now whith sybot 1.4
Just uninstalled 1.3 download and installed 1.4 updated inmunizated etc
and guest what hapend, things have changed a lot, or 1.3 did not find this or 1.4 is caming whith some staf or dont know any more anything .. you tell me...
tanks for your help..
here is the log...
--- Search result list ---
--- System information ---
Windows 2000 (Build: 2195) Service Pack 4
/ DataAccess: Microsoft Data Access Components KB870669
/ DataAccess: Security Update for Microsoft Data Access Components
/ Internet Explorer 6 / SP1: Revisión de Windows 2000 - KB883939
/ Outlook Express 6 / SP1: Revisión de Windows 2000 - KB897715
/ Windows 2000 / SP4: Windows 2000 Service Pack 4
/ Windows 2000 / SP5: Revisión de Windows 2000 - KB329115
/ Windows 2000 / SP5: Revisión de Windows 2000 - KB842773
/ Windows 2000 / SP5: Revisión de Windows 2000 - KB890046
/ Windows 2000 / SP5: Windows Installer 3.1 (KB893803)
/ Windows 2000 / SP5: Revisión de Windows 2000 - KB894320
/ Windows 2000 / SP5: Revisión de Windows 2000 - KB896358
/ Windows 2000 / SP5: Revisión de Windows 2000 - KB896422
/ Windows 2000 / SP5: Revisión de Windows 2000 - KB901214
/ Windows 2000 / SP5: Paquete acumulativo de actualizaciones para Windows 2000 SP4
/ Windows Media Player: Revisión del Reproductor de Windows Media [consulte Q828026 para obtener más información]
/ Windows Media Player / SP0: Revisión del Reproductor de Windows Media [consulte Q828026 para obtener más información]
/ Windows Media Player 9 / SP0: Revisión del Reproductor de Windows Media 9 [Para más información, consulte KB885492]
--- Startup entries list ---
Located: HK_LM:Run, DAEMON Tools-1033
command: "D:\instalaciones\programas\daemontools\daemon.exe" -lang 1033
file: D:\instalaciones\programas\daemontools\daemon.exe
size: 73728
MD5: 05f19ee0628a18bf79c377bf7ee9403d
Located: HK_LM:Run, Synchronization Manager
command: mobsync.exe /logon
file: C:\WINDOWS\system32\mobsync.exe
size: 111888
MD5: 869697fd0b75de3cb54c17ccfc4e4f1c
Located: HK_CU:Run, internat.exe
command: internat.exe
file: C:\WINDOWS\system32\internat.exe
size: 20752
MD5: f85a35fd8b47cff695561c5df574bd31
Located: HK_CU:Run, msnmsgr
command: "C:\Archivos de programa\MSN Messenger\msnmsgr.exe" /background
file: C:\Archivos de programa\MSN Messenger\msnmsgr.exe
size: 6856704
MD5: 79ac63592f9b6750f2026a2520c11bee
Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
Located: WinLogon, DfLogon
command: LogonDll.dll
file: LogonDll.dll
Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
Located: WinLogon, wzcnotif
command: wzcdlg.dll
file: wzcdlg.dll
--- Browser helper object list ---
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
BHO name:
CLSID name: AcroIEHlprObj Class
description: Adobe Acrobat reader
classification: Legitimate
known filename: AcroIEhelper.ocx<br>AcroIEhelper.dll
info link:
http://www.adobe.com/products/acrobat/readstep2.html
info source: TonyKlein
Path: C:\Archivos de programa\Adobe\Acrobat 5.0\Reader\ActiveX\
Long name: AcroIEHelper.ocx
Short name: ACROIE~1.OCX
Date (created): 26/07/2005 09:43:50 p.m.
Date (last access): 02/02/2006
Date (last write): 16/04/2001 03:39:02 p.m.
Filesize: 37808
Attributes: archive
MD5: 8394ABFC1BE196A62C9F532511936DF7
CRC32: 71D6E350
Version: 1.0.0.1
{53707962-6F74-2D53-2644-206D7942484F} ()
BHO name:
CLSID name:
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDhelper.dll
info link:
http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\ARCHIV~1\SPYBOT~1\
Long name: SDHelper.dll
Short name: SDHELPER.DLL
Date (created): 02/02/2006 03:40:30 p.m.
Date (last access): 02/02/2006
Date (last write): 31/05/2005 01:04:00 a.m.
Filesize: 853672
Attributes: archive
MD5: 250D787A5712D7768DDC133B3E477759
CRC32: D4589A41
Version: 1.4.0.0
--- ActiveX list ---
DirectAnimation Java Classes (DirectAnimation Java Classes)
DPF name: DirectAnimation Java Classes
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\Java\classes\dajava.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\dajava.cab
info link:
info source: Patrick M. Kolla
Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
Installer:
Codebase: file://C:\WINDOWS\Java\classes\xmldso.cab
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla
Yahoo! Chat (Yahoo! Chat)
DPF name: Yahoo! Chat
CLSID name:
Installer:
Codebase:
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
{0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object)
DPF name:
CLSID name: CKAVWebScan Object
Installer: C:\WINDOWS\Downloaded Program Files\kavwebscan.inf
Codebase:
http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
description:
classification: Legitimate
known filename:
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\system32\Kaspersky Lab\Kaspersky On-line Scanner\
Long name: kavwebscan.dll
Short name: KAVWEB~1.DLL
Date (created): 01/07/2005 02:43:00 p.m.
Date (last access): 02/02/2006
Date (last write): 01/07/2005 02:43:00 p.m.
Filesize: 729088
Attributes: archive
MD5: 8DC015FB6181B3CF5F10BCC1FB0F9A09
CRC32: 0D11687F
Version: 5.0.67.0
{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
DPF name:
CLSID name: Shockwave ActiveX Control
Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
Codebase:
http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
description: Macromedia ShockWave Flash Player 7
classification: Legitimate
known filename: SWDIR.DLL
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\SYSTEM32\Macromed\Director\
Long name: SwDir.dll
Short name: SWDIR.DLL
Date (created): 25/07/2005 09:48:10 p.m.
Date (last access): 02/02/2006
Date (last write): 19/05/2005 02:58:34 p.m.
Filesize: 54488
Attributes: archive
MD5: 2B75B8197F3BCBB199EAA3AFE3FB3CA3
CRC32: ED72FE89
Version: 10.1.0.11
{2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing)
DPF name:
CLSID name: Yahoo! Audio Conferencing
Installer: C:\WINDOWS\Downloaded Program Files\yacscom.inf
Codebase:
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
description: Yahoo Audio Conferencing
classification: Legitimate
known filename: YACSCOM.DLL
info link:
info source: Patrick M. Kolla
Path: C:\ARCHIV~1\Yahoo!\MESSEN~1\
Long name: yacscom.dll
Short name:
Date (created): 26/07/2005 11:52:02 p.m.
Date (last access): 02/02/2006
Date (last write): 06/08/2004 02:58:46 p.m.
Filesize: 233472
Attributes: archive
MD5: CA589915BF9D36ABD1256D490FDE5F48
CRC32: FC5260C3
Version: 1.0.0.45
{30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class)
DPF name:
CLSID name: YInstStarter Class
Installer: C:\WINDOWS\Downloaded Program Files\yinst.inf
Codebase:
http://download.yahoo.com/dl/yinst/yinst_current.cab
description: Yahoo! Installation helper
classification: Legitimate
known filename: %SystemRoot%\Downloaded Program Files\yinsthelper.dll
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\Downloaded Program Files\
Long name: yinsthelper.dll
Short name: YINSTH~1.DLL
Date (created): 07/11/2004 03:29:46 p.m.
Date (last access): 02/02/2006
Date (last write): 07/11/2004 03:29:46 p.m.
Filesize: 173168
Attributes: archive
MD5: 4C0658E518FA9D08E884DB717A7087AE
CRC32: FFDA1549
Version: 2004.11.7.1
{B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class)
DPF name:
CLSID name: MsnMessengerSetupDownloadControl Class
Installer: C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.inf
Codebase:
http://messenger.msn.com/download/msnmessengersetupdownloader.cab
description:
classification: Legitimate
known filename: MsnMessengerSetupDownloader.ocx
info link:
info source: Safer Networking Ltd.
Path: C:\WINDOWS\Downloaded Program Files\
Long name: MsnMessengerSetupDownloader.ocx
Short name: MSNMES~1.OCX
Date (created): 17/03/2005 02:48:34 p.m.
Date (last access): 02/02/2006
Date (last write): 17/03/2005 02:48:34 p.m.
Filesize: 113152
Attributes: archive
MD5: 92D24B6643919005213F60D5B537196A
CRC32: 31684779
Version: 1.0.0.2
{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf
Codebase:
http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\System32\macromed\flash\
Long name: Flash.ocx
Short name: FLASH.OCX
Date (created): 09/06/2004 03:59:26 p.m.
Date (last access): 02/02/2006
Date (last write): 09/06/2004 03:59:26 p.m.
Filesize: 939224
Attributes: archive
MD5: FC3E17E12C2E31FAC34B416B3DAB829F
CRC32: D1CF3A57
Version: 7.0.19.0
--- Process list ---
PID: 0 ( 0) [System]
PID: 176 ( 8) \SystemRoot\System32\smss.exe
PID: 200 ( 176) \??\C:\WINDOWS\system32\csrss.exe
PID: 220 ( 176) \??\C:\WINDOWS\system32\winlogon.exe
PID: 252 ( 220) C:\WINDOWS\system32\services.exe
size: 92944
MD5: AD30F8B76A772A28CFBE3297398C0290
PID: 264 ( 220) C:\WINDOWS\system32\lsass.exe
size: 37648
MD5: 115CE9122AFF1D17BBB97DA51BC64DF0
PID: 376 ( 252) C:\Archivos de programa\Faronics\Deep Freeze\Install C-0\DF5Serv.exe
size: 305600
MD5: 09D55AD69D696218524B21F03194BE73
PID: 468 ( 252) C:\WINDOWS\system32\svchost.exe
size: 7952
MD5: 9E64AD53CFD9DA2D22E8A924F8C6E62C
PID: 496 ( 252) C:\WINDOWS\system32\spoolsv.exe
size: 48400
MD5: 1F124B89AA469671821115A39C0FBD27
PID: 528 ( 252) C:\WINDOWS\System32\svchost.exe
size: 7952
MD5: 9E64AD53CFD9DA2D22E8A924F8C6E62C
PID: 556 ( 252) C:\WINDOWS\System32\nvsvc32.exe
size: 69632
MD5: 26712CF8BE48BC767854927435C0B6A9
PID: 576 ( 252) C:\Archivos de programa\Parental Filter\ParentalFilter.exe
size: 245248
MD5: 83C4A02BE525167A58EA9C1872D4939C
PID: 716 ( 252) C:\WINDOWS\system32\regsvc.exe
size: 68368
MD5: 499507036FBD4F0A225B742BC107F675
PID: 732 ( 252) C:\WINDOWS\system32\MSTask.exe
size: 123152
MD5: 12271E6CE3AD715B47C37862BAE1F225
PID: 756 ( 252) C:\WINDOWS\System32\WBEM\WinMgmt.exe
size: 196706
MD5: 881B54A3CB9822C6FBA9FA56B49A6030
PID: 808 ( 252) C:\Archivos de programa\RealVNC\WinVNC\WinVNC.exe
size: 335872
MD5: B84873B030E66DDF3964A31793BB4211
PID: 820 ( 252) C:\WINDOWS\system32\svchost.exe
size: 7952
MD5: 9E64AD53CFD9DA2D22E8A924F8C6E62C
PID: 904 ( 252) C:\WINDOWS\System32\svchost.exe
size: 7952
MD5: 9E64AD53CFD9DA2D22E8A924F8C6E62C
PID: 1012 ( 952) C:\WINDOWS\Explorer.EXE
size: 244496
MD5: 14586805C83DDB7DB7C25A57DD40CD67
PID: 1108 (1012) D:\instalaciones\programas\daemontools\daemon.exe
size: 73728
MD5: 05F19EE0628A18BF79C377BF7EE9403D
PID: 1128 (1012) C:\WINDOWS\system32\internat.exe
size: 20752
MD5: F85A35FD8B47CFF695561C5DF574BD31
PID: 1136 (1012) C:\Archivos de programa\MSN Messenger\msnmsgr.exe
size: 6856704
MD5: 79AC63592F9B6750F2026A2520C11BEE
PID: 1192 ( 376) C:\Archivos de programa\Faronics\Deep Freeze\Install C-0\_$Df\FrzState2k.exe
size: 352660
MD5: 5ADB6D0F34DDD73DAB315F8A89B8EB79
PID: 1088 (1012) C:\Archivos de programa\Spybot - Search & Destroy\SpybotSD.exe
size: 4393096
MD5: 09CA174A605B480318731E691DC98539
PID: 960 (1088) C:\Archivos de programa\Internet Explorer\iexplore.exe
size: 91136
MD5: 0A80D631A93A52F82B799AC67135EB0A
PID: 8 ( 0) System
--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 02/02/2006 03:49:18 p.m.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
http://www.kpponet.mine.nu
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.kpponet.mine.nu
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.kpponet.mine.nu
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
http://www.kpponet.mine.nu
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
http://www.kpponet.mine.nu
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.kpponet.mine.nu
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar
http://www.kpponet.mine.nu
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.kpponet.mine.nu
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.kpponet.mine.nu
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.kpponet.mine.nu
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://www.kpponet.mine.nu
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://www.kpponet.mine.nu
--- Winsock Layered Service Provider list ---
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\msafd.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\msafd.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\msafd.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 3: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 4: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{118E0FA8-2423-4BC6-9C7D-674FB9AED709}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\msafd.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{118E0FA8-2423-4BC6-9C7D-674FB9AED709}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\msafd.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{44713777-91CD-47AC-8013-83E132D4F4D9}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\msafd.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{44713777-91CD-47AC-8013-83E132D4F4D9}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\msafd.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{8377A437-3A01-42D7-BE76-44A387E931E4}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\msafd.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{8377A437-3A01-42D7-BE76-44A387E931E4}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\msafd.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\rnr20.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP
Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS