Unsolved

This post is more than 5 years old

1 Message

2206

July 12th, 2005 17:00

PLEASE help.. removing spoolsrv32 and smitfraud.c

:womansad:Please please help.. am getting desperate.
I have a blue screen background telling me I have smitfraud.c but everything seems to be working ok apart from that although obviously my laptop is very sick..

I have tried all sorts of spyware detection and removel - killbox, Xoftspy, Ewido... still no luck. Can someone help me please?

My HijackThis log is below...

Logfile of HijackThis v1.99.1
Scan saved at 18:50:16, on 12/07/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\PJ Technologies\GOVsrv\GOVsrv.EXE
C:\PROGRA~1\Reuters\Apps\Rua\bin\w32-ix86\mrt\lcfd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\OfficeScan NT\ntrtscan.exe
C:\OfficeScan NT\OfcPfwSvc.exe
C:\Program Files\Novadigm\radexecd.exe
C:\Program Files\Novadigm\radsched.exe
C:\Program Files\Novadigm\Radstgms.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\OfficeScan NT\tmlisten.exe
C:\WINDOWS\TEMP\IBBD5E.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\tp4mon.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\OfficeScan NT\pccntmon.exe
C:\Program Files\Cisco Systems\Aironet Client Monitor\ACUMon.Exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\iPass\iPassConnect\downloader\ipccheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Reuters\Apps\Rua\bin\w32-ix86\mrt\lcfep.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Nortel Networks\Extranet.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\unzipped\hijackthis[1]\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ime.reuters.com/dailybriefing/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ime.reuters.com/dailybriefing/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Reuters Global Desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://wtd.ime.reuters.com/proxy.pac
O2 - BHO: CIEExtension Object - {B51DC573-E998-4834-9B45-BAB7C2AE0A75} - C:\Program Files\Ad-Protect\ADPIEmonitor.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Furl Toolbar - {74E677D9-0F37-4654-85E9-02F36AA295EB} - C:\Program Files\Furl Toolbar\tbu2\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [TivoliGetUsername] C:\WINDOWS\System32\cscript.exe //B //nologo C:\PROGRA~1\Reuters\INVENT~1\GETUSE~1.VBS
O4 - HKLM\..\Run: [TivoliGetUser] C:\PROGRA~1\Reuters\INVENT~1\TIVOLI~1.EXE
O4 - HKLM\..\Run: [ACUMon] "C:\Program Files\Cisco Systems\Aironet Client Monitor\ACUMon.Exe" -a
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [iPCCheck] "C:\Program Files\iPass\iPassConnect\downloader\ipccheck.exe" /startup
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [lcfep] "C:\PROGRA~1\Reuters\Apps\Rua\bin\w32-ix86\mrt\lcfep.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [AS00_Gear511] C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe -hide
O4 - HKLM\..\Run: [Media Gateway] C:\Program Files\Media Gateway\MediaGateway.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [STManager] "C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b
O4 - Global Startup: iPassConnect.lnk = C:\Program Files\iPass\iPassConnect\IPassConnectGUI.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Oracle Logon - {6FD8B8B1-47EF-40E1-880D-BE4C0C0E78FC} - https://issunas1.uki.ime.reuters.co...US/prdwwoa6.htm (file missing)
O9 - Extra 'Tools' menuitem: Oracle Logon - {6FD8B8B1-47EF-40E1-880D-BE4C0C0E78FC} - https://issunas1.uki.ime.reuters.co...US/prdwwoa6.htm (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Product A-Z - {A38E2734-24B9-4936-BDFA-30AF9C55FE5D} - http://paz.hpg.ime.reuters.com/portal/products.cfm (file missing)
O9 - Extra 'Tools' menuitem: Product A-Z - {A38E2734-24B9-4936-BDFA-30AF9C55FE5D} - http://paz.hpg.ime.reuters.com/portal/products.cfm (file missing)
O9 - Extra button: Customer Zone - {B284B9AB-2069-4172-8EE0-C6E696167B11} - http://www.reuters.com/customers (file missing)
O9 - Extra 'Tools' menuitem: Customer Zone - {B284B9AB-2069-4172-8EE0-C6E696167B11} - http://www.reuters.com/customers (file missing)
O9 - Extra button: ITS Services - {B3990768-7F7D-45CE-A067-9ADD73A6377C} - http://www.ime.reuters.com/CIO/ITSERVICES (file missing)
O9 - Extra 'Tools' menuitem: ITS Services - {B3990768-7F7D-45CE-A067-9ADD73A6377C} - http://www.ime.reuters.com/CIO/ITSERVICES (file missing)
O9 - Extra button: GED - {B76D9349-72DA-4FD0-A1DF-579D5A8C9837} - http://www.ime.reuters.com/GED (file missing)
O9 - Extra 'Tools' menuitem: GED - {B76D9349-72DA-4FD0-A1DF-579D5A8C9837} - http://www.ime.reuters.com/GED (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\bmi_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bmi_lsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\bmi_lsp.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\PLUGINS\NPDocBox.dll
O16 - DPF: {0a454840-7232-11d5-b63d-00c04faedb18} -
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/M...Bridge-c139.cab
O16 - DPF: {BD3653E4-884B-43C4-970B-670802501B7F} - http://akamai.downloadv3.com/binari..._1043_EN_XP.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = emea.ime.reuters.com
O17 - HKLM\Software\..\Telephony: DomainName = emea.ime.reuters.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{0CA6E4E5-4D13-4419-A902-03BAA340A827}: NameServer = 10.5.106.10,10.5.75.11
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = emea.ime.reuters.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = emea.ime.reuters.com,uki.ime.reuters.com,amers.ime.reuters.com,apac.ime.reuters.com,ime.reuters.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{0CA6E4E5-4D13-4419-A902-03BAA340A827}: NameServer = 10.5.106.10,10.5.75.11
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = emea.ime.reuters.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = emea.ime.reuters.com,uki.ime.reuters.com,amers.ime.reuters.com,apac.ime.reuters.com,ime.reuters.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = emea.ime.reuters.com,uki.ime.reuters.com,amers.ime.reuters.com,apac.ime.reuters.com,ime.reuters.com
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: GoverLAN Service (GOVsrv) - PJ Technologies, Inc. - C:\Program Files\PJ Technologies\GOVsrv\GOVsrv.EXE
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\PROGRA~1\Reuters\Apps\Rua\bin\w32-ix86\mrt\lcfd.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\OfficeScan NT\OfcPfwSvc.exe
O23 - Service: Radia Notify Daemon (radexecd) - Novadigm - C:\Program Files\Novadigm\radexecd.exe
O23 - Service: Radia Scheduler Daemon (radsched) - Novadigm - C:\Program Files\Novadigm\radsched.exe
O23 - Service: Radia MSI Redirector (Radstgms) - Novadigm - C:\Program Files\Novadigm\Radstgms.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe

4 Apprentice

 • 

8.8K Posts

July 12th, 2005 18:00

Hi

Ron and I got our paths crossed. :)

Please follow my directions and I'll fix the Smitfruad for you.

Steve

4 Apprentice

 • 

8.8K Posts

July 12th, 2005 18:00

Hi and welcome

See if this helps you out?

Please read these instructions carefully and print them out! Be sure to follow ALL instructions!

Please right-click: HERE and go to Save As (in Internet Explorer it's "Save Target As") in order to download Grinler's reg file. Save it to your desktop.

Locate " smitfraud.reg" on your desktop and double-click it. When asked if you want to merge with the registry, click YES. Wait for the "merged successfully" prompt then follow the rest of the instructions below.

Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found:

Security IGuard
Virtual Maid
Search Maid


Exit Add/Remove Programs.

*IMPORTANT* CLICK THIS LINK TO LEARN HOW TO VIEW HIDDEN FILES

I need you to copy all of the Killbox file paths below and paste them into Notepad.

* Please download the Killbox by Option^Explicit. *In the event you already have Killbox, this is a new version that I need you to download.

* Unzip to your desktop.

* Please double-click Killbox.exe to run it.

* Select " Delete on Reboot".

* Open the Notepad file where you saved the file paths earlier and copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C

C:\wp.exe
C:\wp.bmp
C:\bsw.exe
C:\Windows\sites.ini
C:\Windows\popuper.exe
C:\Windows\system32\hhk.dll
C:\Windows\System32\wldr.dll
C:\Windows\System32\helper.exe
C:\Windows\System32\intmon.exe
C:\Windows\System32\shnlog.exe
C:\Windows\System32\intmonp.exe
C:\Windows\System32\msmsgs.exe
C:\Windows\system32\msole32.exe
C:\Windows\System32\ole32vbs.exe


* Return to Killbox, go to the File menu, and choose " Paste from Clipboard".

* Click the red-and-white " Delete File" button. Click " Yes" at the Delete on Reboot prompt. Click " No" at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually.

While your computer is restarting, tap the F8 key continually until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.

Make sure you can view hidden files.

Using Windows Explorer, delete the following, if found, ( please do NOT try to find them by "search" because they will not show up that way)

FOLDERS to delete (in bold) if found:

C:\Program Files\ Search Maid
C:\Program Files\ Virtual Maid
C:\Windows\System32\ Log Files
C:\Program Files\ Security IGuard

While still in Safe Mode, do the following:

Make sure all programs and windows are closed. Run HiJackThis and place a check next to the following items, if found, then click FIX CHECKED

items to fix

Close HiJackThis.

Reboot into normal mode.

1.) Download The Hoster Press "Restore Original Hosts" and press "OK". Exit Program.

2.) Right-Click HERE and Save As to download DelDomains.inf to your desktop.
To use: RIGHT-CLICK DelDomains.inf on your desktop and select: Install (no need to restart)
Note: This will remove all entries in the "Trusted Zone" and "Ranges" also.

3.) Download, install, and run CleanUp!

4.) Run this online virus scan: ActiveScan - Save the results from the scan!

Post a new HiJackThis log along with the results from ActiveScan.

Steve

2 Intern

 • 

5.9K Posts

July 12th, 2005 18:00

Log looks clean.  Probably just registry damage left from the infection.

 

Get smitfraud.reg from

 

http://www.bleepingcomputer.com/files/reg/smitfraud.reg

(comes from:  http://www.bleepingcomputer.com/forums/How_to_remove_the_Smitfraud_Quicknavigate_VirtualMaid-t17258.html )

save it to your desktop then doubleclick on it and let it install.

Ron

No Events found!

Top