smitfraud and pup

Discussion in 'Malware Help (A Specialist Will Reply)' started by taxximom, Aug 6, 2005.

  1. taxximom

    taxximom Private E-2

    My computer was infected with these about a month ago. I could not even get windows to load right. So, I took my computer to a professional. They removed smitfraud and pup supposedly. I have always had all the things suggested on my computer. Adaware, Norton anti-virus, spybot, spyblaster and even a firewall. Well my son late at night went to an objectional site and my computer got highly infected. I paid to get it fixed. It is running like a top. However, everytime I run spybot 37 entries in the registry show up for smitfraud-c that it cannot fix. Pup shows up and it fixes it. However, pup keeps coming back. I ran a Hijack this log and had it analyzed online. Absolutely everything is green. It did not find anything wrong. Spybot suggested running the program at restart. It keeps saying that it cannot fix the smitfraud-c values in the registry. Something about them being used or in memory. All 37 entries look about the same. What do you suggest I do?

    Here is an example of what one of entries say:

    Smitfraud C: User Settings (registry change, nothing done)
    HKEY_USERS\DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZineMap\Domains\awmdavest.com\*!=W=4

    Other then the .com they are the same.

    Pup read:

    pup: Autorun settings (devldr16.exe) (registry value, nothing done)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft Windows\Current Version\Run\devldr16.exe
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow our standard cleanup processes given below. Make sure you have the versions we indicate in the links and also make sure you have all updates.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. taxximom

    taxximom Private E-2

    I am still working on all the processes. I am typing this on another computer.

    I could not boot in safe mode "with networking support". I had four options to pick from. There was only one which said safe mode. I am working on ME. I did the scan in normal mode. Although it gave me issues until I turned my firewall off. I just wanted to make sure there wasn't something I was missing on how to boot in safe mode "with networking support". Do some computers not have this option?

    I guess I wasted my 135.00 having a professional fix this. It doesn't appear he got everything out of here.
     
  4. taxximom

    taxximom Private E-2

    I have done all the thing you have suggested. The 37 items still show up in spybot. When it tries to fix it, I get this message.

    Some problems couldn't be fixed; the reason could be that the associated files are still in use (in memory) This could be fixed after a restart.

    Same things happen when I restart. Could the computer Tech place have made a back up of my registry or something that these are showing up. I am not having computer problems other than Spybot cannot remove these entries.

    Here are the problems I ran into when running your instructions:

    I am current using ME. I could not find an option to run in safe mode "with networking support". The four options I got were. Normal, logged, safe mode and step-by-step confirmation. I had to run Bitdefender and RavAntivirus in normal mode.

    I copied and pasted the results from bitdefender. It had 1 virus it could not remove but I could not figure out what it was.
    RavAntivirus had no problems.
    Adaware quarantined three things (mru list, malware.psguard and whenu.desktop toolbar.
    I could not copy and paste the 37 entries from spybot. However, I have printed them and could try and scan them and attach them.
    I have attached the new hijack this log.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spybot has the ability to save logs. Just save the log and copy it back here as an attachment. What version of Spybot are you running and what is the date of the detections file?

    Please do not post Word documents. Just post plain text attachments (.txt or .logs) The document you attached from BitDefender is a little messed up (has to be manipulated to be viewed). It really shows no problems. Those AOL items are normal and are not problems. They seem to be false positives.

    If you have WeatherBug installed, uninstall it using Add/Remove programs. Either way, delete the below folder:

    C:\Program Files\AWS

    The devldr16.exe autorun item is more than like for your SoundBlaster audio card. Do you have a SoundBlaster card.

    The items that Spybot may be detecting are probably just items put in the Restricted Zone to block some bad websites. Based on the one example you gave, they are not Smitfraud related.
     
    Last edited: Aug 8, 2005
  6. taxximom

    taxximom Private E-2

    Yes I do have a soundblaster card. It came with the computer at the time.

    I have uninstalled weather bug. I haven't used it for years. I found it annoying.

    I think I found the log and attached it from spybot.

    Sorry about the word document.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have you (or anyone else) installed a program called IE-SPYAD on this PC?

    Do you have user logins on this PC or do you just default to everyone logging on to the same default account?
     
    Last edited: Aug 8, 2005
  8. taxximom

    taxximom Private E-2

    I have had different spywares and key logger to see what the kids were doing. I don't remember that paticular name. My son has been going places he is not supposed to. He has been forbidden to use the computer since this last episode. I now have it password protected, but it was not before. I think the software I got was called key key by mikotech. It came with other software. I only use the programs you recommended now. It doesn't mean that someone else didn't install it though. I did a search for files and folders called spyad and nothing came up.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Forget about IE-SpyAD. But answer my second question.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download the attached zip file and extract the fixdomain.reg file from it to your desktop and then follow the steps below.

    Then double-click on the fixdomain.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes

    Now checkout a scan from SpyBot.
     

    Attached Files:

  11. taxximom

    taxximom Private E-2

    I am sorry Chaslang. I thought I did answer it when I said I password protected it so the kids could not get on since this happened. I am the only user.

    I downloaded the tool. It worked perfect. Now the only thing that Spybot finds is pup which you said that is related to the soundblaster card.

    Thanks so much. You are the best. I think you need a raise!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes the file is for your SoundBlaster but I still wonder why Spybot is detecting it as a problem and it also states it is removing it. I went to a PC running WinMe that has that same file loaded for a SoundBlaster at startup and I do not see a problem with Spybot. I wonder if something is not correct in the registry setting. Let's try something.

    Click Start, Run, and enter regedit and click OK. This will run the registry editor. Now navigate to the below registry key.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

    With the above key selected, click File (on the upper menu) and select Export. Then give it a file name (like autoruns). This will save the info from the registry key to a file name autoruns.reg (the .reg is automatically added). Make sure you save it where you can find it. The either put the autoruns.reg file into a zip file to upload here as an attachment or rename the autoruns.reg file to autoruns.txt so you can upload it as an attachment.
     
    Last edited: Aug 9, 2005
  13. taxximom

    taxximom Private E-2

    Here is the file. Here I thought I was all done. That's what I get for thinking.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that looks okay! I still do not know why Spybot is complaining about it.

    At anyrate, now that we have you cleaned up, you should checkout the steps in the below thread:

    How to Protect yourself from malware!
     
  15. taxximom

    taxximom Private E-2

    Thanks Chaslang. Your help is greatly appreciated. I have all the things in your post. I read that already. You guys are definately the best. At least that is my opinion for what that is worth. Depends on who you talk to my kids or my spouse.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  17. taxximom

    taxximom Private E-2

    Chaslang,

    I was following the other post that seemed to have a similar problem. I think I saw another one that might have been showing similar items. I noticed your comment that an application may have done this. I wanted to give you this information on what I had done prior to this happening.

    Someone had installed the yahoo toolbar in my family. I always use the google toobar and it was gone. I uninstalled yahoo and reinstalled google.

    I had just upgraded my version of adaware and spyblaster. I had the current version of spybot and just updated it.

    I have the following on my machine and have had for some time.
    Norton firewall and antivirus
    Google tool bar
    Spybot search and destroy
    spyblaster
    adaware by lavasoft.

    I just thought I would give you any additional information in case this keeps happening to people. That way maybe you can nail down where it is coming from.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks but none of those are reasons for getting Smitfraud or Spysheriff type problems. I'm sure that they can be picked up at a large number of bad sites and that they can be installed when other baddies are installed.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds