HELP!! SmitFraud Removal for Tommy

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tommy2tone_1999, Mar 27, 2008.

  1. tommy2tone_1999

    tommy2tone_1999 Private E-2

    I have run SmitFraudFix to search, and here is the log. Please help me if you can. Is it ok to run SmitFraudFix to clean now?:confused. Also I am unable to log in in Safe Mode because of network restrictions where I work. Can I run in Normal Mode?
     

    Attached Files:

    Last edited: Mar 27, 2008
  2. tommy2tone_1999

    tommy2tone_1999 Private E-2

    I went ahead and ran SmitFraudFix in Normal Mode. Attached is the log. Say a prayer :)
     

    Attached Files:

  3. tommy2tone_1999

    tommy2tone_1999 Private E-2

    Well I found out how to run in Safe Mode (with Networking this time). So I ran SmitFraudFix to detect, then to clean, but I still have the trojan. Attached are my 2 logs. Any advice?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. tommy2tone_1999

    tommy2tone_1999 Private E-2

    Ok I have removed unwanted programs, Run the cleanig program you suggested, and have run a search with SmitfraudFix (not a cleaning step yet). Attached is the search stage log. Vundo has also appeared this morning. Your help is greatly appreciated.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You already did the SmitFraud steps in your first messages. I want you to continue on with the rest of the main body of the READ & RUN ME.
     
  7. tommy2tone_1999

    tommy2tone_1999 Private E-2

    I have run all of the steps of READ & RUN ME ( only exception was that I was not able to find the Quarantine folder for Trend Micro Office Scan - all other quarantine items have been cleared), and I still have IE Windows popping up offering various services from investments to dating porn stars. None of the steps has stopped the file core.cache.dsk from reloading after startup (I started in Safe Mode following the last step of READ & RUN ME, and it was not present, but when I start in Normal Mode, it appears). Thanks for your assistance so far. Do you have any other advice?
     
  8. tommy2tone_1999

    tommy2tone_1999 Private E-2

    Got ahead of myself. I'll try running the alternate scans first and get back to you
     
  9. tommy2tone_1999

    tommy2tone_1999 Private E-2

    I did a little google research and found that core.cache.dsk never runs alone, it always has a partner to reinstall it in the event of removal. The file is sometimes called "core.sys", but in my case, core.sys disguised itself. It renamed itself as a sys file in the same directory as core.cache.dsk (c:\windows\system32\drivers\). In my case it was WudfRdd.sys, created at the same date/same time as the infection occurred. It was almost identical to another file WudfRd.sys, except for the repeated last character. Look for this trait. I then ran avenger and in the window I typed

    Files to delete:
    c:\windows\system32\drivers\WudfRudd.sys
    c:\windows\system32\drivers\core.cache.dsk

    I also checked "Scan for Rootkits", clicked Execute and ran it. I was instructed to reboot, and did. So far so good. If this doesn't work I'll pick up where I left off.

    Thanks for all your help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't want you to run the Alternate Scans. I only want you to do what was requested in the READ & RUN ME if still having problems. It specifies that you need to attach the logs from running various scans. The below is a quote from the Windows XP Cleaning procedure:
    If you have not done the above, then you have not completed the READ & RUN ME.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds