Hii. Thanks for the reply. I followed the procedure you have mentioned. I fixed all the above said 5 entried. But I am not sure it is successful. Because already I fixed "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1" but there was no change. Then here is the log from combofix.
ComboFix 08-03-13.4 - computer 2008-03-14 17:35:03.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.462 [GMT 5.5:30]
Running from: C:\Documents and Settings\computer\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\Downloaded Program Files\Quarantine
C:\WINDOWS\system32\lsprst7.dll
C:\WINDOWS\system32\prsgrc.dll
C:\WINDOWS\system32\setting.ini
C:\WINDOWS\system32\vfl1h75.dll
D:\Autorun.inf
E:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-02-14 to 2008-03-14 )))))))))))))))))))))))))))))))
.
2008-03-13 20:09 . 2008-03-13 20:18 <DIR> d-------- C:\WINDOWS\BDOSCAN8
2008-03-13 19:13 . 2008-03-13 19:13 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-03-13 19:06 . 2008-03-13 19:07 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-03-11 19:03 . 2008-03-11 19:03 <DIR> d-------- C:\fsaua.data
2008-03-11 18:42 . 2008-03-11 18:42 <DIR> d-------- C:\Program Files\McAfee
2008-03-11 18:42 . 2008-03-11 18:42 <DIR> d-------- C:\Program Files\Common Files\McAfee
2008-03-11 18:42 . 2008-03-11 18:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-03-11 18:42 . 2006-12-19 15:06 1,495,552 --a------ C:\WINDOWS\system32\epoPGPsdk.dll
2008-03-11 18:42 . 2007-02-22 20:50 170,408 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2008-03-11 18:42 . 2006-11-30 08:50 72,264 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2008-03-11 18:42 . 2006-11-30 08:50 64,360 --a------ C:\WINDOWS\system32\drivers\mfeapfk.sys
2008-03-11 18:42 . 2006-11-30 08:50 52,136 --a------ C:\WINDOWS\system32\drivers\mfetdik.sys
2008-03-11 18:42 . 2006-11-30 08:50 34,152 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2008-03-11 18:42 . 2006-12-19 15:06 280 --a------ C:\WINDOWS\system32\epoPGPsdk.dll.sig
2008-03-10 20:20 . 2008-03-13 21:29 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-10 20:20 . 2008-03-10 20:20 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-10 20:13 . 2008-01-31 00:46 616,609 -rahs---- C:\WINDOWS\system32\svchost .exe
2008-03-10 20:13 . 2008-01-31 00:46 616,609 -rahs---- C:\WINDOWS\system32\regsvr.exe
2008-03-10 19:34 . 1998-06-19 12:23 270,848 --a------ C:\WINDOWS\UNWISE32.EXE
2008-03-06 18:47 . 2008-03-11 18:18 <DIR> d-------- C:\Program Files\Macrogaming
2008-03-06 18:03 . 2008-03-06 18:03 <DIR> d-------- C:\Documents and Settings\computer\Application Data\LQ Graphics
2008-03-06 15:11 . 2008-03-06 15:12 1,045 --a------ C:\temp.avs
2008-03-06 15:11 . 2008-03-06 15:12 55 --a------ C:\WINDOWS\param.ini
2008-03-06 15:09 . 2004-02-23 21:41 719,872 --a------ C:\WINDOWS\system32\devil.dll
2008-03-06 15:09 . 2005-10-08 01:14 308,224 --a------ C:\WINDOWS\system32\avisynth.dll
2008-03-06 15:09 . 2006-05-11 09:43 163,496 --a------ C:\WINDOWS\system32\help.chm
2008-03-06 15:09 . 2006-05-11 09:41 80 --a------ C:\WINDOWS\system32\Home Page.url
2008-03-04 00:45 . 2008-03-04 00:47 <DIR> d-------- C:\Program Files\Free Video Converter
2008-03-03 00:37 . 2008-03-14 14:32 <DIR> d-------- C:\divx
2008-03-01 03:44 . 2008-03-05 00:25 <DIR> d-------- C:\Documents and Settings\computer\Application Data\dvdcss
2008-03-01 02:45 . 2008-03-01 02:45 42,612 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-02-27 09:07 . 2008-02-27 09:07 <DIR> d-------- C:\Documents and Settings\computer\Application Data\Grisoft
2008-02-27 09:07 . 2007-05-30 17:40 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-26 06:52 . 2008-02-26 06:52 <DIR> d-------- C:\Program Files\PCZeitschaltuhr
2008-02-26 06:52 . 2008-02-27 13:44 <DIR> d-------- C:\Documents and Settings\computer\Application Data\AutoPowerOn
2008-02-23 15:33 . 2007-04-23 05:45 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-02-23 15:33 . 2007-04-23 05:45 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2008-02-23 15:33 . 2007-04-23 05:45 116,472 --------- C:\WINDOWS\system32\pxcpyi64.exe
2008-02-23 15:33 . 2007-04-23 05:45 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-02-23 15:33 . 2007-04-23 05:45 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-02-16 02:01 . 2008-02-16 02:01 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\PDFcreator
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-14 11:51 --------- d-----w C:\Documents and Settings\computer\Application Data\AVG7
2008-03-14 04:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2008-03-12 17:18 --------- d-----w C:\Program Files\Yahoo!
2008-03-12 16:02 --------- d-----w C:\Documents and Settings\computer\Application Data\DMCache
2008-03-07 12:48 --------- d-----w C:\Documents and Settings\computer\Application Data\MegauploadToolbar
2008-03-06 14:00 --------- d-----w C:\Program Files\ANSYS Inc
2008-03-02 08:05 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-03-01 05:45 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-29 21:51 --------- d-----w C:\Program Files\Picasa2
2008-02-27 09:33 --------- d-----w C:\Program Files\Nokia
2008-02-27 03:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-23 10:15 --------- d-----w C:\Documents and Settings\computer\Application Data\DivX
2008-02-23 10:03 --------- d-----w C:\Program Files\DivX
2008-02-20 21:49 --------- d-----w C:\Documents and Settings\computer\Application Data\uTorrent
2008-02-10 09:56 --------- d-----w C:\Documents and Settings\computer\Application Data\IDM
2008-02-02 19:35 --------- d-----w C:\Documents and Settings\computer\Application Data\U3
2008-01-16 16:52 --------- d-----w C:\Documents and Settings\computer\Application Data\PC Suite
2008-01-16 16:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2008-01-16 16:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-01-16 16:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-16 16:43 --------- d-----w C:\Program Files\IVT Corporation
2008-01-15 17:31 --------- d-----w C:\Documents and Settings\computer\Application Data\Nokia
2008-01-15 17:29 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-01-15 17:29 --------- d-----w C:\Program Files\DIFX
2008-01-15 17:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2007-12-23 16:47 32,232 ----a-w C:\license.dat
2007-12-16 17:58 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2007-09-23 12:59 52,768 ----a-w C:\Documents and Settings\computer\Application Data\GDIPFONTCACHEV1.DAT
.
<pre>
--sha-r 616,609 2008-01-30 19:16:02 C:\WINDOWS\system32\svchost .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 17:30 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 21:54 1694208]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"Crammer"="C:\Documents and Settings\computer\Desktop\Dictionary\Crammer.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-05-25 12:21 131072]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-05-25 12:21 155648]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-05-25 12:21 131072]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-25 12:21 16132608 C:\WINDOWS\RTHDCPL.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-08-05 13:20 180269]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb02.exe" [2001-03-22 20:48 192512]
"UDC Integration"="" []
"OrderReminder"="C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-07-21 15:30 98304]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 10:54 282624]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-25 08:44 579072]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 14:55 6731312]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"ShStatEXE"="C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.exe" [2007-02-22 20:50 112216]
"McAfeeUpdaterUI"="C:\Program Files\McAfee\Common Framework\UdaterUI.exe" [2006-12-19 11:27 136768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-11-25 14:26 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk
backup=C:\WINDOWS\pss\BlueSoleil.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^computer^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\computer\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitDownload]
C:\Program Files\BitDownload\BitDownload.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 17:05 81920 C:\Program Files\D-Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
--a------ 2007-01-02 02:52 3739648 C:\Program Files\Google\Google Talk\googletalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 2007-08-29 19:49 2532784 C:\Program Files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 21:54 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\svchost Agent]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-08-10 21:03 68856 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2003-12-13 06:20 33792 C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"84:TCP"= 84:TCP:VRS Recording System Web Control Panel
"81:TCP"= 81:TCP:Axon Web Server
R2 ANSYS FLEXlm license manager;ANSYS FLEXlm license manager;C:\PROGRA~1\ANSYSI~2\SHARED~1\LICENS~1\Intel\lmgrd.exe [2006-03-24 22:04]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22d5b662-c785-11dc-b038-001167558fc8}]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2faa834e-7579-11dc-956b-0019d187a3cf}]
\Shell\Auto\command - G:\MicrosoftPowerPoint.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{56e6491b-4cc8-11dc-9494-0019d187a3cf}]
\Shell\AutoRun\command - I:\188qsm.bat
\Shell\explore\Command - I:\188qsm.bat
\Shell\open\Command - I:\188qsm.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{683226a4-62f0-11dc-950f-0019d187a3cf}]
\Shell\Auto\command - MicrosoftPowerPoint.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aea70086-5c39-11dc-94e5-0019d187a3cf}]
\Shell\AutoRun\command - G:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b8794dac-8b65-11dc-95d3-0019d187a3cf}]
\Shell\AutoRun\command - G:\ntde1ect.com
\Shell\explore\Command - G:\ntde1ect.com
\Shell\open\Command - G:\ntde1ect.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9c4ff5b-e61e-11dc-b0ad-001167558fc8}]
\Shell\AutoRun\command - 2ifetri.cmd
\Shell\explore\Command - 2ifetri.cmd
\Shell\open\Command - 2ifetri.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8c2a2aa-cc00-11dc-b047-001167558fc8}]
\Shell\Auto\command - MicrosoftPowerPoint.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-03-14 11:30:00 C:\WINDOWS\Tasks\A5BD3BC291E6AD36.job"
- c:\docume~1\computer\applic~1\chicproc\Acid the idol.exe
"2008-03-01 14:54:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-12 02:38:21 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\svchost
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-14 17:36:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-14 17:36:42
ComboFix-quarantined-files.txt 2008-03-14 12:06:40
.
2008-02-13 18:30:05 --- E O F ---
Thanks