PDA

View Full Version : Smitfraudfix/hijack this logs Someone help me im not sure where else to go



Rumble_my_heart
2006-07-18, 12:25
Logfile of HijackThis v1.99.1
Scan saved at 4:21:52 AM, on 7/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Neato\MediaFACE 4.0\SetHook.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\COMPUT~1\cac.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnf.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PRISMSVC.EXE
C:\WINDOWS\system32\ScsiAccess.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Venturi2\Client\ventc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\imapi.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\magnify.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre1.5.0_06\bin\javaw.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Mr. & Mrs. Torres\My Documents\hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1D64667F-517D-4c6f-A3DE-6BB09CEBEA91} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: (no name) - {8170D7DC-BDD6-461e-88EB-F047257898C9} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Zango Toolbar - {EA0D26BD-9029-431A-86E0-83152D67828A} - C:\Program Files\Zango Programs\Zango Toolbar\ZangoTB.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [DSS] C:\WINDOWS\system32\wintcpmod.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\HP\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm (file missing)
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.gateway.com
O16 - DPF: {2871FC9B-5E34-4AAE-9E9C-EBD1652D5C92} (Rhapsody Player Engine) - http://forms.real.com/real/player/download.html?f=windows/mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = LUVsME4EVR
O17 - HKLM\Software\..\Telephony: DomainName = LUVsME4EVR
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = LUVsME4EVR
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = LUVsME4EVR
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = LUVsME4EVR
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = LUVsME4EVR
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: PRISMAPI.DLL - C:\WINDOWS\SYSTEM32\PRISMAPI.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Bluetooth Service (btwdins) - Unknown owner - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PRISMSVC - Conexant Systems, Inc. - C:\WINDOWS\system32\PRISMSVC.EXE
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe" /service (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Venturi2 Client (Venturi2) - Fourelle Systems, Inc - C:\Program Files\Venturi2\Client\ventc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


**********************************************

SmitFraudFix v2.72

Scan done at 1:07:01.78, Tue 07/18/2006
Run from
C:\Documents and Settings\Mr. & Mrs. Torres\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles




»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MR


»»»»»»»»»»»»»»»»»»»»»»»» Desktop

C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

steamwiz
2006-07-21, 01:50
Hi

1. Reboot into >>>safe mode (http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406)
2. Double-click smitfraudfix.cmd
3. Select 2 and hit Enter to delete infected files
4. You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection
5. The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file
6. A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt ... Post the contents of the C:\rapport.txt file in your next post here... + a new hijackthis log.

process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool". It is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/processutil/processutil.htm

--
Post the new C:\rapport.txt [/b] file
&
A new hijackthis log



steam

Rumble_my_heart
2006-07-24, 19:12
Well Ive tried Several different times to run my computer in safe mode. But it wont even load. I dont know what the heck is wrong with this damn thing. All I know is that theres a whole bunch of things on my computer I didnt put on it and A whole SH*t load of things running. Im running a few diagnostic programs but I shut them all down trying to run just up to par but WHAT IN THE WORLD AM I SUPPOSED TO DO NOW!! Grr... please help me....

Sincerly,
bitten by the pretender tech. Mr fix it hobbiest

steamwiz
2006-07-25, 01:11
Hi

Run the fix in normal mode... save and post the log...

Then tell us exactly what problems you still have...

steam

Rumble_my_heart
2006-07-30, 10:04
Scan Done BEFORE fix
----------------------------

SmitFraudFix v2.72

Scan done at 5:05:31.87, Thu 07/27/2006
Run from
C:\Documents and Settings\Mr. & Mrs. Torres\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles




»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MR


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End



-------------------
Scan done AFTER fix
-------------------


SmitFraudFix v2.72

Scan done at 5:12:40.75, Thu 07/27/2006
Run from
C:\Documents and Settings\Mr. & Mrs. Torres\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

Rumble_my_heart
2006-07-30, 13:19
this is the hijack this logs...<<<ADD ON>>><<<ADD ON>>>

Logfile of HijackThis v1.99.1
Scan saved at 4:21:52 AM, on 7/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Neato\MediaFACE 4.0\SetHook.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\COMPUT~1\cac.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnf.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PRISMSVC.EXE
C:\WINDOWS\system32\ScsiAccess.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ups.exe
C:\Program Files\Venturi2\Client\ventc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\imapi.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\magnify.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre1.5.0_06\bin\javaw.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Mr. & Mrs. Torres\My Documents\hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1D64667F-517D-4c6f-A3DE-6BB09CEBEA91} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: (no name) - {8170D7DC-BDD6-461e-88EB-F047257898C9} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Zango Toolbar - {EA0D26BD-9029-431A-86E0-83152D67828A} - C:\Program Files\Zango Programs\Zango Toolbar\ZangoTB.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [DSS] C:\WINDOWS\system32\wintcpmod.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\HP\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm (file missing)
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.gateway.com
O16 - DPF: {2871FC9B-5E34-4AAE-9E9C-EBD1652D5C92} (Rhapsody Player Engine) - http://forms.real.com/real/player/download.html?f=windows/mrkt/rhapx/RhapsodyPlayerEngine_Inst_Win.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = LUVsME4EVR
O17 - HKLM\Software\..\Telephony: DomainName = LUVsME4EVR
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = LUVsME4EVR
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = LUVsME4EVR
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = LUVsME4EVR
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: Domain = LUVsME4EVR
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: PRISMAPI.DLL - C:\WINDOWS\SYSTEM32\PRISMAPI.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Bluetooth Service (btwdins) - Unknown owner - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PRISMSVC - Conexant Systems, Inc. - C:\WINDOWS\system32\PRISMSVC.EXE
O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\system32\r_server.exe" /service (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Venturi2 Client (Venturi2) - Fourelle Systems, Inc - C:\Program Files\Venturi2\Client\ventc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

:blush: :laugh: :p:

Rumble_my_heart
2006-07-30, 13:31
Logfile of HijackThis v1.99.1
Scan saved at 5:29:00 AM, on

7/30/2006
Platform: Windows XP SP2

(WinNT 5.01.2600)
MSIE: Internet Explorer v6.00

SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32

\smss.exe
C:\WINDOWS\system32

\winlogon.exe
C:\WINDOWS\system32

\services.exe
C:\WINDOWS\system32

\lsass.exe
C:\WINDOWS\System32

\Ati2evxx.exe
C:\WINDOWS\system32

\svchost.exe
C:\WINDOWS\System32

\svchost.exe
C:\Program

Files\Ahead\InCD\InCDsrv.exe
C:\Program

Files\TGTSoft\StyleXP\StyleXP

Service.exe
C:\Program

Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32

\brsvc01a.exe
C:\WINDOWS\system32

\brss01a.exe
C:\WINDOWS\system32

\spoolsv.exe
C:\WINDOWS\system32

\netdde.exe
C:\PROGRA~1

\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\HP\HP

Software

Update\HPWuSchd2.exe
C:\PROGRA~1\COMMON~1

\AOL\ACS\acsd.exe
C:\Program Files\APC\APC

PowerChute Personal

Edition\mainserv.exe
C:\PROGRA~1

\Grisoft\AVGFRE~1

\avgamsvr.exe
C:\PROGRA~1

\Grisoft\AVGFRE~1

\avgupsvc.exe
C:\PROGRA~1

\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32

\Brmfrmps.exe
C:\WINDOWS\system32

\cisvc.exe
C:\WINDOWS\system32

\CTsvcCDA.EXE
C:\WINDOWS\System32

\svchost.exe
C:\WINDOWS\system32

\drivers\KodakCCS.exe
c:\program

files\mcafee.com\agent\mcdete

ct.exe
c:\PROGRA~1

\mcafee.com\agent\mctskshd.ex

e
C:\PROGRA~1

\McAfee.com\PERSON~1

\MpfService.exe
C:\WINDOWS\system32

\ScsiAccess.EXE
C:\WINDOWS\System32

\tcpsvcs.exe
C:\WINDOWS\System32

\snmp.exe
C:\WINDOWS\System32

\svchost.exe
C:\WINDOWS\System32

\ups.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32

\wbem\wmiapsrv.exe
C:\Program Files\Internet

Explorer\iexplore.exe
C:\Program Files\Yahoo!

\Messenger\YPager.exe
C:\WINDOWS\system32

\cidaemon.exe
C:\WINDOWS\explorer.exe
C:\Program

Files\Adobe\Acrobat 7.0

\Acrobat\Acrobat.exe
C:\DOCUME~1

\MR&MRS~1.TOR\LOCALS~1

\Temp\Adobelm_Cleanup.0001
C:\Program Files\Common

Files\Adobe Systems

Shared\Service\Adobelmsvc.ex

e
C:\DOCUME~1

\MR&MRS~1.TOR\LOCALS~1

\Temp\Adobelm_Cleanup.0001
C:\WINDOWS\system32

\magnify.exe
C:\Program Files\HP\HP Share

-to-Web\hpgs2wnf.exe
C:\Documents and Settings\Mr.

& Mrs. Torres\Desktop\wmp11-

windowsxp-x86-enu\2.exe
C:\Windows\system32

\Firewall.exe
C:\Documents and Settings\Mr.

& Mrs. Torres\Desktop\wmp11-

windowsxp-x86-

enu\wmfdist11.exe
c:\d79110002f9251ba65c57b75344236

0a\update\update.exe
C:\Documents and Settings\Mr.

& Mrs. Torres\Desktop\hijack

this\HijackThis.exe

R0 -

HKCU\Software\Microsoft\Inter

net Explorer\Main,Start Page =

http://www.gateway.com/
R1 -

HKLM\Software\Microsoft\Intern

et

Explorer\Main,Default_Page_UR

L = http://www.gateway.com
R1 -

HKLM\Software\Microsoft\Intern

et Explorer\Main,Search Bar =

http://us.rd.yahoo.com/customiz

e/ie/defaults/sb/msgr7/*http://w

ww.yahoo.com/ext/search/searc

h.html
R0 -

HKLM\Software\Microsoft\Intern

et Explorer\Main,Start Page =

http://www.myspace.com
O2 - BHO: Yahoo! Toolbar

Helper - {02478D38-C3F9-4EFB

-9B51-7695ECA05670} -

C:\Program Files\Yahoo!

\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader

Link Helper - {06849E9F-C8D7-

4D59-B87D-784B7D6BE0B3} -

C:\Program

Files\Adobe\Acrobat 7.0

\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) -

{1D64667F-517D-4c6f-A3DE-

6BB09CEBEA91} - (no file)
O2 - BHO: (no name) -

{53707962-6F74-2D53-2644-

206D7942484F} - C:\PROGRA~1

\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) -

{549B5CA7-4A86-11D7-A4DF-

000874180BB3} - (no file)
O2 - BHO: Yahoo! IE Services

Button - {5BAB4B5B-68BC-4B02

-94D6-2FC0DE4A7897} -

C:\Program Files\Yahoo!

\Common\yiesrvc.dll
O2 - BHO: (no name) -

{724d43a9-0d85-11d4-9908-

00400523e39a} - C:\Program

Files\Siber Systems\AI

RoboForm\roboform.dll
O2 - BHO: (no name) -

{8170D7DC-BDD6-461e-88EB-

F047257898C9} - (no file)
O2 - BHO: Google Toolbar

Helper - {AA58ED58-01DD-4d91-

8333-CF10577473F7} - c:\program

files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF

Conversion Toolbar Helper -

{AE7CD045-E861-484f-8273-

0445EE161910} - C:\Program

Files\Adobe\Acrobat 7.0

\Acrobat\AcroIEFavClient.dll
O2 - BHO: CNavExtBho Class -

{BDF3E430-B101-42AD-A544-

FADC6B084872} - C:\Program

Files\Norton

AntiVirus\NavShExt.dll
O2 - BHO: (no name) -

{FDD3B846-8D59-4ffb-8758-

209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar -

{EF99BD32-C1FB-11D2-892F-

0090271D4F88} - C:\Program

Files\Yahoo!

\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Norton AntiVirus -

{42CDD1BF-3FFB-4238-8AD1-

7859DF00B1D6} - C:\Program

Files\Norton

AntiVirus\NavShExt.dll
O3 - Toolbar: &RoboForm -

{724d43a0-0d85-11d4-9908-

00400523e39a} - C:\Program

Files\Siber Systems\AI

RoboForm\roboform.dll
O3 - Toolbar: &Google -

{2318C2B1-4965-11d4-9B18-

009027A5CD4F} - c:\program

files\google\googletoolbar2.dll
O3 - Toolbar: (no name) -

{EA0D26BD-9029-431A-86E0-

83152D67828A} - (no file)
O3 - Toolbar: Adobe PDF -

{47833539-D0C5-4125-9FA8-

0819E2EAAC93} - C:\Program

Files\Adobe\Acrobat 7.0

\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SmcService]

C:\PROGRA~1

\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [AVG7_CC]

C:\PROGRA~1

\Grisoft\AVGFRE~1\avgcc.exe

/STARTUP
O4 - HKLM\..\Run: [HP Software

Update] c:\Program

Files\HP\HP Software

Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SetDefPrt]

C:\Program

Files\Brother\Brmfl04a\BrStDvP

t.exe
O4 - HKLM\..\Run: [High

Definition Audio Property Page

Shortcut]

HDAudPropShortcut.exe
O4 - HKLM\..\Run: [DSS]

C:\WINDOWS\system32

\wintcpmod.exe
O4 - HKLM\..\Run:

[DigidesignMMERefresh]

C:\Program

Files\Digidesign\Drivers\MMER

efresh.exe
O4 - HKLM\..\Run: [Computer

Alarm Clock] C:\PROGRA~1

\COMPUT~1\cac.exe
O4 - HKLM\..\Run:

[MCUpdateExe] c:\PROGRA~1

\mcafee.com\agent\mcupdate.e

xe
O4 - HKLM\..\Run: [Firewall.exe]

C:\WINDOWS\system32

\Firewall.exe
O4 - HKLM\..\RunOnce:

[InstallDne]

C:\WINDOWS\system32

\rundll32.exe

C:\WINDOWS\system32

\dneinobj.dll,ReInstallDne
O4 - HKCU\..\Run: [Yahoo!

Pager] "C:\Program

Files\Yahoo!

\Messenger\ypager.exe" -quiet
O8 - Extra context menu item:

Convert link target to Adobe

PDF - res://C:\Program

Files\Adobe\Acrobat 7.0

\Acrobat\AcroIEFavClient.dll/Ac

roIECapture.html
O8 - Extra context menu item:

Convert link target to existing

PDF - res://C:\Program

Files\Adobe\Acrobat 7.0

\Acrobat\AcroIEFavClient.dll/Ac

roIEAppend.html
O8 - Extra context menu item:

Convert selected links to Adobe

PDF - res://C:\Program

Files\Adobe\Acrobat 7.0

\Acrobat\AcroIEFavClient.dll/Ac

roIECaptureSelLinks.html
O8 - Extra context menu item:

Convert selected links to

existing PDF - res://C:\Program

Files\Adobe\Acrobat 7.0

\Acrobat\AcroIEFavClient.dll/Ac

roIEAppendSelLinks.html
O8 - Extra context menu item:

Convert selection to Adobe PDF

- res://C:\Program

Files\Adobe\Acrobat 7.0

\Acrobat\AcroIEFavClient.dll/Ac

roIECapture.html
O8 - Extra context menu item:

Convert selection to existing

PDF - res://C:\Program

Files\Adobe\Acrobat 7.0

\Acrobat\AcroIEFavClient.dll/Ac

roIEAppend.html
O8 - Extra context menu item:

Convert to Adobe PDF -

res://C:\Program

Files\Adobe\Acrobat 7.0

\Acrobat\AcroIEFavClient.dll/Ac

roIECapture.html
O8 - Extra context menu item:

Convert to existing PDF -

res://C:\Program

Files\Adobe\Acrobat 7.0

\Acrobat\AcroIEFavClient.dll/Ac

roIEAppend.html
O8 - Extra context menu item:

Send To &Bluetooth -

C:\Program

Files\WIDCOMM\Bluetooth

Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) -

{08B0E5C0-4FCB-11CF-AAA5-

00401C608501} - C:\Program

Files\Java\jre1.5.0_06

\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem:

Sun Java Console - {08B0E5C0

-4FCB-11CF-AAA5-00401C608501}

- C:\Program

Files\Java\jre1.5.0_06

\bin\npjpi150_06.dll
O9 - Extra button: Fill Forms -

{320AF880-6646-11D3-ABEE-

C5DBF3571F46} -

file://C:\Program Files\Siber

Systems\AI

RoboForm\RoboFormComFillFo

rms.html
O9 - Extra 'Tools' menuitem: Fill

Forms - {320AF880-6646-11D3-

ABEE-C5DBF3571F46} -

file://C:\Program Files\Siber

Systems\AI

RoboForm\RoboFormComFillFo

rms.html
O9 - Extra button: Save -

{320AF880-6646-11D3-ABEE-

C5DBF3571F49} -

file://C:\Program Files\Siber

Systems\AI

RoboForm\RoboFormComSave

Pass.html
O9 - Extra 'Tools' menuitem:

Save Forms - {320AF880-6646-

11D3-ABEE-C5DBF3571F49} -

file://C:\Program Files\Siber

Systems\AI

RoboForm\RoboFormComSave

Pass.html
O9 - Extra button: Yahoo!

Services - {5BAB4B5B-68BC-

4B02-94D6-2FC0DE4A7897} -

C:\Program Files\Yahoo!

\Common\yiesrvc.dll
O9 - Extra button: ComcastHSI -

{669B269B-0D4E-41FB-A3D8-

FD67CA94F646} -

http://www.comcast.net/ (file

missing)
O9 - Extra button: RoboForm -

{724d43aa-0d85-11d4-9908-

00400523e39a} -

file://C:\Program Files\Siber

Systems\AI

RoboForm\RoboFormComShow

Toolbar.html
O9 - Extra 'Tools' menuitem:

RoboForm Toolbar - {724d43aa

-0d85-11d4-9908-00400523e39a} -

file://C:\Program Files\Siber

Systems\AI

RoboForm\RoboFormComShow

Toolbar.html
O9 - Extra button: Support -

{8828075D-D097-4055-AA02-

2DBFA9D85E8A} -

http://www.comcastsupport.com/

(file missing)
O9 - Extra button: Help -

{97809617-3937-4F84-B335-

9BB05EF1A8D4} -

http://online.comcast.net/help/

(file missing)
O9 - Extra button:

PartyPoker.com - {B7FE5D70-

9AA2-40F1-9C6B-12A255F085E1} -

C:\Program

Files\PartyPoker\PartyPoker.ex

e (file missing)
O9 - Extra 'Tools' menuitem:

PartyPoker.com - {B7FE5D70-

9AA2-40F1-9C6B-12A255F085E1} -

C:\Program

Files\PartyPoker\PartyPoker.ex

e (file missing)
O9 - Extra button: @btrez.dll,-

4015 - {CCA281CA-C863-46ef-

9331-5C8D4460577F} -

C:\Program

Files\WIDCOMM\Bluetooth

Software\btsendto_ie.htm (file

missing)
O9 - Extra 'Tools' menuitem:

@btrez.dll,-4017 - {CCA281CA-

C863-46ef-9331-5C8D4460577F} -

C:\Program

Files\WIDCOMM\Bluetooth

Software\btsendto_ie.htm (file

missing)
O9 - Extra button: (no name) -

{CD67F990-D8E9-11d2-98FE-

00C0F0318AFE} - (no file)
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-

00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem:

Windows Messenger -

{FB5F1910-F110-11d2-BB9E-

00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O12 - Plugin for .spop:

C:\Program Files\Internet

Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF:

START_PAGE_URL=http://www.

gateway.com
O16 - DPF: {2871FC9B-5E34-

4AAE-9E9C-EBD1652D5C92}

(Rhapsody Player Engine) -

http://forms.real.com/real/player

/download.html?

f=windows/mrkt/rhapx/Rhapsod

yPlayerEngine_Inst_Win.cab
O16 - DPF: {30528230-99f7-4bb4-

88d8-fa1d4f56a2ab} (YInstStarter

Class) - C:\Program

Files\Yahoo!

\Common\yinsthelper.dll
O17 -

HKLM\System\CCS\Services\T

cpip\Parameters: Domain =

LUVsME4EVR
O17 -

HKLM\Software\..\Telephony:

DomainName = LUVsME4EVR
O17 - HKLM\System\CS1

\Services\Tcpip\Parameters:

Domain = LUVsME4EVR
O17 - HKLM\System\CS2

\Services\Tcpip\Parameters:

Domain = LUVsME4EVR
O17 - HKLM\System\CS3

\Services\Tcpip\Parameters:

Domain = LUVsME4EVR
O17 - HKLM\System\CS4

\Services\Tcpip\Parameters:

Domain = LUVsME4EVR
O20 - Winlogon Notify: igfxcui -

C:\WINDOWS\SYSTEM32

\igfxsrvc.dll
O20 - Winlogon Notify:

PRISMAPI.DLL -

C:\WINDOWS\SYSTEM32

\PRISMAPI.DLL
O20 - Winlogon Notify:

WgaLogon -

C:\WINDOWS\SYSTEM32

\WgaLogon.dll
O23 - Service: Adobe LM

Service - Adobe Systems -

C:\Program Files\Common

Files\Adobe Systems

Shared\Service\Adobelmsvc.ex

e
O23 - Service: AOL Connectivity

Service (AOL ACS) - America

Online, Inc. - C:\PROGRA~1

\COMMON~1

\AOL\ACS\acsd.exe
O23 - Service: APC UPS

Service - American Power

Conversion Corporation -

C:\Program Files\APC\APC

PowerChute Personal

Edition\mainserv.exe
O23 - Service: Ati HotKey Poller

- Unknown owner -

C:\WINDOWS\System32

\Ati2evxx.exe
O23 - Service: AVG7 Alert

Manager Server (Avg7Alrt) -

GRISOFT, s.r.o. -

C:\PROGRA~1

\Grisoft\AVGFRE~1

\avgamsvr.exe
O23 - Service: AVG7 Update

Service (Avg7UpdSvc) -

GRISOFT, s.r.o. -

C:\PROGRA~1

\Grisoft\AVGFRE~1

\avgupsvc.exe
O23 - Service: AVG E-mail

Scanner (AVGEMS) - GRISOFT,

s.r.o. - C:\PROGRA~1

\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Belkin 54g

Wireless USB Network Adapter

(Belkin 54g Wireless USB

Network Adapter Service) -

Unknown owner - C:\Program

Files\Belkin\Belkin Wireless

Network Utility\WLService.exe
O23 - Service: Brother Popup

Suspend service for Resource

manager (brmfrmps) - Unknown

owner -

C:\WINDOWS\system32

\Brmfrmps.exe" -service (file

missing)
O23 - Service: BrSplService

(Brother XP spl Service) -

brother Industries Ltd -

C:\WINDOWS\system32

\brsvc01a.exe
O23 - Service: Bluetooth Service

(btwdins) - Unknown owner -

C:\Program

Files\WIDCOMM\Bluetooth

Software\bin\btwdins.exe (file

missing)
O23 - Service: Creative Service

for CDROM Access - Creative

Technology Ltd -

C:\WINDOWS\system32

\CTsvcCDA.EXE
O23 - Service: InstallDriver

Table Manager (IDriverT) -

Macrovision Corporation -

C:\Program Files\Common

Files\InstallShield\Driver\11\Intel

32\IDriverT.exe
O23 - Service: InCD Helper

(InCDsrv) - Ahead Software AG

- C:\Program

Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper

(read only) (InCDsrvR) - Ahead

Software AG - C:\Program

Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService -

Apple Computer, Inc. -

C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera

Connection Software

(KodakCCS) - Eastman Kodak

Company -

C:\WINDOWS\system32

\drivers\KodakCCS.exe
O23 - Service: McAfee WSC

Integration (McDetect.exe) -

McAfee, Inc - c:\program

files\mcafee.com\agent\mcdete

ct.exe
O23 - Service: McAfee Task

Scheduler (McTskshd.exe) -

McAfee, Inc - c:\PROGRA~1

\mcafee.com\agent\mctskshd.ex

e
O23 - Service: McAfee

SecurityCenter Update Manager

(mcupdmgr.exe) - McAfee, Inc -

C:\PROGRA~1

\McAfee.com\Agent\mcupdmgr.

exe
O23 - Service: McAfee Personal

Firewall Service (MpfService) -

McAfee Corporation -

C:\PROGRA~1

\McAfee.com\PERSON~1

\MpfService.exe
O23 - Service: Pml Driver HPZ12

- Unknown owner -

C:\WINDOWS\system32

\HPZipm12.exe (file missing)
O23 - Service: PRISMSVC -

Unknown owner -

C:\WINDOWS\system32

\PRISMSVC.EXE (file missing)
O23 - Service: ScsiAccess -

Unknown owner -

C:\WINDOWS\system32

\ScsiAccess.EXE
O23 - Service: Sygate Personal

Firewall Pro (SmcService) -

Sygate Technologies, Inc. -

C:\Program

Files\Sygate\SPF\smc.exe
O23 - Service: Symantec

Network Drivers Service

(SNDSrvc) - Symantec

Corporation - C:\Program

Files\Common Files\Symantec

Shared\SNDSrvc.exe
O23 - Service: StyleXPService -

Unknown owner - C:\Program

Files\TGTSoft\StyleXP\StyleXP

Service.exe
O23 - Service: Venturi2 Client

(Venturi2) - Unknown owner -

C:\Program Files\Venturi2

\Client\ventc.exe (file missing)
O23 - Service: WAN Miniport

(ATW) Service

(WANMiniportService) - America

Online, Inc. -

C:\WINDOWS\wanmpsvc.exe

:thud:

steamwiz
2006-08-04, 20:48
HI

Sorry about the late reply ... I had an accident at work and have not been able to get on-line for several days...

The last hijackthis log you posted is very difficult to read, although it does appear clean ... it should look like the other hijackthis logs you posted, please run hijackthis again and post a new log.

Also your Smitfraud log is now clean...

Please go into as much detail as possible about any problems you are still having... yes, you have a lot of running processes, but they are all legitimate...

steam

tashi
2006-08-09, 21:53
This topic has been closed to prevent others with similar issues posting in it.
If you need it re-opened please send me or your helper a pm and provide a link to the thread.

Applies only to the original topic starter.