Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Help needed for Trojan-spy.html.smitfraud.c


  • Please log in to reply

#16
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
That would lead me to believe your webserver is giving you the problems.

I don't have much knowledge about that.
Can you try shutting it down for a while to test the effect?

Regards,
  • 0

Advertisements


#17
Diana Moura

Diana Moura

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
It can be... It feels indeed when I shut down the browser windows it works faster. hey Pieter, I really donīt want to bother you anymore, when you have helped me so much already anyway... I really aprecciate what you have done!.. (And I have to stop drinking this cider as I have written this talk almost an hour ago & didnīt notice that I hadnīt posted this to you... DUH!!!)
  • 0

#18
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
It's really no bother. I just don't know very much about server-software.

Regards,
  • 0

#19
Diana Moura

Diana Moura

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
Cool... Well anyway I can have my dear & beautiful Squidward Tentacles wallpaper back to track! Thanks to Pieter.
Well... What do you think we could do as for the mistakes messages then? Also I forgot to tell you that also from īwindows come this message saying that some Active-X component is missing... What should we do?
  • 0

#20
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
I will have to have exact error messages (full text) and I might be able to help you with the ActiveX error

What I believe to be wscript errors are in the webserver software since most of your scripts are in the c:\Inetpub\AdminScripts folder

I have Googled for a solution to replace them but I came up empty-handed
I could even have drawn the wrong conclusion.
Like I said, I hardly know anything about that stuff. So much to learn, so little time.
  • 0

#21
Diana Moura

Diana Moura

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
Right.... Hey letīs do this then, Iīll get back to you tomorrow morning as I donīt think I would be acting clever if I continue to post here tonight. And the most important, as this internet server supplies almost the whole building here where I live, I suspect that in the morning the traffic will be faster, letīs see anyway. Iīll make another try in the morning and will also take notes from the error messages as you asked... Is that OK? :tazz:
  • 0

#22
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
OK with me. :tazz:

~I hear my cushion calling as well~

Regards,
  • 0

#23
Diana Moura

Diana Moura

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
Morning! You know what, today nothing really showed up, apart from the Active-X talk. The message that shows up is more or less the following "Your current security settings are blocking the performance of the Active-X components. For this resason the page may not work properly. " This happened for instance when I tried to play some radio station straight from their site... What do you think? As for the speed of the computer, it has sure improved since you started to help, but it still feels that itīs not that fast as it used to be....
  • 0

#24
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
The method described here:
http://support.micro...kb;en-us;836942
works for any site.

Just add the URL for that radiostation to the entries:
http://*.windowsupdate.microsoft.com
http://*.windowsupdate.com

Only do this for sites you really trust.

Regards,
  • 0

#25
Diana Moura

Diana Moura

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
Cheers!! It worked. :tazz:
  • 0

Advertisements


#26
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
:tazz:

Download this file:
http://www.bleepingc...g/smitfraud.reg
and doubleclick it. Confirm you want to merge it with the registry.

It's an improved version of what we had to remove the keys Smitfraud adds.
Maybe it will gain a bit more speed.

Regards,
  • 0

#27
Diana Moura

Diana Moura

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
I did it. So all what I had to do was to confirm the registry? Apart from that I didnīt really see any window showing up. Is it how itīs suppose to work? Anyway, thanks a lot for your help Pieter... I am already happy about the results...
  • 0

#28
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Yep. That's all it's supposed to do.

I'll keep this thread open for a while longer in case anything turns up.

So all you need to do is reply to this thread and I'll get notified.

Regards,
  • 0

#29
Diana Moura

Diana Moura

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
Morning Pieter! So here I am again... Sorry for annoying you again but now the net wonīt work. Remember when I said to you that I was having some funny problems with starting the net last week, well now it just wonīt work, I mean the pages wonīt load for some reason I donīt know. all I do know is that yesterday after I run Spybot and coulnd erase that BACKWEB LITE stuff I got a notification when restarting my computer (in my firewall software, zonealarm, saying that a new connection was available for the computer, and without me doing anything this "new connection" is now working as defaut. It may be that is the same one, but I am not sure. Well hereīs the IP from this new network : 169. 254ī.0.0/255.255.0.0 and the other one is 62.237.72.128/255.255.0.0
and hereīs my fresh log

Logfile of HijackThis v1.99.1
Scan saved at 20:28:43, on 15/05/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINNT\System32\CTSvcCDA.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\snmp.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\Creative\Audio2K\PROGRAM\CTMIX32.EXE
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Creative\ShareDLL\MediaDet.Exe
C:\WINNT\system32\internat.exe
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
C:\WINNT\System32\mdm.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.wlannet.com:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\fi\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [CreativeMixer] C:\Program Files\Creative\Audio2K\PROGRAM\CTMIX32.EXE /t
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fi\msnappau.exe"
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O15 - Trusted Zone: http://www.virginradio.co.uk
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by19fd.bay19....es/MsnPUpld.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zone...ctor/WebAAS.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTSvcCDA.exe
O23 - Service: Loogisen levyn hallinnan valvontapalvelu (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InCD File System Service (InCDsrv) - Unknown owner - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe


Thanks a lot in advance... What would that be?? :tazz:

Edited by Diana Moura, 16 May 2005 - 03:30 AM.

  • 0

#30
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Looks like somehow a WLAN was implemented on your computer.

inetnum: 62.237.72.0 - 62.237.79.255
netname: WLANNET
descr: WLANnet Finland Oy
descr: Rautatienkatu 15 C, 33100 Tampere

If that is not supposed to be there, fix this line in HijackThis

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.wlannet.com:3128

Regards,
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP