There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
black screen blue screen boot computer connection crash css dell display driver drivers error excel firefox firefox 3 game hard drive internet internet explorer itunes laptop lcd linux malware monitor network networking nvidia outlook outlook 2003 outlook express partition password printer problem problems ram router slow software sound sprtcmd.exe trojan usb video virus vista windows windows xp wireless
Malware Removal & HijackThis Logs
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Security & Malware Removal > Malware Removal & HijackThis Logs >
ATTENTION! HJT log helpers. New canned fix for SpySherrif, Smitfraud & AntivirusGold


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

Closed Thread
 
Thread Tools
Flrman1's Avatar
Distinguished Member with 46,431 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
30-Jun-2005, 10:39 AM #1
ATTENTION! HJT log helpers. New canned fix for SpySherrif, Smitfraud & AntivirusGold
This fix is posted here primarily as a reference for those who are experienced with helping on the forums with these infections. If you are a victim of this infection, It is not recommended that you attempt to fix this on your own. Before you attempt anything, post your Hijack This log in the Security forum and wait for help from one of our experienced helpers.


The following fix provided by noadhfear will work to remove all of these:

AntiVirusGold
Smitfraud
SpySheriff


Note: The smitRem fix will work on 9x systems also, but ewido will only work on XP/2K systems. In noahdfear's original fix he had Adaware included in the fix, but I've found that the smitRem fix and ewido alone work fine. For 9x systems you should use Adaware instead of Ewido.

For XP/2k systems:
Quote:
* Click here to download smitRem.exe.
  • Save the file to your desktop.
  • It is a self extracting file.
  • Doubleclick the smitRem.exe and it will extract the files to a smitRem folder on your desktop.
  • Do not do anything with it yet. You will run the RunThis.bat file later in safe mode.


* Download the trial version of Ewido Security Suite here.
  • Install ewido.
  • During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch ewido
  • It will prompt you to update click the OK button and it will go to the main screen
  • On the left side of the main screen click update
  • Click on Start and let it update.
  • DO NOT run a scan yet. You will do that later in safe mode.


* Click here for info on how to boot to safe mode if you don't already know how.


* Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.


* Restart your computer into safe mode now. Perform the following steps in safe mode:


* Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.


* Run Ewido:
  • Click on scanner
  • Click Complete System Scan and the scan will begin.
  • During the scan it will prompt you to clean files, click OK
  • When the scan is finished, look at the bottom of the screen and click the Save report button.
  • Save the report to your desktop


* Go to Control Panel > Internet Options. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


* Next go to Control Panel > Display. Click on the "Desktop" tab then click the "Customize Desktop" button. Click on the "Web" tab. Under "Web Pages" you should see an entry checked called something like "Security info" or similar.If it is there, select that entry and click the "Delete" button. Click OK then Apply and OK.


* Restart back into Windows normally now.


* Run ActiveScan online virus scan here

When the scan is finished, anything that it cannot clean have it delete it. Make a note of the file location of anything that cannot be deleted so you can delete it yourself.
- Save the results from the scan!

Post a new HiJackThis log along with the results from ActiveScan and the ewido scan
For 98/ME systems:
Quote:
* Click here to download smitRem.exe.
  • Save the file to your desktop.
  • It is a self extracting file.
  • Doubleclick the smitRem.exe and it will extract the files to a smitRem folder on your desktop.
  • Do not do anything with it yet. You will run the RunThis.bat file later in safe mode.



* Go here and download Ad-Aware SE.
  • Install the program and launch it.
  • First in the main window look in the bottom right corner and click on Check for updates now
  • Click Connect and download the latest reference files.
  • Do not run Adaware yet. Just download the updates and have it ready to run later in safe mode.


* Click here for info on how to boot to safe mode if you don't already know how.


* Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.


* Restart your computer into safe mode now. Perform the following steps in safe mode:


* Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.


* Now launch Adaware:
  • From main window click Start then under Select a scan Mode tick Perform full system scan.
  • Next deselect Search for negligible risk entries.
  • Now to scan just click the Next button.
  • When the scan is finished mark everything for removal and get rid of it.
  • Right-click the window and choose select all from the drop down menu and click Next


* Go to Control Panel > Internet Options. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


* Next go to Control Panel > Display. Click on the "Web" tab. Under "View my Active desktop as a web page" you should see an entry checked called something like "Security info" or similar. If it is there, select that entry and click the "Delete" button.
Remove the check by "View my Active desktop as a web page".
Click OK then Apply and OK.


* Restart back into Windows normally now.


* Run ActiveScan online virus scan here

When the scan is finished, anything that it cannot clean have it delete it. Make a note of the file location of anything that cannot be deleted so you can delete it yourself.
- Save the results from the scan!

Post a new HiJackThis log along with the results from ActiveScan
I am attaching my canned fixes for you with all the code tags. Mine is slightly different than the original posted by noadhfear, but not much. Feel free to save it and use it.
Attached Files
File Type: txt smitRem for 9x.txt (3.0 KB, 369 views)
File Type: txt SmitRem.txt (2.8 KB, 421 views)
__________________
If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site.
_____________________________
Microsoft MVP - Internet Explorer

Last edited by flrman1 : 29-Oct-2005 08:30 PM.
Flrman1's Avatar
Distinguished Member with 46,431 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
30-Jun-2005, 11:02 AM #2
I should also mention that if there are other files and HJT entries involved in the log, you will have to add those options to the fix to delete the related files by adding info to download and use Killbox to to delete any other files. Use Killbox or whatever is your preferred method, but I do highly recommend that all of you that help with the logs start using Killbox. It is much easier on the victim that way. They don't have to go through the tedious process of finding all the files. As we all know many of them can't seem to find files that are there anyway.
__________________
If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site.
_____________________________
Microsoft MVP - Internet Explorer
khazars's Avatar
Distinguished Member with 12,178 posts.
 
Join Date: Feb 2004
Location: Glasgow, Scotland
30-Jun-2005, 12:14 PM #3
ok, cheers for the info, killbox it is!
Thx for the update on 9x, this will be very useful.

Last edited by khazars : 30-Jun-2005 07:36 PM. Reason: more info
Flrman1's Avatar
Distinguished Member with 46,431 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
30-Jun-2005, 12:27 PM #4
I edited the part about removing the Security info page in the Display properties. It should be like so:

* Next go to Control Panel > Display. Click on the "Desktop" tab then click the "Customize Desktop" button. Click on the "Web" tab. Under "Web Pages" you should see an entry checked called something like "Security info" or similar.If it is there, select that entry and click the "Delete" button. Click OK then Apply and OK.

Either change that in your text file if you have already downloaded it or redownload it.
__________________
If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site.
_____________________________
Microsoft MVP - Internet Explorer
Cheeseball81's Avatar
Moderator with 71,713 posts.
 
Join Date: Mar 2004
Location: New York
Experience: Mighty Nerdy
30-Jun-2005, 12:27 PM #5
I was hoping this would get "Stickied" sooner or later. Great info! Thank you.
Flrman1's Avatar
Distinguished Member with 46,431 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
30-Jun-2005, 03:19 PM #6
Flrman1's Avatar
Distinguished Member with 46,431 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
30-Jun-2005, 06:21 PM #7
Thanks to cybertech for reminding me that ewido only works on xp/2k boxes. The smitrem fix works fine on 9x boxes, but use Adware in combination with it on 9x. I have edited the original post to reflect that and uploaded my canned response for that too.
cybertech's Avatar
Computer Specs
Moderator with 59,714 posts.
 
Join Date: Apr 2002
Location: Washington State
30-Jun-2005, 06:25 PM #8
Thanks Mark, as always nice job!
Cookiegal's Avatar
Administrator with 54,885 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
30-Jun-2005, 06:37 PM #9
Thanks for posting this Mark. Great work, as always!

Thanks for all you do.
Flrman1's Avatar
Distinguished Member with 46,431 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
30-Jun-2005, 08:44 PM #10
You're Welcome guys. Noahdfear did all the work. I'm just a Parrot!
MFDnNC's Avatar
Distinguished Member with 49,033 posts.
 
Join Date: Sep 2004
30-Jun-2005, 08:50 PM #11
Quote:
Originally Posted by flrman1
You're Welcome guys. Noahdfear did all the work. I'm just a Parrot!
Aren't we all !!!!!!!!!!!!!!!!!!!!!!!!
talon03's Avatar
Computer Specs
Senior Member with 1,024 posts.
 
Join Date: Apr 2005
Location: Newtownards, N. Ireland
Experience: ....................Yeah sure why not.
01-Jul-2005, 07:31 AM #12
Quote:
Originally Posted by MFDnSC
Aren't we all !!!!!!!!!!!!!!!!!!!!!!!!
Nope, I'm an old dog following you guys around trying to learn new tricks!
beardbuster's Avatar
Member with 82 posts.
 
Join Date: Jul 2005
Location: Ohio
Experience: I follow directions to the "T"
02-Jul-2005, 01:16 PM #13
I just wanted to says "THANKS"
That walk thru really rocks and I was able to get back to normal again after becoming infected with SpySheriff
I wanted to add that I have WXP and could not follow the instructions in safe made and had to run all the programs in normal bootup... Not sure if I did anything wrong but I tried and tried and was lucky I was real careful what I deleted without being in safe mode...
again THANKS !!!
Clyde
Flrman1's Avatar
Distinguished Member with 46,431 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
02-Jul-2005, 05:15 PM #14
Welcome to TSG beardbuster. Glad you found this useful!
beardbuster's Avatar
Member with 82 posts.
 
Join Date: Jul 2005
Location: Ohio
Experience: I follow directions to the "T"
03-Jul-2005, 08:45 AM #15
THANKS for the flrman1
I'll be sure to let others know about this place
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who help people like you solve computer problems. See our Welcome Guide to get started.



Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 10:06 AM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.