COMPUTER STUFF
Home > LOEKELOE > COMPUTER STUFF > Virus Antivirus Virus Antivirus Virus Antivirus Virus Antivirus Virus Antivirus Virus
Total Views: 335458
Page 225 of 336 | ‹ First  < 220 221 222 223 224 225 226 227 228 229 230 >  Last ›

L10nelmess1 - 19/02/2012 12:16 AM
#4481

Quote:
Original Posted By Brainniax
gan browser ane gak bisa buka website antivirus
ane coba scan pake smadav & malwarebytes anti malware
ada ketemu sih, udah ane delete juga virusnya
terus ane restart tapi kok masih blm bisa juga ya

ngmpet diman ya itu virus kampret


coba juragan make av luar make eset atau norton

Jukebox355 - 19/02/2012 04:11 AM
#4482

Gan tolong cek notebook ane ada yg aneh ga ya

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:07:16, on 19/02/2012
Platform: Unknown Windows (WinNT 6.01.3505 SP1)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Program Files\OO Software\Defrag\oodtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Eraser\Eraser.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\TweakMASTER\TMTray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Switcher\Switcher.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Users\rizky\AppData\Roaming\DRPSu\DrvUpdater.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Rainmeter\Rainmeter.exe
C:\PROGRA~1\DUMETE~1\DUMeter.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Windows\system32\prevhost.exe
C:\Users\rizky\Downloads\Compressed\Virus Removal Kit\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yandex.ru/?clid=154464
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;192.168.*.*
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: 4*shared.com - {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - C:\Program Files\4*shared.com\prxtb4sh0.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Increase performance and video formats for your HTML5 - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
O2 - BHO: TweakMASTER PRO Component - {7DAAC7DE-9EF0-4FF0-BFA5-AFF3E899054C} - C:\PROGRA~1\TWEAKM~1\TweakBHO.dll
O2 - BHO: ???????@Mail.Ru - {8984B388-A5BB-4DF7-B274-77B879E179DB} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: 4*shared.com Toolbar - {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - C:\Program Files\4*shared.com\prxtb4sh0.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [OODefragTray] C:\Program Files\OO Software\Defrag\oodtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Eraser] "C:\PROGRA~1\Eraser\Eraser.exe" --atRestart
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [4*shared Update] "C:\Program Files\4*shared Desktop\checkUpdate.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [TweakMASTER] "C:\PROGRA~1\TWEAKM~1\TMTray.exe"
O4 - HKLM\..\Run: [SBAMTray] "C:\Program Files\Sunbelt Software\VIPRE\SBAMTray.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Switcher] "C:\Program Files\Switcher\Switcher.exe" /quiet
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [DrvUpdater] C:\Users\rizky\AppData\Roaming\DRPSu\DrvUpdater.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [DU Meter] C:\Program Files\DU Meter\DUMeter.exe
O4 - HKUS\S-1-5-18\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun (User 'Default user')
O4 - Global Startup: Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe
O8 - Extra context menu item: &Download All using 4*shared Desktop - res://C:\Program Files\4*shared Desktop\Desktop.32/D_ALL_LINK
O8 - Extra context menu item: &Download using 4*shared Desktop - res://C:\Program Files\4*shared Desktop\Desktop.32/D_ONE_LINK
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd. - C:\Program Files\DU Meter\DUMeterSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Layanan Pembaruan Google (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Layanan Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MotoHelper Service (MotoHelper) - Unknown owner - C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: VIPRE Antivirus Premium (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBAMSvc.exe
O23 - Service: SB Recovery Service (SBPIMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\VIPRE\SBPIMSvc.exe

--
End of file - 8927 bytes

Note: satu lagi ko... itu unknown windows ya???
arfhere - 19/02/2012 06:22 AM
#4483
Bantuannya dong gan ASAP
Gan, tolong bantu check Loghijack sya ya, belakang ini akun sya sering dibobol.

Spoiler for loghijack

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Web Accelerator\slipcore.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Web Accelerator\slipgui.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\Explorer.exe
C:\Program Files\Smartfren Connex AC682 UI\bin\App.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 -HKCU\Software\Microsoft\Internet Explorer\Main,Start Pagetarget="_blank"http://search.babylon.com/?AF=108976&babsrc=HP_ss&mntrId=c2c256ea000000000000000000000 000[/ur]
R1 -HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL= [url]http://go.microsoft.com/fwlink/?LinkId=69157

R1 -HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL= http://go.microsoft.com/fwlink/?LinkId=54896
R1 -HKLM\Software\Microsoft\Internet Explorer\Main,Search Page= http://go.microsoft.com/fwlink/?LinkId=54896
R0 -HKLM\Software\Microsoft\Internet Explorer\Main,Start Page= http://go.microsoft.com/fwlink/?LinkId=69157
R0 -HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName=
R3 -URLSearchHook: YTNavAssistPlugin Class - {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 -BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 -BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 -BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll
O2 -BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 -BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 -BHO: MegaIeHelperBHO - {77F4E711-789B-447F-9614-96759B2F83C6} - C:\Users\Arief\AppData\Local\Megamedia\Megakey\MegaIeHelper.dll
O2 -BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - C:\Program Files\Web Accelerator\components\NOWImaging.dll
O2 -BHO: Prefetch - {A66AA08A-9BF0-4e87-99E6-6972731D6B99} - C:\Program Files\Web Accelerator\Prefetch.dll
O2 - BHO: ZeonIEEventHelper Class - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Nuance PDF - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe C:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
O4 -HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 -HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 -HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 -HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 -HKLM\..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
O4 - HKLM\..\Run: [PDFHook] C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [SlipStream] "C:\Program Files\Web Accelerator\slipcore.exe"
O4 - HKLM\..\Run: [PDF6 Registry Controller] C:\Program Files\Nuance\PDF Professional 6\RegistryController.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 -HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 -HKLM\..\Run: [Malwarebytes' Anti-Malware]"C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 -HKCU\..\Run: [DAEMON Tools Lite]"C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 -HKCU\..\Run: [Sidebar]C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [IDMan]C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 -Global Startup: 1Dial Web Accelerator.lnk = C:\Program Files\Web Accelerator\slipgui.exe
O8 -Extra context menu item: Append the content of the link to existing PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
O8 -Extra context menu item: Append the content of the selected links to existing PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppendSelLinks.HTML
O8 -Extra context menu item: Append to existing PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIEAppend.HTML
O8 -Extra context menu item: Capture Web Page - C:\Users\Arief\AppData\Local\Megamedia\Megakey\CaptureWebPage.htm
O8 -Extra context menu item: Create PDF file - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
O8 -Extra context menu item: Create PDF file from the content of the link - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECapture.HTML
O8 -Extra context menu item: Create PDF files from the selected links - res://C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll/ZeonIECaptureSelLinks.HTML
O8 -Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 -Extra context menu item: Fetch to Megaupload - C:\Users\Arief\AppData\Local\Megamedia\Megakey\MegaUpload.htm
O8 -Extra context menu item: Open with PDF Professional 6 - res://C:\Program Files\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
O9 -Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} -C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 -Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 -Unknown file in Winsock LSP: c:\programdata\megamedia\megakey\msadm.dll
O10 -Unknown file in Winsock LSP: c:\programdata\megamedia\megakey\msadm.dll
O10 -Unknown file in Winsock LSP: c:\programdata\megamedia\megakey\msadm.dll
O10 -Unknown file in Winsock LSP: c:\programdata\megamedia\megakey\msadm.dll
O10 -Unknown file in Winsock LSP: c:\programdata\megamedia\megakey\msadm.dll
O10 -Unknown file in Winsock LSP: c:\programdata\megamedia\megakey\msadm.dll
O10 -Unknown file in Winsock LSP: c:\programdata\megamedia\megakey\msadm.dll
O10 -Unknown file in Winsock LSP: c:\programdata\megamedia\megakey\msadm.dll
O10 - Unknown file in Winsock LSP: c:\programdata\megamedia\megakey\msadm.dll
O10 - Unknown file in Winsock LSP: c:\programdata\megamedia\megakey\msadm.dll
O10 - Unknown file in Winsock LSP: c:\programdata\megamedia\megakey\msadm.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{81C374A0-7A9F-4FD7-BA45-2EB3BCC7DC10}: NameServer = 10.17.3.244 10.17.3.245
O17 - HKLM\System\CCS\Services\Tcpip\..\{8947BED2-2F81-4E9E-B433-D329B3A9664B}: NameServer = 180.131.144.144,180.131.145.145
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PDFProFiltSrv - Nuance Communications, Inc. - C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 -Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
O23 -Service: UDisk Monitor - Unknown owner - C:\Program Files\Smartfren Connex AC682 UI\bin\MonServiceUDisk.exe
O23 -Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 11527 bytes
FathurrahmanU - 19/02/2012 09:56 AM
#4484

thanks banget gan
kodenn - 19/02/2012 11:44 AM
#4485

Spoiler for combo fix log 1
ComboFix 12-02-17.02 - mituse 02/19/2012 11:01:44.1.4 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.4095.2688 [GMT 7:00]
Running from: c:\users\mituse\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *Enabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
SP: Kaspersky Anti-Virus *Enabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\CFLog
c:\program files\Dealio Toolbar
c:\program files\Dealio Toolbar\FF\chrome.manifest
c:\program files\Dealio Toolbar\FF\chrome\content\chevron.js
c:\program files\Dealio Toolbar\FF\chrome\content\chevron.xul
c:\program files\Dealio Toolbar\FF\chrome\content\JSWidget.js
c:\program files\Dealio Toolbar\FF\chrome\content\login.js
c:\program files\Dealio Toolbar\FF\chrome\content\login.xul
c:\program files\Dealio Toolbar\FF\chrome\content\parser.js
c:\program files\Dealio Toolbar\FF\chrome\content\RadioWidget.js
c:\program files\Dealio Toolbar\FF\chrome\content\RadioWidget.xul
c:\program files\Dealio Toolbar\FF\chrome\content\RssTickerWidget.js
c:\program files\Dealio Toolbar\FF\chrome\content\searchbox.js
c:\program files\Dealio Toolbar\FF\chrome\content\searchbox.xul
c:\program files\Dealio Toolbar\FF\chrome\content\utils.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgichevron.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgicomm.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgihandling.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgilisteners.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgitoolbarplugin.js
c:\program files\Dealio Toolbar\FF\chrome\content\widgitoolbarplugin.xul
c:\program files\Dealio Toolbar\FF\chrome\content\widgiui.js
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\searchbox.dtd
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.dtd
c:\program files\Dealio Toolbar\FF\chrome\locale\EN-US\widgitoolbarplugin.properties
c:\program files\Dealio Toolbar\FF\chrome\skin\amazon.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\apple.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\barnes.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\bestbuy.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\chevron.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\dealio_logo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\ebay.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\facebook.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\googleplus.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\icon_settings.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\macys.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\newegg.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\overstock.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\radio-close.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\radio-minimize.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\radiobeta.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-button-hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-button.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-chevron-hover.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-chevron.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-wmrk-baidu.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-wmrk-yahoo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search-wmrk-yandex.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_amazon.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_baidu.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_dealio.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_ebay.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_yahoo.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\search_yandex.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\searchbox.css
c:\program files\Dealio Toolbar\FF\chrome\skin\splitter.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\target.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\twitter.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\walmart.gif
c:\program files\Dealio Toolbar\FF\chrome\skin\widgitoolbarplugin.css
c:\program files\Dealio Toolbar\FF\install.rdf
c:\program files\Dealio Toolbar\IE\4.9\config.ini
c:\program files\Dealio Toolbar\IE\4.9\dealioToolbarIE.dll
c:\program files\Dealio Toolbar\Res\amazon.gif
c:\program files\Dealio Toolbar\Res\apple.gif
c:\program files\Dealio Toolbar\Res\barnes.gif
c:\program files\Dealio Toolbar\Res\bestbuy.gif
c:\program files\Dealio Toolbar\Res\dealio_logo.gif
c:\program files\Dealio Toolbar\Res\dealio_logo_hover.gif
c:\program files\Dealio Toolbar\Res\ebay.gif
c:\program files\Dealio Toolbar\Res\facebook.gif
c:\program files\Dealio Toolbar\Res\googleplus.gif
c:\program files\Dealio Toolbar\Res\icon_settings.gif
c:\program files\Dealio Toolbar\Res\Lang\res1031.ini
c:\program files\Dealio Toolbar\Res\Lang\res1033.ini
c:\program files\Dealio Toolbar\Res\Lang\res1034.ini
c:\program files\Dealio Toolbar\Res\Lang\res1036.ini
c:\program files\Dealio Toolbar\Res\Lang\res1040.ini
c:\program files\Dealio Toolbar\Res\macys.gif
c:\program files\Dealio Toolbar\Res\newegg.gif
c:\program files\Dealio Toolbar\Res\overstock.gif
c:\program files\Dealio Toolbar\Res\radio-close.gif
c:\program files\Dealio Toolbar\Res\radio-minimize.gif
c:\program files\Dealio Toolbar\Res\radiobeta.gif
c:\program files\Dealio Toolbar\Res\search-button-hover.gif
c:\program files\Dealio Toolbar\Res\search-button.gif
c:\program files\Dealio Toolbar\Res\search-chevron-hover.gif
c:\program files\Dealio Toolbar\Res\search-chevron.gif
c:\program files\Dealio Toolbar\Res\search_amazon.gif
c:\program files\Dealio Toolbar\Res\search_baidu.gif
c:\program files\Dealio Toolbar\Res\search_dealio.gif
c:\program files\Dealio Toolbar\Res\search_ebay.gif
c:\program files\Dealio Toolbar\Res\search_yahoo.gif
c:\program files\Dealio Toolbar\Res\search_yandex.gif
c:\program files\Dealio Toolbar\Res\target.gif
c:\program files\Dealio Toolbar\Res\twitter.gif
c:\program files\Dealio Toolbar\Res\walmart.gif
c:\program files\Dealio Toolbar\Res\widgets.xml
c:\program files\Dealio Toolbar\WidgiHelper.exe
c:\windows\system32\loader.exe
c:\windows\system32\muzapp.exe
c:\windows\system32\themeservice.dll.tmp
c:\windows\system32\themeui.dll.tmp
c:\windows\system32\uxtheme.dll.tmp
.
.
((((((((((((((((((((((((( Files Created from 2012-01-19 to 2012-02-19 )))))))))))))))))))))))))))))))
kodenn - 19/02/2012 11:48 AM
#4486

Spoiler for combofix log 2
.
.
2012-02-19 04:16 . 2012-02-19 04:17 -------- d-----w- c:\users\mituse\AppData\Local\temp
2012-02-19 04:16 . 2012-02-19 04:16 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-18 11:14 . 2012-02-18 11:14 -------- d-----w- c:\users\mituse\AppData\Local\Apple
2012-02-16 13:53 . 2012-02-16 13:53 -------- d-----w- c:\users\mituse\AppData\Local\Norman Malware Cleaner
2012-02-09 13:45 . 2012-02-16 08:01 -------- d-----w- c:\program files\MyDefrag v4.3.1
2012-02-09 13:45 . 2010-05-21 05:11 475648 ----a-w- c:\windows\system32\MyDefragScreenSaver_v4.3.1.scr
2012-02-09 13:45 . 2010-05-21 05:11 1061888 ----a-w- c:\windows\system32\MyDefragScreenSaver_v4.3.1.exe
2012-02-09 13:42 . 2012-02-09 13:42 -------- d-----w- c:\users\mituse\AppData\Roaming\Malwarebytes
2012-02-09 13:41 . 2012-02-09 13:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-02-09 13:41 . 2012-02-09 13:41 -------- d-----w- c:\programdata\Malwarebytes
2012-02-09 13:41 . 2011-12-10 08:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-09 13:28 . 2012-02-09 13:28 -------- d-----w- c:\program files\CCleaner
2012-02-09 13:08 . 2012-02-09 13:08 -------- d-----w- c:\users\mituse\AppData\Roaming\HD Tune Pro
2012-02-09 13:08 . 2012-02-09 13:08 -------- d-----w- c:\program files\HD Tune Pro
2012-02-09 13:06 . 2012-02-09 13:31 -------- dc----w- c:\users\mituse\AppData\Local\MigWiz
2012-02-09 12:22 . 2012-02-09 12:22 -------- d-----w- c:\users\mituse\AppData\Roaming\Smadav
2012-02-09 12:22 . 2012-02-09 12:22 -------- d-----w- c:\program files\Smadav
2012-02-09 12:21 . 2012-02-09 12:21 -------- d-----w- C:\[Smad-Cage]
2012-01-25 17:41 . 2012-01-30 10:23 -------- d-----w- c:\users\mituse\AppData\Local\Samsung
2012-01-25 17:41 . 2012-01-26 07:58 -------- d-----w- c:\users\mituse\AppData\Roaming\Samsung
2012-01-25 17:39 . 2011-12-23 13:58 4659712 ----a-w- c:\windows\system32\Redemption.dll
2012-01-25 17:38 . 2012-01-25 17:38 -------- d-----w- c:\program files\MarkAny
2012-01-25 17:38 . 2012-01-30 10:25 -------- d-----w- c:\program files\Samsung
2012-01-25 17:38 . 2012-01-30 10:23 -------- d-----w- c:\programdata\Samsung
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-26 07:33 . 2011-08-23 16:19 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-23 13:58 . 2011-12-23 13:58 974848 ----a-w- c:\windows\system32\cis-2.4.dll
2011-12-23 13:58 . 2011-12-23 13:58 81920 ----a-w- c:\windows\system32\issacapi_bs-2.3.dll
2011-12-23 13:58 . 2011-12-23 13:58 65536 ----a-w- c:\windows\system32\issacapi_pe-2.3.dll
2011-12-23 13:58 . 2011-12-23 13:58 57344 ----a-w- c:\windows\system32\MTXSYNCICON.dll
2011-12-23 13:58 . 2011-12-23 13:58 57344 ----a-w- c:\windows\system32\MK_Lyric.dll
2011-12-23 13:58 . 2011-12-23 13:58 57344 ----a-w- c:\windows\system32\issacapi_se-2.3.dll
2011-12-23 13:58 . 2011-12-23 13:58 569344 ----a-w- c:\windows\system32\muzdecode.ax
2011-12-23 13:58 . 2011-12-23 13:58 491520 ----a-w- c:\windows\system32\muzapp.dll
2011-12-23 13:58 . 2011-12-23 13:58 49152 ----a-w- c:\windows\system32\MaJGUILib.dll
2011-12-23 13:58 . 2011-12-23 13:58 45056 ----a-w- c:\windows\system32\MaXMLProto.dll
2011-12-23 13:58 . 2011-12-23 13:58 45056 ----a-w- c:\windows\system32\MACXMLProto.dll
2011-12-23 13:58 . 2011-12-23 13:58 40960 ----a-w- c:\windows\system32\MTTELECHIP.dll
2011-12-23 13:58 . 2011-12-23 13:58 40960 ----a-w- c:\windows\system32\MAMACExtract.dll
2011-12-23 13:58 . 2011-12-23 13:58 352256 ----a-w- c:\windows\system32\MSLUR71.dll
2011-12-23 13:58 . 2011-12-23 13:58 258048 ----a-w- c:\windows\system32\muzoggsp.ax
2011-12-23 13:58 . 2011-12-23 13:58 245760 ----a-w- c:\windows\system32\MSCLib.dll
2011-12-23 13:58 . 2011-12-23 13:58 24576 ----a-w- c:\windows\system32\MASetupCleaner.exe
2011-12-23 13:58 . 2011-12-23 13:58 200704 ----a-w- c:\windows\system32\muzwmts.dll
2011-12-23 13:58 . 2011-12-23 13:58 155648 ----a-w- c:\windows\system32\MSFLib.dll
2011-12-23 13:58 . 2011-12-23 13:58 143360 ----a-w- c:\windows\system32\3DAudio.ax
2011-12-23 13:58 . 2011-12-23 13:58 135168 ----a-w- c:\windows\system32\muzaf1.dll
2011-12-23 13:58 . 2011-12-23 13:58 131072 ----a-w- c:\windows\system32\muzmpgsp.ax
2011-12-23 13:58 . 2011-12-23 13:58 122880 ----a-w- c:\windows\system32\muzeffect.ax
2011-12-23 13:58 . 2011-12-23 13:58 118784 ----a-w- c:\windows\system32\MaDRM.dll
2011-12-23 13:58 . 2011-12-23 13:58 110592 ----a-w- c:\windows\system32\muzmp4sp.ax
2011-09-13 16:01 . 2011-08-23 15:28 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-10-13 . C468ADABA2040F6585FE04EA4C81984A . 543232 . . [6.1.7600.16385] . . c:\windows\System32\termsrv.dll
[-] 2009-10-13 . C468ADABA2040F6585FE04EA4C81984A . 543232 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.1.7600.16385_none_8 e7597ebb597acd3\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\progra~1\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll" [2011-03-16 214840]
"{37483b40-c254-4a72-bda4-22ee90182c1e}"= "c:\program files\NCH_EN\prxtbNCH_.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_CLASSES_ROOT\clsid\{37483b40-c254-4a72-bda4-22ee90182c1e}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{37483b40-c254-4a72-bda4-22ee90182c1e}]
2011-05-09 08:49 176936 ----a-w- c:\program files\NCH_EN\prxtbNCH_.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{37483b40-c254-4a72-bda4-22ee90182c1e}"= "c:\program files\NCH_EN\prxtbNCH_.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{37483b40-c254-4a72-bda4-22ee90182c1e}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{37483B40-C254-4A72-BDA4-22EE90182C1E}"= "c:\program files\NCH_EN\prxtbNCH_.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{37483b40-c254-4a72-bda4-22ee90182c1e}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2011-08-23 352976]
"BCU"="c:\program files\DeviceVM\Browser Configuration Utility\BCU.exe" [2010-03-05 411864]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
"IObit Malware Fighter"="c:\program files\IObit\IObit Malware Fighter\IMF.exe" [2011-07-20 4393816]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
kodenn - 19/02/2012 11:50 AM
#4487

Spoiler for combofix log 3
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SM?RT-Protection]
c:\program files\Smadav\SM?RTP.exe [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 4]
2011-08-09 09:56 417112 ----a-w- c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2011-11-01 16:25 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCU]
2010-03-05 03:15 411864 ----a-w- c:\program files\DeviceVM\Browser Configuration Utility\BCU.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bing Bar]
2010-04-27 09:39 243544 ----a-w- c:\program files\MSN Toolbar\Platform\5.0.1449.0\mswinext.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-08-23 10:51 136176 ----atw- c:\users\mituse\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 17:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2010-03-12 06:08 49208 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-12-07 18:36 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2011-08-21 18:18 6276408 ----a-w- c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Default Manager]
2009-11-11 10:43 288088 ----a-w- c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-04-16 15:12 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 11:36 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
2011-02-18 04:47 79192 ----a-w- c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2010-11-19 10:15 9874024 ------w- c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
2009-02-23 13:05 111856 ----a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 06:06 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2011-11-02 03:49 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
2009-02-23 13:05 111856 ----a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-11-02 136176]
R3 apf001;apf001;c:\game\SoftnyxGame\GunboundIDS\apf001.sys [2011-09-08 10872]
R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [x]
R3 EagleXNt;EagleXNt;c:\windows\system32\drivers\EagleXNt.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-11-02 136176]
R3 RTTEAMPT;Realtek Teaming Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtTeam60.sys [2010-01-14 40736]
R3 RTVLANPT;Realtek Vlan Protocol Driver (NDIS 6.2);c:\windows\system32\DRIVERS\RtVlan60.sys [2010-01-14 25376]
R3 TEAM;Realtek Virtual Miniport Driver for Teaming (NDIS 6.2);c:\windows\system32\DRIVERS\RtTeam60.sys [2010-01-14 40736]
R3 VLAN;Realtek Virtual Miniport Driver for VLAN (NDIS 6.2);c:\windows\system32\DRIVERS\RtVLAN60.sys [2010-01-14 25376]
R3 XDva386;XDva386;c:\windows\system32\XDva386.sys [x]
S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys [2011-02-23 16184]
S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2010-06-09 11352]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2010-04-22 22104]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [2011-08-09 328536]
S2 asHmComSvc;ASUS HM Com Service;c:\program files\ASUS\AAHM\1.00.14\aaHMSvc.exe [2010-12-02 915584]
S2 BCUService;Browser Configuration Utility Service;c:\program files\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-03-05 235752]
S2 CDMA Device Service;CDMA Device Service;c:\program files\Samsung\USB Drivers\26_VIA_driver2\x86\VIAService.exe [2011-08-02 63488]
S2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [2011-07-20 820568]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360]
S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\DRIVERS\RtNdPt60.sys [2010-01-14 33056]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-04-03 240232]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\DRIVERS\asmthub3.sys [2011-02-24 100328]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\DRIVERS\asmtxhci.sys [2011-02-24 308200]
S3 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys [2011-07-11 18768]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 19984]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-10 20464]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-01-28 68200]
S3 RegFilter;RegFilter;c:\program files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys [2011-03-22 30600]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-02-16 340072]
S3 UrlFilter;UrlFilter;c:\program files\IObit\IObit Malware Fighter\drivers\win7_x86\UrlFilter.sys [2011-03-22 19280]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-11-02 03:49]
.
2012-02-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-11-02 03:49]
.
2012-02-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2135959015-2625701216-3354975055-1000Core.job
- c:\users\mituse\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-23 10:51]
.
2012-02-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2135959015-2625701216-3354975055-1000UA.job
- c:\users\mituse\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-23 10:51]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2801948
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 202.73.99.2 61.247.0.4 202.73.99.4
FF - ProfilePath - c:\users\mituse\AppData\Roaming\Mozilla\Firefox\Profiles\6xf931qe.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2801948&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2801948&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://id.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=685749&p=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-SearchSettings - c:\program files\Common Files\Spigot\Search Settings\SearchSettings.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-02-19 11:22:34
ComboFix-quarantined-files.txt 2012-02-19 04:22
.
Pre-Run: 144,855,355,392 bytes free
Post-Run: 144,626,806,784 bytes free
.
- - End Of File - - 2F61EFE7C455FD940B92608C7147202E


tolong di cek yah gan ,
SLugin - 19/02/2012 12:57 PM
#4488

sorry newbie nanya lagi

1. komputer gak bisa buka virustotal.com katanya kena virus?virus apa yah?

2. ram ane 2gb,trus suka lemot bngt...pas liat di task manager,memory usage bisa sampe 3-4gb..itu katanya kena virus juga yah? virus apa yah?

dan cara menanggulanginya bagaimana yah?

yang menolong sekali,ane cendolin deh..putus asa nih
aderyandhono - 19/02/2012 02:02 PM
#4489

Quote:
Original Posted By L10nelmess1
Langkah pertama install Anti Virus yang anda percaya dan sudah terupdate lalu lakukan scan sampai selesai.

* Kemudian matikan startup script lewat msconfig atau bisa menggunkan tools yang lain. Lalu hilangkan tanda centang yang anda anggap mencurigakan.

* Pastikan tidak ada file dekstop.ini atau autorun.inf di setiap drive. Bila ada hapus dengan cara manual.

* Klik star >- Run >- ketik Regedit lalu cari HKEY_CURRENT_USERSoftwareMicrosoftSearch AssistantACMru5603, bila sudah ketemu hapus semua yang ada tanda merahnya yang meliputi serviks.sys, serviks.sys(system32), df5srvc.bfe, music, autorun.inf, lirik.rtf & Aplikasi,

* Untuk menghilangkan shortcut Serviks yang berada di Desktop / Wallpaper caranya hampir sama denga versi pendahulunya yaitu Virus Yuyun_Cantix Klik kanan pada layar desktop yang kosong >- klik properties >- pilih Desktop >- Customize Desktop >- klik Clean Desktop Now >- next >- Hilangkan seluruh centangan yang ada kecuali Serviks lalu Next >- Finish.

* Selanjutnya tugas anda hapus “Unused Desktop Shortcuts” di desktop secara manual.


thanks gan work:thumbup
wendiaulia - 19/02/2012 03:07 PM
#4490

gan ada yang krack gak?? maklum miskin maunya yg gratisan aje:sorry
crystal.elegant - 19/02/2012 03:30 PM
#4491

Avast menduduki peringkat teratas dan terbaik yah...
tapi saya lebih menyukai symantec, karena avast bisa delete system registry seenaknya, jika ada virus di registry. kalau symantec masih bisa clean...
ini pendapat aja yah...
nupekong - 19/02/2012 03:38 PM
#4492

kayaknya bakal pake avast nih

tapi males inal iul lg
L10nelmess1 - 19/02/2012 04:21 PM
#4493

Quote:
Original Posted By SLugin
sorry newbie nanya lagi

1. komputer gak bisa buka virustotal.com katanya kena virus?virus apa yah?

2. ram ane 2gb,trus suka lemot bngt...pas liat di task manager,memory usage bisa sampe 3-4gb..itu katanya kena virus juga yah? virus apa yah?

dan cara menanggulanginya bagaimana yah?

yang menolong sekali,ane cendolin deh..putus asa nih


paike virus apa di pc ?
SLugin - 19/02/2012 04:38 PM
#4494

Quote:
Original Posted By L10nelmess1


paike virus apa di pc ?


nothing gan sekarang...dulu pernah pake smadav,pcmav doang..
L10nelmess1 - 19/02/2012 05:39 PM
#4495

Quote:
Original Posted By SLugin


nothing gan sekarang...dulu pernah pake smadav,pcmav doang..


biasaan untuk di kimpoi sma av luar gan
mungkin agan hrus make kaspersky 2012
SLugin - 19/02/2012 05:50 PM
#4496

Quote:
Original Posted By L10nelmess1


biasaan untuk di kimpoi sma av luar gan
mungkin agan hrus make kaspersky 2012


kapersky itu recommended yah?
D21Dorifto - 19/02/2012 06:04 PM
#4497

gan tanya dong kok avira ane g bisa di buka yak

Spoiler for SS


Uploaded with ImageShack


trus kok pas ane pke music player (winamp, KM Player, GOM dll) sering ngadat" yak suaranya, apa itu gara" virus? trus gmana cara perbaikinnya?
L10nelmess1 - 19/02/2012 06:26 PM
#4498

Quote:
Original Posted By SLugin


kapersky itu recommended yah?


jelas dy juara antivirus terbaik 2011

Quote:
Original Posted By D21Dorifto
gan tanya dong kok avira ane g bisa di buka yak

Spoiler for SS


Uploaded with ImageShack


trus kok pas ane pke music player (winamp, KM Player, GOM dll) sering ngadat" yak suaranya, apa itu gara" virus? trus gmana cara perbaikinnya?


gmabr tidak jelas gan
D21Dorifto - 19/02/2012 06:46 PM
#4499

Quote:
Original Posted By L10nelmess1
jelas dy juara antivirus terbaik 2011
gmabr tidak jelas gan


nih gan ane reupload
Spoiler for SS




klo yang soal suaranya agan tau g knapa?
gielang808 - 19/02/2012 08:09 PM
#4500

mau tanya nih dokter b
virus yang khusus nyerang game apa ya? dan CPU usage nya kemakan jadi gede. apakah ini worm atau ramnit?
Page 225 of 336 | ‹ First  < 220 221 222 223 224 225 226 227 228 229 230 >  Last ›
Home > LOEKELOE > COMPUTER STUFF > Virus Antivirus Virus Antivirus Virus Antivirus Virus Antivirus Virus Antivirus Virus