Smithfraud-C, PSguard and Bestweblinks question

Discussion in 'Malware Help (A Specialist Will Reply)' started by Capt'n Crash, Aug 17, 2005.

  1. Capt'n Crash

    Capt'n Crash Private E-2

    Thanks to the information I found on this site I was able to eradicate these nasty pests but I have one thing left to fix that is bugging me a little bit.

    Although my PC seems to be working fine now and no spyware or viruses are being detected when I boot up windows 2000, I used to get a light blue background behind the splash screen - please wait...windows is starting up...preparing network connections etc. Now the background is black (I assume this is a remnant from when the virus changed my desktop background to a black background with the red spyware warning message on it) The black background also persists when windows is shutting down when it used to be light blue before my system was compromised. After bootup the wallpaper I normally use is now restored and displays properly.

    Can anyone tell me which registry setting controls the background screen color at startup and shutdown so I can reset it to its former light blue again?

    Thanks,
    Dave
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download SmitRem

    Then boot to safe mode and run smitRem.exe and follow the prompts.
    It will create a log at C:\smitfiles.txt - Please attach it to your next message.

    If that does not fix your Desktop, one of our registry patches will more than like do it. But let's see what the above does first.
     
  3. Capt'n Crash

    Capt'n Crash Private E-2

    Hi Chaslang,

    Thank you for replying. I have attached the log which was generated at the time I was in the process of eradicating the virus.

    I was able to do a little research on the net while at work today and found a site which gave me the registry key that controls the bootscreen background colour for all versions of windows which I will share:
    HKEY_USERS\.DEFAULT\Control Panel\Colors which the virus set the value data to "0 0 0" which is black. I was able to reset the value to "58 110 165" which is the light blue I was after by comparing it with my wife's machine's registry (also running windows 2000) reboot and now I get the light blue background at bootup and shutdown.

    If you would like I can post my HJT log pre and post infection if you would like to verify that the log is now indeed clean. I am not sure at this point if any other registry setings have been altered which I am not aware of as yet.

    Thanks again for all of the help you are providing on this site, judging by the number of posts since last evening, its apparent that you all are very busy helping people combat these nasty bugs.

    Dave
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have fixed many of these here on MG's. There are loads of thread with registry patches to fix the desktop issues. See msg # 23 in the below thread:

    http://forums.majorgeeks.com/showthread.php?p=609698&posted=1#post609698


    Are you having an additonal problems from this infection. If so, standard cleaning procedures must be run first before we would get to a HijackThis log. I'll give you the full process below if you need it.


    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. Capt'n Crash

    Capt'n Crash Private E-2

    Hello again Chaslang,

    Yes, as I stated in my first post, your forum is a very excellent source of information for removing spyware which provided me with sufficient information through browsing tutorials/stickies/advice on similar HJT logs to eradicate this most invasive virus. I have all the latest Win2k updates, Ad-Aware pro along with SB S&D and Antivirus Personal Classic installed and this bug steamrolled right over them and infected my system.

    I have performed the recommended cleaning processes in the tutorials and done the recommended online scans using trend micro which indicated the system is no longer compromised. I did not however install ewidow as recommended in some of the posts or import any of the registry fixes you provided a link to. I also went into control panel and reset all my internet settings back to default (medium on the slider bars?) for each icon.

    I installed the latest version of HJT and fixed the suspect log entries in safe mode, ran SMITHREM, antivirus, SB S&D and ad-aware in safemode, reboot run HJT and I think the log looks pretty good now with all things Win2k/internet running smoothly as before.

    Attached is the HJT log file after performing the cleaning procedures recommended here.

    Let me know if you think my HJT log is clean.

    Thanks again,
    Dave
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The READ ME FIRST no longer has Trend Micro as the online scanner. You should always be referring to the one in the thread not something you may have saved. The READ ME does change frequently. The two online scanners are now BitDefender and RavAntivirus (which you have not run).

    That said, I see no visible signs of any problems. Are you having any?
     
  7. Capt'n Crash

    Capt'n Crash Private E-2

    Hi Chaslang,

    Thanks for the info regarding the readme first update, RavAntivirus gives me an all clear so I guess I'm good to go!
    Thanks again for helping me out and also for the favorable report on my HJT log. My system has been running well again with no problems that I can detect.

    Have a great weekend!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Enjoy your weekend too!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds