This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Antivermins Vermin - hijackthis log

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Gurus,
Many thanks in advance for anyone who can help me eradicate the Antivermin Vermin from my pc. Please help.

Logfile of HijackThis v1.99.1
Scan saved at 4:24:22 PM, on 12/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\Java\jre1.5.0\bin\jucheck.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\cmunro.REA_SYD\Desktop\hijackthis\HijackThis.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Exonet 6000\exonet.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.radioinfo.com.au/aboutme.php
O1 - Hosts: **isp's etc
O1 - Hosts: 61.9.128.13 login-server.vic.bigpond.net.au login-server sm-server sm-server.vic.bigpond.net.au
O1 - Hosts: 61.9.192.13 login-server.nsw.bigpond.net.au sm-server.nsw.bigpond.net.au
O1 - Hosts: 155.143.229.129 rea-melb-cable melbcable.rutledge.com.au melbcable #Melb Cable Telstra
O1 - Hosts: 203.206.164.142 rea-melb-adsl2 rea-melb2 melbadsl2.rutledge.com.au melbadsl2 rutledge-melb2 #Melb ADSL2 iinet static
O1 - Hosts: 210.23.136.26 rea-melb-adsl rea-melb melbadsl.rutledge.com.au melbadsl rutledge-melb #Melb ADSL pacific net static b1f1a.static.pacific.net.au
O1 - Hosts: 203.206.172.108 rea-syd-adsl sydadsl.rutledge.com.au #rutledge sydney iinet adsl2 static ip
O1 - Hosts: 138.130.43.80 rea-syd-cable sydcable.rutledge.com.au sydcable rutledge-syd-cable rea-syd #Syd Cable Backup
O1 - Hosts: 138.130.35.166 sydhouse.rutledge.com.au sydhouse rutledge-sydhouse #Syd find it out!
O1 - Hosts: 203.171.65.141 rea-mirror-offsite rea-offsite #MR rsync machine aanet static
O1 - Hosts: 203.217.30.162 soundcorp-adsl soundcorp-external #soundcorp iinet adsl2 static ip
O1 - Hosts: 203.94.148.130 fed-square-vpn fedsq-vpn #federation square management vpn link for rea.
O1 - Hosts: 203.171.113.131 clc-adelaide clc-adelaide-router clc-adelaide-adsl #adelaide courts aanet static cisco 1700
O1 - Hosts: 220.240.240.229 transport_hotel #transport new. dsl-229.240.240.220.dsl.comindico.com.au
O1 - Hosts: 218.214.130.97 transport_hotel-old transport-hotel-old #swiftel adsl fixed ip mmserver:30315 player1..4 30316..9
O1 - Hosts: 203.94.148.130 federation-square-vpn fsm fedsquare
O1 - Hosts: 139.132.5.30 b_ga129_controlsys ga129b_controlsys
O1 - Hosts: 139.132.5.31 b_ga129_codec ga129_codec
O1 - Hosts: 139.132.5.32 b_lt01_controlsys lt01b_controlsys
O1 - Hosts: 139.132.5.34 b_lt03_controlsys lt03b_controlsys
O1 - Hosts: 139.132.5.24 b_lt04_controlsys lt04b_controlsys
O1 - Hosts: 139.132.5.25 b_lt04_codec lt04b_codec
O1 - Hosts: 139.132.5.26 b_lt05_controlsys lt05b_controlsys
O1 - Hosts: 139.132.5.27 b_lt05_codec lt05b_codec
O1 - Hosts: 139.132.5.20 b_lt09_controlsys lt09b_controlsys
O1 - Hosts: 139.132.5.21 b_lt09_codec lt09b_codec
O1 - Hosts: 139.132.5.37 b_lt11_controlsys lt11b_controlsys
O1 - Hosts: 139.132.5.36 b_lt11_codec lt11b_codec
O1 - Hosts: 139.132.5.22 b_m107_controlsys m107b_controlsys
O1 - Hosts: 139.132.5.23 b_m107_codec m107b_codec
O1 - Hosts: 128.184.5.26 g_lt01_controlsys lt01g_controlsys
O1 - Hosts: 128.184.5.34 g_sb427_controlsys sb427g_controlsys
O1 - Hosts: 128.184.5.36 g_sb429_controlsys sb429g_controlsys
O1 - Hosts: 128.184.5.28 g_sc422_controlsys sc422g_controlsys
O1 - Hosts: 128.184.5.30 g_sc424_controlsys sc424g_controlsys
O1 - Hosts: 128.184.5.32 g_sc426_controlsys sc426g_controlsys
O1 - Hosts: 128.184.5.22 g_sd464_controlsys sd464g_controlsys
O1 - Hosts: 128.184.5.23 g_sd464_codec sd464g_codec
O1 - Hosts: 128.184.5.20 g_ub1604_controlsys ub1604g_controlsys
O1 - Hosts: 128.184.5.21 g_ub1604_codec ub1604g_codec
O1 - Hosts: 128.184.5.25 g_test_codec
O1 - Hosts: 128.184.147.26 s_d2218_controlsys d2218f_controlsys
O1 - Hosts: 128.184.147.21 s_d2218_codec d2218f_codec
O1 - Hosts: 128.184.147.255? s_d2218_tp d2218f_tp
O1 - Hosts: 128.184.147.20 s_d4108_controlsys d4108f_controlsys
O1 - Hosts: 128.184.147.x s_d4108_codec d4108f_codec
O1 - Hosts: 128.184.110.22 w_b303_controlsys b303w_controlsys
O1 - Hosts: 128.184.110.23 w_b303_codec b303w_codec
O1 - Hosts: 128.184.110.20 w_j222_controlsys j222w_controlsys
O1 - Hosts: 128.184.110.21 w_j222_codec j222w_codec
O1 - Hosts: 139.168.14.99 davidthome #dt bigpond adsl service
O1 - Hosts: 66.102.7.104 www.google.com #redirect to rea homepage for interest!
O1 - Hosts: 64.233.167.9 www.google.com #redirect to rea homepage for interest!
O1 - Hosts: 61.213.147.96 www.yahoo.com #red au.search.yahoo.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [VetTray] C:\Vet\VetTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1159490438546
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - C:\WINDOWS\system32\gwquvw.dll
O21 - SSODL: DCOM Server 3339 - {2C1CD3D7-86AC-4068-93BC-A02304BB3339} - C:\WINDOWS\system32\ruxc.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\Shared\hpqwmi.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
Hello mantissa and Welcome to TomCoyote,

Please do the following:

Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

[external image: Posted Image]

______________________________

Please download the trial version of AVG anti-spyware 7.5from here:
http://www.ewido.net/en/download/
  • Install AVG anti-spyware anti-malware.
  • When installing, under Additional Options uncheck Install background guard and Install scan via context menu.
  • When you run AVG anti-spyware for the first time, you could get a warning "Database could not be found!". Click Ok.
  • The program will prompt you to update. Click the Ok button.
  • The program will now go to the main screen.
You will need to update AVG anti-spyware to the latest definition files.
  • On the left-hand side of the main screen click the Update Button.
  • Click on Start.
The update will start and a progress bar will show the updates being installed.
Once finished updating, close AVG.

If you are having problems with the updater, you can use this link to manually update ewido.
AVG anti-spyware manual updates. Make sure to close AVG anti-spyware before installing the update.
______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter

[external image: Posted Image]

This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.


IMPORTANT: Do NOT run any other options until you are asked to do so!

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

Please post:
C:\rapport.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI