Hey Thanx for the reply n advise..i tried what u saud and here are the logs..
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:55:43 PM, on 1/13/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Policies\Explorer\Run: [status] present
O4 - HKLM\..\Policies\Explorer\Run: [winlogon] C:\heap41a\svchost.exe C:\heap41a\std.txt
O4 - HKLM\..\Policies\Explorer\Run: [Explorer] Winlogons
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{B3C587AA-6F6F-4B8E-874E-5CB879A6C0A1}: NameServer = 218.248.255.145,61.1.64.65
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\aspnet_state.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
--
End of file - 3382 bytes
ComboFix 08-01-13.1 - Administrator 2008-01-13 20:47:48.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.50 [GMT 5.5:30]Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\amvo1.dll
.
((((((((((((((((((((((((( Files Created from 2007-12-13 to 2008-01-13 )))))))))))))))))))))))))))))))
.
2008-01-13 20:47 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-13 13:19 . 2008-01-13 16:36 106,153 -r-hs---- C:\d.com
2008-01-12 19:20 . 2008-01-12 19:20 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-09 18:50 . 2008-01-09 18:50 104,392 -r-hs---- C:\tio8x6.cmd
2008-01-08 21:19 . 2008-01-09 12:55 105,719 -r-hs---- C:\u.bat
2008-01-04 18:33 . 2008-01-04 18:33 104,542 -r-hs---- C:\semo2x.exe
2008-01-04 18:33 . 2008-01-13 20:47 492 -r-hs---- C:\autorun.inf
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-13 09:20 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-10 07:58 --------- d-----w C:\Documents and Settings\Administrator\Application Data\U3
2008-01-06 05:50 --------- d-----w C:\Documents and Settings\Administrator\Application Data\AVG7
2007-12-30 14:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-12-03 10:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-02 07:25 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-02 04:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-02 04:50 --------- d-----w C:\Program Files\Yahoo!
2007-12-02 04:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\PC Suite
2007-12-02 04:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2007-11-20 16:19 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Media Player Classic
2007-11-14 13:06 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Super-Cow
2007-10-30 06:52 3,082 ----a-w C:\WINDOWS\system32\affv11300p2now.sys
2007-08-17 15:23 16,752 ----a-w C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-10-08 06:01 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-10-08 05:57 126976]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-26 12:24 579072]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 15:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-10-25 17:16 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"status"= present
"winlogon"= C:\heap41a\svchost.exe C:\heap41a\std.txt
"Explorer"= Winlogons
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverCD]
F:\Run.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--a------ 2004-03-17 15:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe
R2 SMTPSVC;Simple Mail Transfer Protocol (SMTP);C:\WINDOWS\system32\inetsrv\inetinfo.exe [2004-08-04 00:56]
S3 cheetah1;cheetah1;E:\New Folder\Cheetah Engine 1.4\cheetah.sys []
S3 DADriv1;DADriv1;E:\New Folder\DAEngine\DAK32.sys []
S3 dump_wmimmc;dump_wmimmc;D:\Maple\game\MapleStory\GameGuard\dump_wmimmc.sys []
S3 IlvMoneyDRIVER53;IlvMoneyDRIVER53;E:\Moonlight Engine 1083\IlvMoney1083.sys []
S3 Kaspersky1;Kaspersky1;E:\New Folder\New Folder\Kaspersky.sys []
S3 projectx1;projectx1;E:\Marche0698 Hack Pack\ProjectX_3.0 Engine\ProjectX3.0 Tux-Hack\FelipeZe.sys []
S3 SoRa01;SoRa01;E:\New Folder\SoRa Remak Engine 2.6\SoRa.sys []
S3 sys_com001;sys_com001;E:\New Folder\SysComEngine_1059\syscom.sys []
S3 toBzM;toBzM;C:\toBzM.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79c1991c-9140-11dc-8989-000fea9f9422}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79c1991d-9140-11dc-8989-000fea9f9422}]
\Shell\Auto\command - MicrosoftPowerPoint.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b4280019-24b8-11dc-a297-000fea9f9422}]
\Shell\Auto\command - G:\MicrosoftPowerPoint.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ceeaa4d4-2001-11dc-a283-000fea9f9422}]
\Shell\AutoRun\command - G:\tio8x6.cmd
\Shell\explore\Command - G:\tio8x6.cmd
\Shell\open\Command - G:\tio8x6.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f098327a-226a-11dc-a294-000fea9f9422}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
"2007-08-08 10:49:08 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2007-09-03 03:30:00 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2007-12-03 04:30:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2007-12-31 05:30:01 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2008-01-06 06:30:04 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2008-01-13 07:30:05 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2008-01-13 08:30:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2008-01-13 09:30:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2008-01-13 10:30:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2008-01-13 11:30:03 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2008-01-13 12:30:04 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2007-08-08 10:49:08 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2008-01-13 13:30:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2008-01-08 14:30:01 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2008-01-08 15:30:09 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2008-01-07 16:30:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2008-01-09 17:30:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2007-08-16 10:15:43 C:\WINDOWS\Tasks\At25.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2007-08-16 10:15:43 C:\WINDOWS\Tasks\At26.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2007-10-19 02:00:00 C:\WINDOWS\Tasks\At27.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2007-08-16 10:15:43 C:\WINDOWS\Tasks\At28.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2007-08-16 10:15:43 C:\WINDOWS\Tasks\At29.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2007-10-19 02:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2007-08-16 10:15:43 C:\WINDOWS\Tasks\At30.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2007-08-16 10:15:43 C:\WINDOWS\Tasks\At31.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2007-08-16 10:15:43 C:\WINDOWS\Tasks\At32.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2007-08-16 10:15:43 C:\WINDOWS\Tasks\At33.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2007-09-03 03:30:00 C:\WINDOWS\Tasks\At34.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2007-12-03 04:30:00 C:\WINDOWS\Tasks\At35.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2007-12-31 05:30:02 C:\WINDOWS\Tasks\At36.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2008-01-06 06:30:05 C:\WINDOWS\Tasks\At37.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2008-01-13 07:30:06 C:\WINDOWS\Tasks\At38.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2008-01-13 08:30:01 C:\WINDOWS\Tasks\At39.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2007-08-08 10:49:08 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2008-01-13 09:30:00 C:\WINDOWS\Tasks\At40.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2008-01-13 10:30:00 C:\WINDOWS\Tasks\At41.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2008-01-13 11:30:03 C:\WINDOWS\Tasks\At42.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2008-01-13 12:30:05 C:\WINDOWS\Tasks\At43.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2008-01-13 13:30:00 C:\WINDOWS\Tasks\At44.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2008-01-08 14:30:02 C:\WINDOWS\Tasks\At45.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2008-01-08 15:30:10 C:\WINDOWS\Tasks\At46.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2008-01-07 16:30:00 C:\WINDOWS\Tasks\At47.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2008-01-09 17:30:00 C:\WINDOWS\Tasks\At48.job"
- C:\WINDOWS\system32\N2EkWjYn.exe
"2007-08-19 13:18:45 C:\WINDOWS\Tasks\At49.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2007-08-08 10:49:08 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2007-08-19 13:18:45 C:\WINDOWS\Tasks\At50.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2007-10-19 02:00:00 C:\WINDOWS\Tasks\At51.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2007-08-19 13:18:45 C:\WINDOWS\Tasks\At52.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2007-08-19 13:18:45 C:\WINDOWS\Tasks\At53.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2007-08-19 13:18:45 C:\WINDOWS\Tasks\At54.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2007-08-19 13:18:45 C:\WINDOWS\Tasks\At55.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2007-08-19 13:18:45 C:\WINDOWS\Tasks\At56.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2007-08-19 13:18:45 C:\WINDOWS\Tasks\At57.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2007-09-03 03:30:00 C:\WINDOWS\Tasks\At58.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2007-12-03 04:30:00 C:\WINDOWS\Tasks\At59.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2007-08-08 10:49:08 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2007-12-31 05:30:02 C:\WINDOWS\Tasks\At60.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2008-01-06 06:30:05 C:\WINDOWS\Tasks\At61.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2008-01-13 07:30:06 C:\WINDOWS\Tasks\At62.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2008-01-13 08:30:01 C:\WINDOWS\Tasks\At63.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2008-01-13 09:30:00 C:\WINDOWS\Tasks\At64.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2008-01-13 10:30:01 C:\WINDOWS\Tasks\At65.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2008-01-13 11:30:04 C:\WINDOWS\Tasks\At66.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2008-01-13 12:30:05 C:\WINDOWS\Tasks\At67.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2008-01-13 13:30:00 C:\WINDOWS\Tasks\At68.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2008-01-08 14:30:02 C:\WINDOWS\Tasks\At69.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2007-08-08 10:49:08 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2008-01-08 15:30:10 C:\WINDOWS\Tasks\At70.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2008-01-07 16:30:00 C:\WINDOWS\Tasks\At71.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2008-01-09 17:30:00 C:\WINDOWS\Tasks\At72.job"
- C:\WINDOWS\system32\gpe80vNb.exe
"2007-08-08 10:49:08 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
"2007-08-08 10:49:08 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\Xi3HW3bs.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-13 20:49:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-13 20:50:44
ComboFix-quarantined-files.txt 2008-01-13 15:20:30
.
2007-08-01 13:05:52 --- E O F ---
These are the 2 logs..
I tried the combofix and the problem has stopped..do i have to do anyting else..
you also said that it was due to some USB problem..will i get infected the next time i us the pendrive since i use it quite frequently...thx for the solution if there is any thing else plz do tell..