View Single Post
Old 08-21-2008, 12:11 AM  
arial
Confirmed User
 
arial's Avatar
 
Join Date: Jul 2002
Location: Bay Area
Posts: 4,012
Quote:
Originally Posted by eroticsexxx View Post
Sounds like your PC has been infected by a Smithfraud variant. I deal with those nasty buggers all the time. Those are tough to get rid of because they embed themselves in system processes. You can remove the core, but a benign process simply copies it back into place when you reboot.

Here's what you do to remove them -

Download the smithfraud fix from here:
http://www.bleepingcomputer.com/files/smitfraudfix.php

Download ATF cleaner from here:
http://www.atribune.org/index.php?op...25&Itemi d=25

Download spybot search and destroy from here:
http://www.safer-networking.org

Fully install the spybot search and destroy program FIRST, downloading all updates.

Boot into safe mode and run the "clean" option (#2) of the Smithfruadfix. It will stop all processes while it does its scan, including explorer, so your taskbar and desktop will disappear. It shuts down everything so that the virus doesn't leave any processes to monitors that the core virus was removed.

When it asks to clean the registry, enter "Y".

This will reset your wallpaper, browser search pages, and other elements that these variants target.

Disk cleanup will be started automatically when the clean is done. If you have a lot of time on your hands, let it run. Otherwise, cancel it and run the ATF cleaner, which is much faster. Clear EVERYTHING using ATF cleaner, then run Spybot Search and destroy to clean up the leftovers that may still be present. You can run a viruscan in safe mode while you're at it for good measure.

Reboot and you will be just fine.
That sounds about right also try Hijack This

http://www.merijn.org/programs.php#hijackthis

What happens is the virus is attached to your windows login, so it cant be deleted sometimes cause its in use. Safe mode may not work. If you are able to delete like you said and it shows back up then there is something installed that will redownload the virus if it is deleted. Run Hijack This then post in their forums and they will help you out.
arial is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote