This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Tried a lot of things need help

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I tried all the posted remedies for the task manager not working it always reverts to disabled in registry have desktop background with "warning! spyware" contuniuos bubble on task bar your infected and IE closes after 2 seconds I have read all the self help and followed all instructions. I am at the point of the smitfraud removal so I followed the instruction and I am posting smitfraud report and hijackthis log I appreciate any help Smitfraud Report SmitFraudFix v2.263 Scan done at 9:47:04.12, Wed 12/12/2007 Run from C:\Documents and Settings\Lori\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\WINDOWS\system32\PSIService.exe C:\WINDOWS\system32\wdfmgr.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\system32\lpcywinp.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\regsvr32.exe C:\PROGRA~1\PESTPA~1\PPControl.exe C:\PROGRA~1\PESTPA~1\PPMemCheck.exe C:\PROGRA~1\PESTPA~1\CookiePatrol.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Dell Photo Printer 720\dlbcserv.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\CSCRIPT.EXE C:\WINDOWS\system32\wbem\wmiprvse.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\ace16win.dll FOUND ! C:\WINDOWS\system32\msole32.exe FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Lori »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Lori\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Lori\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" "LoadAppInit_DLLs"=dword:00000001 »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Intel® PRO/100 VE Network Connection - Packet Scheduler Miniport DNS Server Search Order: 24.92.226.9 DNS Server Search Order: 24.92.226.102 DNS Server Search Order: 24.92.226.9 DNS Server Search Order: 24.92.226.102 HKLM\SYSTEM\CCS\Services\Tcpip\..\{251173F2-C84B-44AB-AC2F-85843584D04F}: DhcpNameServer=[removed] [removed] [removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{251173F2-C84B-44AB-AC2F-85843584D04F}: DhcpNameServer=[removed] [removed] [removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\..\{251173F2-C84B-44AB-AC2F-85843584D04F}: DhcpNameServer=[removed] [removed] [removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End Hijackthis log Logfile of HijackThis v1.99.1 Scan saved at 9:49:29 AM, on 12/12/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\WINDOWS\system32\PSIService.exe C:\WINDOWS\system32\wdfmgr.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\system32\lpcywinp.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\regsvr32.exe C:\PROGRA~1\PESTPA~1\PPControl.exe C:\PROGRA~1\PESTPA~1\P
Here is the final smitfraud raport after safe mode SDFix: Version 1.118 Run by [removed] on Wed 12/12/2007 at 10:11 AM Microsoft Windows XP [Version 5.1.2600] Running From: C:\DOCUME~1\Lori\Desktop\smit\SDFix Safe Mode: Checking Services: Restoring Windows Registry Values Restoring Windows Default Hosts File Restoring Missing Security Center Service Restoring Missing SharedAccess Service Rebooting… Normal Mode: Checking Files: Trojan Files Found: C:\15F.TMP - Deleted C:\160.TMP - Deleted C:\161.TMP - Deleted C:\165.TMP - Deleted C:\26.TMP - Deleted C:\27.TMP - Deleted C:\28.TMP - Deleted C:\29.TMP - Deleted C:\8.TMP - Deleted C:\8A.TMP - Deleted C:\8B.TMP - Deleted C:\8C.TMP - Deleted C:\8D.TMP - Deleted C:\9.TMP - Deleted C:\A.TMP - Deleted C:\B.TMP - Deleted C:\PROGRA~1\PAGE~1.HTM - Deleted C:\Program Files\Insider\Insider.exe - Deleted C:\Program Files\Insider\UnInstall.exe - Deleted C:\Program Files\Words\list.txt - Deleted C:\Program Files\Words\script.txt - Deleted C:\Program Files\Words\UnInstall.exe - Deleted C:\A.tmp - Deleted C:\WINDOWS\system32\rasqervy.dll - Deleted C:\WINDOWS\system32\sdfinacs.dll - Deleted C:\WINDOWS\system32\sdfixwcs.dll - Deleted C:\WINDOWS\system32\wuasirvy.dll - Deleted Folder C:\Documents and Settings\All Users\Documents\Settings - Removed Folder C:\Program Files\Insider - Removed Folder C:\Program Files\Temporary - Removed Folder C:\Program Files\WinAble - Removed Folder C:\Program Files\Words - Removed Removing Temp Files… ADS Check: C:\WINDOWS No streams found. C:\WINDOWS\system32 No streams found. C:\WINDOWS\system32\svchost.exe No streams found. C:\WINDOWS\system32\ntoskrnl.exe No streams found. Final Check: disk not found C:\ please note that you need administrator rights to perform deep scan Remaining Services: —————— Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" Remaining Files: ————— File Backups: - C:\DOCUME~1\Lori\Desktop\smit\SDFix\backups\backups.zip Files with Hidden Attributes: Wed 1 Sep 2004 54,384 A..H. — "C:\Program Files\America Online 9.0\aolphx.exe" Wed 1 Sep 2004 156,784 A..H. — "C:\Program Files\America Online 9.0\aoltray.exe" Wed 1 Sep 2004 31,344 A..H. — "C:\Program Files\America Online 9.0\RBM.exe" Thu 6 Sep 2007 88 ..SHR — "C:\WINDOWS\SYSTEM32\3049FD6999.sys" Thu 6 Sep 2007 3,350 A.SH. — "C:\WINDOWS\SYSTEM32\KGyGaAvL.sys" Tue 26 Jul 2005 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Sun 11 Nov 2007 489 A..H. — "C:\Program Files\InterActual\InterActual Player\iti7D.tmp" Mon 10 Dec 2007 14,050 A.SH. — "C:\Documents and Settings\Mike\Local Settings\Temp\ivnFFE5.tmp" Finished!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI