smitfraud-c toolbar888

zero3

New member
I recently purchased a USB wireless router adapter for my pc. The model is Planex GW-US54Mini2. After installing the software, Spyboy pooped up a message saying that install.exe is a smitfraud-c toolbar888 and automatically terminated the process. My new USB wireless adapter would not work without the software. I think this a false positive. Since other spyware programs did not detect anything on it. Please fix this problem. Thanks.

PS: here is the website of Planex
wxx.planex.net
 
Last edited by a moderator:
If you are sure that the software is not infected:
  1. Execute the "install.exe".
  2. When you receive the following message:

    Code:
    Spybot - Search & Destroy
    
    Spybot - Search & Destroy has encountered and
    terminated a process that is listed as part of a
    malicious software.
    
    Process ID:	????
    Filename:	install.exe
    Found in:	????
    Identified as:	Smitfraud-C.Toolbar888
    
    If Spybot - Search & Destroy encounters this process again…
    ● Inform me again.
    ○ Automatically kill this process.
    ○ Allow this process to run (NOT RECOMMENDED).
    
    ■ Delete the associated file.   [?]   [OK]
  3. Check "Allow this process to run (NOT RECOMMENDED)."
  4. Uncheck "Delete the associated file".
  5. Click "OK"
  6. Execute the "install.exe" again.
After the product has been installed:
  • Submit an email to detections#spybot.info (replacing the # with @). The email should contain:
 
Was smitfraud-c toolbar888 confirmed as a false positive? I see a few reportings, but no confirmations. :sad:
 
Last edited:
Thanks Tashi. I was specifically referring to, as of the updates on 5/2. I'm presuming it wasn't another false detection of the smitfraud-c toolbar888, otherwise it would have been stated as such.

Thanks again..
Carol
 
Ok and if in doubt:

  • Open SpyBot.
  • Check for problems.
  • When finished, right click and choose copy results (not the full report) to clipboard and post that into topic.
:)
 
hello,

the reported install.exe is a false positive the dection rules are being corrected, they will be effective with the next update. Teatimer will need to be restarted as well.

Until then please follow md usa spybot fans instructions for allowing the file to execute.
 
Yodama...

Thank you for your reply. I suspected it might be the case, but was not sure and thought it best to check here.

Thanks again,
Carol
 
zero3:
Carol:
Et al:

If you followed my instructions to bypass the termination of the "install.exe", I suggest that after the next set of updates you go into TeaTimer's "White & Black List" and remove the entry that was created. To do that:
  • Right click on the TeaTimer system tray icon and select Settings. This will bring up TeaTimer's "White & Black List". There are four (4) Buttons across the top of the "White & Black List":
    • Allowed processes
    • Blocked processes
    • Allowed registry changes
    • Blocked registry changes
  • Click on the "Allowed processes" button.
  • Remove the entry associated with the "install.exe" by clicking on the scripted black "X" to the right of the entry and then clicking the "OK" button.
 
Last edited:
Black & White List Empty

Hello,

I have the following message:

Category - "Global Browser Toolbar",

Change - "Value deleted", Entry {9FB3908C-6565-4CB0-...}

Could you please let me know - what do I need to do "Allow" or "Deny" ?

Also, the "Black & White List" is Empty. Although, I did many times "Blocked Registry Changes".

Please see the attachment: msg1.zip

Regards,

User67.
 
Back
Top