This thing is a pain. I got it early this morning and have literally been sitting here all day trying to remove it. I've gotten rid of about 99% of the pop-ups, but I want this thing gone for good. My computer is running much slower than it has ever before. I have a paper to write and I'm sick of dealing with this. Spybot keeps telling me I have Smitfraud-C.CoreService, and when I try to "fix selected problems" spybot can NEVER delete HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\core
Please Help! I have a Spybot, HiJackThis, and SDFix log. I'll post them all here. I use Norton Anti-Virus Corporate Edition, Spybot, AdAware, and Windows Defender. I've also disabled my system restore, as I read that it was good to do with this particular malicious software.
SDFix Log:
SDFix: Version 1.94
Run by Jonathan W on Fri 07/27/2007 at 10:05 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\JONATH~1\Desktop\SDFix\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Resetting AppInit_DLLs value
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\Documents and Settings\LocalService\Local Settings\Temp\2.dllb - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\2.dllb - Deleted
C:\WINDOWS\csrss.exe - Deleted
C:\WINDOWS\system32\ldcore.dll - Deleted
C:\WINDOWS\system32\ldinfo.ldr - Deleted
C:\WINDOWS\tcb.pmw - Deleted
C:\WINDOWS\wr.txt - Deleted
Folder C:\WINDOWS\system32\b06FdUe - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1133234765\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1133234765\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\1133234765\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1133234765\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\BitLord\\BitLord.exe"="C:\\Program Files\\BitLord\\BitLord.exe:*:Enabled:BitLord"
"C:\\Program Files\\Soulseek\\slsk.exe"="C:\\Program Files\\Soulseek\\slsk.exe:*:Enabled:SoulSeek"
"C:\\Program Files\\The Princeton Review\\Practice Test System\\Practice Test System\\Practice Test System.exe"="C:\\Program Files\\The Princeton Review\\Practice Test System\\Practice Test System\\Practice Test System.exe:*:Enabled:Macromedia Projector"
"C:\\Program Files\\Trillian\\trillian.exe"="C:\\Program Files\\Trillian\\trillian.exe:*:Enabled:Trillian"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled
xpsp3res.dll,-20000"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\WINDOWS\\TEMP\\win1AB.tmp.exe"="C:\\WINDOWS\\TEMP\\win1AB.tmp.exe:*:Enabled:win1AB.tmp"
"C:\\Program Files\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe"="C:\\Program Files\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe:*:Enabled:Roxio Upnp Service"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled
xpsp3res.dll,-20000"
Remaining Files:
---------------
Backups Folder: - C:\DOCUME~1\JONATH~1\Desktop\SDFix\SDFix\backups\backups.zip
Files with Hidden Attributes:
C:\Documents and Settings\Jonathan W\NetHood\ftp.gcr1.com\Desktop.ini
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\gcshthpA.exe
C:\WINDOWS\system32\33ABE1A679.sys
C:\WINDOWS\system32\KGyGaAvL.sys
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and Settings\Jonathan W\Application Data\Microsoft\Word\~WRL0342.tmp
C:\Documents and Settings\Jonathan W\Application Data\Microsoft\Word\~WRL0673.tmp
C:\Documents and Settings\Jonathan W\Application Data\Microsoft\Word\~WRL1848.tmp
C:\Documents and Settings\Jonathan W\Application Data\Roxio\Dragon\3.x\DiscInfoCache\TSSTcorp_DVD+-RW_TS-L532B_DE03_300_DICV018_DRGV300002C.TMP
C:\Documents and Settings\Jonathan W\Desktop\~WRL0145.tmp
C:\Documents and Settings\Jonathan W\Desktop\~WRL0164.tmp
C:\Documents and Settings\Jonathan W\Desktop\~WRL0386.tmp
C:\Documents and Settings\Jonathan W\Desktop\~WRL0836.tmp
C:\Documents and Settings\Jonathan W\Desktop\~WRL3129.tmp
Finished
Please Help! I have a Spybot, HiJackThis, and SDFix log. I'll post them all here. I use Norton Anti-Virus Corporate Edition, Spybot, AdAware, and Windows Defender. I've also disabled my system restore, as I read that it was good to do with this particular malicious software.
SDFix Log:
SDFix: Version 1.94
Run by Jonathan W on Fri 07/27/2007 at 10:05 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\JONATH~1\Desktop\SDFix\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Resetting AppInit_DLLs value
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\Documents and Settings\LocalService\Local Settings\Temp\2.dllb - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\2.dllb - Deleted
C:\WINDOWS\csrss.exe - Deleted
C:\WINDOWS\system32\ldcore.dll - Deleted
C:\WINDOWS\system32\ldinfo.ldr - Deleted
C:\WINDOWS\tcb.pmw - Deleted
C:\WINDOWS\wr.txt - Deleted
Folder C:\WINDOWS\system32\b06FdUe - Removed
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1133234765\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1133234765\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\1133234765\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1133234765\\ee\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\BitLord\\BitLord.exe"="C:\\Program Files\\BitLord\\BitLord.exe:*:Enabled:BitLord"
"C:\\Program Files\\Soulseek\\slsk.exe"="C:\\Program Files\\Soulseek\\slsk.exe:*:Enabled:SoulSeek"
"C:\\Program Files\\The Princeton Review\\Practice Test System\\Practice Test System\\Practice Test System.exe"="C:\\Program Files\\The Princeton Review\\Practice Test System\\Practice Test System\\Practice Test System.exe:*:Enabled:Macromedia Projector"
"C:\\Program Files\\Trillian\\trillian.exe"="C:\\Program Files\\Trillian\\trillian.exe:*:Enabled:Trillian"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\WINDOWS\\TEMP\\win1AB.tmp.exe"="C:\\WINDOWS\\TEMP\\win1AB.tmp.exe:*:Enabled:win1AB.tmp"
"C:\\Program Files\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe"="C:\\Program Files\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe:*:Enabled:Roxio Upnp Service"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled
Remaining Files:
---------------
Backups Folder: - C:\DOCUME~1\JONATH~1\Desktop\SDFix\SDFix\backups\backups.zip
Files with Hidden Attributes:
C:\Documents and Settings\Jonathan W\NetHood\ftp.gcr1.com\Desktop.ini
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\gcshthpA.exe
C:\WINDOWS\system32\33ABE1A679.sys
C:\WINDOWS\system32\KGyGaAvL.sys
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch5\lock.tmp
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and Settings\Jonathan W\Application Data\Microsoft\Word\~WRL0342.tmp
C:\Documents and Settings\Jonathan W\Application Data\Microsoft\Word\~WRL0673.tmp
C:\Documents and Settings\Jonathan W\Application Data\Microsoft\Word\~WRL1848.tmp
C:\Documents and Settings\Jonathan W\Application Data\Roxio\Dragon\3.x\DiscInfoCache\TSSTcorp_DVD+-RW_TS-L532B_DE03_300_DICV018_DRGV300002C.TMP
C:\Documents and Settings\Jonathan W\Desktop\~WRL0145.tmp
C:\Documents and Settings\Jonathan W\Desktop\~WRL0164.tmp
C:\Documents and Settings\Jonathan W\Desktop\~WRL0386.tmp
C:\Documents and Settings\Jonathan W\Desktop\~WRL0836.tmp
C:\Documents and Settings\Jonathan W\Desktop\~WRL3129.tmp
Finished