 01:44 -------- d-----w- C:\logs
2011-09-14 06:53 . 2011-09-14 06:53 -------- d-----w- c:\documents and settings\User\ChikkaV5
2011-09-14 06:53 . 2011-09-14 06:53 -------- d-----w- c:\program files\Chikka Messenger
2011-09-13 01:45 . 2001-08-17 05:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2011-09-13 01:45 . 2001-08-17 05:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2011-09-07 01:29 . 2011-09-07 01:29 -------- d-----w- c:\documents and settings\User\Application Data\Rovio
2011-09-05 17:04 . 2011-09-05 17:04 183696 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( 在三个月内被修改的档案 ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-18 01:26 . 2011-08-17 02:53 286720 ------w- c:\windows\Setup1.exe
2011-08-18 01:26 . 2011-08-17 02:53 73216 ----a-w- c:\windows\ST6UNST.EXE
2011-08-18 00:35 . 2011-08-08 06:10 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-08-17 10:33 . 2011-08-17 10:33 1056768 ----a-w- c:\windows\system32\temp.002
2011-08-17 10:33 . 2011-08-17 10:33 30749 ----a-w- c:\windows\system32\temp.001
2011-08-17 10:03 . 2011-08-17 10:03 379152 ----a-w- c:\windows\system32\temp.000
2011-08-11 00:44 . 2011-08-08 06:09 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-08-11 00:44 . 2011-08-08 06:09 138192 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-08-08 07:23 . 2011-08-08 06:50 69632 ----a-w- c:\windows\system32\MY3L_EX.DLL
2011-08-08 07:23 . 2011-08-08 06:50 53248 ----a-w- c:\windows\system32\NT_DLL2.DLL
2011-08-08 07:23 . 2011-08-08 06:50 135168 ----a-w- c:\windows\system32\YutianEx.DLL
.
.
((((((((((((((((((((((((((((((((((((( 重要登入点 ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*注意* 空白与合法缺省登录将不会被显示
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-08-08 39408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-09-12 17351304]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-24 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-24 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-24 137752]
"RTHDCPL"="RTHDCPL.EXE" [2009-05-21 17881600]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-01-10 281768]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
c:\documents and settings\User\Start Menu\Programs\Startup\
IPMSG for Win32.lnk - c:\program files\IPMsg\ipmsg.exe [2011-8-11 210432]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2011-9-17 131584]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer_Service.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Windows iLivid Toolbar\\Datamngr\\ToolBar\\dtUser.exe"=
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-8-8 14:09 136360]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe [2011-8-8 14:52 81920]
R2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-10-19 2011944]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe [2011-8-8 14:52 2732032]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-8-8 14:14 136176]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2011-8-8 12:24 1684736]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-8-8 14:14 136176]
.
‘计划任务’ 文件夹 里的内容
.
2011-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-08 06:14]
.
2011-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-08-08 06:14]
.
.
------- 而外的扫描 -------
.
uStart Page = hxxp://www.searchqu.com//406
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
TCP: DhcpNameServer = 124.106.5.2 124.106.6.2
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\5i0ycwro.default\
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com//406
FF - prefs.js: keyword.URL - hxxp://www.searchqu.com/web?src=ffb&appid=102&systemid=406&sr=0&q=
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
AddRemove-YT Security Key Driver - c:\progra~1\UNWISE.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, https://www.gmer.net
Rootkit scan 2011-09-19 11:03
Windows 5.1.2600 Service Pack 2 NTFS
.
扫描被隐藏的进程 。。。
.
扫描被隐藏的启动组 。。。
.
扫描被隐藏的文件 。。。
.
扫描完成
被隐藏的档案: 0
.
**************************************************************************
.
------------------------ 其他运行进程 ------------------------
.
c:\windows\system32\conime.exe
c:\program files\Common Files\EPSON\EBAPI\eEBSVC.exe
c:\windows\RTHDCPL.EXE
c:\progra~1\WINDOW~4\Datamngr\DATAMN~1.EXE
c:\windows\system32\igfxsrvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Bandoo\Bandoo.exe
c:\windows\system32\wscntfy.exe
c:\program files\TeamViewer\Version5\TeamViewer.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
完成时间: 2011-09-19 11:08:01 - 电脑已重新启动
ComboFix-quarantined-files.txt 2011-09-19 03:07
.
Pre-Run: 7,897,862,144 bytes free
Post-Run: 7,898,595,328 bytes free
.
- - End Of File - - C483760C94DAE291710A6A3D0487FC32