DONE! And I think it did the trick. The only part of your reply I didn't get was:
SELECT HijackThis FIX ITEMS: Scan with HijackThis and place a check next to these items:
----------No items specified
Make sure that all browser windows and internet links are closed, even this one!
CLICK ’FIX CHECKED’ with HijackThis.
Was I supposed to do something there? Anyway, I did everything else and that "thing" seems to be gone now. So here are the logs you wanted... and many thanks for all your help!
Best regards,
Beebz
HJT Log:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 7:12:18 PM, on 01/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Clayton's\spyware\HiJackThis_v2.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL =
http://www.google.ca/ig/dell?hl=en&c...row&channel=ca
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: IEHlprObj Class - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\PROGRA~1\IWINGA~1\IWINGA~1.DLL (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [tcrinit] C:\WINDOWS\svcwinra.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) -
http://www.nick.com/common/groove/gx/GrooveAX27.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
--
End of file - 3406 bytes
Rapport.txt:
SmitFraudFix v2.162
Scan done at 17:42:38.87, 01/04/2007
Run from C:\Documents and Settings\Clayton\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{CEB2DA1D-399D-4EC2-A1F1-6B6D6E573C7F}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS1\Services\Tcpip\..\{CEB2DA1D-399D-4EC2-A1F1-6B6D6E573C7F}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS3\Services\Tcpip\..\{CEB2DA1D-399D-4EC2-A1F1-6B6D6E573C7F}: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
AVG Report
NOTE: I saved the wrong report... I saved it before I clicked the "Apply all Actions" button, then everything read "cleaned" instead of "no action taken." Just so you know.
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 7:03:11 PM 01/04/2007
+ Scan result:
C:\Program Files\iWin Games\iWinGamesHookIE.dll -> Adware.BHO : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP244\A0021245.DLL -> Adware.FunWeb : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP247\A0021410.ini -> Adware.Qworke : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP203\A0019518.exe -> Adware.Relevant : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP247\A0021363.exe -> Adware.RK : No action taken.
C:\Documents and Settings\Jonah\Start Menu\Programs\WhenU -> Adware.SaveNow : No action taken.
C:\Documents and Settings\Jonah\Start Menu\Programs\WhenU\Customer Support.lnk -> Adware.SaveNow : No action taken.
C:\Documents and Settings\Jonah\Start Menu\Programs\WhenU\Learn More About WhenU Save.url -> Adware.SaveNow : No action taken.
C:\Documents and Settings\Jonah\Start Menu\Programs\WhenU\Learn More About WhenU SaveNow.url -> Adware.SaveNow : No action taken.
C:\Documents and Settings\Jonah\Start Menu\Programs\WhenU\Uninstall Instructions.lnk -> Adware.SaveNow : No action taken.
C:\Documents and Settings\Jonah\Start Menu\Programs\WhenU\WhenU.com Website.url -> Adware.SaveNow : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0019576.exe -> Adware.SaveNow : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0019577.dll -> Adware.SaveNow : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0019579.exe -> Adware.SaveNow : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0019585.exe -> Adware.SaveNow : No action taken.
C:\Downloads\JQSolitaireSetup-dm[1].exe -> Adware.Trymedia : No action taken.
C:\Downloads\JewelQuestSetup-dm[1].exe -> Adware.Trymedia : No action taken.
C:\Downloads\MysteryCaseFilesSetup-dm[1].exe -> Adware.Trymedia : No action taken.
C:\Documents and Settings\Jonah\Start Menu\Programs\WhenUSearch -> Adware.WhenU : No action taken.
C:\Documents and Settings\Jonah\Start Menu\Programs\WhenUSearch\WhenUSearch Desktop Toolbar.lnk -> Adware.WhenU : No action taken.
C:\Documents and Settings\Lori\Local Settings\Temp\temp.fr0E25\pmsnrr.exe -> Downloader.Zlob.atw : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP247\A0021419.exe -> Downloader.Zlob.atw : No action taken.
C:\Documents and Settings\Lori\Local Settings\Temp\temp.fr0E25\pmmnt.exe -> Downloader.Zlob.bpn : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP246\A0021297.exe -> Downloader.Zlob.bpn : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP246\A0021322.exe -> Downloader.Zlob.bpn : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP247\A0021418.exe -> Downloader.Zlob.bpn : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@www.adobe[1].txt -> TrackingCookie.Adobe : No action taken.
C:\Documents and Settings\Isaac\Cookies\isaac@www.adobe[1].txt -> TrackingCookie.Adobe : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@burstnet[1].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@text.burstnet[1].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@www.burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@www.burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@casalemedia[1].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@com[1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@com[1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Lori\Cookies\lori@com[1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@ehg-bestbuy.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@kmpads[2].txt -> TrackingCookie.Kmpads : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@search.live[1].txt -> TrackingCookie.Live : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@sales.liveperson[2].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@www.myaffiliatepr ogram[1].txt -> TrackingCookie.Myaffiliateprogram : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@navrcholu[2].txt -> TrackingCookie.Navrcholu : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : No action taken.
C:\Documents and Settings\Isaac\Cookies\isaac@data2.perf.overture[1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Isaac\Cookies\isaac@ads.planetactive[1].txt -> TrackingCookie.Planetactive : No action taken.
C:\Documents and Settings\Isaac\Cookies\isaac@www.real[1].txt -> TrackingCookie.Real : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@realguide.real[1].txt -> TrackingCookie.Real : No action taken.
C:\Documents and Settings\Isaac\Cookies\isaac@h.starware[1].txt -> TrackingCookie.Starware : No action taken.
C:\Documents and Settings\Isaac\Cookies\isaac@try.starware[1].txt -> TrackingCookie.Starware : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@try.starware[3].txt -> TrackingCookie.Starware : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@anad.tacoda[2].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@toplist[1].txt -> TrackingCookie.Toplist : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@toplist[1].txt -> TrackingCookie.Toplist : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@login.tracking101[2].txt -> TrackingCookie.Tracking101 : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@m.webtrends[2].txt -> TrackingCookie.Webtrends : No action taken.
C:\Documents and Settings\Isaac\Cookies\isaac@m.webtrends[1].txt -> TrackingCookie.Webtrends : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@m.webtrends[1].txt -> TrackingCookie.Webtrends : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@yadro[2].txt -> TrackingCookie.Yadro : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@yadro[2].txt -> TrackingCookie.Yadro : No action taken.
C:\Documents and Settings\Caitlin\Cookies\caitlin@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Isaac\Cookies\isaac@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Jonah\Cookies\jonah@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Jonah\Local Settings\Temp\laf11.tmp -> Trojan.Zlob : No action taken.
::Report end