2012-05-04, 11:09
My spybot has detected a trojan called win32.agent.adb. Even though spybot corrected it, the trojan appeared again after I did the second scan.
I think this trojan might be the one responsible for this ---» ´´~~ and ^^ (duplication of accent marks)... :s

Could you please help me with this issue?

Thank you for your time and help! =)

Here is the DDS report:

I've also attached the zip'ed attach report from DDS.

Thank you for your time and help! =)

2012-05-06, 11:24
Hi Mar_Rib,

Firstly, welcome to the Safer-Networking Malware Removal Forum. :)
My name is Scolabar, and I'll be helping you with your malware problems.
Logs can take a while to research, so please be patient.
If you no longer require help I would be grateful if you would let me know.

Please note the following important guidelines before proceeding:
The instructions that will be provided are for YOUR computer and system only!
Using these instructions on a different computer can cause damage to that computer and possibly render it inoperable!
If you have any questions or do not understand something, please do not hesitate to ask, don't guess or assume.
Only post your problem at One help site. Applying fixes from multiple help sites can cause problems.
Only reply to this thread, do not start another. Please, continue responding, until I give you the All Clean.
Absence of symptoms does not necessarily mean that everything is clear.
DO NOT run any other fix or removal tools unless instructed to do so!
DO NOT install any other software (or hardware) during the cleaning process. This adds more items to be researched.
Print each set of instructions, if possible. Your Internet connection will not be available during some fix processes.
Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
Note: No Reply Within 3 Days Will Result In Your Topic Being Closed!
Please Note: If you haven't done so already, please read this topic "BEFORE You POST"(Please read this Procedure Before Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288) where the conditions for receiving help here are explained.

Windows 7 Advice:
Please Note: The programs I ask you to use will need to be run in Administrator Mode.
In order to do this Right-click on the program file and select the Run as Administrator option.
Additionally, the built-in User Account Control (UAC) utility, if enabled, may prompt you for permission to run the program.
If prompted, please click on the Allow button.
Reference: User Account Control (UAC) and Running as Administrator (http://support.microsoft.com/kb/922708)

Please be aware that removing Malware is a hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.
In light of this, it would be advisable for you to back up any important files and folders that you don't want to lose before we start.

Backup Your Data - Windows 7 (http://support.microsoft.com/kb/971759)
If you follow these guidelines, things should proceed smoothly. :)
I am currently reviewing your log and will return, as soon as possible, with additional instructions.

Thank you for your patience.


2012-05-06, 11:31
Hi Mar_Rib,

Thank you again for your patience. :)

Please read these instructions carefully before executing and perform the steps, in the order given.
lf, you have any questions about or problems with, executing these instructions, <STOP> do not proceed, post back with the question or problem before going any further.

Before proceeding please make sure any open programs are closed.

Step 1:
Business Computer?

Entries in the log provided lead me to believe this computer may connect to a business network.
Please confirm whether or not this computer is a company-owned computer, a computer used for business or connects to a business network.
If this is not the case, please proceed with Step 2 and clarify for what purposes this computer is used in your next post.

Step 2:
MGA Diagnostics

Please download this tool (http://go.microsoft.com/fwlink/?linkid=52012) from Microsoft and Save it to your Desktop.
Right-click on MGADiag.exe and select the Run As Administrator option to launch the program. If you receive a UAC prompt, please allow it.
Click on the Continue button to proceed.
The program will now run. It will take a short while to complete its diagnosis, please be patient.
When it has finished click on the Copy button.
Click on Start and then click on the Start Search box in the Start Menu.
Copy and Paste the following value into the open text entry box:


Then click on the magnifying glass symbol or press Enter.
This will open an empty Notepad file.
Paste the copied contents into the new Notepad window and Save the file as mgadiag.txt to your Desktop.
Click on the OK button to exit the MGA Diagnostics program.
Then Copy and Paste the entire contents of mgadiag.txt into your next reply.
Step 3:

Please download WVCheck (http://artellos.com/ccount/click.php?id=7) and Save it to your Desktop.
Right-click on WVCheck.exe and select the Run As Administrator option to launch the program. If you receive a UAC prompt, please allow it.
Read the comments on the screen and then press Enter.
The scan can take a while depending on the size of your hard drive.
Once the program is finished, a scan report named WVCheck_hhmm_dd-mm-yyyy.txt will automatically saved to your Desktop and opened in Notepad.
Please Copy and Paste the entire contents of WVCheck_hhmm_dd-mm-yyyy.txt into your next reply.
Step 4:

