Isara - Where You Make a Difference
Home Projects Forum Games
News HQ IsaraPIX IsaraBLOG About Us
      

11/21/2008 06:04 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Make a Difference by using Isara's Guilt-free Shopping for all your Amazon shopping.
 
   Home Forum   Arcade   Calendar  
  Help Search Register  

Pages: [1]
  Add bookmark  |  Print  
Author Topic: Smitfraud Trojan... maybe an adware.  (Read 600 times)
elcangry3512 Offline
Isara Do-Gooder
Joined: 07/23/07
Posts:72
Referrals: 0

View Profile WWW
« on: 02/ 6/2008 07:51 PM »

So, earlier today, at about 5pm, I'm done printing out something for school, and suddenly, an IE window comes up. I never called on it or anything, it just appeared out of nowhere. When I go see, if asks me if I want do download an Ultimate Protection program or something, but I'm not stupid, I know what these things are. So, it appeared every 30 minutes or so, and I just closed and canceled everything. I ran AVG Anti-Spyware, and only found one thing, but it wasn't it. I then ran a thorough scan with Avast! Antivirus Home Edition, and it's still scanning. The page hasn't appeared for a while, but something still doesn't let me access the Task Manager. It says that "the administrator disabled the Task Manager".

I think it's those viruses I "cleaned off" from a friend of mine's USB stick, which I had moved to the Virus Chest, and deleted earlier. Not sure what I should be asking for right now, but any kind of help would be great.

Thanks in advance.
Logged

ZeroG Offline
Forum Moderator
Isara Superhero
Joined: 02/28/06
Posts:1,219
Referrals: 4

View Profile WWW
« Reply #1 on: 02/ 6/2008 08:34 PM »

I had this happen on a friends computer. I googled for the message, and
the instructions for turning the Task manager back on is here:

http://answers.yahoo.com/...qid=20080121112855AAUuIZj

Logged


For as he thinketh in his heart, so is he... -Proverbs 23:7
Hunter Offline
Isara Hero
Joined: 08/03/06
Posts:819
Referrals: 0

View Profile
« Reply #2 on: 02/ 6/2008 08:41 PM »

I would honestly need more information to give an accurate and thorough remedy.
1) your operating system
2) Number of users on the computer
3) Exact name of the product being presented or name of virus/adware if you know it.
4) when you began to notice the problem

For a more general solution, I would start by scanning your computer with spybot. That's my personal favorite. You can find it here.

The problem is that this won't get rid of your problem, if this is the situation I think it may be. Now, I wouldn't normally advise this, and people can scream if they really want, but if you're running windows XP or Vista or Mac OS X 10.5 you can either use System Restore or Time Machine, respectively, to "backtrack" your computer to a few days before you contracted this "issue."
Two problems, this doesn't always work, though it ususally will, and if you have to go with removal, you'll have to do it manually.

In order to remove spyware and viruses ( I still like "viri") manually you'll have to isolate the specific processes running in relation to them and physically erase them. I would recommend Eraser.

Hope this helps. More information could mean a better solution. BTW, if you want to try the restore point, type restore point wizard in windows help. One more word of caution, by loading a restore point, you will effectively be removing all install information done after the date the restore point was created. This can be a serious issue if you don't know what you're doing.

Hunter.
 
EDIT: Good call on that ZeroG, forgot to cover that part.
Logged

"God gave us memories, so that we might have roses in December" - J. M. Barrie.
?Cry 'Havoc', and let slip the dogs of war..." - William Shakespeare
elcangry3512 Offline
Isara Do-Gooder
Joined: 07/23/07
Posts:72
Referrals: 0

View Profile WWW
« Reply #3 on: 02/ 7/2008 01:12 PM »

1) Windows XP Home Edition
2) Just one.
3) Don't remember the name of the Worm. I ran Avast! Antivirus, and it didn't find anything.
4) Yesterday, at about 5 to 6 PM.

I have Spybot, as well. I just use AVG Anti-Spyware as my main spyware program.

System Restore needs to have a Restore Point already in, right? Been a while since I last did that. Don't think I have one since my dad last re-formatted this PC.

EDIT:

I think this may be the cause:



Should I "Purge" them now?
Logged

Hunter Offline
Isara Hero
Joined: 08/03/06
Posts:819
Referrals: 0

View Profile
« Reply #4 on: 02/ 7/2008 06:17 PM »

Should I "Purge" them now?
For the love of all - YES!! Smiley Please.
Smitfraud is probably (read "is") your issue. For more in depth details on removal, please read this.

@Mods - do you think we should change this to something relating to the Smitfraud spyware/trojan?
Logged

"God gave us memories, so that we might have roses in December" - J. M. Barrie.
?Cry 'Havoc', and let slip the dogs of war..." - William Shakespeare
elcangry3512 Offline
Isara Do-Gooder
Joined: 07/23/07
Posts:72
Referrals: 0

View Profile WWW
« Reply #5 on: 02/ 7/2008 08:13 PM »

Alright, thanks for everything. Haven't had any problems lately.
Logged

Hunter Offline
Isara Hero
Joined: 08/03/06
Posts:819
Referrals: 0

View Profile
« Reply #6 on: 02/ 8/2008 08:09 AM »

Always glad to help. On another note, the new spybot S&D can help prevent these occurances because it has a registry shield built in. This means that malware that can infect your registry or even basic changes to your registry will have to be validate by you before they can become effective. This also means that one less beachhead in your system is available for viruses, malware, and spyware. This is a resident scanner, which means it's always on and scanning. Also means you have to worry less. Now if only they'd make an antivirus for humans.
Logged

"God gave us memories, so that we might have roses in December" - J. M. Barrie.
?Cry 'Havoc', and let slip the dogs of war..." - William Shakespeare
Pages: [1]
  Add bookmark  |  Print  
 
Jump to:  

TinyPortal v1.0.5 beta 1© Bloc

Isara Forum Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC
About Isara | Charity Projects | Isara Videos | FAQ | Link to Isara | Tell Others | Contact Isara
Isara.org
© 2005-2008 Isara.org. All Rights Reserved. Privacy Policy.