1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

How can I get rid of trojan-spy.win32@mx

Discussion in 'Windows - Virus and spyware problems' started by fanatic70, Mar 16, 2007.

  1. fanatic70

    fanatic70 Member

    Joined:
    Jan 15, 2007
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    11
    Please someone help!

    I can't get rid of trojan-spy.win32@mx, and additionaly I can't access yahoo.com. I can only view my mailbox trough yahoo.uk or yahoo.de or other yahoo's. I am receiving quite often system alert regarding malware treats as "back door trojan". What does that mean exactly? I have Kaspersky IS 6.0, I also downloaded AVG Antivirus & Anti-Spyware 7.5. I have performed complete system scan, several times but the same problem occure time to time.

    Please someone help. Thanks in advance!
     
  2. syxguns

    syxguns Active member

    Joined:
    Jan 13, 2006
    Messages:
    1,410
    Likes Received:
    4
    Trophy Points:
    68
    This one is going to take a little work. Follow along and maybe we can get this taken care of.

    Turn off system restore to keep the virus from getting back in.
    You must have an Administrator Privilege to be able to disable System Restore on Windows XP.

    1. On the Desktop, Right Click on My Computer
    2. Select the System Restore Tab
    3. Mark the "Turn Off System Restore" to disable and UnMark to Enable
    4. Click Apply on the Bottom of the Dialog Box to save the settings.
    5. A message "This deletes all existing restore points" will appear, click Yes to disable.
    6. Click OK.

    Now download Ewido Anti-Spyware, It's now called AVG: link
    Now download Smitfraudfix: link Extract all files to your desktop and it will create a smitfraudfix folder. Be sure to disable any anti-virus or anti-spyware that detects the smitfraud fix as potential spyware!

    Reboot your computer in safe mode by pressing F8 repeatedly on startup. Run Ewido and delete all infected files that it finds.

    Browse the folder SmitfraudFix on your Desktop and double-click on smitfraudfix.cmd "Enter your Choice: (1,2,3,4,L,Q):" Press no. 2 on your keyboard to select Option 2. Wait for the process to finish.

    If prompted for: Registry cleaning - Do you want to clean the registry? Press Y, as Yes

    It will check if your wininet.dll file is damaged, if so it will ask you to Replace Infected File? Press Y as Yes and hit Enter

    If it prompts you to Reboot your computer, Please do so.

    After reboot, download and scan with CCleaner: link

    Additional Clean-Up (If Present Only):

    Go to Control Panel > Add/Remove programs and uninstall the following:
    - Seekmo Toolbar or just Seekmo
    - AWS or Weatherbug

    Close Add/Remove Programs after successful removal.

    Download and Run HiJackThis: link
    Place the downloaded file in it's own folder called HijackThis under the C: drive. You will have to make the folder for it. After the file is downloaded to that location open the folder and rename HijackThis.exe to HjT.exe (for the fact that some programs try to hide from it. Your final location should be C:\HijackThis\HjT.exe Now you may right click it and paste a shortcut to your desktop.

    Close any running applications and run HijackThis.
    Mark the following entries:
    - O3 - Toolbar: Seekmo Toolbar - {53E0B6E8-A51D-448B-B692-40B67B285543} - C:\Program Files\Seekmo Programs\Seekmo Toolbar\SeekmoTB.dll
    - O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1
    - O11 - Options group: [INTERNATIONAL] International*

    Select the option Fix checked to fix the problem. If prompts to reboot select No.

    Close HiJackThis
    Find and delete the following Directories:
    - C:\Program Files\Seekmo Programs
    - C:\Program Files\AWS

    In order to make sure that Trojan-Spy.Win32@mx is completely eliminated from your computer, carry out a full scan of your computer using Online Virus Scanner. I would suggest running TrendMicro HouseCall and CWShredder: link

    That should take care of the problem. Let me know if you were successful. Good luck!
     
  3. fanatic70

    fanatic70 Member

    Joined:
    Jan 15, 2007
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    11
    Thanks syxguns!

    Your advise was very helpfull!

    I could get rid of the 'trojan' and other Spywares. It took some times but at the end everything works as it supposed to!

    Thanks ones again!
     
  4. fanatic70

    fanatic70 Member

    Joined:
    Jan 15, 2007
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    11
    Thanks syxguns!

    Your advise was very helpfull!

    I could get rid of the 'trojan' and other Spywares. It took some times but at the end everything works as it supposed to!

    Thanks ones again!
     
  5. fanatic70

    fanatic70 Member

    Joined:
    Jan 15, 2007
    Messages:
    4
    Likes Received:
    0
    Trophy Points:
    11
    Thanks syxguns!

    Your advise was very helpfull!

    I could get rid of the 'trojan' and other Spywares. It took some times but at the end everything works as it supposed to!

    Thanks ones again!
     
  6. syxguns

    syxguns Active member

    Joined:
    Jan 13, 2006
    Messages:
    1,410
    Likes Received:
    4
    Trophy Points:
    68
    Not a problem, that's what we're here to do. I'm glad you got it fixed. Now if you do a scan disk and defrag your HDD your computer will run faster. You can find these tools in Accessories under System Tools.
     

Share This Page