|  | 
 
															
															
	
			
			
				| Ugly Virus |  |  
					
					
				 
						| Member 
   | 1. June 2006 @ 22:21 |  Link to this message   |  
						| 
							
							  
 
 Heres my HJY log:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 11:04:51 PM, on 6/1/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\Program Files\LEAD Technologies, Inc\LEADTOOLS ePrint 3.0\Bin\LPSVS03N.EXE
 C:\Program Files\ewido\security suite\ewidoctrl.exe
 C:\WINDOWS\system32\LckFldService.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
 C:\WINDOWS\system32\fxssvc.exe
 C:\WINDOWS\system32\ZoneLabs\isafe.exe
 C:\WINDOWS\system32\dcomcfg.exe
 C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\PROGRA~1\LEADTE~1\LEADTO~1.0\bin\EPRINT3.EXE
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
 C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
 C:\Program Files\SuperGOO\EREG\US\REMIND32.EXE
 C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
 C:\Program Files\ewido\security suite\SecuritySuite.exe
 C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
 C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe
 C:\Program Files\TechSmith\SnagIt 8\TSCHelp.exe
 C:\Program Files\Mozilla Firefox\firefox.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\DOCUME~1\CARLOS~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
 
 O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: Nothing - {6ab7158b-4bff-4160-ad7d-4d622df548cf} - C:\WINDOWS\system32\hp100.tmp
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
 O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
 O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
 O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
 O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
 O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
 O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [ePrint 3.0 Service] C:\PROGRA~1\LEADTE~1\LEADTO~1.0\bin\EPRINT3.EXE
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\COMMON~1\TEKNUM~1\update.exe /startup
 O4 - Startup: SyncBack.lnk = C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
 O4 - Startup: reminder-ScanSoft Product Registration.lnk = C:\Program Files\SuperGOO\EREG\US\REMIND32.EXE
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
 O23 - Service: EPrint III Service - Unknown owner - C:\Program Files\LEAD Technologies, Inc\LEADTOOLS ePrint 3.0\Bin\LPSVS03N.EXE
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
 O23 - Service: LckFldService - Unknown owner - C:\WINDOWS\system32\LckFldService.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
 
 Any help will be appreciated.
 
 
 Thank you, 
 cm
 |  
						| Advertisement   |   |  
						|  |  
						| Member 
   | 1. June 2006 @ 22:25 |  Link to this message   |  
						| 
 Thank you, 
 cm
 |  
						| Senior Member 
   | 2. June 2006 @ 00:25 |  Link to this message   |  
						| 
							
							Hi cmaldona, you got a smitfraud infection...
 Download SmitfraudFix.zip to your desktop -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip
 
 Unzip it (folder named SmitFraudFix) to your desktop:
 
 Open the folder SmitfraudFix and doubleclick smitfraudfix.cmd
 Choose option #1 - Search by typing 1 and pressing "Enter"; a textfile opens and lists the infected files (if those exist)
 
 Post the contents of this textfile to here.
 
 (Some antiviruses recognises process.exe as a malware. It is not malware, it is a program that stops processes)
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| Member 
   | 2. June 2006 @ 08:27 |  Link to this message   |  
						| 
							
							Looks like my PC is really sick. Also, IE keeps on defaulting on this: http://www.securityuptodate.net/
 Here is the result on SmitFraudFix report:
 
 SmitFraudFix v2.53
 
 Scan done at  9:24:05.79, Fri 06/02/2006
 Run from C:\Documents and Settings\Carlos Maldonado\Local Settings\Temp\SmitfraudFix\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in normal mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 C:\WINDOWS\system32\atmclk.exe FOUND !
 C:\WINDOWS\system32\dcomcfg.exe FOUND !
 C:\WINDOWS\system32\dxole32.exe FOUND !
 C:\WINDOWS\system32\hp???.tmp FOUND !
 C:\WINDOWS\system32\hp????.tmp FOUND !
 C:\WINDOWS\system32\imfdfcj.dll FOUND !
 C:\WINDOWS\system32\ld????.tmp FOUND !
 C:\WINDOWS\system32\migicons.exe FOUND !
 C:\WINDOWS\system32\ot.ico FOUND !
 C:\WINDOWS\system32\regperf.exe FOUND !
 C:\WINDOWS\system32\simpole.tlb FOUND !
 C:\WINDOWS\system32\stdole3.tlb FOUND !
 C:\WINDOWS\system32\ts.ico FOUND !
 C:\WINDOWS\system32\1024\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Carlos Maldonado\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\CARLOS~1\FAVORI~1
 
 C:\DOCUME~1\CARLOS~1\FAVORI~1\Antivirus Test Online.url FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 C:\Program Files\Security Toolbar\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="My Current Home Page"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{e5b1e382-817e-4b74-8a96-ec78751e6acf}"="incatenate"
 
 [HKEY_CLASSES_ROOT\CLSID\{e5b1e382-817e-4b74-8a96-ec78751e6acf}\InProcServer32]
 @="C:\WINDOWS\system32\imfdfcj.dll"
 
 [HKEY_CURRENT_USER\Software\Classes\CLSID\{e5b1e382-817e-4b74-8a96-ec78751e6acf}\InProcServer32]
 @="C:\WINDOWS\system32\imfdfcj.dll"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 Your help is appreciated.
 
 
 
 
 
 
 Thank you, 
 cm
 |  
						| Senior Member 
   | 2. June 2006 @ 22:00 |  Link to this message   |  
						| 
							
							Ok lets get you cleaned then....
 Cleaning instructions:
 
 Move HijackThis into its own folder C:\HJT
 
 Download and install Ewido anti-malware -> http://www.ewido.net/en/download
 Update it, but do NOT run a scan yet. We'll use it later.
 
 At frst we'll remove this Norton leftover...
 
 Open Notepad
 -> copy the following lines into a new document:
 
 @echo off
 sc stop SNDSrvc
 sc delete SNDSrvc
 
 Save the document to your desktop as Removal.bat and filetype: All Files
 Go to your desktop and run the file Removal.bat and answer yes to any questions
 
 Restart your computer to the safemode and choose your normal user account -> http://www.pchell.com/support/safemode.shtml
 
 When in safemode, open SmitfraudFix folder and doubleclick the file smitfraudfix.cmd
 Choose option #2 - Clean by typing 2 and pressing "Enter" in order to remove the infected files.
 
 You are asked: "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove your desktop wallpaper and the infected registry keys.
 
 The tool checks if wininet.dll file is infected. You might be asked to replace the infected .dll (if found); answer "Yes" by typing Y and press "Enter".
 
 The tool might have to restart your computer; if it won't do it, restart your computer back to normal mode.
 A textfile will appear after the cleaning process, copy this file and paste it to here.
 
 Tha log is saved to your local diskdrive, usually C:\rapport.txt.
 
 Warning : Running option 2 in a clean computer will delete your desktop wallpaper.
 
 Scan and clean your computer with Ewido and save the report.
 
 Remove this folder if found:
 C:\Program Files\Common Files\Symantec Shared
 
 Post the following logs to here:
 -> a fresh HijackThis log
 -> Ewido's log
 -> contents of C:\rapport.txt
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| Member 
   | 3. June 2006 @ 15:34 |  Link to this message   |  
						| 
							
							First of all thank you for taking the time to help me.
 Here is the HJTL
 
 Logfile of HijackThis v1.99.1
 Scan saved at 4:22:12 PM, on 6/3/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\PROGRA~1\LEADTE~1\LEADTO~1.0\bin\EPRINT3.EXE
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
 C:\Program Files\SuperGOO\EREG\US\REMIND32.EXE
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\Program Files\LEAD Technologies, Inc\LEADTOOLS ePrint 3.0\Bin\LPSVS03N.EXE
 C:\Program Files\ewido\security suite\ewidoctrl.exe
 C:\WINDOWS\system32\LckFldService.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
 C:\WINDOWS\system32\fxssvc.exe
 C:\WINDOWS\system32\ZoneLabs\isafe.exe
 C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
 C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe
 C:\Program Files\TechSmith\SnagIt 8\TSCHelp.exe
 C:\DOCUME~1\CARLOS~1\LOCALS~1\Temp\Temporary Directory 1 for HijackThis.zip\HijackThis.exe
 
 O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: Nothing - {6ab7158b-4bff-4160-ad7d-4d622df548cf} - C:\WINDOWS\system32\hp100.tmp (file missing)
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
 O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
 O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
 O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
 O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
 O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
 O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [ePrint 3.0 Service] C:\PROGRA~1\LEADTE~1\LEADTO~1.0\bin\EPRINT3.EXE
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\COMMON~1\TEKNUM~1\update.exe /startup
 O4 - Startup: SyncBack.lnk = C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
 O4 - Startup: reminder-ScanSoft Product Registration.lnk = C:\Program Files\SuperGOO\EREG\US\REMIND32.EXE
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
 O23 - Service: EPrint III Service - Unknown owner - C:\Program Files\LEAD Technologies, Inc\LEADTOOLS ePrint 3.0\Bin\LPSVS03N.EXE
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
 O23 - Service: LckFldService - Unknown owner - C:\WINDOWS\system32\LckFldService.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
 
 Here is the Ewido log:
 
 ---------------------------------------------------------
 ewido anti-malware - Scan report
 ---------------------------------------------------------
 
 + Created on:			4:16:11 PM, 6/3/2006
 + Report-Checksum:		4DA6D421
 
 + Scan result:
 
 C:\System Volume Information\_restore{02E67161-3C2C-4904-95C9-595227685DF7}\RP2\A0001073.exe -> Downloader.Agent.amv : Cleaned with backup
 
 
 ::Report End
 
 Here is the rapport txt:
 
 SmitFraudFix v2.53
 
 Scan done at  7:53:25.70, Sat 06/03/2006
 Run from C:\Documents and Settings\Carlos Maldonado\My Documents\Save By Owner\Downloads\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in safe mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{e5b1e382-817e-4b74-8a96-ec78751e6acf}"="incatenate"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Killing process
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
 
 C:\WINDOWS\system32\atmclk.exe Deleted
 C:\WINDOWS\system32\dcomcfg.exe Deleted
 C:\WINDOWS\system32\dxole32.exe Deleted
 C:\WINDOWS\system32\hp???.tmp Deleted
 C:\WINDOWS\system32\imfdfcj.dll Deleted
 C:\WINDOWS\system32\ld????.tmp Deleted
 C:\WINDOWS\system32\migicons.exe Deleted
 C:\WINDOWS\system32\ot.ico Deleted
 C:\WINDOWS\system32\regperf.exe Deleted
 C:\WINDOWS\system32\simpole.tlb Deleted
 C:\WINDOWS\system32\stdole3.tlb Deleted
 C:\WINDOWS\system32\ts.ico Deleted
 C:\WINDOWS\system32\1024\ Deleted
 C:\Program Files\Security Toolbar\ Deleted
 
 »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
 
 GenericRenosFix by S!Ri
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
 
 Registry Cleaning done.
 
 »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 As I was running Ewido I got these 2 on the screen:
 
 [URL=http://www.imagehosting.us/index.php?action=show&ident=1401896][I...
 
 I really, really appreciate your assitance.
 
 
 
 
 
 
 
 
 Thank you, 
 cm
 |  
						| Member 
   | 3. June 2006 @ 15:36 |  Link to this message   |  
						| 
 Thank you, 
 cm
 |  
						| Member 
   | 3. June 2006 @ 16:25 |  Link to this message   |  
						| 
							
							Just wanted to give you an update. I ran Panda and found the following:
 
 Incident                                                                        Status                        Location
 
 Adware:adware/gator                                                             Not disinfected               c:\windows\FT1_02_0_402_GEPFAH.EXE
 Adware:adware/emediacodec                                                       Not disinfected               Windows Registry
 Spyware:spyware/cws.olehelp                                                     Not disinfected               Windows Registry
 Adware:adware/securitytoolbar                                                   Not disinfected               Windows Registry
 
 
 
 
 
 Thank you, 
 cm
 |  
						| Senior Member 
   | 4. June 2006 @ 00:58 |  Link to this message   |  
						| 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| Member 
   | 5. June 2006 @ 07:25 |  Link to this message   |  
						| 
							
							I am sorry for the delay, I had a busy weekend but here are my reports:
 
 -------------------------------------------------------------------------------
 KASPERSKY ON-LINE SCANNER REPORT
 Monday, June 05, 2006 8:16:33 AM
 Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
 Kaspersky On-line Scanner version: 5.0.78.0
 Kaspersky Anti-Virus database last update:  4/06/2006
 Kaspersky Anti-Virus database records: 186580
 -------------------------------------------------------------------------------
 
 Scan Settings:
 Scan using the following antivirus database: standard
 Scan Archives: true
 Scan Mail Bases: true
 
 Scan Target - My Computer:
 A:\
 C:\
 D:\
 
 Scan Statistics:
 Total number of scanned objects: 131914
 Number of viruses found: 6
 Number of infected objects: 10
 Number of suspicious objects: 0
 Duration of the scan process: 01:29:07
 
 Infected Object Name / Virus Name / Last Action
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\19A00660	Infected: Trojan-Downloader.Win32.Ladder.a	skipped
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4C853588	Infected: Trojan-Dropper.Win32.Agent.r	skipped
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\5B0C7B89	Infected: Trojan-Downloader.Win32.Agent.ae	skipped
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4C885F84	Infected: Trojan-Downloader.Win32.Agent.ae	skipped
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4C8B0981	Infected: Trojan-Downloader.Win32.Agent.ae	skipped
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4C8F337D	Infected: Trojan-Downloader.Win32.Agent.ae	skipped
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\2C641587	Infected: Trojan-Downloader.Win32.Agent.ae	skipped
 C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4C950776	Infected: Trojan-Downloader.Win32.Agent.ab	skipped
 C:\System Volume Information\_restore{02E67161-3C2C-4904-95C9-595227685DF7}\RP2\A0001074.exe	Infected: Trojan.Win32.StartPage.ajv	skipped
 C:\System Volume Information\_restore{02E67161-3C2C-4904-95C9-595227685DF7}\RP2\A0001079.exe	Infected: Trojan-Downloader.Win32.Zlob.aj	skipped
 
 Scan process completed.
 
 ____________________________________________________________________
 
 
 
 Logfile of HijackThis v1.99.1
 Scan saved at 8:20:28 AM, on 6/5/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\PROGRA~1\LEADTE~1\LEADTO~1.0\bin\EPRINT3.EXE
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\Program Files\SuperGOO\EREG\US\REMIND32.EXE
 C:\Program Files\LEAD Technologies, Inc\LEADTOOLS ePrint 3.0\Bin\LPSVS03N.EXE
 C:\Program Files\ewido\security suite\ewidoctrl.exe
 C:\WINDOWS\system32\LckFldService.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
 C:\WINDOWS\system32\fxssvc.exe
 C:\WINDOWS\system32\ZoneLabs\isafe.exe
 C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
 C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe
 C:\Program Files\TechSmith\SnagIt 8\TSCHelp.exe
 C:\HijackThis.exe
 
 O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
 O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
 O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
 O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
 O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
 O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
 O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [ePrint 3.0 Service] C:\PROGRA~1\LEADTE~1\LEADTO~1.0\bin\EPRINT3.EXE
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\COMMON~1\TEKNUM~1\update.exe /startup
 O4 - Startup: SyncBack.lnk = C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
 O4 - Startup: reminder-ScanSoft Product Registration.lnk = C:\Program Files\SuperGOO\EREG\US\REMIND32.EXE
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
 O23 - Service: EPrint III Service - Unknown owner - C:\Program Files\LEAD Technologies, Inc\LEADTOOLS ePrint 3.0\Bin\LPSVS03N.EXE
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
 O23 - Service: LckFldService - Unknown owner - C:\WINDOWS\system32\LckFldService.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
 
 I really appreciate all you are doing for me.
 
 
 
 
 
 
 
 
 Thank you, 
 cm
 |  
						| Member 
   | 5. June 2006 @ 09:33 |  Link to this message   |  
						| 
							
							Just wanted to give you an update.
 The image I sent you on 06/02/06 is still the same. AVG and
 ZA show the same 2 viruses.
 
 I ran another Panda and here is the result:
 
 
 Incident                                                                        Status                        Location
 
 Potentially unwanted tool:Application/Processor                                 Not disinfected               C:\Documents and Settings\Carlos Maldonado\My Documents\Save By Owner\Downloads\SmitfraudFix.zip[SmitfraudFix/Process.exe]
 Potentially unwanted tool:Application/Processor                                 Not disinfected               C:\Documents and Settings\Carlos Maldonado\My Documents\Save By Owner\Downloads\SmitfraudFix\Process.exe
 Adware:Adware/Twain-Tech                                                        Not disinfected               C:\Recycled\NPROTECT\00010401.inf
 
 
 
 Thank you, 
 cm
 |  
						| Senior Member 
   | 5. June 2006 @ 10:52 |  Link to this message   |  
						| 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. This message has been edited since posting. Last time this message was edited on 5. June 2006 @ 10:53 |  
						| Member 
   | 9. June 2006 @ 17:35 |  Link to this message   |  
						| 
							
							I do not know why I did not see your last post.
 Here is my new report:
 
 SmitFraudFix v2.53
 
 Scan done at 18:33:34.25, Fri 06/09/2006
 Run from C:\Documents and Settings\Carlos Maldonado\My Documents\Save By Owner\Downloads\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in normal mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Carlos Maldonado\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\CARLOS~1\FAVORI~1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="My Current Home Page"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 
 
 
 Thank you, 
 cm
 |  
						| Senior Member 
   | 9. June 2006 @ 21:47 |  Link to this message   |  
						| 
							
							Ok there is a new version of smitfraudfix available (2.56).
 So delete your old version and download the latest version of SmitfraudFix.zip to your desktop -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip
 
 Unzip it (folder named SmitFraudFix) to your desktop:
 
 Open the folder SmitfraudFix and doubleclick smitfraudfix.cmd
 Choose option #1 - Search by typing 1 and pressing "Enter"; a textfile opens and lists the infected files (if those exist)
 
 Post the contents of this textfile to here along with a fresh HijackThis log.
 
 If these logs are clean, then you're clean ;)
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. This message has been edited since posting. Last time this message was edited on 9. June 2006 @ 21:48 |  
						| Member 
   | 10. June 2006 @ 13:46 |  Link to this message   |  
						| 
							
							Okay, Here they are:
 SmitFraudFix v2.58
 
 Scan done at 14:43:55.70, Sat 06/10/2006
 Run from C:\Documents and Settings\Carlos Maldonado\My Documents\Save By Owner\Downloads\SmitfraudFix\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in normal mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Carlos Maldonado\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\CARLOS~1\FAVORI~1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="My Current Home Page"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 
 _____________________________________________________________________
 
 Logfile of HijackThis v1.99.1
 Scan saved at 2:45:16 PM, on 6/10/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\Program Files\LEAD Technologies, Inc\LEADTOOLS ePrint 3.0\Bin\LPSVS03N.EXE
 C:\Program Files\ewido\security suite\ewidoctrl.exe
 C:\WINDOWS\system32\LckFldService.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
 C:\WINDOWS\system32\fxssvc.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\PROGRA~1\LEADTE~1\LEADTO~1.0\bin\EPRINT3.EXE
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
 C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
 C:\WINDOWS\system32\ZoneLabs\isafe.exe
 C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
 C:\WINDOWS\system32\WISPTIS.EXE
 C:\WINDOWS\system32\ntvdm.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\HijackThis.exe
 
 O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
 O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
 O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
 O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
 O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
 O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
 O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [ePrint 3.0 Service] C:\PROGRA~1\LEADTE~1\LEADTO~1.0\bin\EPRINT3.EXE
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 O4 - HKLM\..\Run: [SpywareRemover] C:\Program Files\spywareremover\SpywareRemover.exe -boot
 O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\COMMON~1\TEKNUM~1\update.exe /startup
 O4 - Startup: SyncBack.lnk = C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
 O23 - Service: EPrint III Service - Unknown owner - C:\Program Files\LEAD Technologies, Inc\LEADTOOLS ePrint 3.0\Bin\LPSVS03N.EXE
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
 O23 - Service: LckFldService - Unknown owner - C:\WINDOWS\system32\LckFldService.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
 
 I hope you can tell by looking at these reports that I still have the 2 guys shown on my first post on my screen and they are driving me nuts.
 
 I appreciate your help.
 
 
 
 
 
 Thank you, 
 cm
 |  
						| timmybearJunior Member 
   | 10. June 2006 @ 16:54 |  Link to this message   |  
						|  |  
						| Senior Member 
   | 10. June 2006 @ 21:47 |  Link to this message   |  
						| 
							
							@cmaldona
 You have installed this SpywareRemover program, it can't be trusted so you should uninstall it.
 
 Go to Control Panel -> Add/Remove programs -> Remove SpywareRemover if found
 
 Then fix this entry with HijackThis:
 
 O4 - HKLM\..\Run: [SpywareRemover] C:\Program Files\spywareremover\SpywareRemover.exe -boot
 
 Then remove this folder:
 C:\Program Files\spywareremover
 
 Ok so press "move to vault" and run a full scan with AVG again. It should not be finding it anymore...
 
 When you're ready, reboot and post a new HjT log.
 
 @timmybear
 
 Yes we need your HijackThis log s opost it to here, instructions for posting -> http://forums.afterdawn.com/thread_view.cfm/263784
 (steps 3-5)
 
 Download SmitfraudFix.zip to your desktop -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip
 
 Unzip it (folder named SmitFraudFix) to your desktop:
 
 Open the folder SmitfraudFix and doubleclick smitfraudfix.cmd
 Choose option #1 - Search by typing 1 and pressing "Enter"; a textfile opens and lists the infected files (if those exist)
 
 Post the contents of this textfile to here.
 
 (Some antiviruses recognises process.exe as a malware. It is not malware, it is a program that stops processes)
 
 Then we'll get you cleaned ;)
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. This message has been edited since posting. Last time this message was edited on 10. June 2006 @ 21:47 |  
						| timmybearJunior Member 
   | 11. June 2006 @ 12:57 |  Link to this message   |  
						| 
							
							reports: smithfraud
 SmitFraudFix v2.58
 
 Scan done at 15:55:38.44, Sun 06/11/2006
 Run from C:\Documents and Settings\HP_Administrator\Desktop\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in normal mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 C:\WINDOWS\system32\asxbbx.dll FOUND !
 C:\WINDOWS\system32\hp???.tmp FOUND !
 C:\WINDOWS\system32\hp????.tmp FOUND !
 C:\WINDOWS\system32\ld????.tmp FOUND !
 C:\WINDOWS\system32\ot.ico FOUND !
 C:\WINDOWS\system32\simpole.tlb FOUND !
 C:\WINDOWS\system32\stdole3.tlb FOUND !
 C:\WINDOWS\system32\ts.ico FOUND !
 C:\WINDOWS\system32\1024\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Administrator\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HP_ADM~1\FAVORI~1
 
 C:\DOCUME~1\HP_ADM~1\FAVORI~1\Antivirus Test Online.url FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 C:\Program Files\SpywareQuake.com\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="My Current Home Page"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{5aaf6542-f4ba-4df4-873d-4902ecbe794c}"="antitragus"
 
 [HKEY_CLASSES_ROOT\CLSID\{5aaf6542-f4ba-4df4-873d-4902ecbe794c}\InProcServer32]
 @="C:\WINDOWS\system32\asxbbx.dll"
 
 [HKEY_CURRENT_USER\Software\Classes\CLSID\{5aaf6542-f4ba-4df4-873d-4902ecbe794c}\InProcServer32]
 @="C:\WINDOWS\system32\asxbbx.dll"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 
 -------------
 
 hijack this:
 
 Logfile of HijackThis v1.99.1
 Scan saved at 3:57:22 PM, on 6/11/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
 c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 c:\Program Files\Norton Internet Security\ISSVC.exe
 c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
 C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
 C:\WINDOWS\arservice.exe
 C:\WINDOWS\eHome\ehRecvr.exe
 C:\WINDOWS\eHome\ehSched.exe
 C:\Program Files\ewido anti-malware\ewidoctrl.exe
 C:\Program Files\ewido anti-malware\ewidoguard.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
 C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
 c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\WINDOWS\ehome\RMSvc.exe
 C:\WINDOWS\system32\svchost.exe
 c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
 C:\WINDOWS\system32\dllhost.exe
 C:\WINDOWS\ehome\ehtray.exe
 C:\WINDOWS\eHome\ehmsas.exe
 C:\WINDOWS\ARPWRMSG.EXE
 C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
 C:\WINDOWS\system32\rundll32.exe
 C:\Program Files\DISC\DISCover.exe
 C:\Program Files\DISC\DiscUpdateMgr.exe
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
 C:\Program Files\Common Files\AOL\1143839382\ee\AOLSoftware.exe
 C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
 C:\Program Files\Viewpoint\Viewpoint Toolbar V35\FotomatDeviceConnect.exe
 C:\WINDOWS\system32\RUNDLL32.EXE
 C:\Program Files\QuickTime\qttask.exe
 C:\Program Files\DISC\DiscStreamHub.exe
 C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
 C:\HP\KBD\KBD.EXE
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
 C:\WINDOWS\system32\0175470f.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Logitech\Profiler\lwemon.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\program files\valve\steam\steam.exe
 C:\WINDOWS\ehome\RMSysTry.exe
 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
 C:\Program Files\Xfire\Xfire.exe
 c:\program files\common files\aol\1143839382\ee\aim6.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\WINDOWS\RTHDCPL.EXE
 c:\windows\system\hpsysdrv.exe
 C:\WINDOWS\NOTEPAD.EXE
 C:\Documents and Settings\HP_Administrator\My Documents\HijackThis_v1.99.1.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c...
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c...
 R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
 O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
 O2 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp100.tmp
 O2 - BHO: Nothing - {6ab7158b-4bff-4160-ad7d-4d622df548cf} - C:\WINDOWS\system32\hp101.tmp (file missing)
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
 O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
 O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
 O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
 O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
 O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
 O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
 O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe
 O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [URLLSTCK.exe] c:\Program Files\Norton Internet Security\UrlLstCk.exe
 O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
 O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
 O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1143839382\ee\AOLSoftware.exe
 O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
 O4 - HKLM\..\Run: [ViewpointPhotosDeviceConnect] C:\Program Files\Viewpoint\Viewpoint Toolbar V35\FotomatDeviceConnect.exe
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
 O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
 O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"
 O4 - HKLM\..\Run: [0175470f.exe] C:\WINDOWS\system32\0175470f.exe
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [Start WingMan Profiler] "C:\Program Files\Logitech\Profiler\lwemon.exe" /noui
 O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
 O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
 O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
 O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
 O4 - HKCU\..\Run: [0175470f.exe] C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\0175470f.exe
 O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
 O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
 O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
 O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
 O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxm...
 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
 O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
 O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
 O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
 O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
 O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
 O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
 O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O15 - Trusted Zone: http://*.trymedia.com (HKLM)
 O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/Smiley...
 O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.1.87.cab
 O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
 O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O20 - Winlogon Notify: winuwi32 - winuwi32.dll (file missing)
 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
 O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
 O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
 O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 |  
						| Member 
   | 11. June 2006 @ 13:23 |  Link to this message   |  
						| 
							
							I found the folder C:\Program Files\spywareremover with some contents but the program is not on the list in the Control Panel Add/Remove programs. How do I proceed? If I go to Start - All Programs is not there either.
 Please advise.
 
 
 
 
 Thank you, 
 cm
 |  
						| Senior Member 
   | 12. June 2006 @ 06:26 |  Link to this message   |  
						| 
							
							@timmybear
 You have two antiviruses running, Antivir and Norton, this is not recommended and you should remove one of them.
 Go to Control Panel -> Add/Remove programs -> Remove Antivir or Norton if found
 
 Ok, you got some infections on your computer....
 
 Cleaning instructions:
 
 Download and install Ewido anti-malware -> http://www.ewido.net/en/download
 Update it, but do NOT run a scan yet. We'll use it later.
 
 Go to Control Panel -> Add/Remove programs -> Remove Viewpoint, MyWebSearch or similars if found  if found
 
 Run HijackThis. Press Do a system scan only, then close all other windows, checkmark the following entries and press Fix checked
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
 R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
 O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
 O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
 O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBarBHO.dll
 O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
 O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
 O4 - HKLM\..\Run: [ViewpointPhotosDeviceConnect] C:\Program Files\Viewpoint\Viewpoint Toolbar V35\FotomatDeviceConnect.exe
 O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
 O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
 O4 - HKLM\..\Run: [0175470f.exe] C:\WINDOWS\system32\0175470f.exe
 O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
 O4 - HKCU\..\Run: [0175470f.exe] C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\0175470f.exe
 O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxm...
 O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
 O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/Smiley...
 O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
 O20 - Winlogon Notify: winuwi32 - winuwi32.dll (file missing)
 
 Make your hidden files visible -> http://www.bleepingcomputer.com/tutorials/tutorial62.html
 Restart your computer to the safemode -> http://www.pchell.com/support/safemode.shtml
 
 Delete these folders (if found):
 C:\Program Files\MyWebSearch
 C:\Program Files\Viewpoint
 
 Delete these files (if found):
 C:\WINDOWS\system32\0175470f.exe
 C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\0175470f.exe
 
 When in safemode, open SmitfraudFix folder and doubleclick the file smitfraudfix.cmd
 Choose option #2 - Clean by typing 2 and pressing "Enter" in order to remove the infected files.
 
 You are asked: "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove your desktop wallpaper and the infected registry keys.
 
 The tool checks if wininet.dll file is infected. You might be asked to replace the infected .dll (if found); answer "Yes" by typing Y and press "Enter".
 
 The tool might have to restart your computer; if it won't do it, restart your computer back to normal mode.
 A textfile will appear after the cleaning process, copy this file and paste it to here.
 
 Tha log is saved to your local diskdrive, usually C:\rapport.txt.
 
 Warning : Running option 2 in a clean computer will delete your desktop wallpaper.
 
 Scan and clean your computer with Ewido and save the report.
 
 Clean the Recycle bin and make your hidden files visible again.
 
 Post the following logs to here:
 -> a fresh HijackThis log
 -> Ewido's log
 -> contents of C:\Rapport.txt
 
 -----------------------------------------------------------------------------------------------------------------
 
 @cmaldona
 
 Yes remove that folder and post a fresh HjT log to here
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| Member 
   | 12. June 2006 @ 15:15 |  Link to this message   |  
						| 
							
							Here it is:
 Logfile of HijackThis v1.99.1
 Scan saved at 4:10:04 PM, on 6/12/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\Program Files\LEAD Technologies, Inc\LEADTOOLS ePrint 3.0\Bin\LPSVS03N.EXE
 C:\Program Files\ewido\security suite\ewidoctrl.exe
 C:\WINDOWS\system32\LckFldService.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
 C:\WINDOWS\system32\fxssvc.exe
 C:\WINDOWS\system32\ZoneLabs\isafe.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 C:\PROGRA~1\LEADTE~1\LEADTO~1.0\bin\EPRINT3.EXE
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
 C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
 C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\HijackThis.exe
 
 O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
 O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
 O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
 O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
 O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
 O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
 O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
 O4 - HKLM\..\Run: [VTPreset] VTPreset.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
 O4 - HKLM\..\Run: [ePrint 3.0 Service] C:\PROGRA~1\LEADTE~1\LEADTO~1.0\bin\EPRINT3.EXE
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 O4 - HKCU\..\Run: [Update Service] C:\PROGRA~1\COMMON~1\TEKNUM~1\update.exe /startup
 O4 - Startup: SyncBack.lnk = C:\Program Files\2BrightSparks\SyncBack\SyncBack.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
 O23 - Service: EPrint III Service - Unknown owner - C:\Program Files\LEAD Technologies, Inc\LEADTOOLS ePrint 3.0\Bin\LPSVS03N.EXE
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
 O23 - Service: LckFldService - Unknown owner - C:\WINDOWS\system32\LckFldService.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZONELABS\vsmon.exe
 
 I do not see the ugly guys on my screen anymore. Does it mean this PC is clean?
 
 Your help is highly appreciated.
 
 
 Thank you, 
 cm
 |  
						| Senior Member 
   | 13. June 2006 @ 06:48 |  Link to this message   |  
						| 
							
							Hi cmaldona, you are looking clean now :)
 You should update your Java.
 1. Click "Start"-> "Control panel" -> Double-click Java icon (coffee cup)
 2. Move to "Update" tab and update Java by clicking "Update Now". After that do a restart.
 3. If you can't make automatic update, get new version manually from here -> http://www.java.com/en/download/manual.jsp
 4. After updating, uninstall the old Java (if found) from Add/Remove Programs, named as
 J2SE Runtime Environment 5.0 Update 6
 
 Now that you're clean, here are some tips how to stay clean.
 
 -> Stand Up and Be Counted, Malware Complaints -> http://www.malwarecomplaints.info
 The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.
 
 -> Clear your system restore -> http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore...
 This will clear the system restore folders from possible malware that was left behind during the cleaning process. Remember to create a new restore point after the cleaning.
 
 -> Use CCleaner -> http://www.ccleaner.com
 Download and install CCleaner. Clean your registry and temporary files with it regularly.
 
 -> Use Ad-Aware -> http://www.bleepingcomputer.com/forums/?showtutorial=48
 Download and install Ad-Aware. Update it and scan your computer regularly with it.
 
 -> Use Ewido -> http://www.ewido.net/en
 Download and install Ewido. Update it and scan your computer regularly with it.
 
 -> Install SpywareBlaster -> http://www.javacoolsoftware.com/spywareblaster.html
 SpywareBlaster will prevent spyware from being installed to your computer.
 
 -> Install MVPS Hosts file -> http://mvps.org/winhelp2002/hosts.htm
 This prevents your computer from connecting to harmful sites.
 
 -> Change your browser to Firefox -> http://www.mozilla.org
 Firefox is faster, safer and quicker browser than Internet Explorer.
 
 -> Keep your systen up-to-date -> http://windowsupdate.microsoft.com
 Visit Windows Update regularly.
 
 -> Keep your antivirus and firewall up-to-date
 Scan your computer regularly with your antivirus.
 
 -> Read this article by TonyKlein -> http://castlecops.com/postlite7736-.html
 So how did I get infected in the first place?
 
 Stay clean ;)
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. This message has been edited since posting. Last time this message was edited on 13. June 2006 @ 06:48 |  
						| Member 
   | 13. June 2006 @ 07:47 |  Link to this message   |  
						| 
							
							Thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you, thank you...
 This is why I love AD. You guys are great!!!
 
 
 Thank you, 
 cm
 |  
						| Advertisement   |   |  
						| 
 |  
						| Senior Member 
   | 13. June 2006 @ 07:55 |  Link to this message   |  
						| 
							
							You're welcome :)
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  |