beefstu123
asked on
Time/Date virus
i am using a windows XP SP2 Pro PC which used to have hundreds of infections, all but one remains:
the time/date bar in the lower right hand area of my task bar displays 24 hour time then "VIRUS ALERT!" afterwards. i have tried multiple virus scans and cannot get rid of it. anyone able to help? also the "all Programs" "Logoff" and "restart" buttons in my start menu are missing.
expertex.bmp
the time/date bar in the lower right hand area of my task bar displays 24 hour time then "VIRUS ALERT!" afterwards. i have tried multiple virus scans and cannot get rid of it. anyone able to help? also the "all Programs" "Logoff" and "restart" buttons in my start menu are missing.
expertex.bmp
ASKER CERTIFIED SOLUTION
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
SOLUTION
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
how is it going?
Running smitfraudfix Option 2 should clear the infection and fix the reg entries modified by the virus.
http://siri.geekstogo.com/SmitfraudFix.php
Running smitfraudfix Option 2 should clear the infection and fix the reg entries modified by the virus.
http://siri.geekstogo.com/SmitfraudFix.php
SOLUTION
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
ASKER
great news :D the virus alert msgs are gone, even before i finished the registry work. im still doing a few more tests with the info given, but so far it looks very good. thanx again for ur help
ASKER
All done :) thankyou RiggedyT very much for that link, quite easy to understand and perform. the Virus Alert msgs are now gone.
thnx rpggamergirl for the info, im doin some extra scans now :)
thank you orangutang for ur input, much appreciated :)
thnx rpggamergirl for the info, im doin some extra scans now :)
thank you orangutang for ur input, much appreciated :)
Hey, no problem, it seems like quite the intrusive malware, lol.
Glad you were able to solve it!
Glad you were able to solve it!
OR:
You could also just let combofix remove these bad entries maybe it's all that's needed
Was Combofix run last?
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
-------------------------- ---------- ---------- ---------- ---------- ------
File::
C:\Program Files\NetProject\sbmdl.dll
Folder::
C:\Program Files\NetProject
C:\Documents and Settings\User\Application Data\TmpRecentIcons
C:\Documents and Settings\User\Application Data\shc3v4j0e96n
C:\Documents and Settings\All Users\Application Data\TEMP
C:\Documents and Settings\Coop\Application Data\shc3v4j0e96n
C:\WINDOWS\system32\lphc5v 4j0e96n.ex e
C:\WINDOWS\system32\phc5v4 j0e96n.bmp
C:\WINDOWS\system32\blphc5 v4j0e96n.s cr
C:\WINDOWS\eobp.exe
C:\Uninstall.lnk
Registry::
[-HKEY_LOCAL_MACHINE\~\Bro wser Helper Objects\{99BA268B-4021-473 9-9945-3C7 74217FE75} ]
[HKEY_LOCAL_MACHINE\SOFTWA RE\Microso ft\Interne t Explorer\Toolbar]
"{51D81DD5-55B7-497F-95DB- D356429BB5 4E}"=-
[-HKEY_CLASSES_ROOT\clsid\ {51d81dd5- 55b7-497f- 95db-d3564 29bb54e}]
-------------------------- ---------- ---------- ---------- ---------- ------
3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.
You could also just let combofix remove these bad entries maybe it's all that's needed
Was Combofix run last?
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
--------------------------
File::
C:\Program Files\NetProject\sbmdl.dll
Folder::
C:\Program Files\NetProject
C:\Documents and Settings\User\Application Data\TmpRecentIcons
C:\Documents and Settings\User\Application Data\shc3v4j0e96n
C:\Documents and Settings\All Users\Application Data\TEMP
C:\Documents and Settings\Coop\Application Data\shc3v4j0e96n
C:\WINDOWS\system32\lphc5v
C:\WINDOWS\system32\phc5v4
C:\WINDOWS\system32\blphc5
C:\WINDOWS\eobp.exe
C:\Uninstall.lnk
Registry::
[-HKEY_LOCAL_MACHINE\~\Bro
[HKEY_LOCAL_MACHINE\SOFTWA
"{51D81DD5-55B7-497F-95DB-
[-HKEY_CLASSES_ROOT\clsid\
--------------------------
3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.
You closed the question already, :)
Combofix still need to remove those folders and reg entries.
Combofix still need to remove those folders and reg entries.
For safety reason, when you're done with combofix please uninstall it.
Go to Start > Run and copy and paste next command in the field:
ComboFix /u
Go to Start > Run and copy and paste next command in the field:
ComboFix /u
ASKER
ok i'll do that now :) thanx Rpggamergirl.
just a quick unrelated question, wat RPG's are u into?
just a quick unrelated question, wat RPG's are u into?
I haven't played any in a long time because when I start I CAN'T seem to stop.
FF series, Zelda series, Dark Cloud series, Grandia, Wild Arms III etc, lol.
FF series, Zelda series, Dark Cloud series, Grandia, Wild Arms III etc, lol.
ASKER
nice :) i remeber playin some the original Zelda games on snes and gameboy lol. Final Fantasy :D brilliant games, i know a mate wh still works on completely finishing FF 7 on playstation lol
FF7 is the best in the series IMO and also FF9. I spent time in just upping my levels so my character was really strong during battles with the bosses.
Zelda OoT in N64 was the one that I needed help/guide, that was hard for me, I kept falling off at anything I'm on, stayed up late playing that game till1am and woke up at 5am to continue. I think I must've thrown the controller twice playing that game, lol.
Zelda OoT in N64 was the one that I needed help/guide, that was hard for me, I kept falling off at anything I'm on, stayed up late playing that game till1am and woke up at 5am to continue. I think I must've thrown the controller twice playing that game, lol.
ASKER
lol i know wat u mean :) i've gotten into World of Warcraft lately, i played it for most of the loing weekend we had recently, some mates and i have been online 14 hours straight, then sleep, then more WoW. but ya gotta go outside too lol. yeah, ive thrown quite a few controllers too :p
ASKER
log.txt
hijackthis-TC.log