Please download CKScanner (http://downloads.malwareremoval.com/CKScanner.exe) and Save it to your Desktop.
Make sure that CKScanner.exe is on your Desktop before running the application!
Right-click on CKScanner.exe and select the Run As Administrator option to launch the program. If you receive a UAC prompt, please allow it.
Then click on the Search For Files button.
When the scan has finished (- the hourglass cursor will disappear when the scan has completed) click on the Save List To File button.
A text file will be created on your Desktop named ckfiles.txt. A message box will verify the file saved.
Note: Please run the program ONCE only.
Click on the Exit button to close the program.
Double-click on the ckfiles.txt file to open it.
Then Copy and Paste the entire contents of the file into your next reply.
Step 5:
Include in Next Post

Did you have any problems carrying out the instructions?
Is this computer used for business purposes? Does the computer connect to a business network? If not, please clarify for what purposes the computer is used.
Do you have original Windows installation media for your PC?

No Reply Within 3 Days Will Result In Your Topic Being Closed

2012-05-06, 13:24
Hello Scolabar,
Firstly, thank you for your help.

I had no difficulties, at least for now, with the instructuions. They're quite clear. :) As I'm portuguese, and english is not my native language, some technical vocabulary may be an issue (but in case of doubt I'll ask) and my spelling may be, sometimes, incorrect. Sorry for that! Said that, I'll continue.

My computer is not used for business purposes. Personal use only. Sometimes I use school's wireless network that I configured as business network. But I believe that wasn't what you were referring to. So, my answer is no.

Here it is the mgadiag.txt. I'm still a bit confused with this because you said it would take a short while to complete, but I pressed continue and a second after the diagnostic was finished...I don't know if something bad occured:

Diagnostic Report (1.9.0027.0):
Windows Validation Data-->

Validation Code: 0
Cached Online Validation Code: 0x0
Windows Product Key: *****-*****-2QWT6-HCQXJ-9YQTR
Windows Product Key Hash: PVjSC5x6njvqunmbCY3lOD7rYDo=
Windows Product ID: 00359-OEM-8992687-00007
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.1.7601.2.00010300.1.0.003
ID: {7CDE671D-0276-4218-8760-92ADD614A472}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows 7 Home Premium
Architecture: 0x00000009
Build lab: 7601.win7sp1_gdr.120305-1505
TTS Error:
Validation Diagnostic:
Resolution Status: N/A

Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002

Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002
OGAExec.exe Signed By: N/A, hr = 0x80070002
OGAAddin.dll Signed By: N/A, hr = 0x80070002

OGA Data-->
Office Status: 103 Blocked VLK
Microsoft Office Enterprise 2007 - 103 Blocked VLK
OGA Version: N/A, 0x80070002
Signed By: N/A, hr = 0x80070002
Office Diagnostics: 025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Default Browser: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{7CDE671D-0276-4218-8760-92ADD614A472}</UGUID><Version>1.9.0027.0</Version><OS>6.1.7601.2.00010300.1.0.003</OS><Architecture>x64</Architecture><PKey>*****-*****-*****-*****-9YQTR</PKey><PID>00359-OEM-8992687-00007</PID><PIDType>2</PIDType><SID>S-1-5-21-3494332765-2371890562-776866448</SID><SYSTEM><Manufacturer>ASUSTeK Computer Inc.</Manufacturer><Model>N55SF</Model></SYSTEM><BIOS><Manufacturer>American Megatrends Inc.</Manufacturer><Version>N55SF.207</Version><SMBIOSVersion major="2" minor="6"/><Date>20110829000000.000000+000</Date></BIOS><HWID>43223207018400FE</HWID><UserLCID>0816</UserLCID><SystemLCID>0816</SystemLCID><TimeZone>Hora padrão de GMT(GMT+00:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>_ASUS_</OEMID><OEMTableID>Notebook</OEMTableID></OEM><GANotification/></MachineData><Software><Office><Result>103</Result><Products><Product GUID="{90120000-0030-0000-0000-0000000FF1CE}"><LegitResult>103</LegitResult><Name>Microsoft Office Enterprise 2007</Name><Ver>12</Ver><Val>ACD7202654E586</Val><Hash>fFic3JgCreGGRxyF8uMWB4R4Jcg=</Hash><Pid>89388-707-1528066-65488</Pid><PidType>14</PidType></Product></Products><Applications><App Id="15" Version="12" Result="103"/><App Id="16" Version="12" Result="103"/><App Id="18" Version="12" Result="103"/><App Id="19" Version="12" Result="103"/><App Id="1A" Version="12" Result="103"/><App Id="1B" Version="12" Result="103"/><App Id="44" Version="12" Result="103"/><App Id="A1" Version="12" Result="103"/><App Id="BA" Version="12" Result="103"/></Applications></Office></Software></GenuineResults>

Spsys.log Content: 0x80070002

Licensing Data-->
Versão do serviço de licenciamento de software: 6.1.7601.17514

Nome: Windows(R) 7, HomePremium edition
Descrição: Windows Operating System - Windows(R) 7, OEM_SLP channel
ID da Activação: d2c04e90-c3dd-4260-b0f3-f845f5d27d64
ID da Aplicação: 55c92734-d682-4d71-983e-d6ec3f16059f
PID Expandido: 00359-00178-926-800007-02-1033-7600.0000-2092009
ID da Instalação: 103945100771347876031204703693001654880335757805060443
URL de Certificado do Processador: http://go.microsoft.com/fwlink/?LinkID=88338
URL de Certificado do Computador: http://go.microsoft.com/fwlink/?LinkID=88339
URL da Licença de Utilização: http://go.microsoft.com/fwlink/?LinkID=88341
URL de Certificado da Chave do Produto: http://go.microsoft.com/fwlink/?LinkID=88340
Chave de Produto Parcial: 9YQTR
Estado da Licença: Licenciado
Contagem de rearmamentos restantes do Windows: 1
Hora fidedigna: 06-05-2012 11:03:11

Windows Activation Technologies-->
HrOffline: 0x00000000
HrOnline: 0x00000000
HealthStatus: 0x0000000000000000
Event Time Stamp: 4:17:2012 13:32
ActiveX: Registered, Version: 7.1.7600.16395
Admin Service: Registered, Version: 7.1.7600.16395
HealthStatus Bitmask Output:

HWID Data-->

OEM Activation 1.0 Data-->

OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20001
OEMID and OEMTableID Consistent: yes
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC _ASUS_ Notebook
FACP _ASUS_ Notebook
DBGP _ASUS_ Notebook
HPET _ASUS_ Notebook
MCFG _ASUS_ Notebook
ECDT _ASUS_ Notebook
SLIC _ASUS_ Notebook
SSDT PmRef Cpu0Ist
SSDT PmRef Cpu0Ist

Now, here it goes the WVcheck.txt:

Windows Validation Check
Log Created On: 1107_06-05-2012

Windows Information
Windows Version: Windows 7 Service Pack 1
Windows Mode: Normal
Systemroot Path: C:\Windows

WVCheck's Auto Update Check
Auto-Update Option: Download updates and install them automatically.
Last Success Time for Update Detection: 2012-05-06 09:37:40
Last Success Time for Update Download: 2012-05-04 13:11:42
Last Success Time for Update Installation: 2012-05-04 13:11:46

WVCheck's Registry Check Check
Antiwpa: Not Found
Chew7Hale: Not Found

WVCheck's File Dump
C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ELVD6SE5\_history;sz=300x250;tile=1;dcopt=ist;plat=pc;klg=pt-pt;kt=K;kga=-1;kr=F;kw=uma+antiga+manha;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;ord=983828044806096[1].htm
Size: 282 bytes
Creation; 5/5/2012 19:31:30
Modification; 5/5/2012 19:31:30
MD5; 2003016856b6f37ffb2c07ee5854c491
Matched: *AntiGA*
C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PJJNM0G3\history;sz=300x250;tile=1;dcopt=ist;plat=pc;klg=pt-pt;kt=K;kga=-1;kr=F;kw=uma+antiga+manha;kgg=-1;kcr=us;dc_dedup=1;kmyd=ad_creative_1;ord=2099731727538519[1].htm
Size: 282 bytes
Creation; 5/5/2012 19:31:37
Modification; 5/5/2012 19:31:37
MD5; 2003016856b6f37ffb2c07ee5854c491
Matched: *AntiGA*
Size: 14336 bytes
Creation; 18/2/2011 19:49:48
Modification; 20/11/2010 12:21:26
MD5; 19f75d71e4256f5113d64ce2bb66b838
Matched: slwga.dll
Size: 14336 bytes
Creation; 18/2/2011 19:49:48
Modification; 20/11/2010 12:21:26
MD5; 19f75d71e4256f5113d64ce2bb66b838
Matched: slwga.dll
Size: 14848 bytes
Creation; 14/7/2009 0:52:11
Modification; 14/7/2009 2:41:54
MD5; cc03cf9f24946dcbd70acb3e1b2f05bf
Matched: slwga.dll
Size: 15360 bytes
Creation; 18/2/2011 19:49:28
Modification; 20/11/2010 13:27:28
MD5; b6d6886149573278cba6abd44c4317f5
Matched: slwga.dll
Size: 13824 bytes
Creation; 14/7/2009 0:36:22
Modification; 14/7/2009 2:16:15
MD5; 01fe4bdd0b47a7d8bf34d78d2bc23ddb
Matched: slwga.dll
Size: 14336 bytes
Creation; 18/2/2011 19:49:48
Modification; 20/11/2010 12:21:26
MD5; 19f75d71e4256f5113d64ce2bb66b838
Matched: slwga.dll

WVCheck's Dir Dump
WVCheck found no known bad directories.

WVCheck's Missing File Check
WVCheck found no missing Windows files.

WVCheck's MBAM Quarantine Check
There were no bad files quarantined by MBAM.

WVCheck's HOSTS File Check
WVCheck found no bad lines in the hosts file.

WVCheck's MD5 Check
user32.dll - 5e0db2d8b2750543cd2ebb9ea8e6cdd3

-------- End of File, program close at 1110_06-05-2012 --------

Concerning the CKScanner I didn't install it because I have malwarebytes installed on my pc and I didn't know if it would cause problems. Please tell me if I need to uninstall malware bytes.

Finally, what do you mean with original Windows installation media?


2012-05-08, 10:19
Hi Mar_Rib,

I thought I had replied to your post, but evidently not. My apologies. :sad:

Thank you for the logs and your feedback.

... As I'm portuguese, and english is not my native language, some technical vocabulary may be an issue (but in case of doubt I'll ask) and my spelling may be, sometimes, incorrect. Sorry for that! Said that, I'll continue.No problem. I will try to keep the instructions simple. Just ask, if you have any questions.

... Sometimes I use school's wireless network that I configured as business network. ...When you connect to the school's network, are you connecting to the school's servers or just using the school's network to browse the Internet?

If you connect to the school's servers, it is very important you inform the school's IT department as soon as possible as any malware infection(s) could have been passed on.

Concerning the CKScanner I didn't install it because I have malwarebytes installed on my pc and I didn't know if it would cause problems. Please tell me if I need to uninstall malware bytes.You do not need to uninstall MalwareBytes' Anti-Malware.

Please complete the instructions for the CKScanner tool and post the log in your next reply.

... what do you mean with original Windows installation media?Do you have the original Windows 7 installation DVD for your computer?

No Reply Within 3 Days Will Result In Your Topic Being Closed

2012-05-08, 10:56
Hi Scolabar.

No problem..I'm patient. :)

Concerning the network, I only use it to browse the internet.

Moving on, here it is the ckscanner file:

CKScanner - Additional Security Risks - These are not necessarily bad
c:\users\user\documents\jogos\sims 3\crack\ts3.exe
c:\users\user\documents\jogos\sims 3\crack\tslhost.dll
c:\users\user\documents\jogos\sims 3\the sims 3\crack\ts3.exe
c:\users\user\documents\jogos\sims 3\the.sims.3-crack only\crack.rar
c:\users\user\documents\jogos\sims 3\the.sims.3-crack only\how to crack.txt
c:\users\user\downloads\adobe photoshop cs5 extended\crack\adbe_crack - 32bit.rar
c:\users\user\downloads\adobe photoshop cs5 extended\crack\adbe_crack - 64bit.rar
c:\users\user\downloads\adobe photoshop cs5 extended\crack\apcs5 - crack read me.txt
scanner sequence 3.CE.11.FNNAMI
----- EOF -----

And yes, I have original windows installation media.

p.s. Yesterday, after shuting down my PC and turned it on again appeared an error message of ERUNT saying it wasn't possible to save something..(I can't remember what...) and that I should make something manually! :|


2012-05-09, 05:54
Hi Mar_Rib,

Thank you for the CKScanner log and update regarding ERUNT.

Again, please remember to read the instructions below carefully before executing and perform the steps, in the order given.
If you have any questions about or problems executing these instructions, <STOP> do not proceed, post back with the question or problem before going any further.

Before we proceed please make sure any open programs are closed.

Step 1:
Cracked/Pirated Software Detected!

Having checked through your logs I can detect that cracked software has been downloaded and installed on this computer.

c:\users\user\documents\jogos\sims 3\crack\ts3.exe
c:\users\user\documents\jogos\sims 3\crack\tslhost.dll
c:\users\user\documents\jogos\sims 3\the sims 3\crack\ts3.exe
c:\users\user\documents\jogos\sims 3\the.sims.3-crack only\crack.rar
c:\users\user\documents\jogos\sims 3\the.sims.3-crack only\how to crack.txt
c:\users\user\downloads\adobe photoshop cs5 extended\crack\adbe_crack - 32bit.rar
c:\users\user\downloads\adobe photoshop cs5 extended\crack\adbe_crack - 64bit.rar
c:\users\user\downloads\adobe photoshop cs5 extended\crack\apcs5 - crack read me.txt

In addition to the above, an illegal copy of Microsoft Office is installed on this computer:

Microsoft Office Enterprise 2007

This may or may not be related to your computer issues, however, if you wish to continue receiving assistance, then you must remove the above crack files and uninstall all illegal programs.

May I draw your attention to THIS TOPIC (http://forums.spybot.info/showpost.php?p=25290&postcount=4).

We do not support the use of illegal Pirated/Warez/Cracked software.

If seeking help in our Malware removal forum please know that users who have programs obtained by such methods will be asked to remove them, since our help could otherwise be seen as aiding copyright violations. Aside from the legalities be aware malware authors prey on users looking to circumvent a software's protection mechanisms. There is a high risk of infection involved in downloading and running crack codes.

Step 2:
Re-Run CKScanner

Please re-run CKScanner once only. Then Copy and Paste the contents of the ckfiles.txt log into your next reply.

Step 3:
Re-Run DDS

Please re-run DDS. Then Copy and Paste the contents of the DDS.txt and Attach.txt files into your next post.

Step 4:
Include in Next Post

Did you have any problems carrying out the instructions?

No Reply Within 3 Days Will Result In Your Topic Being Closed

2012-05-09, 10:44
Hi Scolabar,

I removed all the the files you asked me to, but I really can't unistall office because it's essential for my work.

I understand that you can't continue helping me with this issue, so thank you for your time and help!

Mar_ Rib

2012-05-10, 03:20
Hi Mar_Rib,

If Microsoft Office 2007 is, as you say, essential for your work, I would strongly advise that the illegal version of the software is removed and a legitimate copy of the software is purchased and installed in its place. A fully-functional Student version of the software can be purchased relatively cheaply. :scratch:

The continued use of P2P File Sharing software (- see the advisory below) and Cracked/Pirated software will not only eventually completely compromise your own computer but could also potentially compromise the rest of the computers on the school network. :bomb:

Advisory - P2P Software

IMPORTANT: There are also signs of a P2P (Peer-to-Peer) File Sharing Program installed on your computer that I also advise should be uninstalled.

P2P File Sharing Programs are used as a major conduit for spreading malware infection to computer systems these days.

P2P programs open up access to the computer on which the program is installed. The computer's settings are more often than not changed in a manner that renders the computer insecure and access to the computer remains open even when the program is not in use. Consequently, the system's security is completely compromised.

So be aware that it is not just what is downloaded that causes problems, just having a P2P program installed is like leaving all the doors to your house unlocked.

I advise you take the time to read the following articles that explain the risk of installing these programs:

Perils of P2P File Sharing (http://www.techsupportforum.com/forums/f50/perils-of-p2p-file-sharing-305923.html)
Use of P2P File Sharing Programs (http://spywarewarrior.com/viewtopic.php?t=26216)
Clean/Infected P2P Programs (http://malwareremoval.com/p2pindex.php)
Risks of Peer-to-Peer Systems (http://www.fbi.gov/scams-safety/peertopeer/oeertopeer)
File sharing infects 500,000 computers (http://www.itpro.co.uk/195672/file-sharing-infects-500-000-computers)
File-sharing dangers involve more than legal troubles (http://www.usatoday.com/tech/columnist/kimkomando/2006-04-13-file-sharing-woes_x.htm)
How to Prevent the Online Invasion of Spyware and Adware (http://www.internetworldstats.com/articles/art053.htm)

I will now arrange for this topic to be closed.
