UNSOLVED

Hatevirus

updated

20 years ago

H

Hatevirus

8 Posts

0

6128

October 18th, 2006 19:00

System Alert: Trojan-Spy.Win32@mx

Hello, I really need help.I keep getting these system alerts from a program that is pretending to be an official windows warning, telling me i have a trojan and should pay for this anti-virus. It says...Your computer is infected with a backdoor trojan that allows the remote attacker to perform various malicious actions. Click this balloon to download malware removal software. And if I click on it, it directs me to a website where I have to purchase the software, its really a pest. My scan follows. Hope you can help me.

SmitFraudFix v2.110

Scan done at 14:50:22.89, Wed 10/18/2006
Run from C:\Documents and Settings\Lynne\Local Settings\Temporary Internet Files\Content.IE5\UW9IDR7J\SmitfraudFix[1]\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\dpfwu.dll FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Lynne


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Lynne\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Lynne\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop

C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

C:\Program Files\AntivirusGolden\ FOUND !
C:\Program Files\MMediaCodec\ FOUND !
C:\Program Files\SoftCodec\ FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{b166be07-30a4-4d38-b781-44528a630706}"="hydrodictyon"

[HKEY_CLASSES_ROOT\CLSID\{b166be07-30a4-4d38-b781-44528a630706}\InProcServer32]
@="C:\WINDOWS\system32\gqagksr.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{b166be07-30a4-4d38-b781-44528a630706}\InProcServer32]
@="C:\WINDOWS\system32\gqagksr.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{dfa61db1-388e-4c87-8d56-540fa229bcb4}"="contrabandists"

[HKEY_CLASSES_ROOT\CLSID\{dfa61db1-388e-4c87-8d56-540fa229bcb4}\InProcServer32]
@="C:\WINDOWS\system32\dpfwu.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{dfa61db1-388e-4c87-8d56-540fa229bcb4}\InProcServer32]
@="C:\WINDOWS\system32\dpfwu.dll"



»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

Here is my Hijack this log.

Logfile of HijackThis v1.99.1
Scan saved at 8:32:20 PM, on 10/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 SP2 (7.00.5450.0004)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MMediaCodec\isamonitor.exe
C:\Program Files\MMediaCodec\pmsngr.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\MMediaCodec\pmmon.exe
C:\Program Files\MMediaCodec\isamini.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Common Files\AOL\1128742632\ee\AOLSoftware.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/comcast.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydial/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
R3 - URLSearchHook: (no name) - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: (no name) - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - (no file)
O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~2.DLL
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {d869742a-e5d2-4624-96c7-aae26170665e} - C:\Program Files\MMediaCodec\isaddon.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: (no name) - {fe2d25c1-c1db-4b5e-9390-af1cb5302f32} - (no file)
O3 - Toolbar: Seekmo Toolbar - {53E0B6E8-A51D-448B-B692-40B67B285543} - C:\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll
O3 - Toolbar: Protection Bar - {479fd0cf-5be9-4c63-8cda-b6d371c67bd5} - C:\Program Files\MMediaCodec\iesplugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~2.DLL
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1128742632\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.1.720.5674\GoogleToolbarNotifier.exe
O4 - HKCU\..\RunOnce: [CheckNetworkConnection] "C:\Program Files\Support.com\providerComcast\desktopdoctor.exe" /flow /flow=diagnosenetwork /trayclick=true /haveconfirmedwiring=true /haverenewed=true /haverestartedmodem=true /onrestart=true /havehealed=true /issuenumber=5b770785-8e7e-4947-bc8c-1078262046c7
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://km.bar.need2find.com/KM/menusearch.html?p=KM
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20060912/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {416792D8-F532-493A-BECC-1C99A1501FF9} (vmLaunch Class) - http://media2.comcast.net/anon.comcastonline2/onleng/downloads/VideoMail/vmLauncher2.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4871/mcfscan.cab
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: hydrodictyon - {b166be07-30a4-4d38-b781-44528a630706} - C:\WINDOWS\system32\gqagksr.dll (file missing)
O21 - SSODL: contrabandists - {dfa61db1-388e-4c87-8d56-540fa229bcb4} - C:\WINDOWS\system32\dpfwu.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
  • bamajim

    10376 Posts

    304

    0

    Posted October 19th, 2006 02:00


    hatevirus

    I didn't notice that you had edited your first post. If you edit and not add a reply we don't get a notification that you had responded

    You may want to print out these instructions for reference

    1. Go here and Download AVG Anti-Spyware
    ( 30 day free trial version) Save it to Your Desktop
     
    Double Click AVG Anti-Spyware-setup
    (It will create its own folder)
    Once the program starts You will be at the Status menu
    • Under "Your computers Security"
      Click change status on Resident shield to inactive
      Click Update now (next to last update)
      After the update loads
      Under Automatic updates Uncheck download and install updates automatically(recommended)
      (you can always select maual updates the next day)
    At the top toolbar Click Scanner Then the settings tab
    • Under How to act? Set default action for detected malwareTo Quarantine
      Under how to scan All boxes should be checked
      Under Possibly unwanted software All boxes should be checked
      Under reports Select Automatically generate report after every scan
      Uncheck Only if threats were found
      Under what to scan Scan every file should be highlited
    Exit AVG(But do not run it yet)

    2. Reboot into Safe Mode
    This can be done by
    • Restart your PC, and after it starts, but before you see the Windows Splash screen
      Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
      Use your arrow keys and select Safe Mode and then Enter

    3. Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
    • Select option #2 - Clean by typing 2 and press Enter.
      Wait for the tool to complete and disk cleanup to finish.
      You will be prompted : " Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
      The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question " Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if your computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

    4. Run AVG Anti-Spyware
    • Click scanner
      Select Complete system scan
    Once the scan finishes
    • Select Apply all actions (The items found will be quarantined)
      Click save report as (Another window will open)
      Save it to your desktop
      (By default It will be saved in the AVG folder as)
      C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports
    Exit AVG

    Reboot your PC in Normal Mode->>Re run Hijackthis and post a fresh Hijackthis log.
    • Double click the report-scan txt. you saved to your desktop
      It will open in Notepad
      Copy and paste that report as a reply to this thread
    Your reply should include
    • a fresh hijackthis log
      your c:rapport.txt log from Smitfraudfix
      your report_scan.txt from AVG
    You may have to post the results in more than one reply
     
    bamajim   Graduate of Malware Removal University



  • bamajim

    10376 Posts

    304

    0

    Posted October 20th, 2006 01:00

    Hatevirus
     
    You are welcome
     
    Are you still getting the pop-ups?
     
    bamajim   Graduate of Malware Removal University

     

  • Hatevirus

    8 Posts

    304

    0

    Posted October 20th, 2006 01:00

    Hello! Here is my fresh Hijackthis log, etc. Thank you!


    Logfile of HijackThis v1.99.1
    Scan saved at 8:49:50 PM, on 10/19/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 SP2 (7.00.5450.0004)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Support.com\bin\tgcmd.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    C:\Program Files\McAfee.com\VSO\oasclnt.exe
    C:\Program Files\Common Files\AOL\1128742632\ee\AOLSoftware.exe
    C:\Program Files\Yahoo!\browser\ybrwicon.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.1.720.5674\GoogleToolbarNotifier.exe
    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
    c:\progra~1\mcafee.com\vso\mcvsftsn.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/home.html
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
    O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
    O2 - BHO: (no name) - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - (no file)
    O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~2.DLL
    O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
    O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\common\YIeTagBm.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: Seekmo Toolbar - {53E0B6E8-A51D-448B-B692-40B67B285543} - C:\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll
    O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~2\COMCAS~2.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [tgcmd] C:\Program Files\Support.com\bin\tgcmd.exe /server /startmonitor /deaf
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [_AntiSpyware] c:\progra~1\mcafee\MCAFEE~1\masalert.exe
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1128742632\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.1.720.5674\GoogleToolbarNotifier.exe
    O4 - HKCU\..\RunOnce: [CheckNetworkConnection] "C:\Program Files\Support.com\providerComcast\desktopdoctor.exe" /flow /flow=diagnosenetwork /trayclick=true /haveconfirmedwiring=true /haverenewed=true /haverestartedmodem=true /onrestart=true /havehealed=true /issuenumber=5b770785-8e7e-4947-bc8c-1078262046c7
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
    O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
    O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
    O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
    O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20060912/qtinstall.info.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {416792D8-F532-493A-BECC-1C99A1501FF9} (vmLaunch Class) - http://media2.comcast.net/anon.comcastonline2/onleng/downloads/VideoMail/vmLauncher2.cab
    O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
    O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4871/mcfscan.cab
    O18 - Filter: text/html - (no CLSID) - (no file)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 8:37:46 PM 10/19/2006

    + Scan result:



    C:\System Volume Information\_restore{2BA82CAD-B5CF-416F-8549-AF331C2AD039}\RP210\A0086687.exe -> Adware.Altnet : Ignored.
    C:\System Volume Information\_restore{2BA82CAD-B5CF-416F-8549-AF331C2AD039}\RP210\A0086683.exe -> Adware.VMN : Ignored.
    C:\System Volume Information\_restore{2BA82CAD-B5CF-416F-8549-AF331C2AD039}\RP190\A0078636.exe -> Logger.KeyLogger.jm.1 : Cleaned with backup (quarantined).
    C:\Documents and Settings\Lynne\Local Settings\Temporary Internet Files\Content.IE5\90LPACQQ\WinAntiVirusPro2006FreeInstall[1].cab/UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Ignored.
    C:\Documents and Settings\Lynne\Cookies\lynne@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Lynne\Cookies\lynne@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
    C:\Documents and Settings\Lynne\Cookies\lynne@ehg-comcast.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.


    ::Report end

    SmitFraudFix v2.111

    Scan done at 18:24:52.16, Thu 10/19/2006
    Run from C:\Documents and Settings\Lynne\My Documents\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    Fix run in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End


    Bamajim,
    I hope you can help me get rid of these pests in my desktop. All these nasty pop-ups are showing in my comp as well. Thank you for replying to my posts.
  • Hatevirus

    8 Posts

    304

    0

    Posted October 20th, 2006 14:00

    Dear Bamajim,
    Thank you so much! Not getting anymore pop-ups!
  • bamajim

    10376 Posts

    304

    0

    Posted October 20th, 2006 15:00

    Hatevirus
     

    Glad to hear it, and you are welcome, now we have a few things to clean up

    First Go to Add/Remove programs (Click Start->>Control Panel->>Add/Remove Programs)
    and uninstall the following
    • Seekmo Toolbar or it may be listed as just Seekmo
      AWS or it may be listed as Weatherbug
    Close Add/Remove programs

    Next Rerun Hijackthis (scan only) and place checks beside the following entries
    • O3 - Toolbar: Seekmo Toolbar - {53E0B6E8-A51D-448B-B692-40B67B285543} - C:\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll
      O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
      O11 - Options group: [INTERNATIONAL] International*

    Close all other open windows except Hijackthis and Select " Fix checked"
    If prompted to reboot Select No and close Hijackthis

    Next Using Windows Explorer
    • (Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)
    Locate and Delete the following folders (if found)
    • C:\Program Files\Seekmo Programs
      C:\Program Files\AWS
    Close windows explorer->>Reboot your PC->>Rerun Hijackthis and post a Fresh hijackthis log
     
    bamajim   Graduate of Malware Removal University




  • yvan2000

    12 Posts

    304

    0

    Posted October 24th, 2006 12:00

    Bamajim - Thanks for your help in advance

    I tried to follow your procedures but stopped at step 3 "open smitfraudfix foilder". I do not have that option in "safe mode". Or is that a folder? I could not find it on win 2000 Professional. Pleaes advise.

    Here is my log file so far - please help!!

    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 8:35:56 AM 10/24/2006

    + Scan result:



    HKLM\SOFTWARE\Classes\Downloader.Downloader -> Adware.2020Search : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\Downloader.Downloader.1 -> Adware.2020Search : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\Downloader.Downloader\CLSID -> Adware.2020Search : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\Downloader.Downloader\CurVer -> Adware.2020Search : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\2020Search2020Search -> Adware.2020Search : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\BRBHO.ByteRangeBHO -> Adware.CometCursor : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\BRBHO.ByteRangeBHO.1 -> Adware.CometCursor : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\BRBHO.ByteRangeBHO\CLSID -> Adware.CometCursor : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\BRBHO.ByteRangeBHO\CurVer -> Adware.CometCursor : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\BRBHO.CSBrBho -> Adware.CometCursor : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\BRBHO.CSBrBho.1 -> Adware.CometCursor : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\BRBHO.CSBrBho\CLSID -> Adware.CometCursor : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\BRBHO.CSBrBho\CurVer -> Adware.CometCursor : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.Generic : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 -> Adware.Generic : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Security Plugin 2006 -> Adware.IntCodec : Cleaned with backup (quarantined).
    HKU\S-1-5-21-964177134-1173751378-1628904168-1002\Software\Internet Security -> Adware.IntCodec : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\TypeLib\{CE7C3CE2-4B15-11D1-ABED-709549C10000} -> Adware.RegiFast : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Adware.WebSearch : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\AUI -> Adware.WebSearch : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\STO -> Adware.WebSearch : Cleaned with backup (quarantined).
    HKU\S-1-5-21-964177134-1173751378-1628904168-1002\Software\Srng -> Hijacker.ShopNav : Cleaned with backup (quarantined).
    :mozilla.163:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
    :mozilla.12:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.144:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.16:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.17:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.18:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.264:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.288:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.60:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.99:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.124:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.126:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.127:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.128:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.129:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.130:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.194:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.195:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.154:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.155:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.156:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.157:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.158:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.91:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
    :mozilla.201:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
    :mozilla.52:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
    :mozilla.77:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Cookies\yvan@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
    :mozilla.255:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.256:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.115:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.116:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.117:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.182:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.61:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.62:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.63:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.119:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.120:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.56:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.57:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.58:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.59:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.108:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
    :mozilla.11:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
    :mozilla.13:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
    :mozilla.14:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
    :mozilla.15:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
    :mozilla.19:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
    :mozilla.150:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.151:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.152:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.153:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.74:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.75:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.76:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Cookies\yvan@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.147:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
    :mozilla.78:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.79:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.80:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.92:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.125:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.65:C:\Documents and Settings\yvan.YUL-LT-DD40PN21\Application Data\Mozilla\Firefox\Profiles\8s85jbiw.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.


    ::Report end
  • bamajim

    10376 Posts

    304

    0

    Posted October 24th, 2006 15:00

    yvan2000
     
    I will be glad to help you, but you need to open your own topic.
     
    Just go to the Hijackthis Forum and select "New Topic" and I will help you there. When you open your new thread (topic) please post a Hijackthis log. I will see that you have posted and will reply.
     
    If you need help with posting a Hijackthis log here are the instructions
     
    Go Here And download HijackThis

    Save it in a convenient permanent folder such as C:\\HJT\\, double click HijackThis.exe, and hit "Scan". When the scan is finished, the "Scan" button will change into a "Save Log" button. Press that, save the log, Ctrl-A to Select All, and copy its contents AT THE LINK BELOW

    LINK

    and include a description of the problem along with your log

    bamajim   Graduate of Malware Removal University

  • yvan2000

    12 Posts

    304

    0

    Posted October 24th, 2006 19:00

    I appreciate

    I posted my topic here - let me know what you think

    You guys rock!

    Yvan
  • yvan2000

    12 Posts

    304

    0

    Posted October 24th, 2006 19:00

    http://forums.us.dell.com/supportforums/board/message?board.id=si_hijack&message.id=48084

    here si teh link

    yvan
  • casagab

    1 Message

    37

    0

    Posted October 25th, 2006 03:00

    I hade the same problem.
    I just scanned my pc (in safety mode) with Smitfraudfix. Now all is ok.