This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

TheRock

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

SmitFraudFix v2.132 Scan done at 13:05:30.48, Fri 01/14/12507 Run from C:\PCWolfTech\Protection\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
Incident Status Location Spyware:spyware/smitfraud Not disinfected C:\Documents and Settings\Valued Customer\Desktop\Download Music.url Hacktool:HackTool/Samdump Not disinfected C:\Documents and Settings\Valued Customer\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\RockXP4[1].exe[pwdump2\pwdump2.exe] Hacktool:HackTool/Samdump Not disinfected C:\Documents and Settings\Valued Customer\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\RockXP4[1].exe[pwdump2\samdump.dll] Hacktool:HackTool/RockXp4 Not disinfected C:\Documents and Settings\Valued Customer\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\RockXP4[1].exe[RockXP4_.exe] Potentially unwanted tool:Application/Processor Not disinfected C:\PCWolfTech\Protection\SmitfraudFix\SmitfraudFix\Process.exe Potentially unwanted tool:Application/Processor Not disinfected C:\PCWolfTech\Protection\SmitfraudFix.zip[SmitfraudFix/Process.exe] Spyware:Cookie/360i Not disinfected C:\RECYCLER\S-1-5-21-333382404-492721969-313073093-1003\Dc12\43m0prdy.slt\cookies.txt[.ct.360i.com/]
Incident Status Location Spyware:spyware/smitfraud Not disinfected C:\Documents and Settings\Valued Customer\Desktop\Download Music.url Hacktool:HackTool/Samdump Not disinfected C:\Documents and Settings\Valued Customer\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\RockXP4[1].exe[pwdump2\pwdump2.exe] Hacktool:HackTool/Samdump Not disinfected C:\Documents and Settings\Valued Customer\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\RockXP4[1].exe[pwdump2\samdump.dll] Hacktool:HackTool/RockXp4 Not disinfected C:\Documents and Settings\Valued Customer\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\RockXP4[1].exe[RockXP4_.exe] Potentially unwanted tool:Application/Processor Not disinfected C:\PCWolfTech\Protection\SmitfraudFix\SmitfraudFix\Process.exe Potentially unwanted tool:Application/Processor Not disinfected C:\PCWolfTech\Protection\SmitfraudFix.zip[SmitfraudFix/Process.exe] Spyware:Cookie/360i Not disinfected C:\RECYCLER\S-1-5-21-333382404-492721969-313073093-1003\Dc12\43m0prdy.slt\cookies.txt[.ct.360i.com/]
Download smitRem.exe and save the file to your desktop.
Double click on the file to extract it to it's own folder on the desktop.

Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

Next go to Control Panel click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" if present.

Post a new HijackThis Log, the contents of smitfiles.txt by using Add Reply.
Let us know if any problems persist.
ok … did all you said, still can not generate a HJT log, but things do look better… however, background is now blue, and will not show a picture background even though i have told the pc to do so … it just ignors me! Here is the one log i can get for ya. smitRem © log file version 3.2 by noahdfear Microsoft Windows XP [Version 5.1.2600] "IE"="6.0000" The current date is: Fri 01/14/12507 The current time is: 18:20:43.52 Running from C:\PCWolfTech\Protection\SmitRem\smitRem ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Pre-run SharedTask Export (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright© 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\System32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\System32\browseui.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Appinitdll check …….. Thank you Grinler! dumphive.exe ©2000-2004 Markus Stephany REGEDIT4 [Windows] "AppInit_DLLs"="" "DeviceNotSelectedTimeout"="15" "GDIProcessHandleQuota"=dword:00002710 "Spooler"="yes" "swapdisk"="" "TransmissionRetryTimeout"="90" "USERProcessHandleQuota"=dword:00002710 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ XP Firewall allowed access Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL" "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL" "C:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe:*:Enabled:AOL TopSpeed" "C:\\Program Files\\Common Files\\AOL\\1129766971\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1129766971\\ee\\aolsoftware.exe:*:Enabled:AOL Services" "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader" "C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:AOL" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ checking for ShudderLTD key ShudderLTD key present! Running LTDFix/PSGuard.com fix! checking for PSGuard.com key PSGuard.com key present! ShudderLTD key was successfully removed! :) if previously present, PSGuard.com key was successfully removed! :) checking for WinHound.com key WinHound.com key not present! checking for drsmartload2 key drsmartload2 key not present! spyaxe uninstaller NOT present Winhound uninstaller NOT present SpywareStrike uninstaller NOT present AlfaCleaner uninstaller NOT present SpyFalcon uninstaller NOT present SpywareQuake uninstaller NOT present SpywareSheriff uninstaller NOT present Trust Cleaner uninstaller NOT present SpyHeal uninstaller NOT present VirusBurst uninstaller NOT present BraveSentry uninstaller NOT present AntiVermins uninstaller NOT present VirusBursters uninstaller NOT present ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Existing Pre-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ amcompat.tlb nscompat.tlb ~~~ Icons in System32 ~~~ ptainfo1 ptainfo2 ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 Copyright© 2002-2003 [removed] Killing PID 1300 'explorer.exe' Killing PID 1300 'explorer.exe' Killing PID 1300 'explorer.exe' Killing PID 1300 'explorer.exe' Killing PID 1300 'explorer.exe' Killing PID 1300 'explorer.exe' Killing PID 1300 'explorer.exe' Starting registry repairs Registry repairs complete ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SharedTask Export after registry fix (GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler) Copyright© 2006 BleepingComputer.com Registry Pseudo-Format Mode (Not a valid reg file): [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32] @="%SystemRoot%\System32\browseui.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32] @="%SystemRoot%\System32\browseui.dll" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Deleting files ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Remaining Post-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~ Wininet.dll ~~~ CLEAN! :)
While in chat, that pc locked up, lost use of keyboard and mouse. Shutdown the pc, and restarted. Still no keyboard or mouse… tried one more time, now when we try to start it we get a blank monitor, no post nothing… we dont see a thing, and after a short while the monitor gos into is powersaveing standby mode… now what ? checked the monitor on a differant pc just to be sure it was not the monitor, the monitor worked fine. Can not boot to a live boot disk, because we get nothing on the monitor and it apears as if the cdrom is nto spinning, … no lights.
Right Click the Desktop and Select New–> Folder–> Name it SysClean
  • Download the Sysclean Package to the folder you made.
  • Next,download the Virus Pattern Files (Official Pattern Release) to your desktop from Here
  • Right Click and Select Extract All to unzip the folder.
  • Now,from the unzipped folder,move lpt$vpn.XXX file to the SysClean folder.
  • Restart in SAFE MODE(Tap F8 when restarting)
  • Open the SysClean Folder and doubleclick sysclean.com
  • Be sure Automatically clean or delete detected files is checked.
  • Click the Scan button to begin,please be patient,it will take a little bit to finish.
  • Once complete,verify the log from the scan (SYSCLEAN.LOG) is in the SysClean folder and restart back to Normal Mode.
  • Copy&Paste those results in the next reply.
Tutorial from Trend
http://esupport.trendmicro.com/support/vie…entID=en-125991

Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
I need the following logs…

1.SYSCLEAN.LOG
2.DrWeb.csv
Sysclean generated this report, the other drwatever, would not run at all … systematic of the problem we ahve been talking about.

/————————————————————–\
| Trend Micro System Cleaner |
| Copyright 2006, Trend Micro, Inc. |
| http://www.antivirus.com |
\————————————————————–/


12507-01-14, 20:32:20, Auto-clean mode specified.
12507-01-14, 20:32:20, Running scanner "C:\PCWolfTech\Utilities\SysClean\TSC.BIN"…
12507-01-14, 20:32:31, Scanner "C:\PCWolfTech\Utilities\SysClean\TSC.BIN" has finished running.
12507-01-14, 20:32:31, TSC Log:

12507-01-14, 20:33:21, An error was detected on "C:\System Volume Information\*.*": Access is denied.
12507-01-14, 21:17:41, Files Detected:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 3/6/2027 02:17:27
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 177 (150076 Patterns) (2007/01/11) (417700)
Command Line: C:\PCWolfTech\Utilities\SysClean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\PCWolfTech\Utilities\SysClean

43537 files have been read.
43537 files have been checked.
40951 files have been scanned.
72179 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 3/6/2027 03:01:09
———*———*———*———*———*———*———*———*
12507-01-14, 21:17:41, Files Clean:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 3/6/2027 02:17:27
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 177 (150076 Patterns) (2007/01/11) (417700)
Command Line: C:\PCWolfTech\Utilities\SysClean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\PCWolfTech\Utilities\SysClean

43537 files have been read.
43537 files have been checked.
40951 files have been scanned.
72179 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 3/6/2027 03:01:09 43 minutes 33 seconds (2612.48 seconds) has elapsed.

———*———*———*———*———*———*———*———*
12507-01-14, 21:17:41, Clean Fail:
Copyright © 1990 - 2004 Trend Micro Inc.
Report Date : 3/6/2027 02:17:27
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 177 (150076 Patterns) (2007/01/11) (417700)
Command Line: C:\PCWolfTech\Utilities\SysClean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\PCWolfTech\Utilities\SysClean

43537 files have been read.
43537 files have been checked.
40951 files have been scanned.
72179 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 3/6/2027 03:01:09 43 minutes 33 seconds (2612.48 seconds) has elapsed.

———*———*———*———*———*———*———*———*
12507-01-14, 21:17:41, Scanner "C:\PCWolfTech\Utilities\SysClean\VSCANTM.BIN" has finished running.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI