SmitFraud-C.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Glo, Sep 28, 2006.

  1. Glo

    Glo Private E-2

    Hello,
    I hope you can help me. Spybot S&D reports finding Smitfraud-C, which it is unable to remove.

    here are the steps I have taken:

    1. SmitRem.exe on all sign-ons in safemode with network plug pulled.

    2. Make sure hidden system and files extnesions are visible.

    3. Assure CA VS quarantine file is empty

    4. CClenaer on all logons

    5. Spybot again --saved log

    6. Windows Defender

    7. Windows Malicious Software Removal tool

    8. CounterSpy twice as it downloaded updates after first run. Both logs lumped as one; newer logs at top of report. This tool found more nogood stuff!!!

    9. While I have latest Sun Java and IE6, neither Bitdefender (Message= "could not load the Online Scanner") nor Panda Activescan (asks me to click the bar which does not appear) would run.

    10. Followed instructions in Spyware, SmitFraud, SpySherriff, SpyAxe & PSGuard Removal thread. HJT did not display any of the items indicated in the thread. None of the find and delete files or folders were found on my system.

    11. getrunkey and newfiles

    12. Run Spybot S&D again. Smitfraud-c. still appears and cannot be fixed.

    As a side note: Spybot S&D finds and fixes these three itmes, but they reappear next scan:

    MediaPlex (cookie)
    Microsoft.WindowsSecurityCenter_disabled (registrykey)
    Windows.ActiveDesktop (registrykey)

    Symptoms: Seems like my browser does not always visit the URL I key in.

    Three files attched. I will post repley with second three files.

    Thank you.
     

    Attached Files:

  2. Glo

    Glo Private E-2

    Three additional logs attached re SmitFraud-C.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow the directions in the READ & RUN ME properly! You are using a Spybot version that is two years out of date. Uninstall the old version of Spybot, then reboot, then after reboot delete the C:\Program Files\Spybot - Search & Destroy folder.

    Now please follow the directions in the READ ME and install the version of Spybot in the READ ME. Make sure you update it, configure as requested and then do a full scan. Attach a new log from it.

    Is CounterSpy only the free trial from the READ ME? If so, uninstall it to avoid conflicts with Windows Defender.

    I see a folder for Spyware Doctor. Has Spyware Doctor been uninstall? If so, delete the folder for it (C:\Program Files\Spyware Doctor).

    I see left over McAfee software? Did you uninstall it?

    Delete the below folder:
    C:\Program Files\Common Files\{AC9CFFDE-0D40-1033-0715-050405120001}
     
  4. Glo

    Glo Private E-2

    Now please follow the directions in the READ ME and install the version of Spybot in the READ ME. Make sure you update it, configure as requested and then do a full scan. Attach a new log from it.

    Done -- says my puter is clean. Thank you!
    I truly thought I had the most recent version of Spybot S&D installed. With maintaining five computers, it is easy to get mixed up.

    Is CounterSpy only the free trial from the READ ME? If so, uninstall it to avoid conflicts with Windows Defender.

    It is free trial. It had now been uninstalled.

    I see a folder for Spyware Doctor. Has Spyware Doctor been uninstall? If so, delete the folder for it (C:\Program Files\Spyware Doctor).

    I have uninstalled and deleted.

    I see left over McAfee software? Did you uninstall it?

    It is uninstalled. I think I have deleted all leftover folders. What about a folder called MFInstall? Is that part of McAfee?

    Delete the below folder:
    C:\Program Files\Common Files\{AC9CFFDE-0D40-1033-0715-050405120001}


    Done
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No MFinstall is not part of McAfee! We do need to clean up a bunch of left overs from McAfee. And also another malware component.


    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to McAfee Real-time Scanner ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above stop and disable for the following services:
    McAfee SystemGuards
    Microsoft WMI Performance Adapter AddOn

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    McShield

    Now repeat the Delete NT Service steps for:
    McSysmon
    WMIPerAddOn

    If you receive any error messages just ignore them and continue.

    Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O4 - HKLM\..\Run: [0266611154340945mcinstcleanup] C:\DOCUME~1\Gloria\LOCALS~1\Temp\026661~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog
    O4 - HKLM\..\Run: [0086701155900796mcinstcleanup] C:\DOCUME~1\Gloria\LOCALS~1\Temp\008670~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,99/mcinsctl.cab
    O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://mvt.mcafee.com/mvt/cab/mvt.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Program Files\McAfee <--- the whole folder
    C:\WINDOWS\wmiapsrv.exe

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.
     
  6. Glo

    Glo Private E-2

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to McAfee Real-time Scanner ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    [​IMG]

    Tried all three start-up types with same result. Had to click cancel to get out.


    Now repeat the above stop and disable for the following services:
    McAfee SystemGuards
    Microsoft WMI Performance Adapter AddOn


    Done

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    McShield


    Was it ok to have this browser open? You asked me to copy and paste. Received this error.

    [​IMG]

    Went back to services.msc and tried again with same error as above.

    I will post this now. close this browser. Try HJT again with no browser open.

    I will post again if successful. Otherwise, I have stopped at this point waiting for your go ahead.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please complete all instructions! Remember I did say to ignore error messages.

    If you were trying to attach images of messages, you did not attach anything.
     
  8. Glo

    Glo Private E-2

    Here is hjt log and two error messages from previous post.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try fixing the below service one more time:

    McAfee Real-time Scanner

    And then have trying having HJT delete the McShield service. If this still does not work, look for the below folder and tell me if it exists.

    C:\Program Files\McAfee

    If it does exist, what files/folders are found in it. Does the below folder exist in it?

    C:\Program Files\McAfee\VirusScan

    What files are under the VirusScan folder? Try manually deleting all of these McAfee files and folders. Tell me what error message you receive (if you get any).
     
  10. Glo

    Glo Private E-2

    Ok. I gave it another go after rebooting and again in safe mode with same errors you see posted previously. There are no mcafee folders in Program files or root.

    Here is the McAfee history on this machine:
    This is a Dell which came with mcafee free trial. When I upgraded to newest McAfee security center, I was not able to perform some tasks -- upload through Dreamweaver, for example. I contacted McAfee, they emailed me five programs designed to completely eliminate traces of Dell/McAfee installation. I ran those fovie programs. Reinstalled new Security Center. Still could not perform all regular tasks. So I uninstalled the security center and installed CA EZAntivirus.

    BTW -- Now Windows does not shut down. Mouse freezes on desktop and I have to press the button to turn off the machine.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well obviously their tools do not work! ;)

    Let's try a different approach.

    Please run Notepad and copy the following text into a new file:
    Save the file to the desktop as remove.bat and make sure the "Save as type" field says "All files".

    Next, please reboot your computer in Safe Mode.
    Once in safe mode, locate the remove.bat file on your Desktop and double click on it.
    Let me know if you receive any error messages.
    After running the remove.bat file, reboot and attach a new HJT log.
     
  12. Glo

    Glo Private E-2

    Ran the bat. Did not recieve any error message. New HJT log is attached.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but the fix still did not work.

    Download the Registry Search Tool

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection in your antuvirus program, please allow this to run)

    In the dialog that opens enter the following:

    McShield

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and copy the contents of the WordPad window and attach it to this thread.
     
  14. Glo

    Glo Private E-2

    Ok. Here is the RegSearch log. It sure did find the word McShield quite a few times. What next?
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to each of the following keys (one at a time) and take ownership of them (I explained how to do that further down).

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCSHIELD
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\McShield
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MCSHIELD
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\McShield
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCSHIELD
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\McShield

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Take Ownership
    • Repeat these steps for all of the registry keys given above before continue to the next steps below.
    • Now leave RegistrarLite running and continue
    • Now run the fixME.reg REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigateone at a time to each of the above keys we took ownership of to make sure they were deleted.
    • If any of the keys still exist, right click on it and select Delete. Let me know if you have to do this and if you get any error messages at this point.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Then reboot your PC!

    Now repeat the search using RegSrch and attach a new log.

    Also attach a new HJT log
     
  16. Glo

    Glo Private E-2

    # Now navigate one at a time to each of the above keys we took ownership of to make sure they were deleted.
    # If any of the keys still exist, right click on it and select Delete. Let me know if you have to do this and if you get any error messages at this point.


    Results:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCSHIELD
    access denied

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\McShield --gone

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MCSHIELD
    access denied

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\McShield -- gone

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCSHIELD
    -- access denied

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\McShield --gone
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But did you get the error while taking ownership or while trying to delete?


    Repeat the steps but this time we will take ownership at a higher level in the registry key path. Sometimes this is necessary.

    So take ownership at these keys:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet

    If you get an error message while trying to take ownership, give me the message.

    And then try to delete the below keys:

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MCSHIELD

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MCSHIELD

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MCSHIELD


    If you get an error message while trying to delete, give me the message.


    If the above fails, repeat the steps after booting in safe mode.


     
  18. Glo

    Glo Private E-2

    No instances found!

    We did it!

    thank you
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    3. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds