Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses  (Read 4792 times)

0 Members and 1 Guest are viewing this topic.

ash72

    Topic Starter


    Rookie

    Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses
    « on: May 11, 2007, 03:48:03 PM »
    Please can someone have a look at my hijack this log file?  I have cehcked this and other forums, performed some tasks advised, including smitfraudfix.exe, Bruteforce uninstaller and AVG 7.5 antispyware.  Spybot originally found the smitfraud and AVG 7.5 antispyware foubd trojan horses.  I think/hope I have sorted this now but was hoping for some expert advise.

    Thanks.

    Ash72.

    Hijackthis log to follow...
    That's just the way it is

    ash72

      Topic Starter


      Rookie

      Re: Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses
      « Reply #1 on: May 11, 2007, 03:48:32 PM »
      Logfile of Trend Micro HijackThis v2.0.0 (BETA)
      Scan saved at 22:41:14, on 11/05/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
      C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
      C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
      C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
      C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFAGENT.EXE
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\MSI\3D!Turbo Experience\3D!Turbo.exe
      C:\WINDOWS\system32\wuauclt.exe
      D:\Ash\Zip files\HiJackThis_v2.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
      O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
      O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
      O4 - Global Startup: 3D!Turbo Experience.lnk = C:\Program Files\MSI\3D!Turbo Experience\3D!Turbo.exe
      O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
      O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131197105750
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1131208616000
      O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
      O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://help.broadbandassist.com/prequal/MotivePreQual.cab
      O20 - Winlogon Notify: winrvc32 - winrvc32.dll (file missing)
      O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
      O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
      O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
      O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

      --
      End of file - 5404 bytes
      That's just the way it is

      ash72

        Topic Starter


        Rookie

        Re: Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses
        « Reply #2 on: May 11, 2007, 03:49:11 PM »
        Any help would be greatly appreciated.

        Thanks.
        That's just the way it is

        CBMatt

        • Mod & Malware Specialist


        • Prodigy

        • Sad and lonely...and loving every minute of it.
        • Thanked: 167
          • Yes
        • Experience: Experienced
        • OS: Windows 7
        Re: Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses
        « Reply #3 on: May 11, 2007, 07:38:37 PM »
        Ash, I've got you at the top of my list right now.  I have to go take care of a few things, but I'll get back to you within the hour.
        Quote
        An undefined problem has an infinite number of solutions.
        由obert A. Humphrey

        patio

        • Moderator


        • Genius
        • Maud' Dib
        • Thanked: 1769
          • Yes
        • Experience: Beginner
        • OS: Windows 7
        Re: Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses
        « Reply #4 on: May 11, 2007, 08:23:04 PM »
        A Good Start

        I would suggest printing out the instructions and becoming familiar with them beforehand...

        Then run a fresh HJT log and post it and by that time Chris should be back...
        " Anyone who goes to a psychiatrist should have his head examined. "

        CBMatt

        • Mod & Malware Specialist


        • Prodigy

        • Sad and lonely...and loving every minute of it.
        • Thanked: 167
          • Yes
        • Experience: Experienced
        • OS: Windows 7
        Re: Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses
        « Reply #5 on: May 11, 2007, 09:11:30 PM »
        Sorry, I was busy a bit longer than expected.

        Patio's advice is sound.  Thankfully, though, your log looks relatively clean.  The only issue I see is this entry...

        O20 - Winlogon Notify: winrvc32 - winrvc32.dll (file missing)

        Just a leftover Smitfraud registry entry.  Close all windows and have HijackThis fix this entry.  The file should already be gone, but to be on the safe side, reboot into Safe Mode, enable hidden files/folders, and delete the following file if found...

        C:\WINDOWS\system32\winrvc32.dll

        Also, still being on the safe side, follow through with the SmitFraudFix instructions and run another scan with AVG.  Then go ahead and post a fresh HJT log along with an update on how things are going.
        Quote
        An undefined problem has an infinite number of solutions.
        由obert A. Humphrey

        ash72

          Topic Starter


          Rookie

          Re: Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses
          « Reply #6 on: May 12, 2007, 02:30:32 AM »
          Hi Chris, thanks for you help.

          I have followed yours and Patio's advice.  Here is the new Hijackthis log.  Is all OK?
          Logfile of Trend Micro HijackThis v2.0.0 (BETA)
          Scan saved at 09:28:52, on 12/05/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
          C:\WINDOWS\Explorer.EXE
          C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
          C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
          C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
          C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
          C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
          C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFAGENT.EXE
          C:\WINDOWS\AGRSMMSG.exe
          C:\Program Files\MSI\3D!Turbo Experience\3D!Turbo.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\WINDOWS\system32\wuauclt.exe
          D:\Ash\Zip files\HiJackThis_v2.exe

          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
          O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
          O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
          O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
          O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
          O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
          O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
          O4 - Global Startup: 3D!Turbo Experience.lnk = C:\Program Files\MSI\3D!Turbo Experience\3D!Turbo.exe
          O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
          O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
          O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131197105750
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1131208616000
          O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
          O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
          O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://help.broadbandassist.com/prequal/MotivePreQual.cab
          O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
          O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
          O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
          O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
          O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
          O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

          --
          End of file - 5332 bytes
          That's just the way it is

          CBMatt

          • Mod & Malware Specialist


          • Prodigy

          • Sad and lonely...and loving every minute of it.
          • Thanked: 167
            • Yes
          • Experience: Experienced
          • OS: Windows 7
          Re: Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses
          « Reply #7 on: May 12, 2007, 03:21:06 AM »
          It looks pretty clean to me.  Looks like you're doing a pretty decent job with protecting yourself.  Just a couple of things to go over...

          In addition to AVG, I would suggest also getting Spybot - Search & Destroy and AdAware SE Personal.

          For safer browsing you should use, Spyware Blaster and SiteAdvisor.  Both are very handy.

          At this point, it would also be a good idea to clean out your restore points...

          1.  Go to Start > Programs > Accessories > System Tools > System Restore
          2.  Click on System Restore Settings.
          3.  Check Turn off System Restore and click OK.
          4.  Restart your computer.
          5.  Follow steps 1 and 2 to return to the settings, uncheck Turn off System Restore, and click OK.
          6.  Create a new restore point and close the program.

          System Restore will now be active again.  If you would like to learn more about System Restore, go here.

          Infections can return if you restore your computer to an older point for any reason, which is why it's best to do this.  By following all of my steps here, you should be a lot safer online.
          Quote
          An undefined problem has an infinite number of solutions.
          由obert A. Humphrey

          ash72

            Topic Starter


            Rookie

            Re: Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses
            « Reply #8 on: May 12, 2007, 03:30:55 AM »
            Thanks Chris I will do that now.  I already use Spybot - Search & Destroy and Adaware SE Personal.  I will have a look at the safe browsing options.

            Thank you very much for your help.
            That's just the way it is

            CBMatt

            • Mod & Malware Specialist


            • Prodigy

            • Sad and lonely...and loving every minute of it.
            • Thanked: 167
              • Yes
            • Experience: Experienced
            • OS: Windows 7
            Re: Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses
            « Reply #9 on: May 12, 2007, 04:39:04 AM »
            You're welcome; come back anytime.

            And you're right, I see Spybot in your logs.  Silly me.  Heh.
            Quote
            An undefined problem has an infinite number of solutions.
            由obert A. Humphrey

            unlovedwarrior



              Guru

            • someday this name will be known
            • Thanked: 13
              Re: Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses
              « Reply #10 on: May 13, 2007, 03:23:13 PM »
              get superantispyware it does good at smitfruad and other things as well

              ash72

                Topic Starter


                Rookie

                Re: Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses
                « Reply #11 on: May 14, 2007, 01:24:26 AM »
                Chris

                Thanks for your advice on this.  I have cleaned out my system restore and intalled Spyware Blaster and Site Advisor. I am very impressed with Site Advisor.

                As far as I can tell my PC is working absolutely fine now.

                Once again, thanks for your help and recommendations.
                That's just the way it is

                CBMatt

                • Mod & Malware Specialist


                • Prodigy

                • Sad and lonely...and loving every minute of it.
                • Thanked: 167
                  • Yes
                • Experience: Experienced
                • OS: Windows 7
                Re: Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses
                « Reply #12 on: May 14, 2007, 01:41:16 AM »
                I'm glad things are going well for you.  SiteAdvisor is a handy program, but make sure you actually read the reports before entering sites you're not familiar with.  It's still a work in progress, so some sites that are green-lighted aren't always trustworthy (DoubleClick for example).  And just because a site is red-flagged, that doesn't always mean it's bad (Free Download Manager for example).  Please use your own discretion and common sense when viewing unknown sites.
                Quote
                An undefined problem has an infinite number of solutions.
                由obert A. Humphrey