ALso Install the SPYBOT www.safer-networking.org
My system is infected with a virus named Khatarnak.exe, its creating some unwanted files (eg: songs.exe, Documents & settings.exe etc). I used combofix to get rid of this virus, but no use again these files are getting created, some times in tcp/ip property default gateway is missing. I have Symantec Antivirus with latest definations, it is identifying the virus as W32.Imaut,. SAV cleans the virus and prompts for restart, when i restart the system and login, my desktop is missing, i will not be able to find folder options & task manager.
Below is the log file of Combofix:-
ComboFix 09-08-06.01 - User1 08/07/2009 21:52.1.2 - NTFSx86
Microsoft® Windows Vista" Enterprise
Running from: c:\users\User1\Desktop\Com
AV: Symantec AntiVirus *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E
SP: Symantec AntiVirus *disabled* (Updated) {6C85A515-B91D-4D2B-AF18-4
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-D
.
((((((((((((((((((((((((((
.
c:\$recycle.bin\S-1-5-21-3
c:\$recycle.bin\S-1-5-21-3
c:\$recycle.bin\S-1-5-21-3
C:\new folder.exe
C:\Program Files.exe
c:\programdata\Microsoft\N
c:\programdata\Microsoft\N
C:\Windows.exe
c:\windows\Installer\225f8
c:\windows\Installer\2496b
c:\windows\KHATARNAK.exe
c:\windows\system32\khatar
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
ALso Install the SPYBOT www.safer-networking.org
I would start with a scan with http://www.malwarebytes.or
You have to option from here
1. Ok get to another computer with a CD burner and download Dr. web live CD http://www.freedrweb.com/l
If you are using an Ethernet connection update the live CD. If not don't worry about it.
Be sure to change the setting to clean it can and delete if unable to.
2. From rpggamergirl @ http://www.experts-exchang
Please download ComboFix by sUBs:
http://download.bleepingco
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
After it goes through system reboot. It should be clean enough for combofix to do it work.
After all this it should be clean
After combofix is done post the log here to see if more needed to be done.
Then after the system is clean you can install an antivirus of your choice.
CT
Run combofix again using this script.
Open Notepad and paste the text between the lines below into the Notepad window:
------------
File::
C:\New Folder(2).exe
C:\files.exe
C:\Songs.exe
C:\Pictures.exe
C:\Pictures.exe
C:\Documents and Settings.exe
c:\windows\system32\02453.
c:\windows\system32\09B81.
c:\windows\system32\0145E.
Folder::
c:\users\Administrator\App
c:\users\Admin1\AppData\Lo
c:\users\Default\AppData\L
c:\users\User1\AppData\Loc
c:\temp\agentrem
C:\temp
c:\users\User1\temp
------------
Save the above as CFScript.txt on your desktop and drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.
CT
CT is there any way to disable USB storage device and not make any one accessable. One i know is "HKLM\system\currentcontro
You can use that method but i like using this one.
http://support.microsoft.c
If you use the boot cd like i sujected it should find all copies on drives and kill them.
CT
This text replaces the original snippet in post #25072253:
ComboFix 09-08-06.01 - Admin1 08/07/2009 21:52.1.2 - NTFSx86
Microsoft® Windows Vista" Enterprise 6.0.6002.2.1252.1.1033.18.
Running from: c:\users\Admin1\Desktop\Co
AV: Symantec AntiVirus *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E
SP: Symantec AntiVirus *disabled* (Updated) {6C85A515-B91D-4D2B-AF18-4
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-D
.
((((((((((((((((((((((((((
.
c:\$recycle.bin\S-1-5-21-3
c:\$recycle.bin\S-1-5-21-3
c:\$recycle.bin\S-1-5-21-3
C:\new folder.exe
C:\Program Files.exe
c:\programdata\Microsoft\N
c:\programdata\Microsoft\N
c:\users\User1\Copy of Medical Reimbursment Form 07-08 .xls
c:\users\User1\EAM_UNIT_DE
c:\users\User1\Template-Pe
C:\Windows.exe
c:\windows\Installer\225f8
c:\windows\Installer\2496b
c:\windows\KHATARNAK.exe
c:\windows\system32\khatar
----- BITS: Possible infected sites -----
hxxp://192.168.1.2
.
((((((((((((((((((((((((( Files Created from 2009-07-07 to 2009-08-07 ))))))))))))))))))))))))))
.
2009-08-07 16:25 . 2009-08-07 16:25 -------- d-----w- c:\users\User1\AppData\Loc
2009-08-07 16:25 . 2009-08-07 16:25 -------- d-----w- c:\users\Default\AppData\L
2009-08-07 16:25 . 2009-08-07 16:25 -------- d-----w- c:\users\Admin1\AppData\Lo
2009-08-07 16:25 . 2009-08-07 16:25 -------- d-----w- c:\users\Administrator\App
2009-08-07 14:37 . 2009-05-31 16:29 686241 ----a-w- C:\New Folder(2).exe
2009-08-07 14:37 . 2009-05-31 16:29 686241 ----a-w- C:\files.exe
2009-08-07 14:37 . 2009-05-31 16:29 686241 ----a-w- C:\Songs.exe
2009-08-07 14:37 . 2009-05-31 16:29 686241 ----a-w- C:\Pictures.exe
2009-08-07 14:37 . 2009-05-31 16:29 686241 ----a-w- C:\Documents and Settings.exe
2009-08-06 21:05 . 2009-08-04 08:00 259368 ----a-w- c:\programdata\Symantec\Sy
2009-08-06 21:05 . 2009-06-29 20:11 875728 ----a-w- c:\programdata\Symantec\Sy
2009-08-06 21:05 . 2009-06-29 20:11 87888 ----a-w- c:\programdata\Symantec\Sy
2009-08-06 21:05 . 2009-02-18 19:41 2414128 ----a-w- c:\programdata\Symantec\Sy
2009-08-06 21:05 . 2009-02-12 23:03 1181040 ----a-w- c:\programdata\Symantec\Sy
2009-08-06 21:05 . 2009-02-12 23:03 177520 ----a-w- c:\programdata\Symantec\Sy
2009-08-06 21:05 . 2009-02-06 19:26 101936 ----a-w- c:\programdata\Symantec\Sy
2009-08-06 21:05 . 2009-02-06 19:26 371248 ----a-w- c:\programdata\Symantec\Sy
2009-08-06 19:44 . 2009-08-06 19:47 -------- d-----w- C:\SvcTools
2009-08-06 19:33 . 2009-08-06 19:43 -------- d-----w- c:\temp\agentrem
2009-08-06 19:33 . 2009-08-06 19:33 -------- d-----w- C:\temp
2009-08-05 21:03 . 2009-08-05 08:00 259368 ----a-w- c:\programdata\Symantec\De
2009-08-05 21:03 . 2009-06-29 20:11 875728 ----a-w- c:\programdata\Symantec\De
2009-08-05 21:03 . 2009-06-29 20:11 87888 ----a-w- c:\programdata\Symantec\De
2009-08-05 21:03 . 2009-02-18 19:41 2414128 ----a-w- c:\programdata\Symantec\De
2009-08-05 21:03 . 2009-02-12 23:03 1181040 ----a-w- c:\programdata\Symantec\De
2009-08-05 21:03 . 2009-02-12 23:03 177520 ----a-w- c:\programdata\Symantec\De
2009-08-05 21:03 . 2009-02-06 19:26 101936 ----a-w- c:\programdata\Symantec\De
2009-08-05 21:03 . 2009-02-06 19:26 371248 ----a-w- c:\programdata\Symantec\De
2009-08-03 05:37 . 2009-07-18 16:01 78336 ----a-w- c:\windows\system32\ieenco
2009-08-03 05:37 . 2009-07-18 11:35 828416 ----a-w- c:\windows\system32\winine
2009-07-31 09:41 . 2009-07-31 11:23 -------- d-----w- c:\users\User1\AppData\Roa
2009-07-31 09:41 . 2009-08-03 07:04 -------- d-----w- c:\program files\TeamViewer
2009-07-31 09:40 . 2009-07-31 09:40 -------- d-----w- c:\users\User1\temp
2009-07-16 13:44 . 2009-06-15 14:53 156672 ----a-w- c:\windows\system32\t2embe
2009-07-16 13:44 . 2009-06-15 14:52 23552 ----a-w- c:\windows\system32\lpk.dl
2009-07-16 13:44 . 2009-06-15 14:52 72704 ----a-w- c:\windows\system32\fontsu
2009-07-16 13:44 . 2009-06-15 14:51 10240 ----a-w- c:\windows\system32\dciman
2009-07-16 13:44 . 2009-06-15 12:42 289792 ----a-w- c:\windows\system32\atmfd.
2009-07-16 07:28 . 2002-02-18 04:53 46352 ----a-w- c:\windows\setdebug.exe
2009-07-16 07:28 . 2002-02-18 04:52 171280 ----a-w- c:\windows\system32\jit.dl
2009-07-16 07:28 . 2002-02-18 04:52 139536 ----a-w- c:\windows\system32\javaee
2009-07-16 07:28 . 2002-02-18 02:05 6550 ----a-w- c:\windows\jautoexp.dat
2009-07-16 07:28 . 2002-02-18 02:04 313856 ----a-w- c:\windows\system32\dx3j.d
2009-07-16 07:28 . 2009-07-16 07:28 -------- d-----w- c:\windows\Java
2009-07-13 13:02 . 2009-07-13 13:02 94208 ----a-w- c:\programdata\WebEx\WebEx
2009-07-13 13:02 . 2009-07-13 13:02 94208 ----a-w- c:\programdata\WebEx\WebEx
.
((((((((((((((((((((((((((
.
2009-08-07 15:37 . 2009-01-19 09:12 12 ----a-w- c:\windows\bthservsdp.dat
2009-08-07 15:10 . 2009-03-22 19:54 -------- d-----w- c:\program files\OCS Inventory Agent
2009-08-07 14:44 . 2009-01-15 09:40 -------- d-----w- c:\program files\EditPlus 3
2009-08-06 19:38 . 2009-01-26 09:36 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-06 08:00 . 2009-08-06 21:03 259368 ----a-w- c:\programdata\Symantec\De
2009-08-06 08:00 . 2009-08-06 21:03 259368 ----a-w- c:\programdata\Symantec\Sy
2009-08-06 08:00 . 2009-05-21 02:57 259368 ----a-w- c:\programdata\Symantec\De
2009-08-03 15:12 . 2009-03-06 07:34 -------- d-----w- c:\users\User1\AppData\Roa
2009-07-31 06:00 . 2009-04-24 18:38 -------- d-----w- c:\program files\Citrix
2009-07-21 15:08 . 2009-01-14 11:45 -------- d-----w- c:\programdata\Microsoft Help
2009-07-20 03:00 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-19 12:40 . 2009-01-15 05:18 -------- d-----w- c:\program files\Google
2009-07-16 07:28 . 2009-07-16 07:28 2232 ----a-w- c:\windows\Java\Packages\D
2009-07-16 07:28 . 2009-07-16 07:28 155995 ----a-w- c:\windows\Java\Packages\I
2009-07-16 07:28 . 2009-07-16 07:28 2678 ----a-w- c:\windows\Java\Packages\D
2009-07-16 07:28 . 2009-07-16 07:28 2678 ----a-w- c:\windows\Java\Packages\D
2009-07-16 07:28 . 2009-07-16 07:28 2678 ----a-w- c:\windows\Java\Packages\D
2009-07-16 07:28 . 2009-07-16 07:28 2678 ----a-w- c:\windows\Java\Packages\D
2009-07-16 07:28 . 2009-07-16 07:28 2678 ----a-w- c:\windows\Java\Packages\D
2009-07-13 14:23 . 2009-01-26 16:12 -------- d-----w- c:\users\User1\AppData\Roa
2009-07-13 14:23 . 2009-01-26 16:11 -------- d-----w- c:\programdata\WebEx
2009-07-13 13:01 . 2009-01-26 16:11 103752 ----a-w- c:\programdata\WebEx\atmgr
2009-07-13 13:01 . 2009-01-26 16:11 185232 ----a-w- c:\programdata\WebEx\atgpc
2009-07-04 15:18 . 2009-07-04 15:18 4096 ----a-w- c:\windows\system32\02453.
2009-06-29 20:11 . 2009-08-06 21:03 875728 ----a-w- c:\programdata\Symantec\De
2009-06-29 20:11 . 2009-08-06 21:03 875728 ----a-w- c:\programdata\Symantec\Sy
2009-06-29 20:11 . 2009-05-21 02:57 875728 ----a-w- c:\programdata\Symantec\De
2009-06-29 20:11 . 2009-08-06 21:03 87888 ----a-w- c:\programdata\Symantec\De
2009-06-29 20:11 . 2009-08-06 21:03 87888 ----a-w- c:\programdata\Symantec\Sy
2009-06-29 20:11 . 2009-05-21 02:57 87888 ----a-w- c:\programdata\Symantec\De
2009-06-19 14:56 . 2009-05-29 09:30 -------- d-----w- c:\program files\Symantec AntiVirus
2009-06-15 15:36 . 2009-06-15 15:36 163840 ----a-w- c:\programdata\WebEx\WebEx
2009-06-15 15:36 . 2009-06-15 15:36 18432 ----a-w- c:\programdata\WebEx\WebEx
2009-06-15 15:36 . 2009-06-15 15:36 221184 ----a-w- c:\programdata\WebEx\WebEx
2009-06-15 15:36 . 2009-06-15 15:36 69632 ----a-w- c:\programdata\WebEx\WebEx
2009-06-15 15:36 . 2009-06-15 15:36 585728 ----a-w- c:\programdata\WebEx\WebEx
2009-06-15 15:36 . 2009-06-15 15:36 274432 ----a-w- c:\programdata\WebEx\WebEx
2009-06-15 15:36 . 2009-06-15 15:36 221184 ----a-w- c:\programdata\WebEx\WebEx
2009-06-15 15:36 . 2009-06-15 15:36 147968 ----a-w- c:\programdata\WebEx\WebEx
2009-06-15 15:36 . 2009-06-15 15:36 323584 ----a-w- c:\programdata\WebEx\WebEx
2009-06-15 15:36 . 2009-06-15 15:36 28672 ----a-w- c:\programdata\WebEx\WebEx
2009-06-15 15:36 . 2009-06-15 15:36 761344 ----a-w- c:\programdata\WebEx\WebEx
2009-06-15 15:36 . 2009-06-15 15:36 740864 ----a-w- c:\programdata\WebEx\WebEx
2009-06-15 15:34 . 2009-01-26 16:12 46408 ----a-w- c:\programdata\WebEx\atmcc
2009-06-15 15:34 . 2009-01-26 16:11 28488 ----a-w- c:\programdata\WebEx\atgpc
2009-06-11 10:48 . 2009-01-15 10:25 -------- d-----w- c:\programdata\Yahoo!
2009-06-11 10:48 . 2009-01-15 10:25 -------- d-----w- c:\program files\Yahoo!
2009-06-10 19:30 . 2009-06-10 19:30 4096 ----a-w- c:\windows\system32\09B81.
2009-06-09 09:13 . 2009-01-15 05:16 -------- d-----w- c:\program files\FileZilla FTP Client
2009-06-01 09:48 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.da
2009-06-01 09:31 . 2006-11-02 12:37 37665 ----a-w- c:\windows\Fonts\GlobalUse
2009-05-29 09:36 . 2009-05-29 09:36 123952 ----a-w- c:\windows\system32\driver
2009-05-25 07:30 . 2009-05-25 07:30 4096 ----a-w- c:\windows\system32\0145E.
2009-05-21 02:58 . 2009-05-21 02:58 1181040 ----a-w- c:\programdata\Symantec\De
2009-05-21 02:58 . 2009-05-21 02:58 89104 ----a-w- c:\programdata\Symantec\De
2009-05-21 02:58 . 2009-05-21 02:58 876144 ----a-w- c:\programdata\Symantec\De
2009-05-21 02:58 . 2009-05-21 02:58 371248 ----a-w- c:\programdata\Symantec\De
2009-05-21 02:58 . 2009-05-21 02:58 259368 ----a-w- c:\programdata\Symantec\De
2009-05-21 02:58 . 2009-05-21 02:58 2414128 ----a-w- c:\programdata\Symantec\De
2009-05-21 02:58 . 2009-05-21 02:58 177520 ----a-w- c:\programdata\Symantec\De
2009-05-21 02:58 . 2009-05-21 02:58 101936 ----a-w- c:\programdata\Symantec\De
2009-05-13 10:04 . 2009-01-18 14:46 54800 ----a-w- c:\users\Admin1\AppData\Lo
.
((((((((((((((((((((((((((
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWAR
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
[HKEY_LOCAL_MACHINE\SOFTWA
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Windows Mobile Device Center"="c:\windows\Window
"IgfxTray"="c:\windows\sys
"HotKeysCmds"="c:\windows\
"Persistence"="c:\windows\
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"EverdreamLogo"="c:\svctoo
"EverdreamVNC"="c:\svctool
"SunJavaUpdateSched"="c:\p
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-01-31 115560]
"vptray"="c:\progra~1\SYMA
"SMA7.5.257"="c:\svctools\
[HKEY_LOCAL_MACHINE\softwa
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"disablecad"= 1 (0x1)
[HKEY_LOCAL_MACHINE\softwa
"NoAutoUpdate"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM
@="Service"
[HKEY_LOCAL_MACHINE\softwa
"DisableMonitoring"=dword:
[HKEY_LOCAL_MACHINE\softwa
"VistaSp2"=hex(b):29,dc,c0
[HKLM\~\services\sharedacc
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedacc
"{A8464F91-1E3C-47A4-8529-
"{0160EBC0-B37B-4DB7-84F6-
"{F31A000F-5894-4E46-B113-
"{70E25E2C-0CB9-4543-B933-
"{DD6DCE26-5902-4731-9689-
"TCP Query User{44EA496B-1A41-46BA-96
"UDP Query User{87A3DAE7-8AAF-44D5-AE
"{905C847F-3F76-4B9E-988A-
"{91C2923D-3792-4CFF-8BCD-
"{307E93B9-327E-484D-8A8D-
"{7224290B-A8EF-45D3-A37F-
"TCP Query User{05B4AB97-7B93-49C7-BE
"UDP Query User{07747707-4788-4E40-98
"{22B27FEF-3255-4755-A2D5-
"TCP Query User{72B1A746-1DF7-43CC-82
"UDP Query User{3A0EA028-74B7-40C1-A4
"TCP Query User{D749B7AF-9FE7-4996-87
"UDP Query User{77F5C6CF-BF94-493C-A3
"TCP Query User{40A15FF6-96E7-4AC3-9A
"UDP Query User{CE96387A-D4BD-444B-99
"{E6EBDA99-43B7-4521-99A8-
"TCP Query User{D59E3032-5BF1-4F18-B6
"UDP Query User{88992A37-BB0A-46CE-A4
"{6A73B59F-D69B-4D0F-BACE-
"{1ABDA66D-2FB4-40BB-824A-
"TCP Query User{5231FA68-0733-45BA-A2
"UDP Query User{DA121F1D-62F9-4275-BF
"TCP Query User{BCD9A8D0-CC4B-45B4-AB
"UDP Query User{98F88005-6871-4BC1-BF
"{4FE30C5B-44D4-4817-925D-
"{09E4A70C-4933-4EE2-92AF-
"{717AE0EB-FCC8-4E7F-B057-
"{6A5FB4BE-8E02-46DD-9D14-
R1 dwvkbd;DameWare Virtual Keyboard 32 bit Driver;c:\windows\System32
R2 EverdreamVNC;Everdream VNC Server;c:\svctools\VNC\Win
R2 OCS INVENTORY;OCS INVENTORY SERVICE;c:\program files\OCS Inventory Agent\OcsService.exe [2/28/2007 1:02 AM 61440]
R2 SavRoam;SAVRoam;c:\program
R2 SMA7.5.257;Software Management Agent 7.5.257;c:\svctools\7.5.25
R3 DwMirror;DwMirror;c:\windo
R3 EraserUtilRebootDrv;Eraser
R3 xpvcom;XPVCOM Port;c:\windows\System32\d
S2 gupdate1c976ff77de4050;Goo
S3 fssfltr;FssFltr;c:\windows
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 6:08 PM 533360]
S3 PSEXESVC;PsExec;c:\windows
S3 Tomcat6;Apache Tomcat;c:\program files\Apache Software Foundation\Tomcat 6.0\bin\tomcat6.exe [7/22/2008 5:31 AM 57344]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - DEFWATCH
*NewlyCreated* - SYMANTEC_ANTIVIRUS
[HKEY_LOCAL_MACHINE\softwa
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HKEY_LOCAL_MACHINE\SOFTWAR
elplx
csgppw
goxovqi
husmz
awwbn
crjotjgk
jikzcm
xhvmxhojc
.
Contents of the 'Scheduled Tasks' folder
2009-08-07 c:\windows\Tasks\GoogleUpd
- c:\program files\Google\Update\Google
2009-08-07 c:\windows\Tasks\GoogleUpd
- c:\program files\Google\Update\Google
2009-08-07 c:\windows\Tasks\User_Feed
- c:\windows\system32\msfeed
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-
.
------- Supplementary Scan -------
.
uStart Page = hxxp://securityresponse.sy
mStart Page = hxxp://securityresponse.sy
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Offic
TCP: {4A091E5E-4F6D-4F3F-AE4E-D
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/cl
FF - ProfilePath - c:\users\Admin1\AppData\Ro
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-0
.
**************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-07 21:55
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************
.
Completion time: 2009-08-07 21:56
ComboFix-quarantined-files
Pre-Run: 7,527,391,232 bytes free
Post-Run: 7,624,966,144 bytes free
284 --- E O F --- 2009-08-05 21:34
Business Accounts
Answer for Membership
by: vikshiPosted on 2009-08-11 at 11:02:17ID: 25071630
The virus is called W32.SillyFDC
See the link to know more about it an for the removal instrucions
http://www.syma ntec.com/s ecurity_re sponse/wri teup.jsp?d ocid=2006- 071111-064 6-99&tabid =1
If you have MCaffe or symantec or anyother version of antivirus installed,update the antivirus an run a complete scan
Or else run the Stinger from MCaffe
Download from : http://vil.nai.com/vil/sti nger/