Hello Noviciate,
I have completed the steps as listed in your last reply with the exception of a glitch in step 5. I was not able to delete a file named ~DF83E5.tmp from one of the users temp folders. The reason given was the file was being used by another person or program. The system seems to be running well and so far my browser has not been hijacked and no virus warnings have popped up. The files you requested are copied below. I am greatful for your help with this. Please let me know if there is anything else I need to do.
Cheers!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:24:00 PM, on 4/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.liv...m/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://messenger.zon...ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab56907.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
--
End of file - 6262 bytes
Malwarebytes' Anti-Malware 1.10
Database version: 586
Scan type: Full Scan (C:\|)
Objects scanned: 65239
Time elapsed: 24 minute(s), 37 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 20
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 48
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{14e6d991-db22-4661-981d-20c168d6847b} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2242513c-f5e9-41b3-bc89-4d9daf487450} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3b489b37-fc1b-45c8-b1ce-78d9aef5b336} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3d6a6e24-fdff-418e-a93d-9fbdcba377af} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e318e44-0c35-4292-af91-18dd17795636} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{495349a3-3a35-465f-88df-6ccfc1348246} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{575e8879-d6cf-4992-a7fe-651da9277bcb} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{76a15001-ff88-47ee-9e34-9f68e34246af} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{819a1c55-735f-4696-8727-3772ec87ad26} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{8dc7e656-ffbc-4ba2-af81-1c6c4fe04407} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a86bed71-2b56-4778-9c48-829a3d01c687} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{ae119e11-cf86-43cb-91aa-1acf2bbf9ec6} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b5a1ce7f-011d-4475-98db-076aaf3b1d18} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b667f141-171c-4ac6-bd2b-8e0c646fb920} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{da4f8351-05ef-4956-b9ab-1093b732436f} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e1e4e46d-53b8-45dc-abf0-3e7adef79012} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{83b0cadc-ea64-4ac6-822a-3ece95f44da6} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\E404.e404mgr (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\videoPl.chl (Trojan.Zlob) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Program Files\Trend Micro\HijackThis\backups\backup-20080328-211521-944.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009127.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009128.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009129.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009140.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009141.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009142.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009150.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009151.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009152.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009158.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009159.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009160.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009166.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009167.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009168.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009290.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009291.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009292.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009300.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009301.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009302.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009328.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009329.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009330.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009382.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009386.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009387.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009388.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009422.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009423.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP67\A0009424.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009442.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009443.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009444.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009449.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009450.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009451.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009456.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009461.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009462.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009463.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009464.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009465.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009466.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009467.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009469.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{58E946B3-F8B3-45DC-9C18-008C7978C691}\RP68\A0009470.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
SmitFraudFix v2.309
Scan done at 19:20:02.97, Wed 04/02/2008
Run from C:\Documents and Settings\Natalia\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\system32\375013\ Deleted
C:\DOCUME~1\Natalia\STARTM~1\Programs\VirusHeat 4.3 Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
C:\DOCUME~1\Natalia\FAVORI~1\Online Security Test.url Deleted
C:\Program Files\NetProject\ Deleted
C:\Program Files\VirusHeat 4.3\ Deleted
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{6D1D0C24-624F-433D-BE88-BA4BB634E57D}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{6D1D0C24-624F-433D-BE88-BA4BB634E57D}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{6D1D0C24-624F-433D-BE88-BA4BB634E57D}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End