PDA

View Full Version : smitfraud-c help please



darkoni
2008-03-23, 13:40
spybot has picked up a virus called smitfraud-c.gp on my computer but it cant fix it. When I try and fix it a message comes up saying "some problems could not be fixed; the reason couls be that the associated files are still in use (in memory)" I have looked at different forums and found lots of people have been able to get rid of it but only through complicated measures that i don't really understand. I'm not great at computers and really want this smitfraud gone soon as I've had it for a while. please could you give me stright forward, easy to follow advice? Thank you so much!

tashi
2008-03-23, 17:05
Hi there,

When I try and fix it a message comes up saying "some problems could not be fixed; the reason couls be that the associated files are still in use (in memory)"

Have you run Spybot-S&D in safe mode, which gives access to only basic files and drivers. When the machine is operating in normal mode all processes are running.

Scanning with Spybot-S&D in safe mode allows the program to try and remove items that keep reappearing after a scan, despite having been 'fixed'.
http://forums.spybot.info/showpost.php?p=23629&postcount=2


Best regards.

darkoni
2008-03-23, 20:40
Thank you for replying. I'll try that and then let you know.

darkoni
2008-03-23, 21:11
Thank you so much!! that got rid of it! I've sent you a £5 donation as I think your program is great and that the help i recieved got the problem sorted with no problems. Thank you again and keep up the good work!

tashi
2008-03-23, 21:41
Great, thank you for letting us know, and we appreciate your donation. :flowers:

Cheers.

apollo13
2008-09-29, 19:56
Hi, I'm using Windows 2000 Sp4 and I have formatted and reinstall all again
but the trojan "Smitfraud-c.gp" infect again my computer.
I have installed SpyDestroy 1.6 and it remove it, but in 15 minutes the system
present again the virus in file "A.exe" in system32 and this trojan download other virus as "mda.exe" + "msv.exe" in directory system32.
In few minutes the system crash and show me the advise irreversible error on Csrss.exe and the system REBOOT.
I have also installed Internet explorer 6.0 sp1 and activate in Spybot the block access to registry and blocking of explorer option, but the system (new from format) are always infected in few minuted after connection.
My Antivirus is AVAST free.

There is some possibility to solve it.
Using other computer with Windows Xp Sp3 the problem there isn't.

Thanks



Hi there,


Have you run Spybot-S&D in safe mode, which gives access to only basic files and drivers. When the machine is operating in normal mode all processes are running.

Scanning with Spybot-S&D in safe mode allows the program to try and remove items that keep reappearing after a scan, despite having been 'fixed'.
http://forums.spybot.info/showpost.php?p=23629&postcount=2


Best regards.

wyrmrider
2008-09-29, 21:55
Gentlemen:
IMHO anyone with a smitfraud infection is advised to remove themselves to the Malware Removal Forum
read the stickies
and post a hijack this (not here)
give your posts meaningful names including SMITFRAUD

once posted
DO NOT REPLY TO YOUR OWN FIRST POST

some new versions of smitfraud cannot be removed with spybot (or your AV) and you need the guidance of an expert to use the tools needed

tashi
2008-09-29, 22:19
Hello apollo13,

Please follow the procedure in this link: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Then start your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) where a helper will advise you as soon as available.

Best regards. :)

philipq
2008-10-29, 14:28
new member here and this is my first post. good day everyone.
as you can easily guess, i've had this trojan/virus. in fact i have been getting it several times over and spybot 1.6 always can get rid of it but alas it reappears after another spybot scan. out of sight out of mind and the cycle goes on. until today that i decided to google it, leading me to this site.

question: what exactly is smitfraud-C.gp? If it keeps reappearing after eradicating it, this must be doing some serious screwing around in my lappy for it to be so intrusive and pervasive.

drragostea
2008-10-29, 22:26
phili, SmitFraud is a dangerous malware, leading to the installation of backdoors, other trojans, and probably some pop-ups too.
Rogue programs like WinFixer or VirusHeat are part of the notorious SmitFraud trojan family.
http://research.sunbelt-software.com/threatdisplay.aspx?threatid=44645
-