Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Aurora Popups / Nail.exe[CLOSED]


  • This topic is locked This topic is locked

#1
drdomi

drdomi

    New Member

  • Member
  • Pip
  • 7 posts
Hello!

I´m haveing to problems in this PC. First, that box that appears to send error reports to microsoft (Explorer.exe) is coming back everytime I click "don´t send" or "send" report.

I saw that the dwwin.exe, even when I halt its process on the process manager, comes back, so the error appears again.

And another thing is that the micro is infected with nail.exe (is there any relation about these two problems?)

The Hijack logfile is the following:


Logfile of HijackThis v1.99.1
Scan saved at 09:43:26, on 16/5/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\Mixer.exe
C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe
C:\ARQUIV~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Arquivos de programas\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\ARQUIV~1\Grisoft\AVG7\avgamsvr.exe
C:\ARQUIV~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
c:\windows\system32\zvqsik.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\dwwin.exe
C:\Arquivos de programas\Outlook Express\msimn.exe
C:\Arquivos de programas\Messenger\msmsgs.exe
C:\Arquivos de programas\Microsoft Office\Office10\OUTLOOK.EXE
C:\Arquivos de programas\Microsoft Office\Office10\WINWORD.EXE
C:\Documents and Settings\Vendas\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsof...ss/allinone.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32/left.html
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx (file missing)
O2 - BHO: (no name) - {15BCD837-C31B-1802-26AC-0ADB22B9A030} - C:\WINDOWS\System32\bofaqof.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {809F4121-120B-4889-977A-F2680E95F89C} - C:\WINDOWS\System32\sozaqoga.dll
O3 - Toolbar: SuperBar - {0B030927-5065-4C58-8410-ABF179DDF702} - C:\Arquivos de programas\_SUPERBAR\_SUPERBAR.dll (file missing)
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TkBellExe] "C:\Arquivos de programas\Arquivos comuns\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [sfqvuc] c:\windows\system32\sfqvuc.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [smltr327] C:\WINDOWS\System32\smltr327.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\ARQUIV~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [dbpmmqo] c:\windows\system32\zvqsik.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Acrobat Assistant.lnk = C:\Arquivos de programas\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\ARQUIV~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\ARQUIV~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Arquivos de programas\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsof...ss/allinone.asp
O15 - Trusted Zone: www.bradesco.com.br
O15 - Trusted Zone: http://www.bradesco.com.br
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\Security Center\SymWSC.exe
  • 0

Advertisements


#2
ScHwErV

ScHwErV

    Member 5k

  • Retired Staff
  • 21,285 posts
  • MVP
drdomi

Hello and welcome to Geeks To Go.

Lets get to it.

Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later.

Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.

Please run Notepad and copy the following text into a new file:

@ECHO OFF
process -k explorer.exe
cd %windir%
Nail.exe /fullremove
sc config SvcProc start= disabled
sc stop SvcProc
sc delete SvcProc
attrib -s -r -h nail.exe
attrib -s -r -h svcproc.exe
del nail.exe
del svcproc.exe
cd %windir%\system32
attrib -s -r -h DrPMon.dll
del DrPMon.dll
start explorer.exe
exit

Save the file to the desktop as remove.bat and make sure the "Save as type" field says "All files".

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

Once in Safe Mode, please double-click on remove.bat. A window should open and close very quickly --- this is normal.

Then please run Ewido, and run a full scan. Post the log from the scan here for me.

Then please run HijackThis, click Scan, and check:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

Close all open windows except for HijackThis and click Fix Checked.

Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.

Edited by ScHwErV, 16 May 2005 - 07:23 AM.

  • 0

#3
drdomi

drdomi

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Hello!

I followed your tips and it seems that the problem was solved (including that error report box popping! argh!)

Here is the new Hijack log:

Logfile of HijackThis v1.99.1
Scan saved at 11:17:56, on 16/5/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\Mixer.exe
C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe
C:\ARQUIV~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Arquivos de programas\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\ARQUIV~1\Grisoft\AVG7\avgamsvr.exe
C:\ARQUIV~1\Grisoft\AVG7\avgupsvc.exe
C:\Arquivos de programas\ewido\security suite\ewidoctrl.exe
C:\Arquivos de programas\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Documents and Settings\Vendas\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = &http://home.microsof...ss/allinone.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32/left.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx (file missing)
O2 - BHO: (no name) - {15BCD837-C31B-1802-26AC-0ADB22B9A030} - C:\WINDOWS\System32\bofaqof.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {809F4121-120B-4889-977A-F2680E95F89C} - C:\WINDOWS\System32\sozaqoga.dll (file missing)
O4 - HKLM\..\Run: [sfqvuc] c:\windows\system32\sfqvuc.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [smltr327] C:\WINDOWS\System32\smltr327.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\ARQUIV~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Acrobat Assistant.lnk = C:\Arquivos de programas\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\ARQUIV~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\ARQUIV~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
O12 - Plugin for .spop: C:\Arquivos de programas\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsof...ss/allinone.asp
O15 - Trusted Zone: www.bradesco.com.br
O15 - Trusted Zone: http://www.bradesco.com.br
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Arquivos de programas\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Arquivos de programas\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Arquivos de programas\Arquivos comuns\Symantec Shared\Security Center\SymWSC.exe
  • 0

#4
drdomi

drdomi

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Oh!!
And the Ewido Log

---------------------------------------------------------
ewido security suite - Relatório de verificação
---------------------------------------------------------

+ Criado em: 11:12:38, 16/5/2005
+ Relatório-Checksum: EF3F52D2

+ Data da base de dados: 16/5/2005
+ Versão do motor de verificação: v3.0

+ Duração: 24 min
+ Ficheiros Verificados: 39455
+ Velocidade: 27.33 Ficheiros/Segundo
+ Ficheiros infectados: 45
+ Ficheiros removidos: 45
+ Ficheiros postos em quarentena: 0
+ Ficheiros que não podem ser abertos: 0
+ Ficheiros que não podem ser limpos: 0

+ Binder: Sim
+ Crypter: Sim
+ Arquivos: Sim

+ Itens verificados:
C:\

+ Resultado da verificação:
C:\Documents and Settings\Vendas\Configurações locais\Temp\adv.exe -> Spyware.AdultIt.a -> Limpo sem backup
C:\Documents and Settings\Vendas\Configurações locais\Temp\drp1.tmp\thnall1b.exe -> Spyware.BetterInternet -> Limpo sem backup
C:\Documents and Settings\Vendas\Configurações locais\Temp\drp1B5.tmp\thnall1b.exe -> Spyware.BetterInternet -> Limpo sem backup
C:\Documents and Settings\Vendas\Configurações locais\Temp\drp2.tmp\thnall1b.exe -> Spyware.BetterInternet -> Limpo sem backup
C:\Documents and Settings\Vendas\Configurações locais\Temp\drp7C.tmp\thnall1b.exe -> Spyware.BetterInternet -> Limpo sem backup
C:\Documents and Settings\Vendas\Configurações locais\Temporary Internet Files\Content.IE5\571F411A\aurora[1].exe -> Spyware.BetterInternet.c -> Limpo sem backup
C:\Documents and Settings\Vendas\Configurações locais\Temporary Internet Files\Content.IE5\E183EPE5\Nail[1].exe -> Trojan.Nail -> Limpo sem backup
C:\Documents and Settings\Vendas\Cookies\vendas@89971095[1].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\Documents and Settings\Vendas\Cookies\[email protected][1].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\Documents and Settings\Vendas\Cookies\[email protected][1].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\Documents and Settings\Vendas\Cookies\vendas@cgi-bin[1].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\Documents and Settings\Vendas\Cookies\[email protected][1].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\Documents and Settings\Vendas\Cookies\vendas@overture[1].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\Documents and Settings\Vendas\Cookies\[email protected][1].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\Documents and Settings\Vendas\Cookies\[email protected][2].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\Documents and Settings\Vendas\Cookies\[email protected][2].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\RECYCLER\NPROTECT\00002031.exe -> Spyware.Bargainbuddy -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Configurações locais\Temp\205AGABE.dll -> Spyware.Sahat.m -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Configurações locais\Temp\banner.exe -> Spyware.BetterInternet -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Configurações locais\Temp\Cookies\interware@advertising[1].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Configurações locais\Temp\Cookies\[email protected][1].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Configurações locais\Temp\Cookies\interware@tribalfusion[1].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Configurações locais\Temp\GLF81GLF81.EXE -> TrojanDownloader.TSUpdate.f -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Configurações locais\Temp\ICD2.tmp\WinServAdX.dll -> Spyware.WinAD.f -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Configurações locais\Temp\SAHAGE~1.EXE -> Spyware.Sahat.m -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Configurações locais\Temp\targetsaver.exe -> TrojanDownloader.TSUpdate.f -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Configurações locais\Temp\THI49E3.tmp\BTGrab.dll -> Spyware.BiSpy.t -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Configurações locais\Temp\THI696B.tmp\BTGrab.dll -> Spyware.BiSpy.t -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Configurações locais\Temp\THI7265.tmp\BTGrab.dll -> Spyware.BiSpy.t -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Cookies\interware@atdmt[2].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Cookies\interware@burstnet[2].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Cookies\interware@doubleclick[1].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\RECYCLER\S-1-5-21-839522115-1958367476-725345543-500\Dc5.DANIELA\Cookies\interware@tribalfusion[1].txt -> Spyware.Tracking-Cookie -> Limpo sem backup
C:\WINDOWS\BTGrab.dll -> Spyware.BiSpy.t -> Limpo sem backup
C:\WINDOWS\dlmax.dll -> Spyware.DlMax.a -> Limpo sem backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1015.dll -> Spyware.Browsertoolbar -> Limpo sem backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1015.dll -> Spyware.Browsertoolbar -> Limpo sem backup
C:\WINDOWS\Downloaded Program Files\HDPlugin1015.dll -> Spyware.Browsertoolbar -> Limpo sem backup
C:\WINDOWS\Downloaded Program Files\WinServAdX.dll -> Spyware.WinAD.f -> Limpo sem backup
C:\WINDOWS\netturbo.exe -> Spyware.VX2 -> Limpo sem backup
C:\WINDOWS\system32\bofaqof.dll -> Spyware.AdultIt.a -> Limpo sem backup
C:\WINDOWS\system32\DrPMon.dll_tobedeleted -> Trojan.Agent.db -> Limpo sem backup
C:\WINDOWS\system32\jhbraiz.exe -> Trojan.Agent.cp -> Limpo sem backup
C:\WINDOWS\system32\sozaqoga.dll -> TrojanDownloader.Agent.au -> Limpo sem backup
C:\WINDOWS\system32\XXX_Action-uninstall.exe -> Dialer.Generic -> Limpo sem backup


::Fim do Relatório
  • 0

#5
ScHwErV

ScHwErV

    Member 5k

  • Retired Staff
  • 21,285 posts
  • MVP
Have a few more things to deal with. Lets do a virus scan since I see signs of a trojan in your log.

Please run an on-line virus scan at Kaspersky OnLine Scan or if that doesnt work, you can use TrendMicro or BitDefender. (Please post the results of the scan(s) in your next reply)

ScHwErV :tazz:
  • 0

#6
drdomi

drdomi

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Thank you very much!

Anything, I post again.


Dani
  • 0

#7
ScHwErV

ScHwErV

    Member 5k

  • Retired Staff
  • 21,285 posts
  • MVP
Sorry, yes.

Can I get a fresh HiJackThis log and let me know how things are working now.

ScHwErV :tazz:
  • 0

#8
ScHwErV

ScHwErV

    Member 5k

  • Retired Staff
  • 21,285 posts
  • MVP
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member with address of this thread. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP