smitfraud problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by pimpin72, Jan 2, 2006.

  1. pimpin72

    pimpin72 Private E-2

    Hey, I thank you for all your help in the past. I have been diligent in protecting against malware, and I have kept it away pretty good. At least keeping it at bay. Now, it seems I have one of these smitfraud deals, and it will not leave me alone at all. It keeps reinstalling spyaxe3.0. I have attached my HJT log and smit log. Can you tell me how to fix this one? Also, what can I do to prevent it? Switching to Mozilla has really helped in not getting infections, but spyware software still gets detected, just not nearly as much. Thanks again for your help. Scott
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: scvvhost.exe ?

    You should have started a new thread since this is a new problem! I'll move you to one. Also as usual, you must run the READ & RUN ME sticky which has changed significantly since you last post. There are other logs require. But your problem with SpyAxe means you should run one of the other procedures (also mention with in the new READ & RUN ME):

    Smitfraud, SpySheriff, SpyAxe & PSGuard Removal


    Edit: Was able to figure out how to split off to new thread.
     
    Last edited: Jan 3, 2006
  3. pimpin72

    pimpin72 Private E-2

    Spyaxe problem

    Hey chaslang,

    Sorry I didn't relist before. I had bookmarked that page from my previous problem. I can't believe these malware people actually think they can infect our computers with something just so we will buy their protection. What is that? Isn't that extortion or something? Anyways, this one has to be the most annoying. It "pop"s about every ten seconds with a text bubble coming up from my active programs toolbar. It tells me how my computer is infected and to click on it to get the fix. It is an arrow to their website. Also, it does uninstall with it's own uninstaller, and it stays gone as long as I am not connected to the internet. As soon as I am connected to the internet again, the spyaxe program reinstalls itself again. I ran through the first sticky steps with no real affects. Actually, I have run through that page, the smitfraud... page you sent me, and the smitrem.exe program with no visible results whatsoever. None of the registry keys were in my scan that you had flagged. I wish there was something I could get that would keep this stuff away. I hate to bother someone about my problems, when I should be able to fix them myself. Anyways, I am attaching the smit file and the panda log. The fix did not affect the pop-up text bubble from the active toolbar or the installation of the spyaxe program. Please help. Sincerely, Scott
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Spyaxe problem

    Why are you starting another thread? Please stay in one thread.

    I moving you back again!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: scvvhost.exe ?

    Yes there was a result at one time when you ran SmitRem. Look at your Panda log and you will see:

    Virus:W32/Smitfraud.D Not disinfected D:\WINDOWS\system32\wininet.old

    That resulted from running SmitRem when it renamed the infected file and restored a clean one.

    And yes there was something in your HJT log to fix that was shown in that link:
    O4 - HKLM\..\Run: [SpyAxe] D:\Program Files\SpyAxe\spyaxe.exe

    Delete all the stuff in the Panda log. You may need to boot to safe mode to delete them.
     
  6. pimpin72

    pimpin72 Private E-2

    Hi Chaslang,

    I deleted all things that were on my Panda log. One .dll file, wbeconm.dll, would not delete, but I remembered from a previous fix that I can rename these .dll files to get rid of them. Sure enough, I renamed it wbeconm.not, and then rebooted, then brought it back up and deleted it. That, finally, rid me of the spyaxe bug. Interesting about this one, it always started with windows no matter in regular mode or safe mode. Also, if I deleted, or uninstalled the spyaxe software, it would reinstall itself within five minutes. But it would not reinstall itself when I wasn't connected to the internet. So the fix above was done when I had broken off my internet connection. I appreciate your help and patience. It is a bummer that there isn't a good spyware cleaner that can clean these types of problems yet, but one will be out soon. Thanks for your time! Sincerely,
    Scott
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Spy Sweeper is the best thus far at fixing some of the tuffer issues (like Look 2 Me, Virtumonde and a few others).

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds