AntiVirus XP 2008, SmitFraud.c, probably others..

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cde4307, Sep 27, 2008.

  1. cde4307

    cde4307 Private E-2

    OK, this little laptop got hit and exhibited the properties similar to the smitfraud descriptions that I've read (screensaver with spyware warning, disabled the display property tabs).

    From there, I ran a registry key to get the screen saver back, and ran an AntiVir scan and a updated SpyBot scan in Safe mode, each turning up something (spybot turned up a smitfraud.c detection and AntiVir had a few detection of trojans... Sorry, don't have the description since I deleted the quarantine folders).

    During the scans in the 'READ & RUN ME FIRST' guide SAS turned up 'Rouge.AntiVirus XP 2008' and 'Trojan.FakeAlert/Desktop', then MBAM turned up 'Rouge.Multiple', so I'm guessing this was infected even before I got my hands on it.

    Everything ran without error and SAS and MBAM said they cleaned up their respective infections, but I'd appreciate it if someone could look over these logs and let me know what additional actions should be taken. Also, am I OK to move the files I have saved (mostly .doc documents and images underneath 'My Documents') to an clean external drive?

    Logs attached.

    Thanks in advance and a big thumbs up to your excellent guides. They were very helpful!
     

    Attached Files:

  2. cde4307

    cde4307 Private E-2

    Attaching MGLogs.zip...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs look clean.

    The only thing you need to do is download and install:
    Java Runtime 6

    Now we can clean up:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you get a success message, then it is time to do our final steps:
     
  4. cde4307

    cde4307 Private E-2

    Yup. Got the confirmation message and rebooted. Everything looks good!

    Thanks again for your help!
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds