This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Could you have a view to this Hijack This ?

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I discovered in this computer we had several Trojan (particuloarly the ones looking for bank personal data, pw, etc.

I tried to delete them using Spyware Doctor and it was difficult for a particular one "msactp32.exe", Spyware doctor found it, but was unable to delete it :angry: and when I looked for it it didn't appear to be there :angry: . So, I booted from a Windows CD system and I was able to find and delete it :thumbup: .

But it seems to me that my computer is still going too slowly and I would like to be sure that everything has been cleaned :( . So, could you have a look to the following Hijak log and giove me feedback from you?

Thanks so much
***************************************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:31:15, on 29/01/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\issch.exe
C:\Archivos de programa\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\QuickTime\qttask.exe
C:\WINDOWS\system32\rundll32.exe
C:\Archivos de programa\Java\jre6\bin\jusched.exe
C:\Archivos de programa\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Archivos de programa\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Archivos de programa\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Archivos de programa\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Archivos de programa\WinZip\WZQKPICK.EXE
C:\Archivos de programa\Spyware Doctor\BDT\BDTUpdateService.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Java\jre6\bin\jqs.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\Archivos de programa\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
C:\Archivos de programa\Spyware Doctor\pctsAuxs.exe
C:\Archivos de programa\Spyware Doctor\pctsSvc.exe
C:\Archivos de programa\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Archivos de programa\Analog Devices\SoundMAX\SMAgent.exe
C:\Archivos de programa\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Archivos de programa\IVT Corporation\BlueSoleil\BlueSoleil VoIP Plugin.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\Lavasoft\Ad-Aware\AAWTray.exe
C:\Archivos de programa\Windows Live\Toolbar\wltuser.exe
C:\Archivos de programa\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://m.es.yahoo.com/?p=us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
R3 - URLSearchHook: Barra Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\userinit.exe,C:\WINDOWS\system32\msactp32.exe,
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aplicación auxiliar de vínculos de Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Archivos comunes\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Archivos de programa\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Archivos de programa\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Archivos de programa\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Archivos de programa\Norton Internet Security\Engine\17.0.0.136\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Archivos de programa\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Aplicación auxiliar de inicio de sesión - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Archivos de programa\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Archivos de programa\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Archivos de programa\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Archivos de programa\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Archivos de programa\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Archivos de programa\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar3.dll
O3 - Toolbar: Barra Yahoo! - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Archivos de programa\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Archivos de programa\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Archivos de programa\Spyware Doctor\BDT\PCTBrowserDefender.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Archivos de programa\Norton Internet Security\Engine\17.0.0.136\coIEPlg.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Archivos de programa\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Archivos de programa\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Detectando automáticamente EPSON Stylus DX3800 Series en ACER-9B2C6D510E] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P72 "Detectando automáticamente EPSON Stylus DX3800 Series en ACER-9B2C6D510E" /O44 "\\ACER-9B2C6D510E\EPSON Stylus DX3800 Series" /M "Stylus DX3800"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Archivos de programa\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Archivos de programa\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = C:\Archivos de programa\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Archivos de programa\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Agregar entrada - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Archivos de programa\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Agregar entrada en Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Archivos de programa\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {08EC5265-BFFB-48C1-8B3B-B96B19921616} (ReveladoOnline Control) - http://media.fotoprix.com/ReveladoOnline/1.3.1.11/setup.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Archivos de programa\Yahoo!\Common\Yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDC8F8A1-BE08-4941-BCDE-658D02C12EFB}: NameServer = 194.179.1.100,194.179.1.101
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\WINDOWS\system32\Skype4COM.dll
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Archivos de programa\Ares\chatServer.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Archivos de programa\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Archivos de programa\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Archivos de programa\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Archivos de programa\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Archivos de programa\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe
O23 - Service: NMSAccessU - Unknown owner - C:\WINDOWS\system32\NMSAccessU.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Archivos de programa\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Archivos de programa\Spyware Doctor\pctsSvc.exe
O23 - Service: Sophos AutoUpdate Service - Unknown owner - C:\Archivos de programa\Sophos\AutoUpdate\ALsvc.exe (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Archivos de programa\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Start BT in service - Unknown owner - C:\Archivos de programa\IVT Corporation\BlueSoleil\StartSkysolSvc.exe

–
End of file - 12334 bytes
*****************
[external image: Posted Image]


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
HI, LDTate thanks for your answer, I did all what you asked for (inlcuding Java cache) and here you can find the Anti-Malware log. Feeling is that system is going slower than days ago, but it could also be due to the new Security Suite I installed, Norton IS 2010 instead of the Sophos antivirus I had previously. Waiting for your feedback. Thanks again ****************** LOG *********************** Malwarebytes' Anti-Malware 1.44 DataBase Version: 3673 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 01/02/2010 18:46:18 mbam-log-2010-02-01 (18-46-18).txt Scan Type : Quick Scan Objects examined: 125283 Time: 8 minute(s), 55 second(s) In Memory Processes Infected: 0 In Memory Modules Infected: 0 Register Keys Infected: 3 Register Values Infected: 1 Register Data Elements Infected: 0 Infected Folders: 0 Infected Files: 0 In Memory Processes Infected: (Not detected) In Memory Modules Infected: (Not detected) Register Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{09f1adac-76d8-4d0f-99a5-5c907dadb988} (Rogue.Multiple) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully. Register Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> Quarantined and deleted successfully. Register Data Elements Infected: (Not detected) Infected Folders: (Not detected) Infected Files: (Not detected) ************************************************************************
Backdoor.Bot

Whether you wish to continue with cleaning or not, you should be aware that you may have been infected by a backdoor trojan. This type of program has the ability to steal passwords and other information from your system. If you are using your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

Please post back to let me know how you wish to proceed.

Backdoor.Bot

Whether you wish to continue with cleaning or not, you should be aware that you may have been infected by a backdoor trojan. This type of program has the ability to steal passwords and other information from your system. If you are using your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:

  • Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
  • Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
  • Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

Please post back to let me know how you wish to proceed.


Thanks! I already assumed it and the first thing we did was the password changes you suggest using anothe computer !!!! Yes, in fact we discovered it when we were accessing one of our banks accounts and got a request of "full identify, including user and password", what we didn't, of course, and talked to the bank. Yes, we changed all the passwords and the credit card we had used in the last few days using phone, no computer, not the same IP.

What is extrange is that we were using Sophos antivirus software, updated, that is the one used by several of the european central banks !!!!!

Then, the first thing we did was to install Spyware Doctor and run it. It gave to me info about the trojan we had, but was not able to delete it. I did it booting with a different system from CD and deleting, erasing discarding the infected file that was in Windows/System32.

The second extrange thing is that after rebooting, the trojan was again there. In a different place, this time in the register, no files were infected.

So I decided to uninstall Sophos antivirus and install Norton Internet Security 2010 and Lavasoft AD-Aware (additionally to the tools you recomended).

The final situation is the log I sent to you, and an additional scanning by AD-Aware that gave a "non-infection" report.

Anyway. Is there any way to further go on with the cleaning of the computer? Or should we go to the re-formatting of the C: partition? If the Malware tool gives to us a "non-infection" report, using the full scan, can we be "almost" safe?

Thanks for your help and kind regards.
Lets give it a go.

Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.If Vista or Windows 7, skip the Recovery Console part
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Hi, LDTate, thenkas for your answer and help.

I did as you told me. Disabled ADAware and Norton Antivirus and run Combofix.

When Combofix was almost ending, it gave to me an error message:

"RegRuns00 cannot be exported. Error when openning the file. It can be due to a disk error or a file system error"

Anyway, Combofix recorded the Combofix.txt log, here it is:

**************************** Combofix.txt **************************
ComboFix 10-02-03.01 - usuario 03/02/2010 18:13:35.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.34.3082.18.1023.574 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Escritorio\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Antivirus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\maria\Escritorio\Videos.url
c:\documents and settings\maria\Favoritos\Videos.url

.
((((((((((((((((((((((((( Files Created from 2010-01-03 to 2010-02-03 )))))))))))))))))))))))))))))))
.

2010-02-03 08:10 . 2010-02-01 08:46 84912 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100202.041\NAVENG.SYS
2010-02-03 08:10 . 2010-02-01 08:46 177520 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100202.041\NAVENG32.DLL
2010-02-03 08:10 . 2010-02-01 08:46 1647984 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100202.041\NAVEX32A.DLL
2010-02-03 08:10 . 2010-02-01 08:46 1323568 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100202.041\NAVEX15.SYS
2010-02-03 08:10 . 2010-02-01 08:46 371248 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100202.041\EECTRL.SYS
2010-02-03 08:10 . 2010-02-01 08:46 2747440 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100202.041\CCERASER.DLL
2010-02-03 08:10 . 2010-02-01 08:46 259440 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100202.041\ECMSVR32.DLL
2010-02-03 08:10 . 2010-02-01 08:46 102448 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\VirusDefs\20100202.041\ERASER.SYS
2010-02-02 21:27 . 2009-12-05 04:54 529456 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100130.002\BHDrvx86.sys
2010-02-02 21:27 . 2009-12-05 04:54 201616 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100130.002\BHRules.dll
2010-02-02 21:27 . 2009-12-05 04:54 1405840 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100130.002\BHEngine.dll
2010-02-02 21:27 . 2009-12-05 04:54 668720 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100130.002\BHDrvx64.sys
2010-02-02 21:27 . 2009-12-05 04:54 610704 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100130.002\bbRGen.dll
2010-02-02 18:13 . 2010-02-02 18:13 1228584 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\SBTE.dll
2010-02-02 18:13 . 2010-02-02 18:13 247080 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\SBRE.dll
2010-02-02 18:12 . 2010-02-02 18:13 2055864 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\ToolBox\LT\ProcessWatch.exe
2010-02-02 18:12 . 2010-02-02 18:12 110680 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\ToolBox\AutoStart Manager\SO.dll
2010-02-02 18:12 . 2010-02-02 18:12 524200 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\ToolBox\AutoStart Manager\AutoStart Manager.exe
2010-02-01 18:12 . 2009-09-23 12:55 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-02-01 18:11 . 2010-02-01 18:11 862040 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-02-01 18:11 . 2010-02-01 18:11 15880 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-02-01 18:11 . 2010-02-01 18:11 206944 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-02-01 18:11 . 2010-02-01 18:11 390288 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-02-01 18:11 . 2010-02-01 18:11 537576 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-02-01 18:11 . 2010-02-01 18:11 389272 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-02-01 18:11 . 2010-02-01 18:11 163728 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-02-01 18:11 . 2010-02-01 18:11 8 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2010-02-01 18:10 . 2010-02-01 18:10 6296864 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\Resources.dll
2010-02-01 18:10 . 2010-02-01 18:10 327000 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-02-01 18:10 . 2010-02-01 18:10 87496 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-02-01 18:10 . 2010-02-01 18:10 933120 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-02-01 18:10 . 2010-02-01 18:10 3803208 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-02-01 18:10 . 2010-02-01 18:10 816784 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-02-01 18:10 . 2010-02-01 18:10 823928 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-02-01 18:10 . 2010-02-01 18:10 1643272 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-02-01 18:10 . 2010-02-01 18:10 788880 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-02-01 18:09 . 2010-02-01 18:10 1181328 —-a-w- c:\documents and settings\All Users\Datos de programa\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-02-01 18:02 . 2010-02-01 18:02 ——– dc-h–w- c:\documents and settings\All Users\Datos de programa\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2010-02-01 18:02 . 2009-10-03 08:15 2924848 -c–a-w- c:\documents and settings\All Users\Datos de programa\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
2010-02-01 17:29 . 2010-02-01 17:29 ——– d—–w- c:\documents and settings\usuario\Datos de programa\Malwarebytes
2010-02-01 17:29 . 2010-02-01 17:29 ——– d—–w- c:\documents and settings\All Users\Datos de programa\Malwarebytes
2010-01-30 16:52 . 2010-01-30 16:52 ——– d-sh–w- c:\documents and settings\maria\PrivacIE
2010-01-30 08:27 . 2010-01-30 08:27 ——– d-sh–w- c:\documents and settings\maria\IETldCache
2010-01-30 08:19 . 2010-01-30 08:19 0 —-a-w- c:\windows\nsreg.dat
2010-01-29 22:58 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100128.002\Scxpx86.dll
2010-01-29 22:58 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100128.002\IDSvix86.sys
2010-01-29 22:58 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100128.002\IDSXpx86.sys
2010-01-29 22:58 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100128.002\IDSxpx86.dll
2010-01-29 22:58 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100128.002\IDSviA64.sys
2010-01-29 11:30 . 2010-01-29 11:30 ——– d—–w- c:\archivos de programa\Trend Micro
2010-01-29 10:29 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100125.001\IDSvix86.sys
2010-01-29 10:29 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100125.001\IDSXpx86.sys
2010-01-29 10:29 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100125.001\Scxpx86.dll
2010-01-29 10:29 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100125.001\IDSxpx86.dll
2010-01-29 10:29 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100125.001\IDSviA64.sys
2010-01-29 10:18 . 2009-08-29 01:24 784752 —-a-r- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\coFFPlgn\components\coFFPlgn.dll
2010-01-29 10:18 . 2009-08-30 00:16 164216 —-a-r- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPlgn\components\IPSFFPl.dll
2010-01-29 10:17 . 2010-01-29 10:17 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2010-01-29 10:17 . 2010-01-29 10:17 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-01-29 10:17 . 2010-01-29 12:21 ——– d—–w- c:\archivos de programa\Archivos comunes\Symantec Shared
2010-01-29 10:17 . 2010-01-29 10:17 ——– d—–w- c:\archivos de programa\Symantec
2010-01-29 10:16 . 2009-08-30 00:16 467504 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20090828.002\IDSVia64.sys
2010-01-29 10:16 . 2009-08-30 00:16 342576 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20090828.002\IDSVix86.sys
2010-01-29 10:16 . 2009-08-30 00:16 329080 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20090828.002\IDSxpx86.sys
2010-01-29 10:16 . 2009-08-30 00:16 732024 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20090828.002\Scxpx86.dll
2010-01-29 10:16 . 2009-08-30 00:16 488312 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20090828.002\IDSxpx86.dll
2010-01-29 10:16 . 2009-08-26 22:13 900464 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\OCS\hsplayer.dll
2010-01-29 10:16 . 2008-05-23 08:13 288104 —-a-w- c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\CPDOEM\CPDOEM.dll
2010-01-29 10:15 . 2010-01-29 11:10 ——– d—–w- c:\windows\system32\drivers\NIS
2010-01-29 10:15 . 2010-01-29 10:15 ——– d—–w- c:\archivos de programa\Windows Sidebar
2010-01-29 10:15 . 2010-01-29 10:15 ——– d—–w- c:\archivos de programa\Norton Internet Security
2010-01-29 10:15 . 2010-01-29 11:10 ——– d—–w- c:\documents and settings\All Users\Datos de programa\Norton
2010-01-29 10:14 . 2010-01-29 11:10 ——– d—–w- c:\archivos de programa\NortonInstaller
2010-01-29 10:14 . 2010-01-29 11:10 ——– d—–w- c:\documents and settings\All Users\Datos de programa\NortonInstaller
2010-01-27 16:34 . 2010-02-01 17:20 ——– d—–w- c:\archivos de programa\Spyware Doctor
2010-01-27 15:23 . 2010-02-01 17:01 ——– d—a-w- c:\documents and settings\All Users\Datos de programa\TEMP
2010-01-26 23:58 . 2010-01-26 23:58 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-01-26 20:55 . 2009-12-11 08:38 69120 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-01-26 20:37 . 2010-01-26 20:37 ——– d-sh–w- c:\documents and settings\usuario\IECompatCache
2010-01-26 20:33 . 2010-01-26 20:33 ——– d-sh–w- c:\documents and settings\usuario\PrivacIE
2010-01-26 19:30 . 2010-01-26 19:30 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-01-26 18:57 . 2010-01-26 18:57 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-26 18:57 . 2010-01-26 18:57 ——– d-sh–w- c:\documents and settings\usuario\IETldCache
2010-01-26 18:10 . 2010-01-26 21:03 ——– d—–w- c:\windows\ie8updates
2010-01-26 18:09 . 2009-12-21 19:06 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-01-26 18:09 . 2009-12-21 19:06 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-01-26 18:06 . 2010-01-26 18:08 ——– dc-h–w- c:\windows\ie8
2010-01-25 21:51 . 2010-01-25 21:51 ——– d—–w- c:\documents and settings\LocalService\Escritorio
2010-01-25 17:57 . 2010-02-01 18:01 ——– d—–w- c:\documents and settings\All Users\Datos de programa\Lavasoft
2010-01-25 17:31 . 2010-01-25 17:31 ——– d—–w- C:\68ad5b41edd6276c48
2010-01-25 17:10 . 2010-01-25 17:10 152576 —-a-w- c:\documents and settings\usuario\Datos de programa\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-13 08:27 . 2009-11-21 15:58 471552 -c—-w- c:\windows\system32\dllcache\aclayers.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-01 18:32 . 2006-07-10 09:37 ——– d—–w- c:\archivos de programa\Lavasoft
2010-01-29 10:17 . 2010-01-29 10:17 805 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-01-29 10:17 . 2010-01-29 10:17 7443 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-01-25 17:12 . 2006-09-04 17:00 ——– d—–w- c:\archivos de programa\Java
2010-01-25 17:10 . 2009-11-15 22:01 79488 —-a-w- c:\documents and settings\usuario\Datos de programa\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-20 08:12 . 2009-02-11 13:10 ——– d—–w- c:\archivos de programa\Microsoft Silverlight
2009-12-21 19:06 . 2004-08-19 13:42 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-09 15:22 . 2001-08-24 10:00 92744 —-a-w- c:\windows\system32\perfc00A.dat
2009-12-09 15:22 . 2001-08-24 10:00 510070 —-a-w- c:\windows\system32\perfh00A.dat
2009-11-23 11:37 . 2009-11-20 11:45 79488 —-a-w- c:\documents and settings\maria\Datos de programa\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-21 15:58 . 2004-08-19 13:41 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
2001-05-24 11:59 . 2008-02-18 17:27 162304 —-a-w- c:\archivos de programa\UNWISE.EXE
2008-09-30 17:22 . 2008-09-30 17:19 952 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-19 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"EPSON Stylus DX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE" [2005-02-08 98304]
"ISUSScheduler"="c:\archivos de programa\Archivos comunes\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"Adobe Photo Downloader"="c:\archivos de programa\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-22 63712]
"Adobe Reader Speed Launcher"="c:\archivos de programa\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="c:\archivos de programa\QuickTime\qttask.exe" [2008-04-10 77824]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"Detectando automáticamente EPSON Stylus DX3800 Series en ACER-9B2C6D510E"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE" [2005-02-08 98304]
"SunJavaUpdateSched"="c:\archivos de programa\Java\jre6\bin\jusched.exe" [2009-10-11 149280]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Men£ Inicio\Programas\Inicio\
BlueSoleil.lnk - c:\archivos de programa\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-9-30 691720]
LUMIX Simple Viewer.lnk - c:\archivos de programa\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2006-8-24 57344]
Microsoft Office.lnk - c:\archivos de programa\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
WinZip Quick Pick.lnk - c:\archivos de programa\WinZip\WZQKPICK.EXE [2008-9-8 525664]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Archivos de programa\\Ares\\Ares.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Archivos de programa\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Archivos de programa\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Archivos de programa\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Archivos de programa\\Windows Live\\Sync\\WindowsLiveSync.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [01/02/2010 19:12 64288]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1100000.088\SymDS.sys [29/01/2010 11:16 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1100000.088\SymEFA.sys [29/01/2010 11:16 169008]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1100000.088\ccHPx86.sys [29/01/2010 11:16 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1100000.088\Ironx86.sys [29/01/2010 11:16 114736]
R2 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\BASHDefs\20100130.002\BHDrvx86.sys [02/02/2010 22:27 529456]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [10/10/2009 20:47 54752]
R2 NIS;Norton Internet Security;c:\archivos de programa\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe [29/01/2010 11:15 126392]
R2 Start BT in service;Start BT in service;c:\archivos de programa\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [30/09/2007 8:16 51816]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\archivos de programa\Archivos comunes\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [29/01/2010 11:28 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Datos de programa\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\Definitions\IPSDefs\20100128.002\IDSXpx86.sys [29/01/2010 23:58 329592]
S3 fsssvc;Servicio de Windows Live Protección infantil;c:\archivos de programa\Windows Live\Family Safety\fsssvc.exe [05/08/2009 21:48 704864]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\archivos de programa\Lavasoft\Ad-Aware\AAWService.exe [24/09/2009 12:17 1181328]
.
Contents of the 'Scheduled Tasks' folder

2010-02-03 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\archivos de programa\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:10]

2010-02-03 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\archivos de programa\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:10]

2010-02-03 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\archivos de programa\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:10]

2010-02-03 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\archivos de programa\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:10]

2010-02-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\archivos de programa\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 18:10]

2010-02-03 c:\windows\Tasks\User_Feed_Synchronization-{7AED5EFB-C4F1-491C-8666-B61537C9C8B9}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]

2009-05-06 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-22 20:18]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://m.es.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportar a Microsoft Excel - c:\archiv~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: ingdirect.es\www
TCP: {CDC8F8A1-BE08-4941-BCDE-658D02C12EFB} = 194.179.1.100,194.179.1.101
DPF: {08EC5265-BFFB-48C1-8B3B-B96B19921616} - hxxp://media.fotoprix.com/ReveladoOnline/1.3.1.11/setup.exe
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-ISUSPM Startup - c:\archivos de programa\Archivos comunes\InstallShield\UpdateService\isuspm.exe
AddRemove-Ad-Aware SE Personal - c:\archiv~1\Lavasoft\AD-AWA~1\UNWISE.EXE
AddRemove-Language pack for Ad-Aware SE - c:\archiv~1\Lavasoft\AD-AWA~1\Plugins\Langs\UNWISE.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-03 18:20
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NIS]
"ImagePath"="\"c:\archivos de programa\Norton Internet Security\Engine\17.0.0.136\ccSvcHst.exe\" /s \"NIS\" /m \"c:\archivos de programa\Norton Internet Security\Engine\17.0.0.136\diMaster.dll\" /prefetch:1"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"A0C0110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Completion time: 2010-02-03 18:24:43
ComboFix-quarantined-files.txt 2010-02-03 17:24

Pre-Run: 10.287.706.112 bytes libres
Post-Run: 12.363.730.944 bytes libres

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 10E5BCF6CCE157F96D39A1EC048BF458
********************************************************

System seems to run OK, even still slowly, but it could be due to the Norton Internet Security, I don´t know.

Thanks again and kind regards.
You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve performance.

Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START then RUN
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    To be on the safe side, I would also change all my passwords.


    Here's my usual all clean post

    Log looks good :D


    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.


I would suggest you read How to Prevent Malware:
Hi LDTate, thanks so much for all your help. Instead of StartupLite, I use to install in my computers StartupCPL, I feel similar thing. First thing I did was to look at it and didn't found anything suspicious. Combofix was already deleted from desktop, so, no need to execute the command. In fact, I tried, but "combofix" was not found….. Regarding your other suggestions. Internet Explorer already had the settings you suggested, We now have Norton Internet Security (Antivirus+firewall) and AD-Aware (ant-spyware) both with automatic update, as windows updates also has (these ones is "tell me about new updates and let me decide to installl them", I feel enough, provided I install them, what we do). But you know, we are never 100% safe of something come "too inside" of our computer even with the best "anti—everything" we had installed. Thanks again, indeed. I feel this thread can be (hopefully definitely) closed. P.S.: BTW, most probably we will be upgarding our PC in the coming weeks, so, new disk, and probably not clone, but new system ;) Javier
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI