Html.smitfraud.c

Discussion in 'Malware Help (A Specialist Will Reply)' started by pranavkukreja, Apr 17, 2005.

  1. pranavkukreja

    pranavkukreja Private E-2

    Hi, The Above Mentioned Trojan Is On My Comp....protector Plus 200 Sucks And I Know It....now Ad Aware Has Blocked This Trojan From Changing The Search Pages Etc
    But How Do I Delete It...i Cant Find From Where Its Launching
    Pls Help
    I Have The Log File Ready Too....se.dll In The Temp Folder Is Creating The Problem...if I Delete It It Comes Back Again
    Pls Advise,
    Pranav
     
  2. pranavkukreja

    pranavkukreja Private E-2

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! We do not work on these via email. We work thru problems in the thread posted here in the forum for everyone to benefit from the procedures.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. pranavkukreja

    pranavkukreja Private E-2

    hello
    first all i have dial up so its difficult for me to remain online all the time plus the speeds are slow and so are the downloads

    i have ad aware 6 and spybot....spybot showed allcybersearch as a problem and it got fixed....but it keeps coming back
    ad aware 6 did not find anything...but it detected registry modifications and the file se.dll was trying to change the value of search assistant and search pages continuously....almost 2000 events were logged !
    but i block them all by automatic blocking...i tried removing the se..dll from msconfig -> start up but it doesnt work
    rundll32 executes this se.dll file

    also spyware blaster did not run after installation , it said error on disk or virus pls reinstall
    spyware bouncer detected the infected file called gamespy arcade and deleted it...again it found an infected file and deleted it...
    but still that se.dll file exists...now i killed rundlll32 and deleted se.dll
    but im sure next time it will come back again ( when i reboot)

    i did online scans and nothing worked out !!
    im attaching the hijack this log file ..( i installed it in HJT as u said )
    pls help :)
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ad-Aware 6 is way out of date. If you are that out of date with Ad-Aware I would have to assume your other programs are significantly out of date too. You must update your programs regulary. Spybot is now up to 1.4RC1 and Ad-Aware 6 has become Ad-Aware SE 1.05. And there are recent reference list updates too.

    If you are running msconfig to stop anything from loading, please run msconfig and select Normal Startup. We must see everything.

    If you are using SpyBouncer (you said SpywareBounce) uninstall SpyBouncer as it is a rogue/suspect spyware removal tool. See: http://www.spywarewarrior.com/rogue_anti-spyware.htm

    Why is C:\Program Files\Internet Explorer\iexplore.exe running?

    Did you configure the below ProxyOverrides? If not, do you recognize the URLs?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = dynhost.inetcam.com;register.inetcam.com;;localhost

    I do not see an se.dll problem but I do see C:\WINDOWS\Help\SBSI\cabcom.dll
    which is the same problem being experinced in the following thread:
    http://forums.majorgeeks.com/showthread.php?t=60689
     
    Last edited: Apr 18, 2005
  6. pranavkukreja

    pranavkukreja Private E-2

    hi
    i cannot open any application as it says not enough memory
    btw the ieexplorer thing, that was probabaly some IE page that i double clicked on but did not open.

    No, i dont recognise that proxy over ride nor the URL

    Also there is no SBSI folder in windows/help

    SE.dll keeps coming back in windows/temp folder even if i delete it....
    im telling u that dll file is being put there by the trojan ! and there is also folder being created there called ZGtemp...now Rundll32 executes this dll file
    When i delete rundll32...everything becomes ok , and that file is not created
    Is there any way i can change what rundll32 does ?
    if not how do i detect the goddamn trojan !!!!!!!!!!!!!!!!!

    btw im trying to download spybot 1.4 but it isnt downloading....that se.dll takes up all that RAM and i have only 128 mb ram !
    pls advise
     
  7. pranavkukreja

    pranavkukreja Private E-2

    hey no reply !? ?

    anyway i downloaded spybot 1.4
    and it detected lot of stuff. ..some 8 things
    i deleted it all
    but no effect
    coolWWWsearch.Leftovers is the page that is being searched and destroyed by spybot 1.4
    although it keeps coming back
    at present bot had aware and spybot are blocking the registry changes being made by trojan to value =sp , set to c:\windows\temp\se.dll dllinstall

    now pls recommend some suitable action !!!!!!!
    im attaching log file again....
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now your log shows the SE.DLL problem. It did not show in the last one. I know all about the problems is causes and rundll. It just did not show in you log last time. I have to run off to work right now but give the below a run:


    Download this file: SpSeHjfix109

    Unzip it to your desktop or to a folder.

    Boot into Safe Mode

    Start SpSeHjfix, click on " Desinfecton starten" (the other button means close) then it will reboot and finish the cleaning.

    Run SpSeHjfix one more time.

    Reboot in Normal mode.

    Run HijackThis again and post a new log. Also post the log from SpSeHjfix, the log should be on your desktop or the same folder as SpSeHjfix.
     
  9. pranavkukreja

    pranavkukreja Private E-2

    hi champ !
    ive finally installed avg 6.0 and obtained the virus name
    trojan horse.startpage.16.BD !!!!! ive got some solutions from different sites and im trying them out cause avg does not delete it ...ive tried cw shredder and its still not fixed it...will try ure software and if nothing happens i shall mail u the log
    see u in a couple of hours :)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    AVG will not fix it. I have fixed a couple dozen of these here on MG's!
     
  11. gonzal13

    gonzal13 Private E-2

    I would download winpatrol from www.winpatrol.com It gives you more details about what is running and allows you to deleate it or temporariy suspend it.

    Next I would take the shotgun approach and look to see if it is mascarading as a trojan horse or is it a virus. Sometimes you may with some programs get the wrong impression.

    Run at least 2 of these:

    Edit by chaslang: External links removed.

    All of the items you are referring to are available here on MGs. Please do not post links to othersites for programs available here. In addition, they are all referred to in are sticky threads which cover cleaning procedures and most have already been run.

    Winpatrol is also on MGs.


    The problem here is well known. We do not need to dig any deeper. We have seen and fixed hundreds of these!
     
    Last edited by a moderator: Apr 20, 2005

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds