Need help - starting page : www.isafetypage.com

Discussion in 'Malware Help (A Specialist Will Reply)' started by Riccardo, Oct 12, 2006.

  1. Riccardo

    Riccardo Private E-2

    Hi, you may be able to help me fix a problem with my computer...The problem : I surfed on the web and some viruses and spyware attacked me.. I used my Norton Internet Security / norton antivirus 2006 and SpySweeper to clean these.. a lot have been deleted but I got some problems again... My homepage is : isafetypage.com and I think I got other spyware in my computer.

    here is my hijackthis scan infos, hope you can help me.
    Please answer me on <remoevd email to stop spam harvesters pickup up your address> if not.. i'll come see on the forum as many time as possible. Thank's!

    EDIT: Removed inline HJT log
     
    Last edited by a moderator: Oct 12, 2006
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome

    While Hijackthis is a good scanner it does not highlight all malware on a PC, and especially as now malware has becoem sneeky and hides itself from a HJT scan unless you have followed the HJT install, re-naming instructions below,

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. Riccardo

    Riccardo Private E-2

    Hi again !
    I did everything you asked me for but I had a little problem with the first online scan not panda but the other one... I tried 2 twice, first time, my computer froze after doing 70% of the job and deleting 37 threats. Second time, the online scan did all my computer but it has frozen at the end without giving me the log file. So I do not have that one.

    After doing all that, my problem is not fixed yet. I always have www.isafetypage.com has homepage and my computer is slowed down. Please help me fix that problem without format guys !
    Hope you can help me,
    Thank's a lot

    Riccardo
     

    Attached Files:

  4. Riccardo

    Riccardo Private E-2

    Here's the last attach file !
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions for using GetRunKey and ShowNew properly as given in the download links. You are not extracting the files from the ZIP file and running .bat files from a Windows Explorer session. You are running them from inside the ZIP files.

    Do this and then attach new logs from both of them.

    Is your copy of SpySweeper a paid version or a free trial version?
     
  6. Riccardo

    Riccardo Private E-2

    I'll do that and post it this afternoon cause i'm not at home for the moment. SpySweeper, I have the full version, the paid one.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then you can uninstall Windows Defender now to avoid conflicts and excess drain on your CPU.
     
  8. Riccardo

    Riccardo Private E-2

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm going to post two messages! This is the first! Complete this procedure completely including attaching the requested log before doing the second procedure.

    Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named
    SmitfraudFix will be created on your Desktop.

    Open the
    SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note:process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm


    IMPORTANT: Do NOT run any other options until you are asked to do so!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is my second message. Make sure you have follow the first procedure before doing the below.

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.

    Now reboot into normal mode and attach this new rapport.txt log here.

    Now attach new logs from:
    - GetRunKey
    - ShowNew
    - HJT
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds