Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register Members New Posts Donate Unanswered Posts Site Spy Search


Reply
 
Thread Tools
  #1  
Old 13-12-2007, 06:11 AM
No Avatar
drgg  England
CJ New Member
 
drgg is offline
 
Join Date: Dec 2007
Last Online: 16-12-2007 04:37 AM
Posts: 16
iTrader: (0)
drgg is on a distinguished road
Default Please Help!!!

About 4 days ago my laptop got attacked and is now infected ive tried using many anti-spyware programs to get rid of the spyware, trojans, worms etc on my laptop. Ive used Ad-Aware 2007, Kaspersky Anti-Virus, Spyware Terminator, CounterSpy and WinPatrol but i cant get rid of the nasties. Am i just doing something wrong? XP Antivirus tells me that there are 11 infections, but because im not registered i can only scan and not get rid of the infections. The infections they are:

- Trojan Worm.Win32.Womble
- Trojan.Win32.Agent.brk
- Trojan Worm.Win32.NetSky
- Trojan Infostealer.Banker
- Trojan.Tooso
- Spyware Spy.HTML.Paylap.bg
- Spyware.IEMonster
- Spyware.IMMonitor
- Adware Zlob.PornAdvertiser.ba
- Backdoor Win32.Rbot.fm
- Dialer.Xpehbam.biz_dialer

Does anyone know how i can get rid of these infections? Im not good with computers and ive tried everything that i know to get rid of viruses but nothings working.

For some reason i have 3 icons on my desktop that i dont remember installing and everytime i delete them they appear after i turn off the laptop and turn it back on. Thay are Error Cleaner, Privacy Protector and SPyware and Protection. Are they part of the spware on my laptop?

Another problem im also having is with the internet explorer window. It opens automatically every few minutes, is this part of the spyware? Also is there anyway i can stop the windows security alerts and the flashing cross that pops up on my toolbar every few minutes?

If anyone can please help me with how to get rid of the infections or any advice, that would be fantastic! I need help BADLY!!!
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #2  
Old 13-12-2007, 06:12 AM
No Avatar
drgg  England
CJ New Member
 
drgg is offline
 
Join Date: Dec 2007
Last Online: 16-12-2007 04:37 AM
Posts: 16
iTrader: (0)
drgg is on a distinguished road
Default Please Help!!!

Heres the log from Hijack This

[FONT=Times New Roman][SIZE=3]
[FONT=Times New Roman][SIZE=3]Logfile of Trend Micro HijackThis v2.0.2[/SIZE][/FONT]
[SIZE=3][FONT=Times New Roman]Scan saved at 5:24:53 PM, on 13/12/2007[/FONT][/SIZE]
[FONT=Times New Roman][SIZE=3]Platform: Windows XP SP2 (WinNT 5.01.2600)[/SIZE][/FONT]
[SIZE=3][FONT=Times New Roman]MSIE: Internet Explorer v7.00 (7.00.5730.0013)[/FONT][/SIZE]
[SIZE=3][FONT=Times New Roman]Boot mode: Normal[/FONT][/SIZE]
[FONT=Times New Roman][/FONT]
[FONT=Times New Roman][SIZE=3]Running processes:[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSSystem32smss.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32winlogon.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32services.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32lsass.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32svchost.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSSystem32svchost.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32ZoneLabsvsmon.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSExplorer.EXE[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesLavasoftAd-Aware 2007aawservice.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32spoolsv.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesTOSHIBAConfigFreeCFSvcs.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32DVDRAMSV.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesSunbelt SoftwareCounterSpySBCSSvc.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32svchost.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32igfxtray.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32hkcmd.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32wuauclt.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesTOSHIBAE-KEYCeEKey.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesApoint2KApoint.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesTOSHIBATouchPadTPTray.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesToshibaTvsTvsTray.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32TPSMain.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32ZoomingHook.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesTOSHIBATOSHIBA Zooming UtilitySmoothView.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesTOSHIBAAccessibilityFnKeyHook.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32dlatfswctrl.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesTOSHIBATouch and LaunchPadExe.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSAGRSMMSG.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesltmohLtmoh.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32TCtrlIOHook.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesQuickTimeqttask.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesiTunesiTunesHelper.exe[/SIZE][/FONT]
[SIZE=3][FONT=Times New Roman]C:Program FilesZone LabsZoneAlarmzlclient.exe[/FONT][/SIZE]
[FONT=Times New Roman][SIZE=3]C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesBillP StudiosWinPatrolwinpatrol.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesSunbelt SoftwareCounterSpySBCSTray.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesTOSHIBATOSCDSPDtoscdspd.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32ctfmon.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program Filesiriveririver plusiAgent.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesMSN MessengerMsnMsgr.Exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesXP Antivirusxpa.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesApoint2KApntex.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesiPodbiniPodService.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32TPSBattM.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:WINDOWSsystem32RAMASST.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesToshibaTOSHIBA ControlsTFncKy.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]C:Program FilesTrend MicroHijackThisHijackThis.exe[/SIZE][/FONT]
[FONT=Times New Roman][/FONT]
[FONT=Times New Roman][SIZE=3]R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:WINDOWSsystem32dlatfswshx.dll[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O2 - BHO: OFK System - {F08487B1-AFEC-45CF-B2E9-D05DEE137D22} - C:WINDOWSblopenvtok.dll[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [IgfxTray] C:WINDOWSsystem32igfxtray.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [HotKeysCmds] C:WINDOWSsystem32hkcmd.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [nwiz] nwiz.exe /install[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [CeEKEY] C:Program FilesTOSHIBAE-KEYCeEKey.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [Apoint] C:Program FilesApoint2KApoint.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [TPNF] C:Program FilesTOSHIBATouchPadTPTray.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [Tvs] C:Program FilesToshibaTvsTvsTray.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [TPSMain] TPSMain.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [ZoomingHook] ZoomingHook.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [SmoothView] C:Program FilesTOSHIBATOSHIBA Zooming UtilitySmoothView.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [HWSetup] C:Program FilesTOSHIBATOSHIBA AppletHWSetup.exe hwSetUP[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [TOSHIBA Accessibility] C:Program FilesTOSHIBAAccessibilityFnKeyHook.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [dla] C:WINDOWSsystem32dlatfswctrl.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [SVPWUTIL] C:Program FilesToshibaWindows UtilitiesSVPWUTIL.exe SVPwUTIL[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [PadTouch] C:Program FilesTOSHIBATouch and LaunchPadExe.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [AGRSMMSG] AGRSMMSG.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [TCtryIOHook] TCtrlIOHook.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [iTunesHelper] "C:Program FilesiTunesiTunesHelper.exe"[/SIZE][/FONT]
[SIZE=3][FONT=Times New Roman]O4 - HKLM..Run: [ZoneAlarm Client] "C:Program FilesZone LabsZoneAlarmzlclient.exe"[/FONT][/SIZE]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [AVP] "C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe"[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [WinPatrol] C:Program FilesBillP StudiosWinPatrolwinpatrol.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKLM..Run: [SBCSTray] C:Program FilesSunbelt SoftwareCounterSpySBCSTray.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKCU..Run: [TOSCDSPD] C:Program FilesTOSHIBATOSCDSPDtoscdspd.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKCU..Run: [iPlusAgent] "C:Program Filesiriveririver plusiAgent.exe"[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKCU..Run: [MsnMsgr] "C:Program FilesMSN MessengerMsnMsgr.Exe" /background[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - HKCU..Run: [XP Antivirus] C:Program FilesXP Antivirusxpa.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:Program FilesMicrosoft OfficeOFFICE11ONENOTEM.EXE[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O4 - Global Startup: RAMASST.lnk = C:WINDOWSsystem32RAMASST.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~3OFFICE11EXCEL.EXE/3000[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_01binnpjpi150_01.dll[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_01binnpjpi150_01.dll[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0SCIEPlgn.dll[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~3OFFICE11REFIEBAR.DLL[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O21 - SSODL: leorop - {2E9AD39F-F65D-4454-9835-2AA38B594F64} - C:WINDOWSleorop.dll[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O21 - SSODL: nopzet - {52E0071B-BEB8-4436-A595-E00EBD2D82D0} - C:WINDOWSnopzet.dll[/SIZE][/FONT]
[SIZE=3][FONT=Times New Roman]O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:Program FilesLavasoftAd-Aware 2007aawservice.exe[/FONT][/SIZE]
[FONT=Times New Roman][SIZE=3]O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:Program FilesTOSHIBAConfigFreeCFSvcs.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:WINDOWSsystem32DVDRAMSV.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O23 - Service: iPod Service - Apple Computer, Inc. - C:Program FilesiPodbiniPodService.exe[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O23 - Service: LiveUpdate - Symantec Corporation - C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe[/SIZE][/FONT]
[SIZE=3][FONT=Times New Roman]O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:Program FilesSunbelt SoftwareCounterSpySBCSSvc.exe[/FONT][/SIZE]
[FONT=Times New Roman][SIZE=3]O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:WINDOWSsystem32ZoneLabsvsmon.exe[/SIZE][/FONT]
[FONT=Times New Roman][/FONT]
[FONT=Times New Roman][SIZE=3]--[/SIZE][/FONT]
[FONT=Times New Roman][SIZE=3]End of file - 8197 bytes[/SIZE][/FONT]
[/SIZE][/FONT]
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #3  
Old 13-12-2007, 07:35 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Yesterday 08:02 PM
Posts: 4,609
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Please Help!!!

Run another HijackThis scan and just copy and then paste the log from notepad directly into the post. No quotes.
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #4  
Old 13-12-2007, 08:30 AM
No Avatar
drgg  England
CJ New Member
 
drgg is offline
 
Join Date: Dec 2007
Last Online: 16-12-2007 04:37 AM
Posts: 16
iTrader: (0)
drgg is on a distinguished road
Default Please Help!!!

Sorry that it took me so long to reply, for some reasone the replies to my post didnt come up. Anyhow someone helped me out from another forum and this is the new log after he told me to use SmitFraudFix. Sorry i dont know how to put it on notepad so ill have to quote again. Can you save form notepad onto the USB because its not working.

Heres the log from SmitFraudFix
SmitFraudFix v2.266

Scan done at 19:38:39.67, Thu 13/12/2007
Run from C:Program FilesSmitSmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:WINDOWSblopenvt??.dll Deleted
C:WINDOWSjokvip.exe Deleted
C:WINDOWSleorop.dll Deleted
Deleting [HKEY_CLASSES_ROOTCLSID{2E9AD39F-F65D-4454-9835-2AA38B594F64}]
Deleting [HKEY_LOCAL_MACHINESoftwareClassesCLSID{2E9AD39 F-F65D-4454-9835-2AA38B594F64}]
C:WINDOWSnopzet.dll Deleted
Deleting [HKEY_CLASSES_ROOTCLSID{52E0071B-BEB8-4436-A595-E00EBD2D82D0}]
C:WINDOWSretnsrp.dll Deleted
C:DOCUME~1SOCCER~1DesktopError Cleaner.url Deleted
C:DOCUME~1SOCCER~1DesktopPrivacy Protector.url Deleted
C:DOCUME~1SOCCER~1DesktopSpyware?Malware Protection.url Deleted
C:DOCUME~1SOCCER~1FAVORI~1Error Cleaner.url Deleted
C:DOCUME~1SOCCER~1FAVORI~1Privacy Protector.url Deleted
C:DOCUME~1SOCCER~1FAVORI~1Spyware?Malware Protection.url Deleted
C:Program FilesRichVideoCodec Deleted

»»»»»»»»»»»»»»»»»»»»»»»» DNS



»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
And this is the log from Hijack This

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:52:30 PM, on 13/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32ZoneLabsvsmon.exe
C:WINDOWSExplorer.EXE
C:Program FilesLavasoftAd-Aware 2007aawservice.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe
C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe
C:Program FilesTOSHIBAConfigFreeCFSvcs.exe
C:WINDOWSsystem32DVDRAMSV.exe
C:Program FilesSunbelt SoftwareCounterSpySBCSSvc.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32igfxtray.exe
C:WINDOWSsystem32hkcmd.exe
C:Program FilesTOSHIBAE-KEYCeEKey.exe
C:Program FilesApoint2KApoint.exe
C:Program FilesTOSHIBATouchPadTPTray.exe
C:Program FilesToshibaTvsTvsTray.exe
C:WINDOWSsystem32TPSMain.exe
C:WINDOWSsystem32ZoomingHook.exe
C:Program FilesTOSHIBATOSHIBA Zooming UtilitySmoothView.exe
C:Program FilesTOSHIBAAccessibilityFnKeyHook.exe
C:WINDOWSsystem32dlatfswctrl.exe
C:Program FilesTOSHIBATouch and LaunchPadExe.exe
C:WINDOWSAGRSMMSG.exe
C:Program FilesltmohLtmoh.exe
C:WINDOWSsystem32TCtrlIOHook.exe
C:Program FilesQuickTimeqttask.exe
C:Program FilesiTunesiTunesHelper.exe
C:Program FilesZone LabsZoneAlarmzlclient.exe
C:Program FilesBillP StudiosWinPatrolwinpatrol.exe
C:Program FilesSunbelt SoftwareCounterSpySBCSTray.exe
C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe
C:Program FilesTOSHIBATOSCDSPDtoscdspd.exe
C:WINDOWSsystem32ctfmon.exe
C:Program Filesiriveririver plusiAgent.exe
C:Program FilesMSN MessengerMsnMsgr.Exe
C:Program FilesXP Antivirusxpa.exe
C:WINDOWSsystem32RAMASST.exe
C:WINDOWSsystem32TPSBattM.exe
C:Program FilesApoint2KApntex.exe
C:Program FilesiPodbiniPodService.exe
C:Program FilesToshibaTOSHIBA ControlsTFncKy.exe
C:Program FilesTrend MicroHijackThisHijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:WINDOWSsystem32dlatfswshx.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesCommon FilesMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O4 - HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [IgfxTray] C:WINDOWSsystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:WINDOWSsystem32hkcmd.exe
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [CeEKEY] C:Program FilesTOSHIBAE-KEYCeEKey.exe
O4 - HKLM..Run: [Apoint] C:Program FilesApoint2KApoint.exe
O4 - HKLM..Run: [TPNF] C:Program FilesTOSHIBATouchPadTPTray.exe
O4 - HKLM..Run: [Tvs] C:Program FilesToshibaTvsTvsTray.exe
O4 - HKLM..Run: [TPSMain] TPSMain.exe
O4 - HKLM..Run: [ZoomingHook] ZoomingHook.exe
O4 - HKLM..Run: [SmoothView] C:Program FilesTOSHIBATOSHIBA Zooming UtilitySmoothView.exe
O4 - HKLM..Run: [HWSetup] C:Program FilesTOSHIBATOSHIBA AppletHWSetup.exe hwSetUP
O4 - HKLM..Run: [TOSHIBA Accessibility] C:Program FilesTOSHIBAAccessibilityFnKeyHook.exe
O4 - HKLM..Run: [dla] C:WINDOWSsystem32dlatfswctrl.exe
O4 - HKLM..Run: [SVPWUTIL] C:Program FilesToshibaWindows UtilitiesSVPWUTIL.exe SVPwUTIL
O4 - HKLM..Run: [PadTouch] C:Program FilesTOSHIBATouch and LaunchPadExe.exe
O4 - HKLM..Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM..Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM..Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [iTunesHelper] "C:Program FilesiTunesiTunesHelper.exe"
O4 - HKLM..Run: [ZoneAlarm Client] "C:Program FilesZone LabsZoneAlarmzlclient.exe"
O4 - HKLM..Run: [WinPatrol] C:Program FilesBillP StudiosWinPatrolwinpatrol.exe
O4 - HKLM..Run: [SBCSTray] C:Program FilesSunbelt SoftwareCounterSpySBCSTray.exe
O4 - HKLM..Run: [MSConfig] C:WINDOWSPCHealthHelpCtrBinariesMSConfig.exe /auto
O4 - HKLM..Run: [AVP] "C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe"
O4 - HKCU..Run: [TOSCDSPD] C:Program FilesTOSHIBATOSCDSPDtoscdspd.exe
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [iPlusAgent] "C:Program Filesiriveririver plusiAgent.exe"
O4 - HKCU..Run: [MsnMsgr] "C:Program FilesMSN MessengerMsnMsgr.Exe" /background
O4 - HKCU..Run: [XP Antivirus] C:Program FilesXP Antivirusxpa.exe
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:Program FilesMicrosoft OfficeOFFICE11ONENOTEM.EXE
O4 - Global Startup: RAMASST.lnk = C:WINDOWSsystem32RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~3OFFICE11EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_01binnpjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_01binnpjpi150_01.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~3OFFICE11REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:Program FilesLavasoftAd-Aware 2007aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:Program FilesKaspersky LabKaspersky Anti-Virus 7.0avp.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:Program FilesTOSHIBAConfigFreeCFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:WINDOWSsystem32DVDRAMSV.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:Program FilesiPodbiniPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:Program FilesSunbelt SoftwareCounterSpySBCSSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:WINDOWSsystem32ZoneLabsvsmon.exe

--
End of file - 7396 bytes
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #5  
Old 13-12-2007, 08:33 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Yesterday 08:02 PM
Posts: 4,609
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Please Help!!!

So which option did you run with smitfraudfix? # 2 only?

And is that a new hijackthis log, from after smitfraudfix.
__________________
.
.

Last edited by evilfantasy : 13-12-2007 at 08:35 AM.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #6  
Old 13-12-2007, 09:10 AM
No Avatar
drgg  England
CJ New Member
 
drgg is offline
 
Join Date: Dec 2007
Last Online: 16-12-2007 04:37 AM
Posts: 16
iTrader: (0)
drgg is on a distinguished road
Default Please Help!!!

Yeah i just did option 2 and thats the log after using SmitFraud
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #7  
Old 13-12-2007, 09:18 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Yesterday 08:02 PM
Posts: 4,609
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Please Help!!!

I need to know if you are following other advice or not.

Things will get too confusing for me if you are running other fixes then what I suggest. I look at the logs and see things changing. I need to know what all is done every step of the way.

It's your computer, don't get it crashed by running tools from multiple people trying to help at one time.
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #8  
Old 13-12-2007, 09:26 AM
No Avatar
drgg  England
CJ New Member
 
drgg is offline
 
Join Date: Dec 2007
Last Online: 16-12-2007 04:37 AM
Posts: 16
iTrader: (0)
drgg is on a distinguished road
Default Please Help!!!

Oh ok no problem. Well basically all i have done is run the SmitFraudFix program and pressed option 2 and then ran the Hijack This scan again. Do you know if any infecitons have been removed from the new log file because all the things that were happening after my laptop got infected has stopped.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #9  
Old 13-12-2007, 09:33 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Yesterday 08:02 PM
Posts: 4,609
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Please Help!!!

The smitfraudfix cleaned some of it, there are still be items to be fixed. We need to do some cleaning now. The HijackThis log is a nightmare right now.

Follow through with this set of instructions.

Please download ATF Cleaner by Atribune. ATF Cleaner.exe

Make sure that all browser windows are closed.
* Double-click ATF-Cleaner.exe to run the program.
* Under Main choose: Select All and UNCHECK Cookies.
* Click the Empty Selected button.

If you use Firefox browser
* Click Firefox at the top and choose: Select All and UNCHECK Cookies.
* Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
* Click Opera at the top and choose: Select All and UNCHECK Cookies.
* Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main ATF Cleaner menu to close the program.

----------

Please download Combofix by sUBs from either here or here

Save Combofix.exe to your your Desktop.

1. Double click combofix.exe & follow the prompts. (from the keyboard select 1 and press enter)
2. When finished, it will produce a log for you.
3. Attach that log in your next reply.

Note:
Do not mouseclick combofix's window while it's running. That may cause your computer to stall
----------

Then run another HijackThis scan and post the log also.

Use two posts if needed for the combofix log and a New HijackThis log
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #10  
Old 13-12-2007, 09:46 AM
No Avatar
drgg  England
CJ New Member
 
drgg is offline
 
Join Date: Dec 2007
Last Online: 16-12-2007 04:37 AM
Posts: 16
iTrader: (0)
drgg is on a distinguished road
Default Please Help!!!

Hey i cant continue this now. Goin offline from my computer, ill try getting online tomorow if not during the weekend, so ill get back to you then when i come back on the forum. BTW Thanks alot for the help, its greatly appreciated. Thanks!
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote

Please support this forum, donate towards our running costs.


Reply


Thread Tools

Forum Jump


Copyright ©2006 - 2008 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.

Page copy protected against web site content infringement by Copyscape