jroberts2001
New member
PLEASE HELP!!
I think I have a nasty infection of Smitfraud-C and Zlob that Spybot tries to remove but 3 or 4 items stay resident even after a reboot scan and then they start to multiply. I have read the "Before you Post" thread, have downloaded and ran the SmitFraudFix v2.304 and the "rapport.txt" is attached below. After reading other posts on this forum, I realize that I stupidly allowed a "video codec" to install and now I'm hosed!
I have used religiously used Spybot for 4 or 5 years along with either McAfee or Symantec AV. I am currently using Norton 360 (From Symantec) along with Windows Defender on a WinXP desktop. Based on the posts to other Smitfraud-C problems, I am currently running the Kaspersky Online Scanner and will post those results when it finishes. I'm not a professional computer expert but condsider myself to be very advanced and not afraid to do what it takes to get rid of this crap!
Would someone please help me??
THANKS IN ADVANCE!!
***********************************************************************************
The "Rapport.txt" file starts here:
SmitFraudFix v2.304
Scan done at 10:45:18.73, Sat 03/15/2008
Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\antiviirus.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\tmp0.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Owner\FAVORI~1
C:\DOCUME~1\Owner\FAVORI~1\Online Security Test.url FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
C:\Program Files\tmp???????.exe FOUND !
C:\Program Files\antiviirus.exe FOUND !
C:\Program Files\Helper\ FOUND !
C:\Program Files\tmp?.exe FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, following keys are not inevitably infected!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
+--------------------------------------------------+
[!] Suspicious: drnpfdxwlv.dll
BHO: GNX Rolex - {0D504883-70CA-48BD-A282-639753D3B0CE}
TypeLib: {BD2F88C5-20F9-4999-BC1C-7F1632AD141B}
Interface: {49B61FB5-29FA-421A-8725-E926DD1553DD}
Interface: {8B4B7425-C419-4E82-9927-174656EFD307}
[!] Suspicious: altvxvm.dll
SSODL: altvxvm - {92A19031-BC4D-452E-8E6D-0843B6BF6838}
[!] Suspicious: bokpkov.dll
SSODL: bokpkov - {D3CF1643-A5C5-40BB-B52F-8B815892ACB0}
[!] Suspicious: ServiceSrv.dll
SSODL: ServiceSrv - {1761d5fe-d1ab-4008-bf6b-0e6222e62b17}
[!] Suspicious: zip.dll
SSODL: zip - {2a116f4d-d2c1-4c56-a3ab-6f6001395212}
[!] Suspicious: RunOnceDrv.dll
SSODL: RunOnceDrv - {25432165-73a6-4c4b-bd65-85484764dc1e}
[!] Suspicious: ServiceDrv.dll
SSODL: ServiceDrv - {0281259a-f3d8-4e0a-b820-16ff720db35a}
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Broadcom 440x 10/100 Integrated Controller - Packet Scheduler Miniport
DNS Server Search Order: 63.64.9.12
DNS Server Search Order: 63.64.9.20
HKLM\SYSTEM\CCS\Services\Tcpip\..\{A93A97DC-D357-419E-AF59-28F9181220F6}: DhcpNameServer=63.64.9.12 63.64.9.20
HKLM\SYSTEM\CS1\Services\Tcpip\..\{A93A97DC-D357-419E-AF59-28F9181220F6}: DhcpNameServer=63.64.9.12 63.64.9.20
HKLM\SYSTEM\CS3\Services\Tcpip\..\{A93A97DC-D357-419E-AF59-28F9181220F6}: DhcpNameServer=63.64.9.12 63.64.9.20
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=63.64.9.12 63.64.9.20
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=63.64.9.12 63.64.9.20
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=63.64.9.12 63.64.9.20
»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
I think I have a nasty infection of Smitfraud-C and Zlob that Spybot tries to remove but 3 or 4 items stay resident even after a reboot scan and then they start to multiply. I have read the "Before you Post" thread, have downloaded and ran the SmitFraudFix v2.304 and the "rapport.txt" is attached below. After reading other posts on this forum, I realize that I stupidly allowed a "video codec" to install and now I'm hosed!
I have used religiously used Spybot for 4 or 5 years along with either McAfee or Symantec AV. I am currently using Norton 360 (From Symantec) along with Windows Defender on a WinXP desktop. Based on the posts to other Smitfraud-C problems, I am currently running the Kaspersky Online Scanner and will post those results when it finishes. I'm not a professional computer expert but condsider myself to be very advanced and not afraid to do what it takes to get rid of this crap!
Would someone please help me??
THANKS IN ADVANCE!!
***********************************************************************************
The "Rapport.txt" file starts here:
SmitFraudFix v2.304
Scan done at 10:45:18.73, Sat 03/15/2008
Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\antiviirus.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\tmp0.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Owner\FAVORI~1
C:\DOCUME~1\Owner\FAVORI~1\Online Security Test.url FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
C:\Program Files\tmp???????.exe FOUND !
C:\Program Files\antiviirus.exe FOUND !
C:\Program Files\Helper\ FOUND !
C:\Program Files\tmp?.exe FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, following keys are not inevitably infected!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
+--------------------------------------------------+
[!] Suspicious: drnpfdxwlv.dll
BHO: GNX Rolex - {0D504883-70CA-48BD-A282-639753D3B0CE}
TypeLib: {BD2F88C5-20F9-4999-BC1C-7F1632AD141B}
Interface: {49B61FB5-29FA-421A-8725-E926DD1553DD}
Interface: {8B4B7425-C419-4E82-9927-174656EFD307}
[!] Suspicious: altvxvm.dll
SSODL: altvxvm - {92A19031-BC4D-452E-8E6D-0843B6BF6838}
[!] Suspicious: bokpkov.dll
SSODL: bokpkov - {D3CF1643-A5C5-40BB-B52F-8B815892ACB0}
[!] Suspicious: ServiceSrv.dll
SSODL: ServiceSrv - {1761d5fe-d1ab-4008-bf6b-0e6222e62b17}
[!] Suspicious: zip.dll
SSODL: zip - {2a116f4d-d2c1-4c56-a3ab-6f6001395212}
[!] Suspicious: RunOnceDrv.dll
SSODL: RunOnceDrv - {25432165-73a6-4c4b-bd65-85484764dc1e}
[!] Suspicious: ServiceDrv.dll
SSODL: ServiceDrv - {0281259a-f3d8-4e0a-b820-16ff720db35a}
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: Broadcom 440x 10/100 Integrated Controller - Packet Scheduler Miniport
DNS Server Search Order: 63.64.9.12
DNS Server Search Order: 63.64.9.20
HKLM\SYSTEM\CCS\Services\Tcpip\..\{A93A97DC-D357-419E-AF59-28F9181220F6}: DhcpNameServer=63.64.9.12 63.64.9.20
HKLM\SYSTEM\CS1\Services\Tcpip\..\{A93A97DC-D357-419E-AF59-28F9181220F6}: DhcpNameServer=63.64.9.12 63.64.9.20
HKLM\SYSTEM\CS3\Services\Tcpip\..\{A93A97DC-D357-419E-AF59-28F9181220F6}: DhcpNameServer=63.64.9.12 63.64.9.20
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=63.64.9.12 63.64.9.20
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=63.64.9.12 63.64.9.20
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=63.64.9.12 63.64.9.20
»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End