my computers infected this virus today… when I download a video files from internet…
I scanned it with avast but won’t work, when I was take action delete and quarantine…
when I scanned with avast antivir, 3 files are infected, 2 files can heal, and 1 files is hard to remove…
but since my computer infected, I can starting windows normally, I played the game normally, and no error found in windows,
ok I will send report, please help me to resolve this master, thx in advance
AdwCleaner v2.100 - Logfile created 12/13/2012 at 14:26:41
Updated 09/12/2012 by Xplode
Operating system : Windows 7 Professional (32 bits)
User : wahid - WAHID-PC
Boot Mode : Normal
Running from : C:\Users\wahid\Downloads\Programs\adwcleaner.exe
Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
File Deleted : C:\user.js
File Deleted : C:\Users\wahid\AppData\Roaming\Mozilla\Firefox\Profiles\ovi8uwaz.default\BrowserMngr_extensions.sqlite
File Deleted : C:\Users\wahid\AppData\Roaming\Mozilla\Firefox\Profiles\ovi8uwaz.default\browsermngr_prefs.js
File Deleted : C:\Users\wahid\AppData\Roaming\Mozilla\Firefox\Profiles\ovi8uwaz.default\searchplugins\BabylonMngr.xml
Folder Deleted : C:\Program Files\DAEMON Tools Toolbar
Folder Deleted : C:\Program Files\yourfiledownloader
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\Users\wahid\AppData\Roaming\Babylon
Folder Deleted : C:\Users\wahid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Manager
Folder Deleted : C:\Users\wahid\AppData\Roaming\Mozilla\Firefox\Profiles\ovi8uwaz.default\extensions\DTToolbar@toolbarnet.com
Folder Deleted : C:\Users\wahid\AppData\Roaming\yourfiledownloader
***** [Registry] *****
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{2EECD738-5844-4A99-B4B6-146BF802613B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\BabylonToolbar
Key Deleted : HKLM\Software\BrowserMngr
Key Deleted : HKLM\SOFTWARE\Classes\AppID{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\BHO.DLL
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{32099AAC-C132-4136-9E9A-4E364A424E17}
Key Deleted : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj
Key Deleted : HKLM\SOFTWARE\Classes\DTToolbar.ToolBandObj.1
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\S
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{96BD48DD-741B-41AE-AC4A-AFF96BA00F7E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{2EECD738-5844-4A99-B4B6-146BF802613B}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Main [BrowserMngr Start Page]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [BrowserMngrDefaultScope]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{32099AAC-C132-4136-9E9A-4E364A424E17}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]
***** [Internet Browsers] *****
-\ Internet Explorer v8.0.7600.16385
Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=112555&tt=120912_ccp_3912_8&babsrc=NT_ss&mntrId=40311335000000000000000000000000 → hxxp://www.google.com
-\ Mozilla Firefox v15.0.1 (en-US)
Profile name : default
File : C:\Users\wahid\AppData\Roaming\Mozilla\Firefox\Profiles\ovi8uwaz.default\prefs.js
C:\Users\wahid\AppData\Roaming\Mozilla\Firefox\Profiles\ovi8uwaz.default\user.js … Deleted !
Deleted : user_pref(“avg.install.userHPSettings”, "hxxp://search.babylon.com/?affID=112555&tt=120912_ccp_3912_[…]
Deleted : user_pref(“avg.install.userSPSettings”, “Search the web (Babylon)”);
Deleted : user_pref(“browser.newtab.url”, "hxxp://search.babylon.com/?affID=112555&tt=120912_ccp_3912_8&babsrc[…]
Deleted : user_pref(“browser.search.defaultenginename”, “Search the web (Babylon)”);
Deleted : user_pref(“browser.search.order.1”, “Search the web (Babylon)”);
Deleted : user_pref(“extensions.BabylonToolbar.admin”, false);
Deleted : user_pref(“extensions.BabylonToolbar.aflt”, “babsst”);
Deleted : user_pref(“extensions.BabylonToolbar.appId”, “{BDB69379-802F-4eaf-B541-F8DE92DD98DB}”);
Deleted : user_pref(“extensions.BabylonToolbar.autoRvrt”, “false”);
Deleted : user_pref(“extensions.BabylonToolbar.babExt”, “”);
Deleted : user_pref(“extensions.BabylonToolbar.babTrack”, “affID=112555&tt=120912_ccp_3912_8”);
Deleted : user_pref(“extensions.BabylonToolbar.bbDpng”, “26”);
Deleted : user_pref(“extensions.BabylonToolbar.cntry”, “ID”);
Deleted : user_pref(“extensions.BabylonToolbar.dfltLng”, “en”);
Deleted : user_pref(“extensions.BabylonToolbar.envrmnt”, “production”);
Deleted : user_pref(“extensions.BabylonToolbar.excTlbr”, false);
Deleted : user_pref(“extensions.BabylonToolbar.hdrMd5”, “44564C0A42758D4EFEE45D3441360117”);
Deleted : user_pref(“extensions.BabylonToolbar.hmpg”, false);
Deleted : user_pref(“extensions.BabylonToolbar.id”, “40311335000000000000000000000000”);
Deleted : user_pref(“extensions.BabylonToolbar.instlDay”, “15608”);
Deleted : user_pref(“extensions.BabylonToolbar.instlRef”, “sst”);
Deleted : user_pref(“extensions.BabylonToolbar.lastVrsnTs”, “1.6.9.1211:20:27”);
Deleted : user_pref(“extensions.BabylonToolbar.mntrvrsn”, “1.3.1”);
Deleted : user_pref(“extensions.BabylonToolbar.newTab”, false);
Deleted : user_pref(“extensions.BabylonToolbar.pnu_base”, "{"newVrsn":"28","lastVrsn":"28","vrsnLoad[…]
Deleted : user_pref(“extensions.BabylonToolbar.prdct”, “BabylonToolbar”);
Deleted : user_pref(“extensions.BabylonToolbar.prtnrId”, “babylon”);
Deleted : user_pref(“extensions.BabylonToolbar.sg”, “czb”);
Deleted : user_pref(“extensions.BabylonToolbar.smplGrp”, “czb”);
Deleted : user_pref(“extensions.BabylonToolbar.srcExt”, “ss”);
Deleted : user_pref(“extensions.BabylonToolbar.tlbrId”, “base”);
Deleted : user_pref(“extensions.BabylonToolbar.tlbrSrchUrl”, "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=[…]
Deleted : user_pref(“extensions.BabylonToolbar.vrsn”, “1.6.9.12”);
Deleted : user_pref(“extensions.BabylonToolbar.vrsnTs”, “1.6.9.1211:20:27”);
Deleted : user_pref(“extensions.BabylonToolbar.vrsni”, “1.6.9.12”);
Deleted : user_pref(“extensions.BabylonToolbar_i.babExt”, “”);
Deleted : user_pref(“extensions.BabylonToolbar_i.babTrack”, “affID=112555&tt=120912_ccp_3912_8”);
Deleted : user_pref(“extensions.BabylonToolbar_i.newTab”, false);
Deleted : user_pref(“extensions.BabylonToolbar_i.smplGrp”, “none”);
Deleted : user_pref(“extensions.BabylonToolbar_i.srcExt”, “ss”);
Deleted : user_pref(“extensions.BabylonToolbar_i.vrsnTs”, “1.6.9.1211:20:27”);
Deleted : user_pref(“sweetim.toolbar.previous.browser.search.defaultenginename”, “Search the web (Babylon)”);
Deleted : user_pref(“sweetim.toolbar.urls.homepage”, "hxxp://search.babylon.com/?affID=112555&tt=120912_ccp_39[…]
-\ Google Chrome v23.0.1271.97
File : C:\Users\wahid\AppData\Local\Google\Chrome\User Data\Default\Preferences
Deleted [l.1265] : homepage = "hxxp://search.babylon.com/?affID=112555&tt=120912_ccp_3912_8&babsrc=HP_ss&mntrId=403[…]
AdwCleaner[R1].txt - [8384 octets] - [13/12/2012 14:25:42]
AdwCleaner[S1].txt - [7944 octets] - [13/12/2012 14:26:41]
########## EOF - C:\AdwCleaner[S1].txt - [8004 octets] ##########
Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org
Database version: v2012.12.13.02
Windows 7 x86 NTFS
Internet Explorer 8.0.7600.16385
wahid :: WAHID-PC [administrator]
12/13/2012 1:59:48 PM
mbam-log-2012-12-13 (13-59-48).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 237733
Time elapsed: 4 minute(s), 6 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)