| Spyfalcon attack |  | 
			
			
			
				
					
					
				
			
			
			
			
			
				
				
					
				
				
				
				
					
						| froiNewbie 
   | 12. May 2006 @ 21:02 |  Link to this message   | 
					
					
					
						| 
							
							Hi,
I also have Spyfalcon problem. I have followed your instructions on these. I would like to post my hijackthis log file now for your help. Thanks a lot!
 | 
				
				
			
				
				
				
					
						| Advertisement   |   | 
					
						|  | 
				
				
				
					
						| froiNewbie 
   | 12. May 2006 @ 21:07 |  Link to this message   | 
					
					
					
						| 
							
							Logfile of HijackThis v1.99.1
Scan saved at 12:57:06 PM, on 5/13/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
 C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\igfxtray.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
 C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
 C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Documents and Settings\Froi Montero\Local Settings\Application Data\11e2d6fc.exe
 C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
 C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
 C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
 C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
 C:\WINDOWS\system32\svchost.exe
 C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
 C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
 C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
 C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Aware.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Program Files\Yahoo!\Messenger\YPager.exe
 C:\HJT\HijackThis.exe
 
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=21940
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
 O2 - BHO: (no name) - {b0398eca-0bcd-4645-8261-5e9dc70248d0} - (no file)
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
 O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
 O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [11e2d6fc.exe] C:\WINDOWS\system32\11e2d6fc.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [11e2d6fc.exe] C:\Documents and Settings\Froi Montero\Local Settings\Application Data\11e2d6fc.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1162
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{9F5A637B-FE73-435A-B6F4-424D1347ECE3}: NameServer = 202.78.97.41,202.78.97.3
 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
 O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
 O20 - Winlogon Notify: winwcn32 - C:\WINDOWS\SYSTEM32\winwcn32.dll
 O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
 O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
 O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
 O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
 O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
 O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
 O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
 | 
				
				
			
				
				
				
				
				
					
						| Senior Member 
   | 12. May 2006 @ 21:44 |  Link to this message   | 
					
					
					
						| 
							
							Hi froi, you got some infections...
 Download SmitfraudFix.zip to your desktop -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip
 
 Unzip it (folder named SmitFraudFix) to your desktop:
 
 Open the folder SmitfraudFix and doubleclick smitfraudfix.cmd
 Choose option #1 - Search by typing 1 and pressing "Enter"; a textfile opens and lists the infected files (if those exist)
 
 Post the contents of this textfile to here.
 
 (Some antiviruses recognises process.exe as a malware. It is not malware, it is a program that stops processes)
 
 Then we'll continue the cleaning.
 
 
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. | 
				
				
			
				
				
				
				
				
					
						| froiNewbie 
   | 12. May 2006 @ 22:38 |  Link to this message   | 
					
					
					
						| 
							
							SmitFraudFix v2.43
 Scan done at 14:44:46.59, Sat 05/13/2006
 Run from C:\Documents and Settings\Froi Montero\Desktop\SmitfraudFix\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 C:\WINDOWS\system32\appmagr.dll FOUND !
 C:\WINDOWS\system32\dcomcfg.exe FOUND !
 C:\WINDOWS\system32\regperf.exe FOUND !
 C:\WINDOWS\system32\simpole.tlb FOUND !
 C:\WINDOWS\system32\stdole3.tlb FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Froi Montero\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\FROIMO~1\FAVORI~1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="My Current Home Page"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{64ba30a2-811a-4597-b0af-d551128be340}"="AppManager"
 
 [HKEY_CLASSES_ROOT\CLSID\{64ba30a2-811a-4597-b0af-d551128be340}\InProcServer32]
 @="C:\WINDOWS\system32\appmagr.dll"
 
 [HKEY_CURRENT_USER\Software\Classes\CLSID\{64ba30a2-811a-4597-b0af-d551128be340}\InProcServer32]
 @="C:\WINDOWS\system32\appmagr.dll"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 | 
				
				
			
				
				
				
				
				
					
						| Senior Member 
   | 12. May 2006 @ 22:53 |  Link to this message   | 
					
					
					
						| 
							
							Ok...
 Cleaning instructions:
 
 Download and install Ewido, UPDATE it, but do NOT run a scan yet. -> http://www.ewido.net/en/download
 We'll use it later.
 
 Fix the following entries with HijackThis (run HijackThis, press "Do a system scan only", close all other windows, checkmark entries and press Fix checked):
 
 O4 - HKLM\..\Run: [11e2d6fc.exe] C:\WINDOWS\system32\11e2d6fc.exe
 O4 - HKCU\..\Run: [11e2d6fc.exe] C:\Documents and Settings\Froi Montero\Local Settings\Application Data\11e2d6fc.exe
 O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1162
 O20 - Winlogon Notify: winwcn32 - C:\WINDOWS\SYSTEM32\winwcn32.dll
 
 Then we'll take clean these Norton leftovers:
 
 Open Notepad
 -> copy the following lines into a new document:
 
 @echo off
 sc stop Automatic LiveUpdate Scheduler
 sc delete Automatic LiveUpdate Scheduler
 sc stop LiveUpdate
 sc delete LiveUpdate
 
 Save the document to your desktop as Removal.bat and filetype: All Files
 Go to your desktop and run the file Removal.bat and answer yes to any questions.
 
 Make your hidden files visible -> http://www.bleepingcomputer.com/tutorials/tutorial62.html
 
 Restart your computer to the safemode and choose your normal user account -> http://www.pchell.com/support/safemode.shtml
 
 Delete these files (if found):
 C:\WINDOWS\system32\11e2d6fc.exe
 C:\Documents and Settings\Froi Montero\Local Settings\Application Data\11e2d6fc.exe
 C:\WINDOWS\SYSTEM32\winwcn32.dll
 
 When in safemode, open SmitfraudFix folder and doubleclick the file smitfraudfix.cmd
 Choose option #2 - Clean by typing 2 and pressing "Enter" in order to remove the infected files.
 
 You are asked: "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove your desktop wallpaper and the infected registry keys.
 
 The tool checks if wininet.dll file is infected. You might be asked to replace the infected .dll (if found); answer "Yes" by typing Y and press "Enter".
 
 The tool might have to restart your computer; if it won't do it, restart your computer back to normal mode.
 A textfile will appear after the cleaning process, copy this file and paste it to here.
 Tha log is saved to your local diskdrive, usually C:\rapport.txt.
 
 Warning : Running option 2 in a clean computer will delete your desktop wallpaper.
 
 Scan and clean your computer with Ewido and save the log file.
 
 Make your hidden files invisible again -> http://www.bleepingcomputer.com/tutorials/tutorial62.html
 
 Post the following logs to here:
 -> a fresh HijackThis log
 -> Ewido's log
 -> contents of C:\rapport.txt
 
 Do you know what is the name of your ISP (internet service provider) ?
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. This message has been edited since posting. Last time this message was edited on 12. May 2006 @ 22:54 | 
				
				
			
				
				
				
				
				
					
						| froiNewbie 
   | 13. May 2006 @ 00:49 |  Link to this message   | 
					
					
					
						| 
							
							Logfile of HijackThis v1.99.1
Scan saved at 4:55:07 PM, on 5/13/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
 C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
 C:\WINDOWS\Explorer.EXE
 C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
 C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 C:\WINDOWS\system32\igfxtray.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
 C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
 C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\Yahoo!\Messenger\ypager.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\ewido anti-malware\ewidoctrl.exe
 C:\Program Files\ewido anti-malware\ewidoguard.exe
 C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
 C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
 C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
 C:\WINDOWS\system32\svchost.exe
 C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
 C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
 C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\HJT\HijackThis.exe
 C:\WINDOWS\system32\NOTEPAD.EXE
 
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=21940
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
 O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
 O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{9F5A637B-FE73-435A-B6F4-424D1347ECE3}: NameServer = 202.78.97.41,202.78.97.3
 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
 O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
 O20 - Winlogon Notify: winwcn32 - winwcn32.dll (file missing)
 O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
 O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
 O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
 O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
 O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
 O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
 O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
 | 
				
				
			
				
				
				
				
				
					
						| froiNewbie 
   | 13. May 2006 @ 00:54 |  Link to this message   | 
					
					
					
						| 
							
							---------------------------------------------------------
ewido anti-malware - Scan report
 ---------------------------------------------------------
 
 + Created on:			4:53:40 PM, 5/13/2006
 + Report-Checksum:		8E041263
 
 + Scan result:
 
 [848] C:\WINDOWS\system32\winwcn32.dll -> Trojan.Agent.qt : Error during cleaning
 C:\Documents and Settings\Froi Montero\Cookies\froi montero@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
 C:\Documents and Settings\Froi Montero\Cookies\froi montero@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned with backup
 C:\Documents and Settings\Froi Montero\Cookies\froi montero@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup
 C:\Documents and Settings\Froi Montero\Cookies\froi montero@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
 C:\RECYCLER\S-1-5-21-1757981266-1343024091-1060284298-1004\Dc1.exe -> Downloader.Tiny.bw : Cleaned with backup
 C:\WINDOWS\system32\11e2d6fc.exe -> Downloader.Tiny.bw : Cleaned with backup
 C:\WINDOWS\system32\__delete_on_reboot__winwcn32.dll -> Trojan.Agent.qt : Cleaned with backup
 
 
 ::Report End
 | 
				
				
			
				
				
				
				
				
					
						| froiNewbie 
   | 13. May 2006 @ 00:57 |  Link to this message   | 
					
					
					
						| 
							
							SmitFraudFix v2.43
 Scan done at 16:21:58.05, Sat 05/13/2006
 Run from C:\Documents and Settings\Froi Montero\Desktop\SmitfraudFix\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» Killing process
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
 
 C:\WINDOWS\system32\appmagr.dll Deleted
 C:\WINDOWS\system32\dcomcfg.exe Deleted
 C:\WINDOWS\system32\regperf.exe Deleted
 C:\WINDOWS\system32\simpole.tlb Deleted
 C:\WINDOWS\system32\stdole3.tlb Deleted
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
 
 Registry Cleaning done.
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 | 
				
				
			
				
				
				
				
				
					
						| froiNewbie 
   | 13. May 2006 @ 01:02 |  Link to this message   | 
					
					
					
						| 
							
							Whew, finally I don't have the recurring virus alert! :) Unfortunately, I don't know the ISP name. I just pay a monthly rental to our dormitory coordinator.
 Is my PC clean now? :) Thanks a lot for the help!
 | 
				
				
			
				
				
				
				
				
					
						| Senior Member 
   | 13. May 2006 @ 02:30 |  Link to this message   | 
					
					
					
						| 
							
							Almost, just one leftover that needs fixing :)
 Fix this entry with HijackThis:
 O20 - Winlogon Notify: winwcn32 - winwcn32.dll (file missing)
 
 Post a new HjT log to here.
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. | 
				
				
			
				
				
				
				
				
					
						| froiNewbie 
   | 13. May 2006 @ 02:37 |  Link to this message   | 
					
					
					
						| 
							
							Ok, thanks again. :)  Here is it:
 Logfile of HijackThis v1.99.1
 Scan saved at 6:44:26 PM, on 5/13/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
 C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
 C:\WINDOWS\Explorer.EXE
 C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
 C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 C:\WINDOWS\system32\igfxtray.exe
 C:\WINDOWS\system32\hkcmd.exe
 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
 C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
 C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\Yahoo!\Messenger\ypager.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\ewido anti-malware\ewidoctrl.exe
 C:\Program Files\ewido anti-malware\ewidoguard.exe
 C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
 C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
 C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
 C:\WINDOWS\system32\svchost.exe
 C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
 C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
 C:\Program Files\Chikka\chikka.exe
 C:\PROGRA~1\Chikka\BnrRepo2.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\Program Files\ewido anti-malware\SecuritySuite.exe
 C:\HJT\HijackThis.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.latimes.com/sports/basketball/nba/lakers/
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=21940
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
 O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
 O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
 O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
 O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
 O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/...
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O17 - HKLM\System\CCS\Services\Tcpip\..\{9F5A637B-FE73-435A-B6F4-424D1347ECE3}: NameServer = 202.78.97.41,202.78.97.3
 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
 O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
 O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
 O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
 O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
 O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
 O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
 O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
 O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
 O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
 | 
				
				
			
				
				
				
				
				
					
						| Senior Member 
   | 13. May 2006 @ 03:02 |  Link to this message   | 
					
					
					
						| 
							
							You're clean now :)
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. | 
				
				
			
				
				
				
				
				
					
						| froiNewbie 
   | 13. May 2006 @ 06:31 |  Link to this message   | 
					
					
					
						| 
							
							Thanks once again and more power to you! :)
							
						 | 
				
				
			
				
				
				
					
						| Advertisement   |   | 
					
						| 
 | 
				
				
				
					
						| Senior Member 
   | 13. May 2006 @ 11:04 |  Link to this message   | 
					
					
					
						| 
							
							You're welcome :)
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |