Hi! I followed the instructions from Tashi's post of 2006-04-26, and it seems to have worked! Here are my logs. Do they look right? Thanks for your help!
SmitFraudFix v2.65
Scan done at 16:28:37.57, Mon 07/03/2006
Run from C:\Documents and Settings\Kevin\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{a0c51615-738a-4542-801a-5af61614e182}"="bedimples"
[HKEY_CLASSES_ROOT\CLSID\{a0c51615-738a-4542-801a-5af61614e182}\InProcServer32]
@="C:\WINDOWS\system32\higjxe.dll"
[HKEY_CURRENT_USER\Software\Classes\CLSID\{a0c51615-738a-4542-801a-5af61614e182}\InProcServer32]
@="C:\WINDOWS\system32\higjxe.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{62eb0924-19d2-4226-b4b9-8ad1f70904c1}"="bronchovascular"
[HKEY_CLASSES_ROOT\CLSID\{62eb0924-19d2-4226-b4b9-8ad1f70904c1}\InProcServer32]
@="C:\WINDOWS\system32\hvnwm.dll"
[HKEY_CURRENT_USER\Software\Classes\CLSID\{62eb0924-19d2-4226-b4b9-8ad1f70904c1}\InProcServer32]
@="C:\WINDOWS\system32\hvnwm.dll"
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
C:\WINDOWS\system32\higjxe.dll -> Missing File
C:\WINDOWS\system32\hvnwm.dll -> Missing File
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\system32\atmclk.exe Deleted
C:\WINDOWS\system32\dcomcfg.exe Deleted
C:\WINDOWS\system32\ld????.tmp Deleted
C:\WINDOWS\system32\ot.ico Deleted
C:\WINDOWS\system32\simpole.tlb Deleted
C:\WINDOWS\system32\1024\ Deleted
C:\DOCUME~1\Kevin\FAVORI~1\Antivirus Test Online.url Deleted
C:\Program Files\Security Toolbar\ Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 5:53:41 PM 7/3/2006
+ Scan result:
D:\recovered volume 1\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\gdnUS2218.exe -> Downloader.Small.ayl : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\gdnUS2218.exe -> Downloader.Small.czm : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\gdnUS2218.exe -> Downloader.Small.czm : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\gdnUS2218.exe -> Downloader.Small.czm : Cleaned with backup (quarantined).
:mozilla.16:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\e8bxx746.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
D:\recovered volume 1\Documents and Settings\Name\Cookies\name@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
D:\recovered volume 1\Documents and Settings\Name\Cookies\name@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
D:\recovered volume 1\Documents and Settings\Name\Cookies\name@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.14:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\e8bxx746.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.15:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\e8bxx746.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
D:\recovered volume 1\Documents and Settings\Name\Cookies\name@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\WINDOWS\Downloaded Program Files\gdnUS2218.exe -> Trojan.Fakealert : Cleaned with backup (quarantined).
HKU\S-1-5-21-796845957-706699826-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F79FD28E-36EE-4989-AA61-9DD8E30A82FA} -> Trojan.Small : Cleaned with backup (quarantined).
::Report end
SmitFraudFix v2.65
Scan done at 16:28:37.57, Mon 07/03/2006
Run from C:\Documents and Settings\Kevin\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{a0c51615-738a-4542-801a-5af61614e182}"="bedimples"
[HKEY_CLASSES_ROOT\CLSID\{a0c51615-738a-4542-801a-5af61614e182}\InProcServer32]
@="C:\WINDOWS\system32\higjxe.dll"
[HKEY_CURRENT_USER\Software\Classes\CLSID\{a0c51615-738a-4542-801a-5af61614e182}\InProcServer32]
@="C:\WINDOWS\system32\higjxe.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{62eb0924-19d2-4226-b4b9-8ad1f70904c1}"="bronchovascular"
[HKEY_CLASSES_ROOT\CLSID\{62eb0924-19d2-4226-b4b9-8ad1f70904c1}\InProcServer32]
@="C:\WINDOWS\system32\hvnwm.dll"
[HKEY_CURRENT_USER\Software\Classes\CLSID\{62eb0924-19d2-4226-b4b9-8ad1f70904c1}\InProcServer32]
@="C:\WINDOWS\system32\hvnwm.dll"
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
C:\WINDOWS\system32\higjxe.dll -> Missing File
C:\WINDOWS\system32\hvnwm.dll -> Missing File
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\system32\atmclk.exe Deleted
C:\WINDOWS\system32\dcomcfg.exe Deleted
C:\WINDOWS\system32\ld????.tmp Deleted
C:\WINDOWS\system32\ot.ico Deleted
C:\WINDOWS\system32\simpole.tlb Deleted
C:\WINDOWS\system32\1024\ Deleted
C:\DOCUME~1\Kevin\FAVORI~1\Antivirus Test Online.url Deleted
C:\Program Files\Security Toolbar\ Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 5:53:41 PM 7/3/2006
+ Scan result:
D:\recovered volume 1\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\gdnUS2218.exe -> Downloader.Small.ayl : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\gdnUS2218.exe -> Downloader.Small.czm : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\gdnUS2218.exe -> Downloader.Small.czm : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\gdnUS2218.exe -> Downloader.Small.czm : Cleaned with backup (quarantined).
:mozilla.16:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\e8bxx746.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
D:\recovered volume 1\Documents and Settings\Name\Cookies\name@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
D:\recovered volume 1\Documents and Settings\Name\Cookies\name@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
D:\recovered volume 1\Documents and Settings\Name\Cookies\name@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.14:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\e8bxx746.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.15:C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\e8bxx746.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
D:\recovered volume 1\Documents and Settings\Name\Cookies\name@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\WINDOWS\Downloaded Program Files\gdnUS2218.exe -> Trojan.Fakealert : Cleaned with backup (quarantined).
HKU\S-1-5-21-796845957-706699826-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F79FD28E-36EE-4989-AA61-9DD8E30A82FA} -> Trojan.Small : Cleaned with backup (quarantined).
::Report end