Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register Points Site Spy New Posts Donate Unanswered Posts Members Search

>>> Get Paid to Hang Out Here! Activity = Points = Prizes. Want to Know More? <<<

Reply
 
LinkBack Thread Tools
  #1  
Old 15th Aug 2007
No Avatar
donna  United Kingdom
CJ New Member
 
donna is offline
 
Join Date: 15th Aug 2007
Last Online: 15th Aug 2007 08:44 PM
Posts: 3
iTrader: (0)
donna is on a distinguished road
Default not sure what this bug is talks about spyware

HI guys,

I seem to have downloaded something that looks like spyware... its constantly flashing on my bottom toolbar and saying its detected problems on my computer everytime i open something. When i click on the symbol it takes me to: *********************

but thats not all

now whenever i open my web browser i get *********************** even if i change my internet options to another home page such as google or msn its still defaults back to the besecuretoday page. After trying to set up my home page to google.co.uk it also diverts my to the besecuretoday page if i tyoe www.google.co.uk in my address bar, i have to use google.com all the time instead now..and its done the same to msn.

can anyone help me take this off?

Last edited by Dave Hybrid : 15th Aug 2007 at 06:37 PM. Reason: Virus links removed.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #2  
Old 15th Aug 2007
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 2 Hours Ago 06:42 PM
Posts: 4,923
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default not sure what this bug is talks about spyware

Go into add/remove programs and see if anything you know shouldn't be there has been installed that you can un-install.

Please do the following...
Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

Reboot your computer in Safe Mode.
If the computer is running, shut down Windows, and then turn off the power.
Wait 30 seconds, and then turn the computer on.
Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
Ensure that the Safe Mode option is selected.
Press Enter. The computer then begins to start in Safe mode.
Login on your usual account.

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually.
The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

Download HijackThis Here
Once you have it downloaded install/save it to it's own folder!!! This is important for it to work properly.
For example save in C:\program files\hijackthis
You can then create a shortcut on the desktop.
Once installed open the program and select Do a system scan and save logfile.
**Important DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.
Save the log to your desktop.
In the next post click Go Advanced.
Scroll down and click Manage Attachments and add the log as an attachment.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #3  
Old 15th Aug 2007
No Avatar
donna  United Kingdom
CJ New Member
 
donna is offline
 
Join Date: 15th Aug 2007
Last Online: 15th Aug 2007 08:44 PM
Posts: 3
iTrader: (0)
donna is on a distinguished road
Default not sure what this bug is talks about spyware

im sorry for being dim...

ive started my pc in safe mode

ive opened the new folder on my desktop...but there is no options? just a number of files...
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #4  
Old 15th Aug 2007
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 2 Hours Ago 06:42 PM
Posts: 4,923
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default not sure what this bug is talks about spyware

After you have the zip folder on your desktop, Right click on it and select extract or open here.
It should produce one file named SmitfraudFix.
Then go to safe mode and doubleclick the SmitfraudFix folder.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #5  
Old 15th Aug 2007
No Avatar
donna  United Kingdom
CJ New Member
 
donna is offline
 
Join Date: 15th Aug 2007
Last Online: 15th Aug 2007 08:44 PM
Posts: 3
iTrader: (0)
donna is on a distinguished road
Default not sure what this bug is talks about spyware

not quite as dim as i thought i was!! i realised what i had to click and have run the programme.

it seems to have sorted the problem.. my homepage is back to msn again yay!

this is what the txt file said when my comuter restarted:

thanks for your help!!!


SmitFraudFix v2.212
Scan done at 20:19:28.82, 15/08/2007
Run from C:\Documents and Settings\donna\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\SharedTaskScheduler]
"{4a9e875b-d032-45e4-8294-789fe3be5b19}"="atrichia"
[HKEY_CLASSES_ROOT\CLSID\{4a9e875b-d032-45e4-8294-789fe3be5b19}\InProcServer32]
@="C:\WINDOWS\system32\fshqaln.dll"
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4a9e875 b-d032-45e4-8294-789fe3be5b19}\InProcServer32]
@="C:\WINDOWS\system32\fshqaln.dll"

»»»»»»»»»»»»»»»»»»»»»»»» Killing process
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #6  
Old 15th Aug 2007
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 2 Hours Ago 06:42 PM
Posts: 4,923
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default not sure what this bug is talks about spyware

Good job. We need to do a few more steps.

Now run CCleaner. Use the default options.
If you do not have CCleaner please install it. Here
Once CCleaner is open use the default options and click Analyze and it will show a log of what will be removed. Next click Run Cleaner to remove everything.
Next on the upper left of CCleaner select the Issues tab.
Next click Scan For Issues. Next click Fix selected issues.
It will prompt you to make a backup. For the first run I would suggest doing so.

Last. Remove infected restore points.
System Restore
1: Right click on the My Computer icon on your desktop and select properties.
2: Click on the system restore tab.
3: Check the box that says "Turn off system restore on all drives". Click OK.
4: Click Yes when you are prompted to restart the computer
5: To re-enable System Restore, follow steps 1-3, but in step 3, click to clear the Disable System Restore check box.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #7  
Old 15th Aug 2007
Dave Hybrid's Avatar
CJ Administrator
Intel Nvidia
Dave Hybrid is online now
 
Join Date: 18th Apr 2006
Last Online: 7 Minutes Ago 09:11 PM
Age: 26
Posts: 7,514
iTrader: (0)
Dave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond reputeDave Hybrid has a reputation beyond repute
Default not sure what this bug is talks about spyware

Good job EF!

Obviously a dab hand at this stuff.
__________________

Computer Juice raffle
- Win PC hardware of your choice worth £500 / €680 / $1000 - Enter HERE!
__________________

My System: The Hybrid Lappy

CPU(s):
AMD Turion 64 x2 TL-64 2.2GHz
Motherboard:
HP nForce 560
RAM:
2GB DDR2 PC2-5300
Graphics Card(s):
Nvidia 7150M Onboard Integrated
Sound Card:
5.1 Onboard Integrated
Hard Drive(s):
250GB 5400RPM SATA300
Optical Drive(s):
18x CD/DVDRW-DL ATA
Case / PSU:
Stock HP
Cooling:
Stock HP
Network / Internet:
10/100 Nic / 10MB Virgin Cable
Monitor(s):
17" WXGA+ HD BrightView Widescreen
Operating System(s):
Windows Vista Home Premium 32 SP1

Want your system info in your signature?
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #8  
Old 15th Aug 2007
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is offline
Send a message via Yahoo to evilfantasy
 
Join Date: 16th Jul 2007
Last Online: 2 Hours Ago 06:42 PM
Posts: 4,923
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default not sure what this bug is talks about spyware

Sadly I learned mostly from real time experience.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote

Please support this forum, donate towards our running costs.


Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Infected with Spyware Greenhorn Virus, Spyware & Security 4 9th Apr 2008 08:14 PM
Spyware logs Private Baldrick Virus, Spyware & Security 1 2nd Mar 2008 10:58 PM
Spyware Q? Daniels2386 Virus, Spyware & Security 4 11th Jan 2008 11:43 PM
I need a FTP client without spyware! Which... Jacque Web Browsers & FTP Clients 4 19th Mar 2007 03:30 AM


Copyright ©2006 - 2008 Computer Juice - Forums - Free PC Help, IT Support and Repairs.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.

Page copy protected against web site content infringement by Copyscape