Announcement Banner
UNSOLVED

ZENABI

updated

20 years ago

Z

ZENABI

40 Posts

0

2634

October 30th, 2006 20:00

Cannot Remove "Pest Trap"

Hello!
 
On Sunday afternoon two red circles with a white x appeared in the taskbar of our DELL PC that would display a pop-up window saying "Your computer is infected! Windows has detected a spyware infection, Etc."  A little later in the day the computer screen's wallpaper disappeared.  Last but not least, a program started up called "Pest Trap".  Both my wife's user profile and my own user profile are suffering from these symptoms.
 
Ad-Aware and Trend Micro detected and removed this infection but upon re-booting the computer it would come back after a few minutes.
 
After reviewing previous posts here in the DCF, I ended up following a link to bleepingcomputer.com and followed their instructions to remove "Pest Trap" with the "SmitFraudFix" utility.  This appeared to work initially, but after a few minutes the infection would re-appear on both of our accounts.
 
Below is our most recent HJT log file for review.
 
We look forward to hearing back from one of the forum's experts regarding the proper removal of this infection.
 
Thanks for your time and effort!
 
Sincerely,
ZENABI
 

 
Logfile of HijackThis v1.99.1
Scan saved at 4:37:16 PM, on 10/30/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\WDC\SetIcon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Logitech\Video\ManifestEngine.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\winstall.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MI1933~1\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Jeff\cvarqxlw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash/index.cfm
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [SetIcon] \Program Files\WDC\SetIcon.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [HPHUPD08] C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [gwiz] C:\WINDOWS\system32\ntsystem.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Harmony Remote.lnk = C:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} (Support.com ActionRunner Class) - http://help.rr.com/Foundrysdccommon/download/tgctlar.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) - http://www.trendsecure.com/service_components/control/activex/TmHcmsX.CAB
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1125109273140
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
O16 - DPF: {AEF76437-F960-4EBC-97EA-7BBB4230CF38} (OcarptMain Class) - https://oca.microsoft.com/en/secure/ocarpt.CAB
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {C432C4BD-3566-411C-8F3C-E5E0D3AE5D33} (CBrowser Class) - http://viewers.streamingfaith.com/common/mbrowser/MINIBrowser.CAB
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://photo.walmart.com/photo/upload/XUpload.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?325
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: CWShredder Service - Unknown owner - C:\My Downloads\cwshredder.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
  • Bugbatter

    4 Apprentice

    •

    20487 Posts

    765

    0

    Posted October 30th, 2006 23:00

    It appears as if you still have some malware in there. We are researching your log and will reply soon.
    Thank you for waiting patiently. :)
  • zbestwun2001

    4 Apprentice

    •

    8831 Posts

    765

    0

    Posted October 31st, 2006 11:00

    Please download SmitfraudFix
    Extract the content (a folder named SmitfraudFix) to your Desktop.


    Download AVG Anti-Spyware from HERE and save that file to your desktop.
    This is a 30 day trial of the program

    1. Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
    2. Select Change state" to inactivate 'Resident Shield' and 'Automatic Updates'
    3. Right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows".
      Go to Start > Run and type: services.msc
    4. Press "OK".
    5. In Services, click the "Extended tab" and scroll down the list to find AVG Anti-Spyware guard.
    6. When you find the guard service, double-click on it.
    7. In the Properties Window > General Tab that opens, click the "Stop" button.
    8. From the drop-down menu next to "Startup Type", click on "Manual".
    9. Now click "Apply", then "OK" and close the Services window.
    10. Once the setup is complete you will need run AVG AS and update the definition files.
    11. On the main screen select the icon "Update" then select the "Update now" link.
      • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
      • If you are having problems with the updater, manually update with the AVG AS Full database installer from here.
      • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
      • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
      • Under "Reports"
        • Select "Automatically generate report after every scan"
        • Un-Select "Only if threats were found"
        • Close AVG Anti-Spyware, Do Not run a scan just yet. We will shortly.


          Open the SmitfraudFix folder and double-click smitfraudfix.cmd
          Select option #1 - Search by typing 1 and press " Enter"; a text file will appear, which lists infected files (if present).
          Please copy/paste the content of that report into your next reply.

          IMPORTANT: Do NOT run any other options until you are asked to do so!

          Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
          http://www.beyondlogic.org/consulting/proc...processutil.htm



          ZB1
      • ZENABI

        40 Posts

        765

        0

        Posted October 31st, 2006 12:00

        Thanks for the quick response!
         
        I will follow your instructions and post the report this evening after I get home from work.
         
        Does it matter whether I perform this from my user account or my wife's user account since we're both infected?
         
        Sincerely,
        ZENABI

        Message Edited by ZENABI on 10-31-2006 08:29 AM

      • zbestwun2001

        4 Apprentice

        •

        8831 Posts

        765

        0

        Posted October 31st, 2006 13:00

        Post your log first and we will see how things are when we have worked that one.


        ZB1
      • ZENABI

        40 Posts

        765

        0

        Posted November 1st, 2006 02:00

        Hello Again!
         
        As requested, here's the report generated by SmitfraudFix:
         

         
        SmitFraudFix v2.117
        Scan done at 22:30:03.07, Tue 10/31/2006
        Run from C:\Documents and Settings\Jeff\Desktop\SmitfraudFix
        OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
        Fix run in normal mode
        »»»»»»»»»»»»»»»»»»»»»»»» C:\
        C:\winstall.exe FOUND !
        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Jeff

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Jeff\Application Data
        C:\Documents and Settings\Jeff\Application Data\Install.dat FOUND !
        »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

        »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Jeff\FAVORI~1

        »»»»»»»»»»»»»»»»»»»»»»»» Desktop

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
        C:\Program Files\PestTrap\ FOUND !
        »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

        »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
         
         
        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
        !!!Attention, following keys are not inevitably infected!!!
        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
        !!!Attention, following keys are not inevitably infected!!!
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
        "AppInit_DLLs"=""

        »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

        »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection

        »»»»»»»»»»»»»»»»»»»»»»»» End
         

         
        I have also installed AVG Anti-Spyware as instructed.
         
        Thanks again and I look forward to your reply!
         
        Sincerely,
        ZENABI
         
      • zbestwun2001

        4 Apprentice

        •

        8831 Posts

        768

        0

        Posted November 1st, 2006 11:00

        Please print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

        Please reboot your computer in Safe Mode by doing the following :

        * Restart your computer
        * After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
        * Instead of Windows loading as normal, a menu with options should appear;
        * Select the first option, to run Windows in Safe Mode, then press "Enter".
        * Choose your usual account.

        Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
        Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

        You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

        The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

        The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows.
        A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report along with all others into your next reply along with a new HijackThis log.
        The report can also be found at the root of the system drive, usually at C:\rapport.txt

        Warning : Running option #2 on a non-infected computer will remove your Desktop background.


        ____________________________________________________________

        Clean out your Temporary Internet files. Proceed like this:

        * Quit Internet Explorer and quit any instances of Windows Explorer.
        * Click Start, click Control Panel, and then double-click Internet Options.
        * On the General tab, click Delete Files under Temporary Internet Files.
        * In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
        * On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
        * Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
        * Click OK.

        Next Click Start, click Control Panel and then double-click Display.
        Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.
        Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin
        ______________________________

        Close ALL open Windows / Programs / Folders.

        * While in Safe Mode, launch AVG Anti-Spyware by double-clicking the icon on your desktop.
        * Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
        * AVG AS will now begin the scanning process, be patient this may take a little time.
        Once the scan is complete do the following:
        * If you have any infections you will prompted, then select "Apply all actions"
        * Next select the "Reports" icon at the top.
        * Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
        * Close AVG AS and reboot your system back into Normal Mode.



        In your next reply please include:

        1. The report from SmitfraudFix found here: C:\rapport.txt
        2. The report from AVG AS
        3. A fresh HijackThis log

        You may need several replies to post the requested logs, otherwise they might get cut off.
      • ZENABI

        40 Posts

        768

        0

        Posted November 2nd, 2006 02:00

        Here's the AVG AS Report:
         

         
        ---------------------------------------------------------
        AVG Anti-Spyware - Scan Report
        ---------------------------------------------------------
         + Created at: 10:17:46 PM 11/1/2006
         + Scan result: 
         
        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Pest Trap -> Adware.Pesttrap : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\Application Data\WinHound.com -> Adware.WinHound : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\Application Data\WinHound.com\WinHound -> Adware.WinHound : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\Application Data\WinHound.com\WinHound\Autorun -> Adware.WinHound : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\Application Data\WinHound.com\WinHound\Autorun\HKCURun -> Adware.WinHound : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\Application Data\WinHound.com\WinHound\Autorun\HKCURun\RunOnce -> Adware.WinHound : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\Application Data\WinHound.com\WinHound\Autorun\HKCURun\RunOnceEx -> Adware.WinHound : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\Application Data\WinHound.com\WinHound\Autorun\HKLMRun -> Adware.WinHound : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\Application Data\WinHound.com\WinHound\Autorun\HKLMRun\RunOnce -> Adware.WinHound : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\Application Data\WinHound.com\WinHound\Autorun\HKLMRun\RunOnceEx -> Adware.WinHound : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\Application Data\WinHound.com\WinHound\Autorun\StartMenuAllUsers -> Adware.WinHound : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\Application Data\WinHound.com\WinHound\Autorun\StartMenuCurrentUser -> Adware.WinHound : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\Application Data\WinHound.com\WinHound\BrowserObjects -> Adware.WinHound : Cleaned with backup (quarantined).
        C:\Documents and Settings\Angie\dmgsctxw.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Angie\kbekppah.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Angie\scwvdcim.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Angie\xvivzgpd.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Angie\ylkdtmcu.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\anxwqyja.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\cvarqxlw.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\eqbksatf.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\giawykal.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\hivwnfmw.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\nypyibsv.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\pemelpcc.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\pgesktvd.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\turvluso.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\vyfubcsr.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Jeff\zvroaipb.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
        C:\Documents and Settings\Angie\Cookies\angie@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@cbs.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@charmingshoppes.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@dealnews.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@efashionsolutions.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@marketlive.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@omniturechannel.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@reunioncom.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@snapfish.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@viamtvcom.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@bfast[1].txt -> TrackingCookie.Bfast : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@twci.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@e-2dj6wfkyqkczgdq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@e-2dj6wfmyupazifp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@e-2dj6wjk4gldjkfp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@e-2dj6wjkyokdjmao.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@e-2dj6wjkyqmazggo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@e-2dj6wjliehdjidp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@e-2dj6wjloclajofp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@e-2dj6wjlosiazmcq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@e-2dj6wjlygkdzibq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@e-2dj6wjnyaldpkdq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@e-2dj6wjnyeicpeco.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@e-2dj6wjnywicpoko.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@ehg-buyseasons.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@phg.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@data1.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@data2.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@overture[1].txt -> TrackingCookie.Overture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@revenue[1].txt -> TrackingCookie.Revenue : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@anad.tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@anat.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
        C:\Documents and Settings\Angie\Cookies\angie@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.

        ::Report end
         
      • ZENABI

        40 Posts

        768

        0

        Posted November 2nd, 2006 02:00

        Here's the latest Hijack This! Log:
         

        Logfile of HijackThis v1.99.1
        Scan saved at 10:35:06 PM, on 11/1/2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\System32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
        C:\Program Files\Dell\Media Experience\PCMService.exe
        C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
        C:\WINDOWS\System32\DSentry.exe
        C:\Program Files\Common Files\Symantec Shared\ccApp.exe
        C:\WINDOWS\system32\LVCOMSX.EXE
        C:\Program Files\Logitech\Video\LogiTray.exe
        C:\WINDOWS\system32\WDBtnMgr.exe
        C:\Program Files\WDC\SetIcon.exe
        C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
        C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        C:\Program Files\Logitech\MouseWare\system\em_exec.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Logitech\Video\FxSvr2.exe
        C:\Program Files\Dell Support\DSAgnt.exe
        C:\Program Files\Adobe\Photoshop Elements 3.0
        \PhotoshopElementsFileAgent.exe
        C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
        C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
        C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
        C:\WINDOWS\System32\CTsvcCDA.exe
        C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
        C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
        C:\Program Files\Adobe\Photoshop Elements 3.0
        \PhotoshopElementsDeviceConnect.exe
        C:\WINDOWS\system32\HPZipm12.exe
        C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
        C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
        C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
        C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
        C:\WINDOWS\System32\MsPMSPSv.exe
        C:\Program Files\Common Files\Symantec Shared\Security
        Center\SymWSC.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Documents and Settings\Jeff\mdjhjfzo.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\NOTEPAD.EXE
        C:\Program Files\Messenger\msmsgs.exe
        C:\My Downloads\HijackThis.exe
        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-
        7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton
        AntiVirus\NavShExt.dll
        O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -
        C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
        O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint
        Manager\ViewMgr.exe
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
        Files\Real\Update_OB\realsched.exe"  -osboot
        O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common
        Files\Roxio Shared\System\EngUtil.exe"
        O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD
        Creator 6\DragToDisc\DrgToDsc.exe"
        O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media
        Experience\PCMService.exe"
        O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
        O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event
        Monitor\IntelMEM.exe
        O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
        O4 - HKLM\..\Run: [diagent] "C:\Program
        Files\Creative\SBLive\Diagnostics\diagent.exe" startup
        O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec
        Shared\ccRegVfy.exe"
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
        Shared\ccApp.exe"
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI
        Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1
        \SNDMon.exe /Consumer
        O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
        O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program
        Files\Logitech\Video\ISStart.exe
        O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program
        Files\Logitech\Video\LogiTray.exe
        O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
        O4 - HKLM\..\Run: [SetIcon] \Program Files\WDC\SetIcon.exe
        O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone
        Labs\ZoneAlarm\zlclient.exe"
        O4 - HKLM\..\Run: [HPHUPD08] C:\Program Files\HP\Digital
        Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software
        Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
        Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program
        Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [gwiz] C:\WINDOWS\system32\ntsystem.exe
        O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program
        Files\Logitech\Video\ManifestEngine.exe" boot
        O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell
        Support\DSAgnt.exe" /startup
        O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
        O4 - Global Startup: Acrobat Assistant.lnk = C:\Program
        Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
        Files\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program
        Files\HP\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program
        Files\HP\Digital Imaging\bin\hpqthb08.exe
        O4 - Global Startup: Logitech Harmony Remote.lnk = C:\Program
        Files\Logitech\Harmony Remote\harmonyClient.exe
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel
        present
        O8 - Extra context menu item: E&xport to Microsoft Excel -
        res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
        - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-
        AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
        O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD}
        - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
        O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-
        AD55-00010333D0AD} - C:\Program Files\Yahoo!
        \Messenger\yhexbmes0521.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
        C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
        C:\WINDOWS\System32\Shdocvw.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}
        - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-
        BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} (Support.com
        ActionRunner Class) -
        http://help.rr.com/Foundrysdccommon/download/tgctlar.cab
        O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com
        Configuration Class) -
        http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
        O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
        https://support.dell.com/systemprofiler/SysPro.CAB
        O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control)
        - http://housecall60.trendmicro.com/housecall/xscan60.cab
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine
        Advantage Validation Tool) - http://go.microsoft.com/fwlink/?
        LinkId=39204&clcid=0x409
        O16 - DPF: {1EF9F042-C2EB-4293-8213-474CAEEF531D} (TmHcmsX Control) -
        CAB
        O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -
        http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
        O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX
        Scan Agent 6.5) -
        32/activex/hcImpl.cab
        O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID
        Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
        O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo
        Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
        O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
        http://photo.walgreens.com/WalgreensActivia.cab
        O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec
        SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
        O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script
        Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
        O16 - DPF: {49232000-16E4-426C-A231-62846947304B} -
        http://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab
        O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl
        Class) -
        v1-0-3-48.cab
        O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI
        Utility Class) -
        http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
        -
        t/muweb_site.cab?1125109273140
        O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX
        europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
        O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture
        Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan
        Installer Class) -
        http://acs.pandasoftware.com/activescan/as5free/asinst.cab
        O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader
        Class) -
        http://photo.walmart.com/photo/uploads/FujifilmUploadClient.cab
        O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class)
        - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
        O16 - DPF: {AEF76437-F960-4EBC-97EA-7BBB4230CF38} (OcarptMain Class) -
        https://oca.microsoft.com/en/secure/ocarpt.CAB
        O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} -
        http://www.trendmicro.com/spyware-scan/as4web.cab
        O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX
        Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
        O16 - DPF: {C432C4BD-3566-411C-8F3C-E5E0D3AE5D33} (CBrowser Class) -
        http://viewers.streamingfaith.com/common/mbrowser/MINIBrowser.CAB
        O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo
        Class) - https://www-
        secure.symantec.com/techsupp/activedata/SymAData.cab
        O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj
        Class) - https://www-
        secure.symantec.com/techsupp/activedata/ActiveData.cab
        O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software
        XUpload) - http://photo.walmart.com/photo/upload/XUpload.ocx
        O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj
        Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?325
        O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer
        lmi=100
        O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX
        Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
        O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) -
        Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0
        \PhotoshopElementsFileAgent.exe
        O23 - Service: Ati HotKey Poller - Unknown owner -
        C:\WINDOWS\System32\Ati2evxx.exe
        O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation -
        C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s.
        - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec
        Corporation - C:\Program Files\Common Files\Symantec
        Shared\ccEvtMgr.exe
        O23 - Service: Symantec Password Validation Service (ccPwdSvc) -
        Symantec Corporation - C:\Program Files\Common Files\Symantec
        Shared\ccPwdSvc.exe
        O23 - Service: Creative Service for CDROM Access - Creative Technology
        Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
        O23 - Service: CWShredder Service - Unknown owner - C:\My
        Downloads\cwshredder.exe (file missing)
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision
        Corporation - C:\Program Files\Common Files\InstallShield\Driver\11
        \Intel 32\IDriverT.exe
        O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program
        Files\iPod\bin\iPodService.exe
        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1
        \Symantec\LIVEUP~1\LUCOMS~1.EXE
        O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program
        Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
        O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) -
        Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton
        AntiVirus\navapsvc.exe
        O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation -
        C:\Program Files\Intel\NCS\Sync\NetSvc.exe
        O23 - Service: Norton Unerase Protection (NProtectService) - Symantec
        Corporation - C:\Program Files\Norton SystemWorks\Norton
        Utilities\NPROTECT.EXE
        O23 - Service: Photoshop Elements Device Connect
        (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program
        Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32
        \HPZipm12.exe
        O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development
        Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
        O23 - Service: Retrospect Helper - Dantz Development Corporation -
        C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe
        O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development
        Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
        O23 - Service: ScriptBlocking Service (SBService) - Symantec
        Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
        Corporation - C:\Program Files\Common Files\Symantec
        Shared\SNDSrvc.exe
        O23 - Service: Speed Disk service - Symantec Corporation -
        C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation -
        C:\Program Files\Common Files\Symantec Shared\Security
        Center\SymWSC.exe
        O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead
        Systems, Inc. - C:\Program Files\Common Files\Ulead
        Systems\DVD\ULCDRSvr.exe
        O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC -
        C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
         
      • ZENABI

        40 Posts

        768

        0

        Posted November 2nd, 2006 02:00

        Hello!
         
        This evening I ran all of the steps I was instructed to do and have posted all three reports in the following replies.  I did notice the following though:
         
        1) Smitfraudfix did not find wininet.dll to be infected and there was no prompt to replace it.
         
        2) When cleaning out the temp internet files, there was not any checked entries called "Security Info" under the web pages tab.
         
        3) After running AVG AS and rebooting into Normal Mode, everything appeared to be fixed but within two minutes the little red circle with a white "x" and the pop-ups in the lower right hand corner saying that Windows had detected spyware reappeared once again!
         
        Here's the Smitfraudfix Report:
         

         
        SmitFraudFix v2.117
        Scan done at 20:56:53.03, Wed 11/01/2006
        Run from C:\Documents and Settings\Jeff\Desktop\SmitfraudFix
        OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
        Fix run in safe mode
        »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
        !!!Attention, following keys are not inevitably infected!!!
        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll
        »»»»»»»»»»»»»»»»»»»»»»»» Killing process

        »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
        GenericRenosFix by S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
        C:\winstall.exe Deleted
        C:\Documents and Settings\Jeff\Application Data\Install.dat Deleted
        C:\Program Files\PestTrap\ Deleted
        »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
         
        Registry Cleaning done.
         
        »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
        !!!Attention, following keys are not inevitably infected!!!
        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» End
         

        Message Edited by ZENABI on 11-01-2006 10:47 PM

      • zbestwun2001

        4 Apprentice

        •

        8831 Posts

        537

        0

        Posted November 2nd, 2006 13:00

        deleted by author

        Message Edited by zbestwun2001 on 11-02-2006 07:53 AM