“Security warning”

Solved
Hello,

I have a red round icon with a yellow exclamation point that has appeared next to my PC's clock.
It says: "Security warning: your computer may be infected with harmful or unwanted software"

I don't dare click on it.
The information I find is in English, but I'm not fluent enough to understand it well.

Thank you in advance for your help!!

29 answers

  1. Contributor
    Hi,

    - Download the SmitfraudFix software created by S!Ri:
    http://siri.urz.free.fr/Fix/SmitfraudFix.zip and unzip it.

    - Open the "SmitfraudFix" folder that will appear, double-click on "Smitfraudfix.cmd", choose option 1, a log will be generated...

    Copy and paste the report on the forum.

    Then

    Do this operation:

    - Restart the PC in safe mode: tap the F8 key on your keyboard (or F5 depending on the version of Windows) and select "safe mode".

    - Run SmitfraudFix again this time choosing option 2 and answer yes to everything.

    Paste the new report afterwards.

    See you later.
    0
    1. SmitFraudFix v2.119

      Report made at 13:02:58.03, 04/11/2006
      Executed from C:\Documents and Settings\Fff\Desktop\smitfraudfix\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Fix executed in normal mode

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      C:\WINDOWS\system32\ismini.exe PRESENT !
      C:\WINDOWS\system32\drvmam.dll PRESENT !

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Fff

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Fff\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Fff\Favorites

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop items

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="My homepage"

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Warning, the keys that follow are not necessarily infected!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Warning, the keys that follow are not necessarily infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""

      »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

      »»»»»»»»»»»»»»»»»»»»»»»» Searching for wininet.dll infection

      »»»»»»»»»»»»»»»»»»»»»»»» End



      0
      1. Contributor
        If you’re not mistaken, the icon will disappear :)

        I’ll come back this evening if you have any other problems...

        See you later
        0
        1. Here is the second one in safe mode Option 2:
          SmitFraudFix v2.119

          Report made at 13:13:18.84, 04/11/2006
          Executed from C:\smitfraudfix\SmitfraudFix
          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
          Fix executed in safe mode

          »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
          !!!Attention, the following keys are not necessarily infected!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» Stopping processes

          »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

          GenericRenosFix by S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

          C:\WINDOWS\system32\ismini.exe deleted
          C:\WINDOWS\system32\drvmam.dll PRESENT!

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\Favorites

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop items

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, the following keys are not necessarily infected!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, the following keys are not necessarily infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"=""

          »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

          »»»»»»»»»»»»»»»»»»»»»»»» Searching for wininet.dll infection

          »»»»»»»»»»»»»»»»»»»»»»»» End



          It didn't ask me anything so I didn't have to say yes!!!
          The icon in question is still there...

          What exactly did I just do!?
          0
          1. I ran Ad-aware, Spybot, and Ccleaner.
            The latter sees this file: C:\WINDOWS\TEMP\win252.tmp.exe 32.50KB, but doesn't remove it.
            Manually, I can't do it; it's inaccessible...
            0
            1. I removed this file, but the icon is still there!!!
              I think it's some kind of "bullshit" to make me go to a website....
              0
              1. Hi,

                To move forward Kristopher whom I greet well baaass...

                Do the following

                F - Hijackthis - Diagnostic and repair tool
                read demo
                http://pageperso.aol.fr/balltrap34/Hijenr.gif
                http://pageperso.aol.fr/balltrap34/demohijack.htm
                Download the French version here
                http://telechargement.zebulon.fr/160-patch-francais-pour-hijackthis-1991.html
                Copy/paste the report

                Good luck

                A++

                Avoid bold characters, it's really not pleasant at all Thanks
                --
                Don't take offense, stay silent as a carp, and
                pet the dog with the grain!
                0
                1. Good evening,

                  Here is the Hijackthis report:
                  Logfile of HijackThis v1.99.1 Scan saved at 16:48:45, on 04/11/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\WINDOWS\System32\ctfmon.exe C:\Program Files\Microsoft Office\Office\OSA.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\System32\wuauclt.exe D:\Programmes\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sfr.fr/offres-numericable.html R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\System32\drvmam.dll,startup O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe 


                  Thank you.
                  0
                  1. Contributor
                    Hello everyone :)

                    Gribouille, let's keep it simple - leave the reports as they are, without having fun making them bold or putting them in tags because it makes reading more difficult for everyone. Thank you.

                    The file that is the source of your concern is drvmam.dll.

                    Before deleting it, it would be wise to analyze it:

                    1/ Display all files and folders:

                    Click on "Start" -> "Control Panel" -> "Tools" (at the top) -> "Folder Options..." -> "View".

                    Check:
                    "Show hidden files and folders"
                    Uncheck the boxes:
                    "Hide protected operating system files (recommended)"
                    "Hide extensions for known file types"

                    Click on "Apply", then "Ok"

                    2/ Go to http://www.virustotal.com/flash/index_en.html
                    Click on "Browse..." and find the bold file:
                    C:\WINDOWS\system32\drvmam.dll
                    Wait for the rectangle to turn green (on the right) and click on "Send".
                    Once the scan is complete, copy/paste the report on the forum.

                    Have a good Sunday.

                    Bizz ^^Marie^^
                    0
                    1. Hello,

                      Here is the Virustotal report: (not very conclusive)
                      Antivirus Version Update Result
                      AntiVir 7.2.0.37 11.03.2006 no virus found
                      Authentium 4.93.8 11.05.2006 no virus found
                      Avast 4.7.892.0 11.03.2006 no virus found
                      AVG 386 11.04.2006 no virus found
                      BitDefender 7.2 11.05.2006 no virus found
                      CAT-QuickHeal 8.00 11.04.2006 no virus found
                      ClamAV devel-20060426 11.05.2006 no virus found
                      DrWeb 4.33 11.05.2006 BACKDOOR.Trojan
                      eTrust-InoculateIT 23.73.45 11.03.2006 no virus found
                      eTrust-Vet 30.3.3176 11.03.2006 no virus found
                      Ewido 4.0 11.05.2006 no virus found
                      Fortinet 2.82.0.0 11.05.2006 no virus found
                      F-Prot 3.16f 11.04.2006 no virus found
                      F-Prot4 4.2.1.29 11.04.2006 no virus found
                      Ikarus 0.2.65.0 11.03.2006 no virus found
                      Kaspersky 4.0.2.24 11.05.2006 no virus found
                      McAfee 4888 11.03.2006 no virus found
                      Microsoft 1.1609 11.04.2006 no virus found
                      NOD32v2 1.1853 11.03.2006 no virus found
                      Norman 5.80.02 11.03.2006 no virus found
                      Panda 9.0.0.4 11.04.2006 Suspicious file
                      Sophos 4.10.0 10.26.2006 no virus found
                      TheHacker 6.0.1.112 11.03.2006 no virus found
                      0
                      1. Hi,

                        Did you do the <10>???

                        Bizz Kritopher

                        --
                        Don't get upset, stay as quiet as a fish, and
                        pet the dog the right way!
                        0
                        1. I'm sorry, but I don't understand what you mean by:
                          <10> "Security Warning"
                          0
                          1. SORRY!
                            I just understood...

                            I wanted to do it once and it caused me so many problems that I gave up! Moreover, this PC is not connected to the internet...

                            I would like to understand where this red icon with a yellow exclamation point comes from!!
                            0
                            1. Contributor
                              Hi,

                              It's time to put an end to this thing.

                              1/ - Download Pocket Killbox here:
                              http://www.downloads.subratam.org/KillBox.exe
                              Disconnect from the internet.

                              Double click on killbox.exe (Pocket Killbox)

                              - Check: "Delete on reboot"
                              - In "Full Path of File to Delete"
                              copy and paste this:

                              C:\WINDOWS\system32\drvmam.dll

                              - click on the white cross on the red background.
                              - a window will pop up for confirmation: click "YES".
                              - a second window will ask if you want to reboot: click "YES".

                              Let the PC restart.
                              If you see the following message: "pending file rename operations registry data has been removed by external process.", ignore it and restart your PC manually.
                              In image: http://tinypic.com/images/goodbye.jpg

                              2/ Scan your PC with this online antivirus (only under IE):
                              http://www.bitdefender.fr/scan8/ie.html
                              Click "I accept" then also accept the ActiveX blocked by the SP2 anti-popup bar (it will flash at the top).
                              Then, click "Click here to scan".
                              Wait until the end of the scan...
                              Copy/paste the entire report on the forum.

                              See you later.
                              0
                              1. The problem is that I don't use IE, and I really don't want to use it...
                                0
                                1. Contributor
                                  So what? You can still do the 1/, right?

                                  Well, if you want to keep your infections, do as you wish...

                                  But I'm a bit surprised anyway:

                                  How do you manage updates and various online scans without using IE? (I guess it's a philosophical question, with no answer. Or rather, with an implied answer, lol)

                                  See you!
                                  0
                                  • 1
                                  • 2