SmitFraudFix v2.104
Scan done at 7:48:30.68, Mon 10/09/2006
Run from C:\Documents and Settings\McTaggart\Desktop\virus fighting tools\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\system32\ishost.exe Deleted
C:\WINDOWS\system32\isnotify.exe Deleted
C:\WINDOWS\system32\issearch.exe Deleted
C:\WINDOWS\system32\ixt?.dll Deleted
C:\WINDOWS\system32\ot.ico Deleted
C:\WINDOWS\system32\ts.ico Deleted
C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
C:\Program Files\Safety Bar\ Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
AVG log
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 3:18:37 AM 10/11/2006
+ Scan result:
C:\System Volume Information\_restore{CEEC0C29-9C07-442D-B8E2-F6A1DD655C17}\RP642\A0152603.dll -> Downloader.Zlob.ant : Cleaned.
C:\System Volume Information\_restore{CEEC0C29-9C07-442D-B8E2-F6A1DD655C17}\RP639\A0149457.exe -> Downloader.Zlob.aod : Cleaned.
C:\WINDOWS\system32\ishost.exe_tobedeleted -> Downloader.Zlob.aod : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\mctaggart@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\mctaggart@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\mctaggart@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\mctaggart@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\mctaggart@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\mctaggart@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\[email protected][2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\mctaggart@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\[email protected][2].txt -> TrackingCookie.Onestat : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\mctaggart@pro-market[1].txt -> TrackingCookie.Pro-market : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\mctaggart@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\mctaggart@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\McTaggart\Cookies\[email protected][1].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\System Volume Information\_restore{CEEC0C29-9C07-442D-B8E2-F6A1DD655C17}\RP645\A0153786.exe -> Worm.VB.ao : Cleaned.
C:\System Volume Information\_restore{CEEC0C29-9C07-442D-B8E2-F6A1DD655C17}\RP646\A0153800.exe -> Worm.VB.ao : Cleaned.
C:\System Volume Information\_restore{CEEC0C29-9C07-442D-B8E2-F6A1DD655C17}\RP646\A0153815.exe -> Worm.VB.ao : Cleaned.
C:\System Volume Information\_restore{CEEC0C29-9C07-442D-B8E2-F6A1DD655C17}\RP646\A0153828.exe -> Worm.VB.ao : Cleaned.
C:\System Volume Information\_restore{CEEC0C29-9C07-442D-B8E2-F6A1DD655C17}\RP646\A0153840.exe -> Worm.VB.ao : Cleaned.
C:\System Volume Information\_restore{CEEC0C29-9C07-442D-B8E2-F6A1DD655C17}\RP647\A0153846.exe -> Worm.VB.ao : Cleaned.
::Report end