MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 04-29-08, 04:26
stuffeditup stuffeditup is offline
Private E-2
 
Join Date: Dec 2006
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Default Help Removing Smitfraud-C.gp

Hi I have run Smitfraud, spybot and adaware, and Hijack this but I still have 3 instances of the Smitfraud-C.gp. This started in google and I do not know what he managed to download before I got home.

Seriously I need help before he starts using my Laptop and stuffs this up

Hijack Log

Last edited by TimW; 04-29-08 at 13:12.. Reason: Removed inline HJT log..Read and Run First now followed.
Reply With Quote
Sponsored links
  #2  
Old 04-29-08, 13:13
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,715
Thanks: 449
Thanked 4,656 Times in 4,395 Posts
Default Re: Help Removing Smitfraud-C.gp

Welcome to Major Geeks!

Please uninstall HJT as it will be properly installed when you do the following:

Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

READ & RUN ME FIRST. Malware Removal Guide
Reply With Quote
  #3  
Old 04-29-08, 21:13
stuffeditup stuffeditup is offline
Private E-2
 
Join Date: Dec 2006
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Help Removing Smitfraud-C.gp

Well I think I may have done it since running the SAS program and removing the infections then running Spybot the Smitfraud seems to be gone.

So do I continue running the rest or stop here. Also the MGtools.exe did not download I only recieved a attachment.php.

One last thing how is he getting these things in his computer. He had a straight Smitfraud a few weeks ago then this one, and he had only visited YouTube, Weatherbom and Adelaide airport the day before he got it.
We run Spybot, AVG spyware and antivirus, and I have left the SAS antispyware running as well now.

Thanks in advance
Attached Files
File Type: txt SAS Log - 04-30-2008.txt (6.4 KB, 3 views)
Reply With Quote
  #4  
Old 04-30-08, 14:38
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,715
Thanks: 449
Thanked 4,656 Times in 4,395 Posts
Default Re: Help Removing Smitfraud-C.gp

I would suggest that you do the rest of the requested step .....what exactly happened when you downloaded MGTools?

If you want a clue as to where it is coming from:
SAS log:
Known Threat Sources
C:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\KTAHAX87\ajax[1].htm
C:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\H9SKL4WX\errorhandler[1].htm
Reply With Quote
  #5  
Old 04-30-08, 19:19
stuffeditup stuffeditup is offline
Private E-2
 
Join Date: Dec 2006
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Help Removing Smitfraud-C.gp

Ok Tim,
I had already gone ahead and run the Malawarebytes AntiMalaware, but I stopped before running the CCleaner as I was a bit wary of the 1/100 computers failing.

Anyway back to the download of MGTools.

All that downloads is a PHP file.

attachment.php

I have included the mbam log which fould a few more spots of trouble and I ran Spybot again. At the moment he can use the Internet and the computer and I will be checking those files are gone when I get home. Also looking at those files does thos mean he still runs IE5 not version 6 as I thought.
And if all this fails would a complete Harddrive format work, all of our document were backed up last week so it is an easy thing for me to do.
Attached Files
File Type: txt mbam-log-4-30-2008.txt (2.1 KB, 1 views)
Reply With Quote
Sponsored links
  #6  
Old 05-01-08, 00:33
stuffeditup stuffeditup is offline
Private E-2
 
Join Date: Dec 2006
Posts: 15
Thanks: 0
Thanked 0 Times in 0 Posts
Default Re: Help Removing Smitfraud-C.gp

Add another on, I thought we were clear. ( I still haven't run the Ccleaner yet)
But we have found that most of the Internet is clear, but when he hits YouTube it all goes to hell again.
I have upgraded him to IE7
I also could not find the 2 files??
C:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\KTAHAX87\ajax[1].htm
C:\Documents and Settings\Terry\Local Settings\Temporary Internet Files\Content.IE5\H9SKL4WX\errorhandler[1].htm
Reply With Quote
  #7  
Old 05-01-08, 11:19
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 46,715
Thanks: 449
Thanked 4,656 Times in 4,395 Posts
Default Re: Help Removing Smitfraud-C.gp

You ran MalwareBytes but didn't have it fix anything. It shows you are infected....and without logs or having fixed anything with MWB's I cant advise you on what to do. If you feel it would be no trouble to reformat.....go ahead.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Need Help Removing Smitfraud-C.gp Darth_Thomas Malware Removal 9 04-26-08 22:25
problem removing smitfraud zfrangi Malware Removal 3 03-28-08 00:51
removing SmitFraud,etc. post w/attachment Horselady21 Malware Removal 1 03-20-08 11:58
Removing smitfraud martyb688 Malware Removal 5 01-01-08 20:56


All times are GMT -5. The time now is 01:59.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


All content Copyright MajorGeeks.com source code Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger