First, I will list all programs that I downloaded and run:
AD AWARE SE
CWSHREDDER
EWIDO
SPYWARE SCANNER
SPYBOT
WINSOCK XP FIX
XOFTSPY
TDS 3
SPYWARE GUARD
ZONE ALARM TRIAL
CLEAN UP
KILL BOX
SMITFRAUD
TREND MICRO WEB SCAN
TROJAN HUNTER
HOSTS
I get all of that reading others posts forums
I execute ewido and all other scan tools but my pc is still infected.
If you could help me...
I'll already send you my log from hijack this.
Logfile of HijackThis v1.99.1
Scan saved at 11:11:14, on 19/7/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Arquivos de programas\ewido\security suite\ewidoctrl.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\pctspk.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Arquivos de programas\Arquivos comuns\Roxio Shared\Project Selector\projselector.exe
C:\Arquivos de programas\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Arquivos de programas\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Arquivos de programas\Arquivos comuns\InstallShield\Engine\6\Intel 32\{332654785113541.2265441265}\Systems Files\taskmnr.exe
C:\Arquivos de programas\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe
C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe
C:\ARQUIV~1\FREESP~1\SpyWatcher.exe
C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe
C:\winnt\ljiwfqc.exe
c:\arquiv~1\intern~1\iexplore.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\ARQUIV~1\MOZILL~1\FIREFOX.EXE
C:\Arquivos de programas\ewido\security suite\ewidoguard.exe
C:\Arquivos de programas\Internet Explorer\IEXPLORE.EXE
C:\Arquivos de programas\TrojanHunter 4.2\TrojanHunter.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\Administrador\Desktop\Anti SPY\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.hyrzhbdwt...FdaHRjHT81z.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://abcsearch4u.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://abcsearch4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://abcsearch4u.com/
O2 - BHO: (no name) - {03C89125-F56E-B2B2-4135-BB250930D7B9} - C:\DOCUME~1\ADMINI~1\DADOSD~1\MULTIC~1\delete vc.exe (file missing)
O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\WINNT\System32\scpsssh2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\arquivos de programas\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [DeluxeCD] C:\WINNT\System32\cdplayer.exe -tray
O4 - HKLM\..\Run: [projselector] "C:\Arquivos de programas\Arquivos comuns\Roxio Shared\Project Selector\projselector.exe" -r
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Arquivos de programas\Arquivos comuns\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Arquivos de programas\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Arquivos de programas\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Mirebilis ICQ] C:\Arquivos de programas\Arquivos comuns\InstallShield\Engine\6\Intel 32\{332654785113541.2265441265}\Systems Files\taskmnr.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [InterBaseBaseGuardian] C:\Arquivos de programas\Firebird\bin\ibguard.exe -a
O4 - HKLM\..\Run: [OKAYGRAMBROWSEEACH] C:\Documents and Settings\All Users\Dados de aplicativos\Face Style Okay Gram\Load bore.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\ARQUIV~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [intel32.exe] C:\WINNT\System32\intel32.exe
O4 - HKLM\..\Run: [PSGuard spyware remover] C:\Arquivos de programas\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [Spy Watcher] "C:\ARQUIV~1\FREESP~1\SpyWatcher.exe" -S
O4 - HKLM\..\Run: [Zone Labs Client] C:\Arquivos de programas\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [discador] C:\Arquivos de programas\TurboADSL\TurboADSL 0.98\DISCADOR.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Way axis] C:\DOCUME~1\ADMINI~1\DADOSD~1\FLAGRE~1\Body One Soap.exe
O4 - HKCU\..\Run: [iansima] c:\winnt\ljiwfqc.exe
O4 - HKCU\..\Run: [rttpmqd] c:\winnt\ljiwfqc.exe
O4 - HKCU\..\Run: [ytgcfnv] c:\winnt\ljiwfqc.exe
O4 - HKCU\..\Run: [thpvgcx] c:\winnt\cdrmwev.exe
O4 - HKCU\..\Run: [mskbdmc] c:\winnt\cdrmwev.exe
O4 - HKCU\..\Run: [qjlwwis] c:\winnt\cyxnhct.exe
O4 - HKCU\..\Run: [wtjrcgb] c:\winnt\uyufwib.exe
O4 - HKCU\..\Run: [rsyggtd] c:\winnt\uyufwib.exe
O8 - Extra context menu item: &Google Search - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Arquivos de programas\Google\GoogleToolbar1.dll/cmsimilar.html
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {2E3C3651-B19C-4DD9-A979-901EC3E930AF} (ssh2 Class) - https://wwwss.brades...k1/scpsssh2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by22fd.bay22....es/MsnPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3353CF4B-55F5-43C8-A41B-3B4A3E241705}: NameServer = 200.180.128.68,200.199.241.17
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB85E0C8-0764-4B91-859C-C69B74B98554}: NameServer = 200.96.255.198 201.10.120.4
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Serviço administrativo do gerenciador de disco lógico (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Arquivos de programas\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Arquivos de programas\ewido\security suite\ewidoguard.exe
O23 - Service: Hide Files and Folders (HideFilesAndFolders_S) - Unknown owner - C:\WINNT\System32\hffsrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: W2K PCtel speaker phone (Pctspk) - PCtel, Inc. - C:\WINNT\System32\pctspk.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZONELABS\vsmon.exe
AND, i'm not using IE anymore, but Firefox, and I'm now downloading the windows 2000 updates.
Sorry for my bad english,
thanks a lot,
Clarissa