TokyoDriftRockz
2007-03-13, 01:50
(NOTE: this is a long post, but PLEASE read through this, as i have no clue what's happening right now)
Hey guys, i'm new to this forum. I have spybot-sd installed, as well as a portable version of it. I do need some help here, as i've read other threads on Smitfraud-C. as a false positive. Unfortunately, mine isn't logged in a registry file, it's in \Windows\system\svchost.exe. Teatimer is warning me that this is a malicious program. So, being a guy who's smart, i scanned my computer with spybot sd. It found smitfraud-c. again, so i deleted it. Thank god it made a system restore point, because after i deleted it, my computer lagged a bit,and i had to restart my computer.
Unforuntately, a restart didn't fix anything, because now not only spybot bugged me about global start up changes, Gogodata toolbar tray didn't start up, ad-watch was bugging me about registry changes and my winpatrol wouldn't display it's main menu. To top it off, all my .exe extensions were opening with folder lock. So i attempted to go right to the source in my program files to open my antivirus software. No go, as my shortcuts didn't work either. So i tried to scan the computer with the 2 remaining that were open, AVG Antivirus with firewall and AVG Anti-Spyware. Antivirus found 3 trojans, but they were previously there 2-3 weeks ago, and i didn't realize that, but i haven't had any problems with my computer a while back. It also reported a dll32 change and a host change in (i think) WINDOWS\system\drivers\hosts. So, seeing that i couldnt' do anything else, i booted up my computer again in safe mode with networking. I did a system restore, and started my computer normally again. I thought everything was OK, but then immediately after startup spybot started bugging me about smitfraud-c. again (i restored till right up before spybot removed smitfraud-c.). Adaware was warning me about something trying to delete a registry value (AVG-Antivirus from startup) and winpatrol was warning me about a possible hi-jack in my IE home page. My GoGoData Tray also popped up about 50 windows (literally) saying that AVG-Antispyware was trying to be removed from global startup. At that point, i was hoping to run a portable version of spybot/adware and scan my ccomputer, but because my flash drive was flashing non-stop, i had to pull it out and replug it back in. That only made matters worse, cause now all my files were being opened with folder lock. And to make matters worse, all of them ended in a .ink extension. I just gave up and shut down my computer, and went over to my parents comptuer to write this.
Basically, i have a system file infected (possibly) with a Smitfraud-c. virus (or w/e it is) and now i can't do anything without worrying that my computer may crash. Any help?
I know this was a long post, and if you made it to the bottom then congrats to you:bigthumb:
Hey guys, i'm new to this forum. I have spybot-sd installed, as well as a portable version of it. I do need some help here, as i've read other threads on Smitfraud-C. as a false positive. Unfortunately, mine isn't logged in a registry file, it's in \Windows\system\svchost.exe. Teatimer is warning me that this is a malicious program. So, being a guy who's smart, i scanned my computer with spybot sd. It found smitfraud-c. again, so i deleted it. Thank god it made a system restore point, because after i deleted it, my computer lagged a bit,and i had to restart my computer.
Unforuntately, a restart didn't fix anything, because now not only spybot bugged me about global start up changes, Gogodata toolbar tray didn't start up, ad-watch was bugging me about registry changes and my winpatrol wouldn't display it's main menu. To top it off, all my .exe extensions were opening with folder lock. So i attempted to go right to the source in my program files to open my antivirus software. No go, as my shortcuts didn't work either. So i tried to scan the computer with the 2 remaining that were open, AVG Antivirus with firewall and AVG Anti-Spyware. Antivirus found 3 trojans, but they were previously there 2-3 weeks ago, and i didn't realize that, but i haven't had any problems with my computer a while back. It also reported a dll32 change and a host change in (i think) WINDOWS\system\drivers\hosts. So, seeing that i couldnt' do anything else, i booted up my computer again in safe mode with networking. I did a system restore, and started my computer normally again. I thought everything was OK, but then immediately after startup spybot started bugging me about smitfraud-c. again (i restored till right up before spybot removed smitfraud-c.). Adaware was warning me about something trying to delete a registry value (AVG-Antivirus from startup) and winpatrol was warning me about a possible hi-jack in my IE home page. My GoGoData Tray also popped up about 50 windows (literally) saying that AVG-Antispyware was trying to be removed from global startup. At that point, i was hoping to run a portable version of spybot/adware and scan my ccomputer, but because my flash drive was flashing non-stop, i had to pull it out and replug it back in. That only made matters worse, cause now all my files were being opened with folder lock. And to make matters worse, all of them ended in a .ink extension. I just gave up and shut down my computer, and went over to my parents comptuer to write this.
Basically, i have a system file infected (possibly) with a Smitfraud-c. virus (or w/e it is) and now i can't do anything without worrying that my computer may crash. Any help?
I know this was a long post, and if you made it to the bottom then congrats to you:bigthumb: