Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:51:10 AM, on 7/8/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Safe mode with network support
Please download VundoFix.exeto your desktop.
* Double-click *VundoFix.exe* to run it.
* Click the *Scan for Vundo* button.
* Once it's done scanning, click the *Remove Vundo* button.
* You will receive a prompt asking if you want to remove the files, click "YES"
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will reboot your computer, click *OK*.
* Please post the contents of C:\*vundofix.txt* Note: It is possible that VundoFix encountered a file it could not remove.In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the *Scan for Vundo* button." when VundoFix appears at reboot.
==========
Download and Run ComboFix [*]Download this file from either of the two below listed places :
[*]Then double click combofix.exe & follow the prompts.
[*]When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
[*] Open the extracted SDFix folder and double click RunThis.bat to start the script.
[*] Type Y to begin the cleanup process.
[*] It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
[*] Press any Key and it will restart the PC.
[*] When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
[*] Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt (Report.txt will also be copied to Clipboard ready for posting back on the forum).
[*] Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
C:\Program Files\RM-X Player V4.2\ASProtect.dll
C:\Program Files\RM-X Player V4.2\lame_enc.dll
C:\Program Files\RM-X Player V4.2\viscomaudiodata.dll
C:\Program Files\RM-X Player V4.2\viscomaudioencoder.dll
C:\Program Files\RM-X Player V4.2\viscomframe.dll
C:\Program Files\RM-X Player V4.2\viscomqtde.dll
C:\Program Files\RM-X Player V4.2\viscomqtenc.dll
C:\Program Files\RM-X Player V4.2\viscomtran.dll
C:\Program Files\RM-X Player V4.2\viscomwave.dll
C:\WINDOWS\vStrip_css.dll
C:\WINDOWS\vStrip.exe
C:\WINDOWS\vstriplangue.exe
C:\Documents and Settings\Vero\Local Settings\Temp\BIT1.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT10.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT100.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT102.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT103.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT104.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT105.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT106.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT107.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT108.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT109.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT10A.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT10B.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT10D.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT10E.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT10F.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT11.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT110.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT111.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT118.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT119.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT11A.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT11B.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT11C.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT11F.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT12.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT121.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT122.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT123.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT124.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT125.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT126.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT127.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT128.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT129.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT12B.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT12E.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT12F.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT13.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT130.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT131.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT132.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT133.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT134.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT135.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT137.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT139.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT13B.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT13C.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT13D.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT13E.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT13F.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT14.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT140.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT141.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT142.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT143.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT144.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT145.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT146.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT148.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT149.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT14A.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT14B.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT14C.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT15.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT16.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT17.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT18.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT19.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT1A.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT1B.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT1C.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT1D.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT1E.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT1F.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT2.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT20.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT21.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT22.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT23.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT24.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT25.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT26.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT27.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT28.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT29.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT2A.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT2B.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT2C.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT2D.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT2E.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT2F.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT3.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT30.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT31.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT32.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT33.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT34.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT35.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT36.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT37.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT38.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT39.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT3A.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT3B.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT3C.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT3D.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT3E.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT3F.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT4.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT40.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT41.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT42.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT43.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT44.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT45.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT46.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT47.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT48.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT49.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT4A.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT4B.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT4C.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT4D.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT4E.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT4F.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT5.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT50.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT51.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT52.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT53.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT54.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT55.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT56.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT62.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT63.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT64.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT65.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT66.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT67.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT68.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT69.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6A.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6A7.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6A8.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6A9.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6AF.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6B.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6B2.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6B3.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6B9.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6BA.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6BB.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6C.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6C0.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6C1.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6C2.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6C7.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6C8.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6C9.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6CA.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6CF.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6D.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6D0.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6D1.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6D6.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6D7.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6D8.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6D9.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6DE.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6DF.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6E.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6E0.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6E5.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6E6.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6E7.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6E8.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6ED.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6EE.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6EF.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6F.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6F4.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6F5.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6F6.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6F7.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6FC.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6FD.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT6FE.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT7.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT70.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT704.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT705.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT706.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT707.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT708.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT709.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT70A.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT70B.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT70C.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT70D.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT70F.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT71.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT711.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT713.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT719.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT71A.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT71C.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT71D.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT72.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT73.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT74.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT75.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT78.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT79.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT7A.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT7F.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT8.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT84.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT86.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT87.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT89.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT8A.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT8B.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT8C.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT8D.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT8E.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT8F.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT9.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT90.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT91.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT92.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT93.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT94.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT95.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT96.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT97.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT98.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT99.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT9A.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT9B.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT9C.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT9D.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT9E.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BIT9F.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITA.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITA1.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITA2.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITA3.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITA4.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITA5.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITA6.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITA7.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITA8.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITA9.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITAA.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITAD.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITAE.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITAF.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITB.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITB0.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITB1.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITB2.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITB3.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITB4.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITB5.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITB6.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITB7.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITB8.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITB9.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITBA.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITBB.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITBC.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITBD.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITBF.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITC.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITC0.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITC1.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITC2.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITC3.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITC4.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITC5.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITC6.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITC7.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITC8.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITC9.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITCA.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITCB.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITCC.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITCD.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITCE.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITCF.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITD.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITD0.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITD1.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITD2.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITD3.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITD4.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITD5.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITD6.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITD7.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITD8.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITDA.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITDB.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITDC.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITDD.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITDF.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITE.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITE0.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITE2.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITE3.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITE4.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITE5.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITE6.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITE7.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITE8.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITE9.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITEA.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITEB.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITEC.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITED.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITEE.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITEF.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITF.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITF0.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITF1.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITF2.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITF3.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITF4.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITF6.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITF7.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITF8.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITF9.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITFA.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITFB.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITFC.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITFD.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITFE.tmp
C:\Documents and Settings\Vero\Local Settings\Temp\BITFF.tmp
Originally posted by tony909:finally i got this from HijackThis log ,
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:00:47 PM, on 7/11/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Double-click SmitfraudFix.exe Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.
Note : process.exeis detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. http://www.beyondlogic.org/consulting/proc...processutil.htm
============
You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.
Please reboot your computer in Safe Mode by doing the following :
*Restart your computer
*After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
*nstead of Windows loading as normal, a menu with options should appear;
*Select the first option, to run Windows in Safe Mode, then press "Enter".
*Choose your usual account.
Once in Safe Mode, double-click SmitfraudFix.exe Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".
The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt
Warning : running option #2 on a non infected computer will remove your Desktop background.
Scan done at 19:56:30.82, Thu 07/12/2007
Run from C:\Documents and Settings\Administrator\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:09:08 PM, on 7/12/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Safe mode with network support
Under Main select the following:
*Windows Temp
*Current User Temp
*All Users Temp
*Temporary Internet Files
*Prefetch
*Java Cache
*The other boxes are optional*
Then click the Empty Selected button.
Click Exit on the Main menu to close the program.
========
[*]Then double click combofix.exe & follow the prompts.
[*]When finished, it shall produce a log for you. Post that log in your next reply
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:20:02 AM, on 7/14/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Safe mode with network support
Open control panel and add/remove programs, remove dealio (if presents)
Open HijackThis - Click the Do a system scan only button
- Check the following entries (below)
O2 - BHO: (no name) - {36B5DE60-B99B-4775-9DC5-EA538213FDE9} - C:\WINDOWS\System32\vtstr.dll (file missing)
O3 - Toolbar: (no name) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - (no file)
O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb105\Dealio.dll
O3 - Toolbar: (no name) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - (no file)
O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb105\Dealio.dll
O20 - Winlogon Notify: wvusppo - wvusppo.dll (file missing)
Close ALL open windows
Click Fix Checked
Close HijackThis
Remove this folder C:\Program Files\Dealio
==========
Update Java Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
*Download the latest version of Java(TM) SE Runtime Environment 6u2.
*Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
*Click the "Download" button to the right.
*Check the box that says: "Accept License Agreement".
*The page will refresh.
*Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
*Close any programs you may have running - especially your web browser.
*Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
*Check any item with Java Runtime Environment (JRE or J2SE) in the name.
*Click the Remove or Change/Remove button.
*Repeat as many times as necessary to remove each Java versions.
*Reboot your computer once all Java components are removed.
*Then from your desktop double-click on the download to install the newest version.
========
*Note: You will need to use Internet explorer for this scan
*Go here to run an online scan from F-Secure
*Click on Start scanning *This will open a new internet explorer window
*It will require an activex control, please install it
*Click Accept *Click Full System Scan *It will now download the scanner, this may take a while, please be patient
*It will then start scanning, wait for the scan to finish
*Click Automatic cleaning (recommended) *Wait for it finish the cleaning process
*Click show report
*This will open up a window with the results of the scan, copy and paste those results as a reply to this topic