Welcome Guest ( Log In | Register )

      
Discover the best free computer help!
Learn more about Geeks to Go by taking the tour. Spyware, virus, trojan, fake security or privacy alerts? Read the malware cleaning guide.
 
Closed TopicStart new topic
How to remove SmitfraudC [CLOSED], Remove SmitfraudC
murremartin
post Jan 3 2006, 10:12 AM
Post #1


New Member
*
Posts: 6
OS: XP



Hello
I searched with Norman Antivirus and i found SmitfraudC in
C:\Documents And Settings\All users\Application data\Spybot-Search & Destroy\Recovery\SmitfraudC.zip



how can i remove that?
Thank you helpsmilie.gif





This is my log from Hijackthis:


Logfile of HijackThis v1.99.1
Scan saved at 17:20:42, on 2006-01-03
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Norman\Bin\ZLH.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program\MSN Messenger\msnmsgr.exe
C:\Norman\Bin\Zanda.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Norman\Nvc\BIN\NVCSCHED.EXE
C:\Norman\bin\NJEEVES.EXE
C:\Norman\Nvc\BIN\nipsvc.exe
C:\Norman\Nvc\bin\nvcoas.exe
C:\Norman\Nvc\BIN\NIP.EXE
C:\WINDOWS\System32\alg.exe
C:\Norman\Nvc\bin\cclaw.exe
C:\Program\Windows Media Player\wmplayer.exe
C:\Program\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Internet Explorer\iexplore.exe
C:\DOCUME~1\MARTIN~1\LOKALA~1\Temp\Rar$EX00.000\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\Bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program\MSN Messenger\msnmsgr.exe" /background
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1134668841687
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\Program\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\Norman\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\Bin\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Norman\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\Norman\Nvc\BIN\NVCSCHED.EXE



This post has been edited by murremartin: Jan 3 2006, 10:21 AM
Go to the top of the page
 
+Quote Post
tampabelle
post Jan 3 2006, 11:00 AM
Post #2


Member 5k
Group Icon
Posts: 6,363
OS: Windows XP



Hi,

First of all, you are running Hijack This from a temporary folder. Please download and save Hijack This to a permanent folder. (Detailed instructions can be found here).


The file you are referring to appears to have been quarantined by Spybot. It should not pose any problems for you.

Let us do a system scan just to make sure that everything else is fine.

Please visit Panda and do an online scan. Save the scan report.

Run Hijack This and post a fresh HJT log along with Panda scan report.

This post has been edited by tampabelle: Jan 3 2006, 11:00 AM
Go to the top of the page
 
+Quote Post
murremartin
post Jan 3 2006, 11:06 AM
Post #3


New Member
*
Posts: 6
OS: XP



Hello
i also scanned with CWShredder and it founded CWS.msconfig


msconfig i have on autostart on my computer, what should i do?
Go to the top of the page
 
+Quote Post
tampabelle
post Jan 3 2006, 11:31 AM
Post #4


Member 5k
Group Icon
Posts: 6,363
OS: Windows XP



Hi,


Please click on Start ---> Run. Type in - msconfig - and hit enter.

In the Msconfig window, click on General tab and then check the box next to - "Normal Startup - load all device drivers and services".

Reboot the PC.

Please visit Panda and do an online scan. Save the scan report.

Run Hijack This and post a fresh HJT log along with Panda scan report.
Go to the top of the page
 
+Quote Post
tampabelle
post Jan 12 2006, 10:31 AM
Post #5


Member 5k
Group Icon
Posts: 6,363
OS: Windows XP



Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies / Views Topic Information
No New Posts   2 / 535 11th September 2005 - 06:41 AM
Howardyuen started - last by Buckeye_Sam
No New Posts   2 / 1,739 10th September 2005 - 12:41 AM
SaTaNBuGG started - last by Excal
No New Posts   4 / 1,718 3rd October 2005 - 10:37 PM
mktdocdon started - last by loophole
No New Posts   4 / 1,604 25th January 2008 - 07:19 AM
x Despair x started - last by Rorschach112

RSS Time is now: 1st December 2008 - 07:31 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.