Posted 16 July 2005 - 02:49 PM
I got hit with Anti-Virus Gold/AVGOLD and the SmitFraud, but the instructions (while very handy) weren't quite up to date.
I was able to "disinfect" though by some perserverance using the programs and the helps/hints listed above.
after following the instructions I still found these files on my computer:
all of which were created/modified with the time/date I got the infection (I knew right away and shutdown immediately...but...)
so I deleted those I could by hand, had to use the TASK MANAGER to stop those in use and delete. KILLBOX worked on the rest, all EXCEPT winInet.dll, which I couldn't delete no matter what.
however, after several reboots (using KILLBOX) I just now, as I type got my computer back to normal, including my DESKTOP tab on my display.
I also found the following registry entries via HIJACK THIS:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINNT\system32\shdocsv.dll/API32.htm#ID=347;065D
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://shdocsv.dll/asst.htm
I think KILLBOX thru me for a loop, as I thought cutting & pasting the list would take care of all of them in one fell swoop. By the time I used the SmitFraud instructions, it didn't seem to work at all, so I had to
cut & paste
kill and reboot
one by one.
So, I'll monitor my PC for a few days and check back and let you know how it's going...