hi cesarper,
ok thanks for the info. vundo and sdfix came up clean. first we will use hjt. i should have posted to use it earlier to clean up those 04's.
first:
scan with HJT, put a checkmark beside the items below, close all windows and click fix checked.
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
select all those 02- BHO that end in (no file)
O4 - HKLM\..\Run: [AntiVirusPro] C:\Program Files\AntiVirusPro\AntiVirusPro.exe
O4 - HKCU\..\Run: [SSK Service] C:\Documents and Settings\Ale\Desktop\UNKNOWN_PARAMETER_VALUE\details.pif
O4 - Global Startup: AutorunsDisabled
-------------------------------------------------
next:
to show all files do this:
FOr XP: on the desktop double click my computer,go to tools>folder options>view> then select "show hidden files and folders", then UNcheck "hide protected operating system files " also UNcheck "hide extensions for known file types" click apply to all folders, apply then ok
navigate here:
C:\WINDOWS\system32
and delete the .exe >>ctfmona.exe
Note you may see this one:cftmon.exe which is OK note spelling difference between the two.
if you cant delete it try this: bring up task manager by hitting the ctrl-alt-delete keys at once. under the process tab look for ctfmona.exe in the list. if you see if running click on it and then click on end process, then go back and try to delete it.
-----------------------------------------
we are going to run the first step of smitfraudfix again, but lets get a new copy as its updated. you can delete your old copy off the desktop. just run the first step (search):
download SmitfraudFix (by S!Ri) to your Desktop:
http://siri.urz.free.fr/Fix/SmitfraudFix.exe
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.
Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter
This program will scan large amounts of files on your computer for known patterns so please be patient while it works. It will create a file named: c:\rapport.txt
stop at this point and post a HijackThis log along with the contents of the c:\rapport.txt.
--------------------------------------------
reboot computer and run combofix again also and post:
the smitfraud log
the new combofix log.
new hjt log
shelf life
ok thanks for the info. vundo and sdfix came up clean. first we will use hjt. i should have posted to use it earlier to clean up those 04's.
first:
scan with HJT, put a checkmark beside the items below, close all windows and click fix checked.
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file)
select all those 02- BHO that end in (no file)
O4 - HKLM\..\Run: [AntiVirusPro] C:\Program Files\AntiVirusPro\AntiVirusPro.exe
O4 - HKCU\..\Run: [SSK Service] C:\Documents and Settings\Ale\Desktop\UNKNOWN_PARAMETER_VALUE\details.pif
O4 - Global Startup: AutorunsDisabled
-------------------------------------------------
next:
to show all files do this:
FOr XP: on the desktop double click my computer,go to tools>folder options>view> then select "show hidden files and folders", then UNcheck "hide protected operating system files " also UNcheck "hide extensions for known file types" click apply to all folders, apply then ok
navigate here:
C:\WINDOWS\system32
and delete the .exe >>ctfmona.exe
Note you may see this one:cftmon.exe which is OK note spelling difference between the two.
if you cant delete it try this: bring up task manager by hitting the ctrl-alt-delete keys at once. under the process tab look for ctfmona.exe in the list. if you see if running click on it and then click on end process, then go back and try to delete it.
-----------------------------------------
we are going to run the first step of smitfraudfix again, but lets get a new copy as its updated. you can delete your old copy off the desktop. just run the first step (search):
download SmitfraudFix (by S!Ri) to your Desktop:
http://siri.urz.free.fr/Fix/SmitfraudFix.exe
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.
Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter
This program will scan large amounts of files on your computer for known patterns so please be patient while it works. It will create a file named: c:\rapport.txt
stop at this point and post a HijackThis log along with the contents of the c:\rapport.txt.
--------------------------------------------
reboot computer and run combofix again also and post:
the smitfraud log
the new combofix log.
new hjt log
shelf life