As was foretold, we've added advertisements to the forums! If you have questions, or if you encounter any bugs, please visit this thread: https://forums.penny-arcade.com/discussion/240191/forum-advertisement-faq-and-reports-thread/
Options

Trying to get rid of Virus/Malware

Magus`Magus` The fun has been DOUBLED!Registered User regular
edited April 2007 in Help / Advice Forum
I'm not sure how it got on here, but I got that virus/malware that links you to fake anti-spyware programs.

I'm not dumb, so I haven't downloaded anything and did a virus scan (with NOD32) and used SpyBot and AD-AWARE to search.

They found it (or so I thought) and removed it. I got Task Manager working again and everything seemed ok. The problem is, now whenever I open a file on my computer (no matter what it is) sometimes it'll open to the page that has the fake anti-spyware software.

However, no rogue .exes are running in Task Manager and my programs aren't picking anything up. Have I forgot something?

Magus` on

Posts

  • Options
    SarcastroSarcastro Registered User regular
    edited April 2007
    If this happens while you are not connected to the internet, take the title strings and search for them in the registry. There is enough room in there to hide small files without them nessessarily appearing as rouge file on the hard drive.

    Sarcastro on
  • Options
    Seattle ThreadSeattle Thread Registered User regular
    edited April 2007
    What is the name of the spyware in question? Smitfraud.c?

    Seattle Thread on
    kofz2amsvqm3.png
  • Options
    Magus`Magus` The fun has been DOUBLED! Registered User regular
    edited April 2007
    Uh.. couldn't tell you anymore. All the programs I've ran say my computer is virus/spyware free.

    Whoops.

    Magus` on
  • Options
    Seattle ThreadSeattle Thread Registered User regular
    edited April 2007
    Hmm... that's what it sounds like to me, so it's a guess.

    Try updating all your cleaning tools, re-booting in safe mode (without networking) and scan from there.

    Seattle Thread on
    kofz2amsvqm3.png
  • Options
    Magus`Magus` The fun has been DOUBLED! Registered User regular
    edited April 2007
    Already did that. When it happens again, I'll give more info on the site it loads.

    Magus` on
  • Options
    Seattle ThreadSeattle Thread Registered User regular
    edited April 2007
    If it advertises Spy Sheriff or any of it's pseudonyms (look for the product icon that you can see in the image on that wiki page--that's the main identifier), then it's Smitfraud. You'll need a special tool to remove that--the Bleeping Computer link at the bottom of the wiki page should sort it out.

    Seattle Thread on
    kofz2amsvqm3.png
  • Options
    devoirdevoir Registered User regular
    edited April 2007
    http://www.bleepingcomputer.com/forums/topic17258.html

    That should help if it is smitfraud, which is what it sounds like.

    devoir on
  • Options
    Magus`Magus` The fun has been DOUBLED! Registered User regular
    edited April 2007
    The offending web page:
    hereoi1.jpg

    Magus` on
  • Options
    EchoEcho ski-bap ba-dapModerator mod
    edited April 2007
    Run hijack this and post the log it generates here.

    Echo on
  • Options
    clsCorwinclsCorwin Registered User regular
    edited April 2007
    Yea, I think that was Smitfraud

    clsCorwin on
  • Options
    Magus`Magus` The fun has been DOUBLED! Registered User regular
    edited April 2007
    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 11:15:38 AM, on 4/15/2007
    Platform: Windows Vista (WinNT 6.00.1904)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\Program Files\ESET\nod32kui.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Gaim\gaim.exe
    D:\Firefox Downloads\HiJackThis_v2.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
    O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
    O2 - BHO: msnhlp32.msn_hlp - {1CA00D93-19CA-4E4D-BC88-276E38EE3A83} - C:\Windows\system32\msnhlp32.dll
    O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
    O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
    O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
    O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
    O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~1\Office12\GRA8E1~1.DLL
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
    O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
    O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
    O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/ES-MX/a-UNO1/GAME_UNO1.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9396E837-09D3-403E-897D-C5DE72E1C13F}: NameServer = 24.217.0.5,24.217.0.55
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~1\Office12\GR99D3~1.DLL
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

    --
    End of file - 4394 bytes

    Magus` on
  • Options
    EchoEcho ski-bap ba-dapModerator mod
    edited April 2007
    Magus` wrote: »
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9396E837-09D3-403E-897D-C5DE72E1C13F}: NameServer = 24.217.0.5,24.217.0.55

    This line is highly suspect. I think it changes your name server, letting said server control what pages you actually see.

    edit: googling it doesn't really give me an answer, though.

    edit edit: ok, that's probably a legit DNS.

    Echo on
  • Options
    EchoEcho ski-bap ba-dapModerator mod
    edited April 2007
    All these, however, are remnants from removed spyware that can safely be removed with HijackThis.

    O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
    O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
    O2 - BHO: (no name) - {30000273-8230-4dd4-be4f-6889d1e74167} - (no file)
    O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
    O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
    O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
    O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
    O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
    O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
    O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)

    Echo on
  • Options
    Magus`Magus` The fun has been DOUBLED! Registered User regular
    edited April 2007
    Still having issues. Also, that Smitfraud fix doesn't work in Vista. D:

    Magus` on
Sign In or Register to comment.