Author Topic: i need help getting rid of this virus  (Read 584 times)

Offline Kmuk123

  • Hero Member
  • *****
  • Posts: 1050
  • Karma: +0/-0
    • View Profile
i need help getting rid of this virus
« on: December 11, 2006, 01:27:13 AM »
this virus wants me to buy some $60 thing put heres a pic
[color=\"#ff0000\"][/color]
[color=\"#ff0000\"][color=\"#ff0000\"][/color][/color]
[color=\"#0000ff\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"]Msn:[email protected][/color][/color]
[color=\"#008000\"][color=\"#008000\"]-----------------------------------------

[/color]
[/color]
[color=\"#008000\"]!!I have 33 Transactions!![/color]
[color=\"#0000ff\"][color=\"#006400\"]-----------------------------------------[/color][/color][/size][/size][/size]
[color=\"#0000ff\"][color=\"#006400\"]Total ammount of mils sold:67mil[/color][/color]
[color=\"#008000\"][color=\"#006400\"][/color]-----------------------------------------[/color][/size][/size]
[color=\"#008000\"]Total Ammount MMed: 20.6mil[/color]
[color=\"#008000\"]-----------------------------------------[/color]
[color=\"#008000\"]People Who Vouch Me[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]Legit Buyer[/color]
[color=\"#008000\"]Moe C [/color]
[color=\"#008000\"]Who cares[/color]
[color=\"#008000\"]Wee I Can Fly![/color]
[color=\"#008000\"]Blizcrew14[/color]
[color=\"#008000\"]Rofl Pls[/color]
[color=\"#008000\"]Zack The Man[/color]
[color=\"#008000\"]Madhatter

Kirk Hammett[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"]--------------------------------------------[/color]
[color=\"#008000\"]Trusted list[/color]
[color=\"#008000\"]Shamrock[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]blizcrew14[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]kirk hammett

[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"]---------------------------------------[/color][color=\"#ff0000\"][color=\"#ff0000\"][/color][/color][/u][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"][size="1"]Scammers list(never tust these people)[/color][/color][/color][/size][/size][/size][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]C[/color][color=\"#ff0000\"]allum aka fagexfun[/color][/color][/color][/color]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]emon3y[/color][color=\"#ff0000\"]





[/color]
[/size][/color][/size][/size][/size][/size][/size][/color][/size][/size][/size][/size][/size][/color][/size]
[color=\"#008000\"][/color]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][/color]

Offline Kmuk123

  • Hero Member
  • *****
  • Posts: 1050
  • Karma: +0/-0
    • View Profile
i need help getting rid of this virus
« Reply #1 on: December 11, 2006, 01:33:26 AM »
it tells me to donate malware or something liek that
[color=\"#ff0000\"][/color]
[color=\"#ff0000\"][color=\"#ff0000\"][/color][/color]
[color=\"#0000ff\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"]Msn:[email protected][/color][/color]
[color=\"#008000\"][color=\"#008000\"]-----------------------------------------

[/color]
[/color]
[color=\"#008000\"]!!I have 33 Transactions!![/color]
[color=\"#0000ff\"][color=\"#006400\"]-----------------------------------------[/color][/color][/size][/size][/size]
[color=\"#0000ff\"][color=\"#006400\"]Total ammount of mils sold:67mil[/color][/color]
[color=\"#008000\"][color=\"#006400\"][/color]-----------------------------------------[/color][/size][/size]
[color=\"#008000\"]Total Ammount MMed: 20.6mil[/color]
[color=\"#008000\"]-----------------------------------------[/color]
[color=\"#008000\"]People Who Vouch Me[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]Legit Buyer[/color]
[color=\"#008000\"]Moe C [/color]
[color=\"#008000\"]Who cares[/color]
[color=\"#008000\"]Wee I Can Fly![/color]
[color=\"#008000\"]Blizcrew14[/color]
[color=\"#008000\"]Rofl Pls[/color]
[color=\"#008000\"]Zack The Man[/color]
[color=\"#008000\"]Madhatter

Kirk Hammett[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"]--------------------------------------------[/color]
[color=\"#008000\"]Trusted list[/color]
[color=\"#008000\"]Shamrock[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]blizcrew14[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]kirk hammett

[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"]---------------------------------------[/color][color=\"#ff0000\"][color=\"#ff0000\"][/color][/color][/u][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"][size="1"]Scammers list(never tust these people)[/color][/color][/color][/size][/size][/size][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]C[/color][color=\"#ff0000\"]allum aka fagexfun[/color][/color][/color][/color]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]emon3y[/color][color=\"#ff0000\"]





[/color]
[/size][/color][/size][/size][/size][/size][/size][/color][/size][/size][/size][/size][/size][/color][/size]
[color=\"#008000\"][/color]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][/color]

Offline Kmuk123

  • Hero Member
  • *****
  • Posts: 1050
  • Karma: +0/-0
    • View Profile
i need help getting rid of this virus
« Reply #2 on: December 11, 2006, 01:52:15 AM »
bump
[color=\"#ff0000\"][/color]
[color=\"#ff0000\"][color=\"#ff0000\"][/color][/color]
[color=\"#0000ff\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"]Msn:[email protected][/color][/color]
[color=\"#008000\"][color=\"#008000\"]-----------------------------------------

[/color]
[/color]
[color=\"#008000\"]!!I have 33 Transactions!![/color]
[color=\"#0000ff\"][color=\"#006400\"]-----------------------------------------[/color][/color][/size][/size][/size]
[color=\"#0000ff\"][color=\"#006400\"]Total ammount of mils sold:67mil[/color][/color]
[color=\"#008000\"][color=\"#006400\"][/color]-----------------------------------------[/color][/size][/size]
[color=\"#008000\"]Total Ammount MMed: 20.6mil[/color]
[color=\"#008000\"]-----------------------------------------[/color]
[color=\"#008000\"]People Who Vouch Me[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]Legit Buyer[/color]
[color=\"#008000\"]Moe C [/color]
[color=\"#008000\"]Who cares[/color]
[color=\"#008000\"]Wee I Can Fly![/color]
[color=\"#008000\"]Blizcrew14[/color]
[color=\"#008000\"]Rofl Pls[/color]
[color=\"#008000\"]Zack The Man[/color]
[color=\"#008000\"]Madhatter

Kirk Hammett[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"]--------------------------------------------[/color]
[color=\"#008000\"]Trusted list[/color]
[color=\"#008000\"]Shamrock[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]blizcrew14[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]kirk hammett

[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"]---------------------------------------[/color][color=\"#ff0000\"][color=\"#ff0000\"][/color][/color][/u][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"][size="1"]Scammers list(never tust these people)[/color][/color][/color][/size][/size][/size][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]C[/color][color=\"#ff0000\"]allum aka fagexfun[/color][/color][/color][/color]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]emon3y[/color][color=\"#ff0000\"]





[/color]
[/size][/color][/size][/size][/size][/size][/size][/color][/size][/size][/size][/size][/size][/color][/size]
[color=\"#008000\"][/color]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][/color]

Offline Kmuk123

  • Hero Member
  • *****
  • Posts: 1050
  • Karma: +0/-0
    • View Profile
i need help getting rid of this virus
« Reply #3 on: December 11, 2006, 02:07:11 AM »
[3ump
[color=\"#ff0000\"][/color]
[color=\"#ff0000\"][color=\"#ff0000\"][/color][/color]
[color=\"#0000ff\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"]Msn:[email protected][/color][/color]
[color=\"#008000\"][color=\"#008000\"]-----------------------------------------

[/color]
[/color]
[color=\"#008000\"]!!I have 33 Transactions!![/color]
[color=\"#0000ff\"][color=\"#006400\"]-----------------------------------------[/color][/color][/size][/size][/size]
[color=\"#0000ff\"][color=\"#006400\"]Total ammount of mils sold:67mil[/color][/color]
[color=\"#008000\"][color=\"#006400\"][/color]-----------------------------------------[/color][/size][/size]
[color=\"#008000\"]Total Ammount MMed: 20.6mil[/color]
[color=\"#008000\"]-----------------------------------------[/color]
[color=\"#008000\"]People Who Vouch Me[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]Legit Buyer[/color]
[color=\"#008000\"]Moe C [/color]
[color=\"#008000\"]Who cares[/color]
[color=\"#008000\"]Wee I Can Fly![/color]
[color=\"#008000\"]Blizcrew14[/color]
[color=\"#008000\"]Rofl Pls[/color]
[color=\"#008000\"]Zack The Man[/color]
[color=\"#008000\"]Madhatter

Kirk Hammett[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"]--------------------------------------------[/color]
[color=\"#008000\"]Trusted list[/color]
[color=\"#008000\"]Shamrock[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]blizcrew14[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]kirk hammett

[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"]---------------------------------------[/color][color=\"#ff0000\"][color=\"#ff0000\"][/color][/color][/u][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"][size="1"]Scammers list(never tust these people)[/color][/color][/color][/size][/size][/size][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]C[/color][color=\"#ff0000\"]allum aka fagexfun[/color][/color][/color][/color]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]emon3y[/color][color=\"#ff0000\"]





[/color]
[/size][/color][/size][/size][/size][/size][/size][/color][/size][/size][/size][/size][/size][/color][/size]
[color=\"#008000\"][/color]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][/color]

Offline Kmuk123

  • Hero Member
  • *****
  • Posts: 1050
  • Karma: +0/-0
    • View Profile
i need help getting rid of this virus
« Reply #4 on: December 11, 2006, 08:36:08 AM »
bump
[color=\"#ff0000\"][/color]
[color=\"#ff0000\"][color=\"#ff0000\"][/color][/color]
[color=\"#0000ff\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"]Msn:[email protected][/color][/color]
[color=\"#008000\"][color=\"#008000\"]-----------------------------------------

[/color]
[/color]
[color=\"#008000\"]!!I have 33 Transactions!![/color]
[color=\"#0000ff\"][color=\"#006400\"]-----------------------------------------[/color][/color][/size][/size][/size]
[color=\"#0000ff\"][color=\"#006400\"]Total ammount of mils sold:67mil[/color][/color]
[color=\"#008000\"][color=\"#006400\"][/color]-----------------------------------------[/color][/size][/size]
[color=\"#008000\"]Total Ammount MMed: 20.6mil[/color]
[color=\"#008000\"]-----------------------------------------[/color]
[color=\"#008000\"]People Who Vouch Me[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]Legit Buyer[/color]
[color=\"#008000\"]Moe C [/color]
[color=\"#008000\"]Who cares[/color]
[color=\"#008000\"]Wee I Can Fly![/color]
[color=\"#008000\"]Blizcrew14[/color]
[color=\"#008000\"]Rofl Pls[/color]
[color=\"#008000\"]Zack The Man[/color]
[color=\"#008000\"]Madhatter

Kirk Hammett[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"]--------------------------------------------[/color]
[color=\"#008000\"]Trusted list[/color]
[color=\"#008000\"]Shamrock[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]blizcrew14[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]kirk hammett

[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"]---------------------------------------[/color][color=\"#ff0000\"][color=\"#ff0000\"][/color][/color][/u][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"][size="1"]Scammers list(never tust these people)[/color][/color][/color][/size][/size][/size][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]C[/color][color=\"#ff0000\"]allum aka fagexfun[/color][/color][/color][/color]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]emon3y[/color][color=\"#ff0000\"]





[/color]
[/size][/color][/size][/size][/size][/size][/size][/color][/size][/size][/size][/size][/size][/color][/size]
[color=\"#008000\"][/color]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][/color]

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
i need help getting rid of this virus
« Reply #5 on: December 11, 2006, 09:29:11 AM »
Your going to have to be patient
We'll get rid of this thing
I'm just on my way to work, in the meantime

I need to see a couple logs
Download Hijackthis 1.99.1 from my signature below
SAVE it to your desktop

Double click on hijackthis_sfx.exe on desktop
Click the UNZIP button>>OK the prompt
This will self extract to C:\Program Files\HijackThis
Delete hijackthis_sfx.exe from desktop

Go to START>>RUN
Copy>>paste the following to the open field, then hit OK
%systemdrive%\Program Files\HijackThis
This will open the Hijackthis folder
RIGHT CLICK on Hijackthis.exe and select SEND TO>>Desktop (create shortcut)
You can now run Hijackthis.exe from the new shortcut placed on your desktop

Double click to run Hijackthis.exe
Do a "SCAN and Save a Log file"
A log will open in Notepad
Copy and paste the WHOLE contents of the log  here

With that log, I also need  the following
Download the latest version of  [color=\"red\"]SmitfraudFix[/color][/url] (by S!Ri)
Extract the contents (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Kmuk123

  • Hero Member
  • *****
  • Posts: 1050
  • Karma: +0/-0
    • View Profile
i need help getting rid of this virus
« Reply #6 on: December 11, 2006, 04:39:19 PM »
Logfile of HijackThis v1.99.1
Scan saved at 3:38:11 PM, on 12/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdateMgr.exe
C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
C:\Program Files\DISC\DiscGui.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\AOL\1163449185\ee\AOLSoftware.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\DISC\DiscStreamHub.exe
c:\program files\common files\aol\1163449185\ee\aim6.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1a1ddc19-5893-43ab-a73f-f41a0f34d115} - C:\Program Files\Video ActiveX Object\isaddon.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Protection Bar - {5d4831e0-5a7c-4a46-afd5-a79ab8ce36c2} - C:\Program Files\Video ActiveX Object\iesplugin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe
O4 - HKLM\..\Run: [DMAScheduler] c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1163449185\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O21 - SSODL: flammei - {9d635a36-6b3c-4146-8625-f3aaf507bbf8} - C:\WINDOWS\system32\vcehaeb.dll (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
[color=\"#ff0000\"][/color]
[color=\"#ff0000\"][color=\"#ff0000\"][/color][/color]
[color=\"#0000ff\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"]Msn:[email protected][/color][/color]
[color=\"#008000\"][color=\"#008000\"]-----------------------------------------

[/color]
[/color]
[color=\"#008000\"]!!I have 33 Transactions!![/color]
[color=\"#0000ff\"][color=\"#006400\"]-----------------------------------------[/color][/color][/size][/size][/size]
[color=\"#0000ff\"][color=\"#006400\"]Total ammount of mils sold:67mil[/color][/color]
[color=\"#008000\"][color=\"#006400\"][/color]-----------------------------------------[/color][/size][/size]
[color=\"#008000\"]Total Ammount MMed: 20.6mil[/color]
[color=\"#008000\"]-----------------------------------------[/color]
[color=\"#008000\"]People Who Vouch Me[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]Legit Buyer[/color]
[color=\"#008000\"]Moe C [/color]
[color=\"#008000\"]Who cares[/color]
[color=\"#008000\"]Wee I Can Fly![/color]
[color=\"#008000\"]Blizcrew14[/color]
[color=\"#008000\"]Rofl Pls[/color]
[color=\"#008000\"]Zack The Man[/color]
[color=\"#008000\"]Madhatter

Kirk Hammett[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"]--------------------------------------------[/color]
[color=\"#008000\"]Trusted list[/color]
[color=\"#008000\"]Shamrock[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]blizcrew14[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]kirk hammett

[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"]---------------------------------------[/color][color=\"#ff0000\"][color=\"#ff0000\"][/color][/color][/u][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"][size="1"]Scammers list(never tust these people)[/color][/color][/color][/size][/size][/size][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]C[/color][color=\"#ff0000\"]allum aka fagexfun[/color][/color][/color][/color]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]emon3y[/color][color=\"#ff0000\"]





[/color]
[/size][/color][/size][/size][/size][/size][/size][/color][/size][/size][/size][/size][/size][/color][/size]
[color=\"#008000\"][/color]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][/color]

Offline Kmuk123

  • Hero Member
  • *****
  • Posts: 1050
  • Karma: +0/-0
    • View Profile
i need help getting rid of this virus
« Reply #7 on: December 11, 2006, 04:42:11 PM »
SmitFraudFix v2.128

Scan done at 15:41:24.90, Mon 12/11/2006
Run from C:\Documents and Settings\HP_Administrator\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Administrator


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Administrator\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HP_ADM~1\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

C:\Program Files\MalwareWipe\ FOUND !
C:\Program Files\Video ActiveX Object\ FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
 
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
 

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{9d635a36-6b3c-4146-8625-f3aaf507bbf8}"="flammei"

[HKEY_CLASSES_ROOT\CLSID\{9d635a36-6b3c-4146-8625-f3aaf507bbf8}\InProcServer32]
@="C:\WINDOWS\system32\vcehaeb.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{9d635a36-6b3c-4146-8625-f3aaf507bbf8}\InProcServer32]
@="C:\WINDOWS\system32\vcehaeb.dll"



»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~2\\GOEC62~1.DLL"
"LoadAppInit_DLLs"=dword:00000001


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
[color=\"#ff0000\"][/color]
[color=\"#ff0000\"][color=\"#ff0000\"][/color][/color]
[color=\"#0000ff\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"]Msn:[email protected][/color][/color]
[color=\"#008000\"][color=\"#008000\"]-----------------------------------------

[/color]
[/color]
[color=\"#008000\"]!!I have 33 Transactions!![/color]
[color=\"#0000ff\"][color=\"#006400\"]-----------------------------------------[/color][/color][/size][/size][/size]
[color=\"#0000ff\"][color=\"#006400\"]Total ammount of mils sold:67mil[/color][/color]
[color=\"#008000\"][color=\"#006400\"][/color]-----------------------------------------[/color][/size][/size]
[color=\"#008000\"]Total Ammount MMed: 20.6mil[/color]
[color=\"#008000\"]-----------------------------------------[/color]
[color=\"#008000\"]People Who Vouch Me[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]Legit Buyer[/color]
[color=\"#008000\"]Moe C [/color]
[color=\"#008000\"]Who cares[/color]
[color=\"#008000\"]Wee I Can Fly![/color]
[color=\"#008000\"]Blizcrew14[/color]
[color=\"#008000\"]Rofl Pls[/color]
[color=\"#008000\"]Zack The Man[/color]
[color=\"#008000\"]Madhatter

Kirk Hammett[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"]--------------------------------------------[/color]
[color=\"#008000\"]Trusted list[/color]
[color=\"#008000\"]Shamrock[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]blizcrew14[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]kirk hammett

[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"]---------------------------------------[/color][color=\"#ff0000\"][color=\"#ff0000\"][/color][/color][/u][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"][size="1"]Scammers list(never tust these people)[/color][/color][/color][/size][/size][/size][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]C[/color][color=\"#ff0000\"]allum aka fagexfun[/color][/color][/color][/color]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]emon3y[/color][color=\"#ff0000\"]





[/color]
[/size][/color][/size][/size][/size][/size][/size][/color][/size][/size][/size][/size][/size][/color][/size]
[color=\"#008000\"][/color]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][/color]

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
i need help getting rid of this virus
« Reply #8 on: December 11, 2006, 08:02:23 PM »
Print these instructions, Or copy>>paste them too a text file saved to your desktop for reference

==Download the latest version of  Java Runtime Environment (JRE) 5.0 Update 10
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation Multi-language
Save the file to your Desktop.
Don't install it yet

Open your Windows control panel>>Start>>control Panel
Ensure you are in Classic view
Double click to open the Java Icon>>Under the General tab select "Delete Files"
Leave all 3 selections checked and click OK
Exit Java

Access your Add/remove programs via Control Panel
Search in the list for all previous installed versions of Java. (J2SE or Java 2 Runtime Environment.... )
They should have the following icon next to it:  
There may be more than one entry
Remove them all related to Java

Also, Remove any entries related to Viewpoint Manager/media player
You may have more than one, they typically get installed unknowingly

Do a "System scan only" with Hijackthis and put a check next to these entries:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
O2 - BHO: (no name) - {1a1ddc19-5893-43ab-a73f-f41a0f34d115} - C:\Program Files\Video ActiveX Object\isaddon.dll
O3 - Toolbar: Protection Bar - {5d4831e0-5a7c-4a46-afd5-a79ab8ce36c2} - C:\Program Files\Video ActiveX Object\iesplugin.dll
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O15 - Trusted Zone: http://*.trymedia.com (HKLM)
O21 - SSODL: flammei - {9d635a36-6b3c-4146-8625-f3aaf507bbf8} - C:\WINDOWS\system32\vcehaeb.dll (file missing)


After you have ticked the above entries, close All other open windows
Including this one
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis

Reboot your computer into Safe Mode. To boot into Safe Mode, please restart your computer. Tap F8 before Windows loads. Select Safe Mode on the top of the screen that appears.
Sign in with your normal user account

* Clean your Cache and Cookies in IE:
  • Go to Control Panel > Internet Options > General tab
  • Click the "Delete..." button under Browsing History
  • Clean the following>>"Temporary Internet Files>>Cookies>>History"
* Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):
  • Go to Tools > Options.
  • Click Privacy in the menu on the left side of the Options window.
  • Click the Clear button located to the right of each option (History, Cookies, Cache).
  • Click OK to close the Options window

Alternatively, you can clear all information stored while browsing by clicking Clear All.
A confirmation dialog box will be shown before clearing the information.
[/list]==Open the SmitfraudFix folder you extracted to desktop earlier
  • Double-click smitfraudfix.cmd
  • Press any key to continue
  • Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

  • You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

  • The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".
The tool may need to restart your computer to finish the cleaning process.  A text file will appear onscreen, with results from the cleaning process
I'll need to see these later, by default they are also saved at C:\rapport.txt

Reboot back to Normal Windows
Go ahead and install the latest version of Java from the installer on desktop
You can delete the installer after Java has been installed

Come back here and post all the following please
1. Post a fresh Hijackthis log
2. Post the contents of the log from Smitfraudfix, located here>>C:\rapport.txt

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Kmuk123

  • Hero Member
  • *****
  • Posts: 1050
  • Karma: +0/-0
    • View Profile
i need help getting rid of this virus
« Reply #9 on: December 11, 2006, 08:30:48 PM »
java version 6 is out how should i do this from that? and i couldnt find allow all end users
[color=\"#ff0000\"][/color]
[color=\"#ff0000\"][color=\"#ff0000\"][/color][/color]
[color=\"#0000ff\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"]Msn:[email protected][/color][/color]
[color=\"#008000\"][color=\"#008000\"]-----------------------------------------

[/color]
[/color]
[color=\"#008000\"]!!I have 33 Transactions!![/color]
[color=\"#0000ff\"][color=\"#006400\"]-----------------------------------------[/color][/color][/size][/size][/size]
[color=\"#0000ff\"][color=\"#006400\"]Total ammount of mils sold:67mil[/color][/color]
[color=\"#008000\"][color=\"#006400\"][/color]-----------------------------------------[/color][/size][/size]
[color=\"#008000\"]Total Ammount MMed: 20.6mil[/color]
[color=\"#008000\"]-----------------------------------------[/color]
[color=\"#008000\"]People Who Vouch Me[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]Legit Buyer[/color]
[color=\"#008000\"]Moe C [/color]
[color=\"#008000\"]Who cares[/color]
[color=\"#008000\"]Wee I Can Fly![/color]
[color=\"#008000\"]Blizcrew14[/color]
[color=\"#008000\"]Rofl Pls[/color]
[color=\"#008000\"]Zack The Man[/color]
[color=\"#008000\"]Madhatter

Kirk Hammett[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"]--------------------------------------------[/color]
[color=\"#008000\"]Trusted list[/color]
[color=\"#008000\"]Shamrock[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]blizcrew14[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]kirk hammett

[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"]---------------------------------------[/color][color=\"#ff0000\"][color=\"#ff0000\"][/color][/color][/u][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"][size="1"]Scammers list(never tust these people)[/color][/color][/color][/size][/size][/size][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]C[/color][color=\"#ff0000\"]allum aka fagexfun[/color][/color][/color][/color]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]emon3y[/color][color=\"#ff0000\"]





[/color]
[/size][/color][/size][/size][/size][/size][/size][/color][/size][/size][/size][/size][/size][/color][/size]
[color=\"#008000\"][/color]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][/color]

Offline Kmuk123

  • Hero Member
  • *****
  • Posts: 1050
  • Karma: +0/-0
    • View Profile
i need help getting rid of this virus
« Reply #10 on: December 11, 2006, 08:36:06 PM »
wait nvm i got it ty for ur help
[color=\"#ff0000\"][/color]
[color=\"#ff0000\"][color=\"#ff0000\"][/color][/color]
[color=\"#0000ff\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"][/color][/color]
[color=\"#008000\"][color=\"#008000\"]Msn:[email protected][/color][/color]
[color=\"#008000\"][color=\"#008000\"]-----------------------------------------

[/color]
[/color]
[color=\"#008000\"]!!I have 33 Transactions!![/color]
[color=\"#0000ff\"][color=\"#006400\"]-----------------------------------------[/color][/color][/size][/size][/size]
[color=\"#0000ff\"][color=\"#006400\"]Total ammount of mils sold:67mil[/color][/color]
[color=\"#008000\"][color=\"#006400\"][/color]-----------------------------------------[/color][/size][/size]
[color=\"#008000\"]Total Ammount MMed: 20.6mil[/color]
[color=\"#008000\"]-----------------------------------------[/color]
[color=\"#008000\"]People Who Vouch Me[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]Legit Buyer[/color]
[color=\"#008000\"]Moe C [/color]
[color=\"#008000\"]Who cares[/color]
[color=\"#008000\"]Wee I Can Fly![/color]
[color=\"#008000\"]Blizcrew14[/color]
[color=\"#008000\"]Rofl Pls[/color]
[color=\"#008000\"]Zack The Man[/color]
[color=\"#008000\"]Madhatter

Kirk Hammett[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"]--------------------------------------------[/color]
[color=\"#008000\"]Trusted list[/color]
[color=\"#008000\"]Shamrock[/color]
[color=\"#008000\"]Reazee[/color]
[color=\"#008000\"]blizcrew14[/color]
[color=\"#008000\"]Alex5940[/color]
[color=\"#008000\"]kirk hammett

[/color]
[color=\"#008000\"]

[/color]
[color=\"#008000\"][color=\"#008000\"]---------------------------------------[/color][color=\"#ff0000\"][color=\"#ff0000\"][/color][/color][/u][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"][size="1"]Scammers list(never tust these people)[/color][/color][/color][/size][/size][/size][/color][/size][/size]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]C[/color][color=\"#ff0000\"]allum aka fagexfun[/color][/color][/color][/color]
[color=\"#008000\"][color=\"#ff0000\"][color=\"#ff0000\"][color=\"#ff0000\"]emon3y[/color][color=\"#ff0000\"]





[/color]
[/size][/color][/size][/size][/size][/size][/size][/color][/size][/size][/size][/size][/size][/color][/size]
[color=\"#008000\"][/color]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][color=\"#ff0000\"][/color][/size][/size][/color][/size]
[color=\"#008000\"][/color]

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
i need help getting rid of this virus
« Reply #11 on: December 11, 2006, 08:47:45 PM »
Just realized I gave you instructions to

Clean Cache and cookies for IE7, not IE6

If you haven't started the fixes yet, include these instructions for IE6

If you are already underway, don't worry about it, you may not see this till your back in Normal windows
just do it after with these instructions in Normal windows
and your Browser windows closed
* Clean your Cache and Cookies in IE:
  • Go to Control Panel > Internet Options > General tab
  • Click the "Delete Cookies" button
  • Next to it, Click the "Delete Files" button
  • When prompted, place a check in: "Delete all offline content", click OK
Also, AFTER you reboot back to Normal windows
Can you do the following, just as a checkup
Go to start > control panel > Display properties > Desktop > Customize Desktop... > Web tab
Uncheck and delete everything you find in there. (except for "My current home page")
« Last Edit: December 11, 2006, 08:48:24 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here