I am having a bad spyware / virus infection. It looks like smitfraud but I am not 100% sure. I have ran Bit defender online scanner and spybot search and destroy. Any extra assistance would be much appreciated. I have attached my Hi-Jack this log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:24:05 PM, on 3/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\mgmrwm
rv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,ShellNext =
http://antispywareupdates.net/?aid=496.cacbcbR0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system
32\userini
t.exe,C:\W
INDOWS\sys
tem32\mgmr
wmrv.exe,
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7
566d231435
2} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7
695ECA0567
0} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn1
\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lper.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c
281324d548
9} - (no file)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b
467a2233e7
d} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-c
d5f52858c3
1} - (no file)
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-c
e7eb590a94
d} - (no file)
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2
c7e78fbab3
8} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8
ca72550717
b} - (no file)
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-9
28ae5ab496
6} - (no file)
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-8
74a5e5e403
a} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-0
0600f9a01f
1} - (no file)
O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7
960230792f
1} - (no file)
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-8
28942301d3
e} - (no file)
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-7
31BB6995FD
D} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-7
1776572827
4} - (no file)
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-7
33078684f3
c} - (no file)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-0
8002b2f49f
b} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn1
\yt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-2
0066696354
B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ProfileWatcher] C:\Program Files\ProfileWatcher\profi
lewatcher.
exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtectio
n.exe"
O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\EKI
J5000MUI.e
xe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\Update
Service\IS
USPM.exe" -scheduler
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM
.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB920] command /c del "C:\Documents and Settings\All Users\Application Data\ZangoSA\ZangoSAAbout.
mht"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7475] cmd /c del "C:\Documents and Settings\All Users\Application Data\ZangoSA\ZangoSAAbout.
mht"
O4 - HKCU\..\RunOnce: [SpybotDeletingB688] command /c del "C:\Documents and Settings\All Users\Application Data\ZangoSA\ZangoSAEULA.m
ht"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3235] cmd /c del "C:\Documents and Settings\All Users\Application Data\ZangoSA\ZangoSAEULA.m
ht"
O4 - HKUS\S-1-5-21-1417001333-4
84763869-6
82003330-5
00\..\Run:
[MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM
.exe (User '?')
O4 - HKUS\S-1-5-21-1417001333-4
84763869-6
82003330-5
00\..\RunO
nce: [SpybotDeletingB920] command /c del "C:\Documents and Settings\All Users\Application Data\ZangoSA\ZangoSAAbout.
mht" (User '?')
O4 - HKUS\S-1-5-21-1417001333-4
84763869-6
82003330-5
00\..\RunO
nce: [SpybotDeletingB688] command /c del "C:\Documents and Settings\All Users\Application Data\ZangoSA\ZangoSAEULA.m
ht" (User '?')
O4 - HKUS\S-1-5-21-1417001333-4
84763869-6
82003330-5
00\..\RunO
nce: [SpybotDeletingD3235] cmd /c del "C:\Documents and Settings\All Users\Application Data\ZangoSA\ZangoSAEULA.m
ht" (User '?')
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM
.exe (User '?')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM
.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
obe Gamma Loader.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0
800200c9a6
6} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0
800200c9a6
6} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D
4730F4EE49
9} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cabO16 - DPF: {9600F64D-755F-11D4-A47F-0
001023E6D5
A} (Shutterfly Picture Upload Plugin) -
http://web1.shutterfly.com/downloads/Uploader.cabO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2ev
xx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\
ALUSchedul
erSvc.exe
O23 - Service: ##Id_String1.6844F930_1628
_4223_B5CC
_5BB94B879
762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponde
r.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
ice.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\
drivers\w3
2x86\3\HPB
PRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\
drivers\w3
2x86\3\HPB
OID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEU
P~1\LUCOMS
~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk
.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
12.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.ex
e
--
End of file - 8948 bytes
Start Free Trial