Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

how do you remove darksma? [CLOSED]


  • This topic is locked This topic is locked

#16
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Hi there :)

You seems to have leftovers from Symantec (Norton on your PC), this can conflict with Avast! so please run the Norton Removal tool that can be found here http://service1.syma...005033108162039

Did you install Anyplace Control Security?

Please follow these instructions in order.

First off,

Please go to Uploadmalware to upload a suspicious file for analysis.
  • Enter your username from this forum
  • Copy and paste the link to this thread
  • Browse for this filename: C:\windows\ShellIcon32.dll
  • In the comments, please mention that I asked you to upload this file
  • Click on Send File
You may need to show hidden files, which you can do by following the instructions found here.

Please open HijackThis again and choose "Do a system scan only". Please put a check next to each of the following entries (if still present):

O2 - BHO: (no name) - {03E0B753-15AB-43AA-A8A3-809089FEE882} - (no file)
O2 - BHO: (no name) - {EAB976EB-6999-4847-AFAD-D28C6E7EA18A} - (no file)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfar...p1.0.0.15-3.cab
O20 - Winlogon Notify: geBqQGXO - C:\windows\


Now please close all open windows except HJT and press "Fix checked".

Then,

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\windows\E80F62FF5D3C4A1984099721F2928206.TMP
    C:\windows\fmark2.dat
    C:\windows\system32\ilSYIRqr.ini2
    C:\windows\system32\apcmsoyd.ini2
    C:\windows\system32\qsxtbfim.ini2
    C:\windows\system32\YGjRtBeg.ini2
    C:\Documents and Settings\phuong nguyen\Application Data\shcgw5j0ee21
    C:\windows\system32\rqowbkcu.dll
    C:\windows\ShellIcon32.dll
    C:\windows\svcadmin.exe
    C:\windows\system32\mlfcache.dat
    C:\Program Files\shcgw5j0ee21
    C:\Program Files\iSecurity
    H:\.
    Z:\.
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMshcgw5j0ee21
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows defend
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services\\MyWebSearchService
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Z
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{370f512a-bfe6-11dc-bca0-001636a411c6}
    purity
    emptytemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Next,

Let's give MBAM another shot.

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

And finally,


Click on Start, click on Run
Copy and paste the following in bold in the open window and then click OK

"%userprofile%\desktop\dss.exe" /config

This will open up DSS configurationClick on Check All
Click Scan
DSS will now run again when finished
Please post back both logs that open in notepad
Main txt and extra txt
  • 0

Advertisements


#17
Mike

Mike

    Malware Monger

  • Retired Staff
  • 2,745 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP