Thank you for the log. I'm impressed as to how well you succeeded to infect your computer.
You don't have any antivirus software or programme ! You are lucky to have survived for this long without one.
Your computer is indeed very infected by
2. a rogue Trojan Horse
3. a rootkit,
4. a USB infection
5. a worm.
All of the above infection originate from the downloads you have made from peer to peer applications: u.torrent and Go for files.
All of the above infections can be removed but to insure that your system stay stable, we must proceed step by step. From what I gather, you are in Singapore, we are not in the same time zone, hence it may take two, perhaps three days before we solve the issue.
Are you willing to stick with me through the procedures ? Let me know and we shall begin.
The certificate error you got from GMail is due to the rootkit which has changed the time and date of your computer. Try to adjust it, but it may get changed again.
When you answer me, I must know if your Windows XP is genuine or if it's a copy.
1. Where any items found?
2. Did you click "continue" or "skip"?
3. Why do you have oracle in your system ?
Please, delete the previous ZHPDiag logs just like I previously explained, produce a new one and upload on speedyshare.
Thank you again for your patience. As you must be aware now, your computer was badly infected by severe viruses and it take time to clean without having to reformat and lose all of your data and applications.
I have ran as per the steps given by you and below is the link. Because of this issue internet is not opening in my laptop. if try to open gmail it is displaying message as 'The server's security certificate is revoked!'
2. You should now see a window that shows all of your desktop icons, including the rkill.com program.
3. Double-click on the rkill.com in order to automatically attempt to stop any processes associated with the Rogue programs. Please be patient while the program looks for various malware programs and ends them. When it has finished, the black window will automatically close and you can continue with the next step.
If you get a message that rkill is an infection, do not be concerned. This message is just a fake warning given by the Horse when it terminates programs that may potentially remove it. If you run into these infections warnings that close Rkill, a trick is to leave the warning on the screen and then run Rkill again. By not closing the warning, this typically will allow you to bypass the malware trying to protect itself so that rkill can terminate the processes . So, please try running Rkill until malware is no longer running.
As a matter of a fact, if you get messages, it is a sign that the virus is agonizing with excrutiating pain, so you can just grin while it is suffering!:)))
Please, DO NOT REBOOT your computer or the processes will come back to haunt you!
(click on the download @ bleeping computer button)
2.Close all open Windows including this one.
Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix.
3. Double click on the ComboFix icon.
Windows is issuing this prompt because ComboFix does not have a digital signature. This is perfectly normal and safe and you can click on the Run button to continue.
4. Accept the disclaimer and the recovery
5.You should now press the Yes button to continue. If at any time during the Recovery Console installation you receive a message stating that it failed to install, please allow ComboFix to continue with the scan of your computer.
ComboFix will disconnect your computer from the Internet, so do not be surprised or concerned if you receive any warnings stating that you are no longer on the Internet. When ComboFix has finished it will automatically restore your Internet connection.
While the program is scanning your computer, it will change your clock format, so do not be concerned when you see this happen. When ComboFix is finished it will restore your clock settings to their previous settings.
If you see your Windows desktop disappear, do not worry. This is normal and ComboFix will restore your desktop before it is finished. Eventually you will see a new screen that states the program is almost finished and telling you the programs log file, or report, will be located at C:\ComboFix.txt.
During the process, please do not mouse click nor must you tap on the keyboard. Let the tool run.
Rapport de ZHPFix 2013.6.12.3 par Nicolas Coolman, Update du 12/06/2013
Fichier d'export Registre :
Run by Administrator at 6/21/2013 12:09:52 PM
High Elevated Privileges : OK
Windows XP Professional Service Pack 2 (Build 2600)