SmitFraudFix v2.132
Scan done at 8:58:21.18, 01/14/2007 Sun
Run from C:\Documents and Settings\Daniel Neumann\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
ササササササササササササササササササササササササ C:\
ササササササササササササササササササササササササ C:\WINDOWS
ササササササササササササササササササササササササ C:\WINDOWS\system
ササササササササササササササササササササササササ C:\WINDOWS\Web
ササササササササササササササササササササササササ C:\WINDOWS\system32
ササササササササササササササササササササササササ C:\WINDOWS\system32\LogFiles
ササササササササササササササササササササササササ C:\Documents and Settings\Daniel Neumann
ササササササササササササササササササササササササ C:\Documents and Settings\Daniel Neumann\Application Data
ササササササササササササササササササササササササ Start Menu
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !
ササササササササササササササササササササササササ C:\DOCUME~1\DANIEL~1\FAVORI~1
C:\DOCUME~1\DANIEL~1\FAVORI~1\Online Security Test.url FOUND !
ササササササササササササササササササササササササ Desktop
ササササササササササササササササササササササササ C:\Program Files
ササササササササササササササササササササササササ Corrupted keys
ササササササササササササササササササササササササ Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
ササササササササササササササササササササササササ Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{8670ee50-01f9-47da-ac1e-cf8549e9e521}"="eupeptic"
[HKEY_CLASSES_ROOT\CLSID\{8670ee50-01f9-47da-ac1e-cf8549e9e521}\InProcServer32]
@="C:\WINDOWS\system32\axlet.dll"
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8670ee50-01f9-47da-ac1e-cf8549e9e521}\InProcServer32]
@="C:\WINDOWS\system32\axlet.dll"
ササササササササササササササササササササササササ AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~1\\GOEC62~1.DLL"
ササササササササササササササササササササササササ Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"="kdlqq.exe"
kdlqq.exe detected !
ササササササササササササササササササササササササ pe386-msguard-lzx32
ササササササササササササササササササササササササ Scanning wininet.dll infection
ササササササササササササササササササササササササ End
Scan done at 8:58:21.18, 01/14/2007 Sun
Run from C:\Documents and Settings\Daniel Neumann\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
ササササササササササササササササササササササササ C:\
ササササササササササササササササササササササササ C:\WINDOWS
ササササササササササササササササササササササササ C:\WINDOWS\system
ササササササササササササササササササササササササ C:\WINDOWS\Web
ササササササササササササササササササササササササ C:\WINDOWS\system32
ササササササササササササササササササササササササ C:\WINDOWS\system32\LogFiles
ササササササササササササササササササササササササ C:\Documents and Settings\Daniel Neumann
ササササササササササササササササササササササササ C:\Documents and Settings\Daniel Neumann\Application Data
ササササササササササササササササササササササササ Start Menu
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !
ササササササササササササササササササササササササ C:\DOCUME~1\DANIEL~1\FAVORI~1
C:\DOCUME~1\DANIEL~1\FAVORI~1\Online Security Test.url FOUND !
ササササササササササササササササササササササササ Desktop
ササササササササササササササササササササササササ C:\Program Files
ササササササササササササササササササササササササ Corrupted keys
ササササササササササササササササササササササササ Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
ササササササササササササササササササササササササ Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{8670ee50-01f9-47da-ac1e-cf8549e9e521}"="eupeptic"
[HKEY_CLASSES_ROOT\CLSID\{8670ee50-01f9-47da-ac1e-cf8549e9e521}\InProcServer32]
@="C:\WINDOWS\system32\axlet.dll"
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8670ee50-01f9-47da-ac1e-cf8549e9e521}\InProcServer32]
@="C:\WINDOWS\system32\axlet.dll"
ササササササササササササササササササササササササ AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~1\\GOEC62~1.DLL"
ササササササササササササササササササササササササ Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"="kdlqq.exe"
kdlqq.exe detected !
ササササササササササササササササササササササササ pe386-msguard-lzx32
ササササササササササササササササササササササササ Scanning wininet.dll infection
ササササササササササササササササササササササササ End