asdora
Topic Starter
hi there,
winXP
I was infected by this (found by AVG, but could´nt heal it):
Trojan Horse Downloader. Generic2. DTX
Trojan horse Dropper. Generir. FFZ
Trojan Horse Downloader.Agent. ELX
THE COMPUTER IS SLOW (no pop-ups nor advertising… but now I have to click 2 times, instead of 1 time for everything)
I´ve DONE the following:
I´ve followed through with the instructions on the:
"Before Posting A HijackThis Log "Self Help", For Windows 2000 and XP Versions"
USED SPYBOT, ADAWARE, and EWIDO.
SPYBOT found and deleted:
adverstising.com
Avenue A,Inc
CasaleMEdia
FastClick
Hitbox
Hotsearch Bar
MEdiaFlex
ValueClick
WebTrends live
Win3Agent.xv
WinSoftware.WinAntiVirusPro2006
All RED. No green or black entries. is that right?
anything I should try to restore?
ADWARE DELETED:
ArchiveData(auto-quarantine- 2006-07-19 05-32-21.bckp)
Referencefile : SE1R115 18.07.2006
======================================================
TRACKING COOKIE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@spylog[1].txt
obj[1]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@weborama[1].txt
obj[2]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@fortunecity[1].txt
obj[3]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@hotlog[2].txt
obj[4]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\[removed][1].txt
obj[5]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\[removed][2].txt
obj[6]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@tripod[1].txt
obj[7]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@adtech[2].txt
obj[8]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\[removed][1].txt
obj[9]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@maxserving[1].txt
obj[10]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\[removed][1].txt
obj[11]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@2o7[1].txt
obj[12]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@statcounter[1].txt
obj[13]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@revenue[1].txt
obj[14]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\[removed][1].txt
obj[15]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\[removed][2].txt
obj[16]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@bravenet[1].txt
obj[17]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@tribalfusion[2].txt
obj[18]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@trafic[1].txt
obj[19]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\[removed][2].txt
obj[20]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\[removed][2].txt
obj[21]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\[removed][1].txt
obj[22]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@realmedia[1].txt
obj[23]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\[removed][2].txt
obj[24]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@trafficmp[1].txt
obj[25]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@zedo[1].txt
obj[26]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\[removed][1].txt
obj[27]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@seeq[1].txt
obj[28]=IECache Entry : C:\Documents and Settings\Antonio\Cookies\antonio@questionmarket[2].txt
EWIDO found these:
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 08:57:02 19/7/2006
+ Scan result:
C:\Documents and Settings\Antonio\Configurações locais\Temp\43exinjs20.exe -> Backdoor.IRCBot.nw : No action taken.
C:\Documents and Settings\Antonio\Configurações locais\Temp\12exssd32d.exe -> Downloader.Small : No action taken.
C:\Documents and Settings\Antonio\Configurações locais\Temp\6exssd32d.exe -> Downloader.Small : No action taken.
C:\Documents and Settings\Antonio\Configurações locais\Temp\82exssd32d.exe -> Downloader.Small : No action taken.
C:\Documents and Settings\Antonio\Configurações locais\Temp\84exssd32d.exe -> Downloader.Small : No action taken.
C:\Documents and Settings\Antonio\Configurações locais\Temp\91exssd32d.exe -> Downloader.Small : No action taken.
C:\Documents and Settings\Antonio\Cookies\antonio@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Antonio\Cookies\antonio@adbrite[1].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Antonio\Cookies\antonio@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Antonio\Cookies\antonio@burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Antonio\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Antonio\Cookies\[removed][2].txt -> TrackingCookie.Clickhype : No action taken.
C:\Documents and Settings\Antonio\Cookies\antonio@com[1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Antonio\Cookies\[removed][1].txt -> TrackingCookie.Enhance : No action taken.
C:\Documents and Settings\Antonio\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\Antonio\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\Antonio\Cookies\[removed][1].txt -> TrackingCookie.Revenue : No action taken.
C:\Documents and Settings\Antonio\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Antonio\Cookies\antonio@tacoda[2].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Antonio\Cookies\antonio@yadro[2].txt -> TrackingCookie.Yadro : No action taken.
C:\Documents and Settings\Antonio\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : No action taken.
::Report end
HIJACKTHIS LOG
Logfile of HijackThis v1.99.1
Scan saved at 09:04:15, on 19/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Arquivos de programas\ewido anti-spyware 4.0\guard.exe
C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe
C:\Arquivos de programas\Java\jre1.5.0_07\bin\jusched.exe
C:\Arquivos de programas\QuickTime\qttask.exe
C:\Arquivos de programas\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Arquivos de programas\Messenger\msmsgs.exe
C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Arquivos de programas\hijackthis_199\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Arquivos de programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Arquivos de programas\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Arquivos de programas\Java\jre1.5.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [CM-SmWizard] C:\WINDOWS\System\SmWizard.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Arquivos de programas\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w
O4 - HKLM\..\Run: [!ewido] "C:\Arquivos de programas\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Arquivos de programas\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Arquivos de programas\Arquivos comuns\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\ARQUIV~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Arquivos de programas\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\msmsgs.exe
O14 - IERESET.INF: SEARCH_PAGE_URL=&http://home.microsoft.com/intl/br/access/allinone.asp
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARQUIV~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Arquivos de programas\Arquivos comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Arquivos de programas\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Arquivos de programas\Arquivos comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
THANKS.
I REALLY APPRECIATE IT.