here is the logs :
SmitFraudFix v2.81
Scan done at 16:27:07,10, 26.08.2006
Run from C:\Documents and Settings\ilkay\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Srm 5.1.2600] - Windows_NT
Fix ran in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\ilkay\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ilkay\SKKULL~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
———————————————————————————-
hijackthis log :
Logfile of HijackThis v1.99.1
Scan saved at 16:25:58, on 26.08.2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\APACHE\Apache.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\APACHE\Apache.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Winamp\winampa.exe
C:\Documents and Settings\ilkay\Desktop\HijackThis.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\System32\imapi.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar
R3 - URLSearchHook: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Radyo - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll (file missing)
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [fao84aa2] RUNDLL32.EXE w14377ce.dll,n 00384a9f0000000a14377ce
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [D_V_T] C:\\dvt.exe /S \C:\\d_v_t.reg\
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Washer] C:\Program Files\Washer\washer.exe /0
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [a7e55061.exe] C:\Documents and Settings\ilkay\Local Settings\Application Data\a7e55061.exe
O4 - HKCU\..\Run: [Ultimate Defender] "C:\Program Files\Ultimate Defender\App.exe" hide
O4 - HKCU\..\Run: [Rqkawiih] C:\Documents and Settings\ilkay\Application Data\T?sks\wuaclt.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Microsoft Excel'e Gö&nder - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: MynetBatak -
http://212.101.96.32/game/WebRoot/Batak.CAB
O16 - DPF: MynetKing -
http://212.101.96.32/game/WebRoot/King.CAB
O16 - DPF: MynetTavla -
http://oyunsunucu.mynet.com/game/WebRoot/Tavla.CAB
O16 - DPF: {00000000-0000-0000-0000-100005000004} -
http://code.trasferimento.biz/l/33a8bf3d91…ea8abd27_35.exe
O16 - DPF: {0FC8B38E-9293-424C-9D0E-CE60775679CF} (SubClassEditCtrlContainer Class) -
https://sube.garanti.com.tr/lib/JaguarEditControl.CAB
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} -
http://promo.dollarrevenue.com/activex/pro…436342D2D2D.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by14fd.bay14.hotmail.msn.com/resources/MsnPUpld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{96DDF58C-3522-4164-960E-FB3AB9EA4A25}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = 192.168.1.1
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: Internet Settings - C:\WINDOWS\system32\g0220afoed2c0.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Apache - Unknown owner - C:\APACHE\Apache.exe" –ntservice (file missing)
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
————————————————————————————————-
and ewido log file :
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 16:22:32 26.08.2006
+ Scan result:
HKLM\SOFTWARE\Effective-i -> Adware.EffectiveBrandToolbar : Cleaned.
HKLM\SOFTWARE\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Cleaned.
HKLM\SOFTWARE\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Cleaned.
HKU\S-1-5-21-1060284298-688789844-725345543-1003\Software\Effective-i -> Adware.EffectiveBrandToolbar : Cleaned.
HKU\S-1-5-21-1060284298-688789844-725345543-1003\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Cleaned.
HKU\S-1-5-21-1060284298-688789844-725345543-1003\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Cleaned.
C:\WINDOWS\system32\rBstls.dll -> Adware.Look2Me : Cleaned.
[620] C:\WINDOWS\system32\mcports.dll -> Adware.Look2Me : Cleaned.
[696] C:\WINDOWS\system32\mcports.dll -> Adware.Look2Me : Cleaned.
C:\Program Files\Cowabanga\Cowabanga.exe -> Adware.MediaTicket : Cleaned.
C:\Program Files\SystemDoctor 2006 Free -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\Activate.dat -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\DataBase.sav -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\License.rtf -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\ReportListFile.dat -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\SafeMedia -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\SafeMedia\Mp3DB -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\SafeMedia\MpegDB -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\SafeMedia\WaveDB -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\bnlink.dat -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\df_temp.tmp -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\hmlink.dat -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\insthelp.exe -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\lapv.dat -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\lock.dat -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\order.dll -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\pv.dat -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\sd2006url.url -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\support.url -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\umain.xml -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\unins000.dat -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\unins000.exe -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\up.dat -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\updater.dat -> Adware.SystemDoctor2006 : Cleaned.
C:\Program Files\SystemDoctor 2006 Free\updater.exe -> Adware.SystemDoctor2006 : Cleaned.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UCmore - The Search Accelerator -> Adware.UCmore : Cleaned.
HKLM\SOFTWARE\Classes\CLSID\{2178F3FB-2560-458f-BDEE-631E2FE0DFE4} -> Adware.WinAntiVirus : Cleaned.
C:\Program Files\WіnSxS\msiexec.exe -> Downloader.PurityScan.da : Cleaned.
C:\Documents and Settings\ilkay\Application Data\winantiviruspro2006freeinstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned.
C:\Program Files\Ares Lite Edition\AresLite.exe -> Trojan.Small : Cleaned.
::Report end
i m looking forward to get ur reply
