This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Problem with Spyware

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OK, looks like we've just got a little housekeeping to do now.

Please delete the following, you won't need them any more.

Smitfraudfix
Sysclean


Smitfraudfix is updated regularly, so the version you have now will not be of use against future infections, and Sysclean is too unwieldy to use for regular scans.

ATF Cleaner and Malwarebytes' Anti-Malware are both freeware and you can keep them or discard them as you wish.

ATF cleaner is a useful little utility for cleaning out your temp files easily, but if you don't want it just delete it.

Malwarebytes Anti-Malware probably has one of the quickest scanners I've seen, but if you don't want it uninstall it using Control Panel > Add/Remove Programs

As far as I can see, your computer looks clear of infection now.

Are you still noticing any problems ?
  • If you are let me know about them.
  • If not it's time to make your computer more secure.
Below are a series of recommendations which will help you keep more secure online.

Obviously you have already taken care of some of the issues mentioned, but it is important that you read through them, and address any that you may have missed.

THESE STEPS ARE VERY IMPORTANT

Lets reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to clean the restore points.
  • Turn off System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • Check Turn off System Restore.
    • Click Apply, and then click OK.
  • Reboot.
  • Turn ON System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • UN-Check *Turn off System Restore*.
    • Click Apply, and then click OK.
  • NOTE: only do this once, NOT on a regular basis.

Updating Windows and Internet Explorer
It is essential you keep your Operating System up to date with all the latest patches. The bad guys watch for the latest exploits, as soon as Microsoft brings out a patch, the bad guys will bring out an infection to exploit that vulnerability. If you don't have all the latest patches your computer is vulnerable. Please go to the windows update site and get the critical updates.

Use a "secure" browser
Install Internet Explorer 7 or an alternative browser like Firefox or Opera for more secure surfing.
Please remember that there is no such thing as a totally secure browser. Your browsing habits will be the major factor in determining just how safe you are online. If you visit, Crack/Warez sites, Porn sites, or other sites of a questionable nature, you still run a severe risk of getting infected.

The following are free programs that are designed to keep your computer clean. A brief description is included with each item, click on name to go to download site.

  • Spybot S & D
    Spybot is a scanner. It scans for spyware and other malicious programs. It is important to have at least one malware scanner on your computer. Spybot has preventitive tools that stop programs from even installing on your computer.
    To see how to set this up as well as more spybot features, see here
  • WinPatrol by BillPStudios is a programme that monitors your computer and notifies you if there are any unauthorised changes made to it. It gives you the option to allow or forbid the changes, thus guarding you against Malware installations. I consider this one a must have.

    If you find you like it, you can get a lifetime upgrade to the Plus version for a small one time fee.
  • SpywareBlaster
    Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes "kill bits" in the registry, so that certain activex controls can't install.
    If you don't know what activex controls are, see here
  • IE Spyad
    It puts many bad webpages on your restricted zones LIST. This means that you can still view the "bad" webpages, but the webpages can't do certain things (such as use javascripts and cookies). Use IE Spyad for single account computers, and IE Spyad 2 for multi account computers.
  • Hosts file:
  • Make sure you read the instructions on how to install the hosts file, here.

    • Every version of windows has a hosts file as part of them.
    • In a very basic sense, they are used to locate webpages.
    • We can customize a hosts file so that it blocks certain webpages.
    • However, it can slow down certain computers.
  • If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    • Click the start button (at the lower left hand corner of your screen)
    • Click run
    • In the dialog box, type services.msc
    • hit enter, then locate dns client
    • Highlight it, then double-click it.
    • On the dropdown box, change the setting from automatic to manual.
    • Click ok
  • Use an Anti Virus Software - It's very important that your computer has an anti-virus software running. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
    Computer Safety On line - LIST of free Anti virus programs
  • Use a Firewall - I cannot stress enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.
    See here to choose one.
  • Site Advisor This is a utility that can be downloaded and installed. It loads an icon to the taskbar of your browser (versions for IE and Firefox), indicating the trustworthiness of the site you are on. Green for safe, Red for suspicious. Click on the icon to access details that SiteAdvisor has about the site.

Here's links to a few articles which are well worth reading

Finally

NOW is the time you can start to hit back at the people who infected you.
[external image: Posted Image]
Please take the time to go and complain - that forum has a topic for your infection which is Smitfraud……….. (if not, post in the Is your infection not listed here? topic). Please post as a reply, you do not need to register to do so (but you can if you wish). It will also have a list of other places you can go to to register your complaint, depending on the country you are resident in. Please read the topics and complain, it is only with such complaints to government or government agencies that something will get done.

Good evening Gary, I ran a scan utilizing AntiVir and it detected 12 viruses. Whenever attempting to delete any of these twelve files, the following error message would appear: The file could not be marked for deleting after reboot. Error description: Access is denied. Nine of the twelve files were able to be moved to quarantine. Please review the log below from AntiVir. Please advise on how to proceed next. Thank you. AntiVir PersonalEdition Classic Report file date: Saturday, February 23, 2008 16:38 Scanning for 1119284 virus strains and unwanted programs. Licensed to: Avira AntiVir PersonalEdition Classic Serial number: 0000149996-ADJIE-0001 Platform: Windows XP Windows version: (Service Pack 2) [5.1.2600] Username: SYSTEM Computer name: KATHY Version information: BUILD.DAT : 270 15603 Bytes 9/19/2007 13:32:00 AVSCAN.EXE : 7.0.6.1 290856 Bytes 8/23/2007 20:16:29 AVSCAN.DLL : 7.0.6.0 49192 Bytes 8/16/2007 19:23:51 LUKE.DLL : 7.0.5.3 147496 Bytes 8/14/2007 22:32:47 LUKERES.DLL : 7.0.6.1 10280 Bytes 8/21/2007 19:35:20 ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 7/18/2007 21:27:15 ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 12/14/2007 05:57:04 ANTIVIR2.VDF : 7.0.2.113 1673728 Bytes 2/8/2008 05:57:04 ANTIVIR3.VDF : 7.0.2.175 319488 Bytes 2/21/2008 02:29:14 AVEWIN32.DLL : 7.6.0.67 3293696 Bytes 2/21/2008 05:57:10 AVWINLL.DLL : 1.0.0.7 14376 Bytes 2/26/2007 17:36:26 AVPREF.DLL : 7.0.2.2 25640 Bytes 7/18/2007 14:39:17 AVREP.DLL : 7.0.0.1 155688 Bytes 4/16/2007 20:16:24 AVPACK32.DLL : 7.6.0.3 360488 Bytes 2/21/2008 05:57:10 AVREG.DLL : 7.0.1.6 30760 Bytes 7/18/2007 14:17:06 AVARKT.DLL : 1.0.0.20 278568 Bytes 8/28/2007 19:26:33 AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 7/18/2007 14:10:18 NETNT.DLL : 7.0.0.0 7720 Bytes 3/8/2007 18:09:42 RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 8/7/2007 19:38:13 RCTEXT.DLL : 7.0.62.0 86056 Bytes 8/21/2007 19:50:37 SQLITE3.DLL : 3.3.17.1 339968 Bytes 7/23/2007 16:37:21 Configuration settings for the scan: Jobname……………………..: Complete system scan Configuration file……………: c:\program files\avira\antivir personaledition classic\sysscan.avp Logging……………………..: low Primary action……………….: interactive Secondary action……………..: ignore Scan master boot sector……….: off Scan boot sector……………..: on Boot sectors…………………: C:, Scan memory………………….: on Process scan…………………: on Scan registry………………..: on Search for rootkits…………..: off Scan all files……………….: Intelligent file selection Scan archives………………..: on Recursion depth………………: 20 Smart extensions……………..: on Macro heuristic………………: on File heuristic……………….: medium Start of the scan: Saturday, February 23, 2008 16:38 The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'qw.exe' - '1' Module(s) have been scanned Scan process 'ycommon.exe' - '1' Module(s) have been scanned Scan process 'wuauclt.exe' - '1' Module(s) have been scanned Scan process 'wkcalrem.exe' - '1' Module(s) have been scanned Scan process 'dlbkbmon.exe' - '1' Module(s) have been scanned Scan process 'ctfmon.exe' - '1' Module(s) have been scanned Scan process 'cfp.exe' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'ybrwicon.exe' - '1' Module(s) have been scanned Scan process 'dlbkbmgr.exe' - '1' Module(s) have been scanned Scan process 'tp4mon.exe' - '1' Module(s) have been scanned Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'wkcalrem.exe' - '1' Module(s) have been scanned Scan process 'ctfmon.exe' - '1' Module(s) have been scanned Scan process 'cfp.exe' - '1' Module(s) have been scanned Scan process 'ycommon.exe' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'dlbkbmon.exe' - '1' Module(s) have been scanned Scan process 'ybrwicon.exe' - '1' Module(s) have been scanned Scan process 'CFD.exe' - '1' Module(s) have been scanned Scan process 'dlbkbmgr.exe' - '1' Module(s) have been scanned Scan process 'tp4mon.exe' - '1' Module(s) have been scanned Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'alg.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'MDM.EXE' - '1' Module(s) have been scanned Scan process 'cmdagent.exe' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'avguard.exe' - '1' Module(s) have been scanned Scan process 'LEXPPS.EXE' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'LEXBCES.EXE' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'ibmpmsvc.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 47 processes with 47 modules were scanned Start scanning boot sectors: Boot sector 'C:\' [NOTE] No virus was found! Starting to scan the registry. The registry was scanned ( '23' files ). Starting the file scan: Begin scan in 'C:\' C:\pagefile.sys [WARNING] The file could not be opened! C:\System Volume Information\_restore{3BA812C2-6591-45AA-AB03-D2AA30536DB4}\RP70\A0020309.dll [DETECTION] Is the Trojan horse TR/Downloader.Gen [WARNING] An error has occurred and the file was not deleted. ErrorID: 16003 [WARNING] The file could not be deleted! C:\System Volume Information\_restore{3BA812C2-6591-45AA-AB03-D2AA30536DB4}\RP71\A0021309.exe [DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen [WARNING] An error has occurred and the file was not deleted. ErrorID: 16003 [WARNING] The file could not be deleted! C:\System Volume Information\_restore{3BA812C2-6591-45AA-AB03-D2AA30536DB4}\RP71\A0021310.dll [DETECTION] Is the Trojan horse TR/Vundo.Gen [WARNING] An error has occurred and the file was not deleted. ErrorID: 16003 [WARNING] The file could not be deleted! C:\System Volume Information\_restore{3BA812C2-6591-45AA-AB03-D2AA30536DB4}\RP71\A0021311.dll [DETECTION] Is the Trojan horse TR/Vundo.Gen [INFO] The file was moved to '47f0b553.qua'! C:\System Volume Information\_restore{3BA812C2-6591-45AA-AB03-D2AA30536DB4}\RP71\A0021312.dll [DETECTION] Is the Trojan horse TR/PSW.Delf.aox.4 [INFO] The file was moved to '47f0b563.qua'! C:\System Volume Information\_restore{3BA812C2-6591-45AA-AB03-D2AA30536DB4}\RP71\A0021313.dll [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen [INFO] The file was moved to '47f0b59b.qua'! C:\System Volume Information\_restore{3BA812C2-6591-45AA-AB03-D2AA30536DB4}\RP71\A0021314.dll [DETECTION] Is the Trojan horse TR/Rootkit.Gen [INFO] The file was moved to '47f0b5e3.qua'! C:\System Volume Information\_restore{3BA812C2-6591-45AA-AB03-D2AA30536DB4}\RP71\A0021315.exe [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen [INFO] The file was moved to '47f0b611.qua'! C:\System Volume Information\_restore{3BA812C2-6591-45AA-AB03-D2AA30536DB4}\RP71\A0021316.exe [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen [INFO] The file was moved to '47f0b637.qua'! C:\System Volume Information\_restore{3BA812C2-6591-45AA-AB03-D2AA30536DB4}\RP71\A0021342.dll [DETECTION] Is the Trojan horse TR/Crypt.FKM.Gen [INFO] The file was moved to '47f0b655.qua'! C:\System Volume Information\_restore{3BA812C2-6591-45AA-AB03-D2AA30536DB4}\RP71\A0021503.exe [DETECTION] Is the Trojan horse TR/Spy.43391 [INFO] The file was moved to '47f0b684.qua'! C:\System Volume Information\_restore{3BA812C2-6591-45AA-AB03-D2AA30536DB4}\RP72\A0021662.exe [DETECTION] Is the Trojan horse TR/Spy.43391 [INFO] The file was moved to '47f0b6b6.qua'! End of the scan: Saturday, February 23, 2008 18:27 Used time: 1:49:08 min The scan has been done completely. 2398 Scanning directories 199585 Files were scanned 12 viruses and/or unwanted programs were found 0 Files were classified as suspicious: 0 files were deleted 0 files were repaired 9 files were moved to quarantine 0 files were renamed 1 Files cannot be scanned 199573 Files not concerned 894 Archives were scanned 4 Warnings 0 Notes
The files found are your System Restore files which are infected, did you follow the instructions in my closing speech for re-setting your System Restore points? If you had they should have been deleted.

System Restore files are specially protected, and that is the only way to clean them. You cannot be re-infected by them if you did not clean them out unless you do a System Restore, but you should clean them out, otherwise programmes like Anti-Vir will keep flagging them.

I'll repeat the instructions just in case you missed them.

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to clean the restore points (XP accounts are Administrator by default).
  • Turn off System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • Check Turn off System Restore.
    • Click Apply, and then click OK.
  • Reboot.
  • Turn ON System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • UN-Check *Turn off System Restore*.
    • Click Apply, and then click OK.
  • NOTE: only do this once, NOT on a regular basis.

Let me know if Anti-Vir is still flagging them after you've flushed your restore points.
Good afternoon Gary, Sorry, I hadn't replied before now, I have been sick for the past three days. I completed the steps outlined above, ran a new AntiVir scan, and no files were flagged. Thank you very much for all of your advice. I appreciate all your efforts and patience in helping to restore my computer.
Sorry to hear about your illness, hope you're feeling better now. Glad we were able to help you with your computer problems. Keep safe (and well :) ) Gary
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI