Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)
![]() ![]() |
Apr 17 2006, 08:23 PM
Post
#1
|
|
![]() Forum God Group: Root Admin Posts: 39,097 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
QUOTE SmitfraudFix by S!Ri This tool removes Desktop Hijack malware: AdwarePunisher, AdwareSheriff, AlphaCleaner, Antispyware Soldier, AntiVermeans, AntiVermins, AntiVerminser, AntivirusGolden, AVGold, BraveSentry, MalwareWipe, MalwareWiped, MalwaresWipeds, MalwareWipePro, MalwareWiper, PestCapture, PestTrap, PSGuard, quicknavigate.com, Registry Cleaner, Security iGuard, Smitfraud, SpyAxe, SpyCrush, SpyDown, SpyFalcon, SpyGuard, SpyHeal, SpyHeals, SpyLocked, SpyMarshal, SpySheriff, SpySoldier, Spyware Vanisher, Spyware Soft Stop, SpywareLocked, SpywareQuake, SpywareKnight, SpywareSheriff, SpywareStrike, Startsearches.net, TitanShield Antispyware, Trust Cleaner, UpdateSearches.com, Virtual Maid, VirusBlast, VirusBurst, Win32.puper, WinHound, Brain Codec, DirectVideo, EliteCodec, eMedia Codec, FreeVideo, Gold Codec, HQ Codec, iCodecPack, iMediaCodec, Image ActiveX Object, IntCodec, iVideoCodec, JPEG Encoder, Key Generator, Media-Codec, MediaCodec, MMediaCodec, MovieCommander, MPCODEC, My Pass Generator, PCODEC, Perfect Codec, PowerCodec, PornPass Manager, PornMag Pass, PrivateVideo, QualityCodec, Silver Codec, SiteEntry, SiteTicket, SoftCodec, strCodec, Super Codec, TrueCodec, VideoAccess, VideoBox, VidCodecs, Video Access ActiveX Object, Video ActiveX Object, VideoCompressionCodec, VideoKeyCodec, VideosCodec, VirusRay, WinAntiSpyPro, WinMediaCodec, X Password Generator, X Password Manager, ZipCodec... ... ===================================================================== Only for Windows XP and Windows 2000 Hello and welcome to the WhatTheTech Forum's . Use at your own risk: WhatTheTech forum's, does not take responsibility for any outcome of following these directions. Every computer is different, so we cannot guarante the outcome. If you are apprehensive, please post a log from HijackThis in the designated forum and let us take a look and guide you to a clean system. This is a "self help" to remove the infections on Windows 2000 and all XP versions ONLY.If you don't have W2K or XP, please Register and post a HijackThis log for manual removal. Instructions are below. Keep in mind this infection can be accompanied by other infections as well. We strongly suggest you Register after running this fix and posting a HijackThis log for one of the pro's to check over. Please do not delete anything unless instructed to. Download SmitfraudFix (by S!Ri) to your Desktop. http://siri.urz.free.fr/Fix/SmitfraudFix.zip Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop. ![]() ______________________________ Next: Please download Malwarebytes' Anti-Malware to your desktop.
Open the SmitfraudFix folder and double-click smitfraudfix.cmd Select option #1 - Search by typing 1 and press Enter ![]() This program will scan large amounts of files on your computer for known patterns so please be patient while it works. It will create a file named: c:\rapport.txt We suggest you stop at this point and post a HijackThis log along with the contents of the c:\rapport.txt IMPORTANT: Do NOT run any other options until you are asked to do so! Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. Running the Clean Warning: running option #2 on a non infected computer will remove your Desktop background. Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes. Reboot your computer in Safe Mode.
Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool. Select option #2 - Clean by typing 2 and press Enter. Wait for the tool to complete and disk cleanup to finish. You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter. ![]() The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter. A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode. The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply. ______________________________ Clean out your Temporary Internet files. Proceed like this:
Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin. ______________________________ Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware, and run a full scan.
programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess: ______________________________ Open the SmitfraudFix folder and double-click smitfraudfix.cmd Select option #3 - Delete Trusted zone by typing 3 and press Enter Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter. Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection. ______________________________ you need to download HijackThis from here and post your HijackThis log here: Please create a new Topic and post the requested items. Please post: [*]c:\rapport.txt [*]Results from Malwarebytes' Anti-Malware scan [*]A new HijackThis log [/list]Your may need several replies to post the requested logs, otherwise they might get cut off. This post has been edited by LDTate: Jun 8 2008, 06:41 AM |
|
|
|
Sep 23 2006, 10:06 AM
Post
#2
|
|
![]() Forum God Group: Root Admin Posts: 39,097 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Updated Sept.23,2006 to add VirusBurst
|
|
|
|
Oct 14 2006, 08:48 AM
Post
#3
|
|
![]() Forum God Group: Root Admin Posts: 39,097 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Updated to modify Ewido to AVG Anti-Spyware
Oct.14, 2006 |
|
|
|
Dec 21 2006, 08:14 PM
Post
#4
|
|
![]() Forum God Group: Root Admin Posts: 39,097 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Updated to add:
Video ActiveX Object |
|
|
|
Jan 7 2007, 07:55 AM
Post
#5
|
|
![]() Forum God Group: Root Admin Posts: 39,097 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Updated to add:
Generic Zlob |
|
|
|
Mar 21 2007, 05:30 PM
Post
#6
|
|
![]() Forum God Group: Root Admin Posts: 39,097 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Updated to add:
SpyLocked |
|
|
|
May 6 2007, 09:45 AM
Post
#7
|
|
![]() Forum God Group: Root Admin Posts: 39,097 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Updated to add:
PrivateVideo |
|
|
|
Jun 5 2007, 04:52 AM
Post
#8
|
|
![]() Forum God Group: Root Admin Posts: 39,097 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Updated to add:
SPYLOCKED 4.0.EXE SpyLocked 4.1 VideoPlugin PornoPlayer |
|
|
|
Jun 15 2007, 04:41 PM
Post
#9
|
|
![]() Forum God Group: Root Admin Posts: 39,097 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Update to add:
spycrusher |
|
|
|
Jun 23 2007, 08:31 AM
Post
#10
|
|
![]() Forum God Group: Root Admin Posts: 39,097 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Update to add:
Video ActiveX Access |
|
|
|
Jul 7 2007, 06:37 PM
Post
#11
|
|
![]() Forum God Group: Root Admin Posts: 39,097 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Added:
VirusProtectPro |
|
|
|
Aug 13 2007, 05:58 PM
Post
#12
|
|
![]() Forum God Group: Root Admin Posts: 39,097 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Updated to add Ultimate Fixer and Ultimate Defender
|
|
|
|
Sep 1 2007, 07:51 AM
Post
#13
|
|
![]() Forum God Group: Root Admin Posts: 39,097 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
This topic has been left open to allow specific questions and comments related ONLY to this guide. It's NOT for posting HJT logs, links to your logs, or any other general malware help. Replies not following these rules will be deleted. Thanks for your cooperation.
|
|
|
|
Sep 2 2007, 07:10 AM
Post
#14
|
|
![]() Forum God Group: Root Admin Posts: 39,097 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Updated: Sept.02, 2007
This tool removes Desktop Hijack malware: AdwarePunisher, AdwareSheriff, AlphaCleaner, Antispyware Soldier, AntiVermeans, AntiVermins, AntiVerminser, AntivirusGolden, AVGold, BraveSentry, MalwareWipe, MalwareWiped, MalwaresWipeds, MalwareWipePro, MalwareWiper, PestCapture, PestTrap, PSGuard, quicknavigate.com, Registry Cleaner, Security iGuard, Smitfraud, SpyAxe, SpyCrush, SpyDown, SpyFalcon, SpyGuard, SpyHeal, SpyHeals, SpyLocked, SpyMarshal, SpySheriff, SpySoldier, Spyware Vanisher, Spyware Soft Stop, SpywareLocked, SpywareQuake, SpywareKnight, SpywareSheriff, SpywareStrike, Startsearches.net, TitanShield Antispyware, Trust Cleaner, UpdateSearches.com, Virtual Maid, VirusBlast, VirusBurst, Win32.puper, WinHound, Brain Codec, DirectVideo, EliteCodec, eMedia Codec, FreeVideo, Gold Codec, HQ Codec, iCodecPack, iMediaCodec, Image ActiveX Object, IntCodec, iVideoCodec, JPEG Encoder, Key Generator, Media-Codec, MediaCodec, MMediaCodec, MovieCommander, MPCODEC, My Pass Generator, PCODEC, Perfect Codec, PowerCodec, PornPass Manager, PornMag Pass, PrivateVideo, QualityCodec, Silver Codec, SiteEntry, SiteTicket, SoftCodec, strCodec, Super Codec, TrueCodec, VideoAccess, VideoBox, VidCodecs, Video Access ActiveX Object, Video ActiveX Object, VideoCompressionCodec, VideoKeyCodec, VideosCodec, WinAntiSpyPro, WinMediaCodec, X Password Generator, X Password Manager, ZipCodec... |
|
|
|
Sep 5 2007, 04:08 PM
Post
#15
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,037 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
Thanks Larry, thats quite a list, these dirt bags have been busy.
Do I need a new link to the download or will the old one work with all the updates? |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
48 | AplusWebMaster | 831 | Yesterday, 09:48 PM Last post by: AplusWebMaster |
|||
![]() |
17 | sooty4 | 145 | Yesterday, 09:33 PM Last post by: little eagle |
|||
![]() |
3 | fragolla | 45 | Yesterday, 08:00 PM Last post by: BHowett |
|||
![]() |
5 | kimmi8527 | 45 | Yesterday, 01:22 PM Last post by: ken545 |
|||
|
Time is now: 20th November 2008 - 12:49 PM |