daneh
2006-11-05, 02:08
Could someone please look at these attachments to see if I have successfully removed this wonderful malware? I didn't get to save the online scan, I hope it isn't extremely important. As this is the absolute first time ever posting on a forum, I am going to try to paste the logs.
SmitFraudFix v2.118
Scan done at 20:20:06.74, Fri 11/03/2006
Run from C:\Documents and Settings\Bob Anderson\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{27321538-5739-4aa1-b84c-7d18e4383f1f}"="ferrateen"
[HKEY_CLASSES_ROOT\CLSID\{27321538-5739-4aa1-b84c-7d18e4383f1f}\InProcServer32]
@="C:\WINDOWS\System32\rrtcany.dll"
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{27321538-5739-4aa1-b84c-7d18e4383f1f}\InProcServer32]
@="C:\WINDOWS\System32\rrtcany.dll"
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\system32\rrtcany.dll Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
C:\Program Files\iVideoCodec\ Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 9:04:49 PM 11/3/2006
+ Scan result:
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Ignored.
C:\Documents and Settings\Bob Anderson\Local Settings\Temporary Internet Files\Content.IE5\3XB9K0QD\WinAntiVirusPro2006FreeInstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Ignored.
:mozilla.19:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.23:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.24:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.39:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.40:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.89:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.90:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.91:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.92:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.16:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.27:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.98:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.62:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.183:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.184:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.185:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.67:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.132:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.15:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Commission-junction : Cleaned.
:mozilla.16:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Commission-junction : Cleaned.
:mozilla.17:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.31:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.285:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.286:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.292:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.100:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.101:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.102:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.103:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.104:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.105:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.99:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.147:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.250:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.68:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.85:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.305:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.307:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.308:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.317:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.80:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Bob Anderson\Cookies\bob anderson@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.150:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.137:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.138:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.139:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.140:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.148:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.155:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.159:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.162:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.75:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.76:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.77:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.78:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.82:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Bob Anderson\Cookies\bob anderson@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.151:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.152:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.153:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.154:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.165:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.166:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.167:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.168:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.169:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.22:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.23:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.24:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.25:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.227:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.228:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.229:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.230:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.231:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.58:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.59:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.60:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.61:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.265:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.266:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.267:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.186:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.187:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.188:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.189:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.190:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.191:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.192:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.193:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.202:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\LocalService\Cookies\bob anderson@server3.web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.10:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.10:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.11:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.198:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.199:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.200:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.201:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.9:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
::Report end
So this is the rapport and avg logs. I'll have to post the hijackthis log in another post.
Thanks for the help. Dwayne
SmitFraudFix v2.118
Scan done at 20:20:06.74, Fri 11/03/2006
Run from C:\Documents and Settings\Bob Anderson\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{27321538-5739-4aa1-b84c-7d18e4383f1f}"="ferrateen"
[HKEY_CLASSES_ROOT\CLSID\{27321538-5739-4aa1-b84c-7d18e4383f1f}\InProcServer32]
@="C:\WINDOWS\System32\rrtcany.dll"
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{27321538-5739-4aa1-b84c-7d18e4383f1f}\InProcServer32]
@="C:\WINDOWS\System32\rrtcany.dll"
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\system32\rrtcany.dll Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
C:\Program Files\iVideoCodec\ Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 9:04:49 PM 11/3/2006
+ Scan result:
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Ignored.
C:\Documents and Settings\Bob Anderson\Local Settings\Temporary Internet Files\Content.IE5\3XB9K0QD\WinAntiVirusPro2006FreeInstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Ignored.
:mozilla.19:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.23:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.24:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.39:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.40:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.89:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.90:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.91:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.92:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.16:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.27:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.98:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.62:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.183:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.184:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.185:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.67:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.132:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.15:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Commission-junction : Cleaned.
:mozilla.16:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Commission-junction : Cleaned.
:mozilla.17:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.31:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.285:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.286:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.292:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.100:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.101:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.102:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.103:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.104:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.105:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.99:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.147:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.250:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.68:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.85:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.305:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.307:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.308:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.317:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.80:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Bob Anderson\Cookies\bob anderson@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.150:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.137:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.138:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.139:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.140:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.148:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.155:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.159:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.162:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.75:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.76:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.77:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.78:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.82:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Bob Anderson\Cookies\bob anderson@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.151:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.152:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.153:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.154:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.165:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.166:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.167:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.168:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.169:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.22:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.23:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.24:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.25:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.227:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.228:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.229:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.230:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.231:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.58:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.59:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.60:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.61:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.265:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.266:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.267:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.186:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.187:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.188:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.189:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.190:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.191:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.192:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.193:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.202:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\LocalService\Cookies\bob anderson@server3.web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.10:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.10:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.11:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.198:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.199:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.200:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.201:C:\Documents and Settings\Bob Anderson\Application Data\Mozilla\Firefox\Profiles\b4pypxd6.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.9:C:\Documents and Settings\Ana Anderson\Application Data\Mozilla\Firefox\Profiles\ev9zwo3g.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
::Report end
So this is the rapport and avg logs. I'll have to post the hijackthis log in another post.
Thanks for the help. Dwayne