| google homepage keeps changing |  | 
			
			
			
				
					
					
				
			
			
			
			
			
				
				
					
				
				
				
				
					
						| pronneyAccount closed as per user's own request 
   | 6. May 2006 @ 07:20 |  Link to this message   | 
					
					
					
						| 
							
							hi.
i have a problem. my homepage which is set to google automatically changes to http://www.systemuptodate.com/. can anybody help.
 my hijack this file is
 
 Logfile of HijackThis v1.99.1
 Scan saved at 16:17:55, on 06/05/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\Windows Defender\MsMpEng.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 C:\Program Files\Norton AntiVirus\navapsvc.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\Windows Defender\MSASCui.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
 C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
 C:\Program Files\VIA\RAID\raid_tool.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\apps\HijackThis_v1.99.1[1].exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
 O2 - BHO: Nothing - {b0398eca-0bcd-4645-8261-5e9dc70248d0} - C:\WINDOWS\system32\hp8BE4.tmp
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
 O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
 O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
 O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/supergerball/miniclipGameLoader.dll
 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.truprint.co.uk/TruprintActivia.cab
 O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
 O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://activex.webcam.nl/AxisCamControl.cab
 O16 - DPF: {AEF76437-F960-4EBC-97EA-7BBB4230CF38} (OcarptMain Class) - https://oca.microsoft.com/en/secure/ocarpt.CAB
 O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 
 cheers
 
 paul
 | 
				
				
			
				
				
				
					
						| Advertisement   |   | 
					
						|  | 
				
				
				
					
						| pronneyAccount closed as per user's own request 
   | 6. May 2006 @ 07:30 |  Link to this message   | 
					
					
					
						| 
							
							also there is a program running in my system tray saying virus alert
							
						 | 
				
				
			
				
				
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 6. May 2006 @ 07:51 |  Link to this message   | 
					
					
					
						| 
							
							Hi pronney
 Download SmitfraudFix.zip to your desktop -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip
 
 Unzip it (folder named SmitFraudFix) to your desktop:
 
 Open the folder SmitfraudFix and doubleclick smitfraudfix.cmd
 Choose option #1 - Search by typing 1 and pressing "Enter"; a textfile opens and lists the infected files (if those exist)
 
 Post the contents of this textfile to here.
 
 (Some antiviruses recognises process.exe as a malware. It is not malware, it is a program that stops processes)
 | 
				
				
			
				
				
				
				
				
					
						| pronneyAccount closed as per user's own request 
   | 6. May 2006 @ 08:16 |  Link to this message   | 
					
					
					
						| 
							
							SmitFraudFix v2.40
 Scan done at 17:14:53.34, 06/05/2006
 Run from C:\smitfrude\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 C:\WINDOWS\system32\hp????.tmp FOUND !
 C:\WINDOWS\system32\ld????.tmp FOUND !
 C:\WINDOWS\system32\ot.ico FOUND !
 C:\WINDOWS\system32\reglogs.dll FOUND !
 C:\WINDOWS\system32\simpole.tlb FOUND !
 C:\WINDOWS\system32\stdole3.tlb FOUND !
 C:\WINDOWS\system32\ts.ico FOUND !
 C:\WINDOWS\system32\1024\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Pauls\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Pauls\FAVORI~1
 
 C:\DOCUME~1\Pauls\FAVORI~1\Antivirus Test Online.url FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="My Current Home Page"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{35a88e51-b53d-43e9-b8a7-75d4c31b4676}"="Register LogWare"
 
 [HKEY_CLASSES_ROOT\CLSID\{35a88e51-b53d-43e9-b8a7-75d4c31b4676}\InProcServer32]
 @="C:\WINDOWS\system32\reglogs.dll"
 
 [HKEY_CURRENT_USER\Software\Classes\CLSID\{35a88e51-b53d-43e9-b8a7-75d4c31b4676}\InProcServer32]
 @="C:\WINDOWS\system32\reglogs.dll"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 | 
				
				
			
				
				
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 6. May 2006 @ 08:23 |  Link to this message   | 
					
					
					
						| 
							
							* Reboot your computer in Safe Mode (before the Windows icon appears, tap the F8 key continually)
* Double-click smitfraudfix.cmd
 * Select 2 and hit Enter to delete infect files.
 * You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
 * The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
 * A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt
 
 Send contents of that file and a fresh HjT log
 | 
				
				
			
				
				
				
				
				
					
						| pronneyAccount closed as per user's own request 
   | 6. May 2006 @ 08:46 |  Link to this message   | 
					
					
					
						| 
							
							thank you
 it seems to be ok now. all back to normal. have included the files if you still want to see then
 
 paul
 
 SmitFraudFix v2.40
 
 Scan done at 17:39:49.78, 06/05/2006
 Run from C:\smitfrude\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» Killing process
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
 
 C:\WINDOWS\system32\hp????.tmp Deleted
 C:\WINDOWS\system32\ld????.tmp Deleted
 C:\WINDOWS\system32\ot.ico Deleted
 C:\WINDOWS\system32\reglogs.dll Deleted
 C:\WINDOWS\system32\simpole.tlb Deleted
 C:\WINDOWS\system32\stdole3.tlb Deleted
 C:\WINDOWS\system32\ts.ico Deleted
 C:\WINDOWS\system32\1024\ Deleted
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
 
 Registry Cleaning done.
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 Logfile of HijackThis v1.99.1
 Scan saved at 17:44:37, on 06/05/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\Windows Defender\MsMpEng.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 C:\Program Files\Norton AntiVirus\navapsvc.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\Windows Defender\MSASCui.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
 C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\VIA\RAID\raid_tool.exe
 C:\Program Files\Outlook Express\msimn.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\apps\HijackThis_v1.99.1[1].exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
 O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
 O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
 O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
 O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/supergerball/miniclipGameLoader.dll
 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.truprint.co.uk/TruprintActivia.cab
 O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
 O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://activex.webcam.nl/AxisCamControl.cab
 O16 - DPF: {AEF76437-F960-4EBC-97EA-7BBB4230CF38} (OcarptMain Class) - https://oca.microsoft.com/en/secure/ocarpt.CAB
 O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 | 
				
				
			
				
				
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 6. May 2006 @ 08:54 |  Link to this message   | 
					
					
					
						| 
							
							Yes, it looks good and smitfraud is gone.
 These lines needs to be fixed, anyway(open HijackThis, click do a system scan only, checkmark these and press fix checked):
 
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
 O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/supergerball/miniclipGameLoader.dll
 
 Also, Java update would be nice:
 
 Java update:
 
 Click Start -> Control Panel and doubleclick Java-icon (coffee cup).
 Go to "Update" - tab . Update your Java by clicking "Update Now" and then reboot.
 If you are unable to perform an automatic update, please download Java from this address:
 
 
 http://www.java.com/en/download/manual.jsp
 
 
 After reboot, go back to Control Panel and Java.
 In Temporary Internet Files, click Delete Files-button.
 Make sure that all these three options are checkmarked:
 
 
 Downloaded Applets
 Downloaded Applications
 Other Files
 
 
 Click OK in "Delete Temporary Internet Files" window.
 
 After that, you can uninstall older version of Java via Add/remove programs in Control Panel
 
 It should look like this:
 
 Quote:Reboot and send a fresh HjT log.Java 2 Runtime Environment, SE v1.5.0_04
 
 | 
				
				
			
				
				
				
				
				
					
						| pronneyAccount closed as per user's own request 
   | 6. May 2006 @ 09:08 |  Link to this message   | 
					
					
					
						| 
							
							here is the new log file
 
 Logfile of HijackThis v1.99.1
 Scan saved at 18:07:14, on 06/05/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\Windows Defender\MsMpEng.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 C:\Program Files\Norton AntiVirus\navapsvc.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\Windows Defender\MSASCui.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
 C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
 C:\Program Files\VIA\RAID\raid_tool.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\system32\msiexec.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\apps\HijackThis_v1.99.1[1].exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
 O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
 O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
 O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.truprint.co.uk/TruprintActivia.cab
 O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
 O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://activex.webcam.nl/AxisCamControl.cab
 O16 - DPF: {AEF76437-F960-4EBC-97EA-7BBB4230CF38} (OcarptMain Class) - https://oca.microsoft.com/en/secure/ocarpt.CAB
 O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 | 
				
				
			
				
				
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 6. May 2006 @ 09:12 |  Link to this message   | 
					
					
					
						| 
							
							It's clean :)
							
						 | 
				
				
			
				
				
				
				
				
					
						| pronneyAccount closed as per user's own request 
   | 6. May 2006 @ 09:12 |  Link to this message   | 
					
					
					
						| 
							
							thank you for all your help
 paul
 | 
				
				
			
				
				
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 6. May 2006 @ 09:16 |  Link to this message   | 
					
					
					
						| 
							
							Nice to hear and you´re welcome :)
							
						 | 
				
				
			
				
				
				
				
				
					
						| orintukNewbie 
   | 8. May 2006 @ 14:48 |  Link to this message   | 
					
					
					
						| 
							
							Hey please can someone help me ive bene trying to get rid of this stupid thing all day and i cant heres my smitfraudfix thing. Hope someone will help. 
 
 SmitFraudFix v2.41
 
 Scan done at 23:42:47.67, 08/05/2006
 Run from C:\Unzipped\SmitfraudFix[1]\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 C:\WINDOWS\system32\atmclk.exe FOUND !
 C:\WINDOWS\system32\dcomcfg.exe FOUND !
 C:\WINDOWS\system32\hp????.tmp FOUND !
 C:\WINDOWS\system32\regperf.exe FOUND !
 C:\WINDOWS\system32\reglogs.dll FOUND !
 C:\WINDOWS\system32\simpole.tlb FOUND !
 C:\WINDOWS\system32\stdole3.tlb FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Orin\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Orin\FAVORI~1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="My Current Home Page"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 | 
				
				
			
				
				
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 8. May 2006 @ 21:43 |  Link to this message   | 
					
					
					
						| 
							
							@orintuk:
 * Reboot your computer in Safe Mode (before the Windows icon appears, tap the F8 key continually)
 * Double-click smitfraudfix.cmd
 * Select 2 and hit Enter to delete infect files.
 * You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
 * The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
 * A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt
 
 Send contents of that file and a HjT log, instructions -> http://forums.afterdawn.com/thread_view.cfm/263784 (steps 3-5).
 | 
				
				
			
				
				
				
				
				
					
						| orintukNewbie 
   | 9. May 2006 @ 01:05 |  Link to this message   | 
					
					
					
						| 
							
							Hey Kemisti seems to be fine now heres both logs. Thanks
 Logfile of HijackThis v1.99.1
 Scan saved at 10:02:25, on 09/05/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
 C:\WINDOWS\System32\nvsvc32.exe
 C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
 C:\WINDOWS\wanmpsvc.exe
 C:\WINDOWS\notepad.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Documents and Settings\Orin\Local Settings\Temporary Internet Files\Content.IE5\83YXWV0P\HijackThis_v1.99.1[1].exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O4 - Startup: csrss.lnk = ?
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
 O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
 
 SmitFraudFix v2.41
 
 Scan done at  9:58:44.26, 09/05/2006
 Run from C:\Unzipped\SmitfraudFix[1]\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Orin\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Orin\FAVORI~1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 
 What u think?
 | 
				
				
			
				
				
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 9. May 2006 @ 02:07 |  Link to this message   | 
					
					
					
						| 
							
							@orintuk: Smitfraud has left but you have another virus:
 Download MsnVirRem.exe on your desktop from one of the links below :
 http://downloads.malwareremoval.com/MsnVirRem.exe
 http://www.thespykiller.co.uk/forum/index.php?action=tpmod;dl=item9
 
 [*]Close all open windows because this step requires reboot
 [*]Double-click MsnVirRem.exe
 [*]When MsnVirRem opens, click "]Search and Destroy"
 <<Your computer will be checked for infection>>
 [*]When ready, you will be asked to reboot if you have infection , click OK
 [*]Next click "REBOOT" .
 [*]Upon reboot you will get 4 error messages, that's normalK
 [*]MsnVirRem should give you a message, if not double-click  double-click program again .
 Send contents of C:\msnvirrem.log along with a fresh HijackThis log.
 | 
				
				
			
				
				
				
				
				
					
						| orintukNewbie 
   | 9. May 2006 @ 03:04 |  Link to this message   | 
					
					
					
						| 
							
							hey thanks again for the help heres the log for hijakthis but i didnt know how to do one for msn one hope its ok now.
 Logfile of HijackThis v1.99.1
 Scan saved at 12:02:23, on 09/05/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
 C:\WINDOWS\System32\nvsvc32.exe
 C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
 C:\WINDOWS\wanmpsvc.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Documents and Settings\Orin\Desktop\HijackThis_v1.99.1.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/firefox
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O4 - Global Startup: MsnVirRem.exe
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
 O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
 | 
				
				
			
				
				
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 9. May 2006 @ 04:36 |  Link to this message   | 
					
					
					
						|  | 
				
				
			
				
				
				
				
				
					
						| orintukNewbie 
   | 9. May 2006 @ 08:09 |  Link to this message   | 
					
					
					
						| 
							
							Hey i did run the msn program yesterday and follwed the instructions and it deleted the virus on my computer but i didnt know how to get the log file from it. I have ran it again and no infection is found and the log file shows nothing. Does that mean that the virus is gone now cheers.
							
						 | 
				
				
			
				
				
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 9. May 2006 @ 08:26 |  Link to this message   | 
					
					
					
						|  | 
				
				
			
				
				
				
				
				
					
						| guppy99Suspended due to non-functional email address 
   | 9. May 2006 @ 08:41 |  Link to this message   | 
					
					
					
						| 
							
							Hi -Kemisti-
 By any chance would you have time to help in my post for infection of SpyFalcon (and other adware)? I am losing my mind with the constant "security alert" popups!! :-(
 
 You can find my post with my HjT and SmitFraud files already posted just a few under this thread. I hope I don't sound impatient but two days of this and so much wasted time trying all these different fixes...has led me to my current state.
 Thanks so much in advance!
 
 
 ~AB | 
				
				
			
				
				
				
				
				
					
						| orintukNewbie 
   | 9. May 2006 @ 10:07 |  Link to this message   | 
					
					
					
						| 
							
							Thanks for all your help man appreciate it very much !!!!
							
						 | 
				
				
			
				
				
				
				
				
					
						| rdemirciSuspended due to non-functional email address 
   | 9. May 2006 @ 10:50 |  Link to this message   | 
					
					
					
						| 
							
							Hi Kemisti, 
 I got same problem as Pronney's and followed your instructions (thanks for it)to delete the infect files. After deleting I had log file but I don't understant what it means. Also I used HijackThis software but it asked me to ask someone to click some files to delete. If you check my logs below and tell me what to do I would be thanfull for it.
 
 
 SmitFraudFix v2.41
 
 Scan done at 19:04:07.99, 09/05/2006
 Run from C:\Documents and Settings\Refik\Desktop\SmitfraudFix\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» Killing process
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
 
 C:\WINDOWS\system32\atmclk.exe Deleted
 C:\WINDOWS\system32\dcomcfg.exe Deleted
 C:\WINDOWS\system32\hp????.tmp Deleted
 C:\WINDOWS\system32\ld????.tmp Deleted
 C:\WINDOWS\system32\ot.ico Deleted
 C:\WINDOWS\system32\regperf.exe Deleted
 C:\WINDOWS\system32\reglogs.dll Deleted
 C:\WINDOWS\system32\simpole.tlb Deleted
 C:\WINDOWS\system32\stdole3.tlb Deleted
 C:\WINDOWS\system32\ts.ico Deleted
 C:\WINDOWS\system32\1024\ Deleted
 C:\DOCUME~1\Refik\FAVORI~1\Antivirus Test Online.url Deleted
 C:\Program Files\PestTrap\ Deleted
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
 
 Registry Cleaning done.
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 
 -----------------------------------------------------------------
 
 
 
 Logfile of HijackThis v1.99.1
 
 Scan saved at 19:17:16, on 09/05/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\D-Link\AirPlusG+\AirPlus.exe
 C:\WINDOWS\soundman.exe
 C:\Program Files\Apoint2K\Apoint.exe
 C:\PROGRA~1\EzButton\CPATR10.EXE
 C:\Program Files\F-Secure\Common\FSM32.EXE
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\Skype\Phone\Skype.exe
 C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
 C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
 C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
 C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
 C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
 C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
 C:\Program Files\F-Secure\Common\FSMA32.EXE
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\F-Secure\Common\FSMB32.EXE
 C:\WINDOWS\system32\slserv.exe
 C:\Program Files\F-Secure\Common\FCH32.EXE
 C:\Program Files\Apoint2K\Apntex.exe
 C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearchIndexer.exe
 C:\Program Files\F-Secure\Common\FAMEH32.EXE
 C:\Program Files\F-Secure\BackWeb\7681197\Program\F-Secure Automatic Update.exe
 C:\Program Files\F-Secure\Common\FNRB32.EXE
 C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
 C:\Program Files\F-Secure\Common\FIH32.EXE
 C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
 C:\Program Files\F-Secure\FSGUI\fsguiexe.exe
 C:\Program Files\Internet Explorer\IEXPLORE.EXE
 C:\WINDOWS\system32\wuauclt.exe
 C:\Documents and Settings\Refik\Desktop\HijackThis_v1.99.1.exe
 C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearchFilter.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
 O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
 O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
 O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
 O4 - HKLM\..\Run: [GUI] C:\D-Link\AirPlusG+\AirPlus.exe
 O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
 O4 - HKLM\..\Run: [SoundMan] soundman.exe
 O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [CPATR10] C:\PROGRA~1\EzButton\CPATR10.EXE
 O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
 O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
 O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
 O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll/search.htm
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
 O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-gb\msntabres.dll/229?8907aba64705494aa9fee9fa1164fa55
 O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-gb\msntabres.dll/230?8907aba64705494aa9fee9fa1164fa55
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
 O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - BackWeb Technologies Inc.                          - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
 O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
 O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
 O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
 O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
 O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
 
 
 
 thanks,
 
 Refik
 | 
				
				
			
				
				
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 9. May 2006 @ 22:54 |  Link to this message   | 
					
					
					
						| 
							
							@orintuk: Nice to hear :)
 @rdemirci: Logs are clean. Do you still have problems?
 | 
				
				
			
				
				
				
				
				
					
						| rdemirciSuspended due to non-functional email address 
   | 10. May 2006 @ 03:49 |  Link to this message   | 
					
					
					
						| 
							
							Hi Kemisti,
 Thanks for your interest.
 
 My F-secure antvirus program identified "not-virus:Hoax.Win32.Renos" infection but can not take an action for it. My scan results below,
 Scanning Report
 09 May 2006 17:00:00 - 17:31:10
 Computer name: STUDENT
 Target: C:\ D:\
 
 
 --------------------------------------------------------------------------------
 
 Result: 1 viruses found
 
 C:\WINDOWS\system32\reglogs.dll Infection: not-virus:Hoax
 
 
 --------------------------------------------------------------------------------
 
 Statistics
 Files:
 Scanned: 17761
 Infected: 1
 Suspected: 0
 Disinfected: 0
 Renamed: 0
 Deleted: 0
 Not scanned: 5
 Boot Sectors:
 Scanned: 0
 Infected: 0
 Suspected: 0
 Disinfected: 0
 
 Files not scanned:
 Cannot open file C:\hiberfil.sys
 Cannot open file C:\pagefile.sys
 Cannot open file C:\WINDOWS\system32\config\default
 Scanning of C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig705\ENU\Data1.cab\AcroRd32.dll was aborted [F-Secure AVP]
 Scanning of C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig705\ENU\Data1.cab\SVGCore.DLL was aborted [F-Secure AVP]
 
 
 
 Also the computer needed to install updates for windows but it says "updates were unable to be succcessfully installed"  for the "Security Update for Flash Player (KB913433)" file.
 
 Thanks.
 Refik.
 | 
				
				
			
				
				
				
					
						| Advertisement   |   | 
					
						| 
 | 
				
				
				
					
						| -kemisti-AfterDawn Addict 
   | 10. May 2006 @ 03:59 |  Link to this message   | 
					
					
					
						| 
							
							@rdemirci: That file is already deleted:
 SmitFraudFix v2.41
 
 Scan done at 19:04:07.99, 09/05/2006
 Run from C:\Documents and Settings\Refik\Desktop\SmitfraudFix\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» Killing process
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
 
 C:\WINDOWS\system32\atmclk.exe Deleted
 C:\WINDOWS\system32\dcomcfg.exe Deleted
 C:\WINDOWS\system32\hp????.tmp Deleted
 C:\WINDOWS\system32\ld????.tmp Deleted
 C:\WINDOWS\system32\ot.ico Deleted
 C:\WINDOWS\system32\regperf.exe Deleted
 C:\WINDOWS\system32\reglogs.dll Deleted
 C:\WINDOWS\system32\simpole.tlb Deleted
 C:\WINDOWS\system32\stdole3.tlb Deleted
 C:\WINDOWS\system32\ts.ico Deleted
 C:\WINDOWS\system32\1024\ Deleted
 C:\DOCUME~1\Refik\FAVORI~1\Antivirus Test Online.url Deleted
 C:\Program Files\PestTrap\ Deleted
 
 For the updates, have you tried more than once?
 |