|  | 
 
															
															
	
			
			
				| another W32.Myzor.FK |  |  
					
					
				 
						| Lom1114Newbie 
   | 2. June 2006 @ 22:03 |  Link to this message   |  
						| 
							
							hi guys.  can't figure out how to get rid of this one.  please help
 
 Logfile of HijackThis v1.99.1
 Scan saved at 12:38:54 AM, on 6/3/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\WgaTray.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
 C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
 C:\Program Files\ewido anti-malware\ewidoctrl.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\Internet Explorer\IEXPLORE.EXE
 C:\WINDOWS\system32\wuauclt.exe
 C:\DL\HJT\HijackThis_v1.99.1.exe
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www...
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www...
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www...
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www...
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www...
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www...
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
 O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
 O2 - BHO: Nothing - {6ab7158b-4bff-4160-ad7d-4d622df548cf} - C:\WINDOWS\system32\hp100.tmp
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
 O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
 O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
 O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
 O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
 O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
 O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4/vet_install_premium...
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl...
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
 
 
 
 
 
 
 SmitFraudFix v2.53
 
 Scan done at  0:46:51.20, Sat 06/03/2006
 Run from C:\DL\SmitfraudFix\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in normal mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 C:\WINDOWS\system32\atmclk.exe FOUND !
 C:\WINDOWS\system32\dcomcfg.exe FOUND !
 C:\WINDOWS\system32\hp???.tmp FOUND !
 C:\WINDOWS\system32\hp????.tmp FOUND !
 C:\WINDOWS\system32\ld????.tmp FOUND !
 C:\WINDOWS\system32\ot.ico FOUND !
 C:\WINDOWS\system32\regperf.exe FOUND !
 C:\WINDOWS\system32\simpole.tlb FOUND !
 C:\WINDOWS\system32\stdole3.tlb FOUND !
 C:\WINDOWS\system32\1024\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\RAZE\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\RAZE\FAVORI~1
 
 C:\DOCUME~1\RAZE\FAVORI~1\Antivirus Test Online.url FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 C:\Program Files\Security Toolbar\ FOUND !
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
 "Source"="About:Home"
 "SubscribedURL"="About:Home"
 "FriendlyName"="My Current Home Page"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{e5b1e382-817e-4b74-8a96-ec78751e6acf}"="incatenate"
 
 [HKEY_CLASSES_ROOT\CLSID\{e5b1e382-817e-4b74-8a96-ec78751e6acf}\InProcServer32]
 @="C:\WINDOWS\system32\imfdfcj.dll"
 
 [HKEY_CURRENT_USER\Software\Classes\CLSID\{e5b1e382-817e-4b74-8a96-ec78751e6acf}\InProcServer32]
 @="C:\WINDOWS\system32\imfdfcj.dll"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 |  
						| Advertisement   |   |  
						|  |  
						| Senior Member 
   | 2. June 2006 @ 22:19 |  Link to this message   |  
						| 
							
							Hi Lom1114.
 Ok, you got some infections on your computer....
 
 You don't have a firewall on your computer. Download and install one firewall.
 
 These are good (free) firewalls:
 ZoneAlarm --> http://www.zonelabs.com
 Kerio--> http://www.sunbelt-software.com/Kerio.cfm
 Outpost-> http://www.agnitum.com
 
 Cleaning instructions:
 
 Download and install Ewido anti-malware -> http://www.ewido.net/en/download
 Update it, but do NOT run a scan yet. We'll use it later.
 
 Go to Control Panel -> Add/Remove programs -> Remove ViewPoint, PartyPoker if found
 
 Run HijackThis. Press Do a system scan only, then close all other windows, checkmark the following entries and press Fix checked
 
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www...
 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www...
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www...
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www...
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www...
 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www...
 O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
 O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
 O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4/vet_install_premium...
 
