Help--infected with Smitfraud-C and Zeno Search

Hi

Thanks for the heads up. I'll try to remember keep the thread open. Have a nice time in Hawaii :cool:
 
Hi...back from Hawaii...

Hi-
I had to interrupt the problem-solving process that you are so graciously helping me with, in order to go to Hawaii for my friend's wedding. I'm back now (GREAT trip!!!) and I hope you'll help me clean up the loose ends:)

At this point, should I run a Kaspersky or other scan to see where we're at?

Thanks,
George
 
Welcome back :)

Yes, you may run Kaspersky online scanner and post back its report.
 
New Kaspersky report

Hi-
Here's the new Kaspersky report. Thanks, George

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Sunday, July 13, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Saturday, July 12, 2008 22:06:49
Records in database: 946264
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\

Scan statistics:
Files scanned: 94407
Threat name: 2
Infected objects: 4
Suspicious objects: 0
Duration of the scan: 06:55:01


File name / Threat name / Threats count
C:\Documents and Settings\NYP\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.71585 Infected: Backdoor.Win32.VB.dav 1
C:\Documents and Settings\NYP\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.76578 Infected: Backdoor.Win32.VB.dav 1
C:\IBMTOOLS\APPS\RRPC\RRPC\superinstall.EXE Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 2

The selected area was scanned.
 
That looks actually good :) You can remove those two first on the list by clearing quarantine items from Malwarebytes' Anti-Malware program. The third finding is false positive. No need to worry about it.
 
Clearing quarantine items

Hi-
It sounds like we're making a lot of progress, thanks to you. How exactly do I clear the quarantine items, as you mentioned in your last post?
Thanks,
George
 
How exactly do I clear the quarantine items, as you mentioned in your last post?

Hi


Show hidden files
-----------------
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.


Go to C:\Documents and Settings\NYP\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine folder and delete items in it. :)

Then hide hidden files again:
  1. Double-click My Computer.
  2. Click the Tools menu, and then click Folder Options.
  3. Click the View tab.
  4. Put a check by
    Hide file extensions for known file types.
  5. Under the
    Hidden files
    folder, select
    Show hidden files and folders.
  6. Check
    Hide protected operating system files.
  7. Click Apply, and then click OK.
 
A couple of questions...

Hi-

I followed your instructions above. But in step 5, did you mean check "DO NOT show hidden files and folders"?

Should I run any more scans now, or are we finished?

Also, can you recommend anything more I can do to make the computer run more smoothly? Thanks to you, we definitely got rid of my original horrible problem, which was the malware and the continuing pop-ups. It's 100 times better than it was. But the machine still runs very sluggishly, and every so often I get the "blue screen of death" and it reboots for no apparent reason. Is there any solution for that?

Thanks for everything you've done so far!!!!

George
 
I followed your instructions above. But in step 5, did you mean check "DO NOT show hidden files and folders"?
Hiding part is actually meantioned in step 6 :)

Should I run any more scans now, or are we finished?
I think we are finished here.

You may try hints given here to possibly make system faster.
 
Thanks for all your help...

Thanks again for all your help. I appreciate all the time you've put into this project. I will try the hints at the link you sent me.

All the best,
George
 
You're welcome :)

Hopefully you find the hints behind the link helpful.
 
Back
Top