here's smartfix
SmitFraudFix v2.53
Scan done at 15:27:03.48, Fri 06/02/2006
Run from C:\Documents and Settings\User\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
C:\WINDOWS\system32\ld????.tmp FOUND !
C:\WINDOWS\system32\ot.ico FOUND !
C:\WINDOWS\system32\simpole.tlb FOUND !
C:\WINDOWS\system32\stdole3.tlb FOUND !
C:\WINDOWS\system32\ts.ico FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\User\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\User\FAVORI~1
C:\DOCUME~1\User\FAVORI~1\Antivirus Test Online.url FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{e5b1e382-817e-4b74-8a96-ec78751e6acf}"="incatenate"
[HKEY_CLASSES_ROOT\CLSID\{e5b1e382-817e-4b74-8a96-ec78751e6acf}\InProcServer32]
@="C:\WINDOWS\system32\imfdfcj.dll"
[HKEY_CURRENT_USER\Software\Classes\CLSID\{e5b1e382-817e-4b74-8a96-ec78751e6acf}\InProcServer32]
@="C:\WINDOWS\system32\imfdfcj.dll"
»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
and here's ewido
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 3:43:29 PM, 6/2/2006
+ Report-Checksum: 8AC056E1
+ Scan result:
:mozilla.33:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.34:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.35:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.36:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.37:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.38:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.39:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.40:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.41:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.42:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.43:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.44:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.45:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.53:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
:mozilla.54:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
:mozilla.59:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.60:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.61:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.62:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.70:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.73:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.74:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.75:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.76:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.77:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.80:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.81:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.125:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\9kq7jwgf.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\User\Cookies\user@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
::Report End
Although I had ewido installed already with the background guard and text menu thing. Also, www.gamespot.com is not working for me, which is odd because everyother site seems to, maybe it's down but I can't find anything that says so.