No prob about the delay. One wuestion before i paste the relevent info, when i run a scan with adaware and it brings up VX2 files ,can i select all these to be repaired.
Logfile of HijackThis v1.98.2
Scan saved at 14:52:04, on 13/12/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Arquivos de programas\VIAudioi\SBADeck\ADeck.exe
C:\Arquivos de programas\iGv6\Discador iG.exe
C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe
C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Arquivos de programas\DIGStream\digstream.exe
C:\Arquivos de programas\Java\j2re1.4.2_06\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\ARQUIV~1\iGv6\sysbrand.exe
C:\ARQUIV~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\ARQUIV~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Arquivos de programas\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\ssoftsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Arquivos de programas\ewido\security suite\ewidoguard.exe
C:\Arquivos de programas\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\HJT\HJT.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.veloxzone.com.br/homeF2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O3 - Toolbar: &Rádio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &iG - {7EEF1E3D-FD97-4401-BCDB-5827F2D11709} - C:\ARQUIV~1\iGv6\igshop.dll (file missing)
O4 - HKLM\..\Run: [AudioDeck] C:\Arquivos de programas\VIAudioi\SBADeck\ADeck.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Discador iG] "C:\Arquivos de programas\iGv6\Discador iG.exe" boot
O4 - HKLM\..\Run: [Windows Compliant] bxfhzm.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\ARQUIV~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\ARQUIV~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [DIGStream] C:\Arquivos de programas\DIGStream\digstream.exe
O4 - HKLM\..\Run: [FX] C:\WINDOWS\Downloaded Program Files\ieloader.exe
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Arquivos de programas\Creative\Video Blaster WebCam Control\CAMTRAY.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Arquivos de programas\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Arquivos de programas\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SysBrand] "C:\ARQUIV~1\iGv6\sysbrand.exe"
O4 - HKCU\..\Run: [Worms2.exe] C:\DOCUME~1\JACQUE~1\Desktop\Jogos\Worms2.exe /r
O4 - HKCU\..\Run: [Slta] C:\Documents and Settings\Jacqueline\Dados de aplicativos\tets.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Arquivos de programas\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Arquivos de programas\Messenger\MSMSGS.EXE
O9 - Extra button: Barra do iG - {FD1672E0-AE0D-465B-B345-F7B0944A121D} - C:\ARQUIV~1\iGv6\igshop.dll (file missing)
O12 - Plugin for .pdf: C:\Arquivos de programas\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Arquivos de programas\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: SEARCH_PAGE_URL=&
http://home.microsoft.com/intl/br/access/allinone.aspO16 - DPF: {556DDE35-E955-11D0-A707-000000521957} -
http://www.xblock.com/download/xclean_micro.exeO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cabO16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) -
http://www.bitdefender.com/scan/Msie/bitdefender.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cabO16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) -
http://us.dl1.yimg.com/download.yahoo.com/...ropper1_4us.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{EA2F02FD-C012-4C77-93CE-932B0491908F}: NameServer = 200.165.132.154 200.165.132.147
Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.
------- System Files in System32 Directory -------
O volume na unidade C nÆo tem nome.
O n£mero de s‚rie do volume ‚ 90C4-AC26
Pasta de C:\WINDOWS\System32
13/12/2004 14:46 223.243 guard.tmp
13/12/2004 11:25 224.241 t0r80a9ued.dll
13/12/2004 10:28 225.424 n22ulcf91f2.dll
11/12/2004 22:17 225.792 fpr0039me.dll
11/12/2004 16:50 223.405 m6po0g73e6.dll
11/12/2004 15:49 224.796 ibrop.dll
11/12/2004 09:38 225.005 j40s0ed7eh0.dll
10/12/2004 07:21 223.190 f0l02a3mgd.dll
10/12/2004 07:21 222.636 jtn8075ue.dll
09/12/2004 13:19 222.824 gpl2l33o1.dll
09/12/2004 13:03 222.402 lv8o09l3e.dll
09/12/2004 12:55 223.191 o8pqli7518.dll
09/12/2004 10:11 <DIR> dllcache
09/12/2004 09:25 224.367 i2240cfqef2e0.dll
09/12/2004 09:22 223.036 f2l00c3mef.dll
09/12/2004 08:45 223.879 n4r2le9o1h.dll
08/12/2004 20:33 222.989 n26qlcj51fo.dll
08/12/2004 11:38 224.460 gp82l3lo1.dll
07/12/2004 13:39 226.261 f4j20e1oeh.dll
07/12/2004 10:28 223.146 en68l1ju1.dll
06/12/2004 18:02 224.542 fn0021dmg.dll
06/12/2004 17:30 30.208 shdocpe.dll
21 arquivo(s) 4.509.037 bytes
1 pasta(s) 32.753.995.776 bytes dispon¡veis
------- Hidden Files in System32 Directory -------
O volume na unidade C nÆo tem nome.
O n£mero de s‚rie do volume ‚ 90C4-AC26
Pasta de C:\WINDOWS\System32
09/12/2004 10:11 <DIR> dllcache
06/12/2004 17:30 30.208 shdocpe.dll
06/11/2004 15:29 488 WindowsLogon.manifest
06/11/2004 15:29 488 logonui.exe.manifest
06/11/2004 15:29 749 sapi.cpl.manifest
06/11/2004 15:29 749 nwc.cpl.manifest
06/11/2004 15:29 749 cdplayer.exe.manifest
06/11/2004 15:29 749 wuaucpl.cpl.manifest
06/11/2004 15:29 749 ncpa.cpl.manifest
8 arquivo(s) 34.929 bytes
1 pasta(s) 32.753.991.680 bytes dispon¡veis
---------- Files Named "Guard" -------------
O volume na unidade C nÆo tem nome.
O n£mero de s‚rie do volume ‚ 90C4-AC26
Pasta de C:\WINDOWS\System32
13/12/2004 14:46 223.243 guard.tmp
1 arquivo(s) 223.243 bytes
0 pasta(s) 32.753.987.584 bytes dispon¡veis
--------- Temp Files in System32 Directory --------
O volume na unidade C nÆo tem nome.
O n£mero de s‚rie do volume ‚ 90C4-AC26
Pasta de C:\WINDOWS\System32
13/12/2004 14:46 223.243 guard.tmp
28/10/2001 15:06 2.969 CONFIG.TMP
2 arquivo(s) 226.212 bytes
0 pasta(s) 32.753.987.584 bytes dispon¡veis
---------------- User Agent ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{20B2C9A7-ADF8-461F-842B-0941A98B562E}"=""
------------ Keys Under Notify ------------
REGEDIT4
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
"Logoff"="ChainWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
"Logoff"="CryptnetWlxLogoffEvent"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SMDEn]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\q4nule591h.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
---------------- Xfind Results -----------------
C:\WINDOWS\System32\GUARD.TMP +++ File read error
-------------- Locate.com Results ---------------
C:\WINDOWS\SYSTEM32\
cdplay~1.man Sat 6 Nov 2004 15:29:34 A..HR 749 0,73 K
en68l1~1.dll Tue 7 Dec 2004 10:28:48 ..S.R 223.146 217,91 K
f0l02a~1.dll Fri 10 Dec 2004 7:21:16 ..S.R 223.190 217,96 K
f2l00c~1.dll Thu 9 Dec 2004 9:22:56 ..S.R 223.036 217,81 K
f4j20e~1.dll Tue 7 Dec 2004 13:39:04 ..S.R 226.261 220,96 K
fn0021~1.dll Mon 6 Dec 2004 18:02:26 ..S.R 224.542 219,28 K
fpr003~1.dll Sat 11 Dec 2004 22:17:02 ..S.R 225.792 220,50 K
gp82l3~1.dll Wed 8 Dec 2004 11:38:38 ..S.R 224.460 219,20 K
gpl2l3~1.dll Thu 9 Dec 2004 13:19:08 ..S.R 222.824 217,60 K
guard.tmp Mon 13 Dec 2004 14:46:28 ..S.R 223.243 218,01 K
i2240c~1.dll Thu 9 Dec 2004 9:25:26 ..S.R 224.367 219,11 K
ibrop.dll Sat 11 Dec 2004 15:49:54 ..S.R 224.796 219,53 K
j40s0e~1.dll Sat 11 Dec 2004 9:38:12 ..S.R 225.005 219,73 K
jtn807~1.dll Fri 10 Dec 2004 7:21:14 ..S.R 222.636 217,42 K
logonu~1.man Sat 6 Nov 2004 15:29:40 A..HR 488 0,48 K
lv8o09~1.dll Thu 9 Dec 2004 13:03:02 ..S.R 222.402 217,19 K
m6po0g~1.dll Sat 11 Dec 2004 16:50:12 ..S.R 223.405 218,17 K
n22ulc~1.dll Mon 13 Dec 2004 10:28:04 ..S.R 225.424 220,14 K
n26qlc~1.dll Wed 8 Dec 2004 20:33:18 ..S.R 222.989 217,76 K
n4r2le~1.dll Thu 9 Dec 2004 8:45:42 ..S.R 223.879 218,63 K
ncpacp~1.man Sat 6 Nov 2004 15:29:34 A..HR 749 0,73 K
nwccpl~1.man Sat 6 Nov 2004 15:29:34 A..HR 749 0,73 K
o8pqli~1.dll Thu 9 Dec 2004 12:55:54 ..S.R 223.191 217,96 K
sapicp~1.man Sat 6 Nov 2004 15:29:34 A..HR 749 0,73 K
shdocpe.dll Mon 6 Dec 2004 17:30:26 ..SHR 30.208 29,50 K
t0r80a~1.dll Mon 13 Dec 2004 11:25:52 ..S.R 224.241 218,98 K
window~1.man Sat 6 Nov 2004 15:29:40 A..HR 488 0,48 K
wuaucp~1.man Sat 6 Nov 2004 15:29:34 A..HR 749 0,73 K
28 items found: 28 files, 0 directories.
Total of file sizes: 4.513.758 bytes 4,30 M
Log for VX2.BetterInternet File Finder (msg126)
Files Found---
Additional Files---
Keys Under Notify---
crypt32chain
cryptnet
cscdll
ScCertProp
Schedule
sclgntfy
SensLogn
SMDEn
termsrv
wlballoon
Guardian Key--- is called:
User Agent String---
{20B2C9A7-ADF8-461F-842B-0941A98B562E}
* DLLCompare Log version(1.0.0.97)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________
C:\WINDOWS\SYSTEM32\en68l1~1.dll Tue 7 Dec 2004 10:28:48 ..S.R 223.146 217,91 K
C:\WINDOWS\SYSTEM32\f0l02a~1.dll Fri 10 Dec 2004 7:21:16 ..S.R 223.190 217,96 K
C:\WINDOWS\SYSTEM32\f2l00c~1.dll Thu 9 Dec 2004 9:22:56 ..S.R 223.036 217,81 K
C:\WINDOWS\SYSTEM32\f4j20e~1.dll Tue 7 Dec 2004 13:39:04 ..S.R 226.261 220,96 K
C:\WINDOWS\SYSTEM32\fn0021~1.dll Mon 6 Dec 2004 18:02:26 ..S.R 224.542 219,28 K
C:\WINDOWS\SYSTEM32\fpr003~1.dll Sat 11 Dec 2004 22:17:02 ..S.R 225.792 220,50 K
C:\WINDOWS\SYSTEM32\gp82l3~1.dll Wed 8 Dec 2004 11:38:38 ..S.R 224.460 219,20 K
C:\WINDOWS\SYSTEM32\gpl2l3~1.dll Thu 9 Dec 2004 13:19:08 ..S.R 222.824 217,60 K
C:\WINDOWS\SYSTEM32\i2240c~1.dll Thu 9 Dec 2004 9:25:26 ..S.R 224.367 219,11 K
C:\WINDOWS\SYSTEM32\ibrop.dll Sat 11 Dec 2004 15:49:54 ..S.R 224.796 219,53 K
C:\WINDOWS\SYSTEM32\j40s0e~1.dll Sat 11 Dec 2004 9:38:12 ..S.R 225.005 219,73 K
C:\WINDOWS\SYSTEM32\jtn807~1.dll Fri 10 Dec 2004 7:21:14 ..S.R 222.636 217,42 K
C:\WINDOWS\SYSTEM32\lv8o09~1.dll Thu 9 Dec 2004 13:03:02 ..S.R 222.402 217,19 K
C:\WINDOWS\SYSTEM32\m6po0g~1.dll Sat 11 Dec 2004 16:50:12 ..S.R 223.405 218,17 K
C:\WINDOWS\SYSTEM32\n22ulc~1.dll Mon 13 Dec 2004 10:28:04 ..S.R 225.424 220,14 K
C:\WINDOWS\SYSTEM32\n26qlc~1.dll Wed 8 Dec 2004 20:33:18 ..S.R 222.989 217,76 K
C:\WINDOWS\SYSTEM32\n4r2le~1.dll Thu 9 Dec 2004 8:45:42 ..S.R 223.879 218,63 K
C:\WINDOWS\SYSTEM32\o8pqli~1.dll Thu 9 Dec 2004 12:55:54 ..S.R 223.191 217,96 K
C:\WINDOWS\SYSTEM32\shdocpe.dll Mon 6 Dec 2004 17:30:26 ..SHR 30.208 29,50 K
C:\WINDOWS\SYSTEM32\t0r80a~1.dll Mon 13 Dec 2004 11:25:52 ..S.R 224.241 218,98 K
________________________________________________
1.262 items found: 1.262 files (20 H/S), 0 directories.
Total of file sizes: 235.650.088 bytes 224,73 M
Administrator Account = True
--------------------End log---------------------