Smitfraud-C.gp fake svchost.exe cant remove

Discussion in 'Malware Help (A Specialist Will Reply)' started by veroqtno, Jan 3, 2009.

  1. veroqtno

    veroqtno Private E-2

    Hi,
    can you halp me with this?
    I try Windows XP Cleaning Procedure but doesnt help me ... every time when some tool delate the svchost.exe few minutes and its appear again.
     

    Attached Files:

  2. veroqtno

    veroqtno Private E-2

    I also tryed with SmitfraudFix.exe but its the same effect.

    Sorry for my english.

    May be i must forat my C: drive and install fresh copy of windows to solve this problem ?
     

    Attached Files:

  3. veroqtno

    veroqtno Private E-2

    After several attempts under save mode and normal windows mode finally i get rid from this shits (i think). I did the same things every time i try.

    But last time when i started ComboFix, log file was different.

    Sorry for the inconvenience :) Happy New Year :D
     

    Attached Files:

  4. veroqtno

    veroqtno Private E-2

    C:\Windows\svchost.exe is here again ... :confused :(

    Now i'll preinstall my windows ... nothing help.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All you had to to do was have some patienc and wait for us to be able to answer your thread. Your constant posting kept bumping your thread back to the bottom of our work queue. This was explained in the READ & RUN ME and in our sticky threads. See: Don't Bump! It Only Hurts You!!!

    If you have not formatted, try the below.

    First you must put your PC into normal startup mode with MSconfig as we requested in step 1 of the READ & RUN ME.

    Is the below something you installed and recognize?
    O4 - Startup: eggdrop.lnk = E:\Opit\Test 2\eggdrop.exe

    Uninstall the below old versions of software:
    Java(TM) 6 Update 10


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds