Logfile of HijackThis v1.99.1
Scan saved at 22:58:09, on 01-12-2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\ARCHIV~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\ARCHIV~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\ARCHIV~1\Iomega\System32\AppServices.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\ARCHIV~1\Grisoft\AVGFRE~1\avgcc.exe
C:\ARCHIV~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Archivos de programa\D-Tools\daemon.exe
C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe
C:\Archivos de programa\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\ZoneLabs\vsmon.exe
C:\Archivos de programa\FlashGet\flashget.exe
C:\Archivos de programa\Webroot\Spy Sweeper\SpySweeper.exe
C:\Archivos de programa\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Archivos de programa\ReGetDx\regetdx.exe
C:\Archivos de programa\Internet Explorer\IEXPLORE.EXE
C:\HjackThis\HJT\HijackThis[www.trucoswindows.net].exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O1 - Hosts: 200.45.4.174 ogg.muchina.com
O1 - Hosts: 200.45.4.174 gg.muchina.com
O1 - Hosts: 200.45.4.174 update.nprotect.net
O1 - Hosts: 200.45.4.174 ogg.muchina.com
O1 - Hosts: 200.45.4.174 gg.muchina.com
O1 - Hosts: 200.45.4.174 update.nprotect.net
O1 - Hosts: 200.45.4.174 ogg.muchina.com
O1 - Hosts: 200.45.4.174 gg.muchina.com
O1 - Hosts: 200.45.4.174 update.nprotect.net
O1 - Hosts: 200.45.4.174 ogg.muchina.com
O1 - Hosts: 200.45.4.174 gg.muchina.com
O1 - Hosts: 200.45.4.174 update.nprotect.net
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\ARCHIV~1\FlashGet\jccatch.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\ARCHIV~1\FlashFXP\IEFlash.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\ARCHIV~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\ARCHIV~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\ARCHIV~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Archivos de programa\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Zone Labs Client] C:\Archivos de programa\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Archivos de programa\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Archivos de programa\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Archivos de programa\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Archivos de programa\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Archivos de programa\Archivos comunes\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Archivos de programa\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Archivos de programa\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Descargar con &ReGet Deluxe - C:\Archivos de programa\Archivos comunes\ReGet Shared\CC_Link.htm
O8 - Extra context menu item: Descargar todo con &ReGet Deluxe - C:\Archivos de programa\Archivos comunes\ReGet Shared\CC_All.htm
O8 - Extra context menu item: Download All by FlashGet - C:\Archivos de programa\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Archivos de programa\FlashGet\jc_link.htm
O8 - Extra context menu item: Download with NetPumper - C:\Archivos de programa\NetPumper\AddUrl.htm
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Instantánea de caché de la página - res://C:\Archivos de programa\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Páginas similares - res://C:\Archivos de programa\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Páginas vinculadas - res://C:\Archivos de programa\Google\GoogleToolbar1.dll/cmbacklinks.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\j2re1.4.1_06\bin\npjpi141_06.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\j2re1.4.1_06\bin\npjpi141_06.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Investigador - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Encarta Researcher\EROProj.dll
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARCHIV~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARCHIV~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\MSMSGS.EXE
O12 - Plugin for .dll: C:\Archivos de programa\Internet Explorer\PLUGINS\npq3plug.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cabO16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
http://www.musicnotes.com/download/mnviewer.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineS...er.cab28578.cabO16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KX-HCM10 Control) -
http://candidcamera.ecasd.k12.wi.us/kxhcm10.ocxO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by13fd.bay13.hotmail.msn.com/resources/MsnPUpld.cabO16 - DPF: {555500CD-CB54-11D6-8DB9-0000864598B3} (Diagmgr Class) -
http://isupport4.hp.com/awebui/jsp/answerw...DiagManager.CABO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Messe...StatsClient.cabO16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} -
http://l00kl23.com/default.cab?uid=87&id=5...1s&ppd=4&tag=23O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) -
http://sc.groups.msn.com/controls/FileUC/MsnUpld.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMesse...pDownloader.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://cdn2.zone.msn.com/binFramework/v10/...ro.cab34246.cabO16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
http://us.dl1.yimg.com/download.yahoo.com/...utocomplete.cabO16 - DPF: {C4660846-8760-4852-8154-82438E33E383} (FileSharingCtrl Class) -
http://appdirectory.messenger.msn.com/AppD...sharingctrl.cabO16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) -
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -
http://fdl.msn.com/zone/datafiles/heartbeat.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\ARCHIV~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Archivos de programa\Archivos comunes\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARCHIV~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARCHIV~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Archivos de programa\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\ARCHIV~1\Iomega\System32\AppServices.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Archivos de programa\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Archivos de programa\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
********
20:21: | Start of Session, Jueves, 01 de Diciembre de 2005 |
20:21: Spy Sweeper started
20:21: Sweep initiated using definitions version 576
20:21: Starting Memory Sweep
20:33: Memory Sweep Complete, Elapsed Time: 00:12:21
20:33: Starting Registry Sweep
20:35: Found Adware: dealhelper
20:35: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/dhsigned.ocx\ (ID = 124794)
20:35: Found Adware: instant access
20:35: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/system32/p2ecom.dll\ (ID = 128807)
20:36: Found Adware: ist istbar
20:36: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\istactivex.dll (ID = 129174)
20:36: Found Trojan Horse: magiccontrol
20:36: HKCR\clsid\{4a6fa2eb-f381-4503-87d0-be4cc57deb8e}\ (7 subtraces) (ID = 134658)
20:36: HKCR\interface\{0fd5fdc2-2080-4c47-9e7a-724a6201551b}\ (5 subtraces) (ID = 134663)
20:36: HKCR\interface\{4c7f0895-6fd8-46ee-880e-053df58ddae3}\ (5 subtraces) (ID = 134665)
20:36: HKCR\interface\{510c3373-4842-4944-8729-0aff6725a132}\ (8 subtraces) (ID = 134668)
20:36: HKCR\mslagent.3.1\ (3 subtraces) (ID = 134671)
20:36: HKCR\mslagent.3\ (3 subtraces) (ID = 134672)
20:36: HKCR\navipromo.egnaviscoring.1\ (3 subtraces) (ID = 134675)
20:36: HKCR\navipromo.egnaviscoring\ (3 subtraces) (ID = 134676)
20:36: HKLM\software\classes\clsid\{4a6fa2eb-f381-4503-87d0-be4cc57deb8e}\ (7 subtraces) (ID = 134681)
20:36: HKLM\software\classes\interface\{0fd5fdc2-2080-4c47-9e7a-724a6201551b}\ (5 subtraces) (ID = 134686)
20:36: HKLM\software\classes\interface\{4c7f0895-6fd8-46ee-880e-053df58ddae3}\ (5 subtraces) (ID = 134688)
20:36: HKLM\software\classes\interface\{510c3373-4842-4944-8729-0aff6725a132}\ (8 subtraces) (ID = 134691)
20:36: HKLM\software\classes\mslagent.3.1\ (3 subtraces) (ID = 134693)
20:36: HKLM\software\classes\mslagent.3\ (3 subtraces) (ID = 134694)
20:36: HKLM\software\classes\navipromo.egnaviscoring.1\ (3 subtraces) (ID = 134697)
20:36: HKLM\software\classes\navipromo.egnaviscoring\ (3 subtraces) (ID = 134698)
20:36: HKLM\software\classes\typelib\{5630b768-1c09-4105-9e03-e35985e36b0b}\ (5 subtraces) (ID = 134702)
20:36: HKCR\typelib\{5630b768-1c09-4105-9e03-e35985e36b0b}\ (5 subtraces) (ID = 134711)
20:36: Found Adware: elitemediagroup-mediamotor
20:36: HKLM\software\classes\typelib\{466c63ac-f26e-49f1-861a-e07da768a46a}\ (9 subtraces) (ID = 140131)
20:36: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/m67m.ocx\ (2 subtraces) (ID = 140170)
20:36: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\m67m.ocx (ID = 140199)
20:36: HKCR\typelib\{466c63ac-f26e-49f1-861a-e07da768a46a}\ (9 subtraces) (ID = 140223)
20:36: Found Trojan Horse: sdbot
20:36: HKU\.default\software\microsoft\windows\currentversion\run\ || microsoft windows update (ID = 140586)
20:36: HKU\.default\software\microsoft\windows\currentversion\run\ || svphost.exe (ID = 140587)
20:36: HKU\.default\software\microsoft\windows\currentversion\runonce\ || microsoft windows update (ID = 140592)
20:36: HKLM\system\currentcontrolset\services\microsoft update\ (13 subtraces) (ID = 140657)
20:36: Found Adware: topsearch
20:36: HKLM\software\classes\typelib\{edd3b3e9-3ffd-4836-a6de-d4a9c473a971}\ (9 subtraces) (ID = 143928)
20:36: HKCR\typelib\{edd3b3e9-3ffd-4836-a6de-d4a9c473a971}\ (9 subtraces) (ID = 143930)
20:36: Found Trojan Horse: trojan-backdoor-soundcheck
20:36: HKLM\system\currentcontrolset\services\msdirectx\ (7 subtraces) (ID = 144200)
20:36: Found Adware: winad
20:36: HKLM\software\windows adstatus\ (4 subtraces) (ID = 147240)
20:36: Found Adware: ist software
20:36: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/ysbactivex.dll\ (2 subtraces) (ID = 147854)
20:36: Found Adware: ist yoursitebar
20:36: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\ysbactivex.dll (ID = 147857)
20:36: Found Adware: surf accuracy
20:36: HKLM\software\sacc\ (5 subtraces) (ID = 203068)
20:36: HKLM\software\microsoft\windows\currentversion\uninstall\sacc\ (2 subtraces) (ID = 203070)
20:36: HKLM\software\media gateway\ (8 subtraces) (ID = 359545)
20:36: Found Adware: directrevenue-abetterinternet
20:36: HKCR\aurorahandlerdll.aurorahandlerdllobj\ (5 subtraces) (ID = 359578)
20:36: HKCR\aurorahandlerdll.aurorahandlerdllobj.1\ (3 subtraces) (ID = 359584)
20:36: HKLM\software\classes\aurorahandlerdll.aurorahandlerdllobj\ (5 subtraces) (ID = 359725)
20:36: HKLM\software\classes\aurorahandlerdll.aurorahandlerdllobj.1\ (3 subtraces) (ID = 359731)
20:36: HKLM\software\classes\typelib\{6d992911-b563-47fc-ab29-437f42d1c729}\ (9 subtraces) (ID = 359756)
20:36: HKCR\aurorahandlerdll.aurorahandlerdllobj\ (5 subtraces) (ID = 360169)
20:36: HKCR\mediagatewayx.installer\ (3 subtraces) (ID = 372857)
20:36: HKCR\mediagatewayx.installer\clsid\ (1 subtraces) (ID = 372859)
20:36: HKLM\software\classes\mediagatewayx.installer\ (3 subtraces) (ID = 398902)
20:36: HKLM\software\classes\mediagatewayx.installer\clsid\ (1 subtraces) (ID = 398904)
20:36: HKCR\interface\{544b6a3f-4024-4403-9661-69b8410be505}\ (8 subtraces) (ID = 479497)
20:36: HKCR\typelib\{6d992911-b563-47fc-ab29-437f42d1c729}\ (9 subtraces) (ID = 480791)
20:36: Found Adware: 7adpower
20:36: HKCR\vacpro.internazionale_ver15\ (3 subtraces) (ID = 483863)
20:36: HKCR\typelib\{97794ca1-fd62-4485-bdb0-9d878f24b4a4}\ (9 subtraces) (ID = 483895)
20:36: HKLM\software\classes\vacpro.internazionale_ver15\ (3 subtraces) (ID = 483936)
20:36: HKLM\software\classes\typelib\{97794ca1-fd62-4485-bdb0-9d878f24b4a4}\ (9 subtraces) (ID = 483937)
20:36: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/mediagatewayx.dll\ (2 subtraces) (ID = 763026)
20:36: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\mediagatewayx.dll (ID = 763028)
20:36: HKCR\clsid\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8}\ (6 subtraces) (ID = 815132)
20:36: HKLM\software\classes\clsid\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8}\ (6 subtraces) (ID = 815145)
20:36: Found Adware: 180search assistant/zango
20:36: HKLM\software\microsoft\code store database\distribution units\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8}\ (9 subtraces) (ID = 832871)
20:36: Found Trojan Horse: spamrelayer_alpiok
20:36: HKCR\clsid\{6368d1fc-6f5c-4f1b-b164-e67214f678e9}\ (3 subtraces) (ID = 945518)
20:36: HKLM\software\classes\clsid\{6368d1fc-6f5c-4f1b-b164-e67214f678e9}\ (3 subtraces) (ID = 945546)
20:36: HKLM\software\microsoft\windows\currentversion\shellserviceobjectdelayload\ || systray.exbr (ID = 945548)
20:36: Found Adware: spad
20:36: HKU\S-1-5-21-1614895754-616249376-725345543-1006\software\microsoft\internet explorer\menuext\shorten url\ (1 subtraces) (ID = 141891)
20:36: HKU\S-1-5-21-1614895754-616249376-725345543-1006\software\aurorahandler\ (19 subtraces) (ID = 360172)
20:36: HKU\S-1-5-21-1614895754-616249376-725345543-1006\software\aurorahandler\ (19 subtraces) (ID = 480802)
20:36: HKU\S-1-5-21-1614895754-616249376-725345543-1006\software\aurorahandler\ || aut9i1m4eofsfinalad (ID = 512963)
20:36: Found Adware: ebates money maker
20:36: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\microsoft\internet explorer\extensions\cmdmapping\ || {6685509e-b47b-4f47-8e16-9a5f3a62f683} (ID = 125587)
20:36: Found Adware: webrebates
20:36: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\microsoft\internet explorer\extensions\{6685509e-b47b-4f47-8e16-9a5f3a62f683}\ (6 subtraces) (ID = 125589)
20:36: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\microsoft\internet explorer\extensions\{6685509e-b47b-4f47-8e16-9a5f3a62f683}\ (6 subtraces) (ID = 125589)
20:36: Found Adware: dashbar hijack
20:36: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\microsoft\internet explorer\main\ || search bar (ID = 126821)
20:36: Found Adware: instafinder
20:36: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\instafink\ (199 subtraces) (ID = 128666)
20:36: Found Adware: internetoptimizer
20:36: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\avenue media\ (ID = 128887)
20:37: Found Trojan Horse: spooner-a
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\microsoft\windows\currentversion\run\ || sp (ID = 142057)
20:37: Found Adware: spysheriff
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\microsoft\windows\currentversion\run\ || spysheriff (ID = 142123)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\spysheriff\ (30 subtraces) (ID = 142125)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\microsoft\windows\currentversion\run\ || windows installer (ID = 142127)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\aurorahandler\ (19 subtraces) (ID = 360172)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\aurorahandler\ (19 subtraces) (ID = 480802)
20:37: Found Trojan Horse: trojan-backdoor-securemulti
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\microsoft\windows\currentversion\run\ || windows installer (ID = 484139)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\microsoft\windows\currentversion\run\ || sninstall (ID = 484220)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\aurorahandler\ || aut9i1m4eofsfinalad (ID = 512963)
20:37: Found Adware: gain-supported software
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1005\software\gator.com\ (10 subtraces) (ID = 528932)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1004\software\microsoft\internet explorer\extensions\cmdmapping\ || {6685509e-b47b-4f47-8e16-9a5f3a62f683} (ID = 125587)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1004\software\microsoft\internet explorer\extensions\{6685509e-b47b-4f47-8e16-9a5f3a62f683}\ (6 subtraces) (ID = 125589)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1004\software\microsoft\internet explorer\extensions\{6685509e-b47b-4f47-8e16-9a5f3a62f683}\ (6 subtraces) (ID = 125589)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1004\software\microsoft\internet explorer\main\ || search bar (ID = 126821)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1004\software\instafink\ (18 subtraces) (ID = 128666)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1004\software\avenue media\ (ID = 128887)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1004\software\msbb\ (11 subtraces) (ID = 135781)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1004\software\microsoft\windows\currentversion\run\ || microsoft windows update (ID = 140604)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1004\software\aurorahandler\ (17 subtraces) (ID = 360172)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1004\software\aurorahandler\ (17 subtraces) (ID = 480802)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1004\software\aurorahandler\ || aut9i1m4eofsfinalad (ID = 512963)
20:37: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1004\software\gator.com\ (10 subtraces) (ID = 528932)
20:38: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1003\software\microsoft\internet explorer\extensions\cmdmapping\ || {6685509e-b47b-4f47-8e16-9a5f3a62f683} (ID = 125587)
20:38: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1003\software\microsoft\internet explorer\extensions\{6685509e-b47b-4f47-8e16-9a5f3a62f683}\ (4 subtraces) (ID = 125589)
20:38: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1003\software\microsoft\internet explorer\extensions\{6685509e-b47b-4f47-8e16-9a5f3a62f683}\ (4 subtraces) (ID = 125589)
20:38: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1003\software\instafink\ (21 subtraces) (ID = 128666)
20:38: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1003\software\microsoft\windows\currentversion\run\ || windows installer (ID = 142127)
20:38: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1003\software\aurorahandler\ (17 subtraces) (ID = 360172)
20:38: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1003\software\aurorahandler\ (17 subtraces) (ID = 480802)
20:38: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1003\software\microsoft\windows\currentversion\run\ || windows installer (ID = 484139)
20:38: HKU\WRSS_Profile_S-1-5-21-1614895754-616249376-725345543-1003\software\aurorahandler\ || aut9i1m4eofsfinalad (ID = 512963)
20:40: HKU\S-1-5-18\software\microsoft\windows\currentversion\run\ || microsoft windows update (ID = 140604)
20:40: HKU\S-1-5-18\software\microsoft\windows\currentversion\runonce\ || microsoft windows update (ID = 140628)
20:40: Registry Sweep Complete, Elapsed Time:00:06:11
20:40: Starting Cookie Sweep
20:40: Found Spy Cookie: yieldmanager cookie
20:40: victor@ad.yieldmanager[2].txt (ID = 3751)
20:40: Found Spy Cookie: ads.tripod.lycos.com cookie
20:40: victor@ads.tripod.lycos[1].txt (ID = 2133)
20:40: Found Spy Cookie: advertising cookie
20:40: victor@advertising[2].txt (ID = 2175)
20:40: Found Spy Cookie: atlas dmt cookie
20:40: victor@atdmt[2].txt (ID = 2253)
20:40: Found Spy Cookie: fastclick cookie
20:40: victor@fastclick[2].txt (ID = 2651)
20:40: Found Spy Cookie: fe.lea.lycos.com cookie
20:40: victor@fe.lea.lycos[1].txt (ID = 2660)
20:40: Found Spy Cookie: trafficmp cookie
20:40: victor@trafficmp[1].txt (ID = 3581)
20:40: Found Spy Cookie: tribalfusion cookie
20:40: victor@tribalfusion[1].txt (ID = 3589)
20:40: Found Spy Cookie: ademails.com cookie
20:40: victor@www.ademails[2].txt (ID = 2066)
20:40: Found Spy Cookie: zedo cookie
20:40: victor@zedo[2].txt (ID = 3762)
20:40: leonel araneda g@atdmt[2].txt (ID = 2253)
20:40: Found Spy Cookie: belnk cookie
20:40: leonel araneda g@belnk[2].txt (ID = 2292)
20:40: Found Spy Cookie: enhance cookie
20:40: leonel araneda g@c.enhance[1].txt (ID = 2614)
20:40: leonel araneda g@dist.belnk[2].txt (ID = 2293)
20:40: Found Spy Cookie: hotbar cookie
20:40: leonel araneda g@hotbar[2].txt (ID = 2797)
20:40: Found Spy Cookie: dashbar cookie
20:40: leonel araneda g@results.dashbar[1].txt (ID = 2496)
20:40: Found Spy Cookie: domain sponsor cookie
20:40: leonel araneda g@searchportal.domainsponsor[1].txt (ID = 2534)
20:40: Found Spy Cookie: 888 cookie
20:40: leonel araneda s@888[1].txt (ID = 2019)
20:40: Found Spy Cookie: hbmediapro cookie
20:40: leonel araneda s@adopt.hbmediapro[1].txt (ID = 2768)
20:40: Found Spy Cookie: atwola cookie
20:40: leonel araneda s@atwola[2].txt (ID = 2255)
20:40: leonel araneda s@belnk[1].txt (ID = 2292)
20:40: Found Spy Cookie: cassava cookie
20:40: leonel araneda s@cassava[1].txt (ID = 2362)
20:40: Found Spy Cookie: dealtime cookie
20:40: leonel araneda s@dealtime[2].txt (ID = 2505)
20:40: leonel araneda s@dist.belnk[2].txt (ID = 2293)
20:40: leonel araneda s@hotbar[1].txt (ID = 2797)
20:40: Found Spy Cookie: touchclarity cookie
20:40: leonel araneda s@msn.touchclarity[1].txt (ID = 3566)
20:40: leonel araneda s@stat.dealtime[2].txt (ID = 2506)
20:40: Found Spy Cookie: tracking cookie
20:40: leonel araneda s@tracking[1].txt (ID = 3571)
20:40: alexis@belnk[2].txt (ID = 2292)
20:40: Cookie Sweep Complete, Elapsed Time: 00:00:18
20:40: Starting File Sweep
20:41: Found System Monitor: family keylogger
20:41: c:\documents and settings\victor\menú inicio\programas\family keylogger (ID = -2147480995)
20:42: c:\documents and settings\leonel araneda s\configuración local\temp\fsg_tmp (ID = -2147480935)
20:42: Found Adware: whenu weathercast
20:42: c:\documents and settings\victor\menú inicio\programas\weathercast (1 subtraces) (ID = -2147480072)
20:42: Found Adware: clocksync
20:42: c:\documents and settings\victor\menú inicio\programas\clocksync (1 subtraces) (ID = -2147481241)
20:42: Found Adware: powerscan
20:42: c:\documents and settings\victor\menú inicio\programas\power scan (1 subtraces) (ID = -2147480462)
20:42: c:\documents and settings\leonel araneda g\configuración local\temp\fsg_tmp (ID = -2147480935)
20:42: c:\windows\system32\ctf (15 subtraces) (ID = -2147480992)
20:42: c:\documents and settings\leonel araneda g\menú inicio\programas\spysheriff (1 subtraces) (ID = -2147479942)
20:47: spysheriff.lnk (ID = 143527)
20:48: spysheriff.lnk (ID = 143527)
20:48: aurl.dat (ID = 70478)
20:48: backup-20050908-175702-458.inf (ID = 114205)
20:49: cmediagnostics.log (ID = 61291)
21:56: secure32.html (ID = 184319)
21:56: info.txt (ID = 90430)
21:57: license.txt (ID = 109585)
21:57: fkl.chm (ID = 60750)
21:57: hfixcfg (ID = 61483)
22:00: appmgrgui.zip (ID = 61281)
22:06: weathercast.lnk (ID = 130071)
22:08: power scan.lnk (ID = 72676)
22:09: BHO Shield: found: IEFlash.dll-- BHO installation allowed at user request
22:16: clocksync.lnk (ID = 53208)
22:19: Found Adware: blazefind
22:19: info.txt (ID = 51461)
22:21: ActiveX Shield: found: Adware: 7adpower, version 1.0.0.0 -- Installation denied
22:22: gatorsupportinfo.txt (ID = 61414)
22:24: Found Adware: sexfiles dialers
22:24: dating.lnk (ID = 75396)
22:24: program's home page.url (ID = 60745)
22:24: mail to support.url (ID = 60757)
22:24: registration.url (ID = 60766)
22:24: download lastest version.url (ID = 60745)
22:24: resetsettings.bat (ID = 109589)
22:24: odm.cfg (ID = 61553)
22:24: bundle.inf (ID = 61287)
22:24: Found Adware: whenu
22:24: wuinst.inf (ID = 74480)
22:24: Found Adware: java byteverify
22:24: loaderadv661.jar-5e55058-36d4cb64.zip (ID = 64819)
22:25: Warning: Unhandled Archive Type
22:25: Warning: Unhandled Archive Type
22:25: Warning: Unhandled Archive Type
22:27: Warning: Unhandled Archive Type
22:27: Warning: Unhandled Archive Type
22:29: File Sweep Complete, Elapsed Time: 01:48:48
22:29: Full Sweep has completed. Elapsed time 02:08:13
22:29: Traces Found: 934
22:54: Removal process initiated
22:54: Quarantining All Traces: 180search assistant/zango
22:54: Quarantining All Traces: directrevenue-abetterinternet
22:54: Quarantining All Traces: family keylogger
22:55: Quarantining All Traces: ist istbar
22:55: Quarantining All Traces: magiccontrol
22:55: Quarantining All Traces: sdbot
22:55: Quarantining All Traces: spamrelayer_alpiok
22:55: Quarantining All Traces: spysheriff
22:55: Quarantining All Traces: trojan-backdoor-securemulti
22:55: Quarantining All Traces: blazefind
22:55: Quarantining All Traces: gain-supported software
22:55: Quarantining All Traces: internetoptimizer
22:55: Quarantining All Traces: spad
22:55: Quarantining All Traces: spooner-a
22:55: Quarantining All Traces: trojan-backdoor-soundcheck
22:55: Quarantining All Traces: 7adpower
22:55: Quarantining All Traces: clocksync
22:55: Quarantining All Traces: dashbar hijack
22:55: Quarantining All Traces: dealhelper
22:55: Quarantining All Traces: ebates money maker
22:55: Quarantining All Traces: elitemediagroup-mediamotor
22:55: Quarantining All Traces: instafinder
22:55: Quarantining All Traces: instant access
22:55: Quarantining All Traces: ist software
22:55: Quarantining All Traces: ist yoursitebar
22:55: Quarantining All Traces: java byteverify
22:55: Quarantining All Traces: powerscan
22:55: Quarantining All Traces: sexfiles dialers
22:55: Quarantining All Traces: surf accuracy
22:55: Quarantining All Traces: topsearch
22:55: Quarantining All Traces: webrebates
22:55: Quarantining All Traces: whenu weathercast
22:55: Quarantining All Traces: whenu
22:55: Quarantining All Traces: winad
22:55: Quarantining All Traces: 888 cookie
22:55: Quarantining All Traces: ademails.com cookie
22:55: Quarantining All Traces: ads.tripod.lycos.com cookie
22:55: Quarantining All Traces: advertising cookie
22:55: Quarantining All Traces: atlas dmt cookie
22:55: Quarantining All Traces: atwola cookie
22:55: Quarantining All Traces: belnk cookie
22:55: Quarantining All Traces: cassava cookie
22:55: Quarantining All Traces: dashbar cookie
22:55: Quarantining All Traces: dealtime cookie
22:55: Quarantining All Traces: domain sponsor cookie
22:55: Quarantining All Traces: enhance cookie
22:55: Quarantining All Traces: fastclick cookie
22:55: Quarantining All Traces: fe.lea.lycos.com cookie
22:55: Quarantining All Traces: hbmediapro cookie
22:55: Quarantining All Traces: hotbar cookie
22:55: Quarantining All Traces: touchclarity cookie
22:55: Quarantining All Traces: tracking cookie
22:55: Quarantining All Traces: trafficmp cookie
22:55: Quarantining All Traces: tribalfusion cookie
22:55: Quarantining All Traces: yieldmanager cookie
22:55: Quarantining All Traces: zedo cookie
22:56: Removal process completed. Elapsed time 00:01:34
********
20:18: | Start of Session, Jueves, 01 de Diciembre de 2005 |
20:18: Spy Sweeper started
20:19: Messenger service has been disabled.
20:20: Your spyware definitions have been updated.
20:20: Your definitions are up to date.
20:21: | End of Session, Jueves, 01 de Diciembre de 2005 |