This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

KotaGuy: Please advise...

2 min read

This thread's last reply is from June 13, 2006, 9:09 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

I am having some malware problems. I read your reply to a forum blog
on a
> similar problem. I downloaded the smitfraudfix program and ran it.
> Below, I am pasting in the contents of the text file that it brought
up.
>
> Could you please advise me as to my next move. Thanks so much,
>
>
> SmitFraudFix v2.58
>
> Scan done at 0:16:20.82, Mon 06/12/2006
> Run from C:\Documents and Settings\Lori\Desktop\SmitfraudFix
> OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
> Fix ran in normal mode
>
> »»»»»»»»»»»»»»»»»»»»»»»» C:\
>
>
> »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
>
> C:\WINDOWS\alexaie.dll FOUND !
> C:\WINDOWS\alxie328.dll FOUND !
> C:\WINDOWS\alxtb1.dll FOUND !
> C:\WINDOWS\bg.gif FOUND !
> C:\WINDOWS\BTGrab.dll FOUND !
> C:\WINDOWS\close-bar.gif FOUND !
> C:\WINDOWS\dlmax.dll FOUND !
> C:\WINDOWS\infected.gif FOUND !
> C:\WINDOWS\Pynix.dll FOUND !
> C:\WINDOWS\susp.exe FOUND !
> C:\WINDOWS\star.gif FOUND !
> C:\WINDOWS\warning-bar-ico.gif FOUND !
>
> »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
>
>
> »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
>
>
> »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
>
> C:\WINDOWS\system32\adobepnl.dll FOUND !
> C:\WINDOWS\system32\jao.dll FOUND !
> C:\WINDOWS\system32\questmod.dll FOUND !
> C:\WINDOWS\system32\runsrv32.dll FOUND !
> C:\WINDOWS\system32\runsrv32.exe FOUND !
> C:\WINDOWS\system32\tcpservice2.exe FOUND !
> C:\WINDOWS\system32\txfdb32.dll FOUND !
> C:\WINDOWS\system32\udpmod.dll FOUND !
> C:\WINDOWS\system32\users32.exe FOUND !
> C:\WINDOWS\system32\wstart.dll FOUND !
>
> »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Lori\Application
Data
>
>
> »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
>
>
> »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Lori\FAVORI~1
>
>
> »»»»»»»»»»»»»»»»»»»»»»»» Desktop
>
>
> »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
>
>
> »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
>
>
> »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
>
> [HKEY_CURRENT_USER\Software\Microsoft\Internet
> Explorer\Desktop\Components\0]
> "Source"="About:Home"
> "SubscribedURL"="About:Home"
> "FriendlyName"="My Current Home Page"
>
>
> »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
> !!!Attention, following keys are not inevitably infected!!!
>
> SrchSTS.exe by S!Ri
> Search SharedTaskScheduler's .dll
>
> »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
>
>
> »»»»»»»»»»»»»»»»»»»»»»»» End
Hi :wave:

I am currently looking over your log. As I am an Undergraduate, everything that I post to you must be checked by an expert. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long. I will post back shortly with a potential fix.

Thanks for your patience!
Thank you titan9

stealindaylight
could you stick to your original thread please, this topic is now locked

http://www.malwareremoval.com/forum/viewtop ... highlight=
He had emailed me, Nellie... I asked him not to that and instead for him to post to my attention here... but seeing as how Bob4 has his other topic he can continue there.

stealindaylight... please follow the instructions set out to you by Bob4.

Thanks.