This is a cure if anyone is attacked by MS antispyware 2009
This is a cure if anyone is attacked by MS antispyware 2009
Author
Discussion

Big Fella

Original Poster:

107 posts

246 months

Monday 29th December 2008
quotequote all
Hi all,

My laptop was attacked by MS Antispyware 2009 and after taking advice from thos forum, I fond a cure and so thought to post here in case anyone else gets hit with it:

Do the following:

To restart the computer in Safe Mode, please do the following:

1. Click on Start >> Turn Off Computer >> Restart.
2. Keep pressing the F8 key while the system is restarting.
3. You will get a list of starting options.
4. Select "Safe Mode with Networking" by using the up and down arrow keys.
5. Press Enter key to start the system in Safe Mode.
6. Please Follow the steps and Link to run the program and clean the infections:
7. http://siri.urz.free.fr/Fix/SmitfraudFix.exe

1. Click on the link given above,
2. Hit on "RUN" / "OPEN" /"SAVE" the file.
3. Press any key from the keyboard, then Type "2" and press "Enter" on the keyboard
4. It will analyze and delete/KILL the infections.
5. Press "Y" and "Enter" to clean the registry .
6. You can see a "RAPPORT" Notepad LOG File.
7. Close the log file window and the smitfraud Blue colour window.
8. Restart the computer.

This worked for me when my laptop was infected by the above.

Hope this helps.

Regards,
BF

Zod

35,295 posts

287 months

Monday 29th December 2008
quotequote all
just in case anyone is wondering, "MS antispyware 2009" is malware that has nothing to do with Microsoft, so don't try deleting genuine Microsoft applications.

LeoSayer

7,819 posts

273 months

Monday 29th December 2008
quotequote all
I had that bd on my xp desktop pc.

I tried smitfraud and a few other fixes which didn't work. I managed to edit my registry and delete the program files to get rid of it but I was still unable to update my AVG anti-virus, spybot or adaware.

In the end I gave up and reinstalled windows xp from scratch.

The_Jackal

4,854 posts

226 months

Monday 29th December 2008
quotequote all
How do you get this in the first place? Is it an exe thing or a dodgy website?

LeoSayer

7,819 posts

273 months

Monday 29th December 2008
quotequote all
The_Jackal said:
How do you get this in the first place? Is it an exe thing or a dodgy website?
I think it was a pop-up from a website. It looks very convincing like windows defender or something and it sits in your taskbar and at no time did I ask for anything be installed. Other people use the pc, so I don't know if it was me who got it or not.

The advice with all pop-up style stuff is to close down your browser, don't click on it.

http://news.bbc.co.uk/1/hi/technology/7779223.stm

buggalugs

9,279 posts

266 months

Monday 29th December 2008
quotequote all
The_Jackal said:
How do you get this in the first place? Is it an exe thing or a dodgy website?
Normaly via email!

There's a very interesting disection of an earlier version here -

http://www.theregister.co.uk/2008/08/22/anatomy_of...

LeoSayer

7,819 posts

273 months

Monday 29th December 2008
quotequote all
buggalugs said:
Very interesting.

My AVG free failed to pick it up so I now use Avast instead. Avast has since picked this up once, on my laptop.

buggalugs

9,279 posts

266 months

Monday 29th December 2008
quotequote all
LeoSayer said:
buggalugs said:
Very interesting.

My AVG free failed to pick it up so I now use Avast instead. Avast has since picked this up once, on my laptop.
It's a difficult one. As the bloke in the article said, there were hundreds of different versions on the master site and it almost seemed to be updated daily, so the anti virus people have to work very hard to keep up with the new versions. There will always be a lag of a day or so as new versions come out before detection becomes mainstream.

plastik

32 posts

214 months

Monday 29th December 2008
quotequote all
to have a totally clear system, i use the following on all my clients machines if infected.

first thing kaspersky is installed , updated and authorised.

install- hijack this, malwarebytes antimalware and install spybot search and destroy, also have combofix ready and cccleaner if need be.

do a full scan with kaspersky as normal, delete everything it finds, boot in safe mode F8 then scan again, you have to manually start kaspersky but it will function as per normal.

after a scan restart.
run and update malwarebytes and scan, delete anything you find, do the same with spybot s&d, then run hijack this and check the registry against the scan results site, delete anything listed as nasty.

restart and boot into safe mode, run the above again and then restart.

when back to desktop run combo fix, you may need a few files from microsoft if you dont have them, it will get them for you.

when using this application follow the instructions carefully if your not sure choose no. it will ask you to do a back up however in most cases this will not be needed. let it run it will take some time, when it restarts it will continue its job and that will be that.

do a quick check with the other apps and that should be that.

check your control panel for an application with the word bonjior in its name, this is a trojan/worm application
also check for anything with homeview in its title.


another way of checking things is to goto the start click on run and enter msconfig, in the startup tab you will see a list of items in the start up routine, check for strange names like qrrtteex.exe or anything that makes no sense or is gibberish, this will be asomething linked in the start up, however hijack this will pick it up in its scan log and the results page will tell you which ones to click and delete.

i havent put links for the apps here as im not sure im allowed to or not, if i am allowed i will put the links here and some screenshots of the procedures. there is aa new rootkit with attatched trojans and worm package that has hit several systems i have had to work on lately. and the only way bar a total wipe down and reformat/install was to follow this procedure.antivirus software is only as good as the people who let it do its job, doesnt help when clients disable it because they think thats whats making thier systems slow. go figure " hey client you got several hundred different problems on here"




Hut49

3,544 posts

291 months

Monday 29th December 2008
quotequote all
plastik said:

check your control panel for an application with the word bonjior in its name, this is a trojan/worm application
Is that the correct spelling? (Apple has an application called Bonjour which is installed with iTunes)

Panclan

907 posts

267 months

Monday 29th December 2008
quotequote all
www.malwarebytes.org removes the infection, or it did last time I used it

plastik

32 posts

214 months

Monday 29th December 2008
quotequote all
sorry bit dyslexic and make mistakes with spelling and what i see on screen, its something i have to live with, even with spell checkers i dont always see things it shows me.

bonjour is how it is, im reffering to pc's though and not macs. macs.. god i love them, but they were so much better in os9, never needed an anti virus application on amac before the intels and osx.

i have a client with a several xserves and a few nodes and several times his systems have been hit, mainly by employees attatching various flash drives or opening up attatchments they shouldnt. like i said a security software works as long as the person behind it doesnt disable it.

The_Jackal

4,854 posts

226 months

Monday 29th December 2008
quotequote all
The Bonjour component IS installed as part of iTunes on a PC.

plastik

32 posts

214 months

Monday 29th December 2008
quotequote all
yes but this one has no reference or part of itunes, its a different entity that links to various registry keys and system32 exe files that are not apple related.

Funk

27,644 posts

238 months

Monday 29th December 2008
quotequote all
Panclan said:
www.malwarebytes.org removes the infection, or it did last time I used it
Best fix I've found for the machines I've been asked to remove it from!

philthy

4,697 posts

269 months

Monday 29th December 2008
quotequote all
Funk said:
Panclan said:
www.malwarebytes.org removes the infection, or it did last time I used it
Best fix I've found for the machines I've been asked to remove it from!
Me too.

V12Les

3,985 posts

225 months

Monday 29th December 2008
quotequote all
Panclan said:
www.malwarebytes.org removes the infection, or it did last time I used it
Bigthumbuphere...many times.

Scraggles

7,619 posts

253 months

Tuesday 30th December 2008
quotequote all
mate has avast and was panicking that his wife might find out that he had infected their computer after visting adult sites, spent 3 hours and getting more and more wound up.

rebooted into safe mode, downloaded malwarebytes, could not update it, but it found 26 infections that avast missed, but avast is free he whined...

seems I was checking the same sites he was, nod32 popped up and blocked it, some sort of porntube that needs a "special" codec to play the "films", was unable to close firefox and had to use taskmanager

Taita

7,995 posts

232 months

Tuesday 30th December 2008
quotequote all
Surely using a proper browser, decent HOSTS file and not clicking on pop ups will defeat all this?

Scraggles

7,619 posts

253 months

Tuesday 30th December 2008
quotequote all
that assumes the person behind the computer is sensible, knows what a host file is and how to edit it, vista is known to slow down if using a large one, so the sites I find to cause me hassles get blocked at the router.

friend in question has a 6 year old computer, does all accounts on paper even though he has office installed, has not gotten round to using it.

suggested he use eset's security suite as it was idiot proof, but no, avast is free and as it is his business PC, he has to skimp on it wherever possible to save less than a few pints of beer a month smile