about blank homepage and security warning on desktop

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ramador, Jun 6, 2005.

  1. Ramador

    Ramador Private E-2

    :confused: I have run cws shredder, adaware, hs remove, stinger, and spybot search and destroy, and nothing works. My homepage still resets to "about blank" . On top of that, today I turn my computer on and I get:

    "A fatal error in IE has occured at 00028:c0011e36in vxd vmm(01)+00010e36. Error was caused by Trojan-spy.html.smitfraud.c"..

    I have attached a copy of my hijackthis logfile.

    Any help would be appreciated.

    Edit by chaslang: Unrequested, very old version, inline log removed

    Thank you
     
    Last edited by a moderator: Jun 7, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the announcement and sticky threads. HJT logs should only be posted when requested and then they must be attachments to your message. Also, your version of HijackThis is extremely old. Please run the steps below.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    Also to get you started and to reduce the size of your HJT log. Do the following:

    After doing ALL of the above you still have a problem, boot into normal mode and make sure you follow these directions:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Ramador

    Ramador Private E-2

    I tried all of the scans, and a bunch of files were deleted or cleaned (approx. 80 total), but I still have the problem. Here is my hijack this log file.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First a few notes:
    - Ad-aware should not be running when using HijackThis.
    - You did not exit browers: C:\Program Files\Internet Explorer\iexplore.exe
    - You install HijackThis exactly where I requested that you not install it. C:\Documents and Settings\Owner\Desktop\HijackThis.exe

    Something appears strange in your HJT log. I see no O4 lines for programs that load at startup. Did you edit this log? Or are you using HijackThis to filter any lines? If so, you must not do that.


    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\SMSSU.EXE
    C:\WINDOWS\System32\Tmntsrv32.EXE

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://targetclicks.net/srch.php?qq=%s
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O15 - Trusted IP range: 206.161.125.149
    O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
    O16 - DPF: {D7A7442D-85A9-475F-82F9-65ED4110B4C5} (iiittt Class) - http://gpstool.globaladserver.com/v30/gpstool.cab
    O19 - User stylesheet: C:\WINDOWS\windows.dat

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\SMSSU.EXE
    C:\WINDOWS\System32\Tmntsrv32.EXE

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. Ramador

    Ramador Private E-2

    I exited all browsers ( I printed the instructions this time), and moved Hijack this to a folder on my c drive (removed it from my desktop ).

    I then did everything you listed below:

    In Hijack this
    -killed SMSSU.exe and and tmntsrv32.exe
    -did a scan
    -checked everything you indicated

    Exited HJT
    Rebooted in safe mode with Netowrk connection
    Deleted SMSUU.exe and TMNTSRV32.exe (this took a little work. I had to end process and quickly attempt to delete the file, as the process would restart automatically within 5 seconds or so )
    Ran CC cleaner
    and lastly, reset my web settings.

    After doing all of that, my Internet explorer still defaults back to "About:blank".
    I have attached a copy of my latest HJT log.

    By the way, I may have deleted the O4's a while back when I had a similar issue, but I am not sure.

    Any help you could provide would be greatly appreciated.
    Thank you.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have some of the same problems along with a new one. Notice the below are in your new log:


    C:\WINDOWS\System32\SMSSU.EXE
    C:\WINDOWS\System32\Tmntsrv32.EXE

    O2 - BHO: XMLDP Class - {60371670-81B9-4d06-9C42-4DEC1AABE62B} - C:\WINDOWS\xmllib.dll
    O4 - HKCU\..\Run: [Tmntsrv32] C:\WINDOWS\System32\Tmntsrv32.EXE
    O19 - User stylesheet: C:\WINDOWS\windows.dat
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download the following tool: Pocket KillBox

    Extract Pocket Killbox to its own folder but do not run it yet. We will need it later.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis again and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes. (I double checking to make sure they are not running again - now matter what happens here, just continue):
    C:\WINDOWS\System32\SMSSU.EXE
    C:\WINDOWS\System32\Tmntsrv32.EXE

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: XMLDP Class - {60371670-81B9-4d06-9C42-4DEC1AABE62B} - C:\WINDOWS\xmllib.dll
    O4 - HKCU\..\Run: [Tmntsrv32] C:\WINDOWS\System32\Tmntsrv32.EXE
    O19 - User stylesheet: C:\WINDOWS\windows.dat

    After clicking Fix, exit HJT.

    Now run Pocket Killbox.

    Now, Copy and Paste C:\WINDOWS\xmllib.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINDOWS\System32\SMSSU.EXE into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the RedX and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINDOWS\System32\Tmntsrv32.EXE into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the RedX and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    Now, Copy and Paste C:\WINDOWS\windows.dat into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your PC to reboot.

    If you get an error message about Pending Operations, just reboot your PC yourself.

    Now get a new HJT log and post it here. And tell us how these steps went and how things are working.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds