I cannot remove Smitfraud-C. and Virtumonde. I thought I might be able to fix this on my own; so, after reading several threads, I installed Smitfraudfix. It hangs at the disk clean-up stage. I am not as clever as I thought. I need the help of an expert.
I have completed the steps outlined in the sticky. Below is the HJT log. The second post is the Kaspersky log. Thanks for your help.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:27:49 PM, on 9/17/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
H:\WINNT\System32\smss.exe
H:\WINNT\system32\winlogon.exe
H:\WINNT\system32\services.exe
H:\WINNT\system32\lsass.exe
H:\WINNT\system32\svchost.exe
H:\WINNT\system32\spoolsv.exe
H:\Program Files\Avira\AntiVir Server\avguard.exe
H:\WINNT\System32\svchost.exe
H:\Program Files\ewido\security suite\ewidoctrl.exe
H:\WINNT\system32\hidserv.exe
H:\WINNT\System32\llssrv.exe
H:\WINNT\System32\nvsvc32.exe
H:\WINNT\system32\regsvc.exe
H:\WINNT\system32\MSTask.exe
H:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
H:\WINNT\system32\stisvc.exe
H:\WINNT\System32\WBEM\WinMgmt.exe
H:\WINNT\system32\svchost.exe
H:\WINNT\system32\Dfssvc.exe
H:\WINNT\System32\msdtc.exe
H:\WINNT\Explorer.EXE
H:\WINNT\System32\svchost.exe
H:\WINNT\TBPanel.exe
H:\Program Files\Common Files\Real\Update_OB\realsched.exe
H:\Program Files\LogMeIn\LogMeInSystray.exe
H:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
H:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
H:\Program Files\Winamp\winampa.exe
H:\Program Files\QuickTime\qttask.exe
H:\Program Files\Micro Innovations\Wireless Keyboard & Optical Mouse\mouse32a.exe
H:\Program Files\Micro Innovations\Wireless Keyboard & Optical Mouse\kbdap32a.exe
H:\Program Files\iTunes\iTunesHelper.exe
H:\Program Files\Windows Media Player\mebelucu4.exe
H:\WINNT\mgrs.exe
H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
H:\PROGRA~1\COMMON~1\ICROSO~1.NET\spoolsv.exe
H:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
H:\Program Files\iPod\bin\iPodService.exe
H:\WINNT\system32\wuauclt.exe
H:\Program Files\Alias\Alias SketchBook Pro 2.0\AliasSketchSnap.exe
H:\Program Files\BUFFALO\Client Manager 2\ClientMgr2.exe
H:\Program Files\Internet Explorer\iexplore.exe
H:\Program Files\Internet Explorer\iexplore.exe
H:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = H:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = H:\windows\system32\blank.htm
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - H:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - h:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [Gainward] H:\WINNT\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "H:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LogMeIn GUI] "H:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [NeroCheck] H:\WINNT\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] H:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [WinampAgent] H:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] H:\Program Files\Micro Innovations\Wireless Keyboard & Optical Mouse\mouse32a.exe
O4 - HKLM\..\Run: [OFFICEKB] H:\Program Files\Micro Innovations\Wireless Keyboard & Optical Mouse\kbdap32a.exe
O4 - HKLM\..\Run: [iTunesHelper] "H:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [outlook] H:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [bantool] H:\WINNT\system32\sdadlrow-t2.exe
O4 - HKLM\..\Run: [g4356cbvy63] H:\WINNT\g4356cbvy63
O4 - HKLM\..\Run: [mebelucu] H:\Program Files\Windows Media Player\mebelucu4.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "H:\WINNT\system32\gvdwwaxg.dll",forkonce
O4 - HKLM\..\Run: [xunkjuni] rundll32.exe "H:\Program Files\xunkjuni\dknmtyhm.dll",Init
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [swg] H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Ocao] "H:\PROGRA~1\COMMON~1\ICROSO~1.NET\spoolsv.exe" -vt yazb
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] H:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: 360Share Pro On Startup.lnk = H:\Program Files\360Share Pro\Gui\360Share Pro.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = H:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = H:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Alias SketchBook Snapshot.lnk = H:\Program Files\Alias\Alias SketchBook Pro 2.0\AliasSketchSnap.exe
O4 - Global Startup: ClientManager2.lnk = H:\Program Files\BUFFALO\Client Manager 2\ClientMgr2.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Betus Poker - {40B2063F-DB01-4962-BE63-59435C01283C} - H:\PROGRA~1\BETUSP~1\client.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - H:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - H:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://H:\Program Files\Autodesk Architectural Desktop 3\AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://H:\Program Files\Autodesk Architectural Desktop 3\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://H:\Program Files\Autodesk Architectural Desktop 3\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://H:\Program Files\Autodesk Architectural Desktop 3\AcPreview.ocx
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\..\{42B9155E-5837-42CA-9427-8FC59E492D45}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{42B9155E-5837-42CA-9427-8FC59E492D45}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{42B9155E-5837-42CA-9427-8FC59E492D45}: NameServer = 192.168.1.1
O20 - AppInit_DLLs: h:\winnt\system32\ldcore.dll
O23 - Service: Avira AntiVir Server (AntiVirService) - AVIRA GmbH - H:\Program Files\Avira\AntiVir Server\avguard.exe
O23 - Service: Avira Internet Update Manager (AVUpdateManager) - AVIRA GmbH - H:\Program Files\Avira\Internet Update Manager\Updmgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - H:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - H:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Google Updater Service (gusvc) - Google - H:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - H:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - H:\WINNT\System32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - H:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 7957 bytes
I have completed the steps outlined in the sticky. Below is the HJT log. The second post is the Kaspersky log. Thanks for your help.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:27:49 PM, on 9/17/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
H:\WINNT\System32\smss.exe
H:\WINNT\system32\winlogon.exe
H:\WINNT\system32\services.exe
H:\WINNT\system32\lsass.exe
H:\WINNT\system32\svchost.exe
H:\WINNT\system32\spoolsv.exe
H:\Program Files\Avira\AntiVir Server\avguard.exe
H:\WINNT\System32\svchost.exe
H:\Program Files\ewido\security suite\ewidoctrl.exe
H:\WINNT\system32\hidserv.exe
H:\WINNT\System32\llssrv.exe
H:\WINNT\System32\nvsvc32.exe
H:\WINNT\system32\regsvc.exe
H:\WINNT\system32\MSTask.exe
H:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
H:\WINNT\system32\stisvc.exe
H:\WINNT\System32\WBEM\WinMgmt.exe
H:\WINNT\system32\svchost.exe
H:\WINNT\system32\Dfssvc.exe
H:\WINNT\System32\msdtc.exe
H:\WINNT\Explorer.EXE
H:\WINNT\System32\svchost.exe
H:\WINNT\TBPanel.exe
H:\Program Files\Common Files\Real\Update_OB\realsched.exe
H:\Program Files\LogMeIn\LogMeInSystray.exe
H:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
H:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
H:\Program Files\Winamp\winampa.exe
H:\Program Files\QuickTime\qttask.exe
H:\Program Files\Micro Innovations\Wireless Keyboard & Optical Mouse\mouse32a.exe
H:\Program Files\Micro Innovations\Wireless Keyboard & Optical Mouse\kbdap32a.exe
H:\Program Files\iTunes\iTunesHelper.exe
H:\Program Files\Windows Media Player\mebelucu4.exe
H:\WINNT\mgrs.exe
H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
H:\PROGRA~1\COMMON~1\ICROSO~1.NET\spoolsv.exe
H:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
H:\Program Files\iPod\bin\iPodService.exe
H:\WINNT\system32\wuauclt.exe
H:\Program Files\Alias\Alias SketchBook Pro 2.0\AliasSketchSnap.exe
H:\Program Files\BUFFALO\Client Manager 2\ClientMgr2.exe
H:\Program Files\Internet Explorer\iexplore.exe
H:\Program Files\Internet Explorer\iexplore.exe
H:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = H:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = H:\windows\system32\blank.htm
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - H:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - h:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [Gainward] H:\WINNT\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "H:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LogMeIn GUI] "H:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [NeroCheck] H:\WINNT\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] H:\WINNT\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [WinampAgent] H:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] H:\Program Files\Micro Innovations\Wireless Keyboard & Optical Mouse\mouse32a.exe
O4 - HKLM\..\Run: [OFFICEKB] H:\Program Files\Micro Innovations\Wireless Keyboard & Optical Mouse\kbdap32a.exe
O4 - HKLM\..\Run: [iTunesHelper] "H:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [outlook] H:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [bantool] H:\WINNT\system32\sdadlrow-t2.exe
O4 - HKLM\..\Run: [g4356cbvy63] H:\WINNT\g4356cbvy63
O4 - HKLM\..\Run: [mebelucu] H:\Program Files\Windows Media Player\mebelucu4.exe
O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "H:\WINNT\system32\gvdwwaxg.dll",forkonce
O4 - HKLM\..\Run: [xunkjuni] rundll32.exe "H:\Program Files\xunkjuni\dknmtyhm.dll",Init
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [swg] H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Ocao] "H:\PROGRA~1\COMMON~1\ICROSO~1.NET\spoolsv.exe" -vt yazb
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] H:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: 360Share Pro On Startup.lnk = H:\Program Files\360Share Pro\Gui\360Share Pro.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = H:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = H:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Alias SketchBook Snapshot.lnk = H:\Program Files\Alias\Alias SketchBook Pro 2.0\AliasSketchSnap.exe
O4 - Global Startup: ClientManager2.lnk = H:\Program Files\BUFFALO\Client Manager 2\ClientMgr2.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - H:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Betus Poker - {40B2063F-DB01-4962-BE63-59435C01283C} - H:\PROGRA~1\BETUSP~1\client.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - H:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - H:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://H:\Program Files\Autodesk Architectural Desktop 3\AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://H:\Program Files\Autodesk Architectural Desktop 3\InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://H:\Program Files\Autodesk Architectural Desktop 3\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://H:\Program Files\Autodesk Architectural Desktop 3\AcPreview.ocx
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\..\{42B9155E-5837-42CA-9427-8FC59E492D45}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{42B9155E-5837-42CA-9427-8FC59E492D45}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{42B9155E-5837-42CA-9427-8FC59E492D45}: NameServer = 192.168.1.1
O20 - AppInit_DLLs: h:\winnt\system32\ldcore.dll
O23 - Service: Avira AntiVir Server (AntiVirService) - AVIRA GmbH - H:\Program Files\Avira\AntiVir Server\avguard.exe
O23 - Service: Avira Internet Update Manager (AVUpdateManager) - AVIRA GmbH - H:\Program Files\Avira\Internet Update Manager\Updmgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - H:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - H:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Google Updater Service (gusvc) - Google - H:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - H:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - H:\WINNT\System32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - H:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
--
End of file - 7957 bytes