PDA

View Full Version : SmitFraud problem



CliveG
2007-02-22, 12:28
Hi,
I have a WIN98 system that appears to be infected by this issue. As with all of the other threads I cannot seem to remove it. Can I be saved!!:sad:

Shaba
2007-02-23, 10:01
Hi CliveG

Use this (http://downloads.malwareremoval.com/hijackthis_sfx.exe) link to get HijackThis.
Save it to your desktop and then double-click to run it.
It will install the program in c:\program files\HijackThis.
Browse to that location with windows explorer, and double click on the HijackThis.exe program to run. Choose the 'Do a system scan and save a logfile'
That will allow you to save the log to the desktop (or some other place) and leave open a notepad file with the HijackThis log in it.

Now post your HijackThis log into this topic.

CliveG
2007-02-23, 12:25
Logfile of HijackThis v1.99.1
Scan saved at 11:22:17, on 23/02/07
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\D-LINK\AIRPLUS XTREME G\AIRPLUSCFG.EXE
C:\PROGRAM FILES\ALPHA NETWORKS\ANIWZCS SERVICE\WZCSLDR.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\ADAT\USERINIT.EXE
C:\PROGRAM FILES\COMMON FILES\EUEH\RNQNGEJY.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\CLIVE\HIJACKTHIS\HJT.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.axlquotes.com/axl-dlls/publish?url=/entrance.shtml&page1=hotview
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.axlquotes.com/axl-dlls/publish?url=/entrance.shtml&page1=hotview
F1 - win.ini: run=hpfsched
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {F018CD1E-5AA5-7E5D-DB4B-5B9099D069C6} - blank (file missing)
O2 - BHO: (no name) - {F61CC34C-06A5-7209-DB4B-5B9099D06CC6} - blank (file missing)
O2 - BHO: (no name) - {A64ECD1B-06A6-7259-DB4B-5B9099D06C9F} - blank (file missing)
O2 - BHO: (no name) - {A04ECC48-5BA8-7201-DB4B-5B9099D13AC6} - blank (file missing)
O2 - BHO: (no name) - {F74CC348-07A4-7E0D-DB4B-5B9099D138C9} - (no file)
O2 - BHO: (no name) - {021E2CF4-D34F-4C9C-8338-51BBB4E690F3} - C:\WINDOWS\SYSTEM\DDCAXUR.DLL
O2 - BHO: (no name) - {04FA0B79-DA7F-84CC-8E00-0A8A57B64FAD} - C:\WINDOWS\SYSTEM\TTRGMXC.DLL
O2 - BHO: (no name) - {AB45C91E-07A3-2F0F-DB4B-5B9099D13F9B} - C:\WINDOWS\SYSTEM\NHYLJ.DLL (file missing)
O2 - BHO: (no name) - {DD61DC80-C1D3-11DB-B219-000F3DADFAEA} - C:\WINDOWS\SYSTEM\RQONN.DLL
O2 - BHO: (no name) - {C16A776D-EBDB-CD74-F1D9-B2DEBDB30AC0} - C:\WINDOWS\SYSTEM\SAUX.DLL (file missing)
O2 - BHO: (no name) - {68919920-C31A-11DB-B219-000F3DADFAEA} - C:\WINDOWS\SYSTEM\XXYAA.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [D-Link AirPlus Xtreme G] C:\PROGRAM FILES\D-LINK\AIRPLUS XTREME G\AIRPLUSCFG.EXE
O4 - HKLM\..\Run: [ANIWZCSService] C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\SYSTEM\E_S4I0K2.EXE /P24 "EPSON Stylus Photo RX500" /O7 "EPUSB1:" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [WINXTX32] rundll32 WINXTX32.DLL,run
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NPFMonitor] C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O4 - HKLM\..\RunServices: [ALU Scheduler Service] C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - HKCU\..\Run: [Aubs] "C:\WINDOWS\adat\userinit.exe" -vt yazb
O4 - HKCU\..\Run: [Mjcchxm] C:\Program Files\Common Files\Eueh\rnqngejy.exe
O4 - Startup: BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe
O4 - Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} - http://www.thepaymentcentre.com/build/preload.cab
O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} - http://pictures02.aol.co.uk/ygp/aol/plugin/download/YGPPicDownload.en-UK.9.1.6.18.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-12.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.bigfishgames.com/online/feedingfrenzy/Game/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.bigfishgames.com/online/ricochetlostworlds/ReflexiveWebGameLoader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by122fd.bay122.hotmail.msn.com/activex/HMAtchmt.ocx

Shaba
2007-02-23, 12:31
Hi

Open HijackThis, click do a system scan only and checkmark these:

O2 - BHO: (no name) - {F018CD1E-5AA5-7E5D-DB4B-5B9099D069C6} - blank (file missing)
O2 - BHO: (no name) - {F61CC34C-06A5-7209-DB4B-5B9099D06CC6} - blank (file missing)
O2 - BHO: (no name) - {A64ECD1B-06A6-7259-DB4B-5B9099D06C9F} - blank (file missing)
O2 - BHO: (no name) - {A04ECC48-5BA8-7201-DB4B-5B9099D13AC6} - blank (file missing)
O2 - BHO: (no name) - {F74CC348-07A4-7E0D-DB4B-5B9099D138C9} - (no file)
O2 - BHO: (no name) - {021E2CF4-D34F-4C9C-8338-51BBB4E690F3} - C:\WINDOWS\SYSTEM\DDCAXUR.DLL
O2 - BHO: (no name) - {04FA0B79-DA7F-84CC-8E00-0A8A57B64FAD} - C:\WINDOWS\SYSTEM\TTRGMXC.DLL
O2 - BHO: (no name) - {AB45C91E-07A3-2F0F-DB4B-5B9099D13F9B} - C:\WINDOWS\SYSTEM\NHYLJ.DLL (file missing)
O2 - BHO: (no name) - {DD61DC80-C1D3-11DB-B219-000F3DADFAEA} - C:\WINDOWS\SYSTEM\RQONN.DLL
O2 - BHO: (no name) - {C16A776D-EBDB-CD74-F1D9-B2DEBDB30AC0} - C:\WINDOWS\SYSTEM\SAUX.DLL (file missing)
O2 - BHO: (no name) - {68919920-C31A-11DB-B219-000F3DADFAEA} - C:\WINDOWS\SYSTEM\XXYAA.DLL
O4 - HKLM\..\Run: [WINXTX32] rundll32 WINXTX32.DLL,run
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

Close all windows including browser and press fix checked.

Look in your control panels add/remove programs for PuritySCAN By OIN, OuterInfo, OIN or similar , click on it and click remove.

If not listed, download and run this uninstaller:
Uninstaller (http://www.outerinfo.com/OiUninstaller.exe)

Tutorial for the uninstaller if needed (http://www.outerinfo.com/howto.html)

Reboot

Post a fresh HJT log.

CliveG
2007-02-23, 12:57
Hi Shaba,

I cannot seem to be able to connect to the internet with my browser now. Have to use my work laptop :sad:

CliveG
2007-02-23, 13:05
Hi Shaba,
After another reboot, things got better! Here is the HJT log after completing your last post
Logfile of HijackThis v1.99.1
Scan saved at 11:52:31, on 23/02/07
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\D-LINK\AIRPLUS XTREME G\AIRPLUSCFG.EXE
C:\PROGRAM FILES\ALPHA NETWORKS\ANIWZCS SERVICE\WZCSLDR.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\CLIVE\HIJACKTHIS\HJT.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.axlquotes.com/axl-dlls/publish?url=/entrance.shtml&page1=hotview
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.axlquotes.com/axl-dlls/publish?url=/entrance.shtml&page1=hotview
F1 - win.ini: run=hpfsched
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [D-Link AirPlus Xtreme G] C:\PROGRAM FILES\D-LINK\AIRPLUS XTREME G\AIRPLUSCFG.EXE
O4 - HKLM\..\Run: [ANIWZCSService] C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\SYSTEM\E_S4I0K2.EXE /P24 "EPSON Stylus Photo RX500" /O7 "EPUSB1:" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [WINXTX32] rundll32 WINXTX32.DLL,run
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NPFMonitor] C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O4 - HKLM\..\RunServices: [ALU Scheduler Service] C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - HKCU\..\Run: [Aubs] "C:\WINDOWS\adat\userinit.exe" -vt yazb
O4 - Startup: BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe
O4 - Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} - http://www.thepaymentcentre.com/build/preload.cab
O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} - http://pictures02.aol.co.uk/ygp/aol/plugin/download/YGPPicDownload.en-UK.9.1.6.18.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-12.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.bigfishgames.com/online/feedingfrenzy/Game/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.bigfishgames.com/online/ricochetlostworlds/ReflexiveWebGameLoader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by122fd.bay122.hotmail.msn.com/activex/HMAtchmt.ocx

Shaba
2007-02-23, 17:47
Hi

Open HijackThis, click do a system scan only and checkmark these:

O4 - HKLM\..\Run: [WINXTX32] rundll32 WINXTX32.DLL,run
O4 - HKCU\..\Run: [Aubs] "C:\WINDOWS\adat\userinit.exe" -vt yazb

Close all windows including browser and press fix checked.

Please print these instructions out, or write them down, as you can't read them during the fix.

Please download MWav (http://www.spywareinfo.dk/download/mwav.exe):

Unzip it to its predetermined directory (C:\Kaspersky)
Locate kavupd.exe in the new folder and double-click to Update.
If your firewall gives any messages about this program accessing to internet, allow it.
If it says the signatures are more than 30 days old, keep trying, until you get the actual definition updates.
When you see Updates Downloaded Successfully, hit Enter to continue.
Restart onto Safe Mode (http://www.pchell.com/support/safemode.shtml)

Delete if found:

C:\WINDOWS\adat
C:\WINDOWS\SYSTEM\DDCAXUR.DLL
C:\WINDOWS\SYSTEM\TTRGMXC.DLL
C:\WINDOWS\SYSTEM\RQONN.DLL
C:\WINDOWS\SYSTEM\XXYAA.DLL

Empty Recycle Bin

Locate the Kaspersky folder.
Locate mwavscan.com and double-click on it to launch the MWAV Scanner.Now lets do the settings:
Leave the Default Settings checked.
Add a check to Drives
This will light up All Drives
Add a check to Scan all Files
Click Scan Clean to begin.
This scan might take around 3+ hours to finish when set to scan everything.
Please be sure it has finished before proceeding.
Once the Scan has finished, all entries identified as Infected, will be displayed in the lower panel.
Highlight everything that is inside the lower panel and hit Ctrl+C at the same time to copy.
Open an empty notepad file and paste the results (Ctrl+V) to it. Save the notepad to your desktop, name it as you want (e.g; MWav Results).Reboot into normal Windows and post the results here along with a fresh HijackThis log.

CliveG
2007-02-23, 20:11
Hi Shaba,
Here is the HijackThis log

Logfile of HijackThis v1.99.1
Scan saved at 19:11:20, on 23/02/07
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\D-LINK\AIRPLUS XTREME G\AIRPLUSCFG.EXE
C:\PROGRAM FILES\ALPHA NETWORKS\ANIWZCS SERVICE\WZCSLDR.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\CLIVE\HIJACKTHIS\HJT.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.axlquotes.com/axl-dlls/publish?url=/entrance.shtml&page1=hotview
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.axlquotes.com/axl-dlls/publish?url=/entrance.shtml&page1=hotview
F1 - win.ini: run=C:\WINDOWS\hpfsched.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [D-Link AirPlus Xtreme G] C:\PROGRAM FILES\D-LINK\AIRPLUS XTREME G\AIRPLUSCFG.EXE
O4 - HKLM\..\Run: [ANIWZCSService] C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\SYSTEM\E_S4I0K2.EXE /P24 "EPSON Stylus Photo RX500" /O7 "EPUSB1:" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [WINXTX32] rundll32 WINXTX32.DLL,run
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NPFMonitor] C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O4 - HKLM\..\RunServices: [ALU Scheduler Service] C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - Startup: BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe
O4 - Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} - http://www.thepaymentcentre.com/build/preload.cab
O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} - http://pictures02.aol.co.uk/ygp/aol/plugin/download/YGPPicDownload.en-UK.9.1.6.18.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-12.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.bigfishgames.com/online/feedingfrenzy/Game/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.bigfishgames.com/online/ricochetlostworlds/ReflexiveWebGameLoader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by122fd.bay122.hotmail.msn.com/activex/HMAtchmt.ocx

CliveG
2007-02-23, 20:12
And the MWav Results

File C:\WINDOWS\SYSTEM\ssqomjk.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ha. No Action Taken.
File C:\WINDOWS\SYSTEM\winxtx32.dll infected by "Trojan.Win32.Agent.qt" Virus. Action Taken: File Deleted.
File C:\WINDOWS\SYSTEM\yayxwvw.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ha. No Action Taken.
File C:\WINDOWS\SYSTEM\byxvvsr.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ha. No Action Taken.
File C:\WINDOWS\SYSTEM\vxrjjwbu.dll infected by "Trojan.Win32.BHO.g" Virus. Action Taken: File Deleted.
File C:\WINDOWS\SYSTEM\jkkhife.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ha. No Action Taken.
File C:\WINDOWS\SYSTEM\ddcaxur.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ha. No Action Taken.
File C:\WINDOWS\SYSTEM\mpseltcw.dll infected by "Trojan.Win32.BHO.g" Virus. Action Taken: File Deleted.
File C:\WINDOWS\SYSTEM\ljjihhg.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ha. No Action Taken.
File C:\WINDOWS\SYSTEM\bvvkofha.dll infected by "Trojan.Win32.BHO.g" Virus. Action Taken: File Deleted.
File C:\WINDOWS\SYSTEM\bptpyvnr.dll infected by "Trojan.Win32.BHO.g" Virus. Action Taken: File Deleted.
File C:\WINDOWS\SYSTEM\ssqomjk.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ha. No Action Taken.
File C:\WINDOWS\SYSTEM\yayxwvw.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ha. No Action Taken.
File C:\WINDOWS\SYSTEM\byxvvsr.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ha. No Action Taken.
File C:\WINDOWS\SYSTEM\jkkhife.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ha. No Action Taken.
File C:\WINDOWS\SYSTEM\ddcaxur.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ha. No Action Taken.
File C:\WINDOWS\SYSTEM\ljjihhg.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ha. No Action Taken.
File C:\WINDOWS\TEMP\win41D3.TMP.exe infected by "Trojan-Downloader.Win32.Agent.bgn" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\win6240.TMP.exe infected by "Trojan-Spy.Win32.Agent.or" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\win195.TMP.exe infected by "Trojan-Downloader.Win32.Agent.bgn" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\mst3113.TMP infected by "Trojan.Win32.Agent.qt" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\win3100.TMP.exe infected by "Trojan-Spy.Win32.Agent.or" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\win273.TMP.exe infected by "Trojan-Downloader.Win32.Agent.bgn" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\win22B6.TMP.exe infected by "Trojan-Spy.Win32.Agent.or" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\mst22D0.TMP infected by "Trojan.Win32.Agent.qt" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\win1295.TMP.exe infected by "Trojan-Downloader.Win32.Agent.bgn" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\mst2122.TMP infected by "Trojan.Win32.Agent.qt" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\win20E1.TMP.exe infected by "Trojan-Spy.Win32.Agent.or" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\winB240.TMP.exe infected by "Trojan-Downloader.Win32.Agent.bgn" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\winC0E5.TMP.exe infected by "Trojan-Spy.Win32.Agent.or" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\mstC0F5.TMP infected by "Trojan.Win32.Agent.qt" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\winE023.TMP.exe infected by "Trojan-PSW.Win32.LdPinch.sh" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\winE0A5.TMP.exe infected by "Trojan-Downloader.Win32.Agent.bgn" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\mstE2C3.TMP infected by "Trojan.Win32.Agent.qt" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\winE282.TMP.exe infected by "Trojan-Spy.Win32.Agent.or" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\winB131.TMP.exe infected by "Trojan-Downloader.Win32.Agent.bgn" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\winB332.TMP.exe infected by "Trojan-Spy.Win32.Agent.or" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\mstB335.TMP infected by "Trojan.Win32.Agent.qt" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\win6315.TMP.exe infected by "Trojan-Downloader.Win32.Agent.bgn" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\mst72A3.TMP infected by "Trojan.Win32.Agent.qt" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\win72A5.TMP.exe infected by "Trojan-Spy.Win32.Agent.or" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\win6141.TMP.exe infected by "Trojan-Downloader.Win32.Agent.bgn" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\win63B1.TMP.exe infected by "Trojan-Spy.Win32.Agent.or" Virus. Action Taken: File Deleted.
File C:\WINDOWS\TEMP\mst63B0.TMP infected by "Trojan.Win32.Agent.qt" Virus. Action Taken: File Deleted.
File C:\WINDOWS\Downloaded Program Files\popcaploader.dll tagged as not-a-virus:Downloader.Win32.PopCap.b. No Action Taken.
File C:\WINDOWS\Temporary Internet Files\Content.IE5\Y8AHZPK0\antzom[1].exe infected by "Trojan-Downloader.Win32.Agent.bgn" Virus. Action Taken: File Deleted.
File C:\WINDOWS\Temporary Internet Files\Content.IE5\ET0JQHSJ\xc29[1].exe infected by "Trojan.Win32.Agent.qt" Virus. Action Taken: File Deleted.
File C:\WINDOWS\Temporary Internet Files\Content.IE5\GL27GPUV\xc29[1].exe infected by "Trojan.Win32.Agent.qt" Virus. Action Taken: File Deleted.
File C:\WINDOWS\Temporary Internet Files\Content.IE5\EA7VDGJR\xc36[1].exe infected by "Trojan-Spy.Win32.Agent.or" Virus. Action Taken: File Deleted.
File C:\WINDOWS\Temporary Internet Files\Content.IE5\EA7VDGJR\xc36[2].exe infected by "Trojan-Spy.Win32.Agent.or" Virus. Action Taken: File Deleted.
File C:\WINDOWS\Temporary Internet Files\Content.IE5\0HIBGXQB\xc60[1].exe infected by "Trojan-PSW.Win32.LdPinch.sh" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\23027E9F.exe infected by "Trojan-Downloader.Win32.Small.dod" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\4CBC1381.TMP infected by "Trojan-Downloader.Win32.Agent.bdr" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\595173FD.EXE infected by "Trojan-Downloader.Win32.Tiny.fk" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\4DC9073E.exe infected by "Trojan-Downloader.Win32.Tiny.fk" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\4EC85225.exe infected by "Trojan-Downloader.Win32.Tiny.fk" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\4ECB7C22.exe infected by "Trojan-Downloader.Win32.Tiny.fk" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\4FCD7106.exe infected by "Trojan-Downloader.Win32.Tiny.fk" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\69C00879.000 infected by "Trojan-Downloader.Win32.PurityScan.co" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\69C65C71.000 infected by "Trojan-Downloader.Win32.PurityScan.dx" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\69C65C71.exe infected by "Trojan-Downloader.Win32.PurityScan.dx" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\69C9066E.dll tagged as not-a-virus:AdWare.Win32.PurityScan.ak. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\69C9066E.exe infected by "Trojan-Downloader.Win32.PurityScan.dt" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\69D05A67.dll tagged as not-a-virus:AdWare.Win32.PurityScan.ak. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\69D05A67.exe tagged as not-a-virus:AdWare.Win32.PurityScan.fo. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\69D30463.dll tagged as not-a-virus:AdWare.Win32.PurityScan.ak. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\69D30463.exe tagged as not-a-virus:AdWare.Win32.PurityScan.fo. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\69D62E5F.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\69DA585C.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\03994A48.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\56FA20D6.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\69DD0258.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\4E1161CA.exe infected by "Trojan-Downloader.Win32.Tiny.fk" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\4AEC497F.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ft. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\548808AC.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ft. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\46C2601D.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\46C60A19.dll tagged as not-a-virus:AdWare.Win32.PurityScan.ak. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\46C60A19.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\46C93415.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\6221128E.exe infected by "Trojan-Downloader.Win32.Tiny.fk" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\496D34E1.exe infected by "Trojan-Downloader.Win32.PurityScan.dt" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\49715EDD.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\70F60F15.exe infected by "Trojan-Downloader.Win32.Tiny.fk" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\4E7B5E74.exe infected by "Trojan-Downloader.Win32.PurityScan.dt" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\4E7E0871.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\34F35E8E.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\4FE64A08.exe infected by "Trojan-Downloader.Win32.Tiny.fk" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\53140ECF.TMP infected by "Trojan-Downloader.Win32.Agent.bdr" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\12696CD7.dll infected by "Trojan-Spy.Win32.VBStat.h" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\2C992205.dll tagged as not-a-virus:AdWare.Win32.PurityScan.ak. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2C992205.exe tagged as not-a-virus:AdWare.Win32.PurityScan.fo. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2C9C4C02.exe infected by "Trojan-Downloader.Win32.PurityScan.dt" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\2C9F75FE.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\2CA31FFA.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\33214593.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\4AEC497F.exe infected by "Trojan-Downloader.Win32.Tiny.fk" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\0D1354B3.dll tagged as not-a-virus:AdWare.Win32.PurityScan.ak. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0D177EAF.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\3250239D.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\7AD644BD.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\523C3BBC.exe infected by "Trojan-Downloader.Win32.Tiny.fk" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\58BA3697.dll infected by "Trojan-Spy.Win32.VBStat.h" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\58BE6093.exe tagged as not-a-virus:AdWare.Win32.Agent.at. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\735A7F4B.exe infected by "Trojan-Downloader.Win32.PurityScan.dt" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\735D2947.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Program Files\Norton AntiVirus\Quarantine\69886B39.exe infected by "Trojan-Downloader.Win32.PurityScan.dc" Virus. Action Taken: File Deleted.
File C:\Clive\Hijackthis\backups\backup-20070223-114322-227.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ha. No Action Taken.
File C:\Downloads\BIGKAHUNAREEFSETUP-DM[1].EXE tagged as not-a-virus:AdWare.Win32.Trymedia.b. No Action Taken.
v

Shaba
2007-02-24, 11:04
Hi

Empty this folder:

C:\Program Files\Norton AntiVirus\Quarantine\

Empty Recycle Bin

Open HijackThis, click do a system scan only and checkmark this

O4 - HKLM\..\Run: [WINXTX32] rundll32 WINXTX32.DLL,run

Close all windows including browser and press fix checked

Please download the Killbox (http://download.bleepingcomputer.com/spyware/KillBox.zip).
Unzip it to the desktop.

Please run Killbox.

Select "Delete on Reboot" and "All files"

Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\WINDOWS\SYSTEM\ssqomjk.dll
C:\WINDOWS\SYSTEM\yayxwvw.dll
C:\WINDOWS\SYSTEM\byxvvsr.dll
C:\WINDOWS\SYSTEM\jkkhife.dll
C:\WINDOWS\SYSTEM\ddcaxur.dll
C:\WINDOWS\SYSTEM\ljjihhg.dll
C:\WINDOWS\SYSTEM\ssqomjk.dll
C:\WINDOWS\SYSTEM\yayxwvw.dll
C:\WINDOWS\SYSTEM\byxvvsr.dll
C:\WINDOWS\SYSTEM\jkkhife.dll
C:\WINDOWS\SYSTEM\ddcaxur.dll
C:\WINDOWS\SYSTEM\ljjihhg.dll

Go to the File menu, and choose "Paste from Clipboard".

Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here (http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe) to download and run missingfilesetup.exe. Then try TheKillbox again..

If your computer does not restart automatically, please restart it manually.

Empty this folder:

C:\!KillBox

Empty Recycle Bin

Re-scan with mwav

Send:

- a fresh HijackThis log
- mwav results

CliveG
2007-02-24, 14:42
Hi Shaba,
Things are looking better :)

MWAV results

File C:\WINDOWS\Downloaded Program Files\popcaploader.dll tagged as not-a-virus:Downloader.Win32.PopCap.b. No Action Taken.
File C:\Clive\Hijackthis\backups\backup-20070223-114322-227.dll tagged as not-a-virus:AdWare.Win32.Virtumonde.ha. No Action Taken.
File C:\Downloads\BIGKAHUNAREEFSETUP-DM[1].EXE tagged as not-a-virus:AdWare.Win32.Trymedia.b. No Action Taken.

CliveG
2007-02-24, 14:45
And the Hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 13:47:17, on 24/02/07
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
c:\windows\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\D-LINK\AIRPLUS XTREME G\AIRPLUSCFG.EXE
C:\PROGRAM FILES\ALPHA NETWORKS\ANIWZCS SERVICE\WZCSLDR.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\CLIVE\HIJACKTHIS\HJT.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.axlquotes.com/axl-dlls/publish?url=/entrance.shtml&page1=hotview
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.axlquotes.com/axl-dlls/publish?url=/entrance.shtml&page1=hotview
F1 - win.ini: run=C:\WINDOWS\hpfsched.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [D-Link AirPlus Xtreme G] C:\PROGRAM FILES\D-LINK\AIRPLUS XTREME G\AIRPLUSCFG.EXE
O4 - HKLM\..\Run: [ANIWZCSService] C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\SYSTEM\E_S4I0K2.EXE /P24 "EPSON Stylus Photo RX500" /O7 "EPUSB1:" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [KB918547] C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NPFMonitor] C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O4 - HKLM\..\RunServices: [ALU Scheduler Service] C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - HKCU\..\RunServices: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - Startup: BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe
O4 - Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR2.DLL/cmtrans.html
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} - http://www.thepaymentcentre.com/build/preload.cab
O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} - http://pictures02.aol.co.uk/ygp/aol/plugin/download/YGPPicDownload.en-UK.9.1.6.18.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-12.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.bigfishgames.com/online/feedingfrenzy/Game/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.bigfishgames.com/online/ricochetlostworlds/ReflexiveWebGameLoader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2A493D5F-8914-4D3E-8BF3-767F281862F4} (TraderMediaImgX Control) - http://sell.autotrader.co.uk/uk-ola/common/TraderMediaX.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by122fd.bay122.hotmail.msn.com/activex/HMAtchmt.ocx

Shaba
2007-02-24, 14:53
Hi

Yes they are :)

Delete these:

C:\Clive\Hijackthis\backups\backup-20070223-114322-227.dll

C:\Downloads\BIGKAHUNAREEFSETUP-DM[1].EXE

Empty Recycle Bin

Otherwise looking good.

How are things running now?

CliveG
2007-02-24, 15:53
yes things are running a lot better (I think!)

When I do a spybot search I still get Smitfraud-C.Toolbar 888. I'll also do a norton scan and MWAV scan as well.

Shaba
2007-02-24, 16:44
Hi

Please send spybot report here :)

CliveG
2007-02-25, 22:10
Hi Shaba,
I have done spybot/norton/mvwav.... checks and all now seems clear. Many thanks for the support and I'll happily make a donation :bigthumb:

Thanks again

Shaba
2007-02-26, 17:02
Hi

Then you're clean!

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt

Change the Download unsigned ActiveX controls to Disable

Change the Initialize and script ActiveX controls not marked as safe to Disable

Change the Installation of desktop items to Prompt

Change the Launching programs and files in an IFRAME to Prompt

Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.

If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

See this link for a listing of some online & their stand-alone antivirus programs:

Virus, Spyware, and Malware Protection and Removal Resources (http://www.bleepingcomputer.com/forums/topic405.html)


Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

For a tutorial on Firewalls and a listing of some available ones see the link below:

Understanding and Using Firewalls (http://www.bleepingcomputer.com/tutorials/tutorial60.html)


Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com (http://www.windowsupdate.com) regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

A tutorial on installing & using this product can be found here:

Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer (http://www.bleepingcomputer.com/forums/?showtutorial=48)

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/tutorials/tutorial49.html)


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

IE/Spyad (http://www.spywarewarrior.com/uiuc/resource.htm) <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
Winpatrol (http://www.winpatrol.com/) <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

Stand Up and Be Counted ---> Malware Complaints (http://www.malwarecomplaints.info/index.php) <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place (http://castlecops.com/postlite7736-.html)

Happy surfing and stay clean!

Shaba
2007-03-01, 19:10
Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.