Solved

Topsecuritysite and Guarduptodate

Posted on 2006-06-11
3
559 Views
Last Modified: 2013-12-04
I am running Winxp Pro SP2 with all the latest updates.  Internet Explorer had been hijacked by Guarduptodate and or Topsecuritysite.  I could not find a fix for this so I restored a bacdkup that I made 6 months ago.  My operating system is on c: and most of my programs are stored on D:.  I only restored C drive.  All seemed well yesterday after the restore. Today its back.  I am using the firewall on my linksys router,  I have windows firewall turned on,  I am running Norton Anti Virus.  

How can I get rid of this and keep it from comming back.
0
Comment
Question by:tcassio
  • 2
3 Comments
 
LVL 97

Expert Comment

by:war1
ID: 16881124
Greetings, tcassio !

1. You have a new version of Smitfraud. Download SmitfraudFix (by S!Ri) to your Desktop (Win2k/WinXP only!).
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

How to extract (decompress) zipped or compressed files
http://www.lvsonline.com/compresstut/index.shtml

Note : process.exe is part of the SmitFraudFix tool and is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky, Panda) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm

2. Reboot into Safe Mode
How to start the computer in Safe mode
http://service1.symantec.com/SUPPORT/tsgen...src=sec_doc_nam

3. Open the SmitfraudFix folder and double-click smitfraudfix.cmd

Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually.


Best wishes!
0
 

Author Comment

by:tcassio
ID: 16881313
Thanks,
That got rid of it.  How do I keep it from comming back ?
0
 
LVL 97

Accepted Solution

by:
war1 earned 500 total points
ID: 16881355
tcassio,

Glad SmitFraud is gone. It will not come back unless you download a file with the SmitFraud in it or click on a link that you should not.
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Task Scheduler Task from Logon Event 4624 5 81
Was laptop hacked? 11 84
Group Policies review 1 56
Changing the domain admin password 9 35
SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
No security measures warrant 100% as a "silver bullet". The truth is we also cannot assume anything but a defensive and vigilance posture. Adopt no trust by default and reveal in assumption. Only assume anonymity or invisibility in the reverse. Safe…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now