Need help about Smitfraud-c

Discussion in 'Malware Help (A Specialist Will Reply)' started by riot21, Oct 24, 2008.

  1. riot21

    riot21 Private E-2

    I've got infected at the beginning of this week. So i tried a lot of things to fix it before arriving. I used Spybot to clean up the mess made by smitfraud, but even he say he has done the job, i always get a alert.

    So i tried to follow the Cleaning procedure, so here's my logs. But there's still something in my computer.

    Its my first time to encounter such thing so help me. I want to know how its going and what to do next.
     

    Attached Files:

  2. riot21

    riot21 Private E-2

    here's the MGtools logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0
    Viewpoint

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now use windows explorer to find and delete:
    C:\Documents and Settings\All Users\Application Data\wxqxyhmj
    C:\Documents and Settings\All Users\Application Data\Viewpoint
    C:\WINDOWS\system32\iulspmux.ini

    Reboot and see if those folders/files are gone. Then download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds