Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
Blue screen / Trojan-spy.HTML.smitfraud.c [RESOLVED], Why me? I'm no freek
johanvd
post Aug 8 2005, 01:23 PM
Post #1


Member
**
Posts: 11
From: Belgium
OS: Windows XP



I search for help on the Trojan-spy.HTML.smitfraud.c and this is my hijackthis.log

Logfile of HijackThis v1.99.1
Scan saved at 21:18:36, on 8/08/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\WINXP\explorer.exe
C:\WINXP\System32\SMSSU.EXE
C:\WINXP\System32\Tmntsrv32.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINXP\System32\SMSSU.EXE
C:\WINXP\System32\Tmntsrv32.EXE
C:\Program Files\Outlook Express\Msimn.exe
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Bluetooth\BTNtService.exe
C:\WINXP\System32\nvsvc32.exe
C:\WINXP\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Johan\Bureaublad\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - Default URLSearchHook is missing
O2 - BHO: XMLDP Class - {60371670-81B9-4d06-9C42-4DEC1AABE62B} - C:\WINXP\xmllib.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINXP\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINXP\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINXP\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NAVNet] "C:\DOCUME~1\Johan\LOCALS~1\Temp\9C.tmp" /m
O4 - HKLM\..\Run: [smalfd] C:\WINXP\System32\tedxlz.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINXP\System32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [SMSSU] C:\WINXP\System32\SMSSU.EXE
O4 - HKCU\..\Run: [Tmntsrv32] C:\WINXP\System32\Tmntsrv32.EXE
O4 - HKCU\..\Run: [Win32res] C:\WINXP\win32res.exe
O4 - Startup: Outlook Express.lnk = C:\Program Files\Outlook Express\MSIMN.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\Bluetooth\BTNtService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINXP\System32\nvsvc32.exe

Hopefully, someone can help ? Any support is greatly appreciated. Thank you in advance !

Greetings from Belgium,
Johan Van Driessche
Go to the top of the page
 
+Quote Post

Posts in this topic
- johanvd   Blue screen / Trojan-spy.HTML.smitfraud.c [RESOLVED]   Aug 8 2005, 01:23 PM
- - Excal   Hi johanvd and welcome to GeeksToGo! My name i...   Aug 13 2005, 04:46 PM
- - johanvd   Hi Excal, thank you for helping ! Followed ev...   Aug 14 2005, 04:11 AM
- - Excal   Try running this: Run this online virus scan: Act...   Aug 14 2005, 01:30 PM
- - johanvd   Hi Excal, I followed your recommendations and ple...   Aug 15 2005, 03:49 AM
- - Excal   download next tool to your desktop: http://users....   Aug 15 2005, 07:30 AM
- - johanvd   Hi Excal, I downloaded this program before and ba...   Aug 15 2005, 12:01 PM
- - Excal   You still getting those entries. If so can you te...   Aug 15 2005, 12:28 PM
- - johanvd   Hi Excal, Okay, I runned Spy Sweeper and this is ...   Aug 15 2005, 03:14 PM
- - Excal   Silent Runners: Please click this link to download...   Aug 15 2005, 05:47 PM
- - johanvd   Okay, done that. Here is the result - "Silen...   Aug 16 2005, 01:17 AM
- - Excal   Launch Notepad, and copy/paste the box below into ...   Aug 16 2005, 10:01 AM
- - johanvd   Followed every step, I get a prompt "Are you ...   Aug 16 2005, 10:56 AM
- - Excal   Please try this: Launch Notepad, and copy/paste t...   Aug 16 2005, 11:21 AM
- - johanvd   Hi Excal, Problem solved When I rebooted in s...   Aug 17 2005, 02:53 PM
- - Excal   Great job, it appears your computer is clean E...   Aug 17 2005, 08:10 PM
- - johanvd   Hi Excal, I'm very happy with the service you...   Aug 18 2005, 01:56 PM
- - Excal   Thank you good luck and safe surfing Excal   Aug 18 2005, 02:01 PM
- - Michelle   Since this issue appears to be resolved ... this T...   Aug 22 2005, 10:04 PM


Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies / Views Topic Information
No New Posts   8 / 1,155 12th November 2005 - 10:01 AM
dnulnoj started - last by Michelle
No new   46 / 6,220 19th September 2005 - 02:01 PM
cryptopsy started - last by rambro
No New Posts   10 / 3,447 13th August 2005 - 08:13 AM
hunterwang started - last by greyknight17
No new   16 / 1,869 10th September 2005 - 05:57 AM
RecoDesign started - last by LostAccount

RSS Time is now: 21st November 2009 - 01:09 PM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising