I have some malware that keeps giving me unwanted pop-ups. Spybot keeps finding smithfraud-c.toolbar888, which keeps coming back. My AVG anti-virus found collected.11.b during a scan.
Here is my HJK log:
Logfile of HijackThis v1.99.1
Scan saved at 1:57:04 AM, on 4/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Cisco-Linksys LLC\Wireless-G Notebook Adapter with SRX400\WPC54GX4.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LA.EXE /P24 "EPSON Stylus Photo R1800" /O6 "USB002" /M "Stylus Photo R1800"
O4 - HKLM\..\Run: [RunUtility] C:\Program Files\Cisco-Linksys LLC\Wireless-G Notebook Adapter with SRX400\WPC54GX4.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Atii2odtu-e9 - ATI Technologies Inc. - (no file)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
I did the Panda online virus scan, and it found a bunch of stuff:
Incident Status Location
Adware:adware/cashsaver Not disinfected c:\windows\system32\CSUninstall.exe
Adware:adware/sbsoft Not disinfected Windows Registry
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\_\Application Data\Mozilla\Firefox\Profiles\3jmj4u2i.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\_\Application Data\Mozilla\Firefox\Profiles\3jmj4u2i.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\_\Application Data\Mozilla\Firefox\Profiles\3jmj4u2i.default\cookies.txt[.com.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\_\Application Data\Mozilla\Firefox\Profiles\3jmj4u2i.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\_\Cookies\_@anm.co[1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\_\Cookies\_@atwola[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\_\Cookies\_@belnk[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\_\Cookies\_@burstnet[2].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\_\Cookies\_@ccbill[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\_\Cookies\_@cgi-bin[6].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\_\Cookies\_@cgi-bin[8].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\_\Cookies\_@com[1].txt
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\_\Cookies\_@ct.360i[2].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\_\Cookies\_@did-it[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\_\Cookies\_@dist.belnk[2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\_\Cookies\_@gostats[2].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\_\Cookies\_@go[2].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\_\Cookies\_@kinghost[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\_\Cookies\_@stats1.reliablestats[1].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\_\Cookies\_@target[1].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\_\Cookies\_@winantivirus[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\_\Cookies\_@www.burstbeacon[2].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\_\Cookies\_@www.myaffiliateprogram[1].txt
Spyware:Cookie/web-stat Not disinfected C:\Documents and Settings\_\Cookies\_@www.web-stat[2].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\_\Cookies\_@xiti[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\_\Cookies\_@yadro[1].txt
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Documents and Settings\_\Local Settings\Temporary Internet Files\Content.IE5\6VY36DIR\WinAntiVirusPro2007FreeInstall[1].cab[UWA7P_0001_N91M0809NetInstaller.exe]
Adware:Adware Program Not disinfected C:\Temp\Hjk\backups\backup-20040829-230206-805.inf
Adware:Adware/MediaTickets Not disinfected C:\Temp\Hjk\backups\backup-20040829-230206-838
Adware:Adware/MediaTickets Not disinfected C:\Temp\Hjk\backups\backup-20040829-230206-838.inf
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\ywmamsfu.dll
Can anyone suggest anything?
Thanks.
Here is my HJK log:
Logfile of HijackThis v1.99.1
Scan saved at 1:57:04 AM, on 4/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Cisco-Linksys LLC\Wireless-G Notebook Adapter with SRX400\WPC54GX4.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EPSON Stylus Photo R1800] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9LA.EXE /P24 "EPSON Stylus Photo R1800" /O6 "USB002" /M "Stylus Photo R1800"
O4 - HKLM\..\Run: [RunUtility] C:\Program Files\Cisco-Linksys LLC\Wireless-G Notebook Adapter with SRX400\WPC54GX4.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Atii2odtu-e9 - ATI Technologies Inc. - (no file)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
I did the Panda online virus scan, and it found a bunch of stuff:
Incident Status Location
Adware:adware/cashsaver Not disinfected c:\windows\system32\CSUninstall.exe
Adware:adware/sbsoft Not disinfected Windows Registry
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\_\Application Data\Mozilla\Firefox\Profiles\3jmj4u2i.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\_\Application Data\Mozilla\Firefox\Profiles\3jmj4u2i.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\_\Application Data\Mozilla\Firefox\Profiles\3jmj4u2i.default\cookies.txt[.com.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\_\Application Data\Mozilla\Firefox\Profiles\3jmj4u2i.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\_\Cookies\_@anm.co[1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\_\Cookies\_@atwola[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\_\Cookies\_@belnk[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\_\Cookies\_@burstnet[2].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\_\Cookies\_@ccbill[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\_\Cookies\_@cgi-bin[6].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\_\Cookies\_@cgi-bin[8].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\_\Cookies\_@com[1].txt
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\_\Cookies\_@ct.360i[2].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\_\Cookies\_@did-it[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\_\Cookies\_@dist.belnk[2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\_\Cookies\_@gostats[2].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\_\Cookies\_@go[2].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\_\Cookies\_@kinghost[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\_\Cookies\_@stats1.reliablestats[1].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\_\Cookies\_@target[1].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\_\Cookies\_@winantivirus[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\_\Cookies\_@www.burstbeacon[2].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\_\Cookies\_@www.myaffiliateprogram[1].txt
Spyware:Cookie/web-stat Not disinfected C:\Documents and Settings\_\Cookies\_@www.web-stat[2].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\_\Cookies\_@xiti[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\_\Cookies\_@yadro[1].txt
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Documents and Settings\_\Local Settings\Temporary Internet Files\Content.IE5\6VY36DIR\WinAntiVirusPro2007FreeInstall[1].cab[UWA7P_0001_N91M0809NetInstaller.exe]
Adware:Adware Program Not disinfected C:\Temp\Hjk\backups\backup-20040829-230206-805.inf
Adware:Adware/MediaTickets Not disinfected C:\Temp\Hjk\backups\backup-20040829-230206-838
Adware:Adware/MediaTickets Not disinfected C:\Temp\Hjk\backups\backup-20040829-230206-838.inf
Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\SYSTEM32\ywmamsfu.dll
Can anyone suggest anything?
Thanks.