SmitFraudFix download problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by jonnygreenphelan, Jan 12, 2008.

  1. jonnygreenphelan

    jonnygreenphelan Private E-2

    Okay so I was really hoping to get through the whole read me first malware removal instructions before having to ask for help. So I decided to try to remove the malware which I believe I may have gotten. A program called spyguardpro installed itself on my computer and after some research I found that it likely has something to do with the trojan zlob. So as directed by the first step I tried to follow the instructions of how to remove zlob or associated programs. So I have to download smitfraudfix.exe. Simple right? Nope my computer won't let me download it! I have never had trouble downloading any file. I tried using both firefox and IE both download it but then it isn't there to use. Firefox says its done downloading then when I open it it doesn't exist. IE finishes downloading then tries to copy the file from some random '714gl1wx3' to 'c:\'. WTF???? I have never seen anything like this. I've tried multiple mirrors and multiple download locations. I've even tried running the file directly and not saving it to disk. Am I just and idiot who can't download a simple file? Or is it possible that my computer is infected with something that intentionally blocks the download of smitfraud.exe. Any help would be appreciated.
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!

    Run through these step in the order laid out, just to see if the cleanup routines which are the early steps allow you to download files, do please tell us any errors or issues in downloading. But if you can run many of the scans to get logs from the guide below do attach which ones you can get.



    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. jonnygreenphelan

    jonnygreenphelan Private E-2

    I went ahead and continued with the cleaning procedures and found out why I couldn't download smitfraud. It was because my virus scanner wouldn't let me. I had to disable the virus scanner to let me download it. I ran it and it seemed to help. I'm going to post all my logs in hopes someone will check if its clean. Also I had a few problems during the cleaning procedures.
    1) I could not delete everything from c:\quarantine. I did it manually because I couldn't find anything on how to empty my quarantine folder with my virus scan program.
    2) I had trouble with combofix. First my virus scan program really didn't like reboot.exe. It did reboot however it said don't run any programs untill it finishes the computer was already loading programs so I closed them. I'm not sure if combofix completely finished. Should I have possibly turned off my virus scanner while I ran combofix. Also it never changed my time back from 24hr to 12hr time and changed my date a day back. I don't know how to change it back and I would really like to.
    The rest went okay. Spybot found zeno which it seems to be the major problem. AVG found several entries. Also now it seems that I must re do my selective startup selections. Having to run all this in normal startup sure is a pain because it takes long to reboot everytime.
    A great deal of thanks in advance for any and all help you provide!!
     

    Attached Files:

  4. jonnygreenphelan

    jonnygreenphelan Private E-2

    I couldn't also include the combofix log so here it is.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure it helped since you did not do step 2. At least not according to the fact that you only posted one rapport.txt log which was from the scan only part and does not fix anything.

    ComboFix did not run complete but it did fix much of your SmitFraud problem.

    This is because ComboFix did not run properly thanks to McAfee getting in the way. Too bad McAfee cannot detect and remove real malware instead of detecting tools being used to fix your malware that it misses. ;)

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.


    NOOO!!! You should never be using MSconfig for anything other than temporary debugging.

    How to deal with startup processes.
    • First you should uninstall any software that you do not use.
    • Second if you have processes still trying to load at startup even though you have uninstalled them. You can simple use HijackThis to easily remove the startup. That way you will not have to manually edit the registry.
    • Third for software you do not want to uninstall but you don't want it to load at startup, look in the program for an option not to load when Windows starts and disable it this way. If you cannot find an option like that you have two possible actions:
      • if you never want it to load at startup, use HJT to permanently remove the startup.
      • if you sometimes want it to load at startup, use a program like Startup CPL to enable or disable as you see fit.
    I will fix some of these unnecessary startups for you in the below procedure which will help significantly. Other items you need to take care of. Note that McAfee is a major cause for slow startup.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_04

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [{A7-76-67-79-ZN}] C:\Documents and Settings\Laura Chris Green\Local Settings\Temp\T0CHD001.exe CHD001
    O4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exe
    O4 - HKLM\..\Run: [VetTray] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [ugac] "C:\PROGRA~1\COMMON~1\SPYGUA~1\ugac.exe" -start
    O4 - HKLM\..\Run: [troy44] C:\WINDOWS\troy44.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
    O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe
    O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
    O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
    O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner\RegClean.exe"
    O4 - Startup: Robin Hood Update.lnk = C:\Program Files\Robin Hood - The Legend of Sherwood (Demo)\WiseUpdt.exe
    O4 - Startup: Spruce - Auto Update.lnk = C:\Program Files\Spruce\Spruce.exe
    O4 - Startup: TA_Start.lnk = C:\Documents and Settings\Laura Chris Green\Local Settings\Temp\T0CHD001.exe
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O16 - DPF: {54771E6F-A5A2-4413-8FB8-7B8F85398174} - http://dl.lygo.com/Sidesearch/en_US/Lycos/Sidesearch.cab

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
    Last edited: Jan 15, 2008
  6. jonnygreenphelan

    jonnygreenphelan Private E-2

    Thanks so very much for the help I am very grateful. Actually I think I just forgot to attach the report file for the smitfraud fix so I think I did use it right. I attached another rapport.txt file that was created when I did the clean with smitfraud. Anyways I did the procedures you listed and will attach the avenger and mgtools log files. My computer seems to be running fine really. It takes less time to start up. However one weird thing is that it brings up the windows/system32 folder when I start up. This seems strange to me and I hope it isn't doesn't mean my computer is seriously infected. There were a lot more things to fix then I thought I would have to do. I guess my computer was pretty messed up. I will definitely be more careful in the future and employ good malware protection techniques. So here are my logs. I have a feeling I'm still not clean however just from glancing at the avenger log. Anything else I can do to clean my computer?
    Thanks very much
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    It did not find anything to fix but as I said before, ComboFix did.

    Not malware. It is bug caused by how Dell setup your sound card to load at startup. This registry key is not properly setup and causes the system32 folder to open at startup. This bug is even documented in the below link.

    http://www.softwaretipsandtricks.com/startup_applications/7383-leng.html

    You can checked for the fix that is mentioned with Dell.


    What is in the below folder?
    C:\WINDOWS\SYSTEM32\cvirte

    Other than the above suspicious folder, your logs are clean.
     
  8. jonnygreenphelan

    jonnygreenphelan Private E-2

    Okay I fixed the opening up of window system 32 folder with the patch from dell and I checked c:\window\system32\cvirte. Cvirte seemed to have something to do with National Instruments software. I installed Labview a while ago for a class and recently uninstalled it because I don't need it anymore. It seems to have missed that folder. However I went ahead and deleted it anyways because I don't have and NI software. I also toggled my system restore. It seems i'm okay for now. Thanks a bunch again for helping me out.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds