i want to get rid of smithfraud.c

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by syrk, Sep 30, 2005.

  1. syrk

    syrk Private First Class

    spybot scans show that i have the smithfraud.c trojan. spybot however is not able to get rid of it. i have tried many resident and online scans but to no avail: the smithfraud.c trojan will not go away. i have tried the following: trend micro anti spyware, ewido security suite, norton av 2003, ad aware se personal, spybot, cwshredder, a squared, ms anti spyware beta 1, spyware doctor, panda, housecall, ravi. can you help me please. syrk
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please follow standard cleanup procedures as given below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above and you still have a problem, make sure you have booted to normal mode and run the steps below:



    [​IMG] Download HijackThis 1.99.1

    [​IMG] Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    [​IMG] Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    [​IMG]Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    [​IMG]Run HijackThis and save your log file.

    [​IMG] Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    [​IMG]Need help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. syrk

    syrk Private First Class

    bjgarrick,

    i was unable to run the scans on safe mode networking support. i guess i should take care of this problem later. otherwise everything went fine. i enclose a hjt log. thanx. syrk
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The READ ME FIRST states:

     
  5. syrk

    syrk Private First Class

    thank you chaslang. as i stated previously i have not been able to run these scans in safe mode but i did manage to run them in normal mode. syrk.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did they find anything?

    Attach a new HJT log for BJ to look at when he gets back!
     
  7. syrk

    syrk Private First Class

    i ran the online scans in normal mode since for some reason i'm not able to do it in safe mode with network support: bitdefender, stinger, trend micro house call, ravantivirus. all came out clean. then i ran the other scans all clean except for spybot which still shows smithfraud.c. i attach a new hjt log. thanx syrk
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think you should attach the log from Spybot too. This one sounds like it could be some registry entries that must be fixed.
     
  9. syrk

    syrk Private First Class

    chaslang, i need a clarification. when you say log from spybot, do you mean fixes.txt, resident log, or update downloads.log? thanx again. syrk
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spybot produces a log of what problems it finds when it runs a scan. That is what we need to see.

    Normally it is named: SpybotSD.Results.txt
     
  11. syrk

    syrk Private First Class

    chaslang, here's the log from spybot. thanx again. syrk
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the attached zip file and extract the fixdSF.reg file from it to your desktop and then follow the steps below.

    Then double-click on the fixSF.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.


    Then reboot your PC and run a new scan with Spybot. Let me know how things look.

    Note the below item in Spybot is not a problem:

    Windows Security Center.AntiVirusDisableNotify: Settings (Registry change, fixed)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0
     

    Attached Files:

  13. syrk

    syrk Private First Class

    chaslang, i have added the attached file to my registry and have run a spybot scan. spybot reports one "problem" (marked in bright red):windows security center.antivirusdisablenotify. i have not allowed spybot to fix it. i attach a new spybot log. thanx. syrk
     

    Attached Files:

  14. syrk

    syrk Private First Class

    chaslang, i dont know if this is related to my smithfraud.c problem but i just received an e-mail from post office which reads:

    "Your email account has been used to send a large amount of spam during the last week.Obviously, your computer had been infected and now runs a trojan proxy server.Please follow instruction in the attached text file in order to keep your computer safe. Have a nice day,wanadoo.fr user support team."

    i have not opened up the attached text file.

    what's your take on this.

    syrk
     
  15. syrk

    syrk Private First Class

    chaslang, sorry to pile more stuff on you as the sun is still sleeping on your side of the great pond. i ran the microworld av & spyware free online scan with the following results:
    1. cydoor.topics. a spyware/adware found in file system,
    2. 180solutions. a spyware/adware found in file system,
    3. gonnasearch. a spyware/adware found in file system,
    4. whenu.savenow. a spyware/adware found in file system, and
    5. cws.therealsearch. a spyware/adware found in file system.
    again. syrk
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would not run it. At least not without verifying that they actually sent it to you. And also ask them if it is still happening since you have already been working on cleaning things. What was the name of the attached file? I
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I know what Microworld is but I do not know what "spyware free online scan " is?

    It would be better if you posted the logs. Also since they do not clean anything, run Ewido which you already seem to have installed.
    • Launch ewido, there should be an icon on your desktop double-click it.
    • The program will have a window come up. One of the buttons on the left is to Update. Click the Update button.and then Start the Update. The update will start and a progress bar will show the updates being installed.
    • After it completes the update, click the Scanner button

    Now exit Ewido. Now print the below instructions or save them locally because I want you do have no browsers opened and also have no connection to the internet (unplug your cable) while doing the below.

    Okay, reboot into safe mode and follow the steps below. (If you have any problems at all trying to get into safe mode to complete these steps, just run them in normal boot mode and make sure you tell me when you come back.)

    Open up Ewido and do the following:

    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.

    Once the scan has completed, there will be a button located on the bottom of the screen named Save report

    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    Since you also have SpySweeper installed, I would also suggest running a full scan withit while in safe mode. Save its log too.

    Reboot into normal mode and reconnect to the internet.

    Come back here and post the Ewido Scan Report and the log from SpySweeper.
    Also post (you will need a second message) the log from Microworld.
     
  18. syrk

    syrk Private First Class

    chaslang, thanx for getting back to me. i scanned with bitdefender which reported that the attached file contained MyDoom so i deleted the e-mail and the attachment. seems to be a new scam method. i'll launch ewido tomorrow and get back to you. thanx again. syrk.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome! Never trust messages like this. Even if they look valid, they should be questioned first.
     
  20. syrk

    syrk Private First Class

    chaslang, i just finished running ewido and spysweeper scans (safe mode with cable unplugged): ewido came up empty handed meanwhile spysweeper zapped sdbot trojan horse (i attach the log from spysweeper). i will run microworld tomorrow. thanx. syrk
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Looks like everything is in pretty good shape now. Are you having any other malware problems?
     
  22. syrk

    syrk Private First Class

    chaslang, i've not been able to send the complete log from microworld given its incredible size (18.9 mo) so i'm sending you what i call the summary of the scan. according to microworld av & spyware toolkit utility i've got 15 viruses/spywares/adwares and a total of 159 errors (i've no idea what an error is) : cydoor.topics; 180solutions; gonnasearch; easysearch; whenu.savenow; cws.therealsearch. thanx. syrk
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most of what you posted in the summary appears to be false positives. Some point to files related to your NBA game just because the filename is the same as that of malware. That is poor programming on Microworlds part. I would not be too concerned about them. What version of the scanner are you running?

    But just as a safety net, try scanning and fixing problems using the below (save a log to post too):

    Spy Sweeper
     
  24. syrk

    syrk Private First Class

    i'm running microworld's version 7.2.2, virus signuture 27.09.05. i'm attaching the latest spysweeper log which looks clean to me. thanx a lot. syrk
     

    Attached Files:

  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! You can uninstall SpySweeper if desired or keep it (it's up to you). I find it to be pretty good.

    Okay so other then what Mircoworld was saying, how is everything working?
    If everything is working well then you should work through the steps in the below sticky:

    How to Protect yourself from malware!
     
  26. syrk

    syrk Private First Class

    chaslang, what do you suggest i do about *windows security center antivirus disable notify* which shows up everytime i run spybot? syrk
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Read the end of message # 12 again!
     
  28. syrk

    syrk Private First Class

    chaslang, i ran a new scan called *pest patrol* and it found cydoor.topicks spyware.

    Adware "Cydoor.TOPicks.a" found in:
    key "hkey_classes_root \interface\{ce9b37ec-d243-47a2-83db-3a8350175193}"

    key "hkey_local_machine \software\classes\interface\{ce9b37ec-d243-47a2-83db-3a8350175193}"

    syrk
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! That registry was also mentioned in your Mircoworld log and I thought maybe it was a false positive related to all the stuff for:

    C:\Documents and Settings\utilisateur\Mes documents\nba live 2004

    Is this a legal copy of this game? Or did you install a cracked illegal version from somewhere? This program may be the source of your infection and may have to be uninstalled. According to Microworld the below registry key and files should be deleted.
    However again, I have to emphasize that it is possible that the file being named could be legit and just part of that game. If the game is legal, I would be less concerned. Even the last index.html file seems to be legit from Dell. But the two registry keys are more than likely from Cydoor and should be deleted. Tell me what you would like to do.


    HKEY_CLASSES_ROOT\interface\{ce9b37ec-d243-47a2-83db-3a8350175193}
    HKEY_LOCAL_MACHINE\software\classes\interface\{ce9b37ec-d243-47a2-83db-3a8350175193}

    C:\WINDOWS\DOWNLO~1\conflict.1
    .
    C:\WINDOWS\system32\start.cdi

    C:\Documents and Settings\utilisateur\Application Data\opera\opera\profile\toolbar

    C:\Documents and Settings\utilisateur\Mes documents\nba live 2004\saves\001\settings.dat

    C:\Documents and Settings\utilisateur\Mes documents\nba live 2004\saves\002\settings.dat

    C:\Documents and Settings\utilisateur\Mes documents\nba live 2004\saves\005\settings.dat

    C:\Documents and Settings\utilisateur\Mes documents\nba live 2004\saves\006\settings.dat

    C:\Documents and Settings\utilisateur\Mes documents\nba live 2004\saves\007\settings.dat

    C:\Documents and Settings\utilisateur\Mes documents\nba live 2004\saves\008\settings.dat

    C:\Documents and Settings\utilisateur\Mes documents\nba live 2004\settings\settings.dat

    C:\Documents and Settings\utilisateur\Local Settings\application data\dell\solutioncenter\index.html
     
    Last edited: Oct 9, 2005
  30. syrk

    syrk Private First Class

    chaslang, thanx for getting back to me. this is a legal copy of the game. syrk
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Well according to a few sources the below registry keys are from CYdoor


    HKEY_CLASSES_ROOT\interface\{ce9b37ec-d243-47a2-83db-3a8350175193}
    HKEY_LOCAL_MACHINE\software\classes\interface\{ce9b37ec-d243-47a2-83db-3a8350175193}

    But I find it rather strange that at the same time, your scans are also picking up Cydoor in a bunch of other places. If we remove these registry keys and they are related to your game, it could break the game. You could do a registry backup first, and then fix them. What would you like to do?
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure you ran Ewido as directed earlier? You said it came up clean. Ewido normally detects and removes this. It will find it as something like:

    HKLM\SOFTWARE\Classes\Interface\{CE9B37EC-D243-47A2-83DB-3A8350175193}\ProxyStubClsid32\\ -> Spyware.P2PNetworking : Cleaned with backup
     
  33. syrk

    syrk Private First Class

    chaslang, let me run ewido again just to make sure. syrk
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! Are your Ewido detections up to date?

    Let's backup your regstry. Download, install, and run: Erunt to make a backup. Then if necessary we will delete those registry keys.
     
  35. syrk

    syrk Private First Class

    chaslang, following your instructions i ran ewido and still no sign of cydoor. syrk
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! But did you use Erunt to backup your registry. If so, do the below:

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixcyd.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixcyd.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes
    Now see if your scans are clean!
     
  37. syrk

    syrk Private First Class

    sorry chaslang but something is not clear to me:
    "copy the contents of the below quote box to notepad": understood.
    "then click file and save as. change the save as type to all files". not understood. please clarify. syrk
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click File, click Save As, and then in the next window there is box labeled "Save As Type" change this to All Files. Otherwise instead of getting a filenamed fixcyd.reg you will get fixcyd.reg.txt which cannot be merged into the registry by double clicking on it.
     
  39. syrk

    syrk Private First Class

    chaslang, i have not had time to run your procedure to rid myself of cydoor.topicks spyware. in the meantime i have noticed something very unusual to say the least: my c:\\program files\google folder has grown in size to 19,941 files and 21.4 go. all the files are identical except one: file type tmp, size 1.10 mo. all except one were created on october 5 and 6. chaslang.....help! syrk
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are 'go' and 'mo" abbreviations you use in France for kb (kilobyte) and mb (megabyte)?

    I'm not sure what you are seeing in your Google folder. I do not use it but I'm not sure why they would be downloading files there. What it the Google folder for? Is there for Google Toolbar?
     
  41. syrk

    syrk Private First Class

    e.g., 21.4 Go = 23,073,038,336 octets.

    there are 19,941 files inside the google folder, each one of them is 1.10 Mo in size.

    the oldest file in the folder is indeed the google client ie toolbar file.
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So you use the term octets instead of byte.

    If you do not know what these files are, I would suggest uninstalling Google Toolbar for now and deleting that folder. You can always reinstall later.
     
  43. syrk

    syrk Private First Class

    done. i uninstalled google toolbar and deleted the folder. i will next tackle cydoor.topicks.a. byte (bite) is not a nice word in french. thanx again chaslang. syrk
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let me know the results of trying what I gave you in message # 36.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds