View Single Post
Old 07-04-2007, 11:59 AM   #6 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,480
OS: N/A


Re: Please help me... Comp infected

Quote:
ComboFix 07-06-18.2 - C:\Documents and Settings\Owner\Desktop\misc\ComboFix.exe
"Owner" - 2007-07-03 19:12:33 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\Owner\Desktop\misc\ComboFix-Do.txt
I have just noticed that you're using an old copy of ComboFix. Why is this so? I specifically requested that you download it from http://download.bleepingcomputer.com...a/ComboFix.exe

Please delete that copy & grab the new one.


----------------


Open notepad and copy/paste the text in the quotebox below into it:

Code:
File::
C:\Temp\aZ001.exe
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\java.jar-8fba448-7160b407.zip
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\javainstaller.jar-31f00108-504ba244.zip
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\javainstaller.jar-31f09a69-6670cbe8.zip
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\javainstaller.jar-4514e5ea-69e89e9c.zip
C:\Documents and Settings\Owner\.jpi_cache\jar\1.0\loaderadv698.jar-b667ebb-59488282.zip
C:\Program Files\NetPumper\ZM\minime.exe
C:\Program Files\Outlook Express\w2.exe
C:\Temp\aZ001.exe
C:\WINDOWS\Down(0).exe
C:\WINDOWS\system32\cdees.exe
C:\WINDOWS\system32\Down(0).exe
C:\WINDOWS\system32\msCMTsrvc.exe
Folder::
C:\DOCUME~1\ALLUSE~1\APPLIC~1\SalesMonitor
C:\Temp\iee
C:\WINDOWS\system32\CO
C:\WINDOWS\system32\CG
C:\WINDOWS\system32\CG
Save this as ComboFix-Do.txt




Refering to the picture above, drag ComboFix-Do.txt into ComboFix.exe
Then post the resultant log
__________________

Question - what have you done for the community today?
sUBs is offline