This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

svchost.exe and explorer.exe using too much ram

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there,
I got a problem. I posted about a few months ago but nobody answered, and now I think it is starting to get severe. I am now nocticing that one of the SVCHOST.EXE processes is not using too much cpu but it is using between 50MB-100MB of ram. Then about 12:30 am this morning, Jan 2, 07, explorer.exe shot-up to 100% cpu and about 110MB ram. This would happen sparaticoly, if that is how you spell it. What I mean is that this would go on for about 2 minutes then go back down to 30% and then back up to 100%. This was doing this for about 45 minutes. As of right now, and I just got back on my computer, my SVCHOST.EXE ram as avg. 52MB of ram, and explorer is back down to 42MB of ram. I also did a virus scan, and McAfee only found 9 minor cookies.

In addition, I first posted in the "Computer problems" forum asking about the SVCHOST.exe problem, but then after I did some research, I found one topic of another guy who sounded like I am having the same problem, and here his topic was that the tech asked him to run some sort of rootkit finder, and here it was the lzx32.sys rootkit. Now I am affraid of running a rootkit finder because McAfee told me not to have too many tools installed because they might conflict with McAfee, and the other reason is I do not know which one to use thinking what if it is a rootkit installer instead of a finder. So to make a long story short, I did a *.sys search on my hard-drive. I did not thankfully find the lzx32.sys rootkit, but I did find 2 other weird files. They are 1731a9bc94.sys and sabprocenum.sys.

Furthermore, I cannot run most of my startup files so I appoligize if this makes things more complicated for you guys when reading my HJT log. However, with what is just running in the background now, I only have about 100 MB of ram left, which if I did run the other stuff it would bring my system down to a craw. So here is my HJT log…

Logfile of HijackThis v1.99.1
Scan saved at 10:06:07 AM, on 1/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Task Scheduler (mctskshd.exe) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mctskshd.exe
O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
You have a clean log :thumbup: Svchost manages your desktop and uses some resources. not according to this, and I can't run rootkitRevealer. I did some research, and found a topic about using a tool called smitfraudfx.exe. So this is my scan down below using smitfraudfx.exe SmitFraudFix v2.132 Scan done at 14:25:54.85, Fri 01/05/2007 Run from C:\Documents and Settings\backupAccount\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS C:\WINDOWS\alxie328.dll FOUND ! C:\WINDOWS\alxtb1.dll FOUND ! C:\WINDOWS\blue-bg.gif FOUND ! C:\WINDOWS\box_1.gif FOUND ! C:\WINDOWS\box_2.gif FOUND ! C:\WINDOWS\box_3.gif FOUND ! C:\WINDOWS\BTGrab.dll FOUND ! C:\WINDOWS\close-bar.gif FOUND ! C:\WINDOWS\dlmax.dll FOUND ! C:\WINDOWS\footer_back.gif FOUND ! C:\WINDOWS\header_1.gif FOUND ! C:\WINDOWS\main_back.gif FOUND ! C:\WINDOWS\Pynix.dll FOUND ! C:\WINDOWS\remove-spyware-btn.gif FOUND ! C:\WINDOWS\sep_hor.gif FOUND ! C:\WINDOWS\sep_vert.gif FOUND ! C:\WINDOWS\spacer.gif FOUND ! C:\WINDOWS\warning-bar-ico.gif FOUND ! C:\WINDOWS\win-sec-center-logo.gif FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\jao.dll FOUND ! C:\WINDOWS\system32\questmod.dll FOUND ! C:\WINDOWS\system32\tcpservice2.exe FOUND ! C:\WINDOWS\system32\txfdb32.dll FOUND ! C:\WINDOWS\system32\udpmod.dll FOUND ! C:\WINDOWS\system32\winapi32.dll FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\backupAccount »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\backupAccount\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\BACKUP~1\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="\\\\?\\C:\\WINDOWS\\system32\\com5.ale" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "system"="cszvu.exe" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
You did indeed have an infection called Smitfraud, What I meant by a clean log is that nothing on HJT looks bad.

It looks like you ran option 1 that gave you the report, lets run Option 2


You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

In case you need it again
Download SmitfraudFix
Extract the content (a folder named SmitfraudFix) to your Desktop.

Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run Ewido and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.
Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode

  • Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
  • Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.
  • You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.
  • The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".
  • The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart into normal Windows.
  • A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt





Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start> Control Panel and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete Offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button.
  • Click Apply then OK.





  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • Ewido will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5
IMPORTANT: Do not open any other windows or programs while AVG is scanning, it may interfere with the scanning process:


Post the log from Smitfraud fix, the AVG Spyware log and a New HJT log please
Ok, one thing you are going to shoot me is that I missed your message that I should of cleaned out my tempory internet files. So basically what I did was this in the exact order

1. already had Smitfraud.cmd so I did not need to download that.
2. downloaded AVG Anit-spyware 7.5
3. set the settings in AVG
4. rebooted to safe mode
5. used Smithfraud.cmd option 2 and saved the report
6. rebooted the computer to normal mode
7 ran AVG and saved report
8 Did a HJT log
9. post my logs here which here they are as followed….

HJT…
Logfile of HijackThis v1.99.1
Scan saved at 12:32:32 AM, on 1/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\hphmon06.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\notepad.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCPitstop Optimize Registration Reminder] C:\Program Files\PCPitstop\Optimize\Reminder.exe
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [dmgsv.exe] C:\WINDOWS\system32\dmgsv.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

SmitFraud.cmd …
SmitFraudFix v2.132

Scan done at 23:06:04.82, Fri 01/05/2007
Run from C:\Documents and Settings\backupAccount\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\alxie328.dll Deleted
C:\WINDOWS\alxtb1.dll Deleted
C:\WINDOWS\blue-bg.gif Deleted
C:\WINDOWS\box_1.gif Deleted
C:\WINDOWS\box_2.gif Deleted
C:\WINDOWS\box_3.gif Deleted
C:\WINDOWS\BTGrab.dll Deleted
C:\WINDOWS\close-bar.gif Deleted
C:\WINDOWS\dlmax.dll Deleted
C:\WINDOWS\footer_back.gif Deleted
C:\WINDOWS\header_1.gif Deleted
C:\WINDOWS\main_back.gif Deleted
C:\WINDOWS\Pynix.dll Deleted
C:\WINDOWS\remove-spyware-btn.gif Deleted
C:\WINDOWS\sep_hor.gif Deleted
C:\WINDOWS\sep_vert.gif Deleted
C:\WINDOWS\spacer.gif Deleted
C:\WINDOWS\warning-bar-ico.gif Deleted
C:\WINDOWS\win-sec-center-logo.gif Deleted
C:\WINDOWS\system32\jao.dll Deleted
C:\WINDOWS\system32\questmod.dll Deleted
C:\WINDOWS\system32\tcpservice2.exe Deleted
C:\WINDOWS\system32\txfdb32.dll Deleted
C:\WINDOWS\system32\udpmod.dll Deleted
C:\WINDOWS\system32\winapi32.dll Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"system"="cszvu.exe"


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

AVG report
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 12:26:41 AM 1/6/2007

+ Scan result:



C:\WINDOWS\system32\rfscanax.dll -> Adware.AdwareSheriff : No action taken.
D:\owner d drive\AOL Downloads\gozilla.exe -> Adware.EZula : No action taken.
C:\WINDOWS\ho5.exe -> Dropper.Delf.ux : No action taken.
:mozilla.48:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.10:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@sonycorporate.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
:mozilla.30:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.52:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Clickbank : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.54:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.49:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.50:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.51:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\backupAccount\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\backupAccount\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\backupAccount\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.29:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@overture[2].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@edge.ru4[2].txt -> TrackingCookie.Ru4 : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.24:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.25:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.26:C:\Documents and Settings\backupAccount\Application Data\Mozilla\Firefox\Profiles\x99xae2d.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\backupAccount\Cookies\backupaccount@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\WINDOWS\system32\csynb.exe -> Trojan.Small.fb : No action taken.
[972] VM_01C30000 -> Trojan.Small.fb : No action taken.


::Report end
Good Morning killerBob :D

You are doing well, you had no markers in your original HJT for Smithfraud so I am glad you posted the log from it, it looks like that infection is gone.


Look at your AVG log, when you set it up, you have it at No Action Taken you should have changed it to Quarantine or Delete as there are entries in there that are part of smitfraud. I would change it and run AVG again.

You can run this tool to clean you up real well after you run AVG.

Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up


Let me see the AVG report and a New HJT log.
Hphmon06.exe
This program is not required to start automatically as you can run it when you need to. It is advised that you disable this program so that it does not take up necessary resources.

You can remove this with HJT.
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe

Let me know if it helped

Look at your AVG log, when you set it up, you have it at No Action Taken you should have changed it to Quarantine or Delete as there are entries in there that are part of smitfraud. I would change it and run AVG again.
/quote]


I did changed it to quarantine. I can't look at it now because I got a warning "MALEWARE FOUND" in big red letters which I like to take care of first.

Also I am concerend about my other windows account. I only ran smitFraudFix.cmd through one account called "backupAccount", which I noticed that it only scanned that account. If you look at my first smitFraudFix.cmd report, you will see that the folder C:\documents and settings\backupAccount and subfolders where scanned, but I also have c:\ducuments and settings\owner and sub folders. Would this matter?

Last, as to about the first HJT log, I really appoligize for for not running in normal mode. But like said I could not boot in normal mode because my ram was so low, even without all my startup files running. Also because it took awhile to get help, I had more serious problems that where getting worst to the point that I coudd only boot into safe mode with networking. If you have a second, and this might help you diagnosing with future logs of mine, the last post of the following thread… http://forums.tomcoyote.org/index.php?showtopic=74501&hl descripes the problems that I was having while waiting for someone to post in here. I did this because I did not know what to do since you have this 5 day waiting policy and we should not to reply in your threads before a specialist post back first, and I needed to get through sombody to let you guys know.

Anyways to make a long story short, I will need to fix this warning first and then I will do another AVG scan and post back. Also, with the hphmon06.exe, even though it is not important to have logged on, still it should not be taking 260MB of ram.

I will get back to you shortly. thanks a bunch
Ok, first, like I said when I booted my computer up this morning, I got an AVG warning saying "MALEWARE FOUND!" in Big red letters. After posting the above reply, I went to take care of that warning first by choosing "clean and quarintine (recomended)", and clicked on OK. The warning box went away, and then I right clicked on the AVG icon on the systray, and selected open Main Window. I then double checked to make sure that the settings said "Quarintine". It did. Then I did another scan. After the scan, it reported more medium maleware, and the files from previously that said "take no action" was found again, but would you beleive that the darn same files said "take no action" again. I do not know what I am doing wrong, but AVG is not killing the files. So here is that report… ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 11:22:46 AM 1/6/2007 + Scan result: C:\WINDOWS\system32\rfscanax.dll -> Adware.AdwareSheriff : No action taken. D:\owner d drive\AOL Downloads\gozilla.exe -> Adware.EZula : No action taken. HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-59D4-4008-9058-080011001200} -> Adware.TitanShieldAntispyware : No action taken. HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-C1EC-0345-6EC2-4D0300000000} -> Adware.TitanShieldAntispyware : No action taken. HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-F09C-02B4-6EC2-AD0300000000} -> Adware.TitanShieldAntispyware : No action taken. HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CEFF6CD-6F08-4E4D-BCCD-FF7415288C3B} -> Adware.TitanShieldAntispyware : No action taken. HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7B55BB05-0B4D-44FD-81A6-B136188F5DEB} -> Adware.TitanShieldAntispyware : No action taken. HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8333C319-0669-4893-A418-F56D9249FCA6} -> Adware.TitanShieldAntispyware : No action taken. HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9C691A33-7DDA-4C2F-BE4C-C176083F35CF} -> Adware.TitanShieldAntispyware : No action taken. HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E52DEDBB-D168-4BDB-B229-C48160800E81} -> Adware.TitanShieldAntispyware : No action taken. HKU\S-1-5-21-602162358-308236825-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFD2825E-0785-40C5-9A41-518F53A8261F} -> Adware.TitanShieldAntispyware : No action taken. C:\WINDOWS\ho5.exe -> Dropper.Delf.ux : No action taken. C:\WINDOWS\system32\csynb.exe -> Trojan.Small.fb : No action taken. C:\WINDOWS\system32\dmgsv.exe -> Trojan.Small.fb : No action taken. [264] VM_00B40000 -> Trojan.Small.fb : No action taken. ::Report end next my HJT program said I do not have write access to this folder. please select another location. I wonder if the reason is because I logged on as my other account which does not have adminivstrative rights? Could this be possible? BTW… I atleast got my taskbar back to the way it suppose to look like.

Killerbob,

You are also being helped here
http://spywarewarrior.com/viewtopic.php?p=147454#147454

All of the spyware forums have to many posters posting with malware problems to have more than one person helping you, decide which forum you want to stay with and have the courtesy to let us know which forum you want to help you. We all work together and makes no difference to me which one you choose.


Ok, I posted there because like I said, my computer was getting worse, and no one had said anything for 4 days. I really did not mean to take 2 people to help me and did not know you guys work together. I thought that maybe another site would of replied faster. Then again, why I posted here was because you directly told me what to do, where the specialist at spyware warrior just asked me if I wanted to format the hardrive, or I will try my best on cleaning the files, not too promising to me. But in any event I would like to stay with tomcoyote if you do not mind since you have aleardy cleaned some of the files.

Also, not to sound cruel or sacrastict or how ever you might take it, and just as a suggestion, maybe you guys could lower the after 5 day no reply policy to maybe after 3 days? It is just a suggestion, and I understand you guys get really swamp, and you are volenteers, but to me it I thought you guys where just ignoring me especially when I kept on seeing the "Views" part was increasing, ut still said 0 replies. I think it would be better if the users would be notified, even if it is a message saying, "I see your message, and someone will get to you as soon as possible. This way the user knows you aknolwede them, and the user can keep on reporting new problems. Or stop using the "we look at the 0 replies first" and instead, let the users reply new updates of what is happening to our computer while we are waiting for a specialist.

As you can see, when I first posted here, my HJT did not look so bad, and I think this was why some of you overlooked at my post because you know that other people have more serious threats. However, in the long run, I had the most threatening virus or maleware or what ever smitfraud is considered as. Also, rembering that I have seen some of these files previously and looking at the dates of the files, some of them have been on my computer since May of 2005 when my Desktop was Hijacked. So in otherwords who knows what this hacker or hackers had or has done to me for almost 2 years now.
Also, I forgot to mention, since I would like to choose this forum, what would you like me to do with why AVG will not kill those certain files? I have set my settings to "Quarentine" but for some reason, AVG will not kill them. And just as a reminder, I also asked about why HJT will not save a report. How would you like me to fix that? It is in the "c:\HijackThis\" directory and I could save logs before.

Ken, do you understand I am sticking with this forum?

Bob, like you said , we are all volunteers and do this whenever we get a spare moment , we all don't just sit in front of our computer 24 hours aday waiting for replies. I understand how frustrating this all is, you just have to use a little patience and we will try to clean you up best we can.

One of the infections you have may be interferring with AVG ??????

Do this and we can procede with some other infections that you have. Log into windows normally as you would when you want to use your computer.


You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download FixWareout from one of these sites:
FixWareout Subratam
FixWareout Lonny
  • Save it to your desktop and run it.
  • Click Next, then Install,
  • Then make sure "Run fixit" is checked and click Finish.
  • The fix will begin; follow the prompts.
  • You will be asked to reboot your computer; please do so.
  • Your system may take longer than usual to load; this is normal.
  • At the end of the fix, you may need to restart your computer again.
Save the contents of the logfile C:\fixwareout\report.txt and post it into your next reply.

Now lets check some settings on your system. For (2000/XP) Only)
  • Go to Start > control panel.
  • If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections.
  • Then right click on your default connection, usually local area connection for cable and dsl.
  • Left click on properties.
  • Click the Networking tab.
  • Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically
  • Press OK twice to get out of the properties screen and reboot if it asks.
    That option might not be available on some systems
  • Next Go start> Run type cmd and hit OK
  • Type in ipconfig /flushdns then hit enter
    (that space between g and / is needed)
  • Type exit hit enter

All the info that Blender gave you over at SpywareWarrior was true and up to date. We may clean your system but its possible that it has been badly compromised so I would refrain from any online transactions that involve personal information.



After you run FixWareout, reboot and run this tool.

Download the Gromozon removal tool from Here:

Save the tool to your desktop.
Disconnect from internet and shut down any unecessary applications and your antivirus to prevent conflicts.
Double click the tool you just saved.
It may or may not find anything. It should ask if you want to continue regardless. If something is found you will be told to reboot.
Hit OK to continue.
Machine will be rebooted.
The removal tool will start its second phase of scan
Let it finish.
Press exit.
At this time you will be asked if you want to download/install Prevx1. Your choice whether or not to install this. Click no if you don't want it.
I would say no for now at least till we figure out what else is going on.
Log should be in c:\gromozon_removal.log. I will need this later.



Use the link in my signature to download and install a fresh copy of HJT, it will by default install in C:\Program Files\Hijackthis

Post the log from Fix Wareout , Gromozon and a New HJT log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI