Hello
A couple months ago Symantec's Auto-Protect feature began finding a "trojan." Symantec says it is Trojan-Spy.HTML.Smitfraud.c [Kaspersky]. I have been too busy to do much about it, but I have tried in the past to run smitfraudfix, Spy-bot, and winscp. Nothing seems to work completely. I have read many other forums and the like, and have finally decided to post some of my own reports. Here is the required DDS file. Wasn't sure if I should post the Attach file as well. I am running a kaspersky scan right now. And can supply a HJT report if needed.
Thank you
DDS (Version 1.0.1) - NTFSx86
Run by Michael at 18:50:47.52 on Mon 12/15/2008
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.2037.812 [GMT -5:00]
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\lxbccoms.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\lxdacoms.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\TVersity\Media Server\MediaServer.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\System32\alg.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\PROGRA~2\Stardock\XGF\XGFRuntimeServer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Symantec AntiVirus\DWHWIZRD.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\windows live safety center\wlschost.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Symantec AntiVirus\SavUI.exe
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\PROGRA~1\Java\jre6\bin\jp2launcher.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Users\Michael\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
uRun: [Aim6]
mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\programs\partygaming\partypoker\RunApp.exe
IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - c:\program files\bodog poker\BPGame.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - c:\programs\partygaming\partypoker\RunApp.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - c:\program files\bodog poker\BPGame.exe
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2008\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: avgwlntf - avgwlntf.dll
Notify: igfxcui - igfxdev.dll
STS: {E31004D1-A431-41B8-826F-E902F9D95C81} - %SystemRoot%\System32\DreamScene.dll
SEH: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
============= SERVICES / DRIVERS ===============
R2 lxbc_device;lxbc_device;c:\windows\system32\lxbccoms.exe -service []
R2 lxda_device;lxda_device;c:\windows\system32\lxdacoms.exe -service []
R2 SavRoam;SAVRoam;"c:\program files\symantec antivirus\SavRoam.exe" [2006-11-28 122008]
R2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\viewpoint\common\ViewpointService.exe" [2007-10-23 24652]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-9-5 99376]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-1-25 42000]
=============== Created Last 30 ================
2008-12-10 22:32 2,048 a------- c:\windows\system32\tzres.dll
2008-12-10 22:13 28,672 a------- c:\windows\system32\Apphlpdm.dll
2008-12-10 22:13 4,240,384 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2008-12-10 22:12 296,960 a------- c:\windows\system32\gdi32.dll
2008-12-10 02:55 2,546 a------- c:\windows\system32\tmp.reg
2008-12-10 02:55 691 a------- c:\users\michael\appdata\roaming\GetValue.vbs
2008-12-10 02:55 35 a------- c:\users\michael\appdata\roaming\SetValue.bat
2008-12-10 02:55 289,144 a------- c:\windows\system32\VCCLSID.exe
2008-12-10 02:55 288,417 a------- c:\windows\system32\SrchSTS.exe
2008-12-10 02:55 135,168 a------- c:\windows\system32\swreg.exe
2008-12-10 02:55 87,552 a------- c:\windows\system32\VACFix.exe
2008-12-10 02:55 79,360 a------- c:\windows\system32\swxcacls.exe
2008-12-10 02:55 53,248 a------- c:\windows\system32\Process.exe
2008-12-10 02:55 51,200 a------- c:\windows\system32\dumphive.exe
2008-12-10 02:55 25,600 a------- c:\windows\system32\WS2Fix.exe
2008-12-10 02:35 <DIR> --d----- c:\users\michael\SmitfraudFix
2008-12-04 03:07 <DIR> --d----- c:\program files\Trend Micro
2008-12-04 02:22 <DIR> --d----- C:\VundoFix Backups
2008-12-03 20:55 410,984 a------- c:\windows\system32\deploytk.dll
2008-12-03 20:48 <DIR> --d----- c:\users\michael\appdata\roaming\LimeWire
2008-12-03 20:46 <DIR> --d----- c:\program files\LimeWire
2008-12-03 09:37 1,524,736 a------- c:\windows\system32\wucltux.dll
2008-12-03 09:36 83,456 a------- c:\windows\system32\wudriver.dll
2008-12-03 09:36 162,064 a------- c:\windows\system32\wuwebv.dll
2008-12-03 09:36 31,232 a------- c:\windows\system32\wuapp.exe
2008-12-02 20:09 <DIR> --d----- c:\program files\WinSCP
2008-12-01 15:29 <DIR> --d----- c:\program files\iPod
2008-12-01 15:29 <DIR> --d----- c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-01 15:29 <DIR> --d----- c:\program files\iTunes
2008-12-01 15:29 <DIR> --d----- c:\progra~2\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-30 21:32 241,152 a------- c:\windows\system32\PortableDeviceApi.dll
2008-11-30 21:32 425,472 a------- c:\windows\system32\PhotoMetadataHandler.dll
2008-11-30 21:32 347,136 a------- c:\windows\system32\WindowsCodecsExt.dll
2008-11-30 21:32 712,704 a------- c:\windows\system32\WindowsCodecs.dll
2008-11-30 21:32 1,645,568 a------- c:\windows\system32\connect.dll
2008-11-21 12:57 <DIR> --d----- c:\users\michael\appdata\roaming\dBpoweramp
2008-11-20 19:21 <DIR> --d----- c:\programdata\WindowsSearch
2008-11-16 16:39 <DIR> --d----- c:\programdata\acccore
2008-11-16 16:39 <DIR> --d----- c:\progra~2\acccore
==================== Find3M ====================
2008-12-15 01:50 0 a------- c:\windows\system32\drivers\lvuvc.hs
2008-12-11 01:37 3,308 a------- c:\windows\bthservsdp.dat
2008-12-01 15:21 143,360 a------- c:\windows\inf\infstrng.dat
2008-12-01 15:21 86,016 a------- c:\windows\inf\infpub.dat
2008-10-31 22:44 52,736 a------- c:\windows\apppatch\iebrshim.dll
2008-10-31 22:44 2,154,496 a------- c:\windows\apppatch\AcGenral.dll
2008-10-31 22:44 541,696 a------- c:\windows\apppatch\AcLayers.dll
2008-10-31 22:44 460,288 a------- c:\windows\apppatch\AcSpecfc.dll
2008-10-31 22:44 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2008-10-29 01:29 2,927,104 a------- c:\windows\explorer.exe
2008-10-15 23:47 827,392 a------- c:\windows\system32\wininet.dll
2008-10-06 20:43 86,016 a------- c:\windows\inf\infstor.dat
2008-09-30 16:43 1,286,152 a------- c:\windows\system32\msxml4.dll
2008-09-18 00:09 3,601,464 a------- c:\windows\system32\ntkrnlpa.exe
2008-09-18 00:09 3,549,240 a------- c:\windows\system32\ntoskrnl.exe
2008-09-17 23:56 125,952 a------- c:\windows\system32\wersvc.dll
2008-09-17 23:56 147,456 a------- c:\windows\system32\Faultrep.dll
2008-09-17 21:16 2,032,640 a------- c:\windows\system32\win32k.sys
2008-07-21 01:46 174 a--sh--- c:\program files\desktop.ini
2008-07-21 01:23 665,600 a------- c:\windows\inf\drvindex.dat
2008-04-16 00:12 32 a------- c:\programdata\ezsid.dat
2008-04-16 00:12 32 a------- c:\progra~2\ezsid.dat
2008-03-23 04:15 87,608 a------- c:\users\michael\appdata\roaming\inst.exe
2008-03-23 04:15 47,360 a------- c:\users\michael\appdata\roaming\pcouffin.sys
2006-11-02 07:40 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:40 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:40 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:40 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
2008-03-24 07:09 32,768 a--sh--- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008032420080325\index.dat
2008-03-24 07:09 32,768 a--sh--- c:\windows\system32\config\systemprofile\appdata\roaming\microsoft\internet explorer\userdata\index.dat
============= FINISH: 18:51:55.93 ===============