smitfraud creating fake registry entries??



Hey group,

I have just begun to post here (new ISP, new news server).

My intention is to exchange information and help where I can.
I am also registered in the Hijackthis forums (german) and work as a TS
agent at a Dutch firm. I actually love helping ppl, it's my second nature.

Here is one bit of info I would like to discuss:

I have been seeing lot's of variants of Smitfraud during my daily work.
There aren particularly difficult to remove, even w/o tools (I have seen
insofar: spysheriff, spyquake, virusbust, win antivirus pro 2006, winfixer
and pest trap).

What I noticed is that you can find at least two or three entries related to
other trojan/viruses in the registry, sometimes quite strange ones, as they
are unusual or even old (sasser, sober, mydoom).

When you try to search those critters in the filesystem you wont normally be
able to find them, even using DIR [filename] /a

Looking the files up in the quarantine of the AV is normally also negative.

My theory is that those entries are put there by smitfraud itself
to mislead the legitime antivirus and the user so that he thinks he actually
needs the paid version of the rogue scanner.

Have any of you some info on this?



.



Relevant Pages

  • Re: Report on Smitfraud-c and Smitfraud-C.toolbar888
    ... | The bad stuff is all in the Windows/System32 file and in the registry. ... FakeAlert and Zlob Trojans. ... Maybe you had both a SmitFraud and Vundo infection. ...
    (microsoft.public.windowsxp.general)
  • Re: Report on Smitfraud-c and Smitfraud-C.toolbar888
    ... | The bad stuff is all in the Windows/System32 file and in the registry. ... | There was a time that the computer would only boot in safe mode. ... FakeAlert and Zlob Trojans. ... Maybe you had both a SmitFraud and Vundo infection. ...
    (microsoft.public.windowsxp.general)