Hi,
I've done you told me but SpyBot still detects the 3 entries for the 'Win32.Banker.ekn'. :sad:
I've run SUPERAntiSpyware and it detected some threats, but not the 'Win32.Banker.ekn' entries. They are in quarantine. Should I delete them from there?
Then I've run Kaspesky and it detected some others threats too.
The logs follow:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 01/21/2008 at 10:18 PM
Application Version : 3.9.1008
Core Rules Database Version : 3384
Trace Rules Database Version: 1378
Scan type : Complete Scan
Total Scan Time : 02:48:20
Memory items scanned : 389
Memory threats detected : 0
Registry items scanned : 8642
Registry threats detected : 0
File items scanned : 135508
File threats detected : 4
Adware.Tracking Cookie
C:\Documents and Settings\ROBERIO\Cookies\roberio@ads.abril.com[1].txt
C:\Documents and Settings\ROBERIO\Cookies\roberio@ad.adnetwork.com[2].txt
Trojan.Downloader-Gen
C:\WINDOWS\SYSTEM32\STU.DLL
Unclassified.Unknown Origin
D:\MEUS DOCUMENTOS\PROGRAMAS\PESSOAIS\PC\DRIVES\P4P800E-DELUXE\378RAID_100137\378RAID\WINXP\FASTTX2K.SYS
The Kaspesky's log:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, January 22, 2008 9:53:51 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 22/01/2008
Kaspersky Anti-Virus database records: 526268
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
Scan Statistics:
Total number of scanned objects: 235839
Number of viruses found: 2
Number of infected objects: 7
Number of suspicious objects: 0
Duration of the scan process: 03:22:52
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Dados de aplicativos\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Dados de aplicativos\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Histórico\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Configurações locais\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Configurações locais\Histórico\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Configurações locais\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\ROBERIO\.housecall6.6\Quarantine\mdelk.exe.bac_a01456 Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\ROBERIO\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\ROBERIO\Configurações locais\Dados de aplicativos\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\ROBERIO\Configurações locais\Histórico\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\ROBERIO\Configurações locais\Histórico\History.IE5\MSHist012008012220080123\index.dat Object is locked skipped
C:\Documents and Settings\ROBERIO\Configurações locais\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\ROBERIO\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\ROBERIO\ntuser.dat Object is locked skipped
C:\Documents and Settings\ROBERIO\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\ROBERIO\UserData\index.dat Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{1112CD02-B90E-4226-8E24-9C9D042B5813}\RP170\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd8925.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\Meus Documentos C\Programas\Diversos\DAP 5.3.9.8 & Language\dap53lang.exe/WISE0021.BIN/dapiebar.dll Infected: not-a-virus:AdWare.Win32.Dap.c skipped
E:\Meus Documentos C\Programas\Diversos\DAP 5.3.9.8 & Language\dap53lang.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.Dap.c skipped
E:\Meus Documentos C\Programas\Diversos\DAP 5.3.9.8 & Language\dap53lang.exe WiseSFX: infected - 2 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{1112CD02-B90E-4226-8E24-9C9D042B5813}\RP89\A0012905.exe Object is locked skipped
E:\System Volume Information\_restore{ED8B2F9C-2807-476C-9B80-AF4C801C46F9}\RP354\A0053864.exe/WISE0021.BIN/dapiebar.dll Infected: not-a-virus:AdWare.Win32.Dap.c skipped
E:\System Volume Information\_restore{ED8B2F9C-2807-476C-9B80-AF4C801C46F9}\RP354\A0053864.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.Dap.c skipped
E:\System Volume Information\_restore{ED8B2F9C-2807-476C-9B80-AF4C801C46F9}\RP354\A0053864.exe WiseSFX: infected - 2 skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.