hi!
this is my combofix log...
ComboFix 08-09-03.03 - MUKUL 2008-09-04 12:25:20.1 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.62 [GMT 5.5:30]
Running from: C:\Documents and Settings\MUKUL\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\system.exe
.
((((((((((((((((((((((((( Files Created from 2008-08-04 to 2008-09-04 )))))))))))))))))))))))))))))))
.
2008-09-03 18:54 . 2008-09-03 18:54 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-09-03 18:54 . 2008-09-03 18:54 <DIR> d-------- C:\Documents and Settings\MUKUL\Application Data\SUPERAntiSpyware.com
2008-09-03 18:54 . 2008-09-03 18:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-03 18:53 . 2008-09-03 18:53 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-03 18:45 . 2008-09-04 12:21 2,610 --a------ C:\WINDOWS\system32\Config.MPF
2008-09-03 18:39 . 2008-09-03 18:39 <DIR> d--hs---- C:\FOUND.000
2008-09-03 00:34 . 2008-09-03 00:34 <DIR> dr-hs---- C:\Config
2008-09-03 00:33 . 2004-08-04 00:56 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-09-03 00:33 . 2004-08-03 23:08 26,496 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys
2008-09-03 00:33 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-09-03 00:33 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\dllcache\usbscan.sys
2008-09-03 00:33 . 2001-08-17 13:56 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS
2008-09-03 00:33 . 2001-08-17 13:56 7,552 --a------ C:\WINDOWS\system32\dllcache\sonypvu1.sys
2008-09-03 00:33 . 2001-08-17 22:36 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-09-03 00:02 . 2008-09-03 00:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-09-03 00:01 . 2008-09-03 00:01 <DIR> d-------- C:\Program Files\Yahoo!
2008-09-02 23:45 . 2008-09-02 23:45 0 --a------ C:\WINDOWS\nsreg.dat
2008-09-02 23:44 . 2008-09-02 23:44 <DIR> d--hs---- C:\Recycled
2008-09-02 23:43 . 2008-09-02 23:43 <DIR> d---s---- C:\Documents and Settings\MUKUL\UserData
2008-09-02 23:29 . 2006-03-03 08:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2008-09-02 23:28 . 2007-11-22 06:44 201,320 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-09-02 23:28 . 2007-07-13 06:20 113,952 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-09-02 23:28 . 2007-11-22 06:44 79,304 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-09-02 23:28 . 2007-12-02 12:51 40,488 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2008-09-02 23:28 . 2007-11-22 06:44 35,240 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-09-02 23:28 . 2007-11-22 06:44 33,832 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2008-09-02 23:27 . 2008-09-02 23:27 <DIR> d-------- C:\Program Files\McAfee.com
2008-09-02 23:27 . 2008-09-02 23:27 <DIR> d-------- C:\Program Files\McAfee
2008-09-02 23:27 . 2008-09-02 23:27 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-09-02 23:25 . 2008-09-02 23:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-11-30 4662776]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-08-19 1576176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2004-12-21 33792]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-09-05 113664]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
S3 slnt;Realtek RTL8139 Family PCI Fast Ethernet NIC;C:\WINDOWS\system32\DRIVERS\slnt.sys [2004-06-22 18004]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dddbca40-7921-11dd-949c-8e63abdacea9}]
\Shell\Auto\command - G:\system.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL system.exe
\Shell\Explore\command - G:\system.exe
\Shell\Open\command - G:\system.exe
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKCU-Explorer_Run-winlogon - C:\Config\system.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\MUKUL\Application Data\Mozilla\Firefox\Profiles\dtzna7o6.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 6.0\Reader\browser\nppdf32.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-04 12:29:58
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-04 12:31:35
ComboFix-quarantined-files.txt 2008-09-04 07:01:30
Pre-Run: 7,507,394,560 bytes free
Post-Run: 7,522,770,944 bytes free
115
-----------------------
well could you please tell me how do i erase this virus from my memory stick??? will formatting it be ok??
but if i format it, do i do it from some other (uninfected) comp or will mine be ok??
loverboy_muks@yahoo.co.in