 Make your hidden files visible -> http://www.bleepingcomputer.com/tutorials/tutorial62.html
 Restart your computer to the safemode -> http://www.pchell.com/support/safemode.shtml
 
 Delete these folders (if found):
 C:\Program Files\PartyGaming
 C:\Program Files\ViewPoint
 
 When in safemode, open SmitfraudFix folder and doubleclick the file smitfraudfix.cmd
 Choose option #2 - Clean by typing 2 and pressing "Enter" in order to remove the infected files.
 
 You are asked: "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove your desktop wallpaper and the infected registry keys.
 
 The tool checks if wininet.dll file is infected. You might be asked to replace the infected .dll (if found); answer "Yes" by typing Y and press "Enter".
 
 The tool might have to restart your computer; if it won't do it, restart your computer back to normal mode.
 A textfile will appear after the cleaning process, copy this file and paste it to here.
 
 Tha log is saved to your local diskdrive, usually C:\rapport.txt.
 
 Warning : Running option 2 in a clean computer will delete your desktop wallpaper.
 
 Scan and clean your computer with Ewido and save the report.
 
 Clean the Recycle bin and make your hidden files visible again.
 
 Post the following logs to here:
 -> a fresh HijackThis log
 -> Ewido's log
 -> contents of C:\rapport.txt
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| Lom1114Newbie 
   | 2. June 2006 @ 23:03 |  Link to this message   |  
						| 
							
							Thanks JaPK you've given me hope again!
 fresh HijackThis log
 Logfile of HijackThis v1.99.1
 Scan saved at 1:58:04 AM, on 6/3/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\WgaTray.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
 C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
 C:\Program Files\ewido anti-malware\ewidoctrl.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\WINDOWS\system32\NOTEPAD.EXE
 C:\DL\HJT\HijackThis_v1.99.1.exe
 
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
 O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
 O2 - BHO: Nothing - {6ab7158b-4bff-4160-ad7d-4d622df548cf} - C:\WINDOWS\system32\hp100.tmp (file missing)
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
 O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
 O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
 O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
 O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl...
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 
 
 
 
 Ewido's log
 ---------------------------------------------------------
 ewido anti-malware - Scan report
 ---------------------------------------------------------
 
 + Created on:			1:55:01 AM, 6/3/2006
 + Report-Checksum:		74BB992F
 
 + Scan result:
 
 HKU\S-1-5-21-790525478-1078081533-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB} -> Adware.Generic : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@adtech[1].txt -> TrackingCookie.Adtech : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@com[1].txt -> TrackingCookie.Com : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@microsoftwga.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@news.com[1].txt -> TrackingCookie.Com : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@revenue[1].txt -> TrackingCookie.Revenue : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
 C:\Documents and Settings\RAZE\Cookies\raze@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
 C:\Documents and Settings\RAZE\Local Settings\Temp\Cookies\raze@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\RAZE\Local Settings\Temp\Cookies\raze@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned with backup
 C:\Documents and Settings\RAZE\Local Settings\Temp\Cookies\raze@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
 C:\Documents and Settings\RAZE\Local Settings\Temp\Cookies\raze@centrport[1].txt -> TrackingCookie.Centrport : Cleaned with backup
 C:\Documents and Settings\RAZE\Local Settings\Temp\Cookies\raze@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Cleaned with backup
 C:\Documents and Settings\RAZE\Local Settings\Temp\Cookies\raze@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
 C:\Documents and Settings\RAZE\Local Settings\Temp\Cookies\raze@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
 C:\Documents and Settings\RAZE\Local Settings\Temp\Cookies\raze@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
 C:\Documents and Settings\RAZE\Local Settings\Temp\Cookies\raze@sportingnews.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\RAZE\Local Settings\Temp\Cookies\raze@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
 C:\Documents and Settings\RAZE\Local Settings\Temp\Cookies\raze@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
 C:\Program Files\Media-codec -> Trojan.Small : Cleaned with backup
 C:\Program Files\Media-Codec\uninst.exe -> Trojan.Small : Cleaned with backup
 
 
 ::Report End
 
 
 rapport.txt
 SmitFraudFix v2.53
 
 Scan done at  1:34:37.23, Sat 06/03/2006
 Run from C:\DL\SmitfraudFix\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
 Fix ran in safe mode
 
 »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
 "{e5b1e382-817e-4b74-8a96-ec78751e6acf}"="incatenate"
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Killing process
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
 
 C:\WINDOWS\system32\atmclk.exe Deleted
 C:\WINDOWS\system32\dcomcfg.exe Deleted
 C:\WINDOWS\system32\hp???.tmp Deleted
 C:\WINDOWS\system32\ld????.tmp Deleted
 C:\WINDOWS\system32\ot.ico Deleted
 C:\WINDOWS\system32\regperf.exe Deleted
 C:\WINDOWS\system32\simpole.tlb Deleted
 C:\WINDOWS\system32\stdole3.tlb Deleted
 C:\WINDOWS\system32\1024\ Deleted
 C:\Program Files\Security Toolbar\ Deleted
 
 »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
 
 GenericRenosFix by S!Ri
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
 
 Registry Cleaning done.
 
 »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» End
 |  
						| Senior Member 
   | 2. June 2006 @ 23:20 |  Link to this message   |  
						| 
							
							Ok almost clean.
 Install a firewall.
 
 Then fix this entry with HijackThis:
 O2 - BHO: Nothing - {6ab7158b-4bff-4160-ad7d-4d622df548cf} - C:\WINDOWS\system32\hp100.tmp (file missing)
 
 Restart your computer and post a new HijackThis log to here.
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| Lom1114Newbie 
   | 2. June 2006 @ 23:41 |  Link to this message   |  
						| 
							
							Ok I installed ZoneAlarm and deleted that entry.
 
 Logfile of HijackThis v1.99.1
 Scan saved at 2:40:18 AM, on 6/3/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\WINDOWS\system32\WgaTray.exe
 C:\WINDOWS\Explorer.EXE
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 C:\Program Files\Messenger\msmsgs.exe
 C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
 C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
 C:\Program Files\ewido anti-malware\ewidoctrl.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 C:\Program Files\iPod\bin\iPodService.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Program Files\Internet Explorer\IEXPLORE.EXE
 C:\Virus Fixers\HJT\HijackThis_v1.99.1.exe
 
 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
 O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
 O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
 O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
 O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
 O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
 O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
 O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/cl...
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
 O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 |  
						| aabbccddSuspended permanently 
   | 2. June 2006 @ 23:59 |  Link to this message   |  
						| 
							
							JaPK ,just making sure iam clean??
 Logfile of HijackThis v1.99.1
 Scan saved at 2:56:24 AM, on 6/3/2006
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\Windows Defender\MsMpEng.exe
 C:\WINDOWS\SYSTEM32\SVCHOST.EXE
 C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
 C:\Program Files\ewido anti-malware\ewidoctrl.exe
 C:\PROGRA~1\TRENDM~1\INTERN~2\PCCTLCOM.EXE
 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 C:\WINDOWS\system32\svchost.exe
 C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
 C:\WINDOWS\system32\Ati2evxx.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Windows Defender\MSASCui.exe
 C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
 C:\Program Files\WinPortrait\wpctrl.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe
 C:\PROGRAM FILES\SLYSOFT\ANYDVD\ANYDVD.EXE
 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
 C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
 C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
 C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
 C:\PROGRA~1\TRENDM~1\INTERN~2\TMPROXY.EXE
 C:\WINDOWS\system32\MsPMSPSv.exe
 C:\PROGRA~1\TRENDM~1\INTERN~2\TMPFW.EXE
 C:\Program Files\WinPortrait\floater.exe
 C:\PROGRA~1\TRENDM~1\INTERN~2\PccGuide.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
 C:\WINDOWS\system32\wuauclt.exe
 C:\Documents and Settings\Led Zeppelin\Desktop\HijackThis.exe
 C:\PROGRA~1\TRENDM~1\INTERN~2\TSC.EXE
 
 O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
 O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
 O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
 O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\WinPortrait\wpctrl.exe"
 O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe"
 O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
 O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
 O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
 O4 - HKCU\..\Run: [Gadwin PrintScreen 3.1] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
 O4 - Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
 O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www3.ca.com/securityadvisor/pestscan/pestscan.cab
 O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
 O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
 O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
 O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
 O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
 O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
 O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
 O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
 O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
 
 SmitFraudFix v2.45
 
 Scan done at  2:58:33.75, Sat 06/03/2006
 Run from C:\Documents and Settings\Led Zeppelin\Desktop\SmitfraudFix
 OS: Microsoft Windows XP [Version 5.1.2600]
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Led Zeppelin\Application Data
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\LEDZEP~1\FAVORI~1
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
 
 
 »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
 !!!Attention, following keys are not inevitably infected!!!
 
 SrchSTS.exe by S!Ri
 Search SharedTaskScheduler's .dll
 
 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
 
 
 |  
						| Senior Member 
   | 3. June 2006 @ 00:09 |  Link to this message   |  
						| 
							
							@Lom1114
 You're clean now :)
 
 Now that you're clean, here are some tips how to stay clean.
 
 -> Stand Up and Be Counted, Malware Complaints -> http://www.malwarecomplaints.info
 The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.
 
 -> Clear your system restore -> http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore...
 This will clear the system restore folders from possible malware that was left behind during the cleaning process. Remember to create a new restore point after the cleaning.
 
 -> Use CCleaner -> http://www.ccleaner.com
 Download and install CCleaner. Clean your registry and temporary files with it regularly.
 
 -> Use Ad-Aware -> http://www.bleepingcomputer.com/forums/?showtutorial=48
 Download and install Ad-Aware. Update it and scan your computer regularly with it.
 
 -> Use Ewido -> http://www.ewido.net/en
 Download and install Ewido. Update it and scan your computer regularly with it.
 
 -> Install SpywareBlaster -> http://www.javacoolsoftware.com/spywareblaster.html
 SpywareBlaster will prevent spyware from being installed to your computer.
 
 -> Install MVPS Hosts file -> http://mvps.org/winhelp2002/hosts.htm
 This prevents your computer from connecting to harmful sites.
 
 -> Change your browser to Firefox -> http://www.mozilla.org
 Firefox is faster, safer and quicker browser than Internet Explorer.
 
 -> Keep your systen up-to-date -> http://windowsupdate.microsoft.com
 Visit Windows Update regularly.
 
 -> Keep your antivirus and firewall up-to-date
 Scan your computer regularly with your antivirus.
 
 -> Read this article by TonyKlein -> http://castlecops.com/postlite7736-.html
 So how did I get infected in the first place?
 
 Stay clean ;)
 
 -----------------------------------------------------------------------
 
 @aabbccdd
 
 You're looking clean, altough you have an outdated version of smitfraudfix. Latest version -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip
 
 Then you have two antiviruses and firewalls running, you got trendmicro, avg, zonealarm....
 
 You should only keep one firewall and one antivirus.
 
 So what of those you want to remove and what to keep?
 
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| aabbccddSuspended permanently 
   | 3. June 2006 @ 01:43 |  Link to this message   |  
						| 
							
							JaPK i never downloaded AVG or zonealarm i only have Trend Mirco on my machine sure yout reading the right log file,thanks
 |  
						| Senior Member 
   | 3. June 2006 @ 04:40 |  Link to this message   |  
						| 
							
							@aabbccdd
 Ok you're right, I was looking on the wrong HjT log file :D
 
 Your log is clean, sorry :)
 
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  
						| Lom1114Newbie 
   | 3. June 2006 @ 12:11 |  Link to this message   |  
						| 
							
							Thank you JaPK
you're doing wonderful deeds here
 |  
						| Advertisement   |   |  
						| 
 |  
						| Senior Member 
   | 4. June 2006 @ 01:10 |  Link to this message   |  
						| 
							
							You're welcome Lom1114 :)
 
 I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere. |  |