Kindly be advised we cannot cancel subscriptions or issue refunds on the forum.
You may cancel your Bitdefender subscription from Bitdefender Central or by contacting Customer Support at: https://www.bitdefender.com/consumer/support/help/

Thank you for your understanding.

Error Smart

Options
jeffers
edited March 2008 in Malware talk

bit defender keeps saying i have 856 password protected items that cant be scanned but offers no help as to what to do about this so i was at microsoft trying to scan registry when i was offered error smart ? i thought microsoft was scanning my computer for errors when this error smart pops up and says i have 469 errors and to continue i must purchase ??? anyone heard of this :blink: whats the point of bit defender if i have to purchase other software

Comments

  • Chesda
    edited March 2008
    Options

    jeffers,


    That error smart that pops up is malware that disguises itself as an anti-spyware program, in order to trick the owner of the infected computer to buy the program, by repeatedly informing them of false threats to their system.


    They often causing more damage to the computer by removing, moving or editing important files and changing the registry.


    Attempting to remove it using the "Add/Remove Programs" control panel may sometimes work. However, these programs has a tendency to reinstall itself due to hidden components.


    I can advise you to avoid such products.


    But for now, please download Hijackthis here


    Run it and do a System Scan, then post the log - We will tell you what to fix.


    Best of luck

  • thanx i have done that but i am computer dummy and need to have things explained what to do so i have copied and paste log :blink:


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 06:16:59, on 16/03/2008


    Platform: Windows XP SP2 (WinNT 5.01.2600)


    MSIE: Internet Explorer v7.00 (7.00.6000.16608)


    Boot mode: Normal


    Running processes:


    C:\WINDOWS\System32\smss.exe


    C:\WINDOWS\system32\winlogon.exe


    C:\WINDOWS\system32\services.exe


    C:\WINDOWS\system32\lsass.exe


    C:\WINDOWS\system32\Ati2evxx.exe


    C:\WINDOWS\system32\svchost.exe


    C:\WINDOWS\System32\svchost.exe


    C:\WINDOWS\system32\spoolsv.exe


    C:\WINDOWS\system32\Ati2evxx.exe


    C:\WINDOWS\Explorer.EXE


    C:\WINDOWS\ehome\ehtray.exe


    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe


    C:\WINDOWS\SOUNDMAN.EXE


    C:\WINDOWS\zHotkey.exe


    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe


    C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe


    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


    C:\WINDOWS\system32\ctfmon.exe


    C:\Program Files\Messenger\msmsgs.exe


    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe


    C:\Program Files\BigFix\bigfix.exe


    C:\Corel\Suite8\Programs\DAD8.EXE


    C:\WINDOWS\eHome\ehRecvr.exe


    C:\WINDOWS\eHome\ehSched.exe


    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS


    C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe


    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe


    C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe


    C:\Program Files\ErrorSmart\ErrorSmart.exe


    C:\WINDOWS\system32\dllhost.exe


    C:\WINDOWS\System32\svchost.exe


    C:\WINDOWS\eHome\ehmsas.exe


    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe


    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.co.uk/talktalk


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll


    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll


    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll


    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll


    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll


    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe


    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime


    O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE


    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe


    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE


    O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe


    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"


    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall


    O4 - HKLM\..\Run: [bitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"


    O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"


    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"


    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background


    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')


    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')


    O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe


    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe


    O4 - Global Startup: Corel Desktop Application Director 8.LNK = C:\Corel\Suite8\Programs\DAD8.EXE


    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1201289261531


    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab


    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe


    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe


    O23 - Service: lxcr_device - - C:\WINDOWS\system32\lxcrcoms.exe


    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS


    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe


    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe


    --


    End of file - 6123 bytes

  • Chesda
    Options

    jeffers,


    This application seems legit, but if you were unaware of downloading it it most likely be adware.


    Adware is not normally a threat, but is usually considered a nuisance. It might have been installed by another application. It can pop up advertisements even if you have a popup blocker on your computer. It can monitor your computer usage to generate ads that you are more likely to respond to. Adware can consume processing power and network bandwidth, thus slowing down your computer and interrupting your workflow.


    To remove it try Uninstalling it by going Control Panel, "Add/Remove Progams" and remove it.


    If you have any troubles uninstalling it Press "Ctrl"+"Alt"+del, Processes tab, Search for Errorsmart.exe and End the process before uninstalling.


    Best of luck

  • thanx i have removed it from control panel and checked windows explorer to see if it has gone....it hasnt and when i try to delete it it says its in use by another person or program...any ideas what to do next plz :unsure:

  • Niels
    Options

    Dear jeffers,


    Do you mean that all the program parts are still in the installation directory?


    Try this download windows installer cleanup. Install it start it afterwards see if you can see an entry called Error Smart or AntiSpyware LLC if present select the entry and press on remove confirm the warning.


    Best regards


    Niels

  • Dear jeffers,


    Do you mean that all the program parts are still in the installation directory?


    Try this download windows installer cleanup. Install it start it afterwards see if you can see an entry called Error Smart or AntiSpyware LLC if present select the entry and press on remove confirm the warning.


    Best regards


    Niels


    thanx for help it has now gone


    jeffers

  • Niels
    Options

    Dear jeffers,


    Good to hear that your problem is solved. You are welcome.


    Best regards


    Niels