MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal > Malware Removal FAQ
Register FAQ Members List Calendar Mark Forums Read

Malware Removal FAQ testing

Closed Thread
Thread Tools Rate Thread Display Modes
Old 10-05-05, 17:01
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 81,682
Thanks: 66
Thanked 8,191 Times in 4,526 Posts
Default Removing Zlob aka SmitFraud, SpySheriff, Infections

PLEASE NOTE: This is a generic procedure meant to cover multiple infection types which are typically classified as part of SmitFraud or Zlob infections.

This cleanup procedure should work for removing malware problems related to any of the below (and and many more):
  • AntiVirusGold
  • AntiVirusXP 2007. 2008, 2009
  • MalwareWipe
  • PSGuard
  • Search Maid
  • Security IGuard
  • Smitfraud
  • SpyAxe
  • SpyFalcon
  • SpySheriff
  • SpywareQuake
  • SpywareStrike
  • SystemAntiVirus 2008
  • Search Maid
  • Virtual Maid
  • Virus Response 2009
  • XPAntiVirus 2007, 2008, 2009
  • Zlob aka Trojan.Zlob aka Trojan-Downloader.Zlob.Media-Codec aka DNS Changer aka
Download SmitFraudFix to your Desktip from one of the below links and use the steps indicated for either link which are slightly different.

Primary Download Link: SmitfraudFix (by S!Ri)
  1. The above link is to a file named Save this file to your Desktop.
  2. Now double click the ZIP file on your Desktop and Extract the contents to your Desktop too. This will create a SmitFraudFix folder on your Desktop.
  3. Double click the SmitFraudFix folder to open the folder.
  4. There will be two parts to how we will use SmitFraudFix
    • Searching
    • Cleaning
  5. Double click the smitfraudfix.cmd file to start the tool.
  6. Now jump down to Step 1 below.
Alternate Download Link: SmitFraudFix (byS!ri)
  1. The above link is to a file named SmitFraudFix.exe. Save this file to your Desktop.
  2. There will be two parts to how we will use SmitFraudFix
    • Searching
    • Cleaning
  3. Double click SmitFraudFix.exe to extract all the files to your Destop. This will create a SmitFraudFix folder on your Desktop. And it will automatically start running the program..
  4. Now jump down to Step 1 below.
Note: process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.
STEP 1: Searching for the infection!
  • You should now see the below window on your monitor (click to enlarge the thumbnail).
  • Select 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt
  • Attach this current C:\rapport.txt log file to a message in your thread now before before doing the second step of the procedure or you will overwrite and loose this info. (See: HOW TO: Attach Items To Your Post )
STEP 2: Cleaning the infection!

Please print out or copy these instructions to Notepad as the internet may not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.
  • Reboot your computer into Safe Mode : Starting your computer in Safe mode
  • Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.
  • Select 2 and hit Enter to delete infect files.
  • You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
  • The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
  • A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt Don't forget to attach this new log to your next message after you finish running the cleaning step and reboot into normal mode.
  • While the tool is cleaning you will see a window like below:

SmitFraudFix has other optional steps that you do not need to run unless specified. They are:

Step 3 to Restore Trusted and Restricted Zones
Step 4 to Search for and Clean DNS Hijacks
"There are 10 types of people in this world. Those who understand binary and those who don't."

Support Majorgeeks on Facebook:

Majorgeeks Newsletter

Last edited by chaslang; 10-08-08 at 23:59.. Reason: Update list with a few common items
The Following 8 Users Say Thank You to chaslang For This Useful Post:
.:{KC}:. (10-07-08), 1611guy (01-01-09), ArsenicY (02-10-09), jonny_aces (07-20-08), la.newbie (03-28-09), Royhoo32 (11-05-08), skyff (01-06-09), urbanphoenix (11-22-08)
Sponsored links
Closed Thread

Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
need help removing Trojan.Zlob-X.a cld1122 Malware Removal 13 12-10-07 21:56
need help in removing Trojan Zlob-X.a mangoo Malware Removal 3 11-19-07 21:01
Removing SpySheriff without any Programme kertenkelle Malware Removal 1 12-30-05 20:41
Special Removal Procedures - Bagle, SmitFraud,Virtumonde,SpyAxe,Look2ME,Zlob chaslang Malware Removal 0 10-09-05 00:42
Smitfraud/Spysheriff Robyn Malware Removal 1 06-19-05 21:35

All times are GMT -5. The time now is 06:58.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds

All content Copyright source code Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger