SmitFraud issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by Burning_Monkey, Jun 18, 2007.

  1. Burning_Monkey

    Burning_Monkey MajorGeek

    Ran into some issues with SmitFraud and some other stuff. Just want to make sure that every thing is cleaned up and looking ok. I followed the regular read-me and then went through the SmitFraud removal also. Please let me know if there is anything else I should or need to do.

    Post 1 of 3 to get all the log files attached
     

    Attached Files:

  2. Burning_Monkey

    Burning_Monkey MajorGeek

    Post 2 of 3 to get all the log files attached.
     

    Attached Files:

  3. Burning_Monkey

    Burning_Monkey MajorGeek

    Post 3 of 3, and now all the log files are attached. Finally :D
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please uninstall and reinstall HJT and rename it as instructed in the Read and RUn First!

    Download and install Registrar Lite

    Then run Registrar Lite.

    Copy and paste the below into the Address box of registrar lit and hit the Enter key.

    HKEY_LOCAL_MACHINE\SYSTEM

    Then click the Security pull down ont the top menu and choose Take Ownership. Click OK in the next window to approve it. Now exit Registrar Lite and continue.

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Now attach new logs:
    ShowNew
    GetRun
    HJT ---> properly renamed.
     
  5. Burning_Monkey

    Burning_Monkey MajorGeek

    Thank you for the help Tim and here is a new set of log files.

    Sorry about blowing it on the HijackThis. I knew I was forgetting something, just couldn't figure out what I was forgetting.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment, SE v1.4.2_03

    Search Assist ----->? Did you install this? Is it something you use?

    Are you networked through this domain?
    Domain = pinnacle.local?

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now(not malware, just a resource hog):

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Attach the avenger log.
     
  7. Burning_Monkey

    Burning_Monkey MajorGeek

    The Search Assist can go.

    That registry key is needed by one of the programs that gets run on this computer.

    Pinnacle is the proper domain name.

    The Avenger log is attached.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That looks good ....
    The HJT line was not a nasty ....just a resource hog and does not need to run at startup.

    Attach new logs for:
    GetRun
    ShowNew
    HJT

    I think we're done, but I want to check before you do the final cleanup.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds