another smithfraud victim

hello, recently my laptop got a virus (Iworm Luder.A) i was able to remove it but it seems to have put smithfraud on my laptop i'm running Windows XP Home and spybot S&D has removed it once but i still don't have control of my desktop. basically i didnt get the whole "blue error" desktop it remained the same instead i just cant modify it in anyway pertaining to the background
everytime i start my computer now it complains about a program (Sasunx.exe) causing an error and needing to close also i seem to have numerous amounts of a certain file in the root directory of the c drive with various names from sqmdata to sqmnoopt please help
«1

Comments

  • Rahina-RescueRahina-Rescue Finland
    edited February 2007
    Hello Sonic_Hawk! and Welcome to Short-media Virus/Spyware Removal Forums :smiles:

    Please Download HJTsetup.exe

    Save HJTsetup.exe to your desktop.

    Double click on the HJTsetup.exe icon on your desktop.
    By default it will install to C:\Program Files\Hijack This.
    Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
    Put a check by Create a desktop icon then click Next again.
    Continue to follow the rest of the prompts from there.
    At the final dialogue box click Finish and it will launch Hijack This.

    Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
    Click Save to save the log file and then the log will open in notepad.
    Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
    Come back here to this thread and Paste the log in your next reply.
    DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
  • edited February 2007
    ah yes hijackthis i've read a previous post about smithfraud that mentioned it.
    i post the log like this right?

    Logfile of HijackThis v1.99.1
    Scan saved at 9:55:47 PM, on 2/15/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    C:\WINDOWS\system32\sessmgr.exe
    C:\WINDOWS\system32\tcpsvcs.exe
    C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    C:\WINDOWS\stsystra.exe
    C:\WINDOWS\sm56hlpr.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\BigFix\bigfix.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Hamachi\hamachi.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MX6214
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.segasages.com/
    O1 - Hosts: 207.210.93.28 game01.us.segaonline.jp127.0.0.1
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [sysinter] C:\WINDOWS\system32\adirss.exe
    O4 - HKLM\..\Run: [Agent] C:\WINDOWS\system32\alsys.exe
    O4 - HKLM\..\Run: [lnwin.exe] C:\WINDOWS\system32\lnwin.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Agent] C:\WINDOWS\system32\alsys.exe
    O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
    O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5BC2959C-9ADC-45FE-B6B0-434B4E63D1B7}: NameServer = 85.255.116.82,85.255.112.117
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.82 85.255.112.117
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.82 85.255.112.117
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.82 85.255.112.117
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
    O21 - SSODL: DCOM Server 60787 - {2C1CD3D7-86AC-4068-93BC-A02304B60787} - C:\WINDOWS\system32\rwgz.dll (file missing)
    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe (file missing)
    O23 - Service: .NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (file missing)
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\system32\nvsvc32.exe (file missing)
    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe (file missing)
    O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
  • Rahina-RescueRahina-Rescue Finland
    edited February 2007
    Please download FixWareout from here:
    http://downloads.subratam.org/Fixwareout.exe

    Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
    The fix will begin; follow the prompts. If your firewall gives an alert, (because this tool will download an additional file from the internet), please don't let your firewall block it, but allow it instead.
    Then you will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
    Once the desktop loads please post the text that will open (report.txt) and a new Hijackthis log

    Please post C:\Fixwareout\Report.txt
  • edited February 2007
    alright! that fixit program got control of my desktop back now all i need to do is fix the function keys because they stopped working well some of them stopped (like lcd brightness) do you know how i would fix this?
  • Rahina-RescueRahina-Rescue Finland
    edited February 2007
    Please Follow my instructions :)

    As i already said, Please Post A Fresh hijackthis logfile & And Fixwareout report which is located here C:\Fixwareout\report.txt
  • edited February 2007
    sorry i forgot to post the logs XD


    Fixwareout Last edited 2/11/2007
    Post this report in the forums please
    ...
    »»»»»Prerun check
    HKLM\SOFTWARE\~\Winlogon\ "System"="kdkxn.exe"

    »»»»» System restarted

    »»»»» Postrun check
    HKLM\SOFTWARE\~\Winlogon\ "system"=""
    ....
    ....
    »»»»» Misc files.
    C:\Documents and Settings\Owner\Application Data\Install.dat Deleted
    ....
    »»»»» Checking for older varients.
    ....

    Search five digit cs, dm, kd, jb, other, files.
    The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.



    Click browse, find the file then click submit.
    http://www.virustotal.com/flash/index_en.html
    Or http://virusscan.jotti.org/

    »»»»» Other



    »»»»» Current runs
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
    "SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
    "SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
    "Reminder"=hex(2):25,57,49,4e,44,49,52,25,5c,43,72,65,61,74,6f,72,5c,52,65,6d,\
    69,6e,64,5f,58,50,2e,65,78,65,00
    "Recguard"=hex(2):25,57,49,4e,44,49,52,25,5c,53,4d,49,4e,53,54,5c,52,45,43,47,\
    55,41,52,44,2e,45,58,45,00
    "IAAnotif"="C:\\Program Files\\Intel\\Intel Matrix Storage Manager\\iaanotif.exe"
    "SigmatelSysTrayApp"="stsystra.exe"
    "SMSERIAL"="sm56hlpr.exe"
    "igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe"
    "igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe"
    "igfxpers"="C:\\WINDOWS\\system32\\igfxpers.exe"
    "Broadcom Wireless Manager UI"="C:\\WINDOWS\\system32\\WLTRAY.exe"
    "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
    "NWEReboot"=""
    "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
    "DAEMON Tools-1033"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033"
    "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    "WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
    "sysinter"="C:\\WINDOWS\\system32\\adirss.exe"
    "Agent"="C:\\WINDOWS\\system32\\alsys.exe"
    "lnwin.exe"="C:\\WINDOWS\\system32\\lnwin.exe"
    "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
    "Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
    "DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"
    "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
    "NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
    "!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
    "nwiz"="nwiz.exe /install"
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\lib\\NMBgMonitor.exe\""
    "MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
    "Agent"="C:\\WINDOWS\\system32\\alsys.exe"
    "Steam"="\"C:\\Program Files\\Valve\\Steam\\Steam.exe\" -silent"
    "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
    ....
    Hosts file was reset, If you use a custom hosts file please replace it
    »»»»» End report »»»»»


    Logfile of HijackThis v1.99.1
    Scan saved at 9:55:47 PM, on 2/15/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    C:\WINDOWS\system32\sessmgr.exe
    C:\WINDOWS\system32\tcpsvcs.exe
    C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    C:\WINDOWS\stsystra.exe
    C:\WINDOWS\sm56hlpr.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\BigFix\bigfix.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Hamachi\hamachi.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MX6214
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.segasages.com/
    O1 - Hosts: 207.210.93.28 game01.us.segaonline.jp127.0.0.1
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [sysinter] C:\WINDOWS\system32\adirss.exe
    O4 - HKLM\..\Run: [Agent] C:\WINDOWS\system32\alsys.exe
    O4 - HKLM\..\Run: [lnwin.exe] C:\WINDOWS\system32\lnwin.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Agent] C:\WINDOWS\system32\alsys.exe
    O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
    O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5BC2959C-9ADC-45FE-B6B0-434B4E63D1B7}: NameServer = 85.255.116.82,85.255.112.117
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.82 85.255.112.117
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.82 85.255.112.117
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.82 85.255.112.117
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
    O21 - SSODL: DCOM Server 60787 - {2C1CD3D7-86AC-4068-93BC-A02304B60787} - C:\WINDOWS\system32\rwgz.dll (file missing)
    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe (file missing)
    O23 - Service: .NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (file missing)
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\system32\nvsvc32.exe (file missing)
    O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
    O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe (file missing)
    O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
  • Rahina-RescueRahina-Rescue Finland
    edited February 2007
    Please Download SDFix and save it to your desktop.

    Please then reboot your computer in Safe Mode by doing the following

    Restart your computer
    After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    Instead of Windows loading as normal, a menu with options should appear;
    Select the first option, to run Windows in Safe Mode, then press "Enter".
    Choose your usual account.



    In Safe Mode, right click the SDFix.zip folder and choose Extract All,
    Open the extracted folder and double click RunThis.bat to start the script.
    Type Y to begin the script.
    It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
    Press any Key and it will restart the PC.

    Your system will take longer that normal to restart as the fixtool will be running and removing files.
    When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.

    Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log
  • edited February 2007
    ok i did that and my function keys still arent working
    here are the logs


    SDFIX:
    SDFix: Version 1.65

    Run by: Owner - Fri 02/16/2007 @ 18:47:51.23

    Microsoft Windows XP [Version 5.1.2600]

    Running From: C:\SDFix

    Safe Mode:
    Checking Services:

    Name:

    Path:


    Restoring Windows Registry Entries
    Restoring Default Hosts File


    Rebooting...

    Normal Mode:
    Checking Files:

    Below files will be copied to Backups folder then removed:

    C:\DOCUME~1\Owner\LOCALS~1\Temp\74c81e11-d538-1a7c-4225-6dd2624c75cc.tmp.exe - Deleted
    C:\WINDOWS\system32\dlh9jkd1q8.exe - Deleted
    C:\WINDOWS\system32\wincom32.ini - Deleted
    C:\WINDOWS\system32\winsub.xml - Deleted
    C:\WINDOWS\system32\zlbw.dll - Deleted



    ADS Check:

    C:\WINDOWS\system32
    No streams found.

    Final Check:


    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
    "C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
    "C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
    "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
    "C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
    "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
    "C:\\DOCUME~1\\Owner\\LOCALS~1\\Temp\\dmx1D.tmp"="C:\\DOCUME~1\\Owner\\LOCALS~1\\Temp\\dmx1D.tmp:*:Enabled:sdfghjgewaertyutrew"
    "C:\\Program Files\\Starcraft\\starcraft.exe"="C:\\Program Files\\Starcraft\\starcraft.exe:*:Enabled:Starcraft"
    "C:\\Diablo\\Diablo.exe"="C:\\Diablo\\Diablo.exe:*:Enabled:Diablo"
    "C:\\WINDOWS\\system32\\game1.exe"="C:\\WINDOWS\\system32\\game1.exe:*:Disabled:enable"
    "C:\\Program Files\\Counter-Strike 1.6\\hl.exe"="C:\\Program Files\\Counter-Strike 1.6\\hl.exe:*:Enabled:Half-Life Launcher"
    "C:\\Program Files\\Counter-Strike 1.6\\hlds.exe"="C:\\Program Files\\Counter-Strike 1.6\\hlds.exe:*:Enabled:HLDS Launcher"
    "C:\\Program Files\\HTTP-Tunnel\\HTTP-TunnelClient.exe"="C:\\Program Files\\HTTP-Tunnel\\HTTP-TunnelClient.exe:*:Enabled:HTTP-Tunnel Client"
    "C:\\Program Files\\BYOND\\bin\\byond.exe"="C:\\Program Files\\BYOND\\bin\\byond.exe:*:Enabled:byond"
    "C:\\Program Files\\Xfire\\xfire.exe"="C:\\Program Files\\Xfire\\xfire.exe:*:Enabled:Xfire"
    "C:\\DOOM Collector's Edition\\Doom2\\skulltag.exe"="C:\\DOOM Collector's Edition\\Doom2\\skulltag.exe:*:Enabled:Skulltag"
    "C:\\Program Files\\Common Files\\AOL\\1135887152\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1135887152\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
    "C:\\Program Files\\Common Files\\AOL\\1135887152\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1135887152\\ee\\aim6.exe:*:Enabled:AIM"
    "C:\\SkullTag\\IdeSE.exe"="C:\\SkullTag\\IdeSE.exe:*:Enabled:IdeSE"
    "C:\\SkullTag\\skulltag.exe"="C:\\SkullTag\\skulltag.exe:*:Enabled:Skulltag"
    "C:\\SkullTag\\STOnline.exe"="C:\\SkullTag\\STOnline.exe:*:Enabled:Skulltag Online"
    "C:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"="C:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe:*:Enabled:Nintendo Wi-Fi USB Connector"
    "C:\\DOOM Collector's Edition\\Doom2\\STOnline.exe"="C:\\DOOM Collector's Edition\\Doom2\\STOnline.exe:*:Enabled:Skulltag Online"
    "C:\\Documents and Settings\\Owner\\Desktop\\hfs1.6a\\hfs.exe"="C:\\Documents and Settings\\Owner\\Desktop\\hfs1.6a\\hfs.exe:*:Enabled:hfs"
    "C:\\DOOM Collector's Edition\\Doom2\\Ide.exe"="C:\\DOOM Collector's Edition\\Doom2\\Ide.exe:*:Enabled:Ide"
    "C:\\Program Files\\Player Connector\\Connector.exe"="C:\\Program Files\\Player Connector\\Connector.exe:*:Enabled:Player Connector"
    "C:\\DOOM Collector's Edition\\Doom2\\GZDoom-Bin-0-9-25\\GZDoom.exe"="C:\\DOOM Collector's Edition\\Doom2\\GZDoom-Bin-0-9-25\\GZDoom.exe:*:Enabled:GZDoom"
    "C:\\Documents and Settings\\Owner\\Desktop\\Download\\HFS\\hfs.exe"="C:\\Documents and Settings\\Owner\\Desktop\\Download\\HFS\\hfs.exe:*:Enabled:hfs"
    "C:\\Program Files\\BitLord\\BitLord.exe"="C:\\Program Files\\BitLord\\BitLord.exe:*:Enabled:BitLord"
    "C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"="C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe:*:Enabled:Age of Empires 3"
    "C:\\Jon\\Emulation\\Super Nintendo\\zsnesv1.36\\v1.36\\ZSNESW.EXE"="C:\\Jon\\Emulation\\Super Nintendo\\zsnesv1.36\\v1.36\\ZSNESW.EXE:*:Enabled:ZSNESW"
    "C:\\Program Files\\zbattle.net\\zbattle.net.exe"="C:\\Program Files\\zbattle.net\\zbattle.net.exe:*:Enabled:zbattle.net"
    "C:\\Jon\\Emulation\\Super Nintendo\\zsnesw142\\zsnesw.exe"="C:\\Jon\\Emulation\\Super Nintendo\\zsnesw142\\zsnesw.exe:*:Enabled:zsnesw"
    "C:\\Program Files\\Teamspeak2_RC2\\server_windows.exe"="C:\\Program Files\\Teamspeak2_RC2\\server_windows.exe:*:Enabled:Server"
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
    "C:\\Program Files\\Valve\\Steam\\SteamApps\\steelwing\\half-life 2 deathmatch\\hl2.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\steelwing\\half-life 2 deathmatch\\hl2.exe:*:Enabled:hl2"
    "C:\\NeverwinterNights\\NWN\\nwmain.exe"="C:\\NeverwinterNights\\NWN\\nwmain.exe:*:Enabled:Neverwinter Nights"
    "C:\\Program Files\\Valve\\Steam\\SteamApps\\steelwing\\source dedicated server\\srcds.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\steelwing\\source dedicated server\\srcds.exe:*:Enabled:srcds"
    "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
    "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
    "C:\\Program Files\\Symantec\\pcAnywhere\\awhost32.exe"="C:\\Program Files\\Symantec\\pcAnywhere\\awhost32.exe:*:Disabled:pcAnywhere Host Service"
    "C:\\Program Files\\Symantec\\pcAnywhere\\awrem32.exe"="C:\\Program Files\\Symantec\\pcAnywhere\\awrem32.exe:*:Disabled:pcAnywhere Remote Service"
    "C:\\WINDOWS\\system32\\vxga4m1et4.exe"="C:\\WINDOWS\\system32\\vxga4m1et4.exe:*:Enabled:enable"
    "C:\\Program Files\\Quake III Arena\\quake3.exe"="C:\\Program Files\\Quake III Arena\\quake3.exe:*:Enabled:quake3"
    "C:\\Documents and Settings\\Owner\\Desktop\\Copy of Sshock2\\SHOCK2.exe"="C:\\Documents and Settings\\Owner\\Desktop\\Copy of Sshock2\\SHOCK2.exe:*:Enabled:System Shock 2"
    "C:\\WINDOWS\\system32\\dplaysvr.exe"="C:\\WINDOWS\\system32\\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "C:\\Program Files\\Unreal Tournament 2004\\System\\UT2004.exe"="C:\\Program Files\\Unreal Tournament 2004\\System\\UT2004.exe:*:Enabled:UT2004"


    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
    "C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"


    Remaining Files:

    Backups Folder: - C:\SDFix\backups\backups.zip


    Checking For Files with Hidden Attributes :


    Finished

    Hijackthis:

    Logfile of HijackThis v1.99.1
    Scan saved at 6:56:49 PM, on 2/16/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    C:\WINDOWS\system32\sessmgr.exe
    C:\WINDOWS\system32\tcpsvcs.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    C:\WINDOWS\stsystra.exe
    C:\WINDOWS\sm56hlpr.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\BigFix\bigfix.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MX6214
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.segasages.com/
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
    O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{00F84775-1792-4DCF-8049-7B85E039F6FE}: NameServer = 192.168.1.250
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5BC2959C-9ADC-45FE-B6B0-434B4E63D1B7}: NameServer = 85.255.116.82,85.255.112.117
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.82 85.255.112.117
    O17 - HKLM\System\CS1\Services\Tcpip\..\{00F84775-1792-4DCF-8049-7B85E039F6FE}: NameServer = 192.168.1.250
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.82 85.255.112.117
    O17 - HKLM\System\CS2\Services\Tcpip\..\{00F84775-1792-4DCF-8049-7B85E039F6FE}: NameServer = 192.168.1.250
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.82 85.255.112.117
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
    O21 - SSODL: DCOM Server 60787 - {2C1CD3D7-86AC-4068-93BC-A02304B60787} - C:\WINDOWS\system32\rwgz.dll (file missing)
    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe (file missing)
    O23 - Service: .NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (file missing)
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\system32\nvsvc32.exe (file missing)
    O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe (file missing)
    O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
  • Rahina-RescueRahina-Rescue Finland
    edited February 2007
    Please download FixWareout from here:
    http://downloads.subratam.org/Fixwareout.exe

    Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
    The fix will begin; follow the prompts. If your firewall gives an alert, (because this tool will download an additional file from the internet), please don't let your firewall block it, but allow it instead.
    Then you will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
    Once the desktop loads please post the text that will open (report.txt) and a new Hijackthis log

    Please post C:\Fixwareout\Report.txt in your next reply
  • edited February 2007
    im sorry? you already had me use fixwareout if you want i can run it again and post the logs
  • Rahina-RescueRahina-Rescue Finland
    edited February 2007
    My bad, i did not notice that i've given instructions for fixwareout already :confused:.

    Please be patient i will be back to you as soon as possible.
  • Rahina-RescueRahina-Rescue Finland
    edited February 2007
    Please open HiJackThis and scan. Check the boxes next to all the entries listed below

    O17 - HKLM\System\CCS\Services\Tcpip\..\{5BC2959C-9ADC-45FE-B6B0-434B4E63D1B7}: NameServer = 85.255.116.82,85.255.112.117
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.82 85.255.112.117
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.82 85.255.112.117
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.82 85.255.112.117


    Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.

    Download ATF-Cleaner by Atribune to your desktop.

    Do NOT run it yet.

    Run ATF Cleaner Under Main choose: Select All
    Click the Empty Selected button.

    If you use Firefox browser Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main menu to close the program.


    Please run an online scan using:

    Kaspersky On-line Scanner

    When you are prompted to install an ActiveX component from Kaspersky, Click Yes.

    The program will launch and then begin downloading the latest definition files
    When the files finish downloading click on NEXT
    Now click on Scan Settings
    In Scan Settings make sure that the following are selected:
    Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)

    Scan Options:

    Scan Archives
    Scan Mail Bases


    Click OK

    Now under select a target to scan:
    Select My Computer
    This program will start and scan your system.
    Online scan can take a long time to complete and the time is impacted by the speed of your internet connection. Be patient and let it run. It is best not to do anything else while the scan is running. This will help it to complete faster.
    When the scan has completed, it will display whether your system has been infected or not
    Click on the Save as Text button:
    Save the file to your desktop or another folder where you can locate it later.
    Attach this file to your next message.

    Please Post a Fresh HJT-Log & Kaspersky Report Let me know how things are running now
  • edited February 2007
    we've got a problem.. the link you gave me appears to take me to the right place but when i click the "accept" button for the privacy statement nothing happens literally nothing happens it just sits there i never got a prompt for an active x control either...
  • Rahina-RescueRahina-Rescue Finland
    edited February 2007
    Hmm, interesting.

    Let's try using F-secure online scanner :thumbsup:


    Please run the F-Secure Online Scanner

    Note: This Scanner is for Internet Explorer Only!


    Follow the Instruction Here for installation.
    Accept the License Agreement.
    Once the ActiveX installs,Click Full System Scan
    Once the download completes,the scan will begin automatically.
    The scan will take some time to finish,so please be patient.
    When the scan completes, click the Automatic cleaning (recommended) button.
    Click the Show Report button and Copy&Paste the entire report in your next reply.

    Also post a HJT Log in your next reply.
  • edited February 2007
    the second link takes me to the same place as the first one both take me to the home page of that website do i do full or custom scan?
  • Rahina-RescueRahina-Rescue Finland
    edited February 2007
    Once the ActiveX installs,Click Full System Scan
  • TroganTrogan London, UK
    edited February 2007
    Whilst we appreciate that you may be busy, it has been 7 days or more since we heard from you.

    Infections can change and fresh instructions will now need to be given. This topic is now closed, if you still require assistance then please start a new topic in the Spyware & Virus Removal Forum

    If you wish this topic reopened, please send a Private Message (PM) to one of the Spyware Mods with a link to your thread.

    Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required.
    If you are not the user who started this thread, you must start a new Thread instead :)
  • TroganTrogan London, UK
    edited March 2007
    Thread reopened!
  • Rahina-RescueRahina-Rescue Finland
    edited March 2007
    Welcome Back Sonic_Hawk. :)

    Please run a Scan with F-secure online scanner, choose Full system scan :).

    When done, post a Fresh HJT logfile along with F-secure Scan Report.
  • edited March 2007
    here it is atlast (sorry it took so long)

    HJT:Logfile of HijackThis v1.99.1
    Scan saved at 6:41:33 PM, on 3/4/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    C:\WINDOWS\stsystra.exe
    C:\WINDOWS\system32\tcpsvcs.exe
    C:\WINDOWS\sm56hlpr.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\system32\WLTRAY.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\BigFix\bigfix.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\DOCUME~1\Owner\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk32.exe
    C:\DOCUME~1\Owner\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fssm32.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=PTB&M=MX6214
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.segasages.com/
    O1 - Hosts: 207.210.93.28 game01.us.segaonline.jp
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
    O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
    O21 - SSODL: DCOM Server 60787 - {2C1CD3D7-86AC-4068-93BC-A02304B60787} - (no file)
    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe (file missing)
    O23 - Service: .NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (file missing)
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\system32\nvsvc32.exe (file missing)
    O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe (file missing)
    O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE






    F-Secure: Scanning Report

    Sunday, March 04, 2007 17:04:59 - 18:21:58

    Computer name: JONLAPTOP
    Scanning type: Scan system for viruses, rootkits, spyware
    Target: C:\ D:\

    Result: 18 malware found

    Email-Worm.Win32.Mixor.a (virus)

      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014518.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014519.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014520.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014521.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014522.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014523.EXE (Disinfected)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014524.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014525.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014526.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014527.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014528.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014529.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014530.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014531.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014532.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014533.EXE (Disinfected & Submitted)
      [*]D:\SYSTEM VOLUME INFORMATION\_RESTORE{9A0B68BF-A813-459E-82EB-B74AEA9AFFBB}\RP29\A0014534.EXE (Disinfected & Submitted)
      Win32.TrojanDownloader.Small (spyware)

        [*]System (Disinfected)
        Statistics

        Scanned:

          [*]Files: 32293
          [*]System: 9724
          [*]Not scanned: 3
          Actions:

            [*]Disinfected: 18
            [*]Renamed: 0
            [*]Deleted: 0
            [*]None: 0
            [*]Submitted: 16
            Files not scanned:

              [*]C:\HIBERFIL.SYS
              [*]C:\PAGEFILE.SYS
              [*]C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
              Options

              Scanning engines:

                [*]F-Secure Libra: 2.4.2, 2007-03-02
                [*]F-Secure AVP: 7.0.171, 2007-03-03
                [*]F-Secure Orion: 1.2.37, 2007-03-04
                [*]F-Secure Blacklight: 1.0.53, 0000-00-00
                [*]F-Secure Draco: 1.0.35, 2007-02-09
                [*]F-Secure Pegasus: 1.19.0, 2007-01-28
                Scanning options:

                  [*]Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX
                  [*]Use Advanced heuristics
                    Copyright © 1998-2006 Product support |Send virus sample to F-Secure

                    F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.








                  • Rahina-RescueRahina-Rescue Finland
                    edited March 2007
                    Excellent work, we only have few things to do :)

                    Part of the fix may require you to be in Safe Mode, which will not allow you to access the internet, or my instructions! I Suggest you print these Instructions out.

                    Please open HiJackThis and scan. Check the boxes next to all the entries listed below


                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)
                    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll (file missing)


                    Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.


                    Download the latest version of Java Runtime Environment (JRE) 6

                    Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
                    Click the "Download" button to the right.
                    Check the box that says: "Accept License Agreement".
                    The page will refresh.

                    Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
                    Close any programs you may have running - especially your web browser.
                    Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.

                    Check any item with Java Runtime Environment (JRE or J2SE) in the name.
                    Click the Remove or Change/Remove button.
                    Repeat as many times as necessary to remove each Java versions.
                    Reboot your computer once all Java components are removed.
                    Then from your desktop double-click on the download to install the newest version.



                    Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)

                    1. Turn off System Restore.
                    On the Desktop, right-click My Computer.
                    Click Properties.
                    Click the System Restore tab.
                    Check Turn off System Restore.
                    Click Apply, and then click OK.2. Restart your computer.

                    3. Turn ON System Restore.
                    On the Desktop, right-click My Computer.
                    Click Properties.
                    Click the System Restore tab.
                    UN-Check Turn off System Restore.
                    Click Apply, and then click OK.

                    System Restore will now be active again.




                    Download CCleaner

                    if you don't use Yahoo toolbar, be sure to UNcheck that option when installing the software or update.

                    Instructions for using CCleaner:
                    1. Launch CCleaner and under Options > Advanced > UNcheck "Only delete files in Windows Temp folder older than 48 hours".
                    2. A pop up box will appear advising this process will permanently delete files from your system.
                    3. To protect logon cookies that you wish to retain, under Options > Cookies. Select and using the arrow move those cookies to the "Cookies to keep" column.
                    4. Then select the items you wish to clean up.
                      1. In the Windows Tab:
                        • Clean all entries in the "Internet Explorer" section.
                        • Clean all the entries in the "Windows Explorer" section.
                        • Clean all entries in the "System" section.
                        • Clean all entries in the "Advanced" section.
                        • Clean any others that you choose.
                      2. In the Applications Tab:
                        • Clean all in the Firefox/Mozilla section if you use it.
                        • Clean all in the Opera section if you use it.
                        • Clean Sun Java in the Internet Section.
                        • Please UNcheck "Utilities" (i.e., Ad-Aware, ewido and other security program logs.)
                    5. Click the "Run Cleaner" button and it will scan and clean your system.
                    6. Click exit.
                    7. Shutdown/restart the computer.



                    Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
                    http://www.ewido.net/en/download/
                    • Install AVG Anti-Spyware by double clicking the installer.
                    • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
                    • On the main screen under Your Computer's security.
                      • Click on Change state next to Resident shield. It should now change to inactive.
                      • Click on Change state next to Automatic updates. It should now change to inactive.
                      • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
                      • Wait until you see the Update succesfull message.
                    • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
                    • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
                    If you are having problems with the updater, you can use this link to manually update ewido.
                    AVG Anti-Spyware manual updates.
                    Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

                    Reboot your computer in Safe Mode.
                    • If the computer is running, shut down Windows, and then turn off the power.
                    • Wait 30 seconds, and then turn the computer on.
                    • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
                    • Ensure that the Safe Mode option is selected.
                    • Press Enter. The computer then begins to start in Safe mode.
                    • Login on your usual account.
                    Once in Safe Mode:

                    Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
                    • Click on Scanner on the toolbar.
                    • Click on the Settings tab.
                      • Under How to act?
                        • Click on Recommended Action and choose Quarantine from the popup menu.
                      • Under How to scan?
                        • All checkboxes should be ticked.
                      • Under Possibly unwanted software:
                        • All checkboxes should be ticked.
                      • Under Reports:
                        • Select Automatically generate report after every scan and uncheck Only if threats were found.
                      • Under What to scan?
                        • Select Scan every file.
                    • Click on the Scan tab.
                    • Click on Complete System Scan to start the scan process.
                    • Let the program scan the machine.
                    • When the scan has finished, follow the instructions below.
                      IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
                      • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
                      • At the bottom of the window click on the Apply all Actions button. (3)
                        scanavgjk2.jpg
                    • When done, click the Save Scan Report button. (4)
                      • Click the Save Report as button.
                      • Save the report to your Desktop.
                    • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
                    Reboot back into Normal Mode, and post a new HJT log, along with the AVG Anti-Spyware log.
                  • edited March 2007
                    !problem! i cant remove the updates to Java Runtime 5.0
                    i was only able to remove update 2 the rest are stuck there when i try to remove the i get this error every time:errorpb4.png

                    so after checking i saw that only one path existed (update 2) and i dont know how to get rid of the others i deleted the java folder and i'm still confused

                    (other problems i noticed include: before finding this site i decided to try and reinstall windows but everytime i tried it would claim that i didnt have a hard drive to install it on.. apparently i also got it stuck in the boot partitions area too whenever i select it it claims that the hal.dll is missing or corrupt and forces restart so i just boot into my original partition (this problem still isnt fixed and i've been meaning to mention it) i also tried removing it from the boot.ini but that just made it change its name to "windows default" system restore doesnt work and this computer claims to not have a battery (but still runs on one lol!) this hasnt been fixed yet either it cant go into standby or hibernate anymore either none of these problems have been fixed yet any help with these as well would be greatly appreciated.)

                    any ideas?

                    also i already had AVG Anti Spyware (got it after the virus) and well the trial ran out
                  • Rahina-RescueRahina-Rescue Finland
                    edited March 2007
                    Sonic_Hawk wrote:
                    !problem! i cant remove the updates to Java Runtime 5.0
                    i was only able to remove update 2 the rest are stuck there when i try to remove the i get this error every time:errorpb4.png

                    so after checking i saw that only one path existed (update 2) and i dont know how to get rid of the others i deleted the java folder and i'm still confused

                    (other problems i noticed include: before finding this site i decided to try and reinstall windows but everytime i tried it would claim that i didnt have a hard drive to install it on.. apparently i also got it stuck in the boot partitions area too whenever i select it it claims that the hal.dll is missing or corrupt and forces restart so i just boot into my original partition (this problem still isnt fixed and i've been meaning to mention it) i also tried removing it from the boot.ini but that just made it change its name to "windows default" system restore doesnt work and this computer claims to not have a battery (but still runs on one lol!) this hasnt been fixed yet either it cant go into standby or hibernate anymore either none of these problems have been fixed yet any help with these as well would be greatly appreciated.)

                    any ideas?

                    also i already had AVG Anti Spyware (got it after the virus) and well the trial ran out


                    Why, did you delete your Java folde r:confused: ? I did not tell you to do that, we were only going to update it to the latest version.

                    ______________________



                    Please run Panda's ActiveScan You will need to use Internet Explorer to run it.

                    • Once you are on the Panda site click the Scan your PC button
                    • A new window will open...click the Check Now button
                    • Enter your Country
                    • Enter your State/Province
                    • Enter your e-mail address and click send
                    • Select either Home User or Company
                    • Click the big Scan Now button
                    o If it wants to install an ActiveX component allow it
                    o It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
                    o When download is complete, click on My Computer to start the scan
                    o When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.


                    Post the contents of the ActiveScan report
                  • Rahina-RescueRahina-Rescue Finland
                    edited March 2007
                    Whilst we appreciate that you may be busy, it has been 7 days or more since we heard from you.

                    Infections can change and fresh instructions will now need to be given. This topic is now closed, if you still require assistance then please start a new topic in the Spyware & Virus Removal Forum

                    If you wish this topic reopened, please send a Private Message (PM) to one of the Spyware Mods with a link to your thread.

                    Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required.
                    If you are not the user who started this thread, you must start a new Thread instead :)
                  • Rahina-RescueRahina-Rescue Finland
                    edited March 2007
                    Topic Re-Opened
                  • edited March 2007
                    here is the report:
                    Incident Status Location

                    Adware:adware/securityerror Not disinfected C:\Documents and Settings\Owner\Favorites\Antivirus Test Online.url
                    Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt[.statcounter.com/]
                    Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt[.casalemedia.com/]
                    Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt[ad.yieldmanager.com/]
                    Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt[.adrevolver.com/]
                    Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt[.yadro.ru/]
                    Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt[.com.com/]
                    Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt[.as-us.falkag.net/]
                    Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt[.burstnet.com/]
                    Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt[www.burstbeacon.com/]
                    Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt[adserver.filefront.com/]
                    Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt[.realmedia.com/]
                    Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt[.zedo.com/]
                    Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt.old[.as-eu.falkag.net/]
                    Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt.old[.bs.serving-sys.com/]
                    Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt.old[.burstnet.com/]
                    Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt.old[.com.com/]
                    Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt.old[.i.screensavers.com/]
                    Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt.old[.realmedia.com/]
                    Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt.old[.revenue.net/]
                    Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt.old[.serving-sys.com/]
                    Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt.old[.yadro.ru/]
                    Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt.old[ad.yieldmanager.com/]
                    Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt.old[adserver.filefront.com/]
                    Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt.old[searchportal.information.com/]
                    Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\w5n70j63.default\cookies.txt.old[www.burstbeacon.com/]
                    Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Owner\Desktop\SDFix\SDFix.exe[SDFix\apps\Process.exe]
                    Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Owner\Desktop\SDFix.zip[SDFix.exe][SDFix\apps\Process.exe]
                    Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\fixwareout\FindT\nircmd.exe
                    Potentially unwanted tool:Application/Processor Not disinfected C:\SDFix\apps\Process.exe
                  • Rahina-RescueRahina-Rescue Finland
                    edited March 2007
                    Please download SmitfraudFix (by S!Ri) to your Desktop.

                    Double-click SmitfraudFix.exe
                    Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
                    Please copy/paste the content of that report into your next reply.

                    **If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.


                    Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
                    http://www.beyondlogic.org/consulting/proc...processutil.htm
                  • edited March 2007
                    here you go: SmitFraudFix v2.158

                    Scan done at 18:11:32.29, Wed 03/28/2007
                    Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix
                    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
                    The filesystem type is NTFS
                    Fix run in normal mode

                    »»»»»»»»»»»»»»»»»»»»»»»» Process

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
                    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                    C:\WINDOWS\stsystra.exe
                    C:\WINDOWS\sm56hlpr.exe
                    C:\WINDOWS\system32\igfxtray.exe
                    C:\WINDOWS\system32\hkcmd.exe
                    C:\WINDOWS\system32\igfxpers.exe
                    C:\WINDOWS\system32\WLTRAY.exe
                    C:\WINDOWS\system32\igfxsrvc.exe
                    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
                    C:\Program Files\D-Tools\daemon.exe
                    C:\Program Files\QuickTime\qttask.exe
                    C:\Program Files\Winamp\winampa.exe
                    C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                    C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
                    C:\Program Files\MSN Messenger\MsnMsgr.Exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
                    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
                    C:\Program Files\BigFix\bigfix.exe
                    C:\WINDOWS\system32\tcpsvcs.exe
                    C:\Program Files\Xfire\xfire.exe
                    C:\WINDOWS\system32\wscntfy.exe
                    C:\Program Files\MSN Messenger\usnsvc.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Program Files\Winamp\winamp.exe
                    C:\WINDOWS\system32\cmd.exe

                    »»»»»»»»»»»»»»»»»»»»»»»» hosts


                    »»»»»»»»»»»»»»»»»»»»»»»» C:\


                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner


                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner\Application Data


                    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                    C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
                    C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Owner\FAVORI~1

                    C:\DOCUME~1\Owner\FAVORI~1\Antivirus Test Online.url FOUND !

                    »»»»»»»»»»»»»»»»»»»»»»»» Desktop


                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


                    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


                    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                    "Source"="About:Home"
                    "SubscribedURL"="About:Home"
                    "FriendlyName"="My Current Home Page"


                    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                    !!!Attention, following keys are not inevitably infected!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                    "{2C1CD3D7-86AC-4068-93BC-A02304B60787}"="DCOM Server 60787"



                    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                    !!!Attention, following keys are not inevitably infected!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                    "AppInit_DLLs"=""


                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                    !!!Attention, following keys are not inevitably infected!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    "system"=""


                    »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32


                    »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


                    »»»»»»»»»»»»»»»»»»»»»»»» End
                  • Rahina-RescueRahina-Rescue Finland
                    edited March 2007
                    Excellent! :smiles:

                    You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

                    Next, please reboot your computer in Safe Mode by doing the following :
                    • Restart your computer
                    • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
                    • Instead of Windows loading as normal, a menu with options should appear;
                    • Select the first option, to run Windows in Safe Mode, then press "Enter".
                    • Choose your usual account.
                    Once in Safe Mode, double-click on SmitfraudFix.exe
                    Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

                    You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

                    The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

                    The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
                    A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
                    The report can also be found at the root of the system drive, usually at C:\rapport.txt

                    Warning : running option #2 on a non infected computer will remove your Desktop background.
                  • edited March 2007
                    here it is:aSmitFraudFix v2.158

                    Scan done at 8:51:30.03, Fri 03/30/2007
                    Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix
                    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
                    The filesystem type is NTFS
                    Fix run in safe mode

                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                    !!!Attention, following keys are not inevitably infected!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                    "{2C1CD3D7-86AC-4068-93BC-A02304B60787}"="DCOM Server 60787"


                    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                    127.0.0.1 localhost
                    207.210.93.28 game01.us.segaonline.jp

                    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                    GenericRenosFix by S!Ri


                    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                    C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
                    C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
                    C:\DOCUME~1\Owner\FAVORI~1\Antivirus Test Online.url Deleted

                    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                    !!!Attention, following keys are not inevitably infected!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    "system"=""


                    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                    Registry Cleaning done.

                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                    !!!Attention, following keys are not inevitably infected!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                    "{2C1CD3D7-86AC-4068-93BC-A02304B60787}"="DCOM Server 60787"



                    »»»»»»»»»»»»»»»»»»»»»»»» End

                    oh and it never prompted me on that wininet.dll thing
                  Sign In or Register to comment.