Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Registers Changes


  • Please log in to reply
10 replies to this topic

#1 falito

falito

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:51 AM

Posted 20 August 2007 - 07:21 PM

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 05:14:13 p.m., on 20/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\Config\lsass.exe
C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe
C:\Archivos de programa\Eset\nod32kui.exe
C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Archivos de programa\Aleric\MyIVO\bin\myivomgr.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Archivos de programa\Aleric\MyIVO\bin\myivosrv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Archivos de programa\Eset\nod32krn.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Aleric\MyIVO\bin\myivodds.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\lsass.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARCHIV~1\MICROS~2\Office12\GRA8E1~1.DLL
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [myivo] C:\Archivos de programa\Aleric\MyIVO\bin\myivomgr.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARCHIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARCHIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARCHIV~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\ARCHIV~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Servicio del iPod (iPod Service) - Apple Inc. - C:\Archivos de programa\iPod\bin\iPodService.exe
O23 - Service: MyIVO - Unknown owner - C:\Archivos de programa\Aleric\MyIVO\bin\myivosrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 4555 bytes

BC AdBot (Login to Remove)

 


#2 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:51 PM

Posted 21 August 2007 - 06:39 AM

Hello there and welcome to Bleeping Computer's security forum.
My name is David, I will be helping you with your log today.

It is a good idea to print off these instructions. There is a possibility some of the instructions will need to be carried out where internet access is not available. It is important that you complete the instructions in the right order, and that you don't miss out any steps.

Please set your system to show all files.
Click Start, open My Computer, select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.

Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following if still present:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Config\lsass.exe

Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!

Now reboot into Safe Mode.
This can be done tapping the F8 key as soon as you start your computer
You will be brought to a menu where you can choose to boot into safe mode.
Make sure you choose the option without networking support.

Using Windows Explorer, please locate the following files/folders, and delete them if still present:

C:\WINDOWS\Config\lsass.exe <--do not delete the legitimate lssas.exe in your 'system32' folder

I want you to clean your cache and cookies from your internet explorer.
There are a few infected files which need to be removed from your system.

° Close all instances of Internet Explorer .
° Go to your control panel and open "Internet Options".
° Click on the "General" tab.
° Click the "Delete Cookies" button, then the "Delete Files" button.
° If prompted, place a tick in the "Delete all offline content" box and click OK.

Also, please clean other Temporary files and Empty the Recycle Bin

° Go to start and click on the "run" button.
° Type the following in the box --> cleanmgr and click ok.
° Let it scan your system for files to remove.
° Make sure only Temporary Files, Temporary Internet Files, and Recycle Bin are checked.
° Press OK to remove them.

Please download Combofix to your desktop.
Doubleclick combofix.exe to launch the application.

Follow the prompts that will be displayed on the screen.
Don't click on the window while the fix is running, because that will cause your system to hang.
When finished, it should produce a log, combofix.txt.
Post this log in your next reply together with a new hijackthislog.

#3 falito

falito
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:51 AM

Posted 21 August 2007 - 11:38 AM

ComboFix 07-08-21.3 - "Ing. H‚ctor Alfaro R" 2007-08-21 9:31:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.3082.18.468 [GMT -7:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup


((((((((((((((((((((((((( Files Created from 2007-07-21 to 2007-08-21 )))))))))))))))))))))))))))))))


2007-08-21 09:24 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-21 09:11 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-08-21 09:11 <DIR> dr-h----- C:\DOCUME~1\ADMINI~1\Datos de programa
2007-08-21 09:11 <DIR> dr------- C:\DOCUME~1\ADMINI~1\Men£ Inicio
2007-08-21 09:11 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Reciente
2007-08-21 09:11 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Plantillas
2007-08-21 09:11 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Impresoras
2007-08-21 09:11 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Entorno de red
2007-08-21 09:11 <DIR> d--h----- C:\DOCUME~1\ADMINI~1\Configuraci¢n local
2007-08-21 09:11 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Mis documentos
2007-08-21 09:11 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Favoritos
2007-08-21 09:11 <DIR> d-------- C:\DOCUME~1\ADMINI~1\Escritorio
2007-08-20 17:13 <DIR> d-------- C:\Archivos de programa\Trend Micro
2007-08-19 14:14 <DIR> d-------- C:\Archivos de programa\iPod
2007-08-19 14:13 <DIR> d-------- C:\Archivos de programa\iTunes
2007-08-19 14:12 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-08-19 14:12 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\DATOSD~1\Apple Computer
2007-08-19 14:12 <DIR> d-------- C:\Archivos de programa\QuickTime
2007-08-19 14:12 <DIR> d-------- C:\Archivos de programa\Archivos comunes\Apple
2007-08-19 14:12 <DIR> d-------- C:\Archivos de programa\Apple Software Update
2007-08-19 14:11 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\DATOSD~1\Apple
2007-08-18 17:56 <DIR> d-------- C:\Archivos de programa\GPS Utility
2007-08-18 16:57 39,552 --a------ C:\WINDOWS\system32\drivers\ser2pl.sys
2007-08-18 15:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\DATOSD~1\allTunes
2007-08-18 15:13 <DIR> d-------- C:\Archivos de programa\allTunes
2007-08-17 15:14 258,048 --a------ C:\WINDOWS\system32\config\SYSTEM~1\ntuser.dat
2007-08-15 12:24 6,005 --a------ C:\sysxdti.exe
2007-08-15 12:24 4,096 --a------ C:\WINDOWS\spload.dll
2007-08-15 12:24 3,328 --a------ C:\WINDOWS\system32\s10192.sys
2007-08-15 12:24 3,072 --a------ C:\WINDOWS\s5292w32.dll
2007-08-14 22:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\DATOSD~1\DataViz
2007-08-14 19:58 16,694 --a------ C:\WINDOWS\system32\drivers\PalmUSBD.sys
2007-08-14 17:26 <DIR> d-------- C:\DOCUME~1\INGALF~1.ALF\Mis documentos
2007-08-14 09:41 <DIR> d-------- C:\Archivos de programa\LegalSounds
2007-08-13 18:46 3,318 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Windows Media Audio 9 Codec.dat
2007-08-13 18:46 2,958 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2007-08-13 18:44 4,131,192 -ra------ C:\WINDOWS\system32\SpoonUninstall.exe
2007-08-13 18:44 13,090 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2007-08-13 18:44 <DIR> d-------- C:\Archivos de programa\Illustrate
2007-08-13 12:07 <DIR> d-------- C:\Archivos de programa\Intel
2007-08-13 12:04 151,552 --a------ C:\WINDOWS\system32\igfxres.dll
2007-08-13 12:02 <DIR> d-------- C:\WINDOWS\system32\ReinstallBackups
2007-08-13 10:12 <DIR> d--h----- C:\WINDOWS\PIF
2007-08-13 09:33 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-08-13 09:33 <DIR> d-------- C:\Archivos de programa\Windows Desktop Search
2007-08-13 08:50 <DIR> d---s---- C:\DOCUME~1\ING~1.HCT\UserData
2007-08-09 20:14 <DIR> d-------- C:\Archivos de programa\Aleric
2007-08-09 19:59 3,846,016 -ra------ C:\WINDOWS\system32\drivers\ALCXWDM.SYS
2007-08-09 19:19 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2007-08-09 19:19 7,552 --a------ C:\WINDOWS\system32\drivers\MSKSSRV.sys
2007-08-09 19:19 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2007-08-09 19:19 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2007-08-09 19:19 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2007-08-09 19:19 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2007-08-09 19:19 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2007-08-09 19:19 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2007-08-09 19:19 4,992 --a------ C:\WINDOWS\system32\drivers\MSPQM.sys
2007-08-09 19:19 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2007-08-09 19:19 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2007-08-09 19:19 171,776 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2007-08-09 19:19 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2007-08-09 19:19 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2007-08-09 17:46 54,784 --a------ C:\WINDOWS\system32\drivers\CDAC11BA.EXE
2007-08-09 17:46 12,464 --a------ C:\WINDOWS\system32\drivers\CDAC15BA.SYS
2007-08-09 17:44 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\DATOSD~1\Autodesk
2007-08-09 17:44 <DIR> d-------- C:\Archivos de programa\AutoCAD 2004
2007-08-09 16:56 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\DATOSD~1\HotSync
2007-08-09 16:15 <DIR> d-------- C:\Archivos de programa\CCleaner
2007-08-09 15:14 <DIR> d-------- C:\Archivos de programa\Ahead
2007-08-09 13:07 74,240 --a------ C:\WINDOWS\ST6UNST.EXE
2007-08-09 13:07 290,816 --------- C:\WINDOWS\Setup1.exe
2007-08-09 12:41 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2007-08-09 12:41 298,104 --a------ C:\WINDOWS\system32\imon.dll
2007-08-09 12:41 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2007-08-09 12:13 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\DATOSD~1\HP
2007-08-09 12:12 51,120 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2007-08-09 12:12 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2007-08-09 12:11 37,376 --a------ C:\WINDOWS\system32\hpz3l3xu.dll
2007-08-09 12:10 94,208 --a------ C:\WINDOWS\system32\HPZipt12.dll
2007-08-09 12:10 69,632 --a------ C:\WINDOWS\system32\HPZipm12.exe
2007-08-09 12:10 61,440 --a------ C:\WINDOWS\system32\HPZinw12.exe
2007-08-09 12:10 57,344 --a------ C:\WINDOWS\system32\HPZisn12.dll
2007-08-09 12:10 306,688 --a------ C:\WINDOWS\IsUninst.exe
2007-08-09 12:10 278,584 --a------ C:\WINDOWS\system32\HPZidr12.dll
2007-08-09 12:10 204,800 --a------ C:\WINDOWS\system32\HPZipr12.dll
2007-08-09 12:08 80,343 --a------ C:\WINDOWS\hpfins05.dat
2007-08-09 12:08 1,547 --------- C:\WINDOWS\hpfmdl05.dat
2007-08-09 11:39 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
2007-08-09 11:31 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.WIN\DATOSD~1\Microsoft Help
2007-08-09 11:02 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-08-09 11:00 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-08-09 10:44 2,883,584 --a------ C:\DOCUME~1\ING~1.HCT\NTUSER.DAT
2007-08-09 10:44 <DIR> dr-h----- C:\DOCUME~1\ING~1.HCT\Datos de programa
2007-08-09 10:44 <DIR> dr------- C:\DOCUME~1\ING~1.HCT\Mis documentos
2007-08-09 10:44 <DIR> dr------- C:\DOCUME~1\ING~1.HCT\Men£ Inicio
2007-08-09 10:44 <DIR> dr------- C:\DOCUME~1\ING~1.HCT\Favoritos
2007-08-09 10:44 <DIR> d--h----- C:\DOCUME~1\ING~1.HCT\Plantillas
2007-08-09 10:44 <DIR> d--h----- C:\DOCUME~1\ING~1.HCT\Impresoras
2007-08-09 10:44 <DIR> d--h----- C:\DOCUME~1\ING~1.HCT\Entorno de red
2007-08-09 10:44 <DIR> d--h----- C:\DOCUME~1\ING~1.HCT\Configuraci¢n local


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-19 14:14 --------- d-------- C:\DOCUME~1\ING~1.HCT\DATOSD~1\Apple Computer
2007-08-18 18:11 --------- d-------- C:\DOCUME~1\ING~1.HCT\DATOSD~1\GPS Utility
2007-08-18 14:40 --------- d-------- C:\DOCUME~1\ING~1.HCT\DATOSD~1\allTunes
2007-08-16 08:46 359040 --a------ C:\WINDOWS\system32\drivers\TCPIP.SYS
2007-08-14 22:06 --------- d-------- C:\DOCUME~1\ING~1.HCT\DATOSD~1\Arcsoft
2007-08-14 19:56 --------- d-------- C:\DOCUME~1\ING~1.HCT\DATOSD~1\Leadertech
2007-08-14 18:14 359040 --a------ C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2007-08-14 09:41 --------- d-------- C:\DOCUME~1\ING~1.HCT\DATOSD~1\LegalSounds
2007-08-13 18:24 --------- d-------- C:\DOCUME~1\ING~1.HCT\DATOSD~1\AccurateRip
2007-08-13 12:06 --------- d-------- C:\DOCUME~1\ING~1.HCT\DATOSD~1\InstallShield
2007-08-10 11:50 --------- d-------- C:\DOCUME~1\ING~1.HCT\DATOSD~1\AdobeUM
2007-08-09 20:19 917504 --a------ C:\WINDOWS\system\cmids3d.dll
2007-08-09 20:19 818496 --a------ C:\WINDOWS\system32\drivers\cmuda.sys
2007-08-09 20:19 712704 --a------ C:\WINDOWS\system32\Audio3D.dll
2007-08-09 20:19 712704 --a------ C:\WINDOWS\system32\a3d.dll
2007-08-09 20:19 32768 --a------ C:\WINDOWS\system32\udaprop.dll
2007-08-09 20:19 28672 --a------ C:\WINDOWS\system32\cmirmdrv.dll
2007-08-09 20:19 233472 --a------ C:\WINDOWS\system32\cmirmdrv.exe
2007-08-09 20:19 151552 --a------ C:\WINDOWS\system32\cmuda.dll
2007-08-09 20:19 1458176 --a------ C:\WINDOWS\system\SmWizard.exe
2007-08-09 19:24 2426 --a------ C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
2007-08-09 19:23 8972 --a------ C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin
2007-08-09 17:48 --------- d-------- C:\DOCUME~1\ING~1.HCT\DATOSD~1\Autodesk
2007-08-09 17:39 --------- d-------- C:\DOCUME~1\ING~1.HCT\DATOSD~1\Help
2007-08-09 16:54 --------- d-------- C:\DOCUME~1\ING~1.HCT\DATOSD~1\HotSync
2007-08-09 12:07 --------- d-------- C:\DOCUME~1\ING~1.HCT\DATOSD~1\HP
2007-08-09 11:00 --------- d-------- C:\DOCUME~1\ING~1.HCT\DATOSD~1\Google
2005-09-01 23:41 20055121 --a------ C:\DOCUME~1\LLAVEI~1\setup.exe
--------- C:\Archivos de programa\Servicios en línea


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]
"nod32kui"="C:\Archivos de programa\Eset\nod32kui.exe" [2007-08-09 12:41]
"Google Desktop Search"="C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-09 16:26]
"myivo"="C:\Archivos de programa\Aleric\MyIVO\bin\myivomgr.exe" [2006-01-01 14:03]
"Cmaudio"="cmicnfg.cpl" []
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 06:42]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\ARCHIV~1\Google\GOOGLE~1\GOEC62~1.DLL

R2 MyIVO;MyIVO;C:\Archivos de programa\Aleric\MyIVO\bin\myivosrv.exe -service
R2 s10192.sys;s10192.sys;\??\C:\WINDOWS\system32\s10192.sys


**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-21 09:32:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-21 9:33:23

--- E O F ---

#4 KoanYorel

KoanYorel

    Bleepin' Conundrum


  • Members
  • 19,461 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:65 miles due East of the &quot;Logic Free Zone&quot;, in Md, USA
  • Local time:12:51 PM

Posted 21 August 2007 - 01:03 PM

Falito,

Please use the ADD REPLY button at the bottom right side of the page when responding to this topic.
Do not make separate threads. Your HJT Tech assistance will be delayed otherwise.

Regards,
KoanYorel
The only easy day was yesterday.

...some do, some don't; some will, some won't (WR)

#5 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:51 PM

Posted 21 August 2007 - 03:02 PM

Thanks a lot Koan. :thumbsup:

Please download the Suspicious File Packer from here:
http://www.safer-networking.org/files/sfp.zip
Unzip it to the desktop but do not run it.

Now reboot into Safe Mode.
This can be done tapping the F8 key as soon as you start your computer
You will be brought to a menu where you can choose to boot into safe mode.
Make sure you choose the option without networking support.

Using Windows Explorer, please locate the following files/folders, and delete them if still present:

C:\sysxdti.exe
C:\WINDOWS\spload.dll
C:\WINDOWS\s5292w32.dll

Please open the Suspicious File Packer you downloaded earlier.
Paste the following bold part into the Suspicious File Packer window:

C:\WINDOWS\system32\s10192.sys

Allow SFP to pack the file. This will generate a CAB archive on your desktop.

Reboot back to normal mode.

Go to this page.
Enter the url of this thread in the first field.
Where it says, browse to the file that you want to submit, click the browse button next to the second field and browse to the CAB archive that was been created on your desktop.
The cab file will be called requested-files[*].cab (the * stands for the date and hour).
Then click the Send File button below.
Please let me know when you have submitted the files.

#6 falito

falito
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:51 AM

Posted 22 August 2007 - 11:07 AM

i send u the cab file. thnks

#7 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:51 PM

Posted 22 August 2007 - 03:53 PM

Thanks for uploading the file.

It is a good idea to print off these instructions. There is a possibility some of the instructions will need to be carried out where internet access is not available. It is important that you complete the instructions in the right order, and that you don't miss out any steps.

Open hijackthis, click 'config' (bottom right) Choose the tab 'misc Tools' on top.
Choose 'delete a file on reboot'. In the field, copy and paste the filepath a few lines below.
Click open. Hijackthis will tell you that this file will be deleted on next reboot and if you want to reboot now.
When asked if you want to reboot now, say Yes:
C:\WINDOWS\system32\s10192.sys

Allow the PC to reboot, if it doesn't do it automatically, please reboot manually.

Please click on start > run > and type: sc stop s10192.sys
Hit enter and let the DOS windows open and close. This is normal.

Do exactly the same for this: sc delete s10192.sys

Please perform this online scan: Kaspersky Webscan
Note that this scanner will only work on Internet Explorer, so please use this browser for the scan.
Read the Requirements and Privacy statement, then select "Accept"
A dialogue box will appearing asking "Do you want to install this software?" Name: kavwebscan_unicode.cab
Select "Install" to download the ActiveX controls that allows ActiveScan to run.

When the download is complete it will say ready, click "Next"
Select a target to scan: Click on "My Computer"
When the scan is complete choose to save the results as "Save as Text"
Post the Kaspersky scan results in your next reply, along with a new Hijackthis log.

#8 falito

falito
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:51 AM

Posted 22 August 2007 - 07:49 PM

run kaspersky and hijack D-J

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, August 22, 2007 5:34:53 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 23/08/2007
Kaspersky Anti-Virus database records: 387299
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
M:\

Scan Statistics:
Total number of scanned objects: 76110
Number of viruses found: 4
Number of infected objects: 6
Number of suspicious objects: 0
Duration of the scan process: 01:48:57

Infected Object Name / Virus Name / Last Action
C:\Archivos de programa\Aleric\MyIVO\db\acclog.csv Object is locked skipped
C:\Archivos de programa\Aleric\MyIVO\log\myivomgr_0.log Object is locked skipped
C:\Archivos de programa\Aleric\MyIVO\log\myivosrv.log Object is locked skipped
C:\Archivos de programa\ESET\cache\CACHE.NDB Object is locked skipped
C:\Archivos de programa\ESET\infected\OHSZSXAA.NQF Infected: Backdoor.Win32.Rbot.bll skipped
C:\Archivos de programa\ESET\infected\QIMYESCA.NQF/data0003 Infected: Virus.Win32.Virut.i skipped
C:\Archivos de programa\ESET\infected\QIMYESCA.NQF/data0004 Infected: not-a-virus:AdWare.Win32.Virtumonde.ks skipped
C:\Archivos de programa\ESET\infected\QIMYESCA.NQF NSIS: infected - 2 skipped
C:\Archivos de programa\ESET\infected\QIMYESCA.NQF PE-Crypt.XorPE: infected - 2 skipped
C:\Archivos de programa\ESET\logs\virlog.dat Object is locked skipped
C:\Archivos de programa\ESET\logs\warnlog.dat Object is locked skipped
C:\d5bcb6ad0122edcdfd63f53d26df\update\update.exe Object is locked skipped
C:\d5bcb6ad0122edcdfd63f53d26df\update\updspapi.dll Object is locked skipped
C:\d5bcb6ad0122edcdfd63f53d26df\update\wpdinstallutil.dll Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Datos de programa\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\dbc2e.ht1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\dbdam Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\dbdao Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\dbeam Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\dbeao Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\dbm Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\dbu2d.ht1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\dbvm.cf1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\dbvmh.ht1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\fii.cf1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\fiih.ht1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\hp Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\hpt2i.ht1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\rpm.cf1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\rpm1m.cf1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\rpm1mh.ht1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\rpmh.ht1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\safeweb\goog-black-enchashm.cf1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\safeweb\goog-black-enchashmh.ht1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\safeweb\goog-black-urlm.cf1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\safeweb\goog-black-urlmh.ht1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\safeweb\goog-malware-domainm.cf1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\safeweb\goog-malware-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\safeweb\goog-white-domainm.cf1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Google\Google Desktop\8af8f3fdb764\safeweb\goog-white-domainmh.ht1 Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Configuración local\Temp\~DF86C6.tmp Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Mis documentos\Mis documentos\Mis imágenes\palmOne Photos\Ing\TARJETA SD\FAMILIA ALFARO TAPIA\fotossancarlos\11-06-05_1026.jpg Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Mis documentos\Mis documentos\Mis imágenes\palmOne Photos\Ing\TARJETA SD\FAMILIA ALFARO TAPIA\fotossancarlos\11-06-05_1812.jpg Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Mis documentos\Mis documentos\Mis imágenes\palmOne Photos\Ing\TARJETA SD\FAMILIA ALFARO TAPIA\fotossancarlos\Foto_032007_001.jpg Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Mis documentos\Mis documentos\Mis imágenes\palmOne Photos\Ing\TARJETA SD\FAMILIA ALFARO TAPIA\fotossancarlos\Foto_032007_002.jpg Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Mis documentos\Mis documentos\Mis imágenes\palmOne Photos\Ing\TARJETA SD\FAMILIA ALFARO TAPIA\fotossancarlos\Foto_032007_003.jpg Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\Mis documentos\Mis documentos\Mis imágenes\palmOne Photos\Ing\TARJETA SD\FAMILIA ALFARO TAPIA\fotossancarlos\Thumbs.db Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Ing. Héctor Alfaro R\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY.002\Configuración local\Archivos temporales de Internet\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY.002\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY.002\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY.002\Configuración local\Historial\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY.002\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY.002\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY.002\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY.002\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY.002\Configuración local\Datos de programa\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY.002\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY.002\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{9CB84EE8-E077-4BE6-AD2D-D92542F0BEE3}\RP89\A0021089.exe Infected: Trojan.Win32.VB.bdb skipped
C:\System Volume Information\_restore{9CB84EE8-E077-4BE6-AD2D-D92542F0BEE3}\RP96\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 05:41:15 p.m., on 22/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe
C:\Archivos de programa\Eset\nod32kui.exe
C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe
C:\Archivos de programa\Aleric\MyIVO\bin\myivomgr.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Archivos de programa\Aleric\MyIVO\bin\myivosrv.exe
C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe
C:\Archivos de programa\Eset\nod32krn.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Archivos de programa\Aleric\MyIVO\bin\myivodds.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Archivos de programa\Microsoft Office\Office12\EXCEL.EXE
C:\Program Files\BitComet\BitComet.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\Trend Micro\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARCHIV~1\MICROS~2\Office12\GRA8E1~1.DLL
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [myivo] C:\Archivos de programa\Aleric\MyIVO\bin\myivomgr.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARCHIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARCHIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARCHIV~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\ARCHIV~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Servicio del iPod (iPod Service) - Apple Inc. - C:\Archivos de programa\iPod\bin\iPodService.exe
O23 - Service: MyIVO - Unknown owner - C:\Archivos de programa\Aleric\MyIVO\bin\myivosrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 4826 bytes

Attached Files



#9 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:51 PM

Posted 23 August 2007 - 05:41 AM

Ok, just a couple more things to do...

We need to purge your infected system restore points.
On the Desktop, right-click My Computer, then click Properties.
Click the System Restore tab near the top of the window.
Check Turn off System Restore, click Apply, and then click OK.
More information on how to disable your system restore can be found here.

