Advice on SmitFraud/ MalwareWipe

Discussion in 'Malware Help (A Specialist Will Reply)' started by Biw, May 30, 2006.

  1. Biw

    Biw Private E-2

    Hi i'm new so be gentle please!

    I have been recently plagued by pop ups and spyware.
    I am using Mozilla Firefox but get pop ups from IE when i'm not even running it. I inadvertently clicked on a warning triangle in my tool tray which opened up MalwareWipe which I have subsequently found to be suspect! I ran Malwarewipe (I know, i'm stupid!) and it told me I have a smitfraud virus.

    I have searched the forums but cannot find any examples of these problems.

    Any help greatly received,

    Many thanks

    Bill
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. Biw

    Biw Private E-2

    Thanks Chas. I was looking on the site whilst on work time so wasn't able to look very well I admit LOL.
    I'll give those a go and get rid of this darned spyware! I had a problem with a CWS Hijack a while back and used the excellent methods from Major Geeks so should be able to manage these pesky things.

    I'll let you know how I get on!

    Many thanks

    Bill
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem Bill! Let me know if those steps work for you and attach the requested logs too.
     
  5. Biw

    Biw Private E-2

    Hi Chas
    I ran everything and all the spyware went away, but I think (ok I know) that I didn't turn off system restore in safe mode and its all back again LOL!

    I'm going to do a total reclean tomorrow and will post logs etc then.

    One question I have is this though; Once you have saved the reg file to your desktop, (in the Malwarewipe removal procedure) it says this in the instructions;

    "Now copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixmwipe.reg and then click save. it to your Desktop. We will use it later after a reboot into safe mode."

    But it doesn't say to do anything with the regfile after. Am I missing something? I clicked on the file in safe mode and it changed the registry files. Was that correct? It seemed to work:)

    Thanks again

    Bill
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for pointing that mistake out! ;)

    It has now been fixed to read as below:
     
  7. Biw

    Biw Private E-2

    Hi Chas
    Strange as this may seem, I booted up my PC at the weekend, my AVG kicked in and discovered a virus. I clicked to 'heal' it and it appears to have sorted out my malware problem! It also healed a 'zlob' file which i believe was to do with the pop ups i was experiencing. All seems to be fine. :confused:

    Could AVG have 'caught up'? If so, how well do you think my problem been sorted.

    Would you recommend I still scanned/ cleaned my system? ( I think thats probably a no-brainer, right?)

    Thanks again

    Bill
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Zlob is the Smitfraud family of issues and it is why I was asking you to run SpywareQuake & SpyFalcon Removal Procedure

    I recommend you still run the above SpywareQuake procedure and attach the smitfiles.txt log that is requested. None of the antivirus programs have been too good at keeping up with the growing number of problems files related to the SmitFraud family.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds