Dolphinsmile
2006-11-30, 01:35
I was recently a victim of the yahoo messenger worm. I need to get rid of that and fix any other problems I have.
Here goes:
SmitFraudFix v2.125
Scan done at 11:41:09.65, Wed 11/29/2006
Run from C:\Documents and Settings\sams club 8261\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 4:32:25 PM 11/29/2006
+ Scan result:
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
E:\STUFF\Programs\New Programs\hacking passes.zip/ad3_hola2.exe/CD_Gif.dll -> Adware.Cydoor : Cleaned with backup (quarantined).
E:\STUFF\Programs\New Programs\hacking passes.zip/ad3_hola2.exe/cd_clint.dll -> Adware.Cydoor : Cleaned with backup (quarantined).
E:\STUFF\Programs\New Programs\hacking passes.zip/ad3_hola2.exe/cd_load.exe -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1555576864-3477723857-56604596-1005\Software\DelFin -> Adware.Delfin : Cleaned with backup (quarantined).
HKU\S-1-5-21-1555576864-3477723857-56604596-1005\Software\DelFin\PromulGate -> Adware.Delfin : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175964.exe -> Adware.DropSpam : Cleaned with backup (quarantined).
C:\Program Files\iWon\iWonBar\1.bin\I1POPSWT.DLL -> Adware.Funweb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1142\A0175891.DLL -> Adware.FunWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175934.dll -> Adware.FunWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175940.DLL -> Adware.FunWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175947.DLL -> Adware.FunWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175948.EXE -> Adware.FunWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175951.DLL -> Adware.FunWeb : Cleaned with backup (quarantined).
HKU\S-1-5-21-1555576864-3477723857-56604596-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2DEA8791-C2B7-48E1-8992-8E8E6A6FE789} -> Adware.Generic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175907.exe -> Adware.HotBar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175911.dll -> Adware.HotBar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1164\A0178424.exe -> Adware.HotBar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1164\A0178427.dll -> Adware.HotBar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175954.DLL -> Adware.IWon : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175970.EXE -> Adware.MyWebSearch : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall4_34.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall4_80.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\appupdate.exe -> Adware.Nexus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1206\A0186236.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1206\A0186237.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1206\A0186238.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1206\A0186240.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1206\A0186241.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00105633.exe -> Adware.Wildtangent : Cleaned with backup (quarantined).
C:\WINDOWS\IFinst25.exe -> Backdoor.Ifinst : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175942.DLL -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\My Documents\Data\Data\popinstlite.exe -> Downloader.Poplite.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\My Documents\Data\popinstlite.exe -> Downloader.Poplite.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Default User\My Documents\Data\Data\popinstlite.exe -> Downloader.Poplite.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Default User\My Documents\Data\popinstlite.exe -> Downloader.Poplite.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1205\A0186151.exe -> Downloader.Small : Cleaned with backup (quarantined).
E:\STUFF\Davids Folder\FUNNY STUFF\9coronas.exe -> Not-A-Virus.BadJoke.Win32.Stupen.c : Ignored.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@servedby.advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@centrport[1].txt -> TrackingCookie.Centrport : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@clickagents[1].txt -> TrackingCookie.Clickagents : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@hotlog[1].txt -> TrackingCookie.Hotlog : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@adserv.internetfuel[1].txt -> TrackingCookie.Internetfuel : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@nitrous.internetfuel[1].txt -> TrackingCookie.Internetfuel : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@oxcash[2].txt -> TrackingCookie.Oxcash : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@paycounter[2].txt -> TrackingCookie.Paycounter : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@www.qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@www.realcastmedia[2].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@spylog[1].txt -> TrackingCookie.Spylog : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@x10[1].txt -> TrackingCookie.X10 : Cleaned.
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1206\A0186232.exe -> Trojan.Imiserv.c : Cleaned with backup (quarantined).
C:\WINDOWS\aad.exe -> Trojan.Imiserv.c : Cleaned with backup (quarantined).
::Report end
hijackthis log on next post
Here goes:
SmitFraudFix v2.125
Scan done at 11:41:09.65, Wed 11/29/2006
Run from C:\Documents and Settings\sams club 8261\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 4:32:25 PM 11/29/2006
+ Scan result:
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
E:\STUFF\Programs\New Programs\hacking passes.zip/ad3_hola2.exe/CD_Gif.dll -> Adware.Cydoor : Cleaned with backup (quarantined).
E:\STUFF\Programs\New Programs\hacking passes.zip/ad3_hola2.exe/cd_clint.dll -> Adware.Cydoor : Cleaned with backup (quarantined).
E:\STUFF\Programs\New Programs\hacking passes.zip/ad3_hola2.exe/cd_load.exe -> Adware.Cydoor : Cleaned with backup (quarantined).
HKU\S-1-5-21-1555576864-3477723857-56604596-1005\Software\DelFin -> Adware.Delfin : Cleaned with backup (quarantined).
HKU\S-1-5-21-1555576864-3477723857-56604596-1005\Software\DelFin\PromulGate -> Adware.Delfin : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175964.exe -> Adware.DropSpam : Cleaned with backup (quarantined).
C:\Program Files\iWon\iWonBar\1.bin\I1POPSWT.DLL -> Adware.Funweb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1142\A0175891.DLL -> Adware.FunWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175934.dll -> Adware.FunWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175940.DLL -> Adware.FunWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175947.DLL -> Adware.FunWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175948.EXE -> Adware.FunWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175951.DLL -> Adware.FunWeb : Cleaned with backup (quarantined).
HKU\S-1-5-21-1555576864-3477723857-56604596-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2DEA8791-C2B7-48E1-8992-8E8E6A6FE789} -> Adware.Generic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175907.exe -> Adware.HotBar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175911.dll -> Adware.HotBar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1164\A0178424.exe -> Adware.HotBar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1164\A0178427.dll -> Adware.HotBar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175954.DLL -> Adware.IWon : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175970.EXE -> Adware.MyWebSearch : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall4_34.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall4_80.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\appupdate.exe -> Adware.Nexus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1206\A0186236.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1206\A0186237.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1206\A0186238.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1206\A0186240.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1206\A0186241.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\RECYCLER\NPROTECT\00105633.exe -> Adware.Wildtangent : Cleaned with backup (quarantined).
C:\WINDOWS\IFinst25.exe -> Backdoor.Ifinst : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1143\A0175942.DLL -> Downloader.IstBar : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\My Documents\Data\Data\popinstlite.exe -> Downloader.Poplite.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\My Documents\Data\popinstlite.exe -> Downloader.Poplite.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Default User\My Documents\Data\Data\popinstlite.exe -> Downloader.Poplite.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Default User\My Documents\Data\popinstlite.exe -> Downloader.Poplite.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1205\A0186151.exe -> Downloader.Small : Cleaned with backup (quarantined).
E:\STUFF\Davids Folder\FUNNY STUFF\9coronas.exe -> Not-A-Virus.BadJoke.Win32.Stupen.c : Ignored.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@servedby.advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@centrport[1].txt -> TrackingCookie.Centrport : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@clickagents[1].txt -> TrackingCookie.Clickagents : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@hotlog[1].txt -> TrackingCookie.Hotlog : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@adserv.internetfuel[1].txt -> TrackingCookie.Internetfuel : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@nitrous.internetfuel[1].txt -> TrackingCookie.Internetfuel : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@oxcash[2].txt -> TrackingCookie.Oxcash : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@paycounter[2].txt -> TrackingCookie.Paycounter : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@www.qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned.
C:\Documents and Settings\LocalService\Cookies\system@www.realcastmedia[2].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@spylog[1].txt -> TrackingCookie.Spylog : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\Linda Younger\Cookies\linda younger@x10[1].txt -> TrackingCookie.X10 : Cleaned.
C:\System Volume Information\_restore{D0AB5F7B-0459-416C-9608-1E15FDE4DE5A}\RP1206\A0186232.exe -> Trojan.Imiserv.c : Cleaned with backup (quarantined).
C:\WINDOWS\aad.exe -> Trojan.Imiserv.c : Cleaned with backup (quarantined).
::Report end
hijackthis log on next post