I have downloaded
AdwCleaner & MalwareBytes and the scanning results are
given below.
For '
Security Check', both links given by you leads to the same site but
I couldn't download it
even after several trials.
Now also HDDefrag.exe is shown in my Task Manager when my computer is started and eats
majority of my CPU.
(1) AdwCleaner Scan Resut: # AdwCleaner v2.300 - Logfile created 05/07/2013 at 09:50:20
# Updated 28/04/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 2 (32 bits)
# User : Madhu Kumar - ABC-28872D74A25
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Madhu Kumar\desktop\adwcleaner.exe
# Option [Delete]
***** [Services] *****
***** [Files / Folders] *****
Deleted on reboot : C:\Documents and Settings\Madhu Kumar\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hiiickddnfnbflkhhfagaflkmpfjabjl
Deleted on reboot : C:\Documents and Settings\Madhu Kumar\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mcmfgmhakbcbniknmlacoelldfiohmnm
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Berowisse22save
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Browsie2suayve
Folder Deleted : C:\Documents and Settings\All Users\Application Data\InstallMate
Folder Deleted : C:\Documents and Settings\All Users\Application Data\SoftSafe
Folder Deleted : C:\Documents and Settings\Madhu Kumar\Local Settings\Application Data\PackageAware
***** [Registry] *****
Key Deleted : HKCU\Software\AppDataLow\SProtector
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10B12E7E-5011-02EF-C8F5-7AD09D424D7C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{380040F4-312B-F07E-C0BA-789502D563A5}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Key Deleted : HKLM\Software\SP Global
Key Deleted : HKLM\Software\SProtector
***** [Internet Browsers] *****
-\\ Internet Explorer v7.0.5730.13
[OK] Registry is clean.
-\\ Google Chrome v [Unable to get version]
File : C:\Documents and Settings\Madhu Kumar\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences
[OK] File is clean.
-\\ Opera v [Unable to get version]
File : C:\Documents and Settings\Madhu Kumar\Application Data\Opera\Opera\operaprefs.ini
[OK] File is clean.
*************************
AdwCleaner[S1].txt - [2487 octets] - [07/05/2013 09:50:20]
########## EOF - C:\AdwCleaner[S1].txt - [2547 octets] ##########
========================================================
(2) MalwareBytes Scan Result: Malwarebytes Anti-Malware (PRO) 1.75.0.1300
www.malwarebytes.orgDatabase version: v2013.05.09.04
Windows XP Service Pack 2 x86 NTFS
Internet Explorer 7.0.5730.13
Madhu Kumar :: ABC-28872D74A25 [administrator]
Protection: Enabled
5/10/2013 3:48:42 AM
MBAM-log-2013-05-10 (08-34-28).txt
Scan type: Full scan (C:\|D:\|E:\|F:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 283603
Time elapsed: 2 hour(s), 59 minute(s), 5 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 7
F:\System Volume Information\_restore{C29D0E16-2114-49CA-A226-02EEA1BAE97C}\RP86\A0023227.exe (Backdoor.Bot) -> No action taken.
F:\System Volume Information\_restore{C29D0E16-2114-49CA-A226-02EEA1BAE97C}\RP86\A0023228.exe (Backdoor.Bot) -> No action taken.
F:\System Volume Information\_restore{C29D0E16-2114-49CA-A226-02EEA1BAE97C}\RP86\A0023229.exe (Backdoor.Bot) -> No action taken.
F:\System Volume Information\_restore{C29D0E16-2114-49CA-A226-02EEA1BAE97C}\RP86\A0023230.exe (Backdoor.Bot) -> No action taken.
F:\System Volume Information\_restore{C29D0E16-2114-49CA-A226-02EEA1BAE97C}\RP86\A0023231.exe (Backdoor.Bot) -> No action taken.
F:\System Volume Information\_restore{C29D0E16-2114-49CA-A226-02EEA1BAE97C}\RP86\A0023232.exe (Backdoor.Bot) -> No action taken.
F:\System Volume Information\_restore{C29D0E16-2114-49CA-A226-02EEA1BAE97C}\RP86\A0023233.EXE (Backdoor.Bot) -> No action taken.
(end)