Hi!
I have problems with win32.agent.at and smitfraud-C.toolbar888.
I followed these steps:
1) Scan with updated Spybot: Every time I scan, the problem seems fixed with exception of just one point of the win32.agent. However, after a new scan all problems reapear. Here is the log:
--------------------------------------------------------------------------
--- Report generated: 2007-03-26 21:36 ---
Smitfraud-C.Toolbar888: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-602162358-813497703-682003330-1003\Software\Microsoft\aldd
Smitfraud-C.Toolbar888: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Araf15
Win32.Agent.At: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\PsapiAnalyzer.PsapiAnalyzer
Win32.Agent.At: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\PsapiAnalyzer.PsapiAnalyzer.1
Win32.Agent.At: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0A07916B-B841-4184-AAD5-06FE2F75788C}
Win32.Agent.At: Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0A07916B-B841-4184-AAD5-06FE2F75788C}
Win32.Agent.At: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-602162358-813497703-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{871A54C1-1EB3-48BD-A879-5DBA4EF16BE6}
Win32.Agent.At: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{871A54C1-1EB3-48bd-A879-5DBA4EF16BE6}
Win32.Agent.At: Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{871A54C1-1EB3-48bd-A879-5DBA4EF16BE6}
BFast: Tracking cookie (Internet Explorer: Andy) (Cookie, nothing done)
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2007-03-11 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-01-15 advcheck.dll (1.2.1.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-03-21 Includes\Cookies.sbi (*)
2006-12-08 Includes\Dialer.sbi (*)
2007-03-21 Includes\DialerC.sbi (*)
2007-03-21 Includes\Hijackers.sbi (*)
2007-03-21 Includes\HijackersC.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2007-03-21 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2007-03-21 Includes\Malware.sbi (*)
2007-03-21 Includes\MalwareC.sbi (*)
2007-03-21 Includes\PUPS.sbi (*)
2007-03-21 Includes\PUPSC.sbi (*)
2007-03-21 Includes\Revision.sbi (*)
2006-12-08 Includes\Security.sbi (*)
2007-03-21 Includes\SecurityC.sbi (*)
2007-03-21 Includes\Spybots.sbi (*)
2007-03-21 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti
2007-03-21 Includes\Trojans.sbi (*)
2007-03-21 Includes\TrojansC.sbi (*)
--------------------------------------------------------------------------
2) Run an on-line Anti Virus scan.
I ran Panda on-line. Here is the log;
--------------------------------------------------------------------------
Incident Status Location
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\blkhlwwg.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\bpevxhuh.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\cknkpevn.dll
Adware:Adware/WebSearch Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\dbxcxubj.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\gaswwrsv.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\hnnkbfoe.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\jlpvxxng.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\lrhtbykh.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\nreiayxk.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\oexorxyx.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\uklfjbpy.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\xhpkfefk.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\yhxvgemp.dll
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Andy\Cookies\andy@bfast[1].txt
Potentially unwanted tool:Application/Reboot.A Not disinfected C:\WINDOWS\pss\Reboot.exeCommon Startup
--------------------------------------------------------------------------
3) Run Spybot in Safe Mode:
I ran SpyBot several times, but the result is similar as in normal mode.
4) HiJackThis log
I ran HijackThis. Here goes the log file:
--------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 09:46:01 p.m., on 26/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos de programa\Eset\nod32kui.exe
C:\Archivos de programa\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Messenger\msmsgs.exe
C:\Archivos de programa\Palm\HOTSYNC.EXE
C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Archivos de programa\Eset\nod32krn.exe
C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Archivos de programa\iPod\bin\iPodService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\ARCHIV~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Andy\Escritorio\hIJACKtHIS\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.clarin.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Archivos de programa\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mHotKey] C:\ARCHIV~1\GENIUS~2\mHotkey.exe
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\qkkvkupe.dll",setvm
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Archivos de programa\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: HotSync Manager.lnk = C:\Archivos de programa\Palm\HOTSYNC.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\Archivos de programa\QUICKEN\QWDLLS.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CD941590-6424-11D2-A82F-00104B7AF15C} (ManagerActiveXBKB Class) - https://www.bankboston.com.br/download/ActiveXBKBCab.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\gnqybxsf.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Archivos de programa\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
--------------------------------------------------------------------------
I appreciate very much your support!
Carlos
I have problems with win32.agent.at and smitfraud-C.toolbar888.
I followed these steps:
1) Scan with updated Spybot: Every time I scan, the problem seems fixed with exception of just one point of the win32.agent. However, after a new scan all problems reapear. Here is the log:
--------------------------------------------------------------------------
--- Report generated: 2007-03-26 21:36 ---
Smitfraud-C.Toolbar888: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-602162358-813497703-682003330-1003\Software\Microsoft\aldd
Smitfraud-C.Toolbar888: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Araf15
Win32.Agent.At: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\PsapiAnalyzer.PsapiAnalyzer
Win32.Agent.At: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\PsapiAnalyzer.PsapiAnalyzer.1
Win32.Agent.At: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0A07916B-B841-4184-AAD5-06FE2F75788C}
Win32.Agent.At: Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0A07916B-B841-4184-AAD5-06FE2F75788C}
Win32.Agent.At: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-602162358-813497703-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{871A54C1-1EB3-48BD-A879-5DBA4EF16BE6}
Win32.Agent.At: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{871A54C1-1EB3-48bd-A879-5DBA4EF16BE6}
Win32.Agent.At: Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{871A54C1-1EB3-48bd-A879-5DBA4EF16BE6}
BFast: Tracking cookie (Internet Explorer: Andy) (Cookie, nothing done)
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2007-03-11 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-01-15 advcheck.dll (1.2.1.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-03-21 Includes\Cookies.sbi (*)
2006-12-08 Includes\Dialer.sbi (*)
2007-03-21 Includes\DialerC.sbi (*)
2007-03-21 Includes\Hijackers.sbi (*)
2007-03-21 Includes\HijackersC.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2007-03-21 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2007-03-21 Includes\Malware.sbi (*)
2007-03-21 Includes\MalwareC.sbi (*)
2007-03-21 Includes\PUPS.sbi (*)
2007-03-21 Includes\PUPSC.sbi (*)
2007-03-21 Includes\Revision.sbi (*)
2006-12-08 Includes\Security.sbi (*)
2007-03-21 Includes\SecurityC.sbi (*)
2007-03-21 Includes\Spybots.sbi (*)
2007-03-21 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti
2007-03-21 Includes\Trojans.sbi (*)
2007-03-21 Includes\TrojansC.sbi (*)
--------------------------------------------------------------------------
2) Run an on-line Anti Virus scan.
I ran Panda on-line. Here is the log;
--------------------------------------------------------------------------
Incident Status Location
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\blkhlwwg.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\bpevxhuh.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\cknkpevn.dll
Adware:Adware/WebSearch Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\dbxcxubj.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\gaswwrsv.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\hnnkbfoe.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\jlpvxxng.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\lrhtbykh.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\nreiayxk.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\oexorxyx.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\uklfjbpy.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\xhpkfefk.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Andy\Configuración local\Temp\yhxvgemp.dll
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Andy\Cookies\andy@bfast[1].txt
Potentially unwanted tool:Application/Reboot.A Not disinfected C:\WINDOWS\pss\Reboot.exeCommon Startup
--------------------------------------------------------------------------
3) Run Spybot in Safe Mode:
I ran SpyBot several times, but the result is similar as in normal mode.
4) HiJackThis log
I ran HijackThis. Here goes the log file:
--------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 09:46:01 p.m., on 26/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos de programa\Eset\nod32kui.exe
C:\Archivos de programa\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Messenger\msmsgs.exe
C:\Archivos de programa\Palm\HOTSYNC.EXE
C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Archivos de programa\Eset\nod32krn.exe
C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Archivos de programa\iPod\bin\iPodService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\ARCHIV~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Andy\Escritorio\hIJACKtHIS\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.clarin.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Archivos de programa\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mHotKey] C:\ARCHIV~1\GENIUS~2\mHotkey.exe
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\qkkvkupe.dll",setvm
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Archivos de programa\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Archivos de programa\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: HotSync Manager.lnk = C:\Archivos de programa\Palm\HOTSYNC.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\Archivos de programa\QUICKEN\QWDLLS.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CD941590-6424-11D2-A82F-00104B7AF15C} (ManagerActiveXBKB Class) - https://www.bankboston.com.br/download/ActiveXBKBCab.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\gnqybxsf.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Archivos de programa\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Archivos de programa\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
--------------------------------------------------------------------------
I appreciate very much your support!
Carlos