SmitFraudFix v2.221 Scan done at 20:51:38,47, 08.09.2007 Run from F:\SmitfraudFix OS: Microsoft Windows [Versjon 6.0.6000] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{f39d0dee-b2f0-4591-9187-1cc39c1df98a}"="biisk" [HKEY_CLASSES_ROOT\CLSID\{f39d0dee-b2f0-4591-9187-1cc39c1df98a}\InProcServer32] @="C:\Windows\system32\kzpkwj.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{f39d0dee-b2f0-4591-9187-1cc39c1df98a}\InProcServer32] @="C:\Windows\system32\kzpkwj.dll" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost ::1 localhost »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri C:\Windows\system32\kzpkwj.dll -> Hoax.Win32.Renos.gen.o C:\Windows\system32\kzpkwj.dll -> Deleted »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files Problem while deleting C:\Windows\system32\sysmain.dll C:\Users\john\AppData\Roaming\MICROS~1\Windows\STARTM~1\VirusProtectPro 3.7.lnk Deleted C:\Users\john\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\VirusProtectPro 3.7 Deleted C:\Users\john\Desktop\VirusProtectPro 3.7.lnk Deleted C:\Users\Public\Desktop\Online Security Guide.url Deleted C:\Users\Public\Desktop\Security Troubleshooting.url Deleted C:\Users\john\FAVORI~1\Online Security Test.url Deleted C:\Program Files\Video ActiveX Access\ Deleted C:\Program Files\VirusProtectPro 3.7\ Deleted »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{6285BE4F-7F03-40C4-9363-DA058C012808}: DhcpNameServer=10.5.5.245 HKLM\SYSTEM\CCS\Services\Tcpip\..\{A789884A-F946-4173-B08F-FB73B7475003}: DhcpNameServer=192.168.1.1 130.67.60.68 193.213.112.4 HKLM\SYSTEM\CS1\Services\Tcpip\..\{6285BE4F-7F03-40C4-9363-DA058C012808}: DhcpNameServer=10.5.5.245 HKLM\SYSTEM\CS1\Services\Tcpip\..\{A789884A-F946-4173-B08F-FB73B7475003}: DhcpNameServer=192.168.1.1 130.67.60.68 193.213.112.4 HKLM\SYSTEM\CS2\Services\Tcpip\..\{6285BE4F-7F03-40C4-9363-DA058C012808}: DhcpNameServer=10.5.5.245 HKLM\SYSTEM\CS2\Services\Tcpip\..\{A789884A-F946-4173-B08F-FB73B7475003}: DhcpNameServer=192.168.1.1 130.67.60.68 193.213.112.4 HKLM\SYSTEM\CS3\Services\Tcpip\..\{6285BE4F-7F03-40C4-9363-DA058C012808}: DhcpNameServer=10.5.5.245 HKLM\SYSTEM\CS3\Services\Tcpip\..\{A789884A-F946-4173-B08F-FB73B7475003}: DhcpNameServer=192.168.1.1 130.67.60.68 193.213.112.4 HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 130.67.60.68 193.213.112.4 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Reboot Problem while deleting C:\Windows\system32\sysmain.dll »»»»»»»»»»»»»»»»»»»»»»»» End