If you notice my ignorance is above average, the cause is not only lack of knowledge; my English is also far from perfect.
My desktop reads a really disgusting DANGER SPYWARE message and right clik mouse doent work. I have noticed more users with the same problem in this forum
I hope to have executed the "You must read this before" instructions as strictly as possible. Except the windows update: i have done nothing at that because my system already was Service Pack 2 when infected!
Well, the problem is still there.
This is my Hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 1:07:09, on 01/04/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\ARCHIV~1\mcafee.com\vso\mcvsrte.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\ARCHIV~1\mcafee.com\vso\mcvsshld.exe
C:\ARCHIV~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\Noj.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Aim\aim.exe
C:\Archivos de programa\Messenger\msmsgs.exe
C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe
c:\archiv~1\mcafee.com\vso\mcvsescn.exe
c:\archiv~1\mcafee.com\vso\mcvsftsn.exe
c:\ARCHIV~1\mcafee.com\vso\mcshield.exe
C:\Seguridad\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.acb.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {B4806B41-011B-11D9-ACFE-00016CA3451D} - C:\WINDOWS\MADOPEW.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\archiv~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\ARCHIV~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\ARCHIV~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\ARCHIV~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\ARCHIV~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Ejv] C:\WINDOWS\Qfq.exe
O4 - HKLM\..\Run: [Vgl] C:\WINDOWS\Ggj.exe
O4 - HKLM\..\Run: [Mhk] C:\WINDOWS\system32\Mgp.exe
O4 - HKLM\..\Run: [Gcp] C:\WINDOWS\system32\Maf.exe
O4 - HKLM\..\Run: [Gof] C:\WINDOWS\system32\Pcv.exe
O4 - HKLM\..\Run: [Kjn] C:\WINDOWS\system32\Ouo.exe
O4 - HKLM\..\Run: [Ogu] C:\WINDOWS\Jhu.exe
O4 - HKLM\..\Run: [Klm] C:\WINDOWS\system32\Jiq.exe
O4 - HKLM\..\Run: [Vdk] C:\WINDOWS\system32\Idt.exe
O4 - HKLM\..\Run: [Aii] C:\WINDOWS\Ikd.exe
O4 - HKLM\..\Run: [Nsg] C:\WINDOWS\system32\Lhn.exe
O4 - HKLM\..\Run: [Euk] C:\WINDOWS\Uun.exe
O4 - HKLM\..\Run: [Kdo] C:\WINDOWS\Mfv.exe
O4 - HKLM\..\Run: [Anv] C:\WINDOWS\system32\Jhc.exe
O4 - HKLM\..\Run: [Goo] C:\WINDOWS\system32\Aid.exe
O4 - HKLM\..\Run: [Okn] C:\WINDOWS\Vep.exe
O4 - HKLM\..\Run: [Pai] C:\WINDOWS\Vro.exe
O4 - HKLM\..\Run: [Isb] C:\WINDOWS\Csg.exe
O4 - HKLM\..\Run: [Jta] C:\WINDOWS\Nfn.exe
O4 - HKLM\..\Run: [Jpr] C:\WINDOWS\system32\Noj.exe
O4 - HKLM\..\Run: [Bba] C:\WINDOWS\Rfn.exe
O4 - HKLM\..\Run: [Het] C:\WINDOWS\system32\Bbn.exe
O4 - HKLM\..\Run: [Qqj] C:\WINDOWS\system32\Omf.exe
O4 - HKLM\..\Run: [Qaj] C:\WINDOWS\Quo.exe
O4 - HKLM\..\Run: [Ook] C:\WINDOWS\Rvq.exe
O4 - HKLM\..\Run: [Qdg] C:\WINDOWS\Uvl.exe
O4 - HKLM\..\Run: [Kum] C:\WINDOWS\system32\Gil.exe
O4 - HKLM\..\Run: [Tcp] C:\WINDOWS\Sbb.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Archivos de programa\Aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Ejv] C:\WINDOWS\Qfq.exe
O4 - HKCU\..\Run: [Vgl] C:\WINDOWS\Ggj.exe
O4 - HKCU\..\Run: [Mhk] C:\WINDOWS\system32\Mgp.exe
O4 - HKCU\..\Run: [Gcp] C:\WINDOWS\system32\Maf.exe
O4 - HKCU\..\Run: [Gof] C:\WINDOWS\system32\Pcv.exe
O4 - HKCU\..\Run: [Kjn] C:\WINDOWS\system32\Ouo.exe
O4 - HKCU\..\Run: [Ogu] C:\WINDOWS\Jhu.exe
O4 - HKCU\..\Run: [Klm] C:\WINDOWS\system32\Jiq.exe
O4 - HKCU\..\Run: [Vdk] C:\WINDOWS\system32\Idt.exe
O4 - HKCU\..\Run: [Aii] C:\WINDOWS\Ikd.exe
O4 - HKCU\..\Run: [Nsg] C:\WINDOWS\system32\Lhn.exe
O4 - HKCU\..\Run: [Euk] C:\WINDOWS\Uun.exe
O4 - HKCU\..\Run: [Kdo] C:\WINDOWS\Mfv.exe
O4 - HKCU\..\Run: [Anv] C:\WINDOWS\system32\Jhc.exe
O4 - HKCU\..\Run: [Goo] C:\WINDOWS\system32\Aid.exe
O4 - HKCU\..\Run: [Okn] C:\WINDOWS\Vep.exe
O4 - HKCU\..\Run: [Pai] C:\WINDOWS\Vro.exe
O4 - HKCU\..\Run: [Isb] C:\WINDOWS\Csg.exe
O4 - HKCU\..\Run: [Jta] C:\WINDOWS\Nfn.exe
O4 - HKCU\..\Run: [Jpr] C:\WINDOWS\system32\Noj.exe
O4 - HKCU\..\Run: [Bba] C:\WINDOWS\Rfn.exe
O4 - HKCU\..\Run: [Het] C:\WINDOWS\system32\Bbn.exe
O4 - HKCU\..\Run: [Qqj] C:\WINDOWS\system32\Omf.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Archivos de programa\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Qaj] C:\WINDOWS\Quo.exe
O4 - HKCU\..\Run: [Ook] C:\WINDOWS\Rvq.exe
O4 - HKCU\..\Run: [Qdg] C:\WINDOWS\Uvl.exe
O4 - HKCU\..\Run: [Kum] C:\WINDOWS\system32\Gil.exe
O4 - HKCU\..\Run: [Tcp] C:\WINDOWS\Sbb.exe
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Archivos de programa\Aim\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1112226959698
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = EBC.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{43A9457D-B600-4D54-A20D-7FFE2E69C4E6}: Domain = EBC.COM
O17 - HKLM\System\CCS\Services\Tcpip\..\{43A9457D-B600-4D54-A20D-7FFE2E69C4E6}: NameServer = 212.89.0.31
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = EBC.local
O17 - HKLM\System\CS1\Services\Tcpip\..\{43A9457D-B600-4D54-A20D-7FFE2E69C4E6}: Domain = EBC.COM
O17 - HKLM\System\CS1\Services\Tcpip\..\{43A9457D-B600-4D54-A20D-7FFE2E69C4E6}: NameServer = 212.89.0.31
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = EBC.local
O17 - HKLM\System\CS2\Services\Tcpip\..\{43A9457D-B600-4D54-A20D-7FFE2E69C4E6}: Domain = EBC.COM
O17 - HKLM\System\CS2\Services\Tcpip\..\{43A9457D-B600-4D54-A20D-7FFE2E69C4E6}: NameServer = 212.89.0.31
O19 - User stylesheet: (file missing)
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\ARCHIV~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARCHIV~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\ARCHIV~1\mcafee.com\vso\mcvsrte.exe
I really appreciate your dedicated help