Results 1 to 9 of 9

Thread: smitfraudfix file download

  1. #1
    Join Date
    Nov 2004
    Posts
    8

    ThumbsUp smitfraudfix file download

    smitfraudfix file download, used to remove nasties like oneclicksearches

  2. #2
    Join Date
    Aug 2004
    Location
    TA HeadQuarter
    Posts
    80

    Re: smitfraudfix file download

    thanks for the patch for smitfraudfix file

  3. #3
    Join Date
    May 2006
    Posts
    2

    Re: smitfraudfix file download

    hello i'm wondering i've been doing a search for the how to Smitfraudfix for this file can anyone help me? Do i just merge the file then restart in safe mode then let it run ?or is there something else that i have to do?Thank you very much

  4. #4
    Join Date
    Sep 2005
    Posts
    1,434

    Re: smitfraudfix file download

    HI,
    There is something on our computer called spyware falcon..I think its a virus cause nobody downloaded it..here is my hijack log

    Logfile of HijackThis v1.99.1
    Scan saved at 12:04:01 PM, on 4/25/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\Program Files\ltmoh\Ltmoh.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
    C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\System32\ezSP_Px.exe
    C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
    C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
    C:\toshiba\ivp\ism\pinger.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\System32\mssearchnet.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\System32\dcomcfg.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.toshiba.com/
    O2 - BHO: Nothing - {edbf1bc8-39ab-48eb-a0a9-c75078eb7c8e} - C:\WINDOWS\System32\hp8D5B.tmp
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (file missing)
    O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - C:\Program Files\Security Toolbar\Security Toolbar.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
    O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
    O4 - HKLM\..\Run: [NAV CfgWiz] C:\PROGRA~1\NORTON~1\Cfgwiz.exe /R
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
    O4 - HKLM\..\Run: [NDSTray.exe] "C:\Program Files\Toshiba\ConfigFree\NDSTray.exe"
    O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
    O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [PrevxHome] C:\Program Files\Prevx Home\SAGUI.exe
    O4 - HKLM\..\Run: [SpyFalcon] C:\Program Files\SpyFalcon\SpyFalcon.exe /h
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache.exe" --ntservice (file missing)
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Prevx Agent (PrevxAgent) - Prevx Ltd. - C:\Program Files\Prevx Home\PXAgent.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

  5. #5
    Join Date
    Oct 2005
    Location
    Mumbai
    Posts
    824

    Re: smitfraudfix file download

    Please download SmitfraudFix
    Extract the content (a folder named SmitfraudFix) to your Desktop.

    Open the SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
    Please copy/paste the content of that report into your next reply.
    My Rig:
    Asus P5Q Deluxe Motherboard - 14000 Rs.
    Graphic Card Ati Sapphire HD 4870 Card - 19000 Rs.
    Smps Corsair 750 Watts - 8200 Rs.
    Corsair Twin 2x 2048 - 8500c5ram (800mhz) - 3000 Rs.
    NZXT Zero Cabinet - 7500 Rs.
    Pentium Quad Core Q9300 Lga 775 Cpu - 12500 Rs.
    250 Gb Hdd Seagate sata - 2350 Rs.
    Dvd Writer Samsung 20x Ide/ Sata - 1500 Rs.

  6. #6
    Join Date
    Sep 2005
    Posts
    1,434

    Re: smitfraudfix file download

    SmitFraudFix v2.34

    Scan done at 12:38:38.37, Tue 04/25/2006
    Run from C:\Documents and Settings\Yuko\Desktop\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600]

    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» C:\


    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» C:\WINDOWS


    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» C:\WINDOWS\system


    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» C:\WINDOWS\Web


    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» C:\WINDOWS\system32

    C:\WINDOWS\system32\hp????.tmp FOUND !
    C:\WINDOWS\system32\ld????.tmp FOUND !
    C:\WINDOWS\system32\mssearchnet.exe FOUND !
    C:\WINDOWS\system32\ncompat.tlb FOUND !
    C:\WINDOWS\system32\nvctrl.exe FOUND !
    C:\WINDOWS\system32\ot.ico FOUND !
    C:\WINDOWS\system32\ts.ico FOUND !
    C:\WINDOWS\system32\1024\ FOUND !

    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» C:\Documents and Settings\Yuko\Application Data


    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» Start Menu

    C:\DOCUME~1\Yuko\STARTM~1\Programs\SpyFalcon FOUND !

    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» C:\DOCUME~1\Yuko\FAVORI~1

    C:\DOCUME~1\Yuko\FAVORI~1\Antivirus Test Online.url FOUND !

    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» Desktop

    C:\DOCUME~1\Yuko\Desktop\SpyFalcon.lnk FOUND !

    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» C:\Program Files

    C:\Program Files\Security Toolbar\ FOUND !
    C:\Program Files\SpyFalcon\ FOUND !

    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» Corrupted keys


    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» Desktop Components

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="about:Home"
    "SubscribedURL"="about:Home"
    "FriendlyName"="My Current Home Page"


    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» Sharedtaskscheduler

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Share dTaskScheduler]
    "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"

    [HKEY_CLASSES_ROOT\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
    @="%SystemRoot%\System32\browseui.dll"

    [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
    @="%SystemRoot%\System32\browseui.dll"


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Share dTaskScheduler]
    "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

    [HKEY_CLASSES_ROOT\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
    @="%SystemRoot%\System32\browseui.dll"

    [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
    @="%SystemRoot%\System32\browseui.dll"


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Share dTaskScheduler]
    "{CA14EE13-ED15-C4A2-17FF-DA4D15C1BC5E}"="Twain"

    [HKEY_CLASSES_ROOT\CLSID\{CA14EE13-ED15-C4A2-17FF-DA4D15C1BC5E}\InProcServer32]
    @="C:\WINDOWS\System32\twain32.dll"

    [HKEY_CURRENT_USER\Software\Classes\CLSID\{CA14EE13-ED15-C4A2-17FF-DA4D15C1BC5E}\InProcServer32]
    @="C:\WINDOWS\System32\twain32.dll"


    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» Scanning wininet.dll infection


    »»»»»»»»»»»»»»»»&#18 7;»»»»»»» End

  7. #7
    Join Date
    Oct 2005
    Location
    Mumbai
    Posts
    824

    Re: smitfraudfix file download

    You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

    Next, please reboot your computer in Safe Mode by doing the following :
    Restart your computer
    After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    Instead of Windows loading as normal, a menu with options should appear;
    Select the first option, to run Windows in Safe Mode, then press "Enter".
    Choose your usual account.
    Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
    Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

    You will be prompted: "Registry cleaning - Do you want to clean the registry?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

    The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

    The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.

    A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.

    The report can also be found at the root of the system drive, usually at C:\rapport.txt

    Warning: running option #2 on a non infected computer will remove your Desktop background.
    My Rig:
    Asus P5Q Deluxe Motherboard - 14000 Rs.
    Graphic Card Ati Sapphire HD 4870 Card - 19000 Rs.
    Smps Corsair 750 Watts - 8200 Rs.
    Corsair Twin 2x 2048 - 8500c5ram (800mhz) - 3000 Rs.
    NZXT Zero Cabinet - 7500 Rs.
    Pentium Quad Core Q9300 Lga 775 Cpu - 12500 Rs.
    250 Gb Hdd Seagate sata - 2350 Rs.
    Dvd Writer Samsung 20x Ide/ Sata - 1500 Rs.

  8. #8
    Join Date
    May 2006
    Posts
    2

    Re: smitfraudfix file download

    I picked up the patch for smitfraudfix but would like to know where can i get the actual program file .I did a google search and the one i find has a virus in it my nod32 antivirus won't let me download it.Anybody have a link to this? Thanks

  9. #9
    Join Date
    Jun 2006
    Posts
    1

    Re: smitfraudfix file download

    T H A N K Y O U !!!

    It worked like a charm - (I did have my doubts)

    Comment: I never hear of any of these baddies being prosecuted; They must cost the public a lot of time and money....

Similar Threads

  1. Replies: 4
    Last Post: 07-02-2011, 10:19 AM
  2. What is SmitFraudFix ?
    By CheckMeNot in forum Networking & Security
    Replies: 3
    Last Post: 09-07-2009, 03:40 PM
  3. SmitFraudFix does n't work
    By Farhat in forum Networking & Security
    Replies: 3
    Last Post: 20-06-2009, 08:22 AM
  4. Replies: 2
    Last Post: 26-11-2008, 06:56 PM
  5. Replies: 0
    Last Post: 26-11-2008, 04:11 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,490,206.77048 seconds with 17 queries