smitfraud remnants on desktop --registry editing required?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by KuriousJorj, May 11, 2005.

  1. KuriousJorj

    KuriousJorj Private E-2

    Today I had my computer on a cable modem; it's rarely connected to the internet (It's a dedicated video editing system). (I'm now on my mom's machine, dialup, thus alot of the programs you recommend aren't practical to download right now.)

    Today, while on the cable modem, I got the trojan-spy.html.smitfraud.c. the symptom is the same as many others here; blue vxd error screen during Win2K loading, followed by a webpage advertisement on my desktop which leads to some spyware site, and also interfears with my IE search engine functions.

    I immediately uninstalled/deleted a new program I'd noticed called "security iguard" (I think it was called). I was running out of time (had to leave, no more internet connection), but found this site.

    Ran all the anti-virus and anti-spy software I could. Ran Hijackthis and LSP, as per this site, and eliminated a "23 - Winsock" entry. Deleted "desktop.html" and "wb.bmp," but couldn't find "wb.exe."

    When I load Win2K now, there's no "blue screen vxd busy/error Cntl-Alt-Del" error screen (wb.bmp), and the old advertisement is gone from the desktop (desktop.html), but I still can't access my desktop properties; it's still "looking" for a webpage to load, and under properties is says:

    res://C:\WINNT\System32\shdoclc.dll/offcancl.htm#C:\WINNT\Web\desktop.html

    I was afraid to delete "shdoclc.dll"

    So how do I restore my normal desktop?

    THANK YOU!


    ps. also have a current Hijackthis log file, but it appears alright.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There can be some other files associated with Smitfraud.c

    There are some standard cleaning procedures we will need to follow and then we will get to a HijackThis log (which may be necessary to finish manual cleaning of Smifraud.c). Please follow the steps below.

    Note: do not delete shdoclc.dll but desktop.html should be deleted.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    Download and install Microsoft® Windows AntiSpyware and make sure you get the updates but do not run a scan yet.

    Now reboot into safe mode with no network support, make sure you have no browsers opened and then run a full scan with MS Antispyware and let it fix what it finds.

    Now reboot into normal mode.



    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. KuriousJorj

    KuriousJorj Private E-2

    well, still not clean...

    The symantic scan found 8 trojans, I deleted them all.

    The MS spyware, and several of the others, found various entries again... Deleted/fixed them all. Installed all MS security updates (even though I rarely have this system connected to the internet.)

    As of now, I still have the "blinking" (slow rate; many seconds) between a dull grey and white desktop. The "desktop" properties still point to:
    file://C:\WINNT\Web\desktop.html
    Even though I deleted it yesterday.

    I've attached the log file.

    This has taken 2.5 hours on a high speed connection; I'm just about ready to reinstall (repair) windows if that would fix this; it would be quicker and easier.

    thanks if you can help me
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: well, still not clean...

    I do not see any signs of Smitfraud.c but let's make sure it is not hiding. Run the steps below so we can be sure it is gone. Some or all of the stuff below may not exist but it will not hurt to look.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Open Control Panel and select Add/Remove Programs look for the below programs and uninstall them if found:
    Search Maid
    Security IGuard
    Virtual Maid

    Now exit Add/Remove Programs.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\msmsgs.exe
    C:\WINDOWS\system32\shnlog.exe
    C:\WINDOWS\system32\intmonp.exe
    C:\Windows\System32\helper.exe
    C:\Windows\System32\ole32vbs.exe
    C:\Windows\system32\msole32.exe
    C:\WINDOWS\system32\hpD167.tmp
    C:\wp.exe
    C:\wp.bmp
    C:\bsw.exe
    C:\Windows\sites.ini
    C:\Windows\popuper.exe
    C:\Program Files\Search Maid<--- the whole folder
    C:\Program Files\Security IGuard<--- the whole folder
    C:\Program Files\Virtual Maid<--- the whole folder
    C:\Windows\System32\Log Files <--- the whole folder


    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now reboot in normal mode and continue with the below.

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixwp.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixwp.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add to the registry say yes.
    Now please download HOSTER and then follow the below steps.

    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program.
    Also you should right click on your Desktop and select Properties. Then click the Desktop tab and then the Customize Desktop button. Now in the next window that comes up click the Web tab. Make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.


    Now post a new HJT log. And tell me how things are working.
     
  5. KuriousJorj

    KuriousJorj Private E-2

    I have Win2K, so I searched the WinNT folder, but none of the files you listed were on my system.

    I followed the rest of your steps, but my desktop is still the "blinking webpage" and I can't access my normal desktop properties. And it still points to "file://C:\WINNT\Web\desktop.html," even though I deleted the "desktop.html" days ago.

    I've attached the hijack logfile.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. I forgot to change the C:\windows text to C:\Winnt before posting.

    Are you saying you could not do the below because you cannot right click to get to it?
    If that is the problem, bring upi Control Panel and select Display, then select Desktop, Customize Desktop, then the Web tab. Now make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.
     
  7. KuriousJorj

    KuriousJorj Private E-2

    can't do...?

    Okay, when I bring up the Display Properties, there's no "Desktop" tab or button to click on...?

    As I said, I can't right-click on the "desktop" (well, I can, but it gives me the options it does when you right-click a web page)...

    So I chose to VIEW > SOURCE, and attached the txt file, in case that helps...

    THANKS for your continuing help!
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: can't do...?

    The last part of my message suggested a different method than right clicking the Desktop. Did you try that?


    Are you sure this file: C:/WINNT/Web/desktop.html has been deleted?


    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixdt.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixdt.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add to the registry say yes.


     
    Last edited: May 16, 2005
  9. KuriousJorj

    KuriousJorj Private E-2

    still no go...

    Yeah, I accessed the display setting via the control panel (didn't explain it well)... But there was no "desktop" tab.

    As for desktop.html, yes, I actually searched both partitions (I have a dual boot system, though these problems have all been isolated to the one partition I used to get online), and I could find no remains of desktop.html

    I added the registry fixes, but it STILL alternates between the dull grey/tan thing...

    So I've manually removed harmful files, scanned in safe mode and show all folders, for viruses and spyware, ran hoster and followed all other directions, including registry fixes, but it seems there is still something "looking" for desktop.html, and somehow, there's some sort of webpage "on top of," or interfearing with, my actual desktop. Even display properties through the control panel won't access it.

    Should I just do a "repair" of that Win2K partition? Would that fix it?

    thanks
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: still no go...

    Try this:

    Open Group Policy Editor by clicking Start, Run and entering gpedit.msc and click OK.
    • Navigate to User Configuration | Administrative Templates | Windows Components | Windows Explorer
    • In the right pane, double click on Turn On Classic Shell
    • Set the radio button to Not Configured then click OK
     
  11. KuriousJorj

    KuriousJorj Private E-2

    thanks!

    By messing with the "gpedit.msc," I was able to get my desktop back, though all pics are .bmp's, as no html or .jpg's can be shown... No big deal, though!

    THANKS FOR YOU HELP, I APPRECIATE IT!!!!!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: thanks!

    You're welcome. It sounds like you have some file association issues. You probably need to reassociate jpg and html files to the proper applications. Did you look into your file associations?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds