Please Help - Trojan-Spy.HTML.Smitfraud.c

Discussion in 'Malware Help (A Specialist Will Reply)' started by Aussie Ev, Apr 23, 2005.

  1. Aussie Ev

    Aussie Ev Private E-2

    I've got what I think is a very nasty bugger. Started off with a blue screen telling me I had Trojan-Spy.HTML.Smitfraud.c, ran various scans including Spybot, AD-Aware, Symantic Anti-Virus now it's a black desktop that I can't control. Also my ISP details keep on getting changed ( ie phone number and user ID ),& keep getting links to an undesired website. Have run Hijack This for you, and if you can help please keep it simple as I'm a novice. Thank you
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the Announcement at the top of the page and also read the sticky thread posts.


    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus RemovalMake sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. cow23

    cow23 Private E-2

    I can get everything off comp besides my background is gone......did you fix yet?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please stay in your own thread you started to work your problem. BJ is helping you there with similar instructions.
     
  5. Aussie Ev

    Aussie Ev Private E-2

    Not yet mate but keep watching this ones a nasty bugger hey...
     
  6. Aussie Ev

    Aussie Ev Private E-2

    Rightio, lets start again.
    Have followed the instructions on your info page, did the security check and virus scan, downloaded all the various spyware/anti-virus buggers and ran them in the 'Safe Mode With Networking' mode results are as follows;
    Stinger - nothing
    CWShredder - nothing
    Kill2Me - nothing
    About:Buster - nothing
    CCleaner - deleated a heap of files, said all was clear
    Ad-Aware - nothing
    Spybot - came up with 5 entries of DSO Exploit, all were fixed (then immunised)
    Ran HijackThis immediately after in normal mode and saved it. Still have problems, I originally had the blue screen stating I was infected with Trojan-Spy.HTML.Smitfraud.c, ran scans with Symantic A-V and AD-Aware came up with wp.exe and wp.bmp but wouldn't delete them so I did it manually.
    Then the desktop screen turned black, and it seems my ISP settings keep getting changed, (phone number & User ID), as well as an undisired website that keeps popping up.
    My Hard Drive is only 2 weeks old and had no problems before this as I constantly ran and updated Symantec A-V, SecretMaker, Spybot, and Ad-Aware. PLEEEEEEEEEEESE Help me Mate/s
     
  7. Aussie Ev

    Aussie Ev Private E-2

    Also my browser address bar seems locked. Background still black.
     
  8. Aussie Ev

    Aussie Ev Private E-2

    Sorry I just realised you asked me post my log....
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your Windows OS and IE versions are way out of date and represent a major security risk. After we address your current problems, you MUST get updated.

    You have multiple antivirus applications installed. This is not a good idea. They can conflict with each other and they each require loads of valuable system resources. Pick which you prefer, and uninstall the other.

    What are the below two programs use for:

    C:\Program Files\Matinsoft\GoldTach\GoldTach.exe <-- is this a firewall?
    C:\Program Files\Secretmaker\secretmaker.exe
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You said you found wp.exe and wp.bmp and deleted them. Typically there is a file named Desktop.html that comes along with those. It is normally located at c:\windows\web\desktop.html

    Look for it and if found, delete it.

    Then download, install, update, and run Spy Sweeper
    Let me know what it finds. Save a log and post it if you can.
     
  11. Aussie Ev

    Aussie Ev Private E-2

    Thanks for replying mate, much appreciated.
    Allright, to begin with I've made a few changes since I last wrote. Symantic AV is gone an am just running AntiVir Personal Ed, have gone through your HJT guide and read other threads and fixed/deleted the parts that I was 100% sure were not meant to be there, also have gone through my registry (HKEY_CURRENY_USER\Software\Microsoft\Windows\CurrentVersion\Policies) and deleted the system file, which got me back my background. I am now running Mozilla Firefox as my browser and since doing the Spy Sweeper scan you recom. no trouble with hijacked ISP settings, (it found: CWS_Hotoffers_DesktopHijacker - Adware and
    SwitchDialer - Adware)
    You are correct GoldTach is a firewall
    SecretMaker gets rid of popups, blocks out ads and stops unwanted guests basically.
    In regards to C:\windows\web\desktop.html , I can't remember if I deleted it beforehand but it's not there now ( as far as I can tell ).
    Have posted my new log for you to cast you wisdom across.
    By the way I know that running 2 AV's isn't good but what about many Spyware/Adware programs?
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmm! This last log still shows both AV Personal and Symantec.
    Running mutliple spyware blocking programs can be a waste of systems resources. It depends on which ones. For example now that we have fixed problems, I would uninstall SpySweeper and keep Microsoft Antisyware since the latter is free and the other is only a 15 day trial. You can keep things like Spybot (without Teatimer or SDhelper) and Spyware Blaster. They do not use resources because they do not run unless you run them. Also the free Ad-aware SE which does not have the active Ad-Watch can be kept.

    Your log is clean but you need your Windows Updates and should follow the steps in the below link:
    How to Protect yourself from malware!
     
  13. Aussie Ev

    Aussie Ev Private E-2

    Thanks so much for your advice and help Mr Chaslang. You and others do a top job. Cheers!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're quite welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds