PDA

View Full Version : anti-vermins



olhorobot
2007-01-17, 22:05
hello!
my computer got infected by anti-vermin systray blinking icon.

windows xp is fully updated and i use AVG free as an antivirus(should i use some other antivirus or anti-spyware?)

i've followed every step in your before you post a log (http://forums.spybot.info/showpost.php?p=1150&postcount=2) and here are de results:

-first : the systray no longerhas the blinking icon or warning i've made the spybot check for problems in all of the users and twice until there was nothing more to remove.

-scan report


Incident Status Location

Adware:adware/safetybar Not disinfected c:\documents and settings\all users\ambiente de trabalho\Online Security Guide.url
Adware:adware/navipromo Not disinfected Windows Registry
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Administrador\Ambiente de trabalho\smitRem\Process.exe
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.sextracker.com/]
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[counter14.sextracker.com/]
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.sextracker.com/]
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[counter9.sextracker.com/]
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[counter9.sextracker.com/]
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[counter5.sextracker.com/]
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[counter1.sextracker.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/SpyLog Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.spylog.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.adtech.de/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[.uol.com.br/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\APRESENTAÇÃO\Application Data\Mozilla\Firefox\Profiles\y61p387b.default\cookies.txt[de.uol.com.br/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\in-move-wd09\Application Data\Mozilla\Firefox\Profiles\eyj2dgmc.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\in-move-wd09\Application Data\Mozilla\Firefox\Profiles\eyj2dgmc.default\cookies.txt[.ccbill.com/]
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\in-move-wd09\Application Data\Mozilla\Firefox\Profiles\eyj2dgmc.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\in-move-wd09\Application Data\Mozilla\Firefox\Profiles\eyj2dgmc.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\in-move-wd09\Application Data\Mozilla\Firefox\Profiles\eyj2dgmc.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\in-move-wd09\Application Data\Mozilla\Firefox\Profiles\eyj2dgmc.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\in-move-wd09\Application Data\Mozilla\Firefox\Profiles\n3noa6jm.Utilizador por Omissão\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\in-move-wd09\Application Data\Mozilla\Firefox\Profiles\n3noa6jm.Utilizador por Omissão\cookies.txt[as1.falkag.de/]
Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\in-move-wd09\Application Data\Mozilla\Firefox\Profiles\n3noa6jm.Utilizador por Omissão\cookies.txt[.paycounter.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\in-move-wd09\Application Data\Mozilla\Firefox\Profiles\n3noa6jm.Utilizador por Omissão\cookies.txt[.fastclick.net/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\in-move-wd09\Application Data\Mozilla\Firefox\Profiles\n3noa6jm.Utilizador por Omissão\cookies.txt[media.fastclick.net/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\in-move-wd09\Application Data\Mozilla\Firefox\Profiles\n3noa6jm.Utilizador por Omissão\cookies.txt[.fastclick.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\in-move-wd09\Cookies\in-move-wd09@ad.yieldmanager[2].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\in-move-wd09\Cookies\in-move-wd09@ads.addynamix[1].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\in-move-wd09\Cookies\in-move-wd09@as1.falkag[2].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\in-move-wd09\Cookies\in-move-wd09@casalemedia[1].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\in-move-wd09\Cookies\in-move-wd09@ccbill[2].txt
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\in-move-wd09\Cookies\in-move-wd09@cs.sexcounter[2].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\in-move-wd09\Cookies\in-move-wd09@questionmarket[2].txt
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\reparação\Application Data\Mozilla\Firefox\Profiles\ho6oklb1.default\cookies.txt[counter3.sextracker.com/]
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\reparação\Application Data\Mozilla\Firefox\Profiles\ho6oklb1.default\cookies.txt[.sextracker.com/]

olhorobot
2007-01-17, 22:06
panda scan (cont.)

Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\reparação\Application Data\Mozilla\Firefox\Profiles\ho6oklb1.default\cookies.txt[.adultfriendfinder.com/]
Potentially unwanted tool:Application/AntiVermins Not disinfected C:\Programas\AntiVerminser\AntiVerminser.exe
Spyware:Cookie/Doubleclick Not disinfected H:\backups\G4\Application Support\Firefox\Profiles\default.du8\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Atlas DMT Not disinfected H:\backups\G4\Application Support\Firefox\Profiles\default.du8\cookies.txt[.atdmt.com/]
Spyware:Cookie/onestat.com Not disinfected H:\backups\G4\Application Support\Firefox\Profiles\default.du8\cookies.txt[stat.onestat.com/]
Spyware:Cookie/cs.sexcounter Not disinfected H:\backups\G4\Application Support\Firefox\Profiles\default.du8\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/adultfriendfinder Not disinfected H:\backups\G4\Application Support\Firefox\Profiles\default.du8\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Yadro Not disinfected H:\backups\G4\Application Support\Firefox\Profiles\default.du8\cookies.txt[.yadro.ru/]
Spyware:Cookie/Casalemedia Not disinfected H:\backups\G4\Application Support\Firefox\Profiles\default.du8\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected H:\backups\G4\Application Support\Firefox\Profiles\default.du8\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected H:\backups\G4\Application Support\Firefox\Profiles\default.du8\cookies.txt[server.iad.liveperson.net/hc/2436666]
Spyware:Cookie/YieldManager Not disinfected H:\backups\G4\Application Support\Firefox\Profiles\default.du8\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Zedo Not disinfected H:\backups\G4\Application Support\Firefox\Profiles\default.du8\cookies.txt[.zedo.com/]
Spyware:Cookie/SexList Not disinfected H:\backups\G4\Application Support\Firefox\Profiles\default.du8\cookies.txt[.sexlist.com/]

-------------------------------------------
- hijackthis report

Logfile of HijackThis v1.99.1
Scan saved at 18:49:39, on 17-01-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programas\Intel\Wireless\Bin\EvtEng.exe
C:\Programas\Intel\Wireless\Bin\S24EvMon.exe
C:\Programas\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Ficheiros comuns\Autodesk Shared\Service\AdskScSrv.exe
C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Programas\Ficheiros comuns\EPSON\EBAPI\SAgent2.exe
C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programas\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
C:\Programas\Intel\Wireless\Bin\OProtSvc.exe
C:\Programas\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programas\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Programas\Intel\Wireless\Bin\ifrmewrk.exe
C:\Programas\Intel\Wireless\Bin\EOUWiz.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\FICHEI~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Programas\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe
C:\Programas\VoipStunt.com\VoipStunt\VoipStunt.exe
C:\Programas\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\FICHEI~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\hjthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pt/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
F2 - REG:system.ini: Shell=
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programas\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programas\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Programas\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Programas\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\FICHEI~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programas\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [stujuci] c:\windows\system32\fzkwkn.exe r
O4 - HKCU\..\Run: [VoipStunt] "C:\Programas\VoipStunt.com\VoipStunt\VoipStunt.exe" -nosplash -minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programas\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: HDDlife.lnk.disabled
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk.disabled
O4 - Global Startup: Adobe Gamma.lnk = C:\Programas\Ficheiros comuns\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk.disabled
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Programas\Ficheiros comuns\Autodesk Shared\acstart16.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: WinZip Quick Pick.lnk.disabled
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Programas\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Programas\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Programas\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Programas\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Programas\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Programas\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Programas\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Programas\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.gaiurb.pt/sig/ActiveX/mgaxctrl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: IntelWireless - C:\Programas\Intel\Wireless\Bin\LgNotify.dll
O21 - SSODL: eupeptic - {8670ee50-01f9-47da-ac1e-cf8549e9e521} - C:\WINDOWS\system32\axlet.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programas\Ficheiros comuns\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Unknown owner - C:\Programas\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe" -win32service (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programas\Ficheiros comuns\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programas\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programas\Ficheiros comuns\EPSON\EBAPI\SAgent2.exe
O23 - Service: EvtEng - Intel Corporation - C:\Programas\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programas\Ficheiros comuns\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programas\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Programas\Ficheiros comuns\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Programas\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Programas\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Programas\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Programas\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Programas\Intel\Wireless\Bin\WLKeeper.exe

----------------------------------------------------

pskelley
2007-01-18, 21:31
Welcome to the forum, the first thing you need to read is this information since you mentioned anti-vermin.
http://forums.spybot.info/showthread.php?t=4015
I can see evidence of the infection in the HJT log and since so much of it is hidden, this will tell us if the infection is still there.
Use "Post Reply" to post the information in the instructions and stay in the same topic.

Thanks

tashi
2007-01-25, 08:20
olhorobot, how is it going?

tashi
2007-01-31, 01:51
This topic has been archived.

If you need it re-opened please send me a private message (pm) and provide a link to the thread. Applies only to the original poster, anyone else with similar problems please start a new topic.