Smitfraud-C.generic found srvhost.exe suspicous

Discussion in 'Malware Help (A Specialist Will Reply)' started by cegan24, Mar 25, 2013.

  1. cegan24

    cegan24 Private E-2

    3 days ago SpyBot SD found a Smitfraud-C.generic virus on my machine within the c:\windows\svchost.exe file. I ran the clean option, but it reappears after re-scanning. Tried some various AV tools online to no avail when I stumbled onto your site.

    I have reviewed the threads I could find that seemed related, and I have followed the instructions on the Read Me First a& Vista & Windows 7 Malware Removal/Cleaning Procedure sections.

    TDS Killer was unable to load its log & driver according to error messages received.

    I have ran all of the software as described and have attached the logs here.

    Any help you can give is greatly appreciated!

    Thanks,

    Chris
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MBAM found and removed it. Are you still having issues?
     
  3. cegan24

    cegan24 Private E-2

    Hi TimW,

    Yes it did report finding and removing files, but upon reboot, it still spawns 10+ svchost.exe's and shows up in scans as being present.

    It has actually gotten worse now, with random reboots and some bluescreens. Had to unplug all USB devices other than mouse & keyboard to stop the BSOD's.

    I am close to just formatting the C drive and starting over, but I am afraid that when I copy data and restore it, or reattach the other drives it will be hiding somewhere and just come back...

    Sooooo frustrating!

    Thanks,

    Chris
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.
     
  5. cegan24

    cegan24 Private E-2

    Thanks, here is the log file. Still having the issues.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!

    Now rerun MBAM and attach the log.
     
  7. cegan24

    cegan24 Private E-2

    Sorry, thought I had done it right by exiting the tea timer from the system tray. I should have it right this time.

    Thanks for your help.
     

    Attached Files:

  8. cegan24

    cegan24 Private E-2

    I just noticed a new symptom, my sound has gone out. Windows thinks it is sending sound, but nothing is making it out of the card. Speakers work find on another system. Not sure when this started as sound was the last thing on my mind with all these other issues, I just noticed today I had not heard a system beep in awhile so I checked and no sound at all is working..
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your latest MBAM log is clear. Other than the sound issue, what is happening?
     
  10. cegan24

    cegan24 Private E-2

    Sound, 17 svchost.exe's running, 1 svchost.exe*32 running, resources slow, browsing slow, BSOD's when anything USB is plugged in other than keyboard/mouse, random reboots.

    All of the other symptoms started when I began troubleshooting the slowness and noticed the many svchosts running, once I started running the tools I downloaded here I got the BSOD's, reboots and sound issues.

    I would simply format and reinstall, and in some ways a clean start would be good as it has been awhile since I did that, my fear is just that whatever caused this is hiding in some file and will come right back again after I restore my non-OS files. Any thoughts on that?

    Thanks,

    Chris
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You might be best off doing a complete restore of your system. Save only your personal data to a thumb drive, those will not be infected. Don't save any exe files or such. Make sure you repartition when you reinstall.
     
  12. cegan24

    cegan24 Private E-2

    Thank you
    The advice on the partition, was great. I have just completed my reinstall of windows 7 ultimate 64 bit.

    Before I started installing applications and restoring data, I wanted to do anything I could to prevent another issue like this by installing the best anti-virus/malware/spyware etc. software I can.

    Would you mind giving your recommendations on the best software for this? I have traditionally used free/donation ware for this like spybot & threatfire, etc. but I don't mind paying for software if it is well recommended.

    I would prefer an all-inclusive application that handles all threats to reduce clutter and resource usage, but if the best thing is multiple apps I am open to that.

    Any advice you can give is appreciated.

    Chris
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  14. cegan24

    cegan24 Private E-2

    TimW,

    Thanks, I have been reviewing the link and I am leaning towards either the Comodo or Antiver products. Any preference based on your experiences?

    I see on the Comodo site that they have a free version and some Pay versions that have additional features. If this is your preference, would you recommend any of the Pay versions over their free one, or do you feel the free version is adequate?

    I will also be installing the other recommended products for antispyware, CCleaner, Java updates and settings changes. Great info!

    Thanks again for all of your support.

    Chris
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I recommend you just stick with the free versions.

    And you are most welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds