This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

need help with reacuring virus

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have system mechanic 6 which removes the icon from my system tray. But it still keeps coming back. Here is my HJT file. Logfile of HijackThis v1.99.1 Scan saved at 6:27:42 PM, on 1/23/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\ihopethisworks\Desktop\Hijackthis\HijackThis.exe C:\Program Files\Windows NT\Accessories\WORDPAD.EXE C:\PROGRA~1\iolo\SYSTEM~1\SysMech6.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1a1ddc19-5893-43ab-a73f-f41a0f34d115} - C:\Program Files\Video ActiveX Object\isaddon.dll (file missing) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: C:\WINDOWS\lbbho.dll - {FEAEC37F-AFAB-4193-8AB5-DB3FC0AE5687} - C:\WINDOWS\lbbho.dll (file missing) O3 - Toolbar: Protection Bar - {5d4831e0-5a7c-4a46-afd5-a79ab8ce36c2} - C:\Program Files\Video ActiveX Object\iesplugin.dll (file missing) O4 - HKLM\..\Run: [FSWebServer] C:\Program Files\Easy File Sharing Web Server\fsws.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\IHOPET~1\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe" O4 - Global Startup: Kaspersky Anti-Hacker.lnk = C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} (WMVHDRatingCtrl Class) - file://E:\components\wmvhdrating.ocx O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe I also ran and folowed the instructions for smitRem before i purchased system mechanic. i read a site that said it might be a trojan horse zlob, because the virus keeps putting a symbol in my task bar. The ballon said system may be infected. Heres the log for that. smitRem © log file version 3.2 by noahdfear Microsoft Windows XP [Version 5.1.2600] "IE"="6.0000" The current date is: Tue 12/26/2006 The current time is: 20:33:12.26 Running from C:\Documents and Settings\[removed]\Desktop\smitRem ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Pre-run SharedTask Export (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright© 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" "{3c767c6b-602d-4b9b-829d-a3dc5b2d89dd}"="haematobia" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3c767c6b-602d-4b9b-829d-a3dc5b2d89dd}\InProcServer32] @="C:\WINDOWS\system32\hjpprpu.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Appinitdll check …….. Thank you Grinler! dumphive.exe ©2000-2004 Markus Stephany REGEDIT4 [Windows] "AppInit_DLLs"="" "DeviceNotSelectedTimeout"="15" "GDIProcessHandleQuota"=dword:00002710 "Spooler"="yes" "swapdisk"="" "TransmissionRetryTimeout"="90" "USERProcessHandleQuota"=dword:00002710 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ XP Firewall allowed access Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\EbatesMoeMoneyMaker\\EbatesMoeMoneyMaker.exe"="C:\\Program Files\\EbatesMoeMoneyMaker\\EbatesMoeMoneyMaker.exe:*:Disabled:EbatesMoeMoneyMaker" "C:\\Program Files\\Warcraft III\\War3.exe"="C:\\Program Files\\Warcraft III\\War3.exe:*:Enabled:Warcraft III" "C:\\Program Files\\Warcraft III\\Warcraft III.exe"="C:\\Program Files\\Warcraft III\\Warcraft III.exe:*:Enabled:Warcraft III" "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\LMpdpsrv.exe"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\LMpdpsrv.exe:*:Enabled:PDP RPC Server" "C:\\Program Files\\THQ\\Dawn of War\\W40k.exe"="C:\\Program Files\\THQ\\Dawn of War\\W40k.exe:*:Enabled:W40K" "C:\\Program Files\\Ascaron Entertainment\\Sacred\\Sacred.exe"="C:\\Program Files\\Ascaron Entertainment\\Sacred\\Sacred.exe:*:Enabled:Sacred" "C:\\Program Files\\LucasArts\\Star Wars Battlefront\\GameData\\Battlefront.exe"="C:\\Program Files\\LucasArts\\Star Wars Battlefront\\GameData\\Battlefront.exe:*:Enabled:Battlefront" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ checking for ShudderLTD key ShudderLTD key not present! checking for PSGuard.com key PSGuard.com key not present! checking for WinHound.com key WinHound.com key not present! checking for drsmartload2 key drsmartload2 key not present! spyaxe uninstaller NOT present Winhound uninstaller NOT present SpywareStrike uninstaller NOT present AlfaCleaner uninstaller NOT present SpyFalcon uninstaller NOT present SpywareQuake uninstaller NOT present SpywareSheriff uninstaller NOT present Trust Cleaner uninstaller NOT present SpyHeal uninstaller NOT present VirusBurst uninstaller NOT present BraveSentry uninstaller NOT present AntiVermins uninstaller NOT present VirusBursters uninstaller NOT present ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Existing Pre-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ Online Security Guide.url Security Troubleshooting.url ~~~ Favorites ~~~ ~~~ system32 folder ~~~ amcompat.tlb nscompat.tlb logfiles ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright© 2002-2003 [removed] Killing PID 1724 'explorer.exe' Starting registry repairs Registry repairs complete ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SharedTask Export after registry fix (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright© 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" "{3c767c6b-602d-4b9b-829d-a3dc5b2d89dd}"="haematobia" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\system32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3c767c6b-602d-4b9b-829d-a3dc5b2d89dd}\InProcServer32] @="C:\WINDOWS\system32\hjpprpu.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Deleting files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Remaining Post-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ logfiles ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~ Wininet.dll ~~~ CLEAN! :) After reading the posts on this site i realize i should of posted hjt then find out if I had to run smitrem. I was wondering if system mechanic was missing something. I also have krenskys viras scan that i run but it says that it hasn't found anything. Any info on this would be greatly appreciated.
dgimse :D

Welcome to Tom Coyote . Sorry about the delay in responding but we are as most times just overwhelmed with logs.

Did you by chance run HJT in Safemode?? If you did, after you run Option 1 for Smitfraud, run HJT in normal windows and post a new log .



Please download SmitfraudFix
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.



Let me see the Smitfraud log and a new HJT log please
well when i first ran smitRem i didn't run HJT. But I went a head and ran Hjt in safe mode recently. Please let me know if ya want to see that log. Here is the rapport from SmitFraudfix. I did not run this in safe mode either. The smitfraud brings me too the antivermins website if I click it. Also I would like to thank you for looking at my post. SmitFraudFix v2.137 Scan done at 14:16:33.59, Wed 01/31/2007 Run from C:\Documents and Settings\ihopethisworks\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\hjpprpu.dll FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\ihopethisworks »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\ihopethisworks\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\IHOPET~1\FAVORI~1 C:\DOCUME~1\IHOPET~1\FAVORI~1\Online Security Test.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files C:\Program Files\Video ActiveX Object\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{3c767c6b-602d-4b9b-829d-a3dc5b2d89dd}"="haematobia" [HKEY_CLASSES_ROOT\CLSID\{3c767c6b-602d-4b9b-829d-a3dc5b2d89dd}\InProcServer32] @="C:\WINDOWS\system32\hjpprpu.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3c767c6b-602d-4b9b-829d-a3dc5b2d89dd}\InProcServer32] @="C:\WINDOWS\system32\hjpprpu.dll" »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End I also ran the Hjt file again in normal mode. Heres that log file Logfile of HijackThis v1.99.1 Scan saved at 2:33:23 PM, on 1/31/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\WINDOWS\notepad.exe C:\Documents and Settings\ihopethisworks\Desktop\Hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1a1ddc19-5893-43ab-a73f-f41a0f34d115} - C:\Program Files\Video ActiveX Object\isaddon.dll (file missing) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: C:\WINDOWS\lbbho.dll - {FEAEC37F-AFAB-4193-8AB5-DB3FC0AE5687} - C:\WINDOWS\lbbho.dll (file missing) O3 - Toolbar: Protection Bar - {5d4831e0-5a7c-4a46-afd5-a79ab8ce36c2} - C:\Program Files\Video ActiveX Object\iesplugin.dll (file missing) O4 - HKLM\..\Run: [FSWebServer] C:\Program Files\Easy File Sharing Web Server\fsws.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\IHOPET~1\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe" O4 - Global Startup: Kaspersky Anti-Hacker.lnk = C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} (WMVHDRatingCtrl Class) - file://E:\components\wmvhdrating.ocx O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe Any suggestions would be greatly appreciated.
dgimse, :D

You always run HJT in normal windows or else it does not show everything. You are infected with Smitfraud, it looks like you may have downloaded a bogus codec.



We need to make sure all hidden files are showing :
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide file extensions for known types option.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Once your system is clean, we suggest that you reverse this to keep critical windows files from accidently being deleted.




Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O2 - BHO: (no name) - {1a1ddc19-5893-43ab-a73f-f41a0f34d115} - C:\Program Files\Video ActiveX Object\isaddon.dll (file missing)
O2 - BHO: C:\WINDOWS\lbbho.dll - {FEAEC37F-AFAB-4193-8AB5-DB3FC0AE5687} - C:\WINDOWS\lbbho.dll (file missing)
O3 - Toolbar: Protection Bar - {5d4831e0-5a7c-4a46-afd5-a79ab8ce36c2} - C:\Program Files\Video ActiveX Object\iesplugin.dll (file missing)

O16 - DPF: {7030CC6C-1A88-4591-BB5A-651B9F7F0C30} (WMVHDRatingCtrl Class) - file://E:\components\wmvhdrating.ocx




Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run Ewido and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.
Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode

  • Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
  • Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.
  • You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.
  • The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".
  • The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart into normal Windows.
  • A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt



Still in Safemode, make sure these are gone, delete them if still present.

C:\Program Files\Video ActiveX Object
C:\WINDOWS\lbbho.dll


Do this is in Safemode also
Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start> Control Panel and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete Offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button.
  • Click Apply then OK.





  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • Ewido will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5
IMPORTANT: Do not open any other windows or programs while AVG is scanning, it may interfere with the scanning process:


Reboot normally.
  • Open the SmitfraudFix folder and double-click smitfraudfix.cmd
  • Select option #3 - Delete Trusted zone by typing 3 and press Enter
  • Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter.
Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.

Post the log from Smitfraud fix, the AVG Spyware log and a New HJT log please
here is my avg scan file report. ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 3:32:15 AM 2/1/2007 + Scan result: HKU\S-1-5-21-1606980848-1563985344-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A1DDC19-5893-43AB-A73F-F41A0F34D115} -> Adware.Generic : Cleaned with backup (quarantined). HKU\S-1-5-21-1606980848-1563985344-1343024091-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2} -> Adware.Generic : Cleaned with backup (quarantined). HKU\.DEFAULT\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined). HKU\S-1-5-18\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\Documents and Settings\ihopethisworks\Application Data\errorsafenewreleaseinstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined). :mozilla.19:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.19:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{ABCF050C-EDAE-4B80-9F26-9554BC878539}\{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt/{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.20:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{ABCF050C-EDAE-4B80-9F26-9554BC878539}\{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt/{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.41:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{E786C734-4453-44A3-B355-04028D5A7E22}\{0397848B-E9FD-4831-8463-782266455555}.txt/{0397848B-E9FD-4831-8463-782266455555}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.48:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.49:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.50:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.2o7 : Error during cleaning. :mozilla.80:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{0002C2FE-5B5C-49A8-81E3-9EE72204DFFA}.txt/{0002C2FE-5B5C-49A8-81E3-9EE72204DFFA}.txt -> TrackingCookie.2o7 : Cleaned. C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{643FF24B-2834-48A3-B4D5-83D05A9B6C04}.txt/{643FF24B-2834-48A3-B4D5-83D05A9B6C04}.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.38:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.39:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.40:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.13:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.Adrevolver : Error during cleaning. :mozilla.15:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.Adrevolver : Error during cleaning. :mozilla.16:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.Adrevolver : Error during cleaning. :mozilla.17:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.Adrevolver : Error during cleaning. :mozilla.18:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.Adrevolver : Error during cleaning. :mozilla.19:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.Adrevolver : Error during cleaning. :mozilla.84:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.85:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.86:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.87:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.88:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.89:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.85:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Advertising : Error during cleaning. :mozilla.86:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Advertising : Error during cleaning. :mozilla.87:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Advertising : Error during cleaning. :mozilla.110:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Atdmt : Error during cleaning. :mozilla.18:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.24:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.Atdmt : Error during cleaning. :mozilla.48:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{E786C734-4453-44A3-B355-04028D5A7E22}\{0397848B-E9FD-4831-8463-782266455555}.txt/{0397848B-E9FD-4831-8463-782266455555}.txt -> TrackingCookie.Atdmt : Error during cleaning. :mozilla.49:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{ABCF050C-EDAE-4B80-9F26-9554BC878539}\{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt/{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt -> TrackingCookie.Atdmt : Error during cleaning. C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{AB1CF3B6-A1C0-4731-BE07-0AF61115369F}.txt/{AB1CF3B6-A1C0-4731-BE07-0AF61115369F}.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.96:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned. :mozilla.52:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Com : Error during cleaning. :mozilla.10:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Doubleclick : Error during cleaning. :mozilla.18:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{ABCF050C-EDAE-4B80-9F26-9554BC878539}\{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt/{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt -> TrackingCookie.Doubleclick : Error during cleaning. :mozilla.20:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.Doubleclick : Error during cleaning. :mozilla.30:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{E786C734-4453-44A3-B355-04028D5A7E22}\{0397848B-E9FD-4831-8463-782266455555}.txt/{0397848B-E9FD-4831-8463-782266455555}.txt -> TrackingCookie.Doubleclick : Error during cleaning. :mozilla.46:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.54:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.62:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.89:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Googleadservices : Error during cleaning. :mozilla.93:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Googleadservices : Error during cleaning. :mozilla.97:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.83:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Information : Error during cleaning. :mozilla.14:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{E786C734-4453-44A3-B355-04028D5A7E22}\{0397848B-E9FD-4831-8463-782266455555}.txt/{0397848B-E9FD-4831-8463-782266455555}.txt -> TrackingCookie.Liveperson : Error during cleaning. :mozilla.15:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{E786C734-4453-44A3-B355-04028D5A7E22}\{0397848B-E9FD-4831-8463-782266455555}.txt/{0397848B-E9FD-4831-8463-782266455555}.txt -> TrackingCookie.Liveperson : Error during cleaning. :mozilla.16:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{E786C734-4453-44A3-B355-04028D5A7E22}\{0397848B-E9FD-4831-8463-782266455555}.txt/{0397848B-E9FD-4831-8463-782266455555}.txt -> TrackingCookie.Liveperson : Error during cleaning. :mozilla.17:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{E786C734-4453-44A3-B355-04028D5A7E22}\{0397848B-E9FD-4831-8463-782266455555}.txt/{0397848B-E9FD-4831-8463-782266455555}.txt -> TrackingCookie.Liveperson : Error during cleaning. :mozilla.39:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{ABCF050C-EDAE-4B80-9F26-9554BC878539}\{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt/{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt -> TrackingCookie.Liveperson : Error during cleaning. :mozilla.40:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{ABCF050C-EDAE-4B80-9F26-9554BC878539}\{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt/{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt -> TrackingCookie.Liveperson : Error during cleaning. :mozilla.41:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{ABCF050C-EDAE-4B80-9F26-9554BC878539}\{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt/{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt -> TrackingCookie.Liveperson : Error during cleaning. :mozilla.42:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{ABCF050C-EDAE-4B80-9F26-9554BC878539}\{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt/{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt -> TrackingCookie.Liveperson : Error during cleaning. :mozilla.46:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{E786C734-4453-44A3-B355-04028D5A7E22}\{0397848B-E9FD-4831-8463-782266455555}.txt/{0397848B-E9FD-4831-8463-782266455555}.txt -> TrackingCookie.Mediaplex : Error during cleaning. :mozilla.47:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{ABCF050C-EDAE-4B80-9F26-9554BC878539}\{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt/{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt -> TrackingCookie.Mediaplex : Error during cleaning. :mozilla.47:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{E786C734-4453-44A3-B355-04028D5A7E22}\{0397848B-E9FD-4831-8463-782266455555}.txt/{0397848B-E9FD-4831-8463-782266455555}.txt -> TrackingCookie.Mediaplex : Error during cleaning. :mozilla.48:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{ABCF050C-EDAE-4B80-9F26-9554BC878539}\{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt/{E99FF860-6DD2-4ABF-AFA1-575AE17FD13E}.txt -> TrackingCookie.Mediaplex : Error during cleaning. :mozilla.57:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.Mediaplex : Error during cleaning. :mozilla.58:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.Mediaplex : Error during cleaning. :mozilla.93:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.68:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.69:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Overture : Cleaned. C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{907D2816-1BF4-4961-A91B-8BCA5F18BEF6}.txt/{907D2816-1BF4-4961-A91B-8BCA5F18BEF6}.txt -> TrackingCookie.Overture : Cleaned. :mozilla.11:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Questionmarket : Error during cleaning. :mozilla.94:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.95:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.80:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Revenue : Error during cleaning. :mozilla.24:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.25:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Sextracker : Error during cleaning. :mozilla.68:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Statcounter : Error during cleaning. :mozilla.69:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Statcounter : Error during cleaning. :mozilla.11:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.Yieldmanager : Error during cleaning. :mozilla.12:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.Yieldmanager : Error during cleaning. :mozilla.21:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{93940653-BFBD-411B-A85B-F5B611893765}\{A584AD11-CD60-42E5-9F2E-206986272924}.txt/{A584AD11-CD60-42E5-9F2E-206986272924}.txt -> TrackingCookie.Yieldmanager : Error during cleaning. :mozilla.33:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.34:C:\Documents and Settings\ihopethisworks\Application Data\Mozilla\Firefox\Profiles\6v9vannr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.81:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Yieldmanager : Error during cleaning. :mozilla.82:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Yieldmanager : Error during cleaning. :mozilla.56:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Zedo : Error during cleaning. :mozilla.57:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Zedo : Error during cleaning. :mozilla.58:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Zedo : Error during cleaning. :mozilla.59:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Zedo : Error during cleaning. :mozilla.60:C:\Program Files\iolo\System Mechanic Professional 6\Undo\Manual\{32918665-DE17-49FA-AA06-D440D5AF4A73}\{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt/{E686B1DE-EEFB-4C46-A02B-B4A1445AB8AA}.txt -> TrackingCookie.Zedo : Error during cleaning. C:\System Volume Information\_restore{BCB25946-1ED3-4DC9-BB9C-FE8EE0CDE9B1}\RP261\A0117607.dll -> Trojan.FakeAlert.an : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BCB25946-1ED3-4DC9-BB9C-FE8EE0CDE9B1}\RP261\A0119711.dll -> Trojan.FakeAlert.an : Cleaned with backup (quarantined). C:\System Volume Information\_restore{BCB25946-1ED3-4DC9-BB9C-FE8EE0CDE9B1}\RP262\A0121218.dll -> Trojan.FakeAlert.an : Cleaned with backup (quarantined). ::Report end and this is smitfraudfix rapport SmitFraudFix v2.137 Scan done at 19:36:39.56, Wed 01/31/2007 Run from C:\Documents and Settings\ihopethisworks\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{3c767c6b-602d-4b9b-829d-a3dc5b2d89dd}"="haematobia" [HKEY_CLASSES_ROOT\CLSID\{3c767c6b-602d-4b9b-829d-a3dc5b2d89dd}\InProcServer32] @="C:\WINDOWS\system32\hjpprpu.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3c767c6b-602d-4b9b-829d-a3dc5b2d89dd}\InProcServer32] @="C:\WINDOWS\system32\hjpprpu.dll" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\DOCUME~1\IHOPET~1\FAVORI~1\Online Security Test.url Deleted C:\Program Files\Video ActiveX Object\ Deleted »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End and my new hjt log Logfile of HijackThis v1.99.1 Scan saved at 4:00:12 PM, on 2/1/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Documents and Settings\ihopethisworks\Desktop\Hijackthis\HijackThis.exe F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O4 - HKLM\..\Run: [FSWebServer] C:\Program Files\Easy File Sharing Web Server\fsws.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\RunOnce: [DELDIR0.EXE] "C:\DOCUME~1\IHOPET~1\LOCALS~1\Temp\DELDIR0.EXE" "C:\Program Files\McAfee\McAfee Shared Components\Guardian\" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe" O4 - Global Startup: Kaspersky Anti-Hacker.lnk = C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe I'm not sure why avg spyware remover had errors removing some of the stuff. But i did run it in safe mode.
System Mechanic may have prevented some of the entries from being removed.

Your log looks good :thumbup: The bad codec that caused you to be infected with Smitfraud is gone :thumbup:


You can right click on System Mechanic in the system tray and disable it and then run this cleaner.

If you don't want the Yahoo Toolbar, be sure to uncheck it during installation
Download and Install CCleaner
* Click on Run Cleaner
* Run the Issues Scan < – After it scans your system, when you click on the Fix button and it asks you to backup the Registry..Say Yes
Tutorial for CCleaner



How are things running now?
well i ran ccleaner and the system seems to be running fine but more importantly is that smitfraud is gone. I was wondering about system mechanic ver. 6. will it quarintine risk and bad files like spybot does? Are quarintine files from a security application bad if I uninstall that same security application. Should I continue to run system mechanic in the background or find another security application that does that. anywho thank you so much, great advice :lol: :lol:
dgimse :D

I have never used System Mechanic so I really can't tell you much about it. I am including some free tools for you to install to help keep you more secure. Myself, my system is running like a top and I have never had much use for those type of programs.


How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • Tom Coyote
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • Geeks To Go
  • Dslreports



Here are some free programs to install, don't leave home without them
  • Spybot Search and Destroy 1.4
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.
  • Ad-Aware SE Personal 1.06
    Check for Updates and run a Full System Scan on a regular basis.
  • Spyware Blaster It will prevent most spyware from ever being installed.
  • Spyware Guard It offers realtime protection from spyware installation attempts.
  • Win Patrol This program will warn you when any changes are being made to your system and give you the option to deny the change.
  • IE-Spyad
    IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 2.0 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
  • Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.
Thanks for stopping by Tom Coyote , I'm glad I was able to help you. :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI