Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Smithfraud C. Virus Help

  • Please log in to reply
1 reply to this topic

#1 dangler


  • Members
  • 1 posts
  • Local time:02:20 PM

Posted 14 November 2005 - 08:22 PM

I am running Windows ME. I use Netscape 7.0 as my main browser. I could stay connected to the internet all day without anything abnormal happening or any pop-ups until about 2 weeks ago. If I am not physically at the machine to immediately close out these pop-ups, the computer locks up completely. As it is, it randomely locks up or does other not normal things. I used to have Norton Anti-Virus and it was up to date. Then all of a sudden it was gone. (I am not too computer savvy, but I know for sure I did not delete it.) Also, my CD no longer works. I had to unplug the cables from it. If it is kept plugged in, the computer bogs down tremedously. I know the CD itself is good, I took it to work and successfully put it into other computers. (I am ok doing things with hardware, but the rest is troublesome).
I proceeded to download spybot and AVG. I ran them both. The only thing that remains is in spybot. It is smithfraud.c . Spybot will not get rid of it. Every time I reconnect to the internet, Spybot finds a registry change and after I am done, I run spybot again and it finds 50 more things and deletes them all except this smithfraud.
I did an internet search on this and I found this site. There is a self-help fix in the topics, but quite honestly they are hard for me to follow and I am having some trouble downloading some of the things that are required.
Here is what I have done. I have downloaded Hijackthis and smitrem.
What can I do from here.? Is there an easier fix?
I hope I have provided enough information and would greatly appreciate some handholding thru this.

BC AdBot (Login to Remove)


#2 stidyup


  • Members
  • 641 posts
  • Gender:Male
  • Local time:02:20 PM

Posted 15 November 2005 - 03:07 AM

If you think you are infected submit a hijackthis log to the HJT Forum.

How to submit a hijackthis log

Download Hijackthis

Try running the following from safe mode (Getting to safe-mode) Sysclean you'll also need the virus template file from here lpt***.zip remember to extract the contents of the zip file into the same folder as Sysclean.com


DrWeb CureIT


KASFX which is powered by the Kaspersky AV engine, you will need internet access to update it. If you haven't got net access in safe mode, update it before you use it.

If your good with the command line also try Sophos Command Line scanner this command will scan all of your hdd's SAV32CLI.EXE -F -di -remove -dn -mbr -all -zip -p=avscanlog.txt and give you a log file to review afterwards.

Also try installing and running A2 Free and Ewido

I'd also run Spybot(Spybot Tutorial) and Adaware

If your using Win2K/XP run adaware/spybot from "safe mode with command prompt" If your using Win9x just run it from safe mode the command line options aren't needed.

At the C:\ prompt type the following:-

C:\progra~1\spybot~1\spybotsd.exe /autocheck /autofix

Edited by stidyup, 15 November 2005 - 03:09 AM.

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users