This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Plz Help, Trojan W32.looksky, safewabenavigate, an oth

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HI There
Plz i need help, it all started with a lot o pop ups, many non credible alerts of looksky trojan, then it also changed my homepage to some antivirus product, it also added some antivirus and malware removal icons on my desktop, and also a toolbar on my internet browser named " the adbpn". Ok the thing is that i read all the threads that were like my case, and i started to fix some stuff (some of the software used were combofix, super anti spyware, etc…), now i dont get the pop ups neither the alerts of trojans, and the icons on my desktop were removed (the malware stuff), but still got "the adbpn" tool bar on my browser and my pc is taking up to 8 minutes to start up, and even 5 minutes just to load my homepage (yahoo), very low performance… PLZ NEED HELP and itll be really appreciated…

HJT LOG:

Logfile of HijackThis v1.99.1
Scan saved at 14:53, on 2007-09-27
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Apache Group\Tomcat 4.1\bin\tomcat.exe
C:\Archivos de programa\IVT Corporation\BlueSoleil\BTNtService.exe
c:\archiv~1\mcafee\mcafee antispyware\massrv.exe
c:\archivos de programa\mcafee.com\agent\mcdetect.exe
c:\ARCHIV~1\mcafee.com\agent\mctskshd.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\ARCHIV~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Archivos de programa\Java\jre1.5.0_06\bin\jusched.exe
c:\archiv~1\mcafee.com\vso\mcvsescn.exe
C:\ARCHIV~1\McAfee\SPAMKI~1\MSKAgent.exe
C:\ARCHIV~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Archivos de programa\Winamp\winampa.exe
C:\archiv~1\mcafee\MCAFEE~3\masalert.exe
C:\Archivos de programa\D-Tools\daemon.exe
C:\Archivos de programa\QuickTime\qttask.exe
C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe
C:\Archivos de programa\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe
C:\Archivos de programa\McAfee\McAfee QuickClean\Plguni.exe
C:\Archivos de programa\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\ARCHIV~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Archivos de programa\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Archivos de programa\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\archiv~1\mcafee.com\vso\mcvsftsn.exe
C:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
C:\Archivos de programa\Paltalk Messenger\palstart.exe
C:\Chameleon\app\cmonitor.exe
G:\Archivos de programa\Paltalk\pnetaware.exe
C:\Archivos de programa\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Archivos de programa\Java\jre1.5.0_06\bin\jucheck.exe
C:\Archivos de programa\MSN Messenger\usnsvc.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: MSVPS System - {428FA4A4-C8EC-427C-85DE-11C80F67893A} - C:\WINDOWS\div32.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Archivos de programa\MSN Apps\ST1.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Archivos de programa\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\es-la\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\es-la\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\archiv~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar2.dll
O3 - Toolbar: The advpn - {E99D4D0C-EB54-46AF-B62A-3AA1F31D53E5} - C:\WINDOWS\advpn.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\ARCHIV~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\ARCHIV~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\ARCHIV~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\ARCHIV~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\ARCHIV~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\ARCHIV~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFExe] C:\ARCHIV~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Archivos de programa\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Archivos de programa\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [WinampAgent] C:\Archivos de programa\Winamp\winampa.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\archiv~1\mcafee\MCAFEE~3\masalert.exe
O4 - HKLM\..\Run: [SemanticInsight] C:\Archivos de programa\RXToolBar\Semantic Insight\SemanticInsight.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Archivos de programa\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [HP Software Update] C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [McRegWiz] c:\ARCHIV~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Archivos de programa\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Archivos de programa\McAfee\McAfee QuickClean\Plguni.exe /START
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\ARCHIV~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKCU\..\Run: [comrepl] C:\WINDOWS\system32\comrepl.exe
O4 - HKCU\..\Run: [swg] C:\Archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Archivos de programa\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Chameleon Monitor.lnk = C:\Chameleon\app\cmonitor.exe
O4 - Startup: PalNetaware.lnk = G:\Archivos de programa\Paltalk\pnetaware.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: PalStart.lnk = C:\Archivos de programa\Paltalk Messenger\palstart.exe
O8 - Extra context menu item: &Search - http://kv.bar.need2find.com/KV/menusearch.html?p=KV
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enlace de descarga usando Mega Manager… - C:\Archivos de programa\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Archivos de programa\Yahoo!\Messenger\yhexbmeses.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Archivos de programa\Yahoo!\Messenger\yhexbmeses.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Archivos de programa\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) - http://secure2.comned.com/signuptemplates/AktiveSekurity.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…tg.1.0.0.33.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\ARCHIV~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Archivos de programa\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: mssql - {18AA9718-A3DE-4169-87D9-E342C41709C6} - C:\WINDOWS\mssql.dll
O21 - SSODL: msmhost - {B1BDE2B6-4655-476A-B8AE-3A289EF68A43} - C:\WINDOWS\msmhost.dll (file missing)
O21 - SSODL: msmdev - {7E47AD17-4F70-4C9C-8B1F-920E074D17FB} - C:\WINDOWS\msmdev.dll (file missing)
O23 - Service: Apache Tomcat 4.1 - Alexandria Software Consulting - C:\Archivos de programa\Apache Group\Tomcat 4.1\bin\tomcat.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Archivos de programa\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\archiv~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\archivos de programa\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\ARCHIV~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARCHIV~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARCHIV~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\ARCHIV~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\ARCHIV~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\ARCHIV~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

ANY HELP WILL BE MUCH APPRECIATED …. THanks

HEy some nre pop up antivirus and scan is coming up again PL HELP (and about the browser toolbar its advpn not adbpn)

new HJT log :

Logfile of HijackThis v1.99.1
Scan saved at 18:55, on 2007-09-27
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Apache Group\Tomcat 4.1\bin\tomcat.exe
C:\Archivos de programa\IVT Corporation\BlueSoleil\BTNtService.exe
c:\archiv~1\mcafee\mcafee antispyware\massrv.exe
c:\archivos de programa\mcafee.com\agent\mcdetect.exe
c:\ARCHIV~1\mcafee.com\agent\mctskshd.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\ARCHIV~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Archivos de programa\Java\jre1.5.0_06\bin\jusched.exe
c:\archiv~1\mcafee.com\vso\mcvsescn.exe
C:\ARCHIV~1\McAfee\SPAMKI~1\MSKAgent.exe
C:\ARCHIV~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Archivos de programa\Winamp\winampa.exe
C:\archiv~1\mcafee\MCAFEE~3\masalert.exe
C:\Archivos de programa\D-Tools\daemon.exe
C:\Archivos de programa\QuickTime\qttask.exe
C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe
C:\Archivos de programa\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe
C:\Archivos de programa\McAfee\McAfee QuickClean\Plguni.exe
C:\Archivos de programa\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\ARCHIV~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Archivos de programa\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Archivos de programa\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\archiv~1\mcafee.com\vso\mcvsftsn.exe
C:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
C:\Archivos de programa\Paltalk Messenger\palstart.exe
C:\Chameleon\app\cmonitor.exe
G:\Archivos de programa\Paltalk\pnetaware.exe
C:\Archivos de programa\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Archivos de programa\Java\jre1.5.0_06\bin\jucheck.exe
C:\Archivos de programa\MSN Messenger\usnsvc.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: MSVPS System - {428FA4A4-C8EC-427C-85DE-11C80F67893A} - C:\WINDOWS\div32.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Archivos de programa\MSN Apps\ST1.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Archivos de programa\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\es-la\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\es-la\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\archiv~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar2.dll
O3 - Toolbar: The advpn - {E99D4D0C-EB54-46AF-B62A-3AA1F31D53E5} - C:\WINDOWS\advpn.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\ARCHIV~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\ARCHIV~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\ARCHIV~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\ARCHIV~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\ARCHIV~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\ARCHIV~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFExe] C:\ARCHIV~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Archivos de programa\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Archivos de programa\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [WinampAgent] C:\Archivos de programa\Winamp\winampa.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\archiv~1\mcafee\MCAFEE~3\masalert.exe
O4 - HKLM\..\Run: [SemanticInsight] C:\Archivos de programa\RXToolBar\Semantic Insight\SemanticInsight.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Archivos de programa\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [HP Software Update] C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [McRegWiz] c:\ARCHIV~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Archivos de programa\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Archivos de programa\McAfee\McAfee QuickClean\Plguni.exe /START
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\ARCHIV~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKCU\..\Run: [comrepl] C:\WINDOWS\system32\comrepl.exe
O4 - HKCU\..\Run: [swg] C:\Archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Archivos de programa\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Chameleon Monitor.lnk = C:\Chameleon\app\cmonitor.exe
O4 - Startup: PalNetaware.lnk = G:\Archivos de programa\Paltalk\pnetaware.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: PalStart.lnk = C:\Archivos de programa\Paltalk Messenger\palstart.exe
O8 - Extra context menu item: &Search - http://kv.bar.need2find.com/KV/menusearch.html?p=KV
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enlace de descarga usando Mega Manager… - C:\Archivos de programa\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Archivos de programa\Yahoo!\Messenger\yhexbmeses.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Archivos de programa\Yahoo!\Messenger\yhexbmeses.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Archivos de programa\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) - http://secure2.comned.com/signuptemplates/AktiveSekurity.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…tg.1.0.0.33.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\ARCHIV~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Archivos de programa\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: mssql - {18AA9718-A3DE-4169-87D9-E342C41709C6} - C:\WINDOWS\mssql.dll
O21 - SSODL: msmhost - {B1BDE2B6-4655-476A-B8AE-3A289EF68A43} - C:\WINDOWS\msmhost.dll (file missing)
O21 - SSODL: msmdev - {7E47AD17-4F70-4C9C-8B1F-920E074D17FB} - C:\WINDOWS\msmdev.dll (file missing)
O23 - Service: Apache Tomcat 4.1 - Alexandria Software Consulting - C:\Archivos de programa\Apache Group\Tomcat 4.1\bin\tomcat.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Archivos de programa\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\archiv~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\archivos de programa\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\ARCHIV~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARCHIV~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARCHIV~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\ARCHIV~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\ARCHIV~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\ARCHIV~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

THANKS IN ADVANCE
Hi Moe_.. and welcome to the forums.

My name is Dave. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can sometimes take a while to research so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • NOTE:Before we start: Please be aware that removing Malware is a hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.
In light of this it would be wise for you to back up any files and folders that you don't want to lose before we start, if possible.

———————————————————————

Appears to be Smitfraud infection.

Please download SmitfraudFix (by S!Ri) to your Desktop.

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.


Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm
Hey IndiGenus thanks a lot for helping out… ok i downloaded smitfraudfix, and did the search, and this is what it showed: SmitFraudFix v2.231 Scan done at 0:15:50.81, 2007-09-28 Run from C:\Documents and Settings\Mohamed\Escritorio\SmitfraudFix OS: Microsoft Windows XP [Versi¢n 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Archivos de programa\Apache Group\Tomcat 4.1\bin\tomcat.exe C:\Archivos de programa\IVT Corporation\BlueSoleil\BTNtService.exe c:\archiv~1\mcafee\mcafee antispyware\massrv.exe c:\archivos de programa\mcafee.com\agent\mcdetect.exe c:\ARCHIV~1\mcafee.com\agent\mctskshd.exe C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE C:\ARCHIV~1\McAfee.com\PERSON~1\MPFSERVICE.exe C:\Archivos de programa\Java\jre1.5.0_06\bin\jusched.exe c:\archiv~1\mcafee.com\vso\mcvsescn.exe C:\ARCHIV~1\McAfee\SPAMKI~1\MSKAgent.exe C:\ARCHIV~1\McAfee.com\PERSON~1\MpfTray.exe C:\Archivos de programa\Winamp\winampa.exe C:\archiv~1\mcafee\MCAFEE~3\masalert.exe C:\Archivos de programa\D-Tools\daemon.exe C:\Archivos de programa\QuickTime\qttask.exe C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe C:\Archivos de programa\Eset\nod32kui.exe C:\WINDOWS\system32\ctfmon.exe C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe C:\Archivos de programa\McAfee\McAfee QuickClean\Plguni.exe C:\Archivos de programa\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\ARCHIV~1\McAfee.com\PERSON~1\MpfAgent.exe C:\Archivos de programa\Eset\nod32krn.exe C:\WINDOWS\System32\nvsvc32.exe C:\Archivos de programa\Yahoo!\Messenger\ymsgr_tray.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe c:\archiv~1\mcafee.com\vso\mcvsftsn.exe C:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe C:\Archivos de programa\Paltalk Messenger\palstart.exe C:\Chameleon\app\cmonitor.exe G:\Archivos de programa\Paltalk\pnetaware.exe C:\Archivos de programa\HP\Digital Imaging\bin\hpqSTE08.exe C:\Archivos de programa\Java\jre1.5.0_06\bin\jucheck.exe C:\Archivos de programa\MSN Messenger\usnsvc.exe C:\Archivos de programa\Internet Explorer\iexplore.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS C:\WINDOWS\mssql.dll FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Mohamed »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Mohamed\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Mohamed\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Archivos de programa »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="Mi p gina de inicio actual" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\ARCHIV~1\\Google\\GOOGLE~3\\GOEC62~1.DLL" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: NIC Fast Ethernet PCI Familia RTL8139 de Realtek - Minipuerto del administrador de paquetes DNS Server Search Order: 200.44.32.12 DNS Server Search Order: 200.11.248.12 HKLM\SYSTEM\CCS\Services\Tcpip\..\{D4255FE7-61EE-4176-B32D-969BE7660FE2}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{D4255FE7-61EE-4176-B32D-969BE7660FE2}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\..\{D4255FE7-61EE-4176-B32D-969BE7660FE2}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Please copy the fix to Notepad/Word, or print it, because you won't always have internet access!

Step 1: Download AVG Anti-Spyware
Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
IMPORTANT! Do not scan yet with AVG Anti-Spyware! We will do this later.

Step 2: Boot into Safe Mode
Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
Step 3: Run SmitfraudFix
Double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

Step 4: Delete Temporary files
Navigate to C:\Windows\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Navigate to C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Clean out your Temporary Internet files. Proceed like this:

Quit Internet Explorer, all browsers and quit any instances of Windows Explorer.

For Internet Explorer 7
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete… under Browsing History.
  • Next to Temporary Internet Files, click Delete files, and then click OK.
  • Next to Cookies, click Delete cookies, and then click OK.
  • Next to History, click Delete history, and then click OK.
  • Click the Close button.
  • Click OK.
For Internet Explorer 4.x - 6.x
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box, and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
For Netscape 4.x and Up
  • Click Edit from the Netscape menubar.
  • Click Preferences… from the Edit menu.
  • Expand the Advanced menu by clicking the triangle sign.
  • Click Cache.
  • Click both the Clear Memory Cache and the Clear Disk Cache buttons.
For Mozilla 1.x and Up
  • Click Edit from the Mozilla menubar.
  • Click Preferences… from the Edit menu.
  • Expand the Advanced menu by clicking the plus sign.
  • Click Cache.
  • Click the Clear Cache button.
For Opera
  • Click File from the Opera menubar.
  • Click Preferences… from the File menu.
  • Click the History and Cache menu.
  • Click the two Clear buttons next to Typed in addresses and Visited addresses (history) and click the Empty now button to clear the Disk cache.
  • Click Ok to close the Preferences menu.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.

Step 5: Run AVG Anti-Spyware
Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Step 6: Reboot your computer
It'll automatically switch to Normal Mode.

Step 7: Post logs
Please post:
  • c:\rapport.txt
  • AVG log
  • Fresh HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
OK, Gonna start working on it right away, but just just to let u know, it even changed my wallapaper (windows xp view) to a some kind of web pic in red sayingbuy some privacy protector, and computer performance is so low. Anyways gonna start working on what u said, and ill be posting all the logs you asked for….
Yes, that's perfectly normal for a Smitfraud infection. That's one of the many wonderful things it does. Don't worry, we'll get that fixed. Just move ahead.
Hi Dave, i did some of what u told me, but i had trouble in step 4, cz in C:\windows\temp i couldnt erase, or it wont erase a folder named hsperfdata_SYSTEM, and inside it there is an unknown file named 488.
and in the same step 4in c:\documents and settings\(every listed user)\local setting\temp, well i checked in all users and i have no folder called local setting therefor no temp folder, so i couldnt erase anything there.

and the last thing, i did the scan thing with avg, it finished up (took almost 4 hours), so following ur guide, i applied all actions and then was going to save report, but just when i clicked on applied action, the computer just jammed (waited almost 20 minutes and nothing its just woudlnt do anything), but all i can tell u from what i saw there were 45 infected objets 5 high risk and the rest medium risk, (it said some were deleted and others quarantine),and found 1,1153 traces…. Anyways im gonna do the scan on the sleep time and ill post it right away (cz it takes a lot of time)… or any other idea?…. so anyways im gonna post the rapport.txt from smitfraudfix and the fresh hijackthis log….and when the avg scanning is done ill post it too, hope this time it doesnt jam when i click on apply all actions..

rapport.txt from smitfraudfix

SmitFraudFix v2.2


Scan done at 17:33:47.46, 2007-09-28
Run from C:\Documents and Settings\Mohamed\Escritorio\SmitfraudFix
OS: Microsoft Windows XP [Versi¢n 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{D4255FE7-61EE-4176-B32D-969BE7660FE2}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS1\Services\Tcpip\..\{D4255FE7-61EE-4176-B32D-969BE7660FE2}: DhcpNameServer=[removed] [removed]
HKLM\SYSTEM\CS3\Services\Tcpip\..\{D4255FE7-61EE-4176-B32D-969BE7660FE2}: DhcpNameServer=[removed] [removed]


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End


And the HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 22:10, on 2007-09-28
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos de programa\Java\jre1.5.0_06\bin\jusched.exe
c:\archiv~1\mcafee.com\vso\mcvsescn.exe
C:\ARCHIV~1\McAfee\SPAMKI~1\MSKAgent.exe
C:\ARCHIV~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Archivos de programa\Winamp\winampa.exe
C:\archiv~1\mcafee\MCAFEE~3\masalert.exe
C:\Archivos de programa\D-Tools\daemon.exe
C:\Archivos de programa\QuickTime\qttask.exe
C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\McAfee\McAfee QuickClean\Plguni.exe
C:\Archivos de programa\Apache Group\Tomcat 4.1\bin\tomcat.exe
C:\Archivos de programa\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
C:\Archivos de programa\IVT Corporation\BlueSoleil\BTNtService.exe
c:\archiv~1\mcafee\mcafee antispyware\massrv.exe
C:\ARCHIV~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\archivos de programa\mcafee.com\agent\mcdetect.exe
C:\Archivos de programa\Yahoo!\Messenger\ymsgr_tray.exe
c:\ARCHIV~1\mcafee.com\agent\mctskshd.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\ARCHIV~1\McAfee.com\PERSON~1\MPFSERVICE.exe
c:\archiv~1\mcafee.com\vso\mcvsftsn.exe
C:\Archivos de programa\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Archivos de programa\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\svchost.exe
C:\Archivos de programa\Messenger\msmsgs.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Paltalk Messenger\palstart.exe
C:\Chameleon\app\cmonitor.exe
G:\Archivos de programa\Paltalk\pnetaware.exe
C:\Archivos de programa\Java\jre1.5.0_06\bin\jucheck.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\Archivos de programa\MSN Messenger\usnsvc.exe
C:\HJT\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Archivos de programa\MSN Apps\ST1.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Archivos de programa\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\es-la\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\es-la\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\archiv~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\ARCHIV~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\ARCHIV~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\ARCHIV~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\ARCHIV~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\ARCHIV~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\ARCHIV~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFExe] C:\ARCHIV~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Archivos de programa\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Archivos de programa\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [WinampAgent] C:\Archivos de programa\Winamp\winampa.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\archiv~1\mcafee\MCAFEE~3\masalert.exe
O4 - HKLM\..\Run: [SemanticInsight] C:\Archivos de programa\RXToolBar\Semantic Insight\SemanticInsight.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Archivos de programa\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [HP Software Update] C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [McRegWiz] c:\ARCHIV~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Archivos de programa\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Archivos de programa\McAfee\McAfee QuickClean\Plguni.exe /START
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\ARCHIV~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKCU\..\Run: [comrepl] C:\WINDOWS\system32\comrepl.exe
O4 - HKCU\..\Run: [swg] C:\Archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Archivos de programa\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Chameleon Monitor.lnk = C:\Chameleon\app\cmonitor.exe
O4 - Startup: PalNetaware.lnk = G:\Archivos de programa\Paltalk\pnetaware.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: PalStart.lnk = C:\Archivos de programa\Paltalk Messenger\palstart.exe
O8 - Extra context menu item: &Search - http://kv.bar.need2find.com/KV/menusearch.html?p=KV
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enlace de descarga usando Mega Manager… - C:\Archivos de programa\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Archivos de programa\Yahoo!\Messenger\yhexbmeses.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Archivos de programa\Yahoo!\Messenger\yhexbmeses.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Archivos de programa\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) - http://secure2.comned.com/signuptemplates/AktiveSekurity.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…tg.1.0.0.33.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\ARCHIV~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Archivos de programa\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apache Tomcat 4.1 - Alexandria Software Consulting - C:\Archivos de programa\Apache Group\Tomcat 4.1\bin\tomcat.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Archivos de programa\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\archiv~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\archivos de programa\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\ARCHIV~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARCHIV~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARCHIV~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\ARCHIV~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\ARCHIV~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\ARCHIV~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
ohhh by the way i did step 3 , two times by mistake :s here its the raapot.txt , the first time i did smitfraudfix SmitFraudFix v2.231 Scan done at 17:29:37.35, 2007-09-28 Run from C:\Documents and Settings\Mohamed\Escritorio\SmitfraudFix OS: Microsoft Windows XP [Versi¢n 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\privacy_danger\ Deleted »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{D4255FE7-61EE-4176-B32D-969BE7660FE2}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{D4255FE7-61EE-4176-B32D-969BE7660FE2}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\..\{D4255FE7-61EE-4176-B32D-969BE7660FE2}: DhcpNameServer=[removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll
Hi, Yes, that second log looks more like it. If you aren't able to get through AVG AS the next time it's run the use your SUPERAntiSpyware program to do a full scan. Make sure it's up to date first. I'm not as familiar with it but I know many experts advise it's use in cases like this. Another observation and something I missed the first look. You appear to have 2 Antivirus programs running, McAfee and NOD32. Running 2 antivirus programs can cause system slowdown issues, conflicts, false positives, ect… I recommend you remove one of them or at least disable real time protection on one. The other items you had problems with don't worry about. ATFCleaner should take care of those things.
hey once again, and thanks for the time Ok i will try again the avg as again at night time, if it does jam again, ill go with the superantispyware (does this one make a report)… Yes its true that i have 2 antivirus programs running, and the nod32 i added it 3 days ago when the whole virus thing on the pc started, haha nerves to get rid of it, and ppl just recommended it to me, anyways which one do u recommend me to keep using, the mcafee or the nod32, and by the way thing is that the mcafee isnt so updated, but it has the firewall included its the whole pack, while the nod32 its just an antivirus (I THINK), or do u know any good free firewall, so i can delete the whole out to dat mcafee central security?so what would u recommend me?
Well I make it a habit not to advise on which AV programs to use. I just recommend. The fact that McAfee isn't updated, and I assume the subscription ran out, is a problem. So if you don't renew that then I would go with Nod32. But you have to make sure it's updated. I will advise on some good free firewalls at the end when your all clean. Remind me if I forget.
Hi Dave…

well the thing with the avg AS didnt work, everytime i drt it to quarantine and click on apply all actions the pc just jams, i tried 3 times, therefore i cant save report cz it jams at apply all actions… so anyways i used superantispyware like u told me and here its the log:

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/27/2007 at 08:20 AM

Application Version : 3.9.1008

Core Rules Database Version : 3314
Trace Rules Database Version: 1316

Scan type : Complete Scan
Total Scan Time : 04:37:31

Memory items scanned : 519
Memory threats detected : 0
Registry items scanned : 5635
Registry threats detected : 50
File items scanned : 75017
File threats detected : 317

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{2AB289AE-4B90-4281-B2AE-1F4BB034B647}
HKCR\CLSID\{2AB289AE-4B90-4281-B2AE-1F4BB034B647}
HKCR\CLSID\{2AB289AE-4B90-4281-B2AE-1F4BB034B647}
HKCR\CLSID\{2AB289AE-4B90-4281-B2AE-1F4BB034B647}\InprocServer32
HKCR\CLSID\{2AB289AE-4B90-4281-B2AE-1F4BB034B647}\InprocServer32#ThreadingModel
HKCR\CLSID\{2AB289AE-4B90-4281-B2AE-1F4BB034B647}\KeyPhrasesFileName
HKCR\CLSID\{2AB289AE-4B90-4281-B2AE-1F4BB034B647}\ProgID
HKCR\CLSID\{2AB289AE-4B90-4281-B2AE-1F4BB034B647}\VersionIndependentProgID
C:\ARCHIVOS DE PROGRAMA\RXTOOLBAR\SFCONT.DLL
HKLM\Software\Classes\CLSID\{4D1C4E81-A32A-416b-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}\InprocServer32
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}\InprocServer32#ThreadingModel
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}\Programmable
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}\TypeLib
C:\ARCHIVOS DE PROGRAMA\NEED2FIND\BAR\2.BIN\ND2FNBAR.DLL
HKLM\Software\Classes\CLSID\{4D1C4E89-A32A-416b-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E89-A32A-416B-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E89-A32A-416B-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E89-A32A-416B-BCDB-33B3EF3617D3}\InprocServer32
HKCR\CLSID\{4D1C4E89-A32A-416B-BCDB-33B3EF3617D3}\InprocServer32#ThreadingModel
HKCR\CLSID\{4D1C4E89-A32A-416B-BCDB-33B3EF3617D3}\Programmable
HKCR\CLSID\{4D1C4E89-A32A-416B-BCDB-33B3EF3617D3}\TypeLib
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D1C4E81-A32A-416b-BCDB-33B3EF3617D3}

Adware.RX Toolbar
HKLM\Software\Classes\CLSID\{59879FA4-4790-461c-A1CC-4EC4DE4CA483}
HKCR\CLSID\{59879FA4-4790-461C-A1CC-4EC4DE4CA483}
HKCR\CLSID\{59879FA4-4790-461C-A1CC-4EC4DE4CA483}
HKCR\CLSID\{59879FA4-4790-461C-A1CC-4EC4DE4CA483}\InprocServer32
HKCR\CLSID\{59879FA4-4790-461C-A1CC-4EC4DE4CA483}\InprocServer32#ThreadingModel
HKCR\CLSID\{59879FA4-4790-461C-A1CC-4EC4DE4CA483}\ProgID
HKCR\CLSID\{59879FA4-4790-461C-A1CC-4EC4DE4CA483}\VersionIndependentProgID
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59879FA4-4790-461c-A1CC-4EC4DE4CA483}

Adware.Tracking Cookie
C:\Documents and Settings\Mohamed\Cookies\mohamed@yadro[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@specificclick[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@realmedia[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed]-auditions[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@a[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@73599386[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@cgi-bin[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@xiti[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@porn-blog[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@keywordmax[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@drivecleaner[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@54528310[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@adrevolver[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@adultadworld[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@statcounter[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@cassava[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@clicktorrent[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@23844616[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@adinterax[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@serving-sys[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@clicksor[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@partypoker[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@zedo[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@revsci[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@cgi-bin[4].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@www.3d-sexgames[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@indexstats[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@adrevolver[3].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@cgi-bin[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@azjmp[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@888[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed]-sys[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@adbrite[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@adultdvdtalk[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@ex=1_[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed].e-planning[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@casalemedia[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@www.888[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@tacoda[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@weborama[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@www.w3counter[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@burstnet[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed]-affiliate[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@3d-sexgames[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@xxxuploads[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@adecn[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@pornotube[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@goclick[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@web-stat[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@adserver[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@toplist[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@euros4click[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@tripod[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@sexinfo101[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@atwola[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@rambler[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@67.15.239[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@plugs[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@porngata[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@tracking.web2corp[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@fortunecity[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@roiservice[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@6427088[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@nextag[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@adultrental[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@ex=1[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@cgi-bin[3].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@alladultchannel[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@gostats[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@pornstarxs[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@55997340[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@qnsr[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@687358[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed]-sex-porn-tv[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@hentaicounter[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@3d-adult-games[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@empornium[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@upspiral[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@adsrevenue[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@ad.z5x[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@epornreview[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@dealtime[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@ad[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@1056735227[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@www.3d-adult-games[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@vodpornos[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@cgi-bin[5].txt
C:\Documents and Settings\Mohamed\Cookies\[removed]-sex-sexy-gallery[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@sexreactor[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed]-counter[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@66651396[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@youporn[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@thesuperxxx[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@adult-sex-porn-tv[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed]-sexpositions[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@list[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@www.xxx69[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@apmebf[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@90874191[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@traffic-tracker[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@ad.103092804[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@44273822[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@realmedia-la[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@gamestats[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed]-flash-games[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@revenue[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@elmaestrodelporno[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@62124831[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@basic[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@adlegend[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@teensart[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@directaclick[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@s[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@worldsexmate[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@partner2profit[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@videonew[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@www.pornlinks4all[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@superstats[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@haporn[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@ats[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@1[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@windowsmedia[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@My[2].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@adbrite[2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@adknowledge[1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@adrevolver[2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@ads.hi5[1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed].e-planning[1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@adsrevenue[2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@apmebf[1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@belnk[1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@casalemedia[1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@hurricanedigitalmedia[2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@nbads[2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@realmedia[2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@revenue[1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@serving-sys[2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@smileycentral[1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@statcounter[1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@tacoda[2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@tdstats[1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@webpower[2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\[removed][2].txt
C:\Documents and Settings\Mohamed\Configuración local\Temp\Cookies\mohamed@zedo[2].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@click_track[1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@webstats[1].txt

Trojan.DNSChanger-Codec
C:\Archivos de programa\VideoAccessCodec\install.ico
C:\Archivos de programa\VideoAccessCodec\Uninstall.exe
C:\Archivos de programa\VideoAccessCodec
C:\WINDOWS\Prefetch\UNINSTALL.EXE-28DB768A.pf

Trojan.VideoCach/Gen
HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}
HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0
HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0
HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0\win32
HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0\FLAGS
HKCR\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}\1.0\HELPDIR
HKCR\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}
HKCR\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\ProxyStubClsid
HKCR\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\ProxyStubClsid32
HKCR\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\TypeLib
HKCR\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}\TypeLib#Version
HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}
HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\ProxyStubClsid
HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\ProxyStubClsid32
HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\TypeLib
HKCR\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}\TypeLib#Version

Trojan.Net-MSV/VPS
HKCR\MSVPS.MSVPSApp
HKCR\MSVPS.MSVPSApp\CLSID
HKCR\MSVPS.MSVPSApp\CurVer

Desktop Hijacker.AboutYourPrivacy
C:\Documents and Settings\Mohamed\Escritorio\Error Cleaner.url
C:\Documents and Settings\Mohamed\Escritorio\Privacy Protector.url
C:\Documents and Settings\Mohamed\Escritorio\Spyware&Malware Protection.url
C:\Documents and Settings\Mohamed\Favoritos\Error Cleaner.url
C:\Documents and Settings\Mohamed\Favoritos\Privacy Protector.url
C:\Documents and Settings\Mohamed\Favoritos\Spyware&Malware Protection.url

Adware.Need2Find
C:\ARCHIVOS DE PROGRAMA\NEED2FIND\BAR\2.BIN\NPND2FN.DLL

My Daily Horoscope
C:\Documents and Settings\Mohamed\Shared\_\MYDAIL~1.EXE

Trojan.Net-MU/Gen
C:\WINDOWS\MAIN_UNINSTALLER.EXE

Trojan.Downloader/Media-Codec
E:\VIDEOACCESSCODECINSTALL.EXE
C:\WINDOWS\Prefetch\VIDEOACCESSCODECINSTALL.EXE-1EEC54DF.pf

Trace.Known Threat Sources
C:\Documents and Settings\Mohamed\Configuración local\Temp\Archivos temporales de Internet\Content.IE5\MC4PNOXN\ping[1].htm
C:\Documents and Settings\Mohamed\Configuración local\Temp\Archivos temporales de Internet\Content.IE5\2X96VATO\Fastmp3_Setup1[1].exe
C:\Documents and Settings\Mohamed\Configuración local\Temp\Archivos temporales de Internet\Content.IE5\MC4PNOXN\ping[2].htm

so there u have all 3 the smigtfraudfix rapport, the superanitspyware log, and the hjt log…

=)
Hi, Can you post a new HijackThis log as it's been a couple of days since the last one you posted. It also looks like the SAS report was done before Smitfraudfix was. Is that correct? Just going by the dates on the logs. That is fine if so. Thanks
Hey Dave, No man the superantispyware i did it yesterday at night, the smitfraud i did before yesterday when i posted it here….
OK here its a new HJT LOG

Logfile of HijackThis v1.99.1
Scan saved at 15:46, on 2007-09-30
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos de programa\Java\jre1.5.0_06\bin\jusched.exe
C:\ARCHIV~1\mcafee.com\vso\mcvsshld.exe
c:\archiv~1\mcafee.com\vso\mcvsescn.exe
C:\ARCHIV~1\McAfee\SPAMKI~1\MSKAgent.exe
C:\ARCHIV~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Archivos de programa\Winamp\winampa.exe
C:\archiv~1\mcafee\MCAFEE~3\masalert.exe
C:\Archivos de programa\Apache Group\Tomcat 4.1\bin\tomcat.exe
C:\Archivos de programa\QuickTime\qttask.exe
C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe
C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Archivos de programa\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe
C:\Archivos de programa\McAfee\McAfee QuickClean\Plguni.exe
C:\Archivos de programa\IVT Corporation\BlueSoleil\BTNtService.exe
c:\archiv~1\mcafee\mcafee antispyware\massrv.exe
C:\ARCHIV~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
c:\archivos de programa\mcafee.com\agent\mcdetect.exe
C:\Archivos de programa\Paltalk Messenger\palstart.exe
c:\ARCHIV~1\mcafee.com\agent\mctskshd.exe
C:\Chameleon\app\cmonitor.exe
c:\ARCHIV~1\mcafee.com\vso\mcvsrte.exe
G:\Archivos de programa\Paltalk\pnetaware.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Archivos de programa\Yahoo!\Messenger\ymsgr_tray.exe
C:\ARCHIV~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Archivos de programa\Eset\nod32krn.exe
C:\Archivos de programa\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
c:\archiv~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\svchost.exe
C:\Archivos de programa\Messenger\msmsgs.exe
C:\Archivos de programa\Java\jre1.5.0_06\bin\jucheck.exe
C:\Archivos de programa\MSN Messenger\usnsvc.exe
C:\Archivos de programa\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Archivos de programa\MSN Apps\ST1.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\archivos de programa\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Archivos de programa\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\es-la\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\es-la\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\archiv~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\archivos de programa\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Archivos de programa\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\ARCHIV~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\ARCHIV~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\ARCHIV~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\ARCHIV~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\ARCHIV~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\ARCHIV~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MPFExe] C:\ARCHIV~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Archivos de programa\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Archivos de programa\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [WinampAgent] C:\Archivos de programa\Winamp\winampa.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\archiv~1\mcafee\MCAFEE~3\masalert.exe
O4 - HKLM\..\Run: [SemanticInsight] C:\Archivos de programa\RXToolBar\Semantic Insight\SemanticInsight.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Archivos de programa\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Archivos de programa\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Archivos de programa\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [HP Software Update] C:\Archivos de programa\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [McRegWiz] c:\ARCHIV~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Archivos de programa\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Archivos de programa\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [McAfee QuickClean Imonitor] C:\Archivos de programa\McAfee\McAfee QuickClean\Plguni.exe /START
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\ARCHIV~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKCU\..\Run: [comrepl] C:\WINDOWS\system32\comrepl.exe
O4 - HKCU\..\Run: [swg] C:\Archivos de programa\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Chameleon Monitor.lnk = C:\Chameleon\app\cmonitor.exe
O4 - Startup: PalNetaware.lnk = G:\Archivos de programa\Paltalk\pnetaware.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Archivos de programa\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: PalStart.lnk = C:\Archivos de programa\Paltalk Messenger\palstart.exe
O8 - Extra context menu item: &Search - http://kv.bar.need2find.com/KV/menusearch.html?p=KV
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enlace de descarga usando Mega Manager… - C:\Archivos de programa\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Archivos de programa\Yahoo!\Messenger\yhexbmeses.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Archivos de programa\Yahoo!\Messenger\yhexbmeses.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Archivos de programa\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) - http://secure2.comned.com/signuptemplates/AktiveSekurity.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…tg.1.0.0.33.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.0) -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejewele…ploader_v10.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\ARCHIV~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Archivos de programa\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apache Tomcat 4.1 - Alexandria Software Consulting - C:\Archivos de programa\Apache Group\Tomcat 4.1\bin\tomcat.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Archivos de programa\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Archivos de programa\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\archiv~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\archivos de programa\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\ARCHIV~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\ARCHIV~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\ARCHIV~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\ARCHIV~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\ARCHIV~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\ARCHIV~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Uppsss you r right, i post it the wrong sas report :s, Sorry about that: didnt notice that
here it is

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/29/2007 at 11:31 PM

Application Version : 3.9.1008

Core Rules Database Version : 3314
Trace Rules Database Version: 1316

Scan type : Complete Scan
Total Scan Time : 02:56:13

Memory items scanned : 176
Memory threats detected : 0
Registry items scanned : 5643
Registry threats detected : 0
File items scanned : 73050
File threats detected : 7

Adware.Tracking Cookie
C:\Documents and Settings\Mohamed\Cookies\mohamed@xiti[1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\[removed][1].txt
C:\Documents and Settings\Mohamed\Cookies\mohamed@weborama[1].txt

Adware.PointsManager-Uninstaller
C:\PROGRAM FILES\ALTNET\DOWNLOAD MANAGER\ALTNETUNINSTALL.EXE

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI