The following instructions have been created to help you to get rid of "Smitfraud-C.MailBot" manually.
Use this guide at your own risk; software should usually be better suited to remove malware, since it is able to look deeper.

If this guide was helpful to you, please consider donating towards this site.

Threat Details:

  • trojan

This trojan gets downloaded and executed in background, it accesses the adressbooks for several email clients like Microsoft Outlook, Eudora and The Bat!
It also creates temporary files , runs them in backgroud. For example it creates a batch file named like itself and executes it with the command executive.
Since the trojan also access libraries used for internet connectivity, it is likely to access the internet without the users knowledge when it has aquired a certain amount of data.
May use WMF exploit to enter the computer.
Supposed Functionality:
supposed to be a Microsoft Outlook Wabber
Removal Instructions:


Important: There are more files that cannot be safely described in simple words. Please use Spybot-S&D to remove them.

Final Words:

If neither Spybot-S&D nor self help did resolve the issue or you would prefer one on one help,
  1. Please read these instructions before requesting assistance,
  2. Then start your own thread in the Malware Removal Forum where a volunteer analyst will advise you as soon as available.