Novacane-406
2007-05-25, 21:48
Let me say that I have no experience trying to repair my own pc. I guess I have been lucky so far, I have never got a virus before in my life, tracking cookies and stuff, but no viruses, this is my first.
I don't know how these things work, I am reading as much as I can now, but I still don't know much. One thing that worries me is that people say my phone bill could be huge, or my personal information could be sent out, both ideas huant me, I live on a fixed income and a huge phone bill could ruin me.
I think that I have the smitfraud toolbar 888 thing that seems to be running so much. I didn't want to bother anyone with my questions, especially since I haven't done much research(some of the instructions here seem like they are wrote in a different language or something) but I thought that following instructions for someone else's pc might mess something up on mine, so I thought I would post and ask for help.
So far it all started with avg saying it found a virus, I healed it, and thought I was done. Start surfing the internet, and what do you know, pop ups and new pages galore. I knew something was wrong and got spybot(I recently had to have a new os installed on the pc and was in the process of downloading all my favorites)
Spybot got all kinds of things, figured everything is better now, but nope. Still didn't think much of it, so I got adaware as a back up, ran it, and it found a bunch more, so I figured that got everything. It did help a lot, no pop ups, but every 15-30 minutes IE opens a new page usually to a antivirus advertisement.
Every time I run Spybot, I get a smitfraud toolbar 888 notification, it says it gets rid of it, but a scan afterwords and it pops up again over and over. So I started reading up on it, and have been reading these boards for a couple days of and on as I can.
So far I have ran sypbot, adaware, a tool called smitfraud fix, vundofix, and avg all in safe and normal modes. I have turned off system restore, and at this point only get online for a few minutes at a time, and the rest I leave the ethernet cable unplugged, this thing has me paranoid, can someone please help me out, and understand I need to take baby steps, this stuff is easy to you guys, but I just don't get it quickly.
From reading other posts I see that you want an online scan, I tried panda, nothing found, didn't know how to get a report, so nothing to post, tried another online scan, found nothing, tried kapernsky and couldn't get it to work. I downloaded hijackthis, and did a scan because thats everyone else does here, lol. here it is, hope you guys can make heads or tails out of it!
Logfile of HijackThis v1.99.1
Scan saved at 1:47:03 PM, on 5/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe
O2 - BHO: (no name) - {2539BA42-C4DD-4D38-89BB-B067308D54BC} - C:\WINDOWS\system32\vturq.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {DA0C29E1-1889-41EC-981F-19C48FFAFCD4} - C:\WINDOWS\system32\ljjjgfc.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178816119000
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ljjjgfc - ljjjgfc.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O20 - Winlogon Notify: winjrs32 - winjrs32.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
I don't know how these things work, I am reading as much as I can now, but I still don't know much. One thing that worries me is that people say my phone bill could be huge, or my personal information could be sent out, both ideas huant me, I live on a fixed income and a huge phone bill could ruin me.
I think that I have the smitfraud toolbar 888 thing that seems to be running so much. I didn't want to bother anyone with my questions, especially since I haven't done much research(some of the instructions here seem like they are wrote in a different language or something) but I thought that following instructions for someone else's pc might mess something up on mine, so I thought I would post and ask for help.
So far it all started with avg saying it found a virus, I healed it, and thought I was done. Start surfing the internet, and what do you know, pop ups and new pages galore. I knew something was wrong and got spybot(I recently had to have a new os installed on the pc and was in the process of downloading all my favorites)
Spybot got all kinds of things, figured everything is better now, but nope. Still didn't think much of it, so I got adaware as a back up, ran it, and it found a bunch more, so I figured that got everything. It did help a lot, no pop ups, but every 15-30 minutes IE opens a new page usually to a antivirus advertisement.
Every time I run Spybot, I get a smitfraud toolbar 888 notification, it says it gets rid of it, but a scan afterwords and it pops up again over and over. So I started reading up on it, and have been reading these boards for a couple days of and on as I can.
So far I have ran sypbot, adaware, a tool called smitfraud fix, vundofix, and avg all in safe and normal modes. I have turned off system restore, and at this point only get online for a few minutes at a time, and the rest I leave the ethernet cable unplugged, this thing has me paranoid, can someone please help me out, and understand I need to take baby steps, this stuff is easy to you guys, but I just don't get it quickly.
From reading other posts I see that you want an online scan, I tried panda, nothing found, didn't know how to get a report, so nothing to post, tried another online scan, found nothing, tried kapernsky and couldn't get it to work. I downloaded hijackthis, and did a scan because thats everyone else does here, lol. here it is, hope you guys can make heads or tails out of it!
Logfile of HijackThis v1.99.1
Scan saved at 1:47:03 PM, on 5/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe
O2 - BHO: (no name) - {2539BA42-C4DD-4D38-89BB-B067308D54BC} - C:\WINDOWS\system32\vturq.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {DA0C29E1-1889-41EC-981F-19C48FFAFCD4} - C:\WINDOWS\system32\ljjjgfc.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178816119000
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ljjjgfc - ljjjgfc.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O20 - Winlogon Notify: winjrs32 - winjrs32.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe