Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

WinAntiSpyware


  • Please log in to reply

#1
ahphoto

ahphoto

    New Member

  • Member
  • Pip
  • 6 posts
Logfile of HijackThis v1.99.1
Scan saved at 17:01:54, on 08-06-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file:///C:\Programas\TOSHIBA\Free Update Service\splash.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programas\google\googletoolbar3.dll
O2 - BHO: (no name) - {B8C5186E-EC37-4889-9C2E-F73649FFB7BB} - C:\Programas\Video ActiveX Access\iesplg.dll
O2 - BHO: (no name) - {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} - C:\WINDOWS\system32\2007rox.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programas\google\googletoolbar3.dll
O3 - Toolbar: Protection Bar - {DF4E7A0C-E233-4906-B4C1-A404356541FF} - C:\Programas\Video ActiveX Access\iesbpl.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Programas\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TouchED] C:\Programas\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [PadTouch] "C:\Programas\TOSHIBA\PadTouch\PadExe.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TFncKy] C:\Programas\Toshiba\Controlos TOSHIBA\TFncKy.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Programas\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programas\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programas\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [AudioHQ] "C:\WINDOWS\system32\audiohq.exe"
O4 - HKLM\..\Run: [SpyHunter] C:\Programas\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Programas\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Lembretes do calendário do Microsoft Works.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programas\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file:///C:\Programas\TOSHIBA\Free Update Service\splash.html
O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} (DialerWeb Class) - http://212.145.159.1...Recomendada.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://mapserver.cm-...er/mgaxctrl.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Programas\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Programas\Ficheiros comuns\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Programas\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programas\Analog Devices\SoundMAX\SMAgent.exe
  • 0

Advertisements


#2
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
1) Download SmitfraudFix.exe by S!Ri from here and save it to your Desktop.

2) Double click SmitfraudFix.exe - this will open a Command Window and also create the SmitfraudFix folder on your Desktop. Once you have read the information, "press any key to continue..."
Press "1" and then <ENTER> to start the search process.
When the search has completed, a text file, rapport.txt, will open with the results in - Copy and paste this report into your next reply.

A copy of the report can be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
For most, this file can be found by double-clicking My Computer and then Local Disk (C:)


IMPORTANT: Do NOT run any other options until you are asked to do so!

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlog...processutil.htm

Post a fresh HJT log run in Normal Mode.

Also, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager...
  • Click Save list... and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.

  • 0

#3
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
I've just received a request for a file that you have on your system. Some people get excited about this sort of thing - sad really!
Right click an empty area of your Desktop and from the menu that appears click New > Compressed (zipped) Folder - the default name will be fine.
Copy and paste the following file(s) into this folder:

C:\Windows\System32\2007rox.dll

Once you have done this, open the folder, if it isn't already, and click File > Add a Password...
Enter infected (all lower case) into the Password: textbox, confirm it in the box underneath, and then click OK.

You may need to set Windows to show All Hidden Files and Folders. Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after doing the above. **

Next. you'll need to go here: http://www.bleepingc...e.php?channel=8
Click the Browse... button, navigate to the file, highlight it and click Open
Copy and paste the address of this page into the appropriate box and, in the "Comments" box, mark the file FAO miekiemoes
When you've done that, hit Send File and you're done.

Thanks for taking the time. :whistling:
  • 0

#4
ahphoto

ahphoto

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
it is a friend's pc, so i'll have it on my hands again Tuesday.
I'll then save that file before the cleanup procedures.
But what is that file? Why is anyone interested in an infected dll?

anyway, it is me who thanks you for taking the time

Edited by ahphoto, 09 June 2007 - 08:34 PM.

  • 0

#5
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts

But what is that file? Why is anyone interested in an infected dll?

Don't what it is. Some people like to take malicious files apart to see what makes them tick. If you know what they do, it's easier to remove them and undo the damage that they cause.
Personally i'd rather watch a good film, but some people like this sort of thing!
  • 0

#6
ahphoto

ahphoto

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
SmitFraudFix v2.195

Scan done at 17:19:31,51, 12-06-2007
Run from C:\Documents and Settings\Claudia Martins\Ambiente de trabalho\SmitfraudFix
OS: Microsoft Windows XP [VersÆo 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Programas\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7Debug\mdm.exe
C:\Programas\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\Programas\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programas\Video ActiveX Access\iesmn.exe
C:\Programas\Video ActiveX Access\imsmain.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Programas\Video ActiveX Access\imsmn.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\LTSMMSG.exe
C:\Programas\Video ActiveX Access\iesmin.exe
C:\Programas\Apoint2K\Apoint.exe
C:\Programas\TOSHIBA\TouchED\TouchED.Exe
C:\Programas\TOSHIBA\PadTouch\PadExe.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Programas\Toshiba\Controlos TOSHIBA\TFncKy.exe
C:\Programas\Microsoft Works\WksSb.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Programas\Apoint2K\Apntex.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programas\Sony Corporation\Image Transfer\SonyTray.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Programas\Microsoft Office\Office10\msoffice.exe
C:\Programas\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\pkjcoxq.dll FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Claudia Martins


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Claudia Martins\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

C:\DOCUME~1\ALLUSE~1\MENUIN~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\MENUIN~1\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\CLAUDI~1\FAVORI~1

C:\DOCUME~1\CLAUDI~1\FAVORI~1\Online Security Test.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Programas

C:\Programas\SpyLocked 4.1\ FOUND !
C:\Programas\Video ActiveX Access\ FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="A minha home page actual"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{e1d3b05d-4dd9-468d-982e-c342f05436e5}"="crowsteps"

[HKEY_CLASSES_ROOT\CLSID\{e1d3b05d-4dd9-468d-982e-c342f05436e5}\InProcServer32]
@="C:\WINDOWS\system32\pkjcoxq.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{e1d3b05d-4dd9-468d-982e-c342f05436e5}\InProcServer32]
@="C:\WINDOWS\system32\pkjcoxq.dll"



»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS



»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End






Logfile of HijackThis v1.99.1
Scan saved at 17:22:25, on 12-06-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Programas\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7Debug\mdm.exe
C:\Programas\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\Programas\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programas\Video ActiveX Access\iesmn.exe
C:\Programas\Video ActiveX Access\imsmain.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Programas\Video ActiveX Access\imsmn.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\LTSMMSG.exe
C:\Programas\Video ActiveX Access\iesmin.exe
C:\Programas\Apoint2K\Apoint.exe
C:\Programas\TOSHIBA\TouchED\TouchED.Exe
C:\Programas\TOSHIBA\PadTouch\PadExe.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Programas\Toshiba\Controlos TOSHIBA\TFncKy.exe
C:\Programas\Microsoft Works\WksSb.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Programas\Apoint2K\Apntex.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programas\Sony Corporation\Image Transfer\SonyTray.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Programas\Microsoft Office\Office10\msoffice.exe
C:\Programas\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Programas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.huddi.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file:///C:\Programas\TOSHIBA\Free Update Service\splash.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programas\google\googletoolbar3.dll
O2 - BHO: (no name) - {B8C5186E-EC37-4889-9C2E-F73649FFB7BB} - C:\Programas\Video ActiveX Access\iesplg.dll
O2 - BHO: (no name) - {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} - C:\WINDOWS\system32\2007rox.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programas\google\googletoolbar3.dll
O3 - Toolbar: Protection Bar - {DF4E7A0C-E233-4906-B4C1-A404356541FF} - C:\Programas\Video ActiveX Access\iesbpl.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Programas\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TouchED] C:\Programas\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [PadTouch] "C:\Programas\TOSHIBA\PadTouch\PadExe.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TFncKy] C:\Programas\Toshiba\Controlos TOSHIBA\TFncKy.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Programas\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programas\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programas\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [AudioHQ] "C:\WINDOWS\system32\audiohq.exe"
O4 - HKLM\..\Run: [SpyHunter] C:\Programas\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Lembretes do calendário do Microsoft Works.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programas\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file:///C:\Programas\TOSHIBA\Free Update Service\splash.html
O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} (DialerWeb Class) - http://212.145.159.1...Recomendada.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://mapserver.cm-...er/mgaxctrl.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Programas\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Programas\Ficheiros comuns\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Programas\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programas\Analog Devices\SoundMAX\SMAgent.exe





AC3Filter (remove only)
Actualização de Segurança para o Windows Media Player (KB911564)
Actualização de Segurança para o Windows Media Player 10 (KB911565)
Actualização de Segurança para o Windows Media Player 10 (KB917734)
Actualização de Segurança para o Windows Media Player 6.4 (KB925398)
Actualização de segurança para Windows XP (KB890046)
Actualização de segurança para Windows XP (KB893066)
Actualização de segurança para Windows XP (KB893756)
Actualização de segurança para Windows XP (KB896358)
Actualização de segurança para Windows XP (KB896422)
Actualização de segurança para Windows XP (KB896423)
Actualização de segurança para Windows XP (KB896424)
Actualização de segurança para Windows XP (KB896428)
Actualização de segurança para Windows XP (KB896688)
Actualização de segurança para Windows XP (KB899587)
Actualização de segurança para Windows XP (KB899588)
Actualização de segurança para Windows XP (KB899591)
Actualização de segurança para Windows XP (KB900725)
Actualização de segurança para Windows XP (KB901017)
Actualização de segurança para Windows XP (KB901214)
Actualização de segurança para Windows XP (KB902400)
Actualização de segurança para Windows XP (KB905414)
Actualização de segurança para Windows XP (KB905749)
Actualização de segurança para Windows XP (KB905915)
Actualização de segurança para Windows XP (KB908519)
Actualização de segurança para Windows XP (KB911562)
Actualização de segurança para Windows XP (KB911567)
Actualização de segurança para Windows XP (KB911927)
Actualização de segurança para Windows XP (KB912812)
Actualização de segurança para Windows XP (KB912919)
Actualização de segurança para Windows XP (KB913446)
Actualização de segurança para Windows XP (KB913580)
Actualização de segurança para Windows XP (KB914388)
Actualização de segurança para Windows XP (KB914389)
Actualização de segurança para Windows XP (KB916281)
Actualização de segurança para Windows XP (KB917159)
Actualização de segurança para Windows XP (KB917344)
Actualização de segurança para Windows XP (KB917422)
Actualização de segurança para Windows XP (KB917953)
Actualização de segurança para Windows XP (KB918118)
Actualização de segurança para Windows XP (KB918439)
Actualização de segurança para Windows XP (KB918899)
Actualização de segurança para Windows XP (KB919007)
Actualização de segurança para Windows XP (KB920213)
Actualização de segurança para Windows XP (KB920214)
Actualização de segurança para Windows XP (KB920670)
Actualização de segurança para Windows XP (KB920683)
Actualização de segurança para Windows XP (KB920685)
Actualização de segurança para Windows XP (KB921398)
Actualização de segurança para Windows XP (KB921883)
Actualização de segurança para Windows XP (KB922616)
Actualização de segurança para Windows XP (KB922819)
Actualização de segurança para Windows XP (KB923191)
Actualização de segurança para Windows XP (KB923414)
Actualização de Segurança para Windows XP (KB923689)
Actualização de segurança para Windows XP (KB923694)
Actualização de segurança para Windows XP (KB923980)
Actualização de segurança para Windows XP (KB924191)
Actualização de segurança para Windows XP (KB924270)
Actualização de segurança para Windows XP (KB924496)
Actualização de segurança para Windows XP (KB924667)
Actualização de segurança para Windows XP (KB925454)
Actualização de segurança para Windows XP (KB925486)
Actualização de segurança para Windows XP (KB925902)
Actualização de segurança para Windows XP (KB926255)
Actualização de segurança para Windows XP (KB926436)
Actualização de segurança para Windows XP (KB927779)
Actualização de segurança para Windows XP (KB927802)
Actualização de segurança para Windows XP (KB928090)
Actualização de segurança para Windows XP (KB928255)
Actualização de segurança para Windows XP (KB928843)
Actualização de segurança para Windows XP (KB929969)
Actualização de segurança para Windows XP (KB930178)
Actualização de segurança para Windows XP (KB931261)
Actualização de segurança para Windows XP (KB931768)
Actualização de segurança para Windows XP (KB931784)
Actualização de segurança para Windows XP (KB932168)
Actualização para Windows XP (KB898461)
Actualização para Windows XP (KB900485)
Actualização para Windows XP (KB908531)
Actualização para Windows XP (KB910437)
Actualização para Windows XP (KB911280)
Actualização para Windows XP (KB916595)
Actualização para Windows XP (KB920872)
Actualização para Windows XP (KB922582)
Actualização para Windows XP (KB927891)
Actualização para Windows XP (KB929338)
Actualização para Windows XP (KB930916)
Actualização para Windows XP (KB931836)
Adobe Audition 1.0
Adobe Reader 6.0.1 - Português
Alps Pointing-device Driver
Colin McRae Rally 04 Demo
Consola TOSHIBA
Controlos TOSHIBA
Correcção para o Windows Media Player 9 [Ver KB885492 para mais informações]
Crystal Wizard Demo 1.1
Daytona USA Demo Killer
Delta Force Black Hawk Down MP Demo
Demo
Dicionário Júnior
Dirt Track Racing 2 Demo
Disco de recordações HP
ffdshow (remove only)
Formatar Placa de Memória SD TOSHIBA
GameSpy Arcade
Google Earth
Google Toolbar for Internet Explorer
Hidden & Dangerous 2 SP Demo
Hijackthis 1.99.1
HijackThis 1.99.1
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB926239)
HP Foto e Imagem 2.0 - All-in-One
HP Foto e Imagem 2.0 - All-in-One Drivers
HP Foto e Imagem 2.0 - hp psc 1100 series
hp psc 1100 series
hp psc 1100 series
IExplorer Security Plug-in
Image Transfer
Intel® Extreme Graphics Driver
Intel® PRO Network Adapters and Drivers
Internet Explorer Secure Bar
InterVideo WinDVD 4
Invasion Normandy Demo
Java 2 Runtime Environment, SE v1.4.2
Jetboat Superchamps 2
koizo.7c
LiveReg (Symantec Corporation)
LiveUpdate 1.7 (Symantec Corporation)
Lord of the Rings: The Fellowship of the Ring DEMO
Lords of Magic Special Edition Demo
Macromedia Flash MX 2004
Macromedia Flash Player 8
Manuais da TOSHIBA
Messenger Service
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Portuguese Language Pack
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Office XP Professional
Microsoft Publisher 2002
Microsoft Rise Of Nations Trial
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Works 6.0
MSXML 4.0 SP2 (KB927978)
MSXML4 Parser
Need For Speed Hot Pursuit 2 Demo
Nemesis of the Roman Empire Demo
Painkiller SP Demo
PC Diagnostic Tool da TOSHIBA
PCFriendly
Pharaoh
Raven Shield Multiplayer Demo
Savage Demo 2.0
Silenciador Acúst. Unid. CD/DVD
SONIC ADVENTURE DX-Director's Cut Demo A Version
Sony USB Driver
SoundMAX
SpellForce Demo 2
SpyHunter
Syberia 2 Demo
Symantec AntiVirus Client
Teclas Rápidas para Escolher Ecrãs TOSHIBA
Test Drive 6 Demo
Test Drive Off-Road 3 Demo
The Demo Version 1.2
The Operational Art of War, Vol. I Demo
TOSHIBA ConfigFree
TOSHIBA Power Saver
TOSHIBA Software Modem
TOSHIBA Utilities
Touch and Launch
Trailer Park Tycoon Demo
Tribes 2 Demo
Utilitário TOSHIBA de Activar/Desactivar TouchPadV2.05.00
Video ActiveX Object 1.15
VobSub v2.23 (Remove Only)
Windows Installer 3.1 (KB893803)
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Safety Alert
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WWII Frontline Command



(i also have submited 2007rox.dll as asked)

Edited by ahphoto, 12 June 2007 - 10:32 AM.

  • 0

#7
miekiemoes

miekiemoes

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 5,503 posts
  • MVP
Thanks for submitting the file. It's the TR/Spy.Banker.Gen, which means you have to change all your passwords afterwards, since this file captures username/password combinations and send this out silently by e-mail.
  • 0

#8
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts

I hope you've read what miekiemoes has posted above - nasty little buggers, password stealers!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Your log doesn't appear to show a third-party software firewall installed - if you have one, and i've missed it, please ignore this.
If you are relying the firewall that comes with Service Pack 2, then you need to install one. While the SP2 firewall is better than nothing, it doesn't monitor outgoing traffic, so anything malicious on your computer can 'phone home' at will.

There are a few free firewalls available.
Zone Alarm: Available here.
Kerio: Available here.
Outpost: Available here.

It is important to note that you should only have one firewall installed at a time, but you can download them all to your Desktop and install each in turn to see which one you prefer.

Understanding and Using Firewalls: http://www.bleepingc...tutorial60.html

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download the trial version of AVG Anti-Spyware from here and save it to your Desktop.

If you already have this program installed, skip to Updating AVG Anti-Spyware: below.

Double click the avgas-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG A-S will open.

* Please note that this program was formerly known as Ewido anti-spyware 4.0.
Taken from the Ewido website -

ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:

Highly improved cleaning
Lower resource usage
Additional languages supported

All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.

  • Updating AVG Anti-Spyware:

    By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either AVG A-S will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed AVG A-S, double click avgas-signatures-full-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is..." - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close AVG A-S.

AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "4" and then <ENTER> to check for updates.
Don't forget to allow SmiUpdate.exe access through your firewall.
Once it has updated, or if there are no updates available, close the window and the folder.

3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

4) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Boot into Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "2" and then <ENTER> to start the cleaning process.
  • Wait for the tool to complete and disk cleanup to finish.
  • You will be prompted "Registry cleaning - Do you want to clean the registry ? Press "Y" and then <ENTER>.
  • The tool will also check if wininet.dll is infected. You may be prompted to "Replace infected file ?" - press "Y" and then <ENTER>.
Your PC now needs to be rebooted. If this does not happen automatically, you will need to do so manually. Either way, your PC will need to be booted back INTO SAFE MODE.

3) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O2 - BHO: (no name) - {FCADDC14-BD46-408A-9842-CDBE1C6D37EB} - C:\WINDOWS\system32\2007rox.dll

CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

4) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.

5) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

6) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files...
Check the box to the left of 'Delete all offline content' and then click on OK.

7) Go to Start > Control Panel > Display.
Select the Desktop Tab, click on Customise Desktop... and then select the Web Tab.
Under Web pages: you may see a checked entry called Security info - or similar. Highlight this entry and then click the Delete button.
Finally click OK > Apply > OK.

8) Empty the Recycle Bin.

9) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG A-S.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that AVG A-S has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When AVG A-S has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close AVG A-S.

10) Reboot into Normal Mode.

11) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "3" and then <ENTER> to "Delete Trusted Zone".
When prompted "Restore Trusted Zone ?", press "Y" and then <ENTER>.

* Please Note: If you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection *

Will you then post the following:
  • A new HJT log,
  • The AVG A-S log,
  • The text file rapport.txt that will be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
    For most, this file can be found by double-clicking My Computer and then Local Disk (C:)
  • A description of how your PC is behaving.

Please ignore my use of the "Quote" tags - it's an old forum glitch that affects certain of my posts. You shouldn't need to do the same.
  • 0

#9
ahphoto

ahphoto

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Note: after running AVG and Smitfraud, when I ran HJT to remove the 2007rox.dll, it was no longer there, so I had to skip that step.
for the moment it seems to be running fine. I also installed AdAware2007 and ZoneAlarm Free.


Logfile of HijackThis v1.99.1
Scan saved at 12:36:50, on 14-06-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Programas\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7Debug\mdm.exe
C:\Programas\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\Programas\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\LTSMMSG.exe
C:\Programas\Apoint2K\Apoint.exe
C:\Programas\TOSHIBA\TouchED\TouchED.Exe
C:\Programas\TOSHIBA\PadTouch\PadExe.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Programas\Toshiba\Controlos TOSHIBA\TFncKy.exe
C:\Programas\Microsoft Works\WksSb.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Programas\Apoint2K\Apntex.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programas\Sony Corporation\Image Transfer\SonyTray.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Programas\Microsoft Office\Office10\msoffice.exe
C:\Programas\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programas\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programas\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Programas\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TouchED] C:\Programas\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [PadTouch] "C:\Programas\TOSHIBA\PadTouch\PadExe.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TFncKy] C:\Programas\Toshiba\Controlos TOSHIBA\TFncKy.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Programas\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programas\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programas\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [AudioHQ] "C:\WINDOWS\system32\audiohq.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Lembretes do calendário do Microsoft Works.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programas\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file:///C:\Programas\TOSHIBA\Free Update Service\splash.html
O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} (DialerWeb Class) - http://212.145.159.1...Recomendada.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://mapserver.cm-...er/mgaxctrl.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Programas\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Programas\Ficheiros comuns\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Programas\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programas\Analog Devices\SoundMAX\SMAgent.exe



---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 20:05:26 13-06-2007

+ Scan result:



C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037581.dll -> Adware.Agent : No action taken.
HKU\S-1-5-21-1703695485-882444029-974109174-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B8C5186E-EC37-4889-9C2E-F73649FFB7BB} -> Adware.Generic : No action taken.
HKU\S-1-5-21-1703695485-882444029-974109174-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E8EDB60C-951E-4130-93DC-FAF1AD25F8E7} -> Adware.Generic : No action taken.
HKU\S-1-5-21-1703695485-882444029-974109174-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB} -> Adware.Generic : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037392.ini -> Adware.Qworke : No action taken.
C:\Documents and Settings\Claudia Martins\Application Data\WinAntiSpyware 2006 -> Adware.RogueSuspect : No action taken.
C:\Documents and Settings\Claudia Martins\Application Data\WinAntiSpyware 2006\Logs -> Adware.RogueSuspect : No action taken.
C:\Documents and Settings\Claudia Martins\Application Data\WinAntiSpyware 2006\Logs\update.log -> Adware.RogueSuspect : No action taken.
HKU\S-1-5-21-1703695485-882444029-974109174-1006\Software\WinAntiSpyware 2006 Free -> Adware.RogueSuspect : No action taken.
HKU\S-1-5-21-1703695485-882444029-974109174-1006\Software\WinAntiSpyware 2006 Free\Settings -> Adware.RogueSuspect : No action taken.
HKU\S-1-5-21-1703695485-882444029-974109174-1006\Software\qwqngoFMnMIouoBeleqownFIgewncwgolanwII -> Adware.RogueSuspect : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037566.exe -> Adware.SpyHunter : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037580.exe -> Adware.SpyLocked : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037441.exe -> Adware.SystemDoctor : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037442.dll -> Adware.WinAntiSpyware : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037443.exe -> Adware.WinAntiSpyware : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037438.exe -> Adware.WinFixer : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037439.exe -> Adware.WinFixer : No action taken.
C:\WINDOWS\Downloaded Program Files\WebRecomendada.dll -> Dialer.DialWeb : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037578.dll -> Downloader.Agent.bkd : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037206.exe -> Downloader.Banload.aoo : No action taken.
C:\WINDOWS\system32\audiohq.exe -> Downloader.Banload.aoo : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037586.exe -> Downloader.Zlob.awv : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037589.exe -> Downloader.Zlob.azc : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037339.exe -> Downloader.Zlob.btj : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037353.exe -> Downloader.Zlob.btj : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037381.exe -> Downloader.Zlob.btj : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037404.exe -> Downloader.Zlob.btj : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037428.exe -> Downloader.Zlob.btj : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037462.exe -> Downloader.Zlob.btj : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037477.exe -> Downloader.Zlob.btj : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037492.exe -> Downloader.Zlob.btj : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037506.exe -> Downloader.Zlob.btj : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037524.exe -> Downloader.Zlob.btj : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037537.exe -> Downloader.Zlob.btj : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037553.exe -> Downloader.Zlob.btj : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037582.exe -> Downloader.Zlob.btj : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037583.exe -> Downloader.Zlob.btj : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037338.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037352.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037380.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037403.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037427.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037461.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037476.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037491.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037505.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037523.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037535.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037552.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037584.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037587.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037588.exe -> Downloader.Zlob.btq : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037337.dll -> Downloader.Zlob.yt : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037351.dll -> Downloader.Zlob.yt : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037379.dll -> Downloader.Zlob.yt : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037402.dll -> Downloader.Zlob.yt : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037426.dll -> Downloader.Zlob.yt : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037460.dll -> Downloader.Zlob.yt : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037475.dll -> Downloader.Zlob.yt : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037490.dll -> Downloader.Zlob.yt : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037504.dll -> Downloader.Zlob.yt : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037522.dll -> Downloader.Zlob.yt : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037536.dll -> Downloader.Zlob.yt : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037551.dll -> Downloader.Zlob.yt : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037585.dll -> Downloader.Zlob.yt : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037382.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][1].txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][1].txt -> TrackingCookie.Itrack : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Onestat : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Sexcounter : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][1].txt -> TrackingCookie.Sextracker : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][1].txt -> TrackingCookie.Sextracker : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Sextracker : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Specificclick : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Statcounter : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][1].txt -> TrackingCookie.Toplist : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Webtrends : No action taken.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037440.exe -> Trojan.Fakealert.fb : No action taken.


::Report end



SmitFraudFix v2.195

Scan done at 18:11:53,50, 13-06-2007
Run from C:\LIMPEZA\SmitfraudFix
OS: Microsoft Windows XP [VersÆo 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\DOCUME~1\CLAUDI~1\FAVORI~1\Online Security Test.url Deleted

»»»»»»»»»»»»»»»»»»»»»»»» DNS



»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

Edited by ahphoto, 14 June 2007 - 09:26 AM.

  • 0

#10
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
The AVG log shows "No action taken". You either didn't follow the instructions and created the log before you had AVG A-S fix what it found, or you didn't have it fix anything. If you didn't fix anything, you'll need to repeat the appropriate instructions and let AVG A-S do it's thing.

Other than that, as long as the PC behaves itself, i'd say you were about done.

1) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O4 - HKLM\..\Run: [AudioHQ] "C:\WINDOWS\system32\audiohq.exe"

O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} (DialerWeb Class) - http://212.145.159.1...Recomendada.cab


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

2) If it still exists, delete this folder: C:\Documents and Settings\Claudia Martins\Application Data\WinAntiSpyware 2006

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

If you don't intend to use the AVG A-S Resident Shield, do the following:
  • Go to Start > Run, enter services.msc and hit OK.
  • Locate and right click AVG Anti-Spyware Guard
  • Select Properties from the menu.
  • Under the General Tab, change the Service status: to Stopped and then the Startup type: to Disabled.
You don't need to have this service running if you aren't using the guard.
Once the trial period has expired, you will need to do this unless you upgrade as well - the real-time protection doesn't work in the free version.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I want you to run your PC as normal for a few days and when you are happy that everything is fine, do the following:

Update your anti-virus program,
Disable System Restore,
Boot into Safe Mode,
Scan your computer for viruses.
When you get the all clear, reboot into Normal Mode.
Re-enable System Restore,
Create a Restore Point.
This will give a clean Restore Point should you need it in the future.
A tutorial for System Restore is available here.

The reason for waiting is that if removing the malware has caused a problem, which it occasionally does, you can put your PC back to how it was before the fix. This will re-install the malware, but an infected PC is better than an expensive paperweight!
  • 0

#11
ahphoto

ahphoto

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
(i don't know what i did not to clean up the files. work stress maybe, i was working on 3pcs at the same tim while doing the cleanup.
i did the cleaning now, but the AudioHQ mentioned before didn't appear at HJT this time, then i saw at AVG log that it AVG had already deleted it)

THanks for all the incredible work you guys are doing

Logfile of HijackThis v1.99.1
Scan saved at 18:26:44, on 15-06-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Programas\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7Debug\mdm.exe
C:\Programas\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\Programas\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\LTSMMSG.exe
C:\Programas\Apoint2K\Apoint.exe
C:\Programas\TOSHIBA\TouchED\TouchED.Exe
C:\Programas\TOSHIBA\PadTouch\PadExe.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Programas\Toshiba\Controlos TOSHIBA\TFncKy.exe
C:\Programas\Microsoft Works\WksSb.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Programas\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\Apoint2K\Apntex.exe
C:\Programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programas\Sony Corporation\Image Transfer\SonyTray.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Programas\Microsoft Office\Office10\msoffice.exe
C:\Programas\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Programas\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Programas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programas\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programas\google\googletoolbar3.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Programas\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TouchED] C:\Programas\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [PadTouch] "C:\Programas\TOSHIBA\PadTouch\PadExe.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TFncKy] C:\Programas\Toshiba\Controlos TOSHIBA\TFncKy.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Programas\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programas\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programas\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programas\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programas\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programas\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Lembretes do calendário do Microsoft Works.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programas\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file:///C:\Programas\TOSHIBA\Free Update Service\splash.html
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://mapserver.cm-...er/mgaxctrl.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programas\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Programas\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Programas\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programas\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Programas\Ficheiros comuns\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Programas\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programas\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe




---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 18:08:39 15-06-2007

+ Scan result:



C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037581.dll -> Adware.Agent : Cleaned with backup (quarantined).
HKU\S-1-5-21-1703695485-882444029-974109174-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B8C5186E-EC37-4889-9C2E-F73649FFB7BB} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1703695485-882444029-974109174-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E8EDB60C-951E-4130-93DC-FAF1AD25F8E7} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1703695485-882444029-974109174-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB} -> Adware.Generic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037392.ini -> Adware.Qworke : Cleaned with backup (quarantined).
C:\Documents and Settings\Claudia Martins\Application Data\WinAntiSpyware 2006 -> Adware.RogueSuspect : Cleaned with backup (quarantined).
C:\Documents and Settings\Claudia Martins\Application Data\WinAntiSpyware 2006\Logs -> Adware.RogueSuspect : Cleaned with backup (quarantined).
C:\Documents and Settings\Claudia Martins\Application Data\WinAntiSpyware 2006\Logs\update.log -> Adware.RogueSuspect : Cleaned with backup (quarantined).
HKU\S-1-5-21-1703695485-882444029-974109174-1006\Software\WinAntiSpyware 2006 Free -> Adware.RogueSuspect : Cleaned with backup (quarantined).
HKU\S-1-5-21-1703695485-882444029-974109174-1006\Software\WinAntiSpyware 2006 Free\Settings -> Adware.RogueSuspect : Cleaned with backup (quarantined).
HKU\S-1-5-21-1703695485-882444029-974109174-1006\Software\qwqngoFMnMIouoBeleqownFIgewncwgolanwII -> Adware.RogueSuspect : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037566.exe -> Adware.SpyHunter : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037580.exe -> Adware.SpyLocked : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037441.exe -> Adware.SystemDoctor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037442.dll -> Adware.WinAntiSpyware : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037443.exe -> Adware.WinAntiSpyware : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037438.exe -> Adware.WinFixer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037439.exe -> Adware.WinFixer : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\WebRecomendada.dll -> Dialer.DialWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037578.dll -> Downloader.Agent.bkd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037206.exe -> Downloader.Banload.aoo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP211\A0037849.exe -> Downloader.Banload.aoo : Cleaned with backup (quarantined).
C:\WINDOWS\system32\audiohq.exe -> Downloader.Banload.aoo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037586.exe -> Downloader.Zlob.awv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037589.exe -> Downloader.Zlob.azc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037339.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037353.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037381.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037404.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037428.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037462.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037477.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037492.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037506.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037524.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037537.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037553.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037582.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037583.exe -> Downloader.Zlob.btj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037338.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037352.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037380.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037403.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037427.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037461.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037476.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037491.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037505.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037523.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037535.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037552.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037584.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037587.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037588.exe -> Downloader.Zlob.btq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037337.dll -> Downloader.Zlob.yt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037351.dll -> Downloader.Zlob.yt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037379.dll -> Downloader.Zlob.yt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037402.dll -> Downloader.Zlob.yt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037426.dll -> Downloader.Zlob.yt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037460.dll -> Downloader.Zlob.yt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037475.dll -> Downloader.Zlob.yt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037490.dll -> Downloader.Zlob.yt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037504.dll -> Downloader.Zlob.yt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037522.dll -> Downloader.Zlob.yt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037536.dll -> Downloader.Zlob.yt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037551.dll -> Downloader.Zlob.yt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037585.dll -> Downloader.Zlob.yt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037382.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][1].txt -> TrackingCookie.Estat : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][1].txt -> TrackingCookie.Itrack : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][1].txt -> TrackingCookie.Toplist : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Weborama : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Claudia Martins\Cookies\claudia [email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{278BED6D-61FE-4EE1-962D-63530B71B720}\RP210\A0037440.exe -> Trojan.Fakealert.fb : Cleaned with backup (quarantined).


::Report end
  • 0

#12
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
Looks OK to me - flush System Restore in a couple of days and that should be your lot.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP