This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

pop-ups, double underlined Intellitxt

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

May I please have some help with this log file. Getting double underlined words within my email that are attached to ads driven by Intellitxt.com. I can no longer reply to any emails. Many thanks!
Logfile of HijackThis v1.99.1
Scan saved at 1:46:43 PM, on 8/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\LTMSG.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\progra~1\mcafee\MCAFEE~1\masalert.exe
C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\SentrilockCardUtility\SentrilockCardUtility.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\WISPTIS.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Owner\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us10.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.comcast.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us10.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: adobepnl.ADOBE_PANEL - {2513A321-CB50-4C5F-91C5-80342AFACFB1} - C:\WINDOWS\system32\adobepnl.dll (file missing)
O2 - BHO: (no name) - {3ceff6cd-6f08-4e4d-bccd-ff7415288c3b} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
O2 - BHO: (no name) - {8333c319-0669-4893-a418-f56d9249fca6} - (no file)
O2 - BHO: (no name) - {87185E78-A61B-4DB3-965A-3235BBD7A622} - C:\WINDOWS\system32\win32hp.dll
O2 - BHO: (no name) - {9c691a33-7dda-4c2f-be4c-c176083f35cf} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: office_pnl.office_panel - {B53455DB-5527-4041-AC41-F86E6947AA47} - C:\WINDOWS\system32\office_pnl.dll (file missing)
O2 - BHO: (no name) - {e52dedbb-d168-4bdb-b229-c48160800e81} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O2 - BHO: (no name) - {ffd2825e-0785-40c5-9a41-518f53a8261f} - (no file)
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Organize.lnk = ?
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SentriLockCardUtility.lnk = C:\Program Files\SentrilockCardUtility\SentrilockCardUtility.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {238EC5B8-0BF5-11D5-826E-00010239321B} (OBXViewer Control) - http://imgweb.charlestoncounty.org/appnet/…x/OBXViewer.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {8285080A-3FAF-41B1-B7BD-933EE724B650} (OBXDocumentSelect Control) - http://imgweb.charlestoncounty.org/appnet/…x/OBXSelect.cab
O16 - DPF: {9145A52A-9B22-4858-AEE7-74D6C7D3F366} (BrowserConfig Class) - https://go1f.wspan.com/secure/DLLs/WSBrowserConfig.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia.com/upload/activex/v2_…tupv2.0.0.9.cab?
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\SYSTEM32\ckpNotify.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Only for Windows XP and Windows 2000

Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

[external image: Posted Image]

______________________________
Next:

Download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.

______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter

[external image: Posted Image]

This program will scan large amounts of files on your computer for known patterns so please be patient while it works. It will create a file named:

c:\rapport.txt

Open that file with Notepad, and "copy/paste" the ENTIRE CONTENTS of it into this thread.
Here ya go! Looks interesting! SmitFraudFix v2.82 Scan done at 19:56:03.68, Tue 08/29/2006 Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS C:\WINDOWS\alexaie.dll FOUND ! C:\WINDOWS\alxie328.dll FOUND ! C:\WINDOWS\alxtb1.dll FOUND ! C:\WINDOWS\about_spyware_bg.gif FOUND ! C:\WINDOWS\about_spyware_bottom.gif FOUND ! C:\WINDOWS\as.gif FOUND ! C:\WINDOWS\as_header.gif FOUND ! C:\WINDOWS\big_red_x.gif FOUND ! C:\WINDOWS\box_1.gif FOUND ! C:\WINDOWS\box_2.gif FOUND ! C:\WINDOWS\box_3.gif FOUND ! C:\WINDOWS\BTGrab.dll FOUND ! C:\WINDOWS\button_buynow.gif FOUND ! C:\WINDOWS\button_freescan.gif FOUND ! C:\WINDOWS\buy_now.gif FOUND ! C:\WINDOWS\click_for_free_scan.gif FOUND ! C:\WINDOWS\close_ico.gif FOUND ! C:\WINDOWS\close-bar.gif FOUND ! C:\WINDOWS\dlmax.dll FOUND ! C:\WINDOWS\download.gif FOUND ! C:\WINDOWS\download_box.gif FOUND ! C:\WINDOWS\download_product.gif FOUND ! C:\WINDOWS\features.gif FOUND ! C:\WINDOWS\footer_back.gif FOUND ! C:\WINDOWS\footer_back.jpg FOUND ! C:\WINDOWS\free_scan_red_btn.gif FOUND ! C:\WINDOWS\header_1.gif FOUND ! C:\WINDOWS\header_2.gif FOUND ! C:\WINDOWS\header_3.gif FOUND ! C:\WINDOWS\header_4.gif FOUND ! C:\WINDOWS\icon_warning_big.gif FOUND ! C:\WINDOWS\infected.gif FOUND ! C:\WINDOWS\infected_top_bg.gif FOUND ! C:\WINDOWS\logo.gif FOUND ! C:\WINDOWS\main_back.gif FOUND ! C:\WINDOWS\navibar_bg.gif FOUND ! C:\WINDOWS\navibar_corner_left.gif FOUND ! C:\WINDOWS\navibar_corner_right.gif FOUND ! C:\WINDOWS\product_box.gif FOUND ! C:\WINDOWS\Pynix.dll FOUND ! C:\WINDOWS\red_warning_ico.gif FOUND ! C:\WINDOWS\remove_spyware_header.gif FOUND ! C:\WINDOWS\rf.gif FOUND ! C:\WINDOWS\rf_header.gif FOUND ! C:\WINDOWS\safe_and_trusted.gif FOUND ! C:\WINDOWS\scan_btn.gif FOUND ! C:\WINDOWS\security-center-bg.gif FOUND ! C:\WINDOWS\security-center-logo.gif FOUND ! C:\WINDOWS\security_center_caption.gif FOUND ! C:\WINDOWS\sep_hor.gif FOUND ! C:\WINDOWS\sep_vert.gif FOUND ! C:\WINDOWS\spacer.gif FOUND ! C:\WINDOWS\spacer.gif' FOUND ! C:\WINDOWS\spyware_detected.gif FOUND ! C:\WINDOWS\spyware-detected.gif FOUND ! C:\WINDOWS\star.gif FOUND ! C:\WINDOWS\star_gray.gif FOUND ! C:\WINDOWS\star_gray_small.gif FOUND ! C:\WINDOWS\star_small.gif FOUND ! C:\WINDOWS\System32fab.exe FOUND ! C:\WINDOWS\ts.gif FOUND ! C:\WINDOWS\ts_header.gif FOUND ! C:\WINDOWS\v.gif FOUND ! C:\WINDOWS\warning_icon.gif FOUND ! C:\WINDOWS\warning-bar-ico.gif FOUND ! C:\WINDOWS\win_logo.gif FOUND ! C:\WINDOWS\x.gif FOUND ! C:\WINDOWS\yellow_warning_ico.gif FOUND ! C:\WINDOWS\ZServ.dll FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\a.exe FOUND ! C:\WINDOWS\system32\bridge.dll FOUND ! C:\WINDOWS\system32\dailytoolbar.dll FOUND ! C:\WINDOWS\system32\jao.dll FOUND ! C:\WINDOWS\system32\mshtml32.tdb FOUND ! C:\WINDOWS\system32\questmod.dll FOUND ! C:\WINDOWS\system32\smaexp32.dll FOUND ! C:\WINDOWS\system32\thlwin32.dll FOUND ! C:\WINDOWS\system32\txfdb32.dll FOUND ! C:\WINDOWS\system32\udpmod.dll FOUND ! C:\WINDOWS\system32\winblsrv.dll FOUND ! C:\WINDOWS\system32\wstart.dll FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Owner\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Running the Clean

Warning: running option #2 on a non infected computer will remove your Desktop background.


Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

[external image: Posted Image]


The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Close ALL open Windows / Programs / Folders. Please start Ewido, and run a full scan.
  • IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it as a text file on your Desktop (make sure to remember where you saved that file, this is important).
Close Ewido and Reboot in Normal Mode.
______________________________

Please post:
  • c:\rapport.txt
  • Ewido log
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
Here we go..already the Intellitxt ads have stopped - so I'm stoked!
hijack this log.

Logfile of HijackThis v1.99.1
Scan saved at 7:26:38 AM, on 8/30/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\progra~1\mcafee\MCAFEE~1\masalert.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
c:\progra~1\mcafee\mcafee antispyware\massrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SentrilockCardUtility\SentrilockCardUtility.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\interMute\SpamSubtract\SpamSub.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Owner\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {87185E78-A61B-4DB3-965A-3235BBD7A622} - C:\WINDOWS\system32\win32hp.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Organize.lnk = ?
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SentriLockCardUtility.lnk = C:\Program Files\SentrilockCardUtility\SentrilockCardUtility.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\Netscape\Communicator\Program\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {238EC5B8-0BF5-11D5-826E-00010239321B} (OBXViewer Control) - http://imgweb.charlestoncounty.org/appnet/…x/OBXViewer.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {8285080A-3FAF-41B1-B7BD-933EE724B650} (OBXDocumentSelect Control) - http://imgweb.charlestoncounty.org/appnet/…x/OBXSelect.cab
O16 - DPF: {9145A52A-9B22-4858-AEE7-74D6C7D3F366} (BrowserConfig Class) - https://go1f.wspan.com/secure/DLLs/WSBrowserConfig.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia.com/upload/activex/v2_…tupv2.0.0.9.cab?
O20 - Winlogon Notify: ckpNotify - C:\WINDOWS\SYSTEM32\ckpNotify.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: McAfee AntiSpyware Service - McAfee, Inc. - c:\progra~1\mcafee\mcafee antispyware\massrv.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
rapport log. SmitFraudFix v2.82 Scan done at 22:07:58.82, Tue 08/29/2006 Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in safe mode »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\alexaie.dll Deleted C:\WINDOWS\alxie328.dll Deleted C:\WINDOWS\alxtb1.dll Deleted C:\WINDOWS\about_spyware_bg.gif Deleted C:\WINDOWS\about_spyware_bottom.gif Deleted C:\WINDOWS\as.gif Deleted C:\WINDOWS\as_header.gif Deleted C:\WINDOWS\big_red_x.gif Deleted C:\WINDOWS\box_1.gif Deleted C:\WINDOWS\box_2.gif Deleted C:\WINDOWS\box_3.gif Deleted C:\WINDOWS\BTGrab.dll Deleted C:\WINDOWS\button_buynow.gif Deleted C:\WINDOWS\button_freescan.gif Deleted C:\WINDOWS\buy_now.gif Deleted C:\WINDOWS\click_for_free_scan.gif Deleted C:\WINDOWS\close-bar.gif Deleted C:\WINDOWS\close_ico.gif Deleted C:\WINDOWS\dlmax.dll Deleted C:\WINDOWS\download.gif Deleted C:\WINDOWS\download_box.gif Deleted C:\WINDOWS\download_product.gif Deleted C:\WINDOWS\features.gif Deleted C:\WINDOWS\footer_back.gif Deleted C:\WINDOWS\footer_back.jpg Deleted C:\WINDOWS\free_scan_red_btn.gif Deleted C:\WINDOWS\header_1.gif Deleted C:\WINDOWS\header_2.gif Deleted C:\WINDOWS\header_3.gif Deleted C:\WINDOWS\header_4.gif Deleted C:\WINDOWS\icon_warning_big.gif Deleted C:\WINDOWS\infected.gif Deleted C:\WINDOWS\infected_top_bg.gif Deleted C:\WINDOWS\logo.gif Deleted C:\WINDOWS\main_back.gif Deleted C:\WINDOWS\navibar_bg.gif Deleted C:\WINDOWS\navibar_corner_left.gif Deleted C:\WINDOWS\navibar_corner_right.gif Deleted C:\WINDOWS\product_box.gif Deleted C:\WINDOWS\Pynix.dll Deleted C:\WINDOWS\red_warning_ico.gif Deleted C:\WINDOWS\remove_spyware_header.gif Deleted C:\WINDOWS\rf.gif Deleted C:\WINDOWS\rf_header.gif Deleted C:\WINDOWS\safe_and_trusted.gif Deleted C:\WINDOWS\scan_btn.gif Deleted C:\WINDOWS\security-center-bg.gif Deleted C:\WINDOWS\security-center-logo.gif Deleted C:\WINDOWS\security_center_caption.gif Deleted C:\WINDOWS\sep_hor.gif Deleted C:\WINDOWS\sep_vert.gif Deleted C:\WINDOWS\spacer.gif Deleted C:\WINDOWS\spacer.gif' Deleted C:\WINDOWS\spyware_detected.gif Deleted C:\WINDOWS\spyware-detected.gif Deleted C:\WINDOWS\star.gif Deleted C:\WINDOWS\star_gray.gif Deleted C:\WINDOWS\star_gray_small.gif Deleted C:\WINDOWS\star_small.gif Deleted C:\WINDOWS\ts.gif Deleted C:\WINDOWS\ts_header.gif Deleted C:\WINDOWS\System32fab.exe Deleted C:\WINDOWS\v.gif Deleted C:\WINDOWS\warning_icon.gif Deleted C:\WINDOWS\warning-bar-ico.gif Deleted C:\WINDOWS\win_logo.gif Deleted C:\WINDOWS\x.gif Deleted C:\WINDOWS\yellow_warning_ico.gif Deleted C:\WINDOWS\ZServ.dll Deleted C:\WINDOWS\system32\a.exe Deleted C:\WINDOWS\system32\bridge.dll Deleted C:\WINDOWS\system32\dailytoolbar.dll Deleted C:\WINDOWS\system32\jao.dll Deleted C:\WINDOWS\system32\mshtml32.tdb Deleted C:\WINDOWS\system32\questmod.dll Deleted C:\WINDOWS\system32\smaexp32.dll Deleted C:\WINDOWS\system32\thlwin32.dll Deleted C:\WINDOWS\system32\txfdb32.dll Deleted C:\WINDOWS\system32\udpmod.dll Deleted C:\WINDOWS\system32\winblsrv.dll Deleted C:\WINDOWS\system32\wstart.dll Deleted »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
ewido log. ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 7:18:45 AM 8/30/2006 + Scan result: C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined). HKU\S-1-5-21-843961626-88516694-4084742014-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B53455DB-5527-4041-AC41-F86E6947AA47} -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\TypeLib\{CE7C3CE2-4B15-11D1-ABED-709549C10000} -> Adware.RegiFast : Cleaned with backup (quarantined). C:\WINDOWS\system32\0.3161127.exe -> Downloader.VB.ajv : Cleaned with backup (quarantined). HKU\S-1-5-21-843961626-88516694-4084742014-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E52DEDBB-D168-4BDB-B229-C48160800E81} -> Hijacker.Generic : Cleaned with backup (quarantined). C:\WINDOWS\system32\uafcaidp.koj -> Hijacker.Small.js : Cleaned with backup (quarantined). :mozilla.141:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.156:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.157:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.159:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.184:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.19:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.20:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.23:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.26:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.27:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.28:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.29:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.30:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.31:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.32:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.33:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.34:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.35:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.37:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.38:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.40:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.41:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.77:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Admarketplace : Cleaned with backup (quarantined). :mozilla.78:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Admarketplace : Cleaned with backup (quarantined). :mozilla.45:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.46:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.47:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.48:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.49:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.44:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). :mozilla.137:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined). :mozilla.251:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.22:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). :mozilla.82:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). :mozilla.83:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). :mozilla.84:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). :mozilla.85:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). :mozilla.86:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). :mozilla.87:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). :mozilla.91:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). :mozilla.92:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). :mozilla.89:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.16:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.17:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.222:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.225:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.226:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.233:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.247:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup (quarantined). :mozilla.248:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup (quarantined). :mozilla.98:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup (quarantined). :mozilla.42:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). :mozilla.43:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). :mozilla.187:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). :mozilla.74:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.75:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.76:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.250:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.63:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.64:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.65:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.189:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.190:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.191:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.192:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.193:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.107:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.108:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.109:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.110:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.111:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.112:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.113:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.114:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.115:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.116:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.117:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.118:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.119:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.120:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.121:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.122:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.123:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.124:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.125:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.126:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.163:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.164:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.165:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.166:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.167:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.168:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.169:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.170:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.171:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.172:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.173:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup (quarantined). :mozilla.237:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined). :mozilla.147:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.228:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.69:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.70:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). :mozilla.71:C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\skuzemch\6u5nssmh.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). C:\WINDOWS\system32\1310.exe -> Trojan.Regger.s : Cleaned with backup (quarantined). ::Report end
looks like there were some nasty pages in there from Lord only knows where! Do you know what it was that got me? Sould I leave ewido and smitfraud on my computer? I also have Adaware and SuperAntispyware from previous hijackthis recommendations…do I still need to keep those on my computer? Many thank yous!
Close all windows/programs and fix these with HijackThis!:

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

O2 - BHO: (no name) - {87185E78-A61B-4DB3-965A-3235BBD7A622} - C:\WINDOWS\system32\win32hp.dll (file missing)

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot


Reboot.

How's it running?
:unsure:

Securing Your PC After An Attack

Sould I leave ewido and smitfraud on my computer?

Unless you upgrade Ewido to the "paid" version, it will expire. So it may be removed (if upgrading isn't an option).

Smitfraud may be removed.

Adaware and SuperAntispyware from previous hijackthis recommendations…do I still need to keep those on my computer?

AdAware is a "keeper". The other is OK (if it's "free").
I'm at work and away from my home computer right now so I won't be able to perform these functions until tonight, but I can't wait. I'll post the outcome then. Was running a tad slow this AM, but otherwise without error messages and those darn double-underlined words throughout the pages! I'm stoked!
I fixed those items you recommended and we're ok - all's clear here. You emancipated me from a batch of evilware! Can you tell how we got ourselves into this mess? I'll look into the link you sent me on protecting myself after infection. Again, many thanks for your support. I can't say enough. Now to go prepare to face T.S. Ernesto.
As far as I know, Smitfraud is spread by malicious web sites.

They must prey on incorrect security settings in your browser.

Check/adjust your settings here:

Jason's Toolbox

Incorrect browser settings can allow websites to download code to your machine, and you don't have to click a thing!!

Thank you for choosing TomCoyote for your malware removal solutions.

M68 :)

Securing Your PC After An Attack
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI