PDA

View Full Version : First Scans 'Zlob Toolbar Warning'



ruckus
2008-03-18, 09:52
Hi there!!! Me again!!!
I have an annoying thing in my toolbar trying to tell me I have a system alert...but I know it is that someone (not me) visiting porn sites and installing bad active x!!
My computer is shared and I didn't put a condom on it quick enough! :P.... hehe :)

Complete Spybot check and fix done only to this point plus AVG Free Edition

First HiJack Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:37:37 PM, on 3/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\HP\KBD\KBD.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\IPWireless Inc\IPWireless PC Software\UEStatus.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {6860A44B-5D3E-433D-A7B5-D517F810D0E7} - C:\Program Files\NetProject\sbmdl.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Internet Service - {DB9FBA9D-AB1B-4CC6-9745-F3B549D64E40} - C:\Program Files\NetProject\wamdl.dll (file missing)
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunOnce: [SpybotDeletingA9012] command /c del "C:\Program Files\VirusHeat 4.3\VirusHeat 4.3.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9279] cmd /c del "C:\Program Files\VirusHeat 4.3\VirusHeat 4.3.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4909] command /c del "C:\Documents and Settings\Ruckus\Start Menu\Programs\VirusHeat 4.3\Uninstall VirusHeat 4.3.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6051] cmd /c del "C:\Documents and Settings\Ruckus\Start Menu\Programs\VirusHeat 4.3\Uninstall VirusHeat 4.3.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4743] command /c del "C:\Documents and Settings\Ruckus\Start Menu\Programs\VirusHeat 4.3\VirusHeat 4.3.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7389] cmd /c del "C:\Documents and Settings\Ruckus\Start Menu\Programs\VirusHeat 4.3\VirusHeat 4.3.lnk"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4904] command /c del "C:\Program Files\VirusHeat 4.3\uninst.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9278] cmd /c del "C:\Program Files\VirusHeat 4.3\uninst.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3576] command /c del "C:\Program Files\VirusHeat 4.3\VirusHeat 4.3.url"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5940] cmd /c del "C:\Program Files\VirusHeat 4.3\VirusHeat 4.3.url"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7043] command /c del "C:\WINDOWS\system32\jdxah.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5523] cmd /c del "C:\WINDOWS\system32\jdxah.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3279] command /c del "C:\WINDOWS\system32\jdxah.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8155] cmd /c del "C:\WINDOWS\system32\jdxah.dll_old"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSetup] D:\Setup\Setup.exe /start /restart /l:enu
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3022] command /c del "C:\Program Files\VirusHeat 4.3\VirusHeat 4.3.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD405] cmd /c del "C:\Program Files\VirusHeat 4.3\VirusHeat 4.3.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7260] command /c del "C:\Documents and Settings\Ruckus\Start Menu\Programs\VirusHeat 4.3\Uninstall VirusHeat 4.3.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1349] cmd /c del "C:\Documents and Settings\Ruckus\Start Menu\Programs\VirusHeat 4.3\Uninstall VirusHeat 4.3.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8631] command /c del "C:\Documents and Settings\Ruckus\Start Menu\Programs\VirusHeat 4.3\VirusHeat 4.3.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5269] cmd /c del "C:\Documents and Settings\Ruckus\Start Menu\Programs\VirusHeat 4.3\VirusHeat 4.3.lnk"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7459] command /c del "C:\Program Files\VirusHeat 4.3\uninst.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4153] cmd /c del "C:\Program Files\VirusHeat 4.3\uninst.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB96] command /c del "C:\Program Files\VirusHeat 4.3\VirusHeat 4.3.url"
O4 - HKCU\..\RunOnce: [SpybotDeletingD302] cmd /c del "C:\Program Files\VirusHeat 4.3\VirusHeat 4.3.url"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9950] command /c del "C:\WINDOWS\system32\jdxah.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8375] cmd /c del "C:\WINDOWS\system32\jdxah.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6913] command /c del "C:\WINDOWS\system32\jdxah.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5194] cmd /c del "C:\WINDOWS\system32\jdxah.dll_old"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Ruckus\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {2E28242B-A689-11D4-80F2-0040266CBB8D} (KXHCM10 Control) - http://www.raddi.com/kxhcm10.ocx
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7221DB26-EB4D-4A6B-862E-E108F79E413E}: NameServer = 202.74.207.10 202.74.207.100
O22 - SharedTaskScheduler: inoperable - {1b40d2ad-d237-4544-b1e1-0bf75bf8fcc0} - C:\WINDOWS\system32\jdxah.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

--
End of file - 10305 bytes

First Kapersky Log:

Tuesday, March 18, 2008 9:18:02 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/03/2008
Kaspersky Anti-Virus database records: 636169


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\
F:\
G:\

Scan Statistics
Total number of scanned objects 69134
Number of viruses found 5
Number of infected objects 7
Number of suspicious objects 0
Duration of the scan process 01:16:52

Infected Object Name Virus Name Last Action
C:\Documents and Settings\Administrator.DJRUCKUS\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Administrator.DJRUCKUS\NTUSER.dat.LOG Object is locked skipped

C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Ruckus\Application Data\Microsoft\MSNLiveFav\LiveFavorites.xml Object is locked skipped

C:\Documents and Settings\Ruckus\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Ruckus\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped

C:\Documents and Settings\Ruckus\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Ruckus\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Ruckus\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Ruckus\Local Settings\History\History.IE5\MSHist012008031820080319\index.dat Object is locked skipped

C:\Documents and Settings\Ruckus\Local Settings\Temp\zs1.exe Infected: not-virus:Hoax.Win32.Renos.bdu skipped

C:\Documents and Settings\Ruckus\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\Ruckus\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Ruckus\ntuser.dat Object is locked skipped

C:\Documents and Settings\Ruckus\ntuser.dat.LOG Object is locked skipped

C:\Porn\VA - TOP Electro-House(part.3)-=$huRe@K=-\dj_rooster_and_sammy_peralta_feat_hcp-take_control_(original_mix).mp3 Object is locked skipped

C:\Program Files\NetProject\sbmdl.dll_old Infected: Trojan-Downloader.Win32.Zlob.jhf skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{A24D9852-A98B-4853-8575-4BD08DECD3BB}\RP100\A0058027.exe Infected: not-a-virus:FraudTool.Win32.VirusProtectPro.v skipped

C:\System Volume Information\_restore{A24D9852-A98B-4853-8575-4BD08DECD3BB}\RP100\A0058029.exe Infected: Trojan-Downloader.Win32.Zlob.jhg skipped

C:\System Volume Information\_restore{A24D9852-A98B-4853-8575-4BD08DECD3BB}\RP100\A0058037.dll Infected: not-virus:Hoax.Win32.Agent.at skipped

C:\System Volume Information\_restore{A24D9852-A98B-4853-8575-4BD08DECD3BB}\RP100\A0058039.dll Infected: Trojan-Downloader.Win32.Zlob.jhf skipped

C:\System Volume Information\_restore{A24D9852-A98B-4853-8575-4BD08DECD3BB}\RP101\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\ModemLog_Wireless Broadband Modem (WDM).txt Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\jdxah.dll_old Infected: not-virus:Hoax.Win32.Agent.at skipped

C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

E:\System Volume Information\_restore{A24D9852-A98B-4853-8575-4BD08DECD3BB}\RP101\change.log Object is locked skipped

Scan process completed.



Sincerely and eternally grateful for people like yourself....David

Shaba
2008-03-19, 11:51
Hi ruckus

Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.exe

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press Enter
This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

IMPORTANT: Do NOT run any other options until you are asked to do so!

**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.

Shaba
2008-03-24, 11:25
Due to the lack of feedback this Topic is closed.

If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send a private message (pm). A valid, working link to the closed topic is required.

Everyone else please begin a New Topic.