ComboFix 07-09-21.2 - "Meka" 2007-10-01 8:05:56.1 - NTFSx86Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.112 [GMT -4:00]* Created a new restore point.((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).C:\DOCUME~1\Guest\APPLIC~1\winantiviruspro2007freeinstall[1].exeC:\Program Files\AntiVirGear 3.7C:\Program Files\AntiVirGear 3.7\vpp.iniD:\Autorun.inf.((((((((((((((((((((((((( Files Created

Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd Select option #2 - Clean by typing 2 and press "Enter" to delete infected files. Logfile of HijackThis v1.99.1Scan saved at 5:55:59 PM, on 1/3/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\brsvc01a.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\System32\brss01a.exeC:\WINDOWS\Explorer.EXEC:\Program Files\QuickTime\qttask.exeC:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exeC:\WINDOWS\Mixer.exeC:\WINDOWS\sm56hlpr.exeC:\WINDOWS\system32\LVCOMSX.EXEC:\Program Files\Logitech\Video\LogiTray.exeC:\PROGRA~1\mcafee.com\agent\mcagent.exeC:\Program Files\Zone Labs\ZoneAlarm\zlclient.exeC:\Program Files\McAfee.com\VSO\mcvsshld.exeC:\Program Files\McAfee.com\VSO\oasclnt.exec:\progra~1\mcafee.com\vso\mcvsescn.exeC:\Program

This program will identify the system security weaknesses in your browser and operating system and provides easy instructions to correct them. The tool may need to restart your computer to finish the cleaning process.

The tool will now check if wininet.dll is infected. Under the Hidden files and folders heading select Show hidden files and folders.

You are infected!! With Adaware and Spybot I got rid of 579 spyware entries, and with Panda and AVG got rid of 229 seperate viruses, mostly backdoor trojans.

Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn3\yt.dllO3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-8CB0-AB60BB9AAE22} - C:\PROGRA~1\VOL_TO~1\VOL_TO~1.DLLO3 - Toolbar: IE Custom Tools - {41F6170D-6AF8-4188-8D92-9DDAB3C71A78} - C:\Program Files\Online Video Add-on\ictmdl.dllO3 - Toolbar: (no name) - Pager]"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]"SymWSC"=2 (0x2)"Pml Driver HPZ12"=3 (0x3)"ose"=3 (0x3)"MDM"=2 (0x2)"DefWatch"=2 (0x2)R3 Radialpoint Security Services;Verizon Internet Security Suite;C:\WINDOWS\system32\dllhost.exe /Processid:{80098F68-1220-4F43-80A8-15C7395B8874}R3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sysS3 gUSBSTOi;gUSBSTOi;\??\C:\DOCUME~1\Meka\LOCALS~1\Temp\gUSBSTOi.sys[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]AutoRun\command- F:\LCMonitor.exe*Newly Created Service* - CATCHME.**************************************************************************catchme 0.3.1061 W2K/XP/Vista -

ForumsJoin Search similar:Cant find the root problemSpigot and others[Malware] Multiple toolbars needed to be removed. Please post the contents of the SmitfraudFix log located at C:\rapport.txt into this thread, along with the Ewido report and a new HijackThis log.

Select the View Tab. Any suggestions at this point would be very welcome. Pls Help!!!!

Nov 12, 2007 HJT Log Help Possible virus Feb 11, 2006 I've tried every virus/malware removal program (HiJack This Log inside) Help pls May 7, 2013 Add New Comment You need I doubt that it'll turn up anything new, but if you would be so kind, hop on over to http://radiosplace.com and get the latest version of HijackThis and post a scan Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended. Make sure you spoil her really good.

SmitFraudFix v2.234Scan done at 9:01:48.98, Mon 10/01/2007Run from C:\Documents and Settings\Meka\Local Settings\Temporary Internet Files\Content.IE5\K4KR08C7\SmitfraudFix[1]\SmitfraudFixOS: Microsoft Windows XP [Version 5.1.2600] - Windows_NTThe filesystem type is NTFSFix run in normal mode»»»»»»»»»»»»»»»»»»»»»»»» ProcessC:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Verizon\Verizon

Might be a good idea to point them to this forum for some security advice (some of that is in my FAQ on prevention and how to avoid spyware/adware).Maybe put the

Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dllO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1100866281\ee\AOLHostManager.exeO4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe Open My Computer.

Logfile of Trend Micro HijackThis v2.0.0 (BETA)Scan saved at 6:01:06 PM, on 9/30/2007Platform: Windows XP SP2 (WinNT 5.01.2600)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Verizon\Verizon Internet Security Suite\Fws.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec

Would it be beneficial to install ethernet before house sale? [HomeImprovement] by oldsam1718. What is HijackThis? Nov 11, 2007 #2 (You must log in or sign up to reply here.) Show Ignored Content Topic Status: Not open for further replies. Due to a few misunderstandings, I just want to make it clear that this site provides only an online analysis, and not HijackThis the program.

Logfile of HijackThis v1.99.0 Scan saved at 10:35:57 PM, on 4/29/2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO2 - BHO: (no name) - {D579A683-0CC7-4023-BAE7-0544D0D1DA3A} - C:\Program Files\Online Video Add-on\isfmdl.dllO3 - Toolbar: HP After the 30 day trial, the advanced features will no longer be available without purchase, however, the program will continue to recieve updates and you can manually scan with the updated

Once I had the real nasties off, I restored it back two weeks and nothing came back from the restore.

