I'm in need of some help. A small error triangle (yellow with an exclamation mark) keeps flashing in my control bar; warning balloons and all sorts of popups for spyware removers (and some lovely porn) keep appearing. I've run my Norton virus killer and Ad-aware, but can't get rid of them. I'm not computer literate, so could do with some assistance please!
Logfile of HijackThis v1.99.1
Scan saved at 20:14:15, on 03/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Please download:
SmitfraudFix (by
S!Ri)
Extract the contents (a folder named
SmitfraudFix) to your Desktop.
Open the
SmitfraudFix folder and double-click
smitfraudfix.cmd Select option #1 -
Search by typing
1 and press"
Enter"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that report into your next reply.
Note :
process.exe
is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
Scan done at 21:44:13.98, 03/11/2006
Run from C:\Documents and Settings\Nia\My Documents\Unzipped\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Nia
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Nia\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Nia\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
C:\Program Files\VidCodecs\ FOUND !
C:\Program Files\VirusBursters\ FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.
Once in Safe Mode, open the
SmitfraudFix folder again and double-click
smitfraudfix.cmd Select option #2 -
Clean by typing
2 and press"
Enter" to delete infected files.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing
Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if
wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing
Y and press "Enter".
The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into your Normal Windows user mode.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at
C:\rapport.txt
Warning : running option #2 on a non infected computer will remove your Desktop background.
Logfile of HijackThis v1.99.1
Scan saved at 13:37:26, on 04/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Scan done at 13:30:23.20, 04/11/2006
Run from C:\Documents and Settings\Nia\My Documents\Unzipped\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
OK, you did good work. Now to remove the rest of the problems...
First:
Your Java application is out of date and causes a slight security risk as a result.
Please follow these steps to remove older version Java components
1. Close any open programs you may have running, especially your web
browser.
2. Click Start-->Control Panel-->Add or Remove Programs.
For those just reading this thread: Depending on your OS, you may have to click Start-->Settings-->Control Panel-->Add or Remove Programs.
3. Click once on any item listing Java Runtime Environment in the name (to highlight it) then click the "Remove" or "Change/Remove" button.
Not every version of Java will begin with "Java" so be sure to read each entry in the list. Repeat step 3 as many times as necessary to remove all versions of Java.
**If you are asked to reboot at any point during the uninstallations, please do so. Then go back to Add/Remove and continue with the rest of the removals...when finished uninstalling all of them, reboot the computer.
4. Navigate to and delete:
C:\Program Files\ Java =this folderif found
5. Then go to
this page.
Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"and click the "Download" button to the right.
6. Check the box that says: "Accept License Agreement"
the page will refresh and click on the link to download Windows Offline Installation with or without Multi-language. Save it to your desktop.
Then from your desktop double-click on jre-1_5_0_09-windowsi586-p.exe to install the newest version.
Please download the
KILLBOX, extract it to your desktop.
DO NOTHING WITH IT YET.
Download and scan with AVG Anti-Spyware v7.5 (
This is Ewido 4.0 renamed. If you already have Ewido installed, please update to this version which has a special "clean driver" for removing persistent malware)
After download, double click on the file to launch the install process.
Choose a language, click "OK" and then click "Next".
After setup completes, click "Finish" to start the program automatically or launch AVG Anti-Spyware by double-clicking its icon on your desktop or in the system tray.
The main "Status" menu will appear. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'.
Then right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows".
Go to Start > Run and type:
services.msc
Press "OK".
Click the "Extended tab" and scroll down the list to find AVG Anti-Spyware guard.
When you find the guard service, double-click on it.
In the Properties Window > General Tab that opens, click the "Stop" button.
From the drop-down menu next to "Startup Type", click on "Manual".
Now click "Apply", then "OK" and close the Services window.
Select the "Update" button and click "Start update". Wait until you see the "Update succesfull message. If you are having problems with the updater, manually update with the AVG Anti-Spyware Full database installer from here.
Once the updates are installed do the following:
Click on the "
Scanner" button and choose the "
Settings" tab.
Under "How to act?", click on "Recommended actions" and choose "Quarantine" to set default action for detected malware.
Under "How to Scan?" check all (default).
Under "Possibly unwanted software" check all (default).
Under "What to Scan?" make sure "Scan every file" is selected (default).
Under "Reports" select "Automatically generate report after every scan" and UNcheck "Only if threats were found".
Close the application and reboot the computer into
Safe mode. Once in safe mode continue with the instructions below:
Open the AVG Anti-Spyware application and click the "
Scan" tab.
Click "
Complete System Scan" to start.
Note: Close all open windows, programs, and DO NOT USE the computer while AVG Anti-Spyware is scanning. If Explorer or other programs are open during the scan that means certain files will also be in use. Some malware will insert itself and hide in areas that are "protected" by Windows when the files are being used. This can hamper AVG Anti-Spyware's ability to clean properly and may result in reinfection.
Note: If AVG Anti-Spyware "crashes" or "hangs" during the scan, try scanning again by doing this:
Scan one sector of the system at a time by using the "Custom Scan" feature. To do this select Scanner > Custom Scan and click on Add drive/directory/file. Browse to C:\Windows > System, add this folder to the list and click on "Start Scan". When the scan is complete, repeat the Custom Scan but this time, browse to and add the System32 folder. Then keep repeating this procedure until all your folders have been scanned. Make sure you include the Documents & Settings folder.
If this still does not help, then turn the ADS scanner off while making a Custom Scan. To do this select Scanner > Scan Settings and untick "Scan in NTFS Alternate Data Streams". Then repeat the steps above for performing a Custom Scan.
When the scan has finished you will be presented with a list of infected objects found. Click "
Apply all actions" to place the files in Quarantine.
IMPORTANT! Do not save the report before you have clicked the
Apply all actions button. If you do, the log that is created will indicate "
No action taken", making it more difficult to interpret the report. So be sure you save it only AFTER clicking the "Apply all actions" button?
Click on "
Save Report" to view all completed scans. Click on the most recent scan you just performed and select "
Save report as" - the default file name will be in date/time format as follows:
Report-Scan-20060620-142816.txt. Save to your desktop. A copy of each report will also be saved in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports\
Exit AVG Anti-Spyware when done.
Please open killbox.exe. First click on Tools-->Delete Temp Files. A box will open with a list of all user profiles.
Check the following boxes at a minimum for each profile by clicking on the drop down and checking the boxes that are enabled. Some will not apply and those boxes will not be available to check. Make sure you do this for all the profiles listed.
Temporary Internet Files
Temp Files
XP Prefetch
If you want to clean your cookies, history, and list of recent files run you may check those boxes as well. Next, click on the Button titled "Delete Selected Temp Files".
Exit by clicking the Button titled "Exit(Save Settings)".
Once back into the main killbox program, check the box
Delete on Reboot.
Highlight the entries below in
Bold text and then copy them.
C:\WINDOWS\system32\darox.exe C:\WINDOWS\system32\dmsvt.exe C:\WINDOWS\system32\admincfg.exe
Then in killbox click File-->Paste from Clipboard. Click the "All Files" button. Then click the
Red X ...and for the confirmation message that will appear, you will need to click
Yes.
A second message will ask to Reboot now? you will need to click
No for now.
Note: Killbox will let you know if a file does not exist.
If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the
Red X ...and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until you've completed the instructions below.
Please run HijackThis again and check the following:
O1 - Hosts: localhost 127.0.0.1 O4 - HKLM\..\Run: C:\WINDOWS\system32\darox.exe O4 - HKLM\..\Run: C:\WINDOWS\system32\dmsvt.exe O4 - HKCU\..\Run: C:\WINDOWS\system32\admincfg.exe
I doubt you are from the Ukraine...but if so, ignore checking the entries below. If not, please put a check in the box next to all of these too: O17 - HKLM\System\CCS\Services\Tcpip\..\{264B02DC-885D-4AF1-973F-ED65FCD7FB68}: NameServer = 85.255.116.62,85.255.112.233 O17 - HKLM\System\CCS\Services\Tcpip\..\{AA517AC4-3046-42B4-B334-D79560C2516E}: NameServer = 85.255.116.62,85.255.112.233 O17 - HKLM\System\CCS\Services\Tcpip\..\{EA769F56-D9D2-4F17-82E0-DF7F94455A92}: NameServer = 85.255.116.62 85.255.112.233 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.62 85.255.112.233 O17 - HKLM\System\CS1\Services\Tcpip\..\{264B02DC-885D-4AF1-973F-ED65FCD7FB68}: NameServer = 85.255.116.62,85.255.112.233 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.62 85.255.112.233
Close all windows now except for the HijackThis application window then click
Fix Checked.
Reboot the computer and post the results from your AVG Anti-Spyware scan along with a fresh HijackThis log. Please advise how the computer is running now. Thanks!
Thank you so much for all of the help, I'm really grateful! I am now free of the pop ups and critical error balloons/warning icons in my tray. My internet connection is much faster too; the only thing that is still a tad slow is the load up time of Windows XP when I log onto my account, but that may be due to the amount on my hardrive or number of programs that load up.
I'm hoping that I ran Killbox correctly. Here are my logs:
Logfile of HijackThis v1.99.1
Scan saved at 23:31:54, on 04/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.
Once the desktop loads post the text that will open (report.txt) and a new Hijackthis log in your next reply. Thanks!
1972vet
3305 Posts
221
0
Posted November 3rd, 2006 19:00
SmitfraudFix (by S!Ri)
Extract the contents (a folder named SmitfraudFix) to your Desktop.
Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press" Enter"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that report into your next reply.
Note :
process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.