Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: Can't remove trojan  (Read 6152 times)

Zanoma

  • Member
  • **
  • Posts: 42
Can't remove trojan
« on: July 17, 2009, 12:53:58 AM »

Hi there

I am close to giving up in this now it's been 2 weeks since I started to try and sort this out

I have a trojan Called smitfraud-c.gp

I have tryed alot of programs to delete this but for some reason I can't

I have also seen that there is a service called power manager which i think is related to this trojan

I have tryed using sdfix etc to sort this but had no luck as of yet

it seems that this smitfraud-c.gp has some how made part of my svchost.exe

thats all I no about it


can any one help me out here I really CBA to format

cheers Alan.
Logged

coolsnakeman

  • Reg Member
  • ***
  • Posts: 421
    • IT Support Belfast
Re: Can't remove trojan
« Reply #1 on: July 17, 2009, 01:54:23 AM »

Hey there,

Well you have 2 options i would say to get rid of that thing the first option would be to format your PC and that you CBA doing. The second option is to actually kill your hard drive but you may not BA to do that either. So its your choice if the virus has locked itself into your registry the only other way to do this is those options unless you can find another way to get rid of it from your registry. If anyone has any other suggestions by all means give them :D
Logged

coolsnakeman

  • Reg Member
  • ***
  • Posts: 421
    • IT Support Belfast
Re: Can't remove trojan
« Reply #2 on: July 17, 2009, 01:56:39 AM »

Hi there

I am close to giving up in this now it's been 2 weeks since I started to try and sort this out

I have a trojan Called smitfraud-c.gp

I have tryed alot of programs to delete this but for some reason I can't

I have also seen that there is a service called power manager which i think is related to this trojan

I have tryed using sdfix etc to sort this but had no luck as of yet

it seems that this smitfraud-c.gp has some how made part of my svchost.exe

thats all I no about it


can any one help me out here I really CBA to format

cheers Alan.
To check your computer for SmitFraud, download SpyHunter Spyware Detection Tool.

SpyHunter spyware detection tool is only a scanner meant to assist you in detecting SmitFraud and other threats. If you detect the presence of SmitFraud on your PC, you have the opportunity to purchase the SpyHunter removal tool to remove any traces of SmitFraud.
Logged

coolsnakeman

  • Reg Member
  • ***
  • Posts: 421
    • IT Support Belfast
Re: Can't remove trojan
« Reply #3 on: July 17, 2009, 01:59:37 AM »

If you CBA with that then go to http://forums.majorgeeks.com/showthread.php?t=158382 which i am sure will point you in the right direction to get rid of that thing. Other than that i think this is a "pain in the arse" virus that the only way to get rid of is to either format or kill your hard drive in 7 easy steps  :P
Logged

oldfogy

  • Helpful
  • Kitizen
  • *
  • Posts: 3568
  • If it ain't broke....... I'll soon fix it.
Re: Can't remove trojan
« Reply #4 on: July 17, 2009, 02:25:08 AM »



I am close to giving up in this now it's been 2 weeks ........

I don't think CBA may have been one of your better ways of asking for help (just a hint for the future)

However.
Firstly you don't say what operating system or what current AV program you are using.

Have you tried "System Restore" obviously going back a few weeks?
Or, have you tried booting into "Safe Mode" then trying to remove it?
Or, you could try "Malwarebytes" or "CCleaner"
Or even one of the may on-line scanners, such as Symantec or Panda, although with Panda you will have to download a small piece of software to begin with, but some people highly recommend the program.

See if the tips on this page help.
http://www.smitfraud.net/
« Last Edit: July 17, 2009, 02:31:52 AM by oldfogy »
Logged

Zanoma

  • Member
  • **
  • Posts: 42
Re: Can't remove trojan
« Reply #5 on: July 17, 2009, 02:42:35 AM »

Windows xp pro service pack3

I disabled my system restore never like it ...

tryed booting into safemode as mostly all virus dont work in safe mode but for some reason I can't remove this :(

Ccleaner is just for cookies and registry files that are no longer in use..... not trojans :P

programs I tryed are

SDfix
spy bot
adawear
and some others that other people used but can't remember the names of now as I uninstalled them......

I am out of idea's now on how to remove this and the dreaded format is drawing closer and closer which I can't be arsed to do as it takes about 6 hours to do :( am guessing that is a new sort of trojan as I cant seem to find much on it ...........
Logged

coolsnakeman

  • Reg Member
  • ***
  • Posts: 421
    • IT Support Belfast
Re: Can't remove trojan
« Reply #6 on: July 17, 2009, 04:19:48 AM »

Well according to the website the previous user posted it has been around for many years. It takes you 6 hours to format XP???? How does that work out then because a standard format on XP would take about 1 hour or an hour and a half at the most so whatever way you are formatting it isn't using the standard CD. Like to said before the hell with getting those programs cause no doubt it will be asking for credit card details to remove the virus. Just kill your hard drive.  How about you check this out. Downloading this may get rid of the virus and actually stop you from having to format as that is what i am guessing what u are looking for: http://www.killdisk.com/
Logged

tuftedduck

  • Senior Kitizen
  • ******
  • Posts: 29658
  • Router Luvvin Duck
Re: Can't remove trojan
« Reply #7 on: July 17, 2009, 06:53:27 AM »

Zanoma, for this infection you need "professional" removal assistance.

Have a read here, it describes the correct way to remove this beast.....not simple, but effective ( and no need to reinstall Windows if done properly )

http://www.bleepingcomputer.com/forums/topic17258.html
Logged

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33884
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Can't remove trojan
« Reply #8 on: July 17, 2009, 11:50:13 AM »

Over the years Ive run into smitfruad quite a lot on infected PCs 
but something else Ive found is that a PC thats been exposed to smitfraud most also has some sort of other viruses lurking in the background too. Win Antivirus is a nasty that often sneaks in there too.

Tools I rely on are HijackThis, the smitfraud removal tool and something called combofix.

bleepingcomputer.com is a good place to download these free tools from, and although Ive not personally used their forums for help they do offer a good and free service.
Theres several other sites that say they can do the job but it normally involves paying for removal tools.

Youve already been given their link for smitfraud removal...  but another one of their tutorials on how to use combofix.
I used this a few weeks back to remove a nasty where others had failed.

http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

oldfogy

  • Helpful
  • Kitizen
  • *
  • Posts: 3568
  • If it ain't broke....... I'll soon fix it.
Re: Can't remove trojan
« Reply #9 on: July 17, 2009, 02:45:54 PM »


It takes you 6 hours to format XP????
How does that work out then because a standard format on XP would take about 1 hour or an hour and a half at the most.....

What the OP possibly means is, 6 hours to get the PC back into some sort of normal running order they way he/she wants it.
On top of that there is then all the time involved with installing additional programs/template and tweaking the said system. Assuming they still have the program on disc or file.
So providing there are no other major issues with the PC, then obviously removing the trojan may be a better bet.

"Although he/she has now already spent 2 + weeks trying to resolve the problem"
Sometimes a format and re-install can be a quicker option, plus it also gets rid of all and any other debis lying around that is certainly now not wanted.

Mine usually takes from start to "final finish" a heck of a lot longer than 6 hours. (more like 6 weeks)
Logged

coolsnakeman

  • Reg Member
  • ***
  • Posts: 421
    • IT Support Belfast
Re: Can't remove trojan
« Reply #10 on: July 17, 2009, 08:33:29 PM »

loll i don't think i would fancy waiting 6 weeks lol. Nasty thing getting a virus in your system only thing is since the internet came about i have never managed to catch a nasty virus (touch wood). Hope all those tips help you out. Give us a shout if you are able to get rid of that thing without a format cause that would be interesting 8)
Logged

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33884
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Can't remove trojan
« Reply #11 on: July 18, 2009, 12:06:57 AM »

I know what you mean...  doesnt take long to install a new system...  but installing everything else and setting it up how you want it  :'(
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

jid

  • Content Team
  • Kitizen
  • *
  • Posts: 1945
Re: Can't remove trojan
« Reply #12 on: July 18, 2009, 10:46:03 AM »

I've come across many viruses in my time (not as many as Kitz though ;) )

I have only seen this one once and I decided that the best option would be to Format.

The machine had more than 80 other infections on there so I came to the conclusion that a 1 and a half hour job and then another day setting it back up was much easier than tackling a virus for days maybe weeks on end :(

However, try these tools which I first used to detect it:-

Spyware Terminator

Spyware Doctor Starter Edition (part of Google Pack)
I have the full copy of Spyware Doctor however the Starter edition can find and remove infections.

Also try Hijack This which Kitz mentioned previously in the thread.

Hope this helps

Regards

Jamie
Logged
Kind Regards
Jamie

BT FTTP - 75meg | Sky Q |  Bridgend Weather

kitz

  • Administrator
  • Senior Kitizen
  • *
  • Posts: 33884
  • Trinity: Most guys do.
    • http://www.kitz.co.uk
Re: Can't remove trojan
« Reply #13 on: July 27, 2009, 12:54:17 PM »

>> I've come across many viruses in my time (not as many as Kitz though Wink )

I first became really interested in them when doing my dissertation and I got sidetracked for a while as [enter geek mode]  I found them quite interesting [/end geek mode].

Once upon a time I used to earn a "bit of beer money" cleaning up infected PCs and I used to be well up on whatever was the latest doing the rounds and I used to be quite stubborn in not letting one defeat me. 
I think the only ones Ive given up on were both in about the early 2000's:
One was a ladies PCs which was fairly old and had been infected with one of the CIH viruses which practically wipes the HDD and also over writes the BIOs..  that was a real nasty and in the end needed a new mo-bo.
The other was SQL-slammer.  PC got infected on the actual night of release into the wild.  There was no fix and no AV that protected against it at the time. :'(

 
These days I dont really see that much of them and its only really the odd occasion when rescuing friends PCs etc.
Logged
Please do not PM me with queries for broadband help as I may not be able to respond.
-----
How to get your router line stats :: ADSL Exchange Checker

oldfogy

  • Helpful
  • Kitizen
  • *
  • Posts: 3568
  • If it ain't broke....... I'll soon fix it.
Re: Can't remove trojan
« Reply #14 on: July 27, 2009, 02:28:45 PM »


.... and the dreaded format is drawing closer and closer which I can't be arsed to do as it takes about 6 hours to do



It takes you 6 hours to format XP????

How does that work out then because a standard format on XP would take about 1 hour or an hour and a half at the most so whatever way you are formatting it isn't using the standard CD.

The time factor is relevant to the size of the XP drive/partition.
I suspect the OP's drive partition is quite large.

Having just installed a 1.5TB drive into one of my PC's it then needed formatting which took just over 5 hours, so I can see what the OP means by not wanting to re-format the drive before re-installing XP.
(When first removing the existing OS ready for a fresh install the drive/partition will have to be formatted before the new installation can take place)

To be able to reduce the formatting time problem I would suggest the XP drive/partition is reduced, possibly to about 40GB, this generally would be more than enough (although my own XP partitions are set at 10, 15 & 20 GB)
Logged