View Single Post
Old 12-05-2007, 08:27 PM   #5 (permalink)
forhockey
Analyst, Security Team
 
forhockey's Avatar
 
Join Date: Sep 2006
Location: Ontario, Canada
Posts: 2,931
OS: Windows 7 Ultimate


Re: Various Trojan horses, viruses and malware

Hi Hobee,

Please copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.

Also be sure to carry out the instructions in the sequence listed below.

--------------------------------------------------------------

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to C:\SDFix

DO NOT run SDFix yet. We will shortly

--------------------------------------------------------------

Update AVG Anti-Spyware

I see you have AVG Anti-Spyware already. Please update it's definitions, and run a scan where I have placed it in this fix.

Run AVG Anti-Spyware
  • From the main screen, click on update, then click the Start
    update
    button.
  • After the update finishes (the status bar at the bottom will display "Update
    successful")
  • select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
  • Select "Do Not Automatically generate report after every scan"
  • Un-Select "Only if threats were found"
  • Exit AVG Anti-Spyware. DO NOT scan yet.

--------------------------------------------------------------
  • Restart your computer in Safe Mode
    • After hearing your computer beep once during startup, but before the Windows icon appears, press F8
    • Instead of Windows loading as normal, a menu should appear
    • Use the up arrow key to highlight Safe Mode and press Enter.
    • Login with your usual account
    • Once you have logged in, a warning message will appear regarding starting windows in Safe mode, click OK and windows will load your desktop environment

    Note: Some systems, this may be the F5 key, so try that if F8 doesn't work.

  • Double-click on SmitfraudFix.exe to start the tool.

  • Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.

  • You will be prompted : "Registry cleaning - Do you want to clean the registry?" answer Yes by typing Y and hit Enter.
    The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot into Safe Mode.

  • The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: (C:\rapport.txt) or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

    --------------------------------------------------------------

    Run SDFix
    • Open the extracted SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    • Paste the contents of the Report.txt back on the forum

    --------------------------------------------------------------

    Run AVG Anti-Spyware

    Run AVG Anti-Spyware with it's updated definitions:(...it's important that all windows must be closed)
    • Click Scanner
    • Click on the Scan tab
    • Click Complete System Scan to begin scanning.
      Once the scan is complete do the following:
    • If you have any infections you will prompted, then select "Apply all actions"
    • Once finished, click the Save report button, then click Save Report As and save it to your desktop. (make sure to remember where you saved that file, this is important).

    --------------------------------------------------------------
  • Next, go to Control Panel click Display>Desktop>Customize Desktop>Web> Now, Uncheck Everything and delete if present:
    · "Security Info"
    · "Warning Message"
    · "Security Desktop"
    · "Warning Homepage"
    · "Desktop Uninstall"


    Also make sure the 'Lock desktop items' box is unticked. Click OK, and then Click Apply, then OK.

  • Restart your computer in Normal Mode

--------------------------------------------------------------
  1. Double-click on SmitfraudFix.exe to start the tool.

  2. Select option #3 - Delete Trusted zone by typing 3 and press Enter

  3. Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter.

    Note: if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.

--------------------------------------------------------------

Please reply back with the following logs:

C:\rapport.txt (From SmitFraudFix)
C:\SDFix\report.txt (From SDFix)
AVG Anti-Spyware Scan Results
__________________


Proud Member of ASAP
Proud Member of UNITE

Keep this forum alive - if you've been helped at this forum, please do consider a donation. Thank you for your support.

Donation link for Tech Support Forum
forhockey is offline