SmitFraudFix v2.329 Scan done at 18:13:22.21, Tue 07/15/2008 Run from C:\Documents and Settings\Ray\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode ������������������������ Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\brss01a.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\system32\Brmfrmps.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\Mcshield.exe C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe C:\WINDOWS\MXOALDR.EXE C:\WINDOWS\system32\atiptaxx.exe C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\Program Files\Brother\ControlCenter2\brctrcen.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Windows Defender\MSASCui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Belkin\F1U201.401\usbshare.exe C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\cmd.exe ������������������������ hosts ������������������������ C:\ ������������������������ C:\WINDOWS ������������������������ C:\WINDOWS\system ������������������������ C:\WINDOWS\Web ������������������������ C:\WINDOWS\system32 C:\WINDOWS\system32\ot.ico FOUND ! C:\WINDOWS\system32\stdole3.tlb FOUND ! C:\WINDOWS\system32\ts.ico FOUND ! C:\WINDOWS\system32\1024\ FOUND ! ������������������������ C:\WINDOWS\system32\LogFiles ������������������������ C:\Documents and Settings\Ray ������������������������ C:\Documents and Settings\Ray\Application Data ������������������������ Start Menu C:\DOCUME~1\Ray\STARTM~1\Programs\SearchVideo FOUND ! ������������������������ C:\DOCUME~1\Ray\FAVORI~1 C:\DOCUME~1\Ray\FAVORI~1\Antivirus Scan.url FOUND ! ������������������������ Desktop ������������������������ C:\Program Files C:\Program Files\ASC 2.1\ FOUND ! ������������������������ Corrupted keys ������������������������ Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" ������������������������ IEDFix !!!Attention, following keys are not inevitably infected!!! IEDFix Credits: Malware Analysis & Diagnostic Code: S!Ri [!] Suspicious: ASCWarning32.dll BHO: ASCWarningBHO Class - {58472BC6-BEA3-42d4-8917-7A8BCB0711B5} TypeLib: {DEC7D971-C561-4350-8B18-73FBC3339459} VersionIndependentProgID: ASCWarning32.WarningBHO ProgID: ASCWarning32.WarningBHO.1 ������������������������ VACFix !!!Attention, following keys are not inevitably infected!!! VACFix Credits: Malware Analysis & Diagnostic Code: S!Ri ������������������������ 404Fix !!!Attention, following keys are not inevitably infected!!! 404Fix Credits: Malware Analysis & Diagnostic Code: S!Ri ������������������������ Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "altmannsberger"="{210b4043-35ca-4aa0-8796-191f9663dfb3}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{629340b5-8df6-4211-9245-a86563a35792}"="enation" ������������������������ AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" ������������������������ Winlogon !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Userinit"="C:\\WINDOWS\\system32\\userinit.exe," "System"="" ������������������������ Rustock ������������������������ DNS Description: Winbond W89C940-Based Ethernet Adapter (Generic) - Packet Scheduler Miniport DNS Server Search Order: 24.159.193.40 DNS Server Search Order: 68.115.71.53 HKLM\SYSTEM\CCS\Services\Tcpip\..\{26ADBD67-C238-428A-8AF1-37434A1679D4}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{26ADBD67-C238-428A-8AF1-37434A1679D4}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\..\{26ADBD67-C238-428A-8AF1-37434A1679D4}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] ������������������������ Scanning for wininet.dll infection ������������������������ End