This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack log file. Help!

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Guys!

This http://search200.com/ age opens once and again no matter if I change my setings back to my start up page. I've already ran CWShredder (found nothing), Spybot (erased a few) and AD-Aware (which just finds icons on my desktop so deleted those but once and again I restar the PC, those icos are back too).

Please let me know what's causing this. Here my Hijack This Log.


——————–

Logfile of HijackThis v1.99.1
Scan saved at 05:13:24 p.m., on 04/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system\Test.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Archivos de programa\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Archivos de programa\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Archivos de programa\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
C:\Archivos de programa\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\carpserv.exe
C:\Archivos de programa\Hewlett-Packard\Toolbox\Apache Tomcat

4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Archivos de programa\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC

Card\PRISMSVR.EXE
C:\Archivos de programa\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Archivos de programa\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\zstatus.exe
C:\Archivos de programa\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC

Card\Monitor.exe
C:\Archivos de programa\WinZip\WZQKPICK.EXE
C:\WINDOWS\TEMP\RT5E17.EXE
C:\Archivos de programa\Trend Micro\OfficeScan Client\pccntupd.exe
c:\archiv~1\intern~1\iexplore.exe
c:\archiv~1\intern~1\iexplore.exe
C:\Documents and Settings\amoreno.BMG\Escritorio\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://sgkrcwsfrwy.com/M2p6Mex17ZZIpMez0ep…6HSsYpeNWfk.cgi
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://www.antmjgyviksuuwenhi.uk/M2p6Mex17…eE6ad7/4fE.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

http://www.hp.com/info/e-center-p
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O1 - Hosts: 172.24.224.22 MEXBMLEXS0001
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de

programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {578B2078-2FC9-E195-7728-055E873ED53D} -

C:\DOCUME~1\amoreno\DATOSD~1\MEETIN~1\FragMedia.exe
O2 - BHO: (no name) - {77686990-1742-F11A-1282-1A108BC8B1DF} -

C:\DOCUME~1\amoreno.BMG\DATOSD~1\MEETIN~1\FragMedia.exe
O2 - BHO: (no name) - {9CD4DA81-3160-F2CE-BDC2-6752FE029EEC} -

C:\ARCHIV~1\MEETIN~1\FragMedia.exe (file missing)
O2 - BHO: (no name) - {C7172F27-ACBE-F696-EBFB-7CB43AD70620} -

C:\DOCUME~1\mgarcia\DATOSD~1\MEETIN~1\FragMedia.exe
O4 - HKLM\..\Run: [Cpqset] C:\Archivos de programa\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Archivos de programa\ATI Technologies\ATI Control

Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe

c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Display Settings] C:\Archivos de programa\HPQ\Notebook

Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [SynTPLpr] C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Archivos de programa\Roxio\Easy CD Creator

5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Archivos de programa\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [Datetonsnewreadme] C:\Documents and Settings\All Users\Datos de

programa\INFOSTYLEDATETONS\TITLEATOM.exe
O4 - HKLM\..\Run: [StatusClient 2.5] C:\Archivos de programa\Hewlett-Packard\Toolbox\Apache

Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Archivos de

programa\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\Archivos de programa\3Com\3Com OfficeConnect Wireless

Utility\3Com Wireless 11g PC Card\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Anti Bore Play Dog] C:\Documents and Settings\All Users\Datos de

programa\nounoozeantibore\Settings junk.exe
O4 - HKLM\..\Run: [defy third barb heck] C:\Documents and Settings\All Users\Datos de

programa\BIRD MODE DEFY THIRD\axis settings.exe
O4 - HKLM\..\Run: [hp 1000 firmware] C:\Archivos de programa\hp LaserJet 1000\fwdl.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Archivos de programa\Trend Micro\OfficeScan

Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [two acid multi media] C:\Documents and Settings\All Users\Datos de

programa\axisfacetwoacid\audiomags.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [book send] C:\DOCUME~1\amoreno.BMG\DATOSD~1\MFCDTI~1\Mp3Army.exe
O4 - Global Startup: 3Com Wireless 11g PC Card.lnk = C:\Archivos de programa\3Com\3Com

OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\Monitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Archivos de programa\Adobe\Acrobat

7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Archivos de programa\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel -

res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de

programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: DigiChat Applet -

http://fanclubchat.musictoday.com/DigiChat…s/Client_IE.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -

http://ak.imgfarm.com/images/nocache/funwe…etup1.0.0.8.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -

http://messenger.msn.com/download/msnmesse…pdownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = bmg.bagint.com
O17 - HKLM\Software\..\Telephony: DomainName = bmg.bagint.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = bmg.bagint.com
O23 - Service: BeSoftMonitorTest - Unknown owner - C:\WINDOWS\system\Test.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard -

C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Archivos de programa\HPQ\Notebook

Utilities\HPWirelessMgr.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Archivos de

programa\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Archivos

de programa\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Archivos de

programa\Trend Micro\OfficeScan Client\tmlisten.exe
Click here to download ewido security suite - it is a trial version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed. If you are having problems with the updater, you can use this link to manually update ewido Then:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin (do not open any folders or open the windows control panel while the scan is in progress).
  • While the scan is in progress you will be prompted to clean files, click OK
  • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.

Reboot when done, rescan with HJT and post a new log here together with the ewido log. (don't use wordwrap)
Okay. I already did Ewido check and I'm posting 2 logfiles. It keeps acting like I said: I open Internet Explorer and has http://search.com and also I do have too those popups, a bar that shows up sometimes and icons are still in the desktop: (Tune Up your PC, Find a Date, My antivirus update, Casino Online, Cellphone ringtones). Here's the log.


EWIDO LOG

———————————————————
ewido security suite - Report de exploración
———————————————————

+ Creado en: 04:58:03 p.m., 05/08/2005
+ Report-Checksum: 89BB1440

+ Scan result:

HKLM\SOFTWARE\AutoLoader -> Spyware.AproposMedia : Limpio con backup
HKLM\SOFTWARE\AutoLoader\qsq51QJjcKXO -> Spyware.AproposMedia : Limpio con backup
HKLM\SOFTWARE\AutoLoader\qsqJ1QJjcKXO -> Spyware.AproposMedia : Limpio con backup
HKLM\SOFTWARE\Classes\CLSID\{204F937E-519E-4597-96FA-8F1F59F3CB6D} -> Spyware.HotBar : Limpio con backup
HKLM\SOFTWARE\Classes\CLSID\{6FB2639A-4BA3-4531-8DB8-FAB03E0A8FFD} -> Spyware.HotBar : Limpio con backup
HKLM\SOFTWARE\Classes\Interface\{A1558B18-F76C-40FE-B358-9E47449F3CFE} -> Spyware.AproposMedia : Limpio con backup
HKLM\SOFTWARE\Classes\Interface\{A2872B10-39F2-42DF-9335-7DD38CF75255} -> Spyware.AproposMedia : Limpio con backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -> Spyware.PopularScreensavers : Limpio con backup
[416] C:\DOCUME~1\amoreno\DATOSD~1\MEETIN~1\FragMedia.exe -> TrojanDownloader.Swizzor.bo : Limpio con backup
C:\Documents and Settings\amoreno\Cookies\amoreno@66.220.17[2].txt -> Spyware.Cookie.66.220.17.154 : Limpio con backup
C:\Documents and Settings\amoreno\Cookies\[removed][2].txt -> Spyware.Cookie.Hitbox : Limpio con backup
C:\Documents and Settings\amoreno.BMG\Cookies\amoreno@atdmt[1].txt -> Spyware.Cookie.Atdmt : Limpio con backup
C:\Documents and Settings\amoreno.BMG\Cookies\[removed][1].txt -> Spyware.Cookie.Lop : Limpio con backup
C:\Documents and Settings\amoreno.BMG\Cookies\amoreno@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Limpio con backup
C:\Documents and Settings\amoreno.BMG\Cookies\amoreno@lop[2].txt -> Spyware.Cookie.Lop : Limpio con backup
C:\Documents and Settings\amoreno.BMG\Cookies\amoreno@questionmarket[2].txt -> Spyware.Cookie.Questionmarket : Limpio con backup
C:\Documents and Settings\amoreno.BMG\Cookies\amoreno@revenue[1].txt -> Spyware.Cookie.Revenue : Limpio con backup
C:\Documents and Settings\amoreno.BMG\Cookies\amoreno@statcounter[1].txt -> Spyware.Cookie.Statcounter : Limpio con backup
C:\Documents and Settings\amoreno.BMG\Cookies\amoreno@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Limpio con backup
C:\Documents and Settings\mgarcia\Cookies\mgarcia@goldenpalace[2].txt -> Spyware.Cookie.Goldenpalace : Limpio con backup
C:\Documents and Settings\mgarcia\Cookies\[removed][2].txt -> Spyware.Cookie.Lop : Limpio con backup


::Fin Report


HIJACK THIS LOG

Logfile of HijackThis v1.99.1
Scan saved at 05:00:21 p.m., on 05/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system\Test.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Archivos de programa\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Archivos de programa\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Archivos de programa\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\TEMP\YV12BB.EXE
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
C:\Archivos de programa\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\carpserv.exe
C:\Archivos de programa\Hewlett-Packard\Toolbox\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Archivos de programa\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\PRISMSVR.EXE
C:\Archivos de programa\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
C:\WINDOWS\system32\zstatus.exe
C:\Archivos de programa\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\Monitor.exe
C:\Archivos de programa\WinZip\WZQKPICK.EXE
C:\Archivos de programa\Trend Micro\OfficeScan Client\pccntupd.exe
c:\archiv~1\intern~1\iexplore.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\ewido\security suite\ewidoctrl.exe
C:\Documents and Settings\amoreno.BMG\Escritorio\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.ykoxtukqyewsg.com/M2p6Mex17ZZIp…aHSsYpeNWfk.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zdtfkbchzbryrqkfc.us/M2p6Mex17Z…eE6ad7/4fE.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/info/e-center-p
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O1 - Hosts: 172.24.224.22 MEXBMLEXS0001
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {578B2078-2FC9-E195-7728-055E873ED53D} - C:\DOCUME~1\amoreno\DATOSD~1\MEETIN~1\FragMedia.exe (file missing)
O2 - BHO: (no name) - {77686990-1742-F11A-1282-1A108BC8B1DF} - C:\DOCUME~1\amoreno.BMG\DATOSD~1\MEETIN~1\Bleh Once.exe
O2 - BHO: (no name) - {9CD4DA81-3160-F2CE-BDC2-6752FE029EEC} - C:\ARCHIV~1\MEETIN~1\FragMedia.exe (file missing)
O2 - BHO: (no name) - {C7172F27-ACBE-F696-EBFB-7CB43AD70620} - C:\DOCUME~1\mgarcia\DATOSD~1\MEETIN~1\FragMedia.exe
O4 - HKLM\..\Run: [Cpqset] C:\Archivos de programa\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Display Settings] C:\Archivos de programa\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [SynTPLpr] C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Archivos de programa\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Archivos de programa\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [Datetonsnewreadme] C:\Documents and Settings\All Users\Datos de programa\INFOSTYLEDATETONS\TITLEATOM.exe
O4 - HKLM\..\Run: [StatusClient 2.5] C:\Archivos de programa\Hewlett-Packard\Toolbox\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Archivos de programa\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\Archivos de programa\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Anti Bore Play Dog] C:\Documents and Settings\All Users\Datos de programa\nounoozeantibore\Settings junk.exe
O4 - HKLM\..\Run: [defy third barb heck] C:\Documents and Settings\All Users\Datos de programa\BIRD MODE DEFY THIRD\axis settings.exe
O4 - HKLM\..\Run: [hp 1000 firmware] C:\Archivos de programa\hp LaserJet 1000\fwdl.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Archivos de programa\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [two acid multi media] C:\Documents and Settings\All Users\Datos de programa\axisfacetwoacid\store bits.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [book send] C:\DOCUME~1\amoreno.BMG\DATOSD~1\MFCDTI~1\Mp3Army.exe
O4 - Global Startup: 3Com Wireless 11g PC Card.lnk = C:\Archivos de programa\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\Monitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Archivos de programa\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: DigiChat Applet - http://fanclubchat.musictoday.com/DigiChat…s/Client_IE.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = bmg.bagint.com
O17 - HKLM\Software\..\Telephony: DomainName = bmg.bagint.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = bmg.bagint.com
O23 - Service: BeSoftMonitorTest - Unknown owner - C:\WINDOWS\system\Test.exe
O23 - Service: ewido security suite control - ewido networks - C:\Archivos de programa\ewido\security suite\ewidoctrl.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Archivos de programa\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\OfficeScan Client\tmlisten.exe
Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.ykoxtukqyewsg.com/M2p6Mex17ZZIp…aHSsYpeNWfk.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zdtfkbchzbryrqkfc.us/M2p6Mex17Z…eE6ad7/4fE.html
O1 - Hosts: 172.24.224.22 MEXBMLEXS0001
O2 - BHO: (no name) - {578B2078-2FC9-E195-7728-055E873ED53D} - C:\DOCUME~1\amoreno\DATOSD~1\MEETIN~1\FragMedia.exe (file missing)
O2 - BHO: (no name) - {77686990-1742-F11A-1282-1A108BC8B1DF} - C:\DOCUME~1\amoreno.BMG\DATOSD~1\MEETIN~1\Bleh Once.exe
O2 - BHO: (no name) - {9CD4DA81-3160-F2CE-BDC2-6752FE029EEC} - C:\ARCHIV~1\MEETIN~1\FragMedia.exe (file missing)
O2 - BHO: (no name) - {C7172F27-ACBE-F696-EBFB-7CB43AD70620} - C:\DOCUME~1\mgarcia\DATOSD~1\MEETIN~1\FragMedia.exe
O4 - HKLM\..\Run: [Anti Bore Play Dog] C:\Documents and Settings\All Users\Datos de programa\nounoozeantibore\Settings junk.exe
O4 - HKLM\..\Run: [defy third barb heck] C:\Documents and Settings\All Users\Datos de programa\BIRD MODE DEFY THIRD\axis settings.exe
O4 - HKLM\..\Run: [two acid multi media] C:\Documents and Settings\All Users\Datos de programa\axisfacetwoacid\store bits.exe
O4 - HKCU\..\Run: [book send] C:\DOCUME~1\amoreno.BMG\DATOSD~1\MFCDTI~1\Mp3Army.exe


Exit HijackThis when done. Reboot into Safe Mode by tapping F8 after the BIOS has loaded. Using Windows Explorer, find and delete the following:

C:\Documents and Settings\All Users\Datos de programa\nounoozeantibore <– folder
C:\Documents and Settings\All Users\Datos de programa\BIRD MODE DEFY THIRD <– folder
C:\Documents and Settings\All Users\Datos de programa\axisfacetwoacid <– folder

Exit Explorer and reboot into Normal Mode. Rescan with HijackThis and post a new log here.
Did all as specified… No Explorer windows open (actually, I closed everything). Now I wnt there, found exactly those folders and delete it from their original location as well recycle bin. Restarted, no icons on desktop (yay) and http://search200.com has gone *does a happy dance* Here it's new log. I guess there's still a bar, don't now if it's a bad one. Thanks fo your advice let me know if this is clean :)


HIJACK LOG FILE 2

Logfile of HijackThis v1.99.1
Scan saved at 06:46:00 p.m., on 05/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system\Test.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
C:\Archivos de programa\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\carpserv.exe
C:\Archivos de programa\Hewlett-Packard\Toolbox\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Archivos de programa\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\PRISMSVR.EXE
C:\Archivos de programa\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
C:\Archivos de programa\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\Monitor.exe
C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Archivos de programa\WinZip\WZQKPICK.EXE
C:\Archivos de programa\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Archivos de programa\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Archivos de programa\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\system32\zstatus.exe
C:\Archivos de programa\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\TEMP\VRB2BE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\amoreno.BMG\Escritorio\HijackThis.exe
C:\WINDOWS\System32\imapi.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.nhhobievxsotvabz.uk/M2p6Mex17ZZ…HSsYpeNWfk.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/info/e-center-p
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [Cpqset] C:\Archivos de programa\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Display Settings] C:\Archivos de programa\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [SynTPLpr] C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Archivos de programa\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Archivos de programa\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [Datetonsnewreadme] C:\Documents and Settings\All Users\Datos de programa\INFOSTYLEDATETONS\TITLEATOM.exe
O4 - HKLM\..\Run: [StatusClient 2.5] C:\Archivos de programa\Hewlett-Packard\Toolbox\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Archivos de programa\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\Archivos de programa\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [defy third barb heck] C:\Documents and Settings\All Users\Datos de programa\BIRD MODE DEFY THIRD\axis settings.exe
O4 - HKLM\..\Run: [hp 1000 firmware] C:\Archivos de programa\hp LaserJet 1000\fwdl.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Archivos de programa\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: 3Com Wireless 11g PC Card.lnk = C:\Archivos de programa\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\Monitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Archivos de programa\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = bmg.bagint.com
O17 - HKLM\Software\..\Telephony: DomainName = bmg.bagint.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = bmg.bagint.com
O23 - Service: BeSoftMonitorTest - Unknown owner - C:\WINDOWS\system\Test.exe
O23 - Service: ewido security suite control - ewido networks - C:\Archivos de programa\ewido\security suite\ewidoctrl.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Archivos de programa\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\OfficeScan Client\tmlisten.exe
Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.nhhobievxsotvabz.uk/M2p6Mex17ZZ…HSsYpeNWfk.html
O4 - HKLM\..\Run: [Datetonsnewreadme] C:\Documents and Settings\All Users\Datos de programa\INFOSTYLEDATETONS\TITLEATOM.exe
O4 - HKLM\..\Run: [defy third barb heck] C:\Documents and Settings\All Users\Datos de programa\BIRD MODE DEFY THIRD\axis settings.exe


Exit HijackThis when done. Reboot into Safe Mode by tapping F8 after the BIOS has loaded. Using Windows Explorer, find and delete the following:

C:\Documents and Settings\All Users\Datos de programa\INFOSTYLEDATETONS <– folder
C:\Documents and Settings\All Users\Datos de programa\BIRD MODE DEFY THIRD <– folder

Exit Explorer and reboot into Normal Mode. Rescan with HijackThis and post a new log here.
Okay. I ran Hijack, fixed those lines. Reboot on safe mode, didn't found any of those folders… neither those titleatom.exe or axis settings.exe

Only thing I found was this Axis Setings.exe-2EF8C97D.pf under Windows/something. Dind't erase that one utl you tell me if I should do it.

So I ran again Hijackthis, here's my log. I guess it's clean so I will wait for your approval ;)

HIJACK THIS LOG

Logfile of HijackThis v1.99.1
Scan saved at 08:12:56 p.m., on 05/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system\Test.exe
C:\Archivos de programa\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Archivos de programa\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Archivos de programa\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Archivos de programa\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINDOWS\TEMP\QM53F9.EXE
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
C:\Archivos de programa\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\carpserv.exe
C:\Archivos de programa\Hewlett-Packard\Toolbox\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Archivos de programa\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\PRISMSVR.EXE
C:\Archivos de programa\Trend Micro\OfficeScan Client\pccntmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
C:\Archivos de programa\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\Monitor.exe
C:\Archivos de programa\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\zstatus.exe
C:\Archivos de programa\Trend Micro\OfficeScan Client\pccntupd.exe
C:\Documents and Settings\amoreno.BMG\Escritorio\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/info/e-center-p
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [Cpqset] C:\Archivos de programa\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Archivos de programa\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Display Settings] C:\Archivos de programa\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [SynTPLpr] C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Archivos de programa\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Archivos de programa\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [StatusClient 2.5] C:\Archivos de programa\Hewlett-Packard\Toolbox\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Archivos de programa\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\Archivos de programa\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [hp 1000 firmware] C:\Archivos de programa\hp LaserJet 1000\fwdl.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Archivos de programa\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: 3Com Wireless 11g PC Card.lnk = C:\Archivos de programa\3Com\3Com OfficeConnect Wireless Utility\3Com Wireless 11g PC Card\Monitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Archivos de programa\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmesse…pdownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = bmg.bagint.com
O17 - HKLM\Software\..\Telephony: DomainName = bmg.bagint.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = bmg.bagint.com
O23 - Service: BeSoftMonitorTest - Unknown owner - C:\WINDOWS\system\Test.exe
O23 - Service: ewido security suite control - ewido networks - C:\Archivos de programa\ewido\security suite\ewidoctrl.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Archivos de programa\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Archivos de programa\Trend Micro\OfficeScan Client\tmlisten.exe
You're welcome - glad to help :D

To help keep you clean follow the recommendations in Tony's article here:

So how did I get infected in the first place?



As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI