NEED HELP TO REMOVE Trojan-Spy.HTML.Smitfraud.c

Discussion in 'Malware Help (A Specialist Will Reply)' started by KittyM, Jun 24, 2005.

  1. KittyM

    KittyM Private E-2

    Okay. If ya'd be so kind... and give me a step by step removal instructions I'd be forever in your debt :D I'm not sure how I got this, but it was today while I was away from the computer at school. My brother was using the computer at the time I was away and who knows what he might of done while on the computer. Anyways... When I went on the computer I saw my desktop with a blue background as my desktop with white text saying...

    "Secruity warning

    A fatal error in IE has occured at 0028:C0011E36 in VXD VMM<01> + 00010E36. Error was caused by Trojan-Spy.HTML.Smitfraud.c

    * System can not function in normal mode. Please check you secruity settings.
    * Scan your PC with any avalible antivirus / spyware remover to fix the problem."

    And yes it said "Please check you secruity settings." It's not a typo. Avast had a pop up with another Trojan. I'm sorry, but I don't have the exact name for it becoz I thought I'd be able to fix this... If I remember it was something like Trojan Win32.Kuang2. I beleve that is gone now since I'm not getting the notification that it's still in my computer. When I right click my desktop to change the picture. I don't have the tabs that you would normally have. It only gives me "Screen Saver" and "Settings". I also use WinPatrol which keeps giving me notifications that during my next start up "C:\WINDOWS\system32\svcnut32.exe home" will automatically run. I clicked No, so it wouldn't. Then a few seconds later a pop up would appear from WinPatrol...

    "A change has been detected in your Internet Explorer Start Page

    Your new page is res://C:\WINDOWS\system32\shdocpv.dll/secruity.htm#subID=PSFV;6384
    If this is ok, then click Yes or press Enter,

    Click No or press Esc and we'll restore your page to about:blank."

    And of course I clicked No so it would restore my default as about:blank. What I done so far was got rid of the Win32.Kuang2 thing from using avast by scanning. I scanned into my local drive and did a standard scan. Deleting it then rescanned using a quickscan to make sure. I haven't restarted my computer yet becoz of the fear of maybe having to reformat or having the computer be to greatly damaged since the desktop said to run in normal mode. I downloaded HijackThis - v1.99.1 and did a scan and this is the result.
    ------------------------------------------------------------------------
    Edit by chaslang: Unrequested inline log removed
    ------------------------------------------------------------------------

    And now I don't know what to do exactly... Can ya help me out?
     
    Last edited by a moderator: Jun 24, 2005
  2. KittyM

    KittyM Private E-2

    Ay sorry I did not read the sticky saying NOT to post the log. Terribly sorry... Um I uploaded it here and ya... Please help :(
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So why did you post another one??

    Please read the announcement and sticky threads. HJT logs should only be posted when requested and then they must be attachments to your message. Please run the steps below.

    - You should first bring up Control Panel and run Add/Remove programs and uninstall Messenger Plus! 3. It can put all kinds of bad stuff on your PC including a LOP infection.

    - Do you know what the below is? I'm not sure if it is valid or not.
    O4 - HKCU\..\Run: [MSNShell] C:\Program Files\MSNShell\BIN\MSNShell.exe autorun

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem, boot into normal mode and make sure you follow these directions:


    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also do you know what the below is:

    O4 - Global Startup: Windows Sniper.lnk = C:\Program Files\WindowsSniper\WindowsSniper.exe


    You seem to be running both Panda and Avast antivirus programs. You must only run one. Uninstall one of them.
     
  5. KittyM

    KittyM Private E-2

    Okay well... The msn stuff are all Plug Ins and winsniper is a program used to minimize and hide windows, but um ok give me a few to do what the direction says...
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What does MSNShell.exe do? I assume it is somehow used with MSN but who makes it and what is it used for?
     
  7. KittyM

    KittyM Private E-2

    that prog just add more game features and such and supposedly handwriting, but msn 7 now has that. It's a bit easier for me to understand becoz it's in chinese.
     
  8. KittyM

    KittyM Private E-2

    Okay I did what ya had on the instructions hopefully I did it right and um here's the results.
     

    Attached Files:

  9. KittyM

    KittyM Private E-2

    I'll check back in the morning for a response...
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not install MessengerPlus3. As I said this can add all kinds of bad stuff to your PC. Sneaky software like this is not to be trusted.

    Stinger should not be running when doing a HijackThis scan.

    You still have both Panda and Avast installed. You MUST uninstall one of them.

    Look in Add/Remove programs for iMesh and uninstall if found.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\Downloaded Program Files\html.exe

    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://C:\WINDOWS\system32\shdocpv.dll/security.htm#subID=PSFV;6384
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://shdocpv.dll/asst.htm
    O2 - BHO: DownloadRedirect Class - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - C:\Program Files\iMesh\iMesh5\iMeshBHO.dll
    O4 - HKLM\..\Run: [FastStart] C:\WINDOWS\system32\svcnut32.exe home
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/14e11a6a5b51c7a68e19/netzip/RdxIE601.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Program Files\iMesh
    C:\WINDOWS\system32\svcnut32.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Additional step to delete html.exe:
    - Click Start, Run, and enter cmd in the box and click OK. This opens a commend prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Downloaded Program Files\
    attrib -r -h -
    s html.exe
    del html.exe
    exit

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  11. KittyM

    KittyM Private E-2

    Thanks so much for your help so far. Things seem to be fine now, but my desktop is still messed up with the msg saying

    "Secruity warning

    A fatal error in IE has occured at 0028:C0011E36 in VXD VMM<01> + 00010E36. Error was caused by Trojan-Spy.HTML.Smitfraud.c

    * System can not function in normal mode. Please check you secruity settings.
    * Scan your PC with any avalible antivirus / spyware remover to fix the problem."

    When I right click my desktop and go to properties I still only have the tabs "Screen Saver" and "Settings" I'd like to get that fixed >< Oh yes while I was uninstalling I've stumbbled across having avast finding Trojan Gen and Win32 Kuang2 I think I was able to get rid of those by telling avast to delete them becoz it isn't coming up anymore. Winpatrol right popped up 2 windows on me saying that my Yahoo Browser wants to change my IE and I clicked no. The second one said myYahoo Browser "A change was made to use the following program for this file type." Then it says rundll32.exe shdocvw.dll,OpenURL %| What should I do now?
     

    Attached Files:

  12. KittyM

    KittyM Private E-2

    oops >< I couldn't find "O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/14e11a6...ip/RdxIE601.cab" Afterwards I did so I did the steps over again and here's the log once again... I still have the same problem though with my desktop
     

    Attached Files:

  13. KittyM

    KittyM Private E-2

    Is it possible that my run32dll got modified?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixadt.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixadt.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.


    Now reboot and do the below.

    Fixing Locked Desktop
    Also you should right click on your Desktop and select Properties. Then click the Desktop tab and then the Customize Desktop button. Now in the next window that comes up click the Web tab. Make sure at the bottom that Lock desktop items is unchecked. Then in the Web pages: box delete all items but My Current Home Page and make sure it is unchecked too. Then click OK. Apply. OK.

    Now let me know where things stand. If this does not work, we will have to run the full Smitfraud cleanup process even though none of the items seem to be showing.
     
  15. KittyM

    KittyM Private E-2

    Thank you so much ^^ It seems to be all fixed now no problems or anything and my desktop is back to the way it was. Thanks for your time and patience =]
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds