afterdawn.com  > forums  > software, operating systems and more  > windows - virus and spyware problems  > theguardservices.com home page hijack + taskbar spyware  
											
												
	
	
						 				 	
	
	
	
		
			
			
			
				
			
		 
	
												 
															
															
	
			
			
				
					theguardservices.com home page hijack + taskbar spyware
				 
				
				
					
				 
				
			 
			
			
			
				
					
					
				 
			
			
			
			
			
				
				
					
				
				
				
				
					
						
							
								chadbrand
							
							
								Newbie
								
									
								
							
							 
						2. May 2006 @ 13:13 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Any help is greatly appreciated!!!
http://download.games.yahoo.com/games/clients/y/et1_x.cab http://aud12.sports.sc5.yahoo.com/java/y/mlbst8408_x.cab http://85.255.113.214/1/gdnUS2218.exe http://85.255.113.214/1/gdnUS2218.exe http://ak.imgfarm.com/images/nocache/funwebproducts/SmileyCentral... http://85.255.113.214/1/gdnUS2218.exe http://moneycentral.msn.com/cabs/pmupd806.exe http://idsm.citadelprocessing.com/SafeCommon/downloads/WalletCab.CAB http://by10fd.bay10.hotmail.msn.com/resources/MsnPUpld.cab http://software-dl.real.com/22ee11265170e847cc16/netzip/RdxIE601.cab http://upload.facebook.com/controls/FacebookPhotoUploader.cab http://85.255.113.214/1/gdnUS2218.exe http://racing.youbet.com/wr_5_5/controls/ybrequest.cab http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/... http://www.napster.com/client/isetup.cab http://upload.facebook.com/controls/FacebookPhotoUploader.cab  
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
					
						
							Advertisement
							 
						 
					
						
							
							
						 
					 
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						2. May 2006 @ 19:50 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Hi chadbrand.
http://www.zonelabs.com http://www.sunbelt-software.com/Kerio.cfm http://www.agnitum.com Cleaning instructions: 
http://www.ewido.net/en/download/ SmitfraudFix.zip  to your desktop -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip SmitfraudFix  and doubleclick smitfraudfix.cmd 
Search  by typing 1  and pressing "Enter "; a textfile opens and lists the infected files (if those exist)
Blacklight  and save it to your desktop http://www.f-secure.com/blacklight/try.shtml blbeta.exe , accept agreement, click > Scan, then > Next
 
							
						 
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
							This message has been edited since posting. Last time this message was edited on 2. May 2006 @ 19:52 
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								chadbrand
							
							
								Newbie
								
									
								
							
							 
						2. May 2006 @ 21:20 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Thanks JaPK!  Here you go...
 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						3. May 2006 @ 01:10 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Hi again chadbrand.
Cleaning instructions: 
http://www.pchell.com/support/safemode.shtml 
http://85.255.113.214/1/gdnUS2218.exe http://85.255.113.214/1/gdnUS2218.exe http://ak.imgfarm.com/images/nocache/funwebproducts/SmileyCentral... http://85.255.113.214/1/gdnUS2218.exe http://moneycentral.msn.com/cabs/pmupd806.exe http://software-dl.real.com/22ee11265170e847cc16/netzip/RdxIE601.cab http://85.255.113.214/1/gdnUS2218.exe  
SmitfraudFix  folder and doubleclick the file smitfraudfix.cmd 
Clean  by typing 2  and pressing "Enter " in order to remove the infected files.
Y  and press "Enter" in order to remove your desktop wallpaper and the infected registry keys.
wininet.dll  file is infected. You might be asked to replace the infected .dll (if found); answer "Yes" by typing Y  and press "Enter".
C:\rapport.txt. 
Warning  : Running option 2 in a clean computer will delete your desktop wallpaper.
 
							
						 
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
							This message has been edited since posting. Last time this message was edited on 3. May 2006 @ 01:11 
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								chadbrand
							
							
								Newbie
								
									
								
							
							 
						3. May 2006 @ 07:52 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Here's Round 2:
HjT  LOG:
HijackThis  v1.99.1
http://aud12.sports.sc5.yahoo.com/java/y/mlbst8408_x.cab http://idsm.citadelprocessing.com/SafeCommon/downloads/WalletCab.CAB http://by10fd.bay10.hotmail.msn.com/resources/MsnPUpld.cab http://upload.facebook.com/controls/FacebookPhotoUploader.cab http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/... http://upload.facebook.com/controls/FacebookPhotoUploader.cab http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4749/mcfs...  
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								chadbrand
							
							
								Newbie
								
									
								
							
							 
						3. May 2006 @ 09:40 Link to this message 
								  
								 
					
					
					
						
						
						
							
							I havent seen any taskbar pop ups in a few hours so it looks like things are better.  How do the logs look?  Might I be out of the woods?  I have not tried to open IE yet, but am using FireFox  without any issues... 
							
						 
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						3. May 2006 @ 10:33 Link to this message 
								  
								 
					
					
					
						
						
						
							
							Hi chadbrand. 
C:\WINDOWS\SYSTEM32\regperf.exe  (Downloader.Zlob.mx)
http://www.thespykiller.co.uk/forum/index.php?board=1.0 regperf.exe 
http://www.thespykiller.co.uk/forum/index.php?topic=5.0 )
http://forums.afterdawn.com/thread_view.cfm/338260  
							
						 
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								chadbrand
							
							
								Newbie
								
									
								
							
							 
						3. May 2006 @ 10:51 Link to this message 
								  
								 
					
					
					
						
						
						
							
							I believe I deleted all of the stuff in the quarantine section when I ran the program last.  Was I not supposed to do that?  Is there any way to get it back in order to do as you requested?  Thanks. 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						3. May 2006 @ 10:56 Link to this message 
								  
								 
					
					
					
						
						
						
							
							It is ok then :)
 
							
						
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
						 
					 
				
				
			
				
				
				
				
				
					
						
							
								chadbrand
							
							
								Newbie
								
									
								
							
							 
						3. May 2006 @ 11:03 Link to this message 
								  
								 
					
					
					
						
						
						
							
							looks good so far... thanks so much!!! 
							
						
						
						
						
						 
					 
				
				
			
				
				
				
					
						
							Advertisement
							 
						 
					
						
							
							  
					 
				
				
				
					
						
							
								
							
							
								Senior Member
								
									
								
							
							 
						3. May 2006 @ 11:06 Link to this message 
								  
								 
					
					
					
						
						
						
							
							You're welcome =) 
							
						
						
						I have moved from AD, I won''t be taking new HijackThis logs from here. Reason: The AD''s Unsupportive athmosphere.
						
						 
					 
				
				
			
			
			
			
			
		
		
	
			
			
		
	 
 
					
						
							afterdawn.com  > forums  > software, operating systems and more  > windows - virus and spyware problems  > theguardservices.com home page hijack + taskbar spyware