There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Virus & Other Malware Removal
Tag Cloud
access acer asus bios bsod computer crash dns drive driver drivers error ethernet excel freeze games gaming graphics hard drive hardware hdmi internet java laptop malware memory monitor motherboard network printer problem ram random registry router slow software sound trojan usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Virus & Other Malware Removal >
ATTENTION! HJT log helpers. New canned fix for SpySherrif, Smitfraud & AntivirusGold (New)

Reply  
Thread Tools
Flrman1's Avatar
Distinguished Member with 46,425 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
30-Jun-2005, 11:39 AM #1
ATTENTION! HJT log helpers. New canned fix for SpySherrif, Smitfraud & AntivirusGold
This fix is posted here primarily as a reference for those who are experienced with helping on the forums with these infections. If you are a victim of this infection, It is not recommended that you attempt to fix this on your own. Before you attempt anything, post your Hijack This log in the Security forum and wait for help from one of our experienced helpers.


The following fix provided by noadhfear will work to remove all of these:

AntiVirusGold
Smitfraud
SpySheriff


Note: The smitRem fix will work on 9x systems also, but ewido will only work on XP/2K systems. In noahdfear's original fix he had Adaware included in the fix, but I've found that the smitRem fix and ewido alone work fine. For 9x systems you should use Adaware instead of Ewido.

For XP/2k systems:
Quote:
* Click here to download smitRem.exe.
  • Save the file to your desktop.
  • It is a self extracting file.
  • Doubleclick the smitRem.exe and it will extract the files to a smitRem folder on your desktop.
  • Do not do anything with it yet. You will run the RunThis.bat file later in safe mode.


* Download the trial version of Ewido Security Suite here.
  • Install ewido.
  • During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch ewido
  • It will prompt you to update click the OK button and it will go to the main screen
  • On the left side of the main screen click update
  • Click on Start and let it update.
  • DO NOT run a scan yet. You will do that later in safe mode.


* Click here for info on how to boot to safe mode if you don't already know how.


* Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.


* Restart your computer into safe mode now. Perform the following steps in safe mode:


* Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.


* Run Ewido:
  • Click on scanner
  • Click Complete System Scan and the scan will begin.
  • During the scan it will prompt you to clean files, click OK
  • When the scan is finished, look at the bottom of the screen and click the Save report button.
  • Save the report to your desktop


* Go to Control Panel > Internet Options. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


* Next go to Control Panel > Display. Click on the "Desktop" tab then click the "Customize Desktop" button. Click on the "Web" tab. Under "Web Pages" you should see an entry checked called something like "Security info" or similar.If it is there, select that entry and click the "Delete" button. Click OK then Apply and OK.


* Restart back into Windows normally now.


* Run ActiveScan online virus scan here

When the scan is finished, anything that it cannot clean have it delete it. Make a note of the file location of anything that cannot be deleted so you can delete it yourself.
- Save the results from the scan!

Post a new HiJackThis log along with the results from ActiveScan and the ewido scan
For 98/ME systems:
Quote:
* Click here to download smitRem.exe.
  • Save the file to your desktop.
  • It is a self extracting file.
  • Doubleclick the smitRem.exe and it will extract the files to a smitRem folder on your desktop.
  • Do not do anything with it yet. You will run the RunThis.bat file later in safe mode.



* Go here and download Ad-Aware SE.
  • Install the program and launch it.
  • First in the main window look in the bottom right corner and click on Check for updates now
  • Click Connect and download the latest reference files.
  • Do not run Adaware yet. Just download the updates and have it ready to run later in safe mode.


* Click here for info on how to boot to safe mode if you don't already know how.


* Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.


* Restart your computer into safe mode now. Perform the following steps in safe mode:


* Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.


* Now launch Adaware:
  • From main window click Start then under Select a scan Mode tick Perform full system scan.
  • Next deselect Search for negligible risk entries.
  • Now to scan just click the Next button.
  • When the scan is finished mark everything for removal and get rid of it.
  • Right-click the window and choose select all from the drop down menu and click Next


* Go to Control Panel > Internet Options. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


* Next go to Control Panel > Display. Click on the "Web" tab. Under "View my Active desktop as a web page" you should see an entry checked called something like "Security info" or similar. If it is there, select that entry and click the "Delete" button.
Remove the check by "View my Active desktop as a web page".
Click OK then Apply and OK.


* Restart back into Windows normally now.


* Run ActiveScan online virus scan here

When the scan is finished, anything that it cannot clean have it delete it. Make a note of the file location of anything that cannot be deleted so you can delete it yourself.
- Save the results from the scan!

Post a new HiJackThis log along with the results from ActiveScan
I am attaching my canned fixes for you with all the code tags. Mine is slightly different than the original posted by noadhfear, but not much. Feel free to save it and use it.
Attachment Blocked
Attachments in the HJT forum are often designed to solve a specific issue and not meant to be used without instructions specific to your computer. If you want help specific to your computer, please post a HiJackThis Log. If you started this thread, please make sure you are logged in to be able to view attachments.
__________________
If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site.

Last edited by flrman1; 29-Oct-2005 at 09:30 PM..
Flrman1's Avatar
Distinguished Member with 46,425 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
30-Jun-2005, 12:02 PM #2
I should also mention that if there are other files and HJT entries involved in the log, you will have to add those options to the fix to delete the related files by adding info to download and use Killbox to to delete any other files. Use Killbox or whatever is your preferred method, but I do highly recommend that all of you that help with the logs start using Killbox. It is much easier on the victim that way. They don't have to go through the tedious process of finding all the files. As we all know many of them can't seem to find files that are there anyway.
__________________
If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site.
khazars's Avatar
Malware Removal Specialist with 12,290 posts.
 
Join Date: Feb 2004
Location: Glasgow, Scotland
30-Jun-2005, 01:14 PM #3
ok, cheers for the info, killbox it is!
Thx for the update on 9x, this will be very useful.

Last edited by khazars; 30-Jun-2005 at 08:36 PM.. Reason: more info
Flrman1's Avatar
Distinguished Member with 46,425 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
30-Jun-2005, 01:27 PM #4
I edited the part about removing the Security info page in the Display properties. It should be like so:

* Next go to Control Panel > Display. Click on the "Desktop" tab then click the "Customize Desktop" button. Click on the "Web" tab. Under "Web Pages" you should see an entry checked called something like "Security info" or similar.If it is there, select that entry and click the "Delete" button. Click OK then Apply and OK.

Either change that in your text file if you have already downloaded it or redownload it.
__________________
If I have helped solve your problem, please Click Here and make a donation to help keep this great site running. 100% goes directly to this site.
Cheeseball81's Avatar
Moderator & Malware Removal Specialist with 80,165 posts.
 
Join Date: Mar 2004
Location: Long Island, NY
Experience: Advanced
30-Jun-2005, 01:27 PM #5
I was hoping this would get "Stickied" sooner or later. Great info! Thank you.
Flrman1's Avatar
Distinguished Member with 46,425 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
30-Jun-2005, 04:19 PM #6
Flrman1's Avatar
Distinguished Member with 46,425 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
30-Jun-2005, 07:21 PM #7
Thanks to cybertech for reminding me that ewido only works on xp/2k boxes. The smitrem fix works fine on 9x boxes, but use Adware in combination with it on 9x. I have edited the original post to reflect that and uploaded my canned response for that too.
cybertech's Avatar
Computer Specs
Malware Removal Specialist with 69,217 posts.
 
Join Date: Apr 2002
Location: Washington State
30-Jun-2005, 07:25 PM #8
Thanks Mark, as always nice job!
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,276 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
30-Jun-2005, 07:37 PM #9
Thanks for posting this Mark. Great work, as always!

Thanks for all you do.
Flrman1's Avatar
Distinguished Member with 46,425 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
30-Jun-2005, 09:44 PM #10
You're Welcome guys. Noahdfear did all the work. I'm just a Parrot!
MFDnNC's Avatar
Distinguished Member with 49,021 posts.
 
Join Date: Sep 2004
30-Jun-2005, 09:50 PM #11
Quote:
Originally Posted by flrman1
You're Welcome guys. Noahdfear did all the work. I'm just a Parrot!
Aren't we all !!!!!!!!!!!!!!!!!!!!!!!!
talon03's Avatar
talon03 talon03 is offline   talon03 has a birthday soon! talon03 has a Profile Picture
Computer Specs
Senior Member with 1,024 posts.
 
Join Date: Apr 2005
Location: Newtownards, N. Ireland
Experience: ....................Yeah sure why not.
01-Jul-2005, 08:31 AM #12
Quote:
Originally Posted by MFDnSC
Aren't we all !!!!!!!!!!!!!!!!!!!!!!!!
Nope, I'm an old dog following you guys around trying to learn new tricks!
beardbuster's Avatar
Member with 90 posts.
 
Join Date: Jul 2005
Location: Ohio
Experience: I follow directions to th
02-Jul-2005, 02:16 PM #13
I just wanted to says "THANKS"
That walk thru really rocks and I was able to get back to normal again after becoming infected with SpySheriff
I wanted to add that I have WXP and could not follow the instructions in safe made and had to run all the programs in normal bootup... Not sure if I did anything wrong but I tried and tried and was lucky I was real careful what I deleted without being in safe mode...
again THANKS !!!
Clyde
Flrman1's Avatar
Distinguished Member with 46,425 posts.
 
Join Date: Jul 2002
Location: Thomasville NC
Experience: 100% Geek
02-Jul-2005, 06:15 PM #14
Welcome to TSG beardbuster. Glad you found this useful!
beardbuster's Avatar
Member with 90 posts.
 
Join Date: Jul 2005
Location: Ohio
Experience: I follow directions to th
03-Jul-2005, 09:45 AM #15
THANKS for the flrman1
I'll be sure to let others know about this place
Reply

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 01:50 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.