We want to create a new, clean restore point. Please first reboot your computer.
On the Desktop, right-click My Computer, then click Properties.
Click the System Restore tab near the top of the window.
Uncheck "Turn off System Restore", click Apply, and then click OK.

Click Start > All Programs > Accessories > System Tools, and select System Restore.
In the System Restore wizard, select the box next the text labeled "Create a restore point" and click the Next button.
Type a description for your new restore point - Something like "After trojan/spyware cleanup".
Click Create, and after it has created the restore point, click "Close".
Further instructions on creating a restore point can be found here

Click start > run and copy and paste: C:\Archivos de programa\ESET\infected
Click edit > select all > and hit the delete button on your keyboard.

Reboot a final time and let me know how the Pc is running.
I see a clean Hijackthis log here! :thumbsup:

#10 falito

falito
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:51 AM

Posted 23 August 2007 - 03:02 PM

running all process this is hijack log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:59:55 p.m., on 23/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe
C:\Archivos de programa\Eset\nod32kui.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe
C:\Archivos de programa\Aleric\MyIVO\bin\myivomgr.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Archivos de programa\Aleric\MyIVO\bin\myivosrv.exe
C:\Archivos de programa\Eset\nod32krn.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Archivos de programa\Aleric\MyIVO\bin\myivodds.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Archivos de programa\Trend Micro\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\ARCHIV~1\MICROS~2\Office12\GRA8E1~1.DLL
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Archivos de programa\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [myivo] C:\Archivos de programa\Aleric\MyIVO\bin\myivomgr.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARCHIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARCHIV~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\ARCHIV~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\ARCHIV~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Servicio del iPod (iPod Service) - Apple Inc. - C:\Archivos de programa\iPod\bin\iPodService.exe
O23 - Service: MyIVO - Unknown owner - C:\Archivos de programa\Aleric\MyIVO\bin\myivosrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 4613 bytes

#11 -David-

-David-

  • Members
  • 10,603 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London
  • Local time:05:51 PM

Posted 23 August 2007 - 03:20 PM

Glad I could help! :flowers:
The latest log is looking clean!
Follow this list and your potential for being infected again will be reduced dramatically.

Use an Anti Virus Software -
* It is very important that your computer has an anti-virus software running on your machine.
* This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
* Click here for more information on -> Computer Safety On line - Anti-Virus
* I would recommend Grisoft's AVG or AVAST.
* These are the more secure and better ones.

Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall -
* I can not stress how important it is that you use a Firewall on your computer.
* Without a firewall your computer is susceptible to being hacked and taken over.
* Simply using a Firewall in its default configuration can lower your risk greatly.
* For an article on Firewalls and a listing of some available ones see the link below:
* Click here for more information on -> Computer Safety On line - Software Firewalls
* I would recommend ZoneAlarm as a firewall as it's easy to use.

Visit Microsoft's Windows Update Site Frequently -
* It is important that you visit http://www.windowsupdate.com regularly.
* This will ensure your computer has always the latest security updates available installed on your computer.
* If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Next, if they're not already present, I would recommend the download and installation of some or all of the following programs (all free), and the updating of them regularly

Install Spybot© - Search and Destroy- Install and download Spybot - Search and Destroy with its TeaTimer option.
* This will provide real-time spyware & hijacker protection on your computer alongside your virus protection.
* You should also scan your computer with program on a regular basis just as you would an anti virus software.
* A tutorial on installing & using this product can be found here:
* Click here for more info -->Instructions for - Spybot S & D and Ad-aware

Install Lavasofts© Ad-Aware - Install and download Ad-Aware.
* You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot.
* A tutorial on installing & using this product can be found here:
* Click here for more info -->Instructions for - Spybot S & D and Ad-aware

Install Javacools© SpywareBlaster -
* SpywareBlaster will added a large list of programs and sites into your Internet Explorer and Firefox settings and that will protect you from running and downloading known malicious programs.
* A article on anti-malware products with links for this program and others can be found here:
* Click here for more info -->Computer Safety on line - Anti-Malware

Update all these programs regularly - Make sure you update all the programs I have listed regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.
:thumbsup: If you wish to learn how to use HijackThis to remove malware, you might like to join the Malware Removal Training Program!

If you have any addition questions just ask...
David




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users