Malware I guess

Discussion in 'Malware Help (A Specialist Will Reply)' started by Barnyard Man, Mar 28, 2007.

  1. Barnyard Man

    Barnyard Man Private E-2

    Not sure which it is. Picked it up the other night while not watching what I was doing. I have Norton anti-virus (current addition) and it will not fix it. I have an icon on the bottom right of my screen that is a question mark with a circle around it and it flashes red with a line through it and a message box pops up (system alert) every so often and tells me I have spyware and to click the icon to go to a sight and pay to have it fixed.

    Any ideas on how to fix this? I don't mind buying a product but I want to know it will work. I ran Ad-Aware SE for free but it only fixed 20 problems and not this one.

    Also have System Alert:Trojan-spy.win32@mx that tells me to click the baloon (misspelled but this is the way it is written) to download official security software which I have not done.

    I did a search and because I am not computer literate, I am not able to follow some of the instructions.

    Any help would really be appreciated? This site was highly recommended by a friend.

    Barnyard Man
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    How are things working now?
     
  3. Barnyard Man

    Barnyard Man Private E-2

    A big thank you.

    I was not able to get the link you posted to Smithfraudfix to work, but found another link, downloaded the program and followed your instructions.

    Again, thank you for your help!:) :) :)

    Last log follows:SmitFraudFix v2.162

    Scan done at 15:24:08.34, Sat 03/31/2007
    Run from C:\Documents and Settings\Valued Customer\Desktop\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» hosts


    127.0.0.1 localhost

    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    First log follows:
    SmitFraudFix v2.162

    Scan done at 15:02:00.10, Sat 03/31/2007
    Run from C:\Documents and Settings\Valued Customer\Desktop\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in normal mode

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{9d6fac42-a7be-4702-87ef-75d8dc14249e}"="hemine"

    [HKEY_CLASSES_ROOT\CLSID\{9d6fac42-a7be-4702-87ef-75d8dc14249e}\InProcServer32]
    @="C:\WINDOWS\system32\tahxqcj.dll"

    [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{9d6fac42-a7be-4702-87ef-75d8dc14249e}\InProcServer32]
    @="C:\WINDOWS\system32\tahxqcj.dll"


    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» hosts


    127.0.0.1 localhost

    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It works fine for me! I even just checked it again. Please do not post logs inline. Attach logs as requested. See: HOW TO: Attach Items To Your Post


    Please indicate how things are working.
     
  5. Barnyard Man

    Barnyard Man Private E-2

    Things are working fine.

    Sorry about posting the logs. I am new to this. I cannot find out how to edit my post or I would delete the logs.

    Thanks for your help!!!

    Barnyard Man

    The link you provided would not work on my computer, sorry but tried it several times and had to go to another site to download the program. Nothing against you, but the link would not work. All that ends well is all well!!!!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can delete SmitFraudFix and any files created by running it.
    2. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    3. After doing the above, you should work thru the below link:
     
  7. Barnyard Man

    Barnyard Man Private E-2

    All done Master. Thanks for your help!

    Barnyard Man:wave :wave
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds