Help me please. I have had Nortan 360 antivirus and it was slowing my system down. So I uninstalled it and installed Avast and did a complete scan and have a bunch of infections. Could some one please tell me how to remove them.
I ran Smitfraudfix and this is the report they gave me:
SmitFraudFix v2.190
Scan done at 21:58:01.57, Sat 06/02/2007
Run from C:\Documents and Settings\ITT Tech Student\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
Logfile of HijackThis v1.99.1
Scan saved at 11:58:01 PM, on 6/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Run SmitFraudfix in fix mode:
You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.
Next, please reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".
The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt
Warning : running option #2 on a non infected computer will remove your Desktop background.
Post the C:Rapport.txt, the avg/ewido online scan log, and a new HijackThis log.
Name: TrackingCookie.Atdmt
Path: C:\Documents and Settings\ITT Tech Student\Cookies\itt tech student@atdmt[2].txt
Risk: Medium
Name: TrackingCookie.Casalemedia
Path: C:\Documents and Settings\ITT Tech Student\Cookies\itt tech student@casalemedia[1].txt
Risk: Medium
Name: TrackingCookie.Doubleclick
Path: C:\Documents and Settings\ITT Tech Student\Cookies\itt tech student@doubleclick[2].txt
Risk: Medium
Name: TrackingCookie.Mediaplex
Path: C:\Documents and Settings\ITT Tech Student\Cookies\itt tech student@mediaplex[2].txt
Risk: Medium
Name: TrackingCookie.Webtrendslive
Path: C:\Documents and Settings\ITT Tech Student\Cookies\itt tech student@statse.webtrendslive[2].txt
Risk: Medium
Name: TrackingCookie.Tribalfusion
Path: C:\Documents and Settings\ITT Tech Student\Cookies\itt tech student@tribalfusion[2].txt
Risk: Medium
Name: TrackingCookie.2o7
Path: C:\Documents and Settings\Matt\Cookies\matt@2o7[2].txt
Risk: Medium
Name: TrackingCookie.Yieldmanager
Path: C:\Documents and Settings\Matt\Cookies\matt@ad.yieldmanager[2].txt
Risk: Medium
Name: TrackingCookie.Euroclick
Path: C:\Documents and Settings\Matt\Cookies\matt@adopt.euroclick[2].txt
Risk: Medium
Name: TrackingCookie.Adrevolver
Path: C:\Documents and Settings\Matt\Cookies\matt@adrevolver[2].txt
Risk: Medium
Name: TrackingCookie.Pointroll
Path: C:\Documents and Settings\Matt\Cookies\matt@ads.pointroll[2].txt
Risk: Medium
Name: TrackingCookie.Advertising
Path: C:\Documents and Settings\Matt\Cookies\matt@advertising[2].txt
Risk: Medium
Name: TrackingCookie.Tacoda
Path: C:\Documents and Settings\Matt\Cookies\matt@anad.tacoda[2].txt
Risk: Medium
Name: TrackingCookie.Atdmt
Path: C:\Documents and Settings\Matt\Cookies\matt@atdmt[2].txt
Risk: Medium
Name: TrackingCookie.2o7
Path: C:\Documents and Settings\Matt\Cookies\matt@blockbuster.112.2o7[1].txt
Risk: Medium
Name: TrackingCookie.Serving-sys
Path: C:\Documents and Settings\Matt\Cookies\matt@bs.serving-sys[1].txt
Risk: Medium
Name: TrackingCookie.Casalemedia
Path: C:\Documents and Settings\Matt\Cookies\matt@casalemedia[1].txt
Risk: Medium
Name: TrackingCookie.Doubleclick
Path: C:\Documents and Settings\Matt\Cookies\matt@doubleclick[1].txt
Risk: Medium
Name: TrackingCookie.Ru4
Path: C:\Documents and Settings\Matt\Cookies\matt@edge.ru4[1].txt
Risk: Medium
Name: TrackingCookie.Hitbox
Path: C:\Documents and Settings\Matt\Cookies\matt@ehg-advanceauto.hitbox[2].txt
Risk: Medium
Name: TrackingCookie.Hitbox
Path: C:\Documents and Settings\Matt\Cookies\matt@ehg-autozone.hitbox[2].txt
Risk: Medium
Name: TrackingCookie.Hitbox
Path: C:\Documents and Settings\Matt\Cookies\matt@ehg-cskautocorporation.hitbox[2].txt
Risk: Medium
Name: TrackingCookie.Fastclick
Path: C:\Documents and Settings\Matt\Cookies\matt@fastclick[2].txt
Risk: Medium
Name: TrackingCookie.Hitbox
Path: C:\Documents and Settings\Matt\Cookies\matt@hitbox[2].txt
Risk: Medium
Name: TrackingCookie.Linksynergy
Path: C:\Documents and Settings\Matt\Cookies\matt@linksynergy[1].txt
Risk: Medium
Name: TrackingCookie.Mediaplex
Path: C:\Documents and Settings\Matt\Cookies\matt@mediaplex[2].txt
Risk: Medium
Name: TrackingCookie.Questionmarket
Path: C:\Documents and Settings\Matt\Cookies\matt@questionmarket[2].txt
Risk: Medium
Name: TrackingCookie.Msn
Path: C:\Documents and Settings\Matt\Cookies\matt@search.msn[1].txt
Risk: Medium
Name: TrackingCookie.Serving-sys
Path: C:\Documents and Settings\Matt\Cookies\matt@serving-sys[1].txt
Risk: Medium
Name: TrackingCookie.Tacoda
Path: C:\Documents and Settings\Matt\Cookies\matt@tacoda[1].txt
Risk: Medium
Name: TrackingCookie.Trafficmp
Path: C:\Documents and Settings\Matt\Cookies\matt@trafficmp[2].txt
Risk: Medium
Name: TrackingCookie.Tribalfusion
Path: C:\Documents and Settings\Matt\Cookies\matt@tribalfusion[2].txt
Risk: Medium
Name: Adware.WebEx
Path: C:\WINDOWS\Downloaded Program Files\ieatgpc.dll
Risk: Medium
C:Rapport.txt
SmitFraudFix v2.190
Scan done at 9:49:36.43, Sun 06/03/2007
Run from C:\Documents and Settings\ITT Tech Student\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
Logfile of HijackThis v1.99.1
Scan saved at 9:59:10 AM, on 6/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
The smitfraud log shows the problem that I was most concerned about being fixed.
Did you have the AVG scan fix the things that it found? If not, you can have it fix all the cookies. I'm not sure about the webex dll because I don't know about that application.
Upload a File to Virustotal Please visit Virustotal
* Click the Browse... button
* Navigate to the file C:\WINDOWS\Downloaded Program Files\ieatgpc.dll * Click the Open button
* Click the Send button
* Copy and paste the results back here please.
There is nothing showing in AVAST that is threatening. I tried to do the Virustotal (C:\WINDOWS\Downloaded Program Files\ieatgpc.dll) but it could not load the file size because it was too big. When I ran a search on the file it stated that the file was damaged.