Thank you very much. This worked whereas my anti-virus programs (PCTools Spyware Doctor, Ad-Aware, CCleaner) did not. Here is rapport.txt:
SmitFraudFix v2.383

Scan done at 13:20:15.46, Thu 12/11/2008
Run from C:\Documents and Settings\den\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINNT\system32\c.ico Deleted
C:\WINNT\system32\m.ico Deleted
C:\WINNT\system32\p.ico Deleted
C:\WINNT\system32\s.ico Deleted
C:\DOCUME~1\den\STARTM~1\Cheap Pharmacy Online.url Deleted
C:\DOCUME~1\den\STARTM~1\Search Online.url Deleted
C:\DOCUME~1\den\STARTM~1\SMS TRAP.url Deleted
C:\DOCUME~1\den\STARTM~1\VIP Casino.url Deleted
C:\DOCUME~1\den\FAVORI~1\Search Online.url Deleted
C:\Program Files\Google\googletoolbar1.dll Deleted

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri

C:\WINNT\system32\ugsaker.dll deleted.


»»»»»»»»»»»»»»»»»»»»»»»» 404Fix

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» RK


»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: NVIDIA nForce MCP Networking Adapter
DNS Server Search Order:

Description: NVIDIA nForce MCP Networking Adapter
DNS Server Search Order:
DNS Server Search Order:

HKLM\SYSTEM\CCS\Services\Tcpip\..\{BFD42E0D-4D89-4593-93E6-EF91D8DC2ED4}: DhcpNameServer=
HKLM\SYSTEM\CCS\Services\Tcpip\..\{C7A0C366-FB27-45E3-8BA1-69C7EEA6791E}: DhcpNameServer=
HKLM\SYSTEM\CCS\Services\Tcpip\..\{E5A5444B-D80F-4CE3-ADD0-3E3E8E1D2C70}: DhcpNameServer=
HKLM\SYSTEM\CS1\Services\Tcpip\..\{BFD42E0D-4D89-4593-93E6-EF91D8DC2ED4}: DhcpNameServer=
HKLM\SYSTEM\CS1\Services\Tcpip\..\{C7A0C366-FB27-45E3-8BA1-69C7EEA6791E}: DhcpNameServer=
HKLM\SYSTEM\CS1\Services\Tcpip\..\{E5A5444B-D80F-4CE3-ADD0-3E3E8E1D2C70}: DhcpNameServer=
HKLM\SYSTEM\CS3\Services\Tcpip\..\{BFD42E0D-4D89-4593-93E6-EF91D8DC2ED4}: DhcpNameServer=
HKLM\SYSTEM\CS3\Services\Tcpip\..\{C7A0C366-FB27-45E3-8BA1-69C7EEA6791E}: DhcpNameServer=
HKLM\SYSTEM\CS3\Services\Tcpip\..\{E5A5444B-D80F-4CE3-ADD0-3E3E8E1D2C70}: DhcpNameServer=
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

Dani AI

Generated

Good start: SmitFraudFix has already removed visible items, and ’s request to run Malwarebytes and HijackThis is the right next step. Post the Malwarebytes log first, then the HijackThis log exactly as requested so helpers can triage persistent items and startup entries.

After those scans, verify and repair the network and persistence vectors that cleaners often miss. From an elevated prompt run these, then reboot:

ipconfig /flushdns
netsh winsock reset
netsh int ip reset resetlog.txt

Check the router next. If DNS servers or admin credentials look unfamiliar, reboot the router, change its admin password, and perform a factory reset if needed. Firmware updates are important — many “DNS hijack” problems survive PC cleanup because the router itself was altered.

Inspect browser and startup persistence. Look for unexpected proxy settings, unknown browser extensions, and scheduled tasks or services that reappear. Use Autoruns (Sysinternals) or msconfig to review auto-start items and remove anything that looks unfamiliar; then re-scan with Malwarebytes. Also clear or delete old System Restore points so a removed infection cannot be restored.

Final cautions: if online accounts were used from the infected machine, change those passwords from a known-clean device. If the system shows continuing odd DNS, redirecting, or reappearing malware, consider an offline rescue scan or a full OS reinstall — that is the only guaranteed way to be certain. After cleanup, keep Windows and AV up to date and enable the firewall.

Once the Malwarebytes and HijackThis logs are posted, targeted follow-up steps can be given.

Hello and Welcome to Daniweb,

Can you pls do the following:

1. - Download Malwarebytes' Anti-Malware (http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button) to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Make sure that you restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

2. - Download and post the log.

In your reply, post the logs (in this order):
1. - Malware Bytes Log
2. - Hijackthis Log

Thanks,

Cohen

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.