How to remove SmitFraud
SmitFraud description
SmitFraud is one of the nastier Trojans out there today. SmitFraud once on your computer will hijack your system causing popus to appear. SmitFraud, once executed, will register itself in your system and run a payload. Your desktop will be hijacked and replacing it you will see a fake warning message instructing you to download a spyware remover (usually iGuard). SmitFraud blocks access to some web sites and will sometimes even prevent internet access period.
How to get rid of SmitFraud
This infection can be removed using Spyware Doctor.
Spyware Doctor is widely valued as one of the best AntiSpyware programs available to protect you from SmitFraud and the latest internet security threats. If your computer is infected with SmitFraud we strongly recommend automatic spyware scanner.
How to manually remove SmitFraud
To get rid of spyware such as SmitFraud you need to remove processes, search and delete registry keys, DLL and other SmitFraud related files from your computer.
Take Note: The manual process of removing spyware from your computer is difficult and puts you at risk of damaging your computer. We advise using our automatic SmitFraud remover.
- Uninstall SmitFraud from Control Panel
Start > Settings > Control Panel > Add/Remove Programs. Double click to uninstall. - End these SmitFraud processes:
intmon.exe
intmonp.exe
msmsgs.exe
msole32.exe
ole32vbs.exe
popuper.exe
bsw.exe
helper.exe
hookdump.exe
To stop processes press Ctrl + Alt + Del or click Start > Run > type "taskmgr". Select malicious process in the list and click "End Process" button. -
Unregister SmitFraud DLL files:
hhk.dll
oleadm.dll
oleadm32.dll
wldr.dll
param32.dll
To unregister DLL click Start > Run > type "regsvr32 /u PATH_TO_FILE/FILE.dll" -
Delete SmitFraud registry entries:
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunWindowsFY
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunWindowsFZ
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunmsn messenger
HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionExplorerBrowser Helper Objects{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF}
HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainDefault_Page_URL=[site address]
HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainDefault_Search_URL=[site address]
HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainSearch Bar=[site address]
HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainSearch Page=[site address]
HKEY_CURRENT_USER SoftwareMicrosoftInternet ExplorerMainLocal Page=[site address]
To open registry editor click Start > Run > type "regedit".
Warning! Manual registry entries editing may cause damage to your system.
Download Uniblue RegistryBooster 2010 to scan for registry errors. -
Search and delete these SmitFraud related files:
winhook.exe
winstall.exe
shnlog.exe
uninstiu.exe
wp.exe
zloader3.exe
hp[X].tmp
