View Single Post
Old 05-13-2007, 09:08 AM   #11 (permalink)
forhockey
Analyst, Security Team
 
forhockey's Avatar
 
Join Date: Sep 2006
Location: Ontario, Canada
Posts: 2,930
OS: Windows 7 Ultimate


Re: Weird secretive viruses and spyware

Quote:
first of all, the SONIC issue now started happening with my COREL PHOTOALBUM and the same message pops up. I think I should revert back to one of my System Restore points or sooner or later this will happen to all my programs. Should I do this and why is this happening?
Please do not revert back an old system restore point, as all the work we've done will be wasted. I've got a few options I want to tryout, and see if it will resolve your SONIC issue. There could be many possibilites behind the reason for your problems with Sonic... One may be that some essential files got moved or deleted. Also, a part of the program may have become corrupt.

Quote:
Second, in the panda scan, (included in next post) the first item is the smitfraud, however the second item's location was: C:\sUBs\TSF\nircmd.exe
Why is TSF in the name?
The ComboFix program created the folder TSF when it was run. Its a false positive by Panda, and there is nothing to worry about :)

Quote:
third, when i ran pandascan the first time, there was a virus that was detected and disinfected, however the computer was accidentally shut down so the report was never produced. The second time I ran pandascan I was able to complete it thoroughly so even though the virus won't appear in the log it was there and it was disinfected.
Panda provides a free online scan to the users. There are some things the scan will remove, and most of the time it will leave behind the infected files because they want you to purchase their product ;) In your case the file was disinfected from your system, and the panda log you provided appears to be listing false positives.

Quote:
fourth, the gap in my icon tray is still there and won't go away. sometimes a bubble appears over the tray with nothing in it.
I'm going to ask for a screenshot, so that I can see exactly what is going wrong. I'll provide instructions later on in my post on how to do this.

Lets get started!!!




Please save these instructions to Notepad as the internet will not be available to you at certain points of the removal process.
Please ensure that there aren't any opened browsers when you are carrying out the procedures below.
Make sure to work through all the Steps in the exact order in which they are listed below.
If there's anything that you don't understand, ask your question(s) before moving on with the fixes.


---------------------------------------------------------------------------------------------

Please capture a screenshot and attach it in your next reply.

In Windows a screenshot of the entire monitor, complete with taskbar, can be copied to the system clipboard by pressing the Print screen key (normally located in the top row on the right-hand side of the keyboard)..

You can then paste the clipboard into a program like MS Paint to save it as an image file or paste it directly into a document.

1. Press the Print screen key
2. Click the "Start" button (normally located in the bottom left of your screen).
3. Click "Run" & type "mspaint" (without quotes) & click the "OK" button.
4. Wait while the application "Paint" opens. Once it is open, proceed to the next step.
5. Click the "Edit" menu and select "Paste".
6. Click the "File" menu and select "Save As...". A dialog box will appear.
7. In the "File name" field, enter a name of your choice.
8. Click the "Save as type" drop-down and select "JPEG (*.JPG;*.JPEG;*.JPE*;.JFIF)".
9. Click the "Save" button.


Please attach the screenshots to your post. To attach a file to a new post, simply:
  1. Click the[Manage Attachments] button under Additional Options > Attach Files on the post composition page.
  2. Click Browse, and navigate to the place where you saved the picture.
  3. Click Upload.

---------------------------------------------------------------------------------------------

I have attached a file to this post - Silver.zip. Download this file to your desktop.

---------------------------------------------------------------------------------------------

Double click on the Silver.zip folder, then double click on Silver.bat . A black box shall open for a few seconds. Once it disappears you may continue onto the next set of instructions.

---------------------------------------------------------------------------------------------

Enter Safe Mode
  1. Restart your computer
  2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8
  3. Instead of Windows loading as normal, a menu should appear
  4. Use the up arrow key to highlight Safe Mode and press Enter.
  5. Login with your usual account
  6. Once you have logged in, a warning message will appear regarding starting windows in Safe mode, click OK and windows will load your desktop environment

Note: Some systems, this may be the F5 key, so try that if F8 doesn't work.

---------------------------------------------------------------------------------------------

Double-click on SmitfraudFix.exe to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot into Normal Windows.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: (C:\rapport.txt) or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

---------------------------------------------------------------------------------------------

Restart your computer in Normal Mode

---------------------------------------------------------------------------------------------

Double-click on SmitfraudFix.exe to start the tool.
Select option #3 - Delete Trusted zone by typing 3 and press Enter
Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter.

Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.

---------------------------------------------------------------------------------------------





Please download this tool > System Repair Engineer
  1. Extract it to it's own folder & double click SREng.exe to run it

  2. Select 'Smart Scan' & tick "Verify Digital Signatures"

  3. Click on the [Scan] button

  4. When finished, click on the [Save Reports] button & save the log to Desktop

  5. Attach the log in your next reply. Dont post it

Note: You may have to rename SREngLog.log to SREngLog.txt before attaching


Please attach the SRengLog to your post. To attach a file to a new post, simply:
  1. Click the[Manage Attachments] button under Additional Options > Attach Files on the post composition page.
  2. Click Browse, and navigate to the Desktop where you saved it.
  3. Click Upload.

---------------------------------------------------------------------------------------------

How is SONIC behaving now?

---------------------------------------------------------------------------------------------

Please include the following in your next reply:

Screenshot -- Attach
C:\rapport.txt
SRengLog -- Attach
Update on SONIC?
Attached Files
File Type: zip Silver.zip (206 Bytes, 4 views)
__________________


Proud Member of ASAP
Proud Member of UNITE

Keep this forum alive - if you've been helped at this forum, please do consider a donation. Thank you for your support.

Donation link for Tech Support Forum

Last edited by forhockey; 05-13-2007 at 09:10 AM.
forhockey is offline