need some help with Smitfraud-C.CoreService

conesean

New member
I ran Spybot and tried to get rid of the infected file. It would not let me delete the file because it is being used by a program.
 
Last edited:
Hello,

Did you run a Spybot-S&D scan in safe mode? In safe mode, you have access to only basic files and drivers. When the machine is operating in normal mode all processes are running.
Scanning with Spybot-S&D in safe mode allows the program to try and remove items that keep reappearing after a scan, despite having been 'fixed'.

Reboot your computer into SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, begin tapping F8.
  • Instead of Windows loading as normal, a menu should appear.
  • Select the first option, to run Windows in Safe Mode.
Open Spybot-S&D while still in safe mode.
  • Close all browsers, check for problems and fix everything found in red
  • Repeat until no more items are found in red
  • Close Spybot-S&D
  • Reboot back into Windows

How to Start Vista in Safe Mode
Windowshelp-Microsoft

A description of the Safe Mode Boot options in Windows XP
http://support.microsoft.com/kb/315222

How to Start a Windows 98-Based Computer in Safe Mode
http://support.microsoft.com/kb/180902
 
Thank you for responding to my problem. I ran spybot in safe mode as per your previously responds. I detected the problem and fixed it. When i opened back off of safe mode I ran SB again and the problem was still there. I will add the results and hopefully that can help.

Smitfraud-C.: [SBI $99619F8C] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-72573027-3237433578-4085058161-1006\Software\Microsoft\instkey

Smitfraud-C.CoreService: [SBI $9C656B9A] Data (File, nothing done)
C:\WINDOWS\SYSTEM32\DRIVERS\core.cache.dsk
 
Back
Top