Whoo boy Smitfraud and others

Discussion in 'Malware Help (A Specialist Will Reply)' started by Xiro17, Nov 28, 2006.

  1. Xiro17

    Xiro17 Private E-2

    Hello to all major geeks helpers.

    I have a serious problem with smitfraud, and others.

    I have done everything asked in the read and run me thread, and I have also attempted to remove this stuff myself, with some success. I went to the special removal section and found a bunch of usefull tools that took some things away.......I think

    Anyways, I have done the best I can to follow the instructions in that one thread, and I apologize in advance for a few things, because they would not work correctly in safe mode, or would just crash IE.

    Bitdefender would not run in safe mode, and neither would Pandascan. Pandascan on the other hand keeps crashing my IE. I have the icky newest one, and I hate it.

    Anyways, Here are my attachments, and the second post will have the others. PLEASE HELP ME!

    If I have done anything incorrectly, please help me correct my ways and return control of my PC to me!!
     

    Attached Files:

  2. Xiro17

    Xiro17 Private E-2

    And here are the others. If I have double added anything, I apologize again, my computer is giving me a massive headache.

    I really just want this finished, and I don't want to spend another hour re-installing Windows, and having to call their support line so I CAN install it.

    Thank you in advance, I have read so many threads of yours from others who you have helped so I wouldn't have to bug you with this, but it just didn't fix my problems.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You don't appear to have SmitFraud problems. At least not anymore. But you do have other problems. First you need go back and propery run steps from the READ ME.

    You did not do step 0 to uninstall all bad programs like these:
    • MediaTickets by OIN
    • Viewpoint Media Player
    • VSAdd-in for Internet Explorer
    You did not do step number 2.

    You also have Spybot's Teatimer running which we specifically indicated not to run.

    Now Disable Spybot's TeaTimer
    • Run Spybot and click Mode
    • Select Advanced Mode.
    • Then click Tools and select Resident.
    • Now in the right window pane, uncheck TeaTimer.
    • Also while this is open, in the left column now select IE Tweaks
    • and then in the right pane make sure all the Miscellaneous locks are unchecked.
    • Now quit Spybot!
    You also did not get your HijackThis log from normal boot mode as requested.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9

    Now install the current version of Sun Java from: Sun Java Runtime Environment



    I also notice too many antispyware blocking tools. Are Ewido and Spy Catcher free trial versions or paid versions?

    Why do you have more than a thousand files related to Nero's database stuff located in the root folder of drive C? You should delete all this stuff and relocate your datebase someplace else. This is a bad thing to do and can slow your PC down and also it makes it to easy for malware files to hide in your root folder.


    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run this Virtumonde aka Trojan Vundo Removal

    Now attach the below new logs and tell me how the above steps went.

    1. ComboFix
    2. VundoFix
    3. GetRunKey
    4. ShowNew
    5. HJT
    Make sure you tell me how things are working now!
     
    Last edited: Nov 29, 2006
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I've been editing my previous message while you have been reading it. Make sure you refresh the page and re-read all steps.
     
  5. Xiro17

    Xiro17 Private E-2

    I have gone through and noticed that those three things were in my add/remove programs. They must have installed themselves somehow at some point. I am being as very clear and honest about this as possible. When I went through the last time and removed stuff from there, the only things in there that were to be removed when I did it were virus alerter, and the smitfraud888 toolbar. I have now uninstalled those.

    I recently downloaded ewido, which is free, but when I attempt to use it, it does not to anything, I get an hourglass and then nothing. spy catcher is also a free version. I will uninstall those, because they haven't done anything for me, and then I will await your next orders.

    Teatimer is also ticked off, and the IE thing is done.

    I am currently waiting for the java download to finish, there's 5 minutes left, I will then install it and do the combofix and vundofix stuff.

    I do apologize for not having everything completely ready for you. I am doing the best I can with a computer that's acting like a pile of junk..
     
    Last edited: Nov 29, 2006
  6. Xiro17

    Xiro17 Private E-2

    Ok, Here are the next 2 posts with my findings.

    Again, I do apologize for the headache this is giving you, I am doing the best I can. I build computers, I don't fix'em...

    Things seem a bit snappier, at least firefox loads much quicker

    I did not uninstall ewido or spycatcher yet, but I probably will, since again as said before, they haven't done anything for me.

    I noticed a new folder named Qoo something, never saw it before.

    anyways, here ya go.
     

    Attached Files:

  7. Xiro17

    Xiro17 Private E-2

    Please let me know what I can do next. I will check my add/remove programs again to see if anything has mysteriously popped up.

    Again, thank you, you have been patient with me on this.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to do this now! They are wasting lots of resources and possibly conflicting with Windows Defender. Uninstall them now before you continue!

    Don't worry about it. It is from running ComboFix and my final instructions (when we get to that point) will clean it up.

    You did not take care of that issue I mentioned with Nero. You should not have ALL of those (greater than a thousand) files in your root folder.



    Continue by downloading a tools we will need - Pocket KillBox

    Extract it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\system32\sjktanlf.dll
    O2 - BHO: (no name) - {EC73E96D-108F-45F9-9ED9-6FBDFB069613} - C:\WINDOWS\system32\gebcc.dll (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\jawsraiq.exe
    C:\WINDOWS\system32\wnststr.exe
    C:\WINDOWS\system32\drvbet.dll
    C:\WINDOWS\system32\drvkid.dll
    C:\WINDOWS\system32\drvsuw.dll
    C:\WINDOWS\system32\efcccay.dll
    C:\WINDOWS\system32\iifggge.dll
    C:\WINDOWS\system32\sjktanlf.dll
    C:\WINDOWS\system32\yaywvsp.dll
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!
    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Nov 29, 2006
  9. Xiro17

    Xiro17 Private E-2

    The above steps went according to plan. I uninstalled ewido and spycatcher, however when I uninstalled spycather it told me that anything it quarantined, would then be active on my computer again - that was not a nice thing to see.

    I did go through and delete everything from the c drive you asked me. I guess it was the .dat and .idx files? Again, when I use Nero, I just let it do what it wants. I have only used it a couple times though since my last re-install of win xp. Files just keep popping up on their own though. I don't know what it's doing.

    Anyways. My computer doesn't seem any snappier than before, it acts just about the same.

    Here are the latest 3 documents you would like from me. Again, thank you for helping me with this.

    For some reason the website is telling me that I've already uploaded the three files you want. I will try it again with a double post. Sorry about the inconvenience.
     
  10. Xiro17

    Xiro17 Private E-2

    Ok, it has accepted them this time.

    I do have a question though, why would I want to take the quick time task thing from where it sits? I can only assume that it's a resource hog, so it's not a big deal.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's hope that they are not so stupid that they would move everything back when you uninstall their program. That would be so ridiculously stupid I cannot believe they would even do it by mistake. Perhaps they were just trying to scare you into not uninstalling their program (also stupid).

    Have HijackThis fix the below leftover from them:

    O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll (file missing)
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not what we would truly call a "resource hog" but it is a waste of system resources and it is totally unnecessary to run at startup and to ALWAYS have it running. There are lot's of programs that fit this description.


    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  13. Xiro17

    Xiro17 Private E-2

    Thank you VERY much for helping me with this.

    I will refer ANYONE I know with spyware/adware/malware any kind of BAD things to you guys. I really appreciate your patience and help!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds