salvation926
2007-05-26, 19:17
All,
I've tried a few things to remove this and I can't seem to get it removed, largely due to my ignorance. Any help would be appreciated.
Spybot told me it was Smitfraud. Here's my HJT log...
SDFix: Version 1.85
Run by James - Sat 05/26/2007 - 11:51:24.89
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\335858~1 - Deleted
C:\WINDOWS\Temp\win10F.tmp.exe - Deleted
C:\WINDOWS\Temp\win112.tmp.exe - Deleted
C:\WINDOWS\Temp\win117.tmp.exe - Deleted
C:\WINDOWS\Temp\win11B.tmp.exe - Deleted
C:\WINDOWS\Temp\win11D.tmp.exe - Deleted
C:\WINDOWS\Temp\win14F.tmp.exe - Deleted
C:\WINDOWS\Temp\win153.tmp.exe - Deleted
C:\WINDOWS\Temp\win159.tmp.exe - Deleted
C:\WINDOWS\Temp\winE3.tmp.exe - Deleted
C:\WINDOWS\Temp\winE5.tmp.exe - Deleted
C:\WINDOWS\Temp\win10F.tmp.exe - Deleted
C:\WINDOWS\Temp\win112.tmp.exe - Deleted
C:\WINDOWS\Temp\win117.tmp.exe - Deleted
C:\WINDOWS\Temp\win11B.tmp.exe - Deleted
C:\WINDOWS\Temp\win11D.tmp.exe - Deleted
C:\WINDOWS\Temp\win14F.tmp.exe - Deleted
C:\WINDOWS\Temp\win153.tmp.exe - Deleted
C:\WINDOWS\Temp\win159.tmp.exe - Deleted
C:\WINDOWS\Temp\winE3.tmp.exe - Deleted
C:\WINDOWS\Temp\winE5.tmp.exe - Deleted
C:\WINDOWS\Temp\removalfile.bat - Deleted
C:\WINDOWS\Temp\win*.tmp - Deleted
Removing Temp Files...
ADS Check:
Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.
Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\ttax.exe"="C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\ttax.exe:LocalSubNet:Enabled:TurboTax"
"C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\updatemgr.exe"="C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager"
"C:\\Program Files\\FEAR\\FEAR.exe"="C:\\Program Files\\FEAR\\FEAR.exe:*:Enabled:FEAR"
"F:\\Media\\Music\\Morpheus Music\\New\\LimeWire\\LimeWire.exe"="F:\\Media\\Music\\Morpheus Music\\New\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files:
---------------
Backups Folder: - C:\SDFix\backups\backups.zip
Checking For Files with Hidden Attributes:
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Program Files\Swarmcast\BITEC.tmp
Finished
I ran VUNDO and followed that. I ran SDFix and followed that. I re-ran Spybot and it still shows it there.
What's next?
James
I've tried a few things to remove this and I can't seem to get it removed, largely due to my ignorance. Any help would be appreciated.
Spybot told me it was Smitfraud. Here's my HJT log...
SDFix: Version 1.85
Run by James - Sat 05/26/2007 - 11:51:24.89
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\335858~1 - Deleted
C:\WINDOWS\Temp\win10F.tmp.exe - Deleted
C:\WINDOWS\Temp\win112.tmp.exe - Deleted
C:\WINDOWS\Temp\win117.tmp.exe - Deleted
C:\WINDOWS\Temp\win11B.tmp.exe - Deleted
C:\WINDOWS\Temp\win11D.tmp.exe - Deleted
C:\WINDOWS\Temp\win14F.tmp.exe - Deleted
C:\WINDOWS\Temp\win153.tmp.exe - Deleted
C:\WINDOWS\Temp\win159.tmp.exe - Deleted
C:\WINDOWS\Temp\winE3.tmp.exe - Deleted
C:\WINDOWS\Temp\winE5.tmp.exe - Deleted
C:\WINDOWS\Temp\win10F.tmp.exe - Deleted
C:\WINDOWS\Temp\win112.tmp.exe - Deleted
C:\WINDOWS\Temp\win117.tmp.exe - Deleted
C:\WINDOWS\Temp\win11B.tmp.exe - Deleted
C:\WINDOWS\Temp\win11D.tmp.exe - Deleted
C:\WINDOWS\Temp\win14F.tmp.exe - Deleted
C:\WINDOWS\Temp\win153.tmp.exe - Deleted
C:\WINDOWS\Temp\win159.tmp.exe - Deleted
C:\WINDOWS\Temp\winE3.tmp.exe - Deleted
C:\WINDOWS\Temp\winE5.tmp.exe - Deleted
C:\WINDOWS\Temp\removalfile.bat - Deleted
C:\WINDOWS\Temp\win*.tmp - Deleted
Removing Temp Files...
ADS Check:
Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.
Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\ttax.exe"="C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\ttax.exe:LocalSubNet:Enabled:TurboTax"
"C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\updatemgr.exe"="C:\\Program Files\\TurboTax\\Home & Business 2006\\32bit\\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager"
"C:\\Program Files\\FEAR\\FEAR.exe"="C:\\Program Files\\FEAR\\FEAR.exe:*:Enabled:FEAR"
"F:\\Media\\Music\\Morpheus Music\\New\\LimeWire\\LimeWire.exe"="F:\\Media\\Music\\Morpheus Music\\New\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files:
---------------
Backups Folder: - C:\SDFix\backups\backups.zip
Checking For Files with Hidden Attributes:
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Program Files\Swarmcast\BITEC.tmp
Finished
I ran VUNDO and followed that. I ran SDFix and followed that. I re-ran Spybot and it still shows it there.
What's next?
James