Name: PPxrare Date: March 21, 2008 at 08:23:29 Pacific Subject: downloaded a plugin = spyware OS: Windows Xp sp2 CPU/Ram: 256 Model/Manufacturer: Acer aspire T300
Comment:
ok so i downloaded a plugin to watch some soccer videos and ended up getting a spyware,
anyways this spyware wanted me to download program called virusheat (which i obviously did not)
i tried searching for the spywares using kaspersky and it only deleted two processes but it can not find the other two.
the other two are sbmnt.exe and sbsm.exe i know them because i kind of memorized my task manager because i use it a lot.
so all i want is a little help getting rid of them. thank you and my computer suddenly closes down like 20 mins after i open it . PS: tried using vundofix and hijackthis , didnt work.
Your computer is infected with Rongue Antispyware VirusHeat and some other viruses (like C:\Program Files\NetProject and C:\Program Files\NetProject\sbsm.exe). Lest try to get rid of them. lets start. Dont scan your computer with any Antivirus or Antispyware. Disable all such applications.
1. Save " HJTInstall.exe" to your desktop. 2. Double click on HJTInstall.exe to run the program. 3. By default it will install to C:\Program Files\Trend Micro\HijackThis. 4. Accept the license agreement by clicking the "I Accept" button. 5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log. 6. Click "Save log" to save the log file and then the log will open in Notepad. 7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log. 8. Paste the log in your next reply. 9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.
thanks for the fast reply here is the hijackthis file. ( ok here is the problem, kaspersky deleted two files as i said above then the other two processes were stil there, anyways i restarted in safe mode then found the folder Netproject and deleted the files and the regeistry files in regedit. i still have the annoying popups and a folder named C:program files/ Helper which seems to have nothing in it but im not able to delete it, so thats the whole story i hope you will be able to help me because i cant play any game because the popups keep minimizing my screen.)
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:56:27 PM, on 3/21/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5450.0004) Boot mode: Normal
>DoubleClick mbam-setup.exe and follow the prompts to install MBA-M. >Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. >If an update is found, it will download and install the latest database updates. >Once the program has loaded, select Perform full scan, then click Scan. >When the scan is complete, click OK, then Show Results to view the results. >Be sure that everything is checked, and click Remove Selected. >When MBAM finishes, Notepad will open with the log. Please save it where you can find it easily. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
THEN:
Download SmitfraudFix.exe from here and save it to your desktop:
>Restart your computer. Before the Windows loading screen appears, keep pressing F8 until you see the boot menu. Select Safe Mode. >Double-click SmitfraudFix.exe >Select 2 and press Enter to clean your system by deleting infected files. >You will be prompted: Do you want to clean the registry ? Answer Y (yes) and press Enter in order to remove the hijacked Desktop background and clean registry keys associated with the infection. >SmitFraudFix will then check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? Answer Y (yes) and press Enter to restore a clean file. >You may have to restart your computer in order to finish the spyware removal process. You can find a report on spyware removal at the root of the system drive. Usually it will be located at C:\rapport.txt.
After runing above tools, Scan your pc with Hijackthis and Post Fresh Hijackthis Log along with Malwarebytes Antimalware and SmitfraudFix Logs in your next reply.
Thanks for the reply and thank you very much for trying to help me , fortunately my brother opened the computer while i was away and downloaded Spybot search and destroy, and i came back to spyware free computer.
But shuld also try to scan with Malwarebytes' Anti-Malware for latest detection, It will detect all other remaining malwares on your computer. Bcoz i cant say that your computer is completely cleaned.!!
The information on Computing.Net is the opinions of its users. Such
opinions may not be accurate and they are to be used at your own risk.
Computing.Net cannot verify the validity of the statements made on this site. Computing.Net and Computing.Net, LLC hereby disclaim all responsibility and liability for the content of Computing.Net and its accuracy.
PLEASE READ THE FULL DISCLAIMER AND LEGAL TERMS BY CLICKING HERE