Hey!
My computer is totally infected with Trojan-Spy.html.smitfraud.c . I've got the blue screen thing and everything! I've got Privacy Scanner that installed while I was on the net, and I can't find it anywhere to delete it. Norton doesn't even touch this hacker code, and neither does Ad-Aware. I've got hijackthis, but don't know much about it.
If you could give me any help, or tips it would be fantastic! Thanks in advance for any help you can hand out! ^_^

Logfile of HijackThis v1.99.1
Scan saved at 3:48:02 PM, on 8/9/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\WINDOWS\cskware.exe
C:\Program Files\Ncxh\Sttdea.exe
C:\WINDOWS\System32\wintask.exe
C:\WINDOWS\System32\dmbindaspf.exe
C:\WINDOWS\System32\vidctrl\vidctrl.exe
C:\DOCUME~1\OWNERH~1.000\LOCALS~1\Temp\sysnet.exe
C:\WINDOWS\System32\exp.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\apisvc.exe
C:\WINDOWS\System32\secserv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
c:\windows\system32\etzvedc.exe
C:\WINDOWS\System32\hhjknl.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\wdwedll.EXE
C:\WINDOWS\wdweenc.EXE
C:\WINDOWS\system\xacuxc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\secserv.exe
C:\WINDOWS\System32\dfsvox.exe
C:\WINDOWS\System32\apisvc.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Cas\Client\casclient.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\qbxasvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\rdso\eetu.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\OWNERH~1.000\LOCALS~1\Temp\mirindaspg.exe
C:\Documents and Settings\Owner.HOMESWEETHOME.000\Local Settings\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
R3 - URLSearchHook: (no name) - _{EA756889-2338-43DB-8F07-D1CA6FB9C90D} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O1 - Hosts: www.google.ae
O1 - Hosts: www.google.am
O1 - Hosts: www.google.as
O1 - Hosts: www.google.at
O1 - Hosts: www.google.az
O1 - Hosts: www.google.be
O1 - Hosts: www.google.bi
O1 - Hosts: www.google.ca
O1 - Hosts: www.google.cd
O1 - Hosts: www.google.cg
O1 - Hosts: www.google.ch
O1 - Hosts: www.google.ci
O1 - Hosts: www.google.cl
O1 - Hosts: www.google.co.cr
O1 - Hosts: www.google.co.hu
O1 - Hosts: www.google.co.il
O1 - Hosts: www.google.co.in
O1 - Hosts: www.google.co.je
O1 - Hosts: www.google.co.jp
O1 - Hosts: www.google.co.ke
O1 - Hosts: www.google.co.kr
O1 - Hosts: www.google.co.ls
O1 - Hosts: www.google.co.nz
O1 - Hosts: www.google.co.th
O1 - Hosts: www.google.co.ug
O1 - Hosts: www.google.co.uk
O1 - Hosts: www.google.co.ve
O1 - Hosts: www.google.com
O1 - Hosts: www.google.com.ag
O1 - Hosts: www.google.com.ar
O1 - Hosts: www.google.com.au
O1 - Hosts: www.google.com.br
O1 - Hosts: www.google.com.co
O1 - Hosts: www.google.com.cu
O1 - Hosts: www.google.com.do
O1 - Hosts: www.google.com.ec
O1 - Hosts: www.google.com.fj
O1 - Hosts: www.google.com.gi
O1 - Hosts: www.google.com.gr
O1 - Hosts: www.google.com.gt
O1 - Hosts: www.google.com.hk
O1 - Hosts: www.google.com.ly
O1 - Hosts: www.google.com.mt
O1 - Hosts: www.google.com.mx
O1 - Hosts: www.google.com.my
O1 - Hosts: www.google.com.na
O1 - Hosts: www.google.com.nf
O1 - Hosts: www.google.com.ni
O1 - Hosts: www.google.com.np
O1 - Hosts: www.google.com.pa
O1 - Hosts: www.google.com.pe
O1 - Hosts: www.google.com.ph
O1 - Hosts: www.google.com.pk
O1 - Hosts: www.google.com.pr
O1 - Hosts: www.google.com.py
O1 - Hosts: www.google.com.sa
O1 - Hosts: www.google.com.sg
O1 - Hosts: www.google.com.sv
O1 - Hosts: www.google.com.tr
O1 - Hosts: www.google.com.tw
O1 - Hosts: www.google.com.ua
O1 - Hosts: www.google.com.uy
O1 - Hosts: www.google.com.vc
O1 - Hosts: www.google.com.vn
O1 - Hosts: www.google.de
O1 - Hosts: www.google.dj
O1 - Hosts: www.google.dk
O1 - Hosts: www.google.es
O1 - Hosts: www.google.fi
O1 - Hosts: www.google.fm
O1 - Hosts: www.google.fr
O1 - Hosts: www.google.gg
O1 - Hosts: www.google.gl
O1 - Hosts: www.google.gm
O1 - Hosts: www.google.hn
O1 - Hosts: www.google.ie
O1 - Hosts: www.google.it
O1 - Hosts: www.google.kz
O1 - Hosts: www.google.li
O1 - Hosts: www.google.lt
O1 - Hosts: www.google.lu
O1 - Hosts: www.google.lv
O1 - Hosts: www.google.mn
O1 - Hosts: www.google.ms
O1 - Hosts: www.google.mu
O1 - Hosts: www.google.mw
O1 - Hosts: www.google.nl
O1 - Hosts: www.google.no
O1 - Hosts: www.google.off.ai
O1 - Hosts: www.google.pl
O1 - Hosts: www.google.pn
O1 - Hosts: www.google.pt
O1 - Hosts: www.google.ro
O1 - Hosts: www.google.ru
O1 - Hosts: www.google.rw
O1 - Hosts: www.google.se
O1 - Hosts: www.google.sh
O1 - Hosts: www.google.sk
O1 - Hosts: www.google.sm
O1 - Hosts: www.google.td
O1 - Hosts: www.google.tm
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfgmgr52.dll
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: (no name) - {5483427F-93B8-1470-5A89-E6B56484CDB2} - C:\DOCUME~1\OWNERH~1.000\LOCALS~1\Temp\ajenkpituzg.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar1.dll
O2 - BHO: RichEditor Class - {F79A2C4B-8776-4ED7-8B2F-4786A4A3500A} - C:\WINDOWS\System32\richedtr.dll
O3 - Toolbar: Date Bar - {A833AB67-7368-457E-B8BF-249CCD8DDD14} - C:\DOCUME~1\OWNERH~1.000\LOCALS~1\Temp\dbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar1.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [AUNPS2] RUNDLL32 AUNPS2.DLL,_Run@16
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [xware] "C:\WINDOWS\cskware.exe"
O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\Zvzscw.exe
O4 - HKLM\..\Run: [Mxpyn] C:\Program Files\Ncxh\Sttdea.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\System32\wintask.exe
O4 - HKLM\..\Run: [o36k3mO] dmbindaspf.exe
O4 - HKLM\..\Run: [mscin] C:\WINDOWS\system32\m190309.EXE
O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\System32\vidctrl\vidctrl.exe
O4 - HKLM\..\Run: [PSof1] C:\WINDOWS\System32\PSof1.exe
O4 - HKLM\..\Run: [richup] C:\WINDOWS\System32\richup.exe
O4 - HKLM\..\Run: [Sysnet] C:\DOCUME~1\OWNERH~1.000\LOCALS~1\Temp\sysnet.exe
O4 - HKLM\..\Run: [checkrun] c:\windows\system32\eliteaaz32.exe
O4 - HKLM\..\Run: [exp] C:\WINDOWS\System32\exp
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [apisvc.exe] C:\WINDOWS\System32\apisvc.exe
O4 - HKLM\..\Run: [secserv.exe] C:\WINDOWS\System32\secserv.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IS CfgWiz] C:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\hhjknl.exe reg_run
O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [wdwedll] C:\WINDOWS\wdwedll.EXE
O4 - HKLM\..\Run: [wdweenc] C:\WINDOWS\wdweenc.EXE
O4 - HKLM\..\Run: [C:\WINDOWS\VCMnet11.exe] C:\WINDOWS\VCMnet11.exe
O4 - HKLM\..\Run: [hcgkajk] c:\windows\system32\etzvedc.exe r
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Z0pqRgi5V] dfsvox.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [CAS Client] "C:\Program Files\Cas\Client\casclient.exe"
O4 - HKCU\..\Run: [CMAPP] "C:\Program Files\CMAPP\Client\cmappclient.exe"
O4 - HKCU\..\Run: [WareOut] "C:\Program Files\WareOut\WareOut.exe"
O4 - HKCU\..\Run: [iwmw] C:\PROGRA~1\COMMON~1\iwmw\iwmwm.exe
O4 - HKCU\..\Run: [PrivacyScanner] C:\Program Files\Privacy Champion\pscan.exe
O4 - HKCU\..\Run: [atiupdate] C:\WINDOWS\System32\msshed32.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O15 - Trusted Zone: *.
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - ms-its:mhtml:file://c:\nosuxxy.mht!
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - ms-its:mhtml:file://c:\nosuxxx.mht!
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} -
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} - ms-its:mhtml:file://c:\nosuxxz.mht!
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{B19DA655-3B03-4E81-A856-AB6285BB91ED}: NameServer = 195.95.218.1,
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\whnhttp.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Windows VisFx Components - Unknown owner - C:\WINDOWS\qbxasvc.exe

Dani AI

Generated

A compact, action-focused recovery workflow for a heavily compromised Windows XP machine (as reported by ), meant to sit above the thread and complement the links and checks that recommended. Prioritize containment, evidence preservation, and a clean removal environment; selective deletions often leave rootkits or backups that cause reinfection. When time or confidence are limited, a secure wipe and clean reinstall is the fastest way to restore trust.

Immediate containment and preparation:

  • Isolate the PC from all networks (unplug Ethernet, disable Wi‑Fi) to stop data leaks or spreading.
  • From a known-clean computer, prepare bootable rescue media (AV rescue ISO) and portable troubleshooting tools (offline scanners, rootkit checker, Sysinternals Autoruns/Process Explorer).
  • Back up only personal data (documents, photos, mail stores). Do not copy executables, installers, or credential files to the backup media.

Cleanup and troubleshooting:

  • Boot the infected machine from rescue media and run full signature and rootkit scans. If Windows must be used, boot Safe Mode and run updated offline tools.
  • Disable System Restore before removal so infected restore points are not retained.
  • Use Autoruns to disable unknown startup items and inspect services; remove only items that are clearly malicious. Avoid blind deletions of system files.
  • Run disk and system repairs (chkdsk and SFC or recovery-console tools) if file corruption or blue screens persist.

Post-clean hardening and fallback:

  • From a clean device, change all passwords and enable two-factor where available.
  • Fully patch the OS, enable firewall/automatic updates, install a reputable anti‑malware product, and schedule regular scans.
  • If instability, rootkit presence, or loss of trust remain, perform a full wipe and reinstall after copying only verified personal files.
  • As advised, place diagnostic tools in their own folders and produce fresh logs for targeted follow-up once the above steps are complete.

Hi NoExpert, welcome to DaniWeb :D

Please follow the suggestions and instructions in the links below to help prevent reinfections, start the cleanup process, and to find out a bit about HijackThis (like putting it in its own permanent folder).

After you've finished the first post (about HijackThis), see post #8 for links to fixes for smitfraud; you may also want to try the suggestions in post #4.

When you've completed all that, and moved HJT, please post a new log.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.