SmitFraudFix v2.334

Scan done at 16:20:38,79, st 21.01.2015
Run from C:\Documents and Settings\Radek\Dokumenty\Downloads\SmitfraudFix
OS: Microsoft Windows XP [Verze 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

 SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

 Killing process


 hosts

127.0.0.1         localhost

 VACFix

VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


 Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


 Generic Renos Fix

GenericRenosFix by S!Ri


 Deleting infected files


 IEDFix

IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri



 404Fix

404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri


 DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{D60D6BA1-7ED4-4918-8350-090CDFF7CF1F}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{D60D6BA1-7ED4-4918-8350-090CDFF7CF1F}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{D60D6BA1-7ED4-4918-8350-090CDFF7CF1F}: DhcpNameServer=192.168.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1


 Deleting Temp Files


 Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


 Registry Cleaning
 
Registry Cleaning done. 
 
 SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


 End

