Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Trojan-spy.win32@mx


  • Please log in to reply

#1
Carlos Mex

Carlos Mex

    Member

  • Member
  • PipPip
  • 17 posts
Hi:

I need help because in my toolbar of windows appers an interrogation mark that changes to a not permission symbol (like the symbol of No Smoking), and its says that a i have a critical system error and when i push it opens a web page of a system named virus busrt that say me that i have win32.mt.rs sipyware and trojan-spy.win32@mx tha is infecting my sistem i've already try to remove wiht the steps that you have bur the probles continues i have mi log of hijack thi that i wil put in this message and i have also the report o ewido so i hope that somebody can help me because i don't know what else to do, i'm from mexico and i will appreciate help to solve the problem from anyone who knows thow to remove this, i live my email if somebody wants to conctact me directly: [email protected].

THanks for your help i will be weating for your help.

Good Day.


This is hijack log

Logfile of HijackThis v1.99.1
Scan saved at 11:33:37 a.m., on 30/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Archivos de programa\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Archivos de programa\ewido anti-spyware 4.0\ewido.exe
C:\Archivos de programa\TrojanHunter 4.6\THGuard.exe
C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe
C:\Archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE
C:\Archivos de programa\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\ewido anti-spyware 4.0\guard.exe
C:\Archivos de programa\Archivos comunes\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Archivos de programa\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\ARCHIV~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Archivos de programa\Trend Micro\PC-cillin 9\Tmntsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCPFW.exe
C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCCLIENT.EXE
C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCGUIDE.EXE
C:\Archivos de programa\Trend Micro\PC-cillin 9\POP3TRAP.EXE
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\HJT\Killer.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c.../search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.mx/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.c...h...DTP&M=L3027
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.prodigy.net.mx/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - Prodigy Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn1\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Archivos de programa\Yahoo!\Common\yiesrvcmx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Archivos de programa\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar2.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Archivos de programa\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Archivos de programa\Trend Micro\PC-cillin 9\Pop3trap.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Archivos de programa\Trend Micro\PC-cillin 9\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCClient.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [!ewido] "C:\Archivos de programa\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [THGuard] "C:\Archivos de programa\TrojanHunter 4.6\THGuard.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\ARCHIV~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [DW4] "C:\Archivos de programa\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Archivos de programa\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Búsqueda en Google - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebse...?p=ZNxmk904YYMX
O8 - Extra context menu item: &Traducir palabra inglesa - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Instantánea de caché de la página - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Páginas similares - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Páginas vinculadas - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmbacklinks.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\ARCHIV~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\ARCHIV~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\ARCHIV~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Yahoo! Servicios - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Archivos de programa\Yahoo!\Common\yiesrvcmx.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Archivos de programa\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Archivos de programa\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Archivos de programa\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1155344534609
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: hydrodictyon - {b166be07-30a4-4d38-b781-44528a630706} - C:\WINDOWS\system32\gqagksr.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Archivos de programa\ewido anti-spyware 4.0\guard.exe
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCPFW.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Archivos de programa\Archivos comunes\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\PC-cillin 9\Tmntsrv.exe



This is ewido report


---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 07:59:52 p.m. 29/09/2006

+ Scan result:



HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 -> Adware.Generic : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Configuración local\Temp\em452\HbTools.mlpX -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Security Plugin 2006 -> Adware.IntCodec : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.IntCodec : Cleaned with backup (quarantined).
:mozilla.12:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.119:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.13:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.14:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.15:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.162:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.16:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.17:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.19:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.20:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.21:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.229:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.22:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.237:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.23:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.272:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.84:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.128:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.129:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.130:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.131:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.132:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.133:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.24:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Aavalue : Cleaned with backup (quarantined).
:mozilla.40:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.41:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.55:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.56:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.92:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
:mozilla.93:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
:mozilla.81:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@com[1].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.430:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Epilot : Cleaned with backup (quarantined).
:mozilla.325:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.326:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.327:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.270:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.271:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.274:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.44:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.45:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.46:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.47:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.48:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos [email protected][2].txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.278:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.279:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.280:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.158:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Starware : Cleaned with backup (quarantined).
:mozilla.159:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Starware : Cleaned with backup (quarantined).
:mozilla.382:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Starware : Cleaned with backup (quarantined).
:mozilla.361:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.362:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.363:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.364:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.365:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.366:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.367:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.368:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.372:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.373:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.379:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.380:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Trafic : Cleaned with backup (quarantined).
:mozilla.381:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.312:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.313:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.314:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.315:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.316:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.35:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.36:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.37:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.38:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.39:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.487:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.488:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.489:C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\cookies.txt.old -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


::Report end


Thanks again
  • 0

Advertisements


#2
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Hi Carlos Mex and Welcome to GeekstoGo!


Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlog...processutil.htm
  • 0

#3
Carlos Mex

Carlos Mex

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Hi Monstercreate:

Thanks for your help i've already do what you tell me and here's the result

SmitFraudFix v2.103

Scan done at 15:14:23.28, 30/09/2006
Run from C:\Documents and Settings\Carlos Hernandez\Escritorio\SmitfraudFix
OS: Microsoft Windows XP [Versi˘n 5.1.2600] - Windows_NT
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\gqagksr.dll FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Carlos Hernandez


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Carlos Hernandez\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

C:\DOCUME~1\ALLUSE~1\MENINI~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\MENINI~1\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\CARLOS~1\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Archivos de programa

C:\Archivos de programa\VideosCodec\ FOUND !
C:\Archivos de programa\VirusBurster\ FOUND !
C:\Archivos de programa\X Password Generator\ FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Mi p gina de inicio actual"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{b166be07-30a4-4d38-b781-44528a630706}"="hydrodictyon"

[HKEY_CLASSES_ROOT\CLSID\{b166be07-30a4-4d38-b781-44528a630706}\InProcServer32]
@="C:\WINDOWS\system32\gqagksr.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{b166be07-30a4-4d38-b781-44528a630706}\InProcServer32]
@="C:\WINDOWS\system32\gqagksr.dll"



»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

Thanks Again
  • 0

#4
Carlos Mex

Carlos Mex

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Sorry i put Monstercreate and i already see that is Cretemonster
  • 0

#5
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Ill answer to most anything these days! :whistling:


Make sure Ewido is Updated with the latest definstions.


You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Next, please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.



Restart the Machine in Safe Mode and Scan with Ewido.

Clean all it finds and save the report.


Restart Normal and post the report from Ewido and C:\rapport.txt


Once those 2 are posted,Please download Combofix to your desktop.
http://download.blee...Bs/combofix.exe

Doubleclick combo.exe to launch the application.

Follow the prompts that will be displayed on the screen.

Don't click on the window while the fix is running, because that will cause your system to hang.

When finished, it should produce a log, combofix.txt

Please post that log in a seperate reply,please.
  • 0

#6
Carlos Mex

Carlos Mex

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Hi Cretemonster:

I've already do what you told me and here are the results of Smitfraud and Ewido. After sending this y will run the combofix and send it.

SmitFraudFix v2.103

Scan done at 19:30:33.06, 30/09/2006
Run from C:\Documents and Settings\Carlos Hernandez\Escritorio\SmitfraudFix
OS: Microsoft Windows XP [Versi˘n 5.1.2600] - Windows_NT
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{b166be07-30a4-4d38-b781-44528a630706}"="hydrodictyon"

[HKEY_CLASSES_ROOT\CLSID\{b166be07-30a4-4d38-b781-44528a630706}\InProcServer32]
@="C:\WINDOWS\system32\gqagksr.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{b166be07-30a4-4d38-b781-44528a630706}\InProcServer32]
@="C:\WINDOWS\system32\gqagksr.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri

C:\WINDOWS\system32\gqagksr.dll -> Hoax.Win32.Renos.gen.e
C:\WINDOWS\system32\gqagksr.dll -> Deleted


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\DOCUME~1\ALLUSE~1\MENINI~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\MENINI~1\Security Troubleshooting.url Deleted
C:\Archivos de programa\VideosCodec\ Deleted
C:\Archivos de programa\VirusBurster\ Deleted
C:\Archivos de programa\X Password Generator\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End


This is the ewido:


---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 09:02:19 p.m. 30/09/2006

+ Scan result:



C:\Documents and Settings\Carlos Hernandez\Cookies\carlos [email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos [email protected][1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos [email protected][1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos [email protected][1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos [email protected][2].txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos [email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).


::Report end

Thanks
  • 0

#7
Carlos Mex

Carlos Mex

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Hi again Cretemonster:

I have the results of th combofix here they are, i was looking at my toolbar and it apperas that the problem is gone because i don´t have the icon of the interrogation mark and no more messages of critical system error had appers.

Carlos Hernandez - 06-10-02 12:35:08.31 Service Pack 2
ComboFix 06.09.28 - Running from: "C:\Trj"

((((((((((((((((((((((((((((((( Files Created from 2006-09-02 to 2006-10-02 ))))))))))))))))))))))))))))))))))


2006-09-30 19:30 53,248 --a------ C:\WINDOWS\system32\Process.exe
2006-09-30 19:30 40,960 --a------ C:\WINDOWS\system32\swsc.exe
2006-09-30 19:30 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2006-09-30 19:30 135,168 --a------ C:\WINDOWS\system32\swreg.exe
2006-09-29 20:18 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2006-09-20 14:43 86,016 --a------ C:\WINDOWS\unvise32qt.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-02 10:01 -------- d-------- C:\Archivos de programa\ewido anti-spyware 4.0
2006-09-29 20:42 -------- d-------- C:\Documents and Settings\Carlos Hernandez\Datos de programa\TrojanHunter
2006-09-29 20:31 -------- d-------- C:\Archivos de programa\TrojanHunter 4.6
2006-09-29 20:18 -------- d-------- C:\Archivos de programa\Internet Explorer
2006-09-29 14:27 -------- d-------- C:\Archivos de programa\CleanUp!
2006-09-29 12:33 -------- d-------- C:\Documents and Settings\Carlos Hernandez\Datos de programa\Lavasoft
2006-09-29 12:32 -------- d-------- C:\Archivos de programa\Lavasoft
2006-09-29 12:14 -------- dr-h----- C:\Documents and Settings\Carlos Hernandez\Datos de programa\yahoo!
2006-09-29 11:29 -------- d-------- C:\Archivos de programa\Archivos comunes
2006-09-28 20:32 -------- d-------- C:\Archivos de programa\MalwareWipe.com
2006-09-28 20:12 -------- d-------- C:\Archivos de programa\Mozilla Firefox
2006-09-27 10:39 1051456 --a------ C:\WINDOWS\system32\drivers\VSAPINT.SYS
2006-09-27 10:38 31248 --a------ C:\WINDOWS\system32\drivers\tmpreflt.sys
2006-09-27 10:38 197648 --a------ C:\WINDOWS\system32\drivers\TmXPFlt.sys
2006-09-26 18:25 -------- d-------- C:\Archivos de programa\Citty Interactive
2006-09-20 14:44 -------- d-------- C:\Archivos de programa\QuickTime
2006-09-20 11:30 -------- d-------- C:\Archivos de programa\TVU Player
2006-09-20 10:06 -------- d---s---- C:\Documents and Settings\Carlos Hernandez\Datos de programa\Microsoft
2006-09-20 10:06 -------- d-------- C:\Archivos de programa\jlgsolera
2006-09-18 17:33 -------- d-------- C:\Archivos de programa\City Interactive
2006-09-14 14:29 -------- d-------- C:\Documents and Settings\Carlos Hernandez\Datos de programa\Mozilla
2006-09-01 17:12 -------- d-------- C:\Archivos de programa\MSN Messenger
2006-08-24 17:41 -------- d-------- C:\Archivos de programa\Yahoo!
2006-08-23 17:57 -------- d-------- C:\Archivos de programa\TryMedia
2006-08-22 20:16 -------- d-------- C:\Archivos de programa\LimeWire
2006-08-21 07:27 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 04:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-21 04:14 128896 --a------ C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-18 17:01 -------- d-------- C:\Archivos de programa\WinRAR
2006-08-17 17:39 -------- d-------- C:\Archivos de programa\Burn4Free
2006-08-15 11:32 -------- d-------- C:\Archivos de programa\Adobe
2006-08-11 20:11 -------- d-------- C:\Archivos de programa\Windows Defender
2006-08-05 11:01 -------- d-------- C:\Archivos de programa\NoAdware
2006-08-03 14:22 -------- d-------- C:\Documents and Settings\Carlos Hernandez\Datos de programa\Adobe
2006-07-29 19:32 48936 --a------ C:\WINDOWS\system32\sirenacm.dll
2006-07-27 08:26 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-07-21 03:28 72704 --a------ C:\WINDOWS\system32\hlink.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="\"C:\\ARCHIV~1\\Yahoo!\\MESSEN~1\\YAHOOM~1.EXE\" -quiet"
"Power2GoExpress"="\"C:\\Archivos de programa\\Microsoft ActiveSync\\WCESCOMM.EXE\""
"MsnMsgr"="\"C:\\Archivos de programa\\MSN Messenger\\MsnMsgr.Exe\" /background"
"H/PC Connection Agent"="\"C:\\Archivos de programa\\Microsoft ActiveSync\\WCESCOMM.EXE\""
"DW4"="\"C:\\Archivos de programa\\The Weather Channel FW\\Desktop Weather\\DesktopWeather.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE"
"RemoteControl"="\"C:\\Archivos de programa\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"Reminder"="%WINDIR%\\Creator\\Remind_XP.exe"
"Pop3trap.exe"="\"C:\\Archivos de programa\\Trend Micro\\PC-cillin 9\\Pop3trap.exe\""
"pccguide.exe"="\"C:\\Archivos de programa\\Trend Micro\\PC-cillin 9\\pccguide.exe\""
"PCCClient.exe"="\"C:\\Archivos de programa\\Trend Micro\\PC-cillin 9\\PCCClient.exe\""
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb08.exe"
"!ewido"="\"C:\\Archivos de programa\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
"THGuard"="\"C:\\Archivos de programa\\TrojanHunter 4.6\\THGuard.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"Power2GoExpress"="NA"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"Power2GoExpress"="NA"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job

Completion time: 02/10/2006 12:35:39.09
ComboFix.txt
  • 0

#8
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Locate and Delete the following:

C:\WINDOWS\unvise32qt.exe<-- File

C:\Archivos de programa\MalwareWipe.com<-- Folder


Please run the F-Secure Online Scanner

Note: This Scanner is for Internet Explorer Only!
  • Follow the Instruction on the F-Secure page for proper installation.
  • Accept the License Agreement.
  • Once the ActiveX installs,Click Full System Scan
  • Once the download completes,the scan will begin automatically.
  • The scan will take some time to finish,so please be patient.
  • When the scan completes, click the Automatic cleaning (recommended) button.
  • Click the Show Report button and Copy&Paste the entire report in your next reply along with a fresh HijackThis log.

  • 0

#9
Carlos Mex

Carlos Mex

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Hi Cretemonster:

Here are the results of the Fsecure and the Hijackthis

Fsecure:


Scanning Report
Monday, October 02, 2006 17:38:25 - 18:15:26
Computer name: CHM
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\ D:\


--------------------------------------------------------------------------------

Result: 6 malware found
Tracking Cookie (spyware)
System (Disinfected)
System
System
System
System
System

--------------------------------------------------------------------------------

Statistics
Scanned:
Files: 18398
System: 4170
Not scanned: 4
Actions:
Disinfected: 1
Renamed: 0
Deleted: 0
None: 5
Submitted: 0
Files not scanned:
C:\HIBERFIL.SYS
C:\PAGEFILE.SYS
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{FE49CA52-BA1E-465A-8AD7-65849FE18EB1}.BIN

--------------------------------------------------------------------------------

Options
Scanning engines:
F-Secure AVP: 6.0.171, 2006-10-02
F-Secure Libra: 2.4.1, 2006-09-29
F-Secure Orion: 1.2.37, 2006-10-02
F-Secure Blacklight: 1.0.31, 0000-00-00
F-Secure Pegasus: 1.19.0, 2006-08-29
F-Secure Draco: 1.0.35, 0259-24-212
Scanning options:
Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX
Use Advanced heuristics


Hijackthis:

Logfile of HijackThis v1.99.1
Scan saved at 07:19:08 p.m., on 02/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Archivos de programa\CyberLink\PowerDVD\PDVDServ.exe
C:\Archivos de programa\Trend Micro\PC-cillin 9\Pop3trap.exe
C:\Archivos de programa\Trend Micro\PC-cillin 9\pccguide.exe
C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCClient.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Archivos de programa\ewido anti-spyware 4.0\ewido.exe
C:\Archivos de programa\TrojanHunter 4.6\THGuard.exe
C:\Archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE
C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe
C:\Archivos de programa\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\ewido anti-spyware 4.0\guard.exe
C:\Archivos de programa\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Archivos de programa\Archivos comunes\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Trend Micro\PC-cillin 9\Tmntsrv.exe
C:\ARCHIV~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Archivos de programa\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCPFW.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ntvdm.exe
C:\HJT\Hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com.mx/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.prodigy.net.mx/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer - Prodigy Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn1\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Archivos de programa\Yahoo!\Common\yiesrvcmx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Archivos de programa\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Archivos de programa\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Archivos de programa\Trend Micro\PC-cillin 9\Pop3trap.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Archivos de programa\Trend Micro\PC-cillin 9\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCClient.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [!ewido] "C:\Archivos de programa\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [THGuard] "C:\Archivos de programa\TrojanHunter 4.6\THGuard.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\ARCHIV~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Archivos de programa\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [DW4] "C:\Archivos de programa\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Archivos de programa\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe
O4 - Global Startup: Inicio rápido de Adobe Reader.lnk = C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Búsqueda en Google - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebse...?p=ZNxmk904YYMX
O8 - Extra context menu item: &Traducir palabra inglesa - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Instantánea de caché de la página - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Páginas similares - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Páginas vinculadas - res://c:\archivos de programa\google\GoogleToolbar2.dll/cmbacklinks.html
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\ARCHIV~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\ARCHIV~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\ARCHIV~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Yahoo! Servicios - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Archivos de programa\Yahoo!\Common\yiesrvcmx.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Archivos de programa\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Archivos de programa\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Archivos de programa\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1155344534609
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-sec.../ols3/fscax.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Archivos de programa\ewido anti-spyware 4.0\guard.exe
O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\PC-cillin 9\PCCPFW.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Archivos de programa\Archivos comunes\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\PC-cillin 9\Tmntsrv.exe

Thanks
  • 0

#10
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
You really ought to be running atleast a firewall other than Microsoft along with some form of Antivirus software.

Here is a list of free ones:


AntiVir® PersonalEdition Classic

AVG Free for Windows

BitDefender 8 Free Edition

avast! 4 Home Edition


You really should install one of these free firewalls as well since Microsofts Firewall leaves alot to be desired.

Sunbelt Kerio Personal Firewall

ZoneAlarm Free

Outpost Firewall FREE


Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report

  • 0

Advertisements


#11
Carlos Mex

Carlos Mex

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Hello:

This is the result of the panda activescan

Incident Status Location

Potentially unwanted tool:Application/FunWeb Not disinfected C:\Archivos de programa\MSN Messenger\MSIMG32.dll
Potentially unwanted tool:application/funweb Not disinfected c:\windows\downloaded program files\f3initialsetup1.0.0.15.inf
Potentially unwanted tool:application/mywebsearch Not disinfected hkey_classes_root\clsid\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Archivos de programa\MSN Messenger\riched20.dll
Potentially unwanted tool:Application/TheSpyGuard Not disinfected C:\Docs\Trivias\SpyGuardInstaller.exe
Potentially unwanted tool:Application/VirusBurst Not disinfected C:\Documents and Settings\Carlos Hernandez\Configuración local\Datos de programa\Mozilla\Firefox\Profiles\2yaks1vn.default\Cache\272F9E08d01
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@go[1].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Carlos Hernandez\Cookies\carlos hernandez@toplist[1].txt
Spyware:Cookie/VirusBurst Not disinfected C:\Documents and Settings\Carlos Hernandez\Cookies\carlos [email protected][2].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Carlos Hernandez\Escritorio\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Trj\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
Virus:Trj/Spyforms.A Disinfected Carpetas locales\Guardados\Fw: Order Approval Notification\DD269901.jpg.exe
Virus:Trj/Downloader.JYO Disinfected Carpetas locales\Guardados\Fw: Order Confirmation number: WC2995036\WC2995036.zip[WC2995036.exe]
I also run the Avast antivirus and this is the result if you need it.

10/03/2006 11:35
Scan of all local drives
File C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\A0017409.exe is infected by Win32:Zlob-JM [Trj], Deleted
File C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\A0017411.exe\[Upack] is infected by Win32:Zlob-KA [Trj], Deleted
File C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\A0017412.exe is infected by Win32:Zlob-KB [Trj], Deleted
File C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\A0017418.exe is infected by Win32:Zlob-JM [Trj], Deleted
File C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\A0017421.exe\[Upack] is infected by Win32:Zlob-KA [Trj], Deleted
File C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\A0017422.exe is infected by Win32:Zlob-KB [Trj], Deleted

Number of searched folders: 4183
Number of tested files: 58962
Number of infected files: 6

Thanks
  • 0

#12
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
All the Avast entries are in System Restore and we will take care of that shortly.

You really should dump all your emails

Virus:Trj/Spyforms.A Disinfected Carpetas locales\Guardados\Fw: Order Approval Notification\DD269901.jpg.exe

Virus:Trj/Downloader.JYO Disinfected Carpetas locales\Guardados\Fw: Order Confirmation number: WC2995036\WC2995036.zip[WC2995036.exe]




Please Install these 2 to add to the Security of the PC!

SpywareBlaster:
http://www.javacools.../downloads.html
Update Immediatly!

WinHelp2002 Hosts File
http://www.mvps.org/...2002/hosts2.htm




Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

  • 0

#13
Carlos Mex

Carlos Mex

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Hello Cretemonster:

This is the result of the Kaspersky scan:

KASPERSKY ONLINE SCANNER REPORT
Tuesday, October 03, 2006 6:30:26 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 4/10/2006
Kaspersky Anti-Virus database records: 228607
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
F:\
G:\
H:\
I:\

Scan Statistics:
Total number of scanned objects: 52928
Number of viruses found: 24
Number of infected objects: 67 / 0
Number of suspicious objects: 0
Duration of the scan process: 00:45:18

Infected Object Name / Virus Name / Last Action
C:\Archivos de programa\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Archivos de programa\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Archivos de programa\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Archivos de programa\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Archivos de programa\MSN Messenger\riched20.dll Infected: not-a-virus:AdWare.Win32.MyWebSearch skipped
C:\Docs\Aplicaciones\burn4free_setup.exe/data0007/NHInstall.exe Infected: not-a-virus:AdWare.Win32.NavExcel.d skipped
C:\Docs\Aplicaciones\burn4free_setup.exe/data0007/v2.0.4b.cab/NHelper.dll Infected: not-a-virus:AdWare.Win32.NavExcel.g skipped
C:\Docs\Aplicaciones\burn4free_setup.exe/data0007/v2.0.4b.cab/NHUninstaller.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\Docs\Aplicaciones\burn4free_setup.exe/data0007/v2.0.4b.cab/NHUpdater.exe Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\Docs\Aplicaciones\burn4free_setup.exe/data0007/v2.0.4b.cab Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\Docs\Aplicaciones\burn4free_setup.exe/data0007 Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\Docs\Aplicaciones\burn4free_setup.exe Inno: infected - 6 skipped
C:\Docs\Aplicaciones\setup.exe/data0002 Infected: Trojan-Downloader.Win32.Wren.d skipped
C:\Docs\Aplicaciones\setup.exe NSIS: infected - 1 skipped
C:\Documents and Settings\All Users\Datos de programa\Microsoft\Windows Defender\Support\WDLog-08112006-201131.log Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Datos de programa\Microsoft\Messenger\[email protected]\SharingMetadata\Logs\Dfsr.log Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Datos de programa\Microsoft\Messenger\[email protected]\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Datos de programa\Microsoft\Messenger\[email protected]\SharingMetadata\Working\database_3C70_134B_7013_B72\dfsr.db Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Datos de programa\Microsoft\Messenger\[email protected]\SharingMetadata\Working\database_3C70_134B_7013_B72\fsr.log Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Datos de programa\Microsoft\Messenger\[email protected]\SharingMetadata\Working\database_3C70_134B_7013_B72\fsrtmp.log Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Datos de programa\Microsoft\Messenger\[email protected]\SharingMetadata\Working\database_3C70_134B_7013_B72\tmp.edb Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Datos de programa\Microsoft\Windows Live Contacts\[email protected]\real\members.stg Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Datos de programa\Microsoft\Windows Live Contacts\[email protected]\shadow\members.stg Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Temp\WCESCOMM.LOG Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Temp\~DFBD49.tmp Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Temp\~DFBDA7.tmp Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Temp\~DFE03A.tmp Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Configuración local\Temp\~DFE065.tmp Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\Escritorio\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Carlos Hernandez\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Carlos Hernandez\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Temp\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configuración local\Temp\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP171\A0016549.exe Infected: Trojan-Downloader.Win32.Zlob.ang skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP171\A0016563.dll Infected: Trojan-Downloader.Win32.Zlob.ang skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP171\A0016564.exe Infected: Trojan-Downloader.Win32.Zlob.ang skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP172\A0016572.exe Infected: Trojan-Downloader.Win32.Zlob.ang skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP172\A0016576.dll Infected: not-a-virus:AdWare.Win32.ProtectionBar.g skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016850.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.an skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016851.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.aq skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016853.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.al skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016854.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016855.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016856.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.af skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016858.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.an skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016859.SCR Infected: not-a-virus:AdWare.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016860.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016861.EXE Infected: not-a-virus:AdWare.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016862.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.an skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016863.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.aq skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016864.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016866.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.w skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016867.DLL Infected: not-a-virus:AdWare.Win32.IWon.a skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016869.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016870.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.as skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016871.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.ad skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016873.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.ab skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP177\A0016874.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.i skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP178\A0016900.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.v skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP178\A0016901.EXE Infected: not-a-virus:AdWare.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP178\A0016902.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\A0017324.dll Infected: not-a-virus:AdWare.Win32.ProtectionBar.g skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\A0017325.dll Infected: Trojan-Downloader.Win32.Zlob.ang skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\A0017326.dll Infected: Trojan-Downloader.Win32.Zlob.ang skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\A0017327.scr Infected: not-a-virus:AdWare.Win32.MyWebSearch skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\A0017407.exe Infected: Trojan-Downloader.Win32.Zlob.anl skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\A0017408.exe Infected: Trojan-Downloader.Win32.Zlob.ang skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\A0017416.exe Infected: Trojan-Downloader.Win32.Zlob.anl skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\A0017417.exe Infected: Trojan-Downloader.Win32.Zlob.ang skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP179\change.log Object is locked skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP49\A0009161.exe Infected: not-a-virus:AdWare.Win32.HotBar.bi skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP49\A0009164.exe Infected: not-a-virus:AdWare.Win32.HotBar.ax skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP49\A0010129.dll Infected: not-a-virus:AdWare.Win32.HotBar.bi skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP53\A0010459.exe/data0007/NHInstall.exe Infected: not-a-virus:AdWare.Win32.NavExcel.d skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP53\A0010459.exe/data0007/v2.0.4b.cab/NHelper.dll Infected: not-a-virus:AdWare.Win32.NavExcel.g skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP53\A0010459.exe/data0007/v2.0.4b.cab/NHUninstaller.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP53\A0010459.exe/data0007/v2.0.4b.cab/NHUpdater.exe Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP53\A0010459.exe/data0007/v2.0.4b.cab Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP53\A0010459.exe/data0007 Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP53\A0010459.exe Inno: infected - 6 skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP53\A0010470.exe/data0007/NHInstall.exe Infected: not-a-virus:AdWare.Win32.NavExcel.d skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP53\A0010470.exe/data0007/v2.0.4b.cab/NHelper.dll Infected: not-a-virus:AdWare.Win32.NavExcel.g skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP53\A0010470.exe/data0007/v2.0.4b.cab/NHUninstaller.exe Infected: not-a-virus:AdWare.Win32.NavExcel skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP53\A0010470.exe/data0007/v2.0.4b.cab/NHUpdater.exe Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP53\A0010470.exe/data0007/v2.0.4b.cab Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP53\A0010470.exe/data0007 Infected: not-a-virus:AdWare.Win32.NavExcel.b skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP53\A0010470.exe Inno: infected - 6 skipped
C:\System Volume Information\_restore{47B33DC1-98CA-43B2-A2B0-8C86CF2FA005}\RP66\A0011054.DLL Infected: not-a-virus:AdWare.Win32.FunWeb.e skipped
C:\Trj\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Trj\SmitfraudFix.zip ZIP: infected - 1 skipped
C:\WINDOWS\$_hpcst$.hpc Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{4064E8EE-520E-4138-9B56-C5063F3114F0}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_750.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

Thanks
  • 0

#14
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Allrighty,looking alot better now! :whistling:


Locate and Delete the following:

C:\Docs\Aplicaciones\burn4free_setup.exe

C:\Docs\Aplicaciones\setup.exe

C:\Trj\SmitfraudFix.zip


Please Install these 2 to add to the Security of the PC!

SpywareBlaster:
http://www.javacools.../downloads.html
Update Immediatly!

WinHelp2002 Hosts File
http://www.mvps.org/...2002/hosts2.htm



Hows the computer acting?
  • 0

#15
Carlos Mex

Carlos Mex

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts
Hello Cretemonster:

Okay, i already delete the files that you told me and install tge spyware and the mvps, the computer it's working slow.

What do you think?

Thanks
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP