Difficulty Removing SmitFraud-C.gp, tried doing the Readme Fix to no avail

Discussion in 'Malware Help (A Specialist Will Reply)' started by Caek, Nov 9, 2009.

  1. Caek

    Caek Private E-2

    Hey guys I've posted once before when I had a previous infection and all went well, however I have this new Smitfraud-C.gp infection which I presume got introduced through my little brother's haphazard surfing. I've tried the works, and it seems like this thing is very situation-exclusive so I'm going to share my logs with you guys. The only program that can detect (but not remove) the infection is Spyware S&D, so I'll include that log as well. Thanks for the attention :)
     

    Attached Files:

  2. Caek

    Caek Private E-2

    Here's the rest :
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please remove MGtools.exe from the below folder. It does not belong here.
    C:\Documents and Settings\CHEESECAEK\My Documents\Downloads\MGtools.exe

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. Caek

    Caek Private E-2

    Sadly, I ran the S&D again and Smitfraud-c.gp is still running amok. It shows in my pc's performance as well, but here are the logs.
    I appreciate everything so muchhhh
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually this is not a correct assessment. It is not running amok. It is not running at all. This is just a dead/orphaned registry key that has been locked.



    let's try another tool!
    1. Download RegASSASSIN.
    2. Unzip the file to your desktop. You will have a new desktop icon named RegAssassin.exe
    3. Reboot your computer into SAFE MODE
    4. Once in SAFE MODE, double click on the RegAssassin icon to open the program.
    5. Checkmark the options "Reset Permissions" and "Delete Registry Keys and all Subkeys".
    6. In the registry key window carefully copy and paste in the below
      • HKEY_CLASSES_ROOT\CLSID\{df8c3aed-b58e-4bcb-96b3-aa1b7bbdbbd4}
    7. Click on Delete hot button. Tell me if you get any error messages
    8. Reboot into Normal Mode.
    9. Attach a new log from Spybot if it still detects it.
     
  6. Caek

    Caek Private E-2

    I received an error message saying RegASSASSIN couldnt delete it. What now o captain?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you have Norton 360 shutdown? It could be interferring. Also did you try deleting it in safe boot mode as suggested?

    If RegAssassin did not work, the only other methods to try are more complex and the first may also fail and the second would require much work to create a special boot CD.

    Here is the first method to try.

    Please download and install Registrar Lite

    Run Registrar Lite navigate to each of the following key and take ownership of it (I explained how to do that further down).

    HKEY_CLASSES_ROOT\CLSID\{df8c3aed-b58e-4bcb-96b3-aa1b7bbdbbd4}



    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the Address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the top Menu
    • Select Take Ownership
    • Now leave RegistrarLite running and continue
    • Now run the fixME.reg REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate to the above keys we took ownership of to make sure it was deleted.
    • If the key still exists, move on down to PART 2 - Setting Permissions for Everyone below!.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    PART 2 - Setting Permissions for Everyone
    Run the below if some of the registry keys still exist after running the above steps.

    Now I want you to use Registar Lite again to navigate to the below key by pasting it into the Address Bar and hitting return. But this time click the Security menu item and select Edit Permissions so we can change permissions to everyone ( I describe this down below the list of registry keys).
    After clicking Edit Permissions , here is what I expect you to see in the Group or user names area of the form:

    Everyone
    SYSTEM

    Select Everyone by clicking on it. Now at the bottom in the Permissions box click the check box for Full Control. The click Apply and then OK to get back to the main Registrar Lite screen. Nowright click on the registry key and select Delete. The click View and Refresh. Check to see if the registry key just deleted truly deleted. If it does not delete, I want you to boot into safe mode and repeat these exact same steps to see if we can do it from safe mode.

    Then reboot your PC!

    Now run Spybot again and attach a new log!

    =================================

    The remaining method to try if all of the above has still failed is even more complex and required creating a special CD to run that allows you to boot your PC to a Windows like environment but you are not really running Windows. Then you can use built-in tools to edit the registry. The CD I'm referring to is the below and you will need your Windows boot CD inorder to create this CD.

    UBCD4Win
     
  8. Caek

    Caek Private E-2

    So the registry key was successfully deleted (I did not have to go to part 2), but as you'll see in my logs it seems that smitfraud-c.gp is still there. What baffles me is that even though we deleted the aforementioned, it comes up during the S&D scan. Here's the log, but I cant attach it because it's over the limit :


    --- Search result list ---
    Smitfraud-C.gp: [SBI $13C1E5FA] Class ID (Registry key, fixing failed)
    HKEY_CLASSES_ROOT\CLSID\{df8c3aed-b58e-4bcb-96b3-aa1b7bbdbbd4}
     
    Last edited by a moderator: Nov 19, 2009
  9. Caek

    Caek Private E-2

    Sorry emergency :

    I forgot to get rid of a space after pasting the registry key in for the second time, and it was still there so I went to Part 2, did what was asked and here is a list of what is shown in the Group or user names area :

    Administrators (SIL\Administrators)
    CHEESECAEK (SIL\CHEESECAEK)
    CREATOR OWNER
    Everyone
    Power Users (SIL\Power Users)
    SYSTEM
    Users (SIL\Users)




    How should I proceed from here?
     
    Last edited: Nov 15, 2009
  10. Caek

    Caek Private E-2

    Hey guys, just wanted to inform you that I found help from another analyst and everything is taken care of.
    I still wanted to thank you all for helping this poor sap out to the very end :)
    Peace <3
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Glad to hear you got it fixed.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds