Richie_B43
New member
Hi guys,
I was lucky enough to find your site whilst doing a Google search for some solution to *ww.syssecuritysite.com, (One 'w' omitted to prevent the address coming up as a link.), which suddenly appeared last night and completly hijacked both Internet Explorer and my Tiscali Broadband browser.
It not only took over my Home Page, it overwrote all URL's typed into the address bar, and also seemed to provide an open door for about five different Trojans, a couple of which my installed anti-virus and anti-spyware could not delete. (Luckily the Google taskbar wasn't affected so I still was able to get access to the net).
I have followed the "self help" removal instructions (very clearly) set out in Tashi's sticky Smitfraud: post and it seems to have done the trick ... so here is my rapport.txt report, Ewido log and HJY log for you to have a look at. (The Spybot-S&D scan came up clear).
Thanks in advance,
Richie.
-----------------------------------------------------
SmitFraudFix v2.68b
Scan done at 17:40:51.75, 07/07/2006
Run from C:\Documents and Settings\Richie\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\system32\ld???.tmp Deleted
C:\WINDOWS\system32\ot.ico Deleted
C:\WINDOWS\system32\regperf.exe Deleted
C:\WINDOWS\system32\stdole3.tlb Deleted
C:\WINDOWS\system32\1024\ Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 18:52:33 07/07/2006
+ Scan result:
HKU\S-1-5-21-117609710-1409082233-839522115-1004\Software\_siq -> Adware.Begin2Search : Cleaned with backup (quarantined).
::Report end
------------------------------------------------------------
ps: I'll post the HJT log on another thread.
R.
I was lucky enough to find your site whilst doing a Google search for some solution to *ww.syssecuritysite.com, (One 'w' omitted to prevent the address coming up as a link.), which suddenly appeared last night and completly hijacked both Internet Explorer and my Tiscali Broadband browser.
It not only took over my Home Page, it overwrote all URL's typed into the address bar, and also seemed to provide an open door for about five different Trojans, a couple of which my installed anti-virus and anti-spyware could not delete. (Luckily the Google taskbar wasn't affected so I still was able to get access to the net).
I have followed the "self help" removal instructions (very clearly) set out in Tashi's sticky Smitfraud: post and it seems to have done the trick ... so here is my rapport.txt report, Ewido log and HJY log for you to have a look at. (The Spybot-S&D scan came up clear).
Thanks in advance,
Richie.
-----------------------------------------------------
SmitFraudFix v2.68b
Scan done at 17:40:51.75, 07/07/2006
Run from C:\Documents and Settings\Richie\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\WINDOWS\system32\ld???.tmp Deleted
C:\WINDOWS\system32\ot.ico Deleted
C:\WINDOWS\system32\regperf.exe Deleted
C:\WINDOWS\system32\stdole3.tlb Deleted
C:\WINDOWS\system32\1024\ Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 18:52:33 07/07/2006
+ Scan result:
HKU\S-1-5-21-117609710-1409082233-839522115-1004\Software\_siq -> Adware.Begin2Search : Cleaned with backup (quarantined).
::Report end
------------------------------------------------------------
ps: I'll post the HJT log on another thread.
R.