This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Smitfraud.c removal

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Here is the generated log from Hijack This 1.99.1. Let me know my next step.

Thanks, Wes

Logfile of HijackThis v1.99.1
Scan saved at 1:27:31 AM, on 6/27/2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\WS_FTP Pro\ftpsched.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\msole32.exe
C:\WINNT\popuper.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\WINNT\System32\intmonp.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\WS_FTP Pro\ftpqueue.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\hpoopm07.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet K Series\bin\hpodev07.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\HEWLET~1\HPOFFI~1\bin\hpoevm07.exe
C:\Documents and Settings\westernmac\My Documents\Aaron\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
F2 - REG:system.ini: Shell=Explorer.exe,
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINNT\System32\hp4333.tmp
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Pop-Up Stopper &Companion - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:\Program Files\Panicware\Pop-Up Stopper Companion\popupus.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [ftpqueue] C:\Program Files\WS_FTP Pro\ftpqueue.exe -tray
O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINNT\System32\spool\DRIVERS\W32X86\hpoopm07.exe
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: HPAiODevice.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet K Series\bin\hpodev07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:tsk.mht!http://69.50.166.110/5/s1//q.chm::/file.exe
O23 - Service: AVSync Manager (AvSynMgr) - Networks Associates Technologies, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Ipswitch WS_FTP Queue (ftpqueue) - Ipswitch, Inc., 81 Hartwell Ave, Lexington MA 02421 - C:\Program Files\WS_FTP Pro\ftpsched.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
Hello Aaron, Welcome to TomCoyote forum. I would be doing you a disservice If I did not point out that you have no critical updates for your Internet Explorer browser. I also suggest that you update your IE browser to the newest version 6.0 for the additional protection it will give you.
You can access windows updates like this: Open Internet Explorer, then Tools at the top, then choose Windows Update and download all critical updates Windows suggests for your operating system and browser.
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 (5.00.2920.0000)
With the malware that is out here now it is no longer a question of will you get infected buy rather when.
________________________________________________________________

Smitfraud/Quicknavigate removal

Please read these instructions carefully and print them out! Be sure to follow ALL instructions!

Please RIGHT-CLICK: HERE and go to Save As (in Internet Explorer it's "Save Target As") in order to download Grinler's reg file. Save it to your desktop.

Locate "smitfraud.reg" on your desktop and double-click it. When asked if you want to merge with the registry, click YES. Wait for the "merged successfully" prompt then follow the rest of the instructions below.

Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found:

Security IGuard
Virtual Maid
Search Maid


Exit Add/Remove Programs.

*IMPORTANT*CLICK THIS LINK TO LEARN HOW TO VIEW HIDDEN FILES

* Please download the Killbox at this link:
http://www.bleepingcomputer.com/files/killbox.php

*In the event you already have Killbox, this is a new version that I need you to download

* Save it to your desktop.

* Please double-click Killbox.exe to run it.

* Select "Delete on Reboot".

* Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C

C:\wp.exe
C:\wp.bmp
C:\bsw.exe
C:\Windows\sites.ini
C:\Windows\popuper.exe
C:\Windows\system32\hhk.dll
C:\Windows\System32\wldr.dll
C:\Windows\system32\perfcii.ini
C:\Windows\System32\helper.exe
C:\Windows\System32\shnlog.exe
C:\Windows\System32\intmon.exe
C:\Windows\System32\intmonp.exe
C:\Windows\System32\msmsgs.exe
C:\Windows\system32\msole32.exe
C:\Windows\System32\ole32vbs.exe


* Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

* Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually.

While your computer is restarting, tap the F8 key continually until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.

Make sure you can view hidden files.

Using Windows Explorer, delete the following, if found, (please do NOT try to find them by "search" because they will not show up that way)

FOLDERS to delete (in bold) if found:

C:\Program Files\Search Maid
C:\Program Files\Virtual Maid
C:\Windows\System32\Log Files
C:\Program Files\Security IGuard

While still in Safe Mode, do the following:

Make sure all programs and windows are closed. Run HiJackThis and place a check next to the following items, if found, then click FIX CHECKED:

F2 - REG:system.ini: Shell=Explorer.exe,
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINNT\System32\hp4333.tmp
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
Above two see this >> http://www.imilly.com/alexa.htm
O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:tsk.mht!http://69.50.166.110/5/s1//q.chm::/file.exe
-Adult Content Dialer


Close HiJackThis.

Reboot into normal mode.

1.) Download The Hoster Press "Restore Original Hosts" and press "OK". Exit Program.

2.) Right-Click HERE and Save As to download DelDomains.inf to your desktop.
To use: RIGHT-CLICK DelDomains.inf on your desktop and select: Install (no need to restart)
Note: This will remove all entries in the "Trusted Zone" and "Ranges" also.

Download, install, and run http://cleanup.stevengould.org/

4.) Run this online virus scan: ActiveScan - Save the results from the scan!

Post a new HiJackThis log along with the results from ActiveScan.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
pskelley,

Thanks for the reply. Your instructions were well written. Here are the steps I have taken.

1) Printed out Post
2) Downloaded all (18) critical updates and service packs from Microsoft
3) Saved and ran smitfraud.reg
4) Security IGuard, Virtual Maid, and Search were not installed
5) Downloaded, saved, and ran Killbox.exe and deleted all paths requested.
6) Deleted C:\WINDOWS\System32\Log Files. The other 3 did not exist.
7) Deleted F2, O9, O9, and O16 from the HijackThis scan. O2 was not there.
8) Ran Hoster
9) Ran CleanUp!
10) Ran Panda's ActiveScan
11) Ran Hijack This
Both logs from 10 and 11 are listed below. Let me know the next step but it's looking a little better already. No blue screen of death now.
ActiveScan:
Incident Status Location

Adware:Adware/Popuper No disinfected C:\WINNT\system32\intmonp.exe
Adware:Adware/Virmaid No disinfected C:\WINNT\popuper.exe
Adware:Adware/Smitfraud No disinfected C:\WINNT\system32\wp.bmp
Adware:Adware/Antivirus-gold No disinfected C:\WINNT\screen.html
Adware:Adware/Virmaid No disinfected C:\WINNT\popuper.exe
Adware:Adware/Antivirus-gold No disinfected C:\WINNT\screen.html
Adware:Adware/Popuper No disinfected C:\WINNT\system32\hhk.dll
Adware:Adware/Popuper No disinfected C:\WINNT\system32\intmonp.exe
Virus:Trj/Clicker.GF Disinfected C:\WINNT\system32\msole32.exe
Adware:Adware/Startpage.ACK No disinfected C:\WINNT\system32\ole32vbs.exe
Adware:Adware/Smitfraud No disinfected C:\WINNT\system32\wp.bmp
HijackThis:
Logfile of HijackThis v1.99.1
Scan saved at 8:41:18 AM, on 6/29/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\WS_FTP Pro\ftpsched.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\WS_FTP Pro\ftpqueue.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\hpoopm07.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet K Series\bin\hpodev07.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\HEWLET~1\HPOFFI~1\bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet K Series\bin\HPOSTS07.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet K Series\bin\HPOFXM07.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\Documents and Settings\westernmac\My Documents\Aaron\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O3 - Toolbar: Pop-Up Stopper &Companion - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:\Program Files\Panicware\Pop-Up Stopper Companion\popupus.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [ftpqueue] C:\Program Files\WS_FTP Pro\ftpqueue.exe -tray
O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINNT\System32\spool\DRIVERS\W32X86\hpoopm07.exe
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: HPAiODevice.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet K Series\bin\hpodev07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: AVSync Manager (AvSynMgr) - Networks Associates Technologies, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Ipswitch WS_FTP Queue (ftpqueue) - Ipswitch, Inc., 81 Hartwell Ave, Lexington MA 02421 - C:\Program Files\WS_FTP Pro\ftpsched.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe

Thanks
Hello again,

Thanks for the reply. Your instructions were well written. Here are the steps I have taken.

You are welcome, let's hope it worked and I wanted to say that: This fix was created by bananafanafo along with the help of many other malware fighters. This fix is courtesy of grinler, to give the credit where it is due. Since the infection compromises the computer, then more and more of the infection gets onboard as time goes by. When the fix is executed, if something is not there, it is probably just a matter of time before it would have been.
Thanks for the detailed feedback, that really helps. To save us both time, be assured I will read all and I will respond to questions only.

Let me say that the HJT log appears to be clean :) Because this is a nasty infection, I would like to take one more look before I give you the all clean information. Please do this:

Ewido trojan scanner: http://www.ewido.net/en/download/
Please download, install, update and scan your system with the free version of Ewido trojan scanner:
  1. When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  2. When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  3. From the main ewido screen, click on update in the left menu, then click the Start update button.
  4. After the update finishes (the status bar at the bottom will display "Update successful"), click on the Scanner button in the left menu, then click on the Start button. This scan can take quite a while to run, so time to go get a drink and a snack….
  5. If ewido finds anything, it will pop up a notification. You can select "clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
  6. When the scan finishes, click on "Save Report". This will create a text file. Please then paste the contents of the text file to this thread.

  7. Post the results of this scan along with a new HJT log. Let me know how things are running, if you are back to normal. Thanks…Phil
Okay Phil,

Please find the HJT log and Ewido log below. It seems the computer is running a bit slower than before the smitfraud.c. Also, I know get an error upon startup that webxscan.exe generated errors. Not sure what that is.

Logfile of HijackThis v1.99.1
Scan saved at 12:09:10 AM, on 6/30/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\WS_FTP Pro\ftpsched.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINNT\Explorer.EXE
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\WS_FTP Pro\ftpqueue.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\hpoopm07.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet K Series\bin\hpodev07.exe
C:\Program Files\ewido\security suite\SecuritySuite.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\HEWLET~1\HPOFFI~1\bin\hpoevm07.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet K Series\bin\HPOSTS07.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet K Series\bin\HPOFXM07.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\Documents and Settings\westernmac\My Documents\Aaron\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O3 - Toolbar: Pop-Up Stopper &Companion - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:\Program Files\Panicware\Pop-Up Stopper Companion\popupus.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [ftpqueue] C:\Program Files\WS_FTP Pro\ftpqueue.exe -tray
O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINNT\System32\spool\DRIVERS\W32X86\hpoopm07.exe
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: HPAiODevice.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet K Series\bin\hpodev07.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: AVSync Manager (AvSynMgr) - Networks Associates Technologies, Inc. - C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Ipswitch WS_FTP Queue (ftpqueue) - Ipswitch, Inc., 81 Hartwell Ave, Lexington MA 02421 - C:\Program Files\WS_FTP Pro\ftpsched.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe

Ewido:
ewido security suite - Scan report
———————————————————

+ Created on: 12:08:09 AM, 6/30/2005
+ Report-Checksum: 55445A32

+ Date of database: 6/30/2005
+ Version of scan engine: v3.0

+ Duration: 37 min
+ Scanned Files: 17671
+ Speed: 7.85 Files/Second
+ Infected files: 3
+ Removed files: 3
+ Files put in quarantine: 3
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0

+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes

+ Scanned items:
C:\

+ Scan result:
C:\WINNT\popuper.exe -> Trojan.Puper.w -> Cleaned with backup
C:\WINNT\system32\intmonp.exe -> Trojan.Puper.w -> Cleaned with backup
C:\WINNT\system32\ole32vbs.exe -> Spyware.Hijacker.Generic -> Cleaned with backup


::Report End
Hello Wes,

Please find the HJT log and Ewido log below. It seems the computer is running a bit slower than before the smitfraud.c. Also, I know get an error upon startup that webxscan.exe generated errors. Not sure what that is.

I must say I am not totally familiar with the Win2000 operating system, I will make suggestions that might speed you up a little after I review the log. I see Ewido picked up on a few items, it does not miss much and we can run more scanners if we wish, but I think you are in good shape. I would appreciate it if you would copy the exact error message your are getting for me. My gut feeling is it may be something left over from one of the malware items that were removed or something left from an old program. When I search for webxscan I return this information from Google:
http://www.google.com/search?sourceid=navc…D:en&q=webxscan Did you every use the Driver Detective program? When I search for webxscan.exe I return nothing which is unusual for Google. If it exists, Google will usually know it. Check that spelling, if it is correct then do a search for the item. You may need to enable the hidden files to see it. If you locate it RIGHT click and look at properties. Once you establish it is not valid then delete it. If it is running, delete it in safe mode. If you are not sure it is bad, then have these folks take a look at the item for you:
http://virusscan.jotti.org/

Your HJT log is also clean, I looked at your running programs and see little you could turn off. Take a look in: http://netsquirrel.com/msconfig/ to see if anything is checked that you do not use often. Please do not uncheck any security programs. If you have room to add additional RAM, I would do so. I would also make sure all of your maintenance programs are you to date. Sometimes a good scan disk and defrag works miracles.
Since your log is clean, Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Those folks will have some great ideas for you. For my two cents, I would use these two programs which will remove much malware that gets in: http://tomcoyote.org/aawsb.php and
SpywareBlaster
http://www.bleepingcomputer.com/forums/tutorial49.html
SpywareGuard:
http://www.bleepingcomputer.com/forums/tutorial50.html
IE-Spyad
http://www.bleepingcomputer.com/forums/tutorial53.html

Spybot has the TeaTimer function: http://www.voiceofthepublic.com/SSD/SI/teatimer.swf.html and most experts agree it does the same job as SpywareGuard so you can use one or the other. The other two programs are realtime protection that use no resources and will be explained and mentioned time and time again in the all clear links.

Keep your antivirus program updated and run it often. Use auto-updates if available. If you do not have a firewall, let me know and I will provide a free one. I also noticed in checking the BleepingComputer links are a little slow. They will work, just be patient.

I hope this information helps you be safe online….Phil

Thanks…pskelley
TomCoyote forum
Slyware Warrior
The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
Phil, Sorry about that but I was typing too fast I guess. The error is webscanx.exe generated errors. Upon doing my own research, it seems most people encounter it because of upgrading to IE 6. The fix is to go back down to IE 5.5. Maybe there is a fix out there which I haven't found yet. Here's McAfee's explanation: WebScanX Error at Bootup Customers using Windows 2000 and VirusScan 5.1x or higher are advised not to upgrade Internet Explorer 6.0 because of an incompatibility with the Download Scan/Internet Filter which results in a WebscanX error at startup. If you are experiencing this issue, you can disable Download Scan/Internet Filter as a workaround and set system scan to scan all files or downgrade to Internet Explorer 5.x.This issue only occurs with people running Windows 2000 professional, VirusScan 5.10 – 5.21, and Internet Explorer 6.0. This is NOT an issue in VirusScan 6.0. I do have VirusScan 5. Don't know if I'm SOL or not. Also, do you suggest Firewalls. I used to use one but it kept getting in the way of doing things so I turned it off. Maybe I should turn it back on again. Thanks
Hi Wes, Sorry about that issue, and my lack of experience with Windows 2000. I also use McAfee and have for years, but I can never get over all of the excuses they come up with. We are advised to get everyone to IE 6.0 for the best protection…so who knew.
Just to mention, I use VirusScanOnline and have the latest and my version is 4.4.
I am still sitting here astounded. I just can not believe McAfee is telling people not to upgrade to IE 6.0 because it does not work right with their software. I am afraid I would have to defer to their instructions not knowing anything about their issues?

I am a firm believer in a firewall. Some folks use a router that has a firewall in it. That would work, but if you are connected to the internet without a router I believe you need a firewall. The links I gave you should cover that information. I use a free version of Zone Alarm and have for years. I do not use ZA on my newest PC with WinXp SP2 opting instead to try out the Security Center firewall. I also have a Dell running WinXpPro with SP1 and use ZA on it not trusting the internet connection firewall built into the Operating System.

Zone Alarm free is a good firewall, there is a little work getting it configured, but once that is done I never hear from it. About the only time I do is when I upgrade to a new version of a program, then I get asked about it the first time and then tell ZA not to ask again. I will leave you with the links I have for free firewalls, and if there is anything else, let me know. I won't close the thread for a couple of days…Phil
I'll toss in Steve Gibsons port check so you can see how your ports are without the firewall: https://grc.com/x/ne.dll?bh0bkyd2

http://www.zonelabs.com/store/content/comp…reeDownload.jsp
http://smb.sygate.com/products/spf_standard.htm
There are others available online, but I know nothing about them.
Phil, Thanks so much for your insight and assistance. I'll check into your links and my webscanx.exe issue and will respond either way by next week. Thanks again, Aaron
I started using zone alarms firewall and everything seems to be functioning well otherwise. Again, thanks for you help and for providing all of the helpful links. I think we can closed this out as resolved. Aaron
Thanks Aaron, good luck and safe surfing :wavey:

